EDBT 2026 Demo / reviewers in the wild / expert
Nen-Fu Huang
dblp:31/7003
· DBLP profile ↗
93ranked-venue papers
47as first author
8since 2021 · last 2027
0000-0003-0231-0232ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 61 · 34 first-author · 2 since 2021Databases, data management, data science and information retrieval · 7 · 4 first-authorApplied, interdisciplinary, general and emerging computing · 5 · 3 since 2021Artificial intelligence and machine learning · 4 · 3 since 2021Systems, architecture and hardware · 4 · 2 first-authorTheory of computation · 4 · 3 first-authorSecurity and privacy · 2Human-computer interaction and ubiquitous computing · 2Software engineering, systems software and programming languages · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer networks
17 papers |
Internet architecture and protocols · 24% Optical networks · 22% Routing and switching · 16% | |
| Computer architecture, parallel and distributed computing, and storage systems
3 papers |
Distributed systems · 40% Performance modeling and evaluation · 27% Parallel and multicore computing · 27% | |
| Network and information security
1 paper |
Network security · 100% |
Topics — the 30 heaviest of 54, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Parallel and multicore computing › parallel architecture
multicore packet processing |
0.2 | 1 | 2016 | qcAffin: A Hardware Topology Aware Interrupt Affinitizing and Balancing Scheme for Multi-Core and Multi-Queue Packet Processing Systems · IEEE Trans. Parallel Distributed Syst. 2016 |
Performance modeling and evaluation
workload characterization |
0.2 | 1 | 2016 | qcAffin: A Hardware Topology Aware Interrupt Affinitizing and Balancing Scheme for Multi-Core and Multi-Queue Packet Processing Systems · IEEE Trans. Parallel Distributed Syst. 2016 |
Distributed systems
fault tolerance |
0.1 | 1 | 2011 | Efficient and Adaptive Stateful Replication for Stream Processing Engines in High-Availability Cluster · IEEE Trans. Parallel Distributed Syst. 2011 |
Distributed systems › fault tolerance › high availability
high-availability cluster |
0.1 | 1 | 2011 | Efficient and Adaptive Stateful Replication for Stream Processing Engines in High-Availability Cluster · IEEE Trans. Parallel Distributed Syst. 2011 |
Distributed systems
replication |
0.1 | 1 | 2011 | Efficient and Adaptive Stateful Replication for Stream Processing Engines in High-Availability Cluster · IEEE Trans. Parallel Distributed Syst. 2011 |
Network security › intrusion detection and prevention › intrusion detection
deep packet inspection |
0.1 | 1 | 2010 | In-Depth Packet Inspection Using a Hierarchical Pattern Matching Algorithm · IEEE Trans. Dependable Secur. Comput. 2010 |
Network security › intrusion detection and prevention
intrusion detection |
0.1 | 1 | 2010 | In-Depth Packet Inspection Using a Hierarchical Pattern Matching Algorithm · IEEE Trans. Dependable Secur. Comput. 2010 |
Network security › intrusion detection and prevention › intrusion detection
pattern matching |
0.1 | 1 | 2010 | In-Depth Packet Inspection Using a Hierarchical Pattern Matching Algorithm · IEEE Trans. Dependable Secur. Comput. 2010 |
Software-defined and programmable networks › programmable data plane
deep packet inspection |
0.1 | 2 | 2016 | qcAffin: A Hardware Topology Aware Interrupt Affinitizing and Balancing Scheme for Multi-Core and Multi-Queue Packet Processing Systems · IEEE Trans. Parallel Distributed Syst. 2016 In-Depth Packet Inspection Using a Hierarchical Pattern Matching Algorithm · IEEE Trans. Dependable Secur. Comput. 2010 |
Internet architecture and protocols
packet processing |
0.1 | 1 | 2016 | qcAffin: A Hardware Topology Aware Interrupt Affinitizing and Balancing Scheme for Multi-Core and Multi-Queue Packet Processing Systems · IEEE Trans. Parallel Distributed Syst. 2016 |
Cellular and mobile networks
mobility management |
0.1 | 3 | 1998 | Architectures and Handoff Schemes for CATV-Based Personal Communications Network · INFOCOM 1998 Virtual LAN Internetworking over ATM Networks for Mobile Stations · INFOCOM 1997 A distributed paths migration scheme for IEEE 802.6 based personal communication networks · IEEE J. Sel. Areas Commun. 1994 |
Routing and switching
IP lookup |
0.0 | 2 | 1999 | A novel IP-routing lookup scheme and hardware architecture for multigigabit switching routers · IEEE J. Sel. Areas Commun. 1999 A Fast IP Routing Lookup Scheme for Gigabit Switching Routers · INFOCOM 1999 |
Routing and switching › IP lookup
longest prefix matching |
0.0 | 2 | 1999 | A novel IP-routing lookup scheme and hardware architecture for multigigabit switching routers · IEEE J. Sel. Areas Commun. 1999 A Fast IP Routing Lookup Scheme for Gigabit Switching Routers · INFOCOM 1999 |
Internet architecture and protocols › multicast
multicast scheduling |
0.0 | 1 | 2004 | Multicast traffic scheduling in single-hop WDM networks with arbitrary tuning latencies · IEEE Trans. Commun. 2004 |
Optical networks › optical switch
tuning delay |
0.0 | 1 | 2004 | Multicast traffic scheduling in single-hop WDM networks with arbitrary tuning latencies · IEEE Trans. Commun. 2004 |
Optical networks
wavelength-division multiplexing |
0.0 | 1 | 2004 | Multicast traffic scheduling in single-hop WDM networks with arbitrary tuning latencies · IEEE Trans. Commun. 2004 |
Internet architecture and protocols › metropolitan area network
distributed queue dual bus |
0.0 | 3 | 1998 | A study of isochronous channel reuse in DQDB metropolitan area networks · IEEE/ACM Trans. Netw. 1998 A Study of Isochronous Channel Reuse in DQDB Metropolitan Area Networks · INFOCOM 1994 A Slot Interleaved Multiple Access Scheme for DQDB Metropolitan Area Networks · INFOCOM 1993 |
Internet architecture and protocols
metropolitan area network |
0.0 | 3 | 1998 | A study of isochronous channel reuse in DQDB metropolitan area networks · IEEE/ACM Trans. Netw. 1998 A Study of Isochronous Channel Reuse in DQDB Metropolitan Area Networks · INFOCOM 1994 A Slot Interleaved Multiple Access Scheme for DQDB Metropolitan Area Networks · INFOCOM 1993 |
Storage systems
storage reliability |
0.0 | 1 | 2011 | Efficient and Adaptive Stateful Replication for Stream Processing Engines in High-Availability Cluster · IEEE Trans. Parallel Distributed Syst. 2011 |
Routing and switching › adaptive routing
deflection routing |
0.0 | 1 | 2002 | Performance Analysis of Deflection Routing in Optical Burst-Switched Networks · INFOCOM 2002 |
Optical networks › optical switching
optical burst switching |
0.0 | 1 | 2002 | Performance Analysis of Deflection Routing in Optical Burst-Switched Networks · INFOCOM 2002 |
Wireless networking › wireless group communication
multicast services |
0.0 | 1 | 2001 | CTMS: a novel constrained tree migration scheme for multicast services in generic wireless systems · IEEE J. Sel. Areas Commun. 2001 |
Optical networks
optical transmission |
0.0 | 1 | 2000 | A novel all-optical transport network with time-shared wavelength channels · IEEE J. Sel. Areas Commun. 2000 |
Optical networks › wavelength-routed network
wavelength routing |
0.0 | 1 | 2000 | A novel all-optical transport network with time-shared wavelength channels · IEEE J. Sel. Areas Commun. 2000 |
Wireless networking
multiple access protocols |
0.0 | 2 | 1995 | DTCAP - A Distributed Tunable-Channel Access Protocol for Multi-Channel Photonic Dual Bus Networks · INFOCOM 1995 A Slot Interleaved Multiple Access Scheme for DQDB Metropolitan Area Networks · INFOCOM 1993 |
Routing and switching
routing |
0.0 | 1 | 1999 | A Fast IP Routing Lookup Scheme for Gigabit Switching Routers · INFOCOM 1999 |
Cellular and mobile networks › mobile networks › mobile network architecture › cellular network architecture
base station architecture |
0.0 | 1 | 1998 | Architectures and Handoff Schemes for CATV-Based Personal Communications Network · INFOCOM 1998 |
Cellular and mobile networks
radio access networks |
0.0 | 1 | 1998 | Architectures and Handoff Schemes for CATV-Based Personal Communications Network · INFOCOM 1998 |
Network optimization and economics
resource allocation |
0.0 | 1 | 1998 | A study of isochronous channel reuse in DQDB metropolitan area networks · IEEE/ACM Trans. Netw. 1998 |
Approximation and online algorithms
approximation algorithms |
0.0 | 3 | 1994 | On the Complexity of Two Circle Strongly Connecting Problems · IEEE Trans. Computers 1992 A Time-Wavelength Scheduling Algorithm for Interconnected WDM Star Networks · INFOCOM 1994 The strongly connecting problem on multihop packet radio networks · IEEE Trans. Commun. 1989 |
Methods — techniques the papers use, named apart from their topics
numerical cost model · 0.5dynamic load balancing · 0.5skippable scan · 0.2hierarchical multipattern matching · 0.2gram frequency analysis · 0.2simulation · 0.2randomization · 0.1dynamic lazy insertion · 0.1counting bloom filter · 0.1heuristic algorithm · 0.1polynomial-time algorithm · 0.0distributed algorithm · 0.0priority-queuing model · 0.0approximation algorithm · 0.0hardware pipeline · 0.0forwarding table compaction · 0.0lower bound analysis · 0.0channel scheduling algorithm · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | Epidemiologically-constrained severity modeling for plant disease detection via progressive multimodal fusion and dynamic multi-task learning
Syed Asif Ahmad Qadri, Nen-Fu Huang |
Expert Syst. Appl. | 2 |
| 2026 | State-of-the-art TinyML approaches for colorectal cancer detection: Current advances, challenges, and future directions
Showkat Ahmad Bhat, Ming-Che Chen, Nen-Fu Huang |
Artif. Intell. Medicine | 3 |
| 2025 | Massive open online course recommendation system based on a reinforcement learning algorithmabstractAbstract Massive open online courses (MOOCs) are open online courses designed on the basis of the teaching progress. Videos and learning exercises are used as learning materials in these courses, which are open to numerous users. However, determining the prerequisite knowledge and learning progress of learners is difficult. On the basis of learners’ online learning trajectory, we designed a set of practice questions for a recommendation system for MOOCs, provided suitable practice questions to students through the LINE chatbot (a type of social media software), and used mobile devices to encourage participation in MOOCs. Reinforcement learning, which involves reward function design and iterative solution improvement, was used to set task goals, including those related to course learning and practice question difficulty. The proposed system encouraged certain learning behaviors among students. Students who used the system exhibited an exercise completion rate of 89.97%, which was higher than that of students who did not use the system (47.23%). The system also increased the students’ overall learning effectiveness. Students who used and did not use the proposed system exhibited average midterm scores of 64.73 and 58.21, respectively. We also collected 227 online questionnaires from students. The results of the questionnaires indicated that 90% of the students were satisfied with the system and hoped to continue using it. Jian-Wei Tzeng, Nen-Fu Huang, An-Chi Chuang, Ting-Wei Huang, Hong-Yi Chang |
Neural Comput. Appl. | 2 |
| 2025 | Advances and Challenges in Computer Vision for Image-Based Plant Disease Detection: A Comprehensive Survey of Machine and Deep Learning ApproachesabstractAs advancements in agricultural technology unfold, machine learning and deep learning approaches are gaining interest in robust plant disease identification. Early disease detection, integral to agricultural productivity, has propelled innovations across all phases of detection. This survey paper provides a meticulous examination of plant disease detection systems, elucidating data collection methodologies and underscoring the pivotal role of datasets in model training. The narrative navigates through the complex areas of data and image processing techniques, segueing into an exploration of various segmentation methods. The survey emphasizes the importance of feature extraction and selection techniques, illustrating their efficacy in increasing classification accuracy. It examines the classification process, embracing both traditional machine learning and avant-garde deep learning methods, with a particular spotlight on Convolutional Neural Networks (CNNs). The study examines over one hundred seminal papers, anatomizing their dataset utilizations, feature considerations, and classification strategies. Overall, the paper contemplates the challenges permeating this vibrant field, addressing critical issues such as dataset diversity, model generalization, and real-world applicability.Note to Practitioners—To ensure crop health and yield, timely and precise plant disease detection is crucial. Our research, titled “Advances And Challenges in Plant Disease Detection: A Comprehensive Survey of Machine and Deep Learning Approaches”, examines the critical role of datasets, advanced image processing, and segmentation techniques in disease detection. This paper presents practitioners with a guide to the latest techniques for enhanced disease detection by emphasizing the significance of feature extraction and highlighting the capabilities of convolutional neural networks (CNNs). By understanding the highlighted challenges, such as dataset diversity and model generalization, industry professionals can better equip themselves to integrate these technological advancements into real-world agricultural applications. Syed Asif Ahmad Qadri, Nen-Fu Huang, Taiba Majid Wani, Showkat Ahmad Bhat |
IEEE Trans Autom. Sci. Eng. | 2 |
| 2023 | Blockchain-based privacy-preserving data-sharing framework using proxy re-encryption scheme and interplanetary file system
Jhong-Ting Lou, Showkat Ahmad Bhat, Nen-Fu Huang |
Peer Peer Netw. Appl. | 3 |
| 2023 | Guest Editorial: Next-Generation Network Automation for Industrial Internet-of-Things in Industry 5.0abstractNetwork automation has originated in the early 21st century by the International Business Machines Corporation (IBM), which was initialized conceptually, including automated configuration, optimization, healing, and protection of network deployment. In the framework of 5G and upcoming 6G, softwarization and virtualization, as well as the conceived pervasive artificial intelligence (AI), have been activating and further proliferating network automation, supporting ubiquitous applications with diverse network demands, which have recently attracted plenty of research efforts. Hao Ran Chi, Ayman Radwan, Nen-Fu Huang, Kim Fung Tsang |
IEEE Trans. Ind. Informatics | 3 |
| 2023 | A Survey of Network Automation for Industrial Internet-of-Things Toward Industry 5.0abstractNetwork automation has been bred by the deployment of 5G based Industrial Internet-of-Things (IIoT) in Industry 4.0, and further approaching pervasive AI and human-robot-interaction/-collaboration toward 6G based Industry 5.0. Hitherto, to the best of the authors knowledge, research efforts are still required to provide a comprehensive review of the state-of-the-art network automation technologies for IIoT in 5G based Industry 4.0 and summary of challenges for next-generation network automation regarding the stricter network requirements of 6G based Industry 5.0. Therefore, in this article, we conduct a comprehensive overview of the state-of-the-art network automation technologies, standardizations, and corresponding impact on IIoT of Industry 4.0. We also forecast the next-generation network automation development toward 6G based Industry 5.0. This article provides blueprint of the next-generation network automation, meanwhile conducting comprehensive overview of the SoA network automation technologies in Industry 4.0, which gains high referable value for the researchers in the relative domain. Hao Ran Chi, Chung Kit Wu, Nen-Fu Huang, Kim Fung Tsang, Ayman Radwan |
IEEE Trans. Ind. Informatics | 3 |
| 2023 | Correlating the Ambient Conditions and Performance Indicators of the LoRaWAN via Surrogate Gaussian Process-Based Bidirectional LSTM Stacked AutoencoderabstractLoRa’s biggest advantage is its flexibility, which is the ability to increase or decrease data rate and range while decreasing or increasing sensitivity. Whenever propagation conditions change frequently, this function allows the spreading factor to be modified accordingly. Despite their efficiency and scalability, adaptive data rate algorithms ignore and fail to factor in the complex correlation between ambient weather parameters influencing the communication channel design. In this research, a Bayesian surrogate Gaussian process-based bidirectional LSTM stacked autoencoder model (BSGP-BLSTM_SAE) is proposed to estimate the channel performance indicators such as received signal strength indicator (RSSI) and signal-to-noise ratio (SNR) and to determine the correlation between the ambient weather conditions and performance indicators for the LoRaWAN network. Bayesian optimization algorithm has been used to optimize the hyper-parameters of the developed model. A LoRaWAN experimental multivariate time series dataset has been used for the evaluation of the developed model, which upon testing and validation produces high accuracy in predicting the channel performance indicators and ambient conditions of the experimental LoRaWAN network. The mean absolute error of the developed model was around 0.45. Thus, the proposed model can predict the link performance indicators and thereby assist in real-time optimization of the transmission parameters to enhance the network performance in LoRaWAN-based systems at different ambient conditions. Showkat Ahmad Bhat, Nen-Fu Huang, Imtiyaz Hussain, Uzair Sajjad |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2019 | A Machine Learning Based Smart Irrigation System with LoRa P2P NetworksabstractIn agriculture, the experiences of farmers are very valuable but difficult to replace and passing on. The lack of working power is also a serious problem for many agriculture countries. For planting organic crops, irrigation is one of the most critical steps but also a very labor intensive work. This paper provides a machine learning-based precise and smart irrigation system with LoRa P2P networks to automatically and seamlessly learn the irrigation experiences from expert farmers for greenhouse organic crops. The proposed system will firstly calculate the amount of water for each irrigation based on the trained irrigation model combined with the environment data, such as air temperature/humidity, soil temperate/humidity, light intensity, etc., and then irrigate the crops automatically via the long-distance and low-power wireless LoRa P2P network. The MAC protocol of standard LoRaWAN is Aloha based (random access) and may not be suitable for real-time automatically control. We implement the automatic irrigation system with LoRa P2P network which is a master-slave and TDM-based MAC protocol. Experimental results show that the proposed smart and precise irrigation system is very suitable for modern green house-based agriculture. Yu-Chuan Chang, Ting-Wei Huang, Nen-Fu Huang |
APNOMS | 3 |
| 2018 | Xiao-Shih: The Educational Intelligent Question Answering Bot on Chinese-Based MOOCsabstractIn this study, the educational intelligent question answering bot named Xiao-Shih has been developed for solving learners' questions as instructors and teaching assistants on MOOCs. Experiments were conducted with Xiao-Shih in a paid course titled "Python for Data Science" on "ShareCourse" which is one of the largest Chinese-based MOOC platform in Taiwan. Over one thousand discussion threads posted in both English and Chinese languages were retrieved to train the bot by natural language processing (NLP) and Random Forest (RF) in machine learning algorithms. This paper presents the implementation details on developing Xiao-Shih. First, we developed an initial version of Xiao-Shih with simply NLP techniques and text similarity approaches. However, Xiao-Shih only obtains 0.413 precision at best with different thresholds of the question similarity. Therefore, features and labels of answering correctness have been collected for the next version of Xiao-Shih. Trained by Random Forest with 70% of the entire dataset, Xiao-Shih obtains 0.833 precision with test dataset. With this educational intelligent question answering bot, learners can solve their problems immediately in seconds rather than wait for humans' response in hours even days. Moreover, Xiao-Shih can also ease instructors' and teaching assistants' burden on answering questions. Hao-Hsuan Hsu, Nen-Fu Huang |
ICMLA | 2 |
| 2017 | A novel vCPE framework for enabling virtual network functions with multiple flow tables architecture in SDN switchesabstractThe virtual Customer Premise Equipment (vCPE) concept has been proposed recently to reduce OPEX and CAPEX. Software-defined networking (SDN) and network functions virtualization (NFV) are key roles for this innovation. This paper proposes a vCPE framework enables deploying VNFs as edge of network. These VNFs are achieved by the synergies between a VNF controller on the cloud and an SDN switch at the edge. A multiple flow table management model is also proposed to implement virtual network functions. Through the proposed vCPE framework, the customer only needs a generic SDN switch at local network and very easy to subscribing different network services, such as Firewall, NAT, DHCP, and applications quality of service (QoS) by a browser-based dashboard. Experiments are conducted to evaluate the performance of VNFs implemented by the proposed multiple flow table management model. The flexibility of framework to integrate with other application classification systems, such as IDS or IPS, is also demonstrated. Nen-Fu Huang, Chi-Hsuan Li, Chia-Chi Chen, I-Hsien Hsu, Che-Chuan Li, Ching-Hsuan Chen |
APNOMS | 1 |
| 2017 | Application identification system for SDN QoS based on machine learning and DNS responsesabstractIn recent years, the demand for application-specific qualify of service (QoS) management has grown. To effectively do application-specific QoS, a system albe to do flow classification at the application level is required. This paper presents an application identification system that can be integrated with a QoS management system in a software defined network (SDN). This paper describes the method to obtain ground truth (label) of the flow from four mainstream operating systems (OS), and the method to classify flow based on supervised machine learning and DNS responses. In our experiment, average F-measure of all applications reached 93.48%. The testing data set contained 294 applications, given that each platform version or execution file of an application was one application. The testing data set included Skype, Facebook, and other popular applications. Results showed that this system can identify application traffic on different platforms with high accuracy. Nen-Fu Huang, Che-Chuan Li, Chi-Hsuan Li, Chia-Chi Chen, Ching-Hsuan Chen, I-Hsien Hsu |
APNOMS | 1 |
| 2017 | Early Notification and Dynamic Routing: An Improved SDN-Based Optimization Mechanism for VM Migration
Xuanlong Qin, Dagang Li 0001, Ching-Hsuan Chen, Nen-Fu Huang |
CollaborateCom | 4 |
| 2017 | Development of Alternative Conception Diagnostic System based on Item Response Theory in MOOCs
Yu-Cheng Cheng, Jian-Wei Tzeng, Nen-Fu Huang, Chia-An Lee |
ICCE | 3 |
| 2016 | Bandwidth distribution for applications in slicing network toward SDN on vCPE frameworkabstractThis paper presents a novel quality-of-service (QoS) management system for SDN networks with the feature of distributing bandwidth for applications in different slicing networks. Thus, the applications in different sliced networks (different divisions of an enterprise) can have different bandwidth management policies. The proposed system is also integrated into a vCPE framework to achieve network function virtualization and easy management. Users are able to subscribe the QoS services for different applications via the proposed web-based user interface. Experiment results demonstrate that the proposed system architecture and algorithms are able to provide efficient QoS services with minimal overhead. Nen-Fu Huang, Sheng-Jung Wu, I-Ju Liao, Che-Wei Lin |
APNOMS | 1 |
| 2016 | Developing a Data-Driven Learning Interest Recommendation System to Promoting Self-Paced Learning on MOOCsabstractA "keywords cloud" learning interest/difficult reminding system based on learners' video watching logs and subtitles is proposed for promoting self-paced MOOC learning. By identifying the hot video segments (via video seek event counts) and weighting the keywords of hot video segments, we are able to establish the "keywords cloud" of each learning topic. This feature is valuable for learners to quick identify the most important or difficult concepts of each topic. This is also useful for the teacher to more understand which parts of the contents of each topic are most difficult for the learners which can be further improved. Hsuan-Ming Chang, Tonny Meng-Lun Kuo, So-Chen Chen, Chia-An Li, Yi-Wei Huang, Yu-Cheng Cheng, Hao-Hsuan Hsu, Nen-Fu Huang, Jian-Wei Tzeng |
ICALT | 8 |
| 2016 | qcAffin: A Hardware Topology Aware Interrupt Affinitizing and Balancing Scheme for Multi-Core and Multi-Queue Packet Processing SystemsabstractInterrupt affinitization of multi-queue network interface cards is a fundamental composition that defines how packets from individual queue are processed by which CPU-cores on multi-core platforms. In this paper, we propose qcAffin to attain an optimal queue-to-core affinitization for packet processing systems based on a numerical cost model derived from hardware topology and runtime system workloads. Static architectural characteristics comprising the memory hierarchy and topology of hardware components are first analyzed to calculate static interrupt affinitization costs. Then we attempt dynamic interrupt affinitization to balance workloads on CPU-cores and improve overall performance. Classical networking applications ranging from bridging, routing, access control list (ACL) matching to deep packet inspection (DPI) with different frame sizes are extensively experimented to compare the performance of the proposed scheme and other existing approaches. As demonstrated in the comparison result, qcAffin achieves the similar performance of the best affinitization approach and outperforms the Linux default affinitizer by averages of 102, 278, 248 and 131 percent on 1G NICs for the four applications. On 10G NICs, dramatic boosts of 1,424 and 1,343 percent are measured for the bridging and routing applications, respectively. Moreover, the effectiveness of dynamic interrupt balancing is justified by a maximum of 150 percent higher system utilization and 1.2 Mpps more throughput compared to the fixed affinitization approach in a simulated setup of unbalanced traffic load. Nen-Fu Huang, Wen-Yen Tsai |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2015 | Fast proxyless stream-based anti-virus for Network Function VirtualizationabstractNetwork anti-virus (AV) solutions are the first line of defense against malicious software. Traditional proxy-based network anti-virus solutions with store-scan-forward techniques decrease network performance and consume massive amounts of memory. Therefore, traditional solutions are not easily adaptable for Network Function Virtualization (NFV). This paper details the work on a novel virus scanning solution for NFV, called StreamAV. It does not require a proxy and maintains high network performance with less memory usage. StreamAV conducts policy matching on streams, rather than on complete files. This eliminates buffering, thereby accelerating traffic and requiring far less memory than solutions that scan complete files. The prototype was 40 times faster than its closest open source competitor, while its memory consumption was only a fraction of that of this competitor. Coverage was 100% with random test samples. Chia-Nan Kao, Salim Si, Nen-Fu Huang, I-Ju Liao, Rong-Tai Liu, Hsien-Wei Hung |
NetSoft | 3 |
| 2013 | Application traffic classification at the early stage by characterizing application rounds
Nen-Fu Huang, Gin-Yuan Jai, Han-Chieh Chao, Yih-Jou Tzang, Hong-Yi Chang |
Inf. Sci. | 1 |
| 2012 | A unique-pattern based pre-filtering method for rule matching of network securityabstractAs a result of continually changing Internet and applications, more and more advanced features are requested to be available in the appliance for more accurately monitoring and managing the network. Therefore, modern networking appliances are equipped with the DPI (Deep Packet Inspection) technology to scan the payload of a packet. A rule (like Snort rules) may consist of several patterns with certain relationships, such as order, relative positions, and offset, etc. The system performance is usually dominated by not only the pattern matching algorithm but also the rule match processing algorithm. This paper proposes a unique-pattern based pre-filtering method for the rule matching. It is employed to filter out unwanted matches after scanning the packet payload by the pattern matching algorithm. The proposed algorithm is also implemented on different multi-core platforms to demonstrate its efficiency and performance. The experimental results indicate that the throughput is improved significantly and can be increased approximately linearly to the number of CPU cores. Nen-Fu Huang, Hsien-Wei Hung, Wen-Yen Tsai |
APCC | 1 |
| 2012 | A port-configuration assisted NIC IRQ affinitization scheme for multi-core packet forwarding applicationsabstractInterrupt affinitization of network interface cards (NICs) is a fundamental composition that defines how packets are processed by which CPU-cores on multi-core platforms. In this paper, we propose a simple port-configuration assisted scheme to attain an optimal affinitization for packet forwarding applications. Experiments ranging from bridging, routing, flow tracking to deep packet inspection are conducted to show the performance impacts utilizing different affinitization approaches. As a result, our proposed scheme achieves the same performance level as the best fixed affinitization scheme. In addition, the effectiveness of interrupt balancing is demonstrated for our scheme to be superior to the widely-deployed irqbalance with varying network settings. Wen-Yen Tsai, Nen-Fu Huang, Hsien-Wei Hung |
GLOBECOM | 2 |
| 2011 | ARMS: An agent-based real-time monitoring system for large scale P2P video streaming platformsabstractThis article proposes an agent-based real-time monitoring system for large scale peer-to-peer video streaming platforms which provides traffic, user receiving quality and system information through web-based presentation. The information is useful for helping service providers to assess the system performance as well as the quality of the streaming service. The monitored information is also stored in backend database and will be valuable to diagnose the streaming system afterwards. In addition, a series of experiments are conducted to evaluate the performance of our system. And we validate the correctness of the monitoring information through simulated experiments and verify the feasibility of our system by combining our real-time monitoring system with a real-world peer-to-peer live streaming system. Nen-Fu Huang, Tzu-Chien Wang, Ming-Hung Wang, Shiu-Shun Peng |
APCC | 1 |
| 2011 | An Efficient Caching Mechanism for Network-Based URL Filtering by Multi-Level Counting Bloom FiltersabstractNetwork-based URL filtering (NUF) is one of the most widely used tools for detecting and stopping malicious and unwanted web traffic, like preventing children from sex. However, currently the conventional techniques still suffer from high bandwidth consumption due to millions of URL analysis requests to the network servers per day. In this paper, a model of NUF using a novel multi-level counting bloom filter (MLCBF) is proposed to address this issue. In the gateways of NUF, MLCBF is used to cache the analysis results from the network server to accelerate web traffic, alleviate the server load, and reduce bandwidth consumption of the entire NUF service. Analysis and trace-based experiments are employed to explore the properties of MLCBF and evaluate its performance in NUF. The results show that the proposed scheme typically eliminates at least 90% of memory requirements as compared to a general hashing table solution. Yi-Hsuan Feng, Nen-Fu Huang |
ICC | 2 |
| 2011 | A Lock-Controlled Session Table Partitioning Scheme with Dynamic Resource Balancing for Multi-Core ArchitectureabstractConnection tracking by manipulating session tables is essential for stateful inspection capable applications such as stateful firewalls, network-based intrusion prevention systems (NIPS), traffic accounting and monitoring to process packets according to session state information. With the prevalence of multi-core computing, it is crucial to optimize the existing connection tracking structures and algorithms to fully utilize the underlying parallelism. In this paper, we propose a lock-controlled session table partitioning scheme accompanied with a dynamic resource balancing algorithm for session-aware multi-core networking systems. Experimental results show that the proposed scheme reduces the number of lock contentions to a maximum of 100 times less and, in turn, boosts the performance to 3.5 Gbps higher than the baseline. 100% resource utilization is also achieved by overcoming the constraint of fixed-sized partitioning. Wen-Yen Tsai, Nen-Fu Huang, Hsien-Wei Hung |
ICC | 2 |
| 2011 | A novel software-based MD5 checksum lookup scheme for anti-virus systemsabstractIn recent years, the size of virus signature databases has been growing rapidly, leading to a corresponding reduction in the performance of anti-virus (AV) software. In general, virus signature databases comprise string-based and hash-based (e.g., MD5) signatures. Currently the majority of signatures are hash-based and Cloud-based AV systems rely on them as the local cache to reduce the network loading. In this paper, we provide a novel scheme for looking up MD5 checksums to improve virus scanning performance involving hash-based signatures. The authors treat the range hash in which characters occur as a filter to avoid unnecessary lookups and keep the range of the exact search range to a minimum. The scheme is 135 times faster than ClamAV's in clean/general cases and only required 4MB of memory for hash-based filtering. This scheme could easily be extended to other hash-based applications. Nen-Fu Huang, Chia-Nan Kao, Rong-Tai Liu |
IWCMC | 1 |
| 2011 | Efficient and Adaptive Stateful Replication for Stream Processing Engines in High-Availability ClusterabstractStateful stream process engines in high availability clusters (HACs) track a large number of concurrent flow states and replicate them to backups to provide reliable functionality. Under high traffic loads, existing solutions in such HACs are expensive owing to precise stateful replication. This work presents two novel methods to address this issue: randomization on replication representation and a replication scheme designed for when system becomes overloaded. A hashing structure called Multilevel Counting Bloom Filter (MLCBF) is proposed as a low resource-consuming solution of stateful replication. Its performance and tradeoffs are then evaluated based on theoretic analysis and extensive trace-based tests. Trace-based simulation reveals that MLCBF reduces network and memory requirements of replication typically by over 90 percent for URL categorization. Most importantly, MLCBF is quite as simple and practical for implementation and maintenance. Moreover, an adaptive scheme called dynamic lazy insertion is designed to prevent replication from overloading system continuously and optimize the throughput of HAC. Testbed evaluation demonstrates its feasibility and effectiveness in an overloaded HAC. Yi-Hsuan Feng, Nen-Fu Huang, Yen-Min Wu |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2010 | SHOCK: A Worst-Case Ensured Sub-Linear Time Pattern Matching Algorithm for Inline Anti-Virus ScanningabstractTo detect viruses, worms and, malware in the multi- gigabit environment, it is crucial for modern content-aware network security appliances to have a fast virus scanning scheme.Signature based multi- pattern matching algorithm is the core technology to enable fast virus scanning accurately and quickly. This paper proposes a multi-pattern matching algorithm with a simple shift/hash technique and a novel heuristic by inspecting overlaps between pairs of patterns to ensure both average and worst-case performance. Experimental results show that our algorithm performs 600 Mbps to 1.4 Gbps faster than the ClamAV AC and BM-based algorithms and achieves a maximum of 3.8 Gbps throughput in inline virus scanning while the memory consumption is nearly the same. Nen-Fu Huang, Wen-Yen Tsai |
ICC | 1 |
| 2010 | Enhancing P2P overlay network architecture for live multimedia streaming
Nen-Fu Huang, Yih-Jou Tzang, Hong-Yi Chang, Chia-Wen Ho |
Inf. Sci. | 1 |
| 2010 | In-Depth Packet Inspection Using a Hierarchical Pattern Matching AlgorithmabstractDetection engines capable of inspecting packet payloads for application-layer network information are urgently required. The most important technology for fast payload inspection is an efficient multipattern matching algorithm, which performs exact string matching between packets and a large set of predefined patterns. This paper proposes a novel Enhanced Hierarchical Multipattern Matching Algorithm (EHMA) for packet inspection. Based on the occurrence frequency of grams, a small set of the most frequent grams is discovered and used in the EHMA. EHMA is a two-tier and cluster-wise matching algorithm, which significantly reduces the amount of external memory accesses and the capacity of memory. Using a skippable scan strategy, EHMA speeds up the scanning process. Furthermore, independent of parallel and special functions, EHMA is very simple and therefore practical for both software and hardware implementations. Simulation results reveal that EHMA significantly improves the matching performance. The speed of EHMA is about 0.89-1,161 times faster than that of current matching algorithms. Even under real-life intense attack, EHMA still performs well. Tzu-Fang Sheu, Nen-Fu Huang, Hsiao Ping Lee |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2009 | A Resource-Efficient Traffic Localization Scheme for Multiple BitTorrentsabstractThe emergence of peer-to-peer (P2P) applications has posed a threat to the operating cost of Internet Service Providers (ISPs) due to the large amount of inter-ISP traffic generated. The problem stems from the mismatch between the P2P overlay network formed randomly and the underlying physical network. Recently, BitTorrent has attracted enormous users by its convenience of large-scale content distribution and has also become a major challenge for ISPs. Therefore, in this paper we proposed an effective B-Proxy scheme to evaluate through realistic simulation on PlanetLab, where hundreds of BitTorrent clients were executed during the experiment. Simulation results show that more than thirty percent of inter-ISP traffic could be saved in a torrent with a relatively small cache size consumed which is only eighth times that of the original file. Nen-Fu Huang, Yen-Ming Chu, Chi-Hung Tsai, Wei-Zen Huang, Wei-Jin Tzeng |
ICC | 1 |
| 2009 | Identifying the Use of Data/Voice/Video-Based P2P Traffic by DNS-Query BehaviorabstractThere are more and more P2P applications in the Internet, with or without encrypted content. The P2P applications can be classified into three categories: file sharing (BT, eMule), VoIP (Skype, MSN), and video streaming (PPStream, PPLive). By observing the common communication nature among the peers, this paper proposes a simple but efficient way to identify the P2P traffic by the DNS query behavior. Experimental results illustrate that the proposed mechanism is able to accurately identify if a host is using data/voice/video-based P2P traffic, even the packet content is encrypted. The proposed mechanism is also capable of detecting future unknown P2P applications as long as they perform the common P2P behaviors. Hung-Shen Wu, Nen-Fu Huang, Guan-Hao Lin |
ICC | 2 |
| 2008 | Evaluation of TCP State Replication Methods for High-Availability Firewall ClustersabstractTo provide the reliable connectivity between two endpoints over the Internet, a firewall cluster for stateful high availability removes the single-point failure by replicating and maintaining TCP connection states to a backup firewall node, at the expense of the costs of network and system resources. In this paper, through trace-based simulations on a prototype implementation, we evaluate the overheads of different state replication methods with a tunable time-triggering parameter. Our evaluation results show that the overheads of precise replication are very high, especially for short flows. We find that a compact data structure employing randomization, a small delay on the replication operations, and host-level aggregation yield significant overhead reductions. Typically, the policy of delayed replication reducing 50% and 74.4% of bandwidth costs only excludes 1.9% and 3.4% of the protection on the pass-through traffic, respectively. These schemes and policies are efficient for alleviating peak system load, reducing the replication bandwidth consumption and still protecting the majority of Internet traffic bytes. Yi-Hsuan Feng, Nen-Fu Huang, Yen-Min Wu |
GLOBECOM | 2 |
| 2008 | A Novel Bandwidth Management Scheme for Video Streaming Service on Public-Shared NetworkabstractThis paper proposes a novel concept of using the sharable bandwidth of public-shared network, like FON network, to construct a scalable, robust, and high availability video streaming delivering system. By the proposed "Bandwidth Expansion" concept and approach, the video streaming source spends only a small amount of bandwidth to deliver the video streaming, but the system is capable to serve a large number of clients to receive the video streaming simultaneously. Two optimal algorithms are proposed to arrange the public-shared bandwidth so that all clients are served and the used resources are minimized. A workable prototype of the proposed PSnet system is also implemented to illustrate the feasibility of the whole concept. Nen-Fu Huang, Hong-Yi Chang, Yuan-Wei Lin, Kuo-Shiang Hsu |
ICC | 1 |
| 2008 | Early Identifying Application Traffic with Application CharacteristicsabstractTo more accurately extract the characteristics of application flows, this paper proposes a set of flow attributes to characterize the possible negotiation behaviors of each flow in application layer perspective. The discriminators are available in the early stage, so they are suitable to support real-time based traffic classification and engineering. The ability of flow attributes was tested with several machine learning algorithms. On the other hand, we also compare the accuracy of our method with other related works that addressed real-time traffic classification problem based on the same sample traffic. The result shows that our method outperforms other previous works in protocol level identification with more than 8%~21% accuracy improvement based on fixed-ratio sample flow sets. Furthermore, the proposed method is also suitable to identify encrypted protocols. Nen-Fu Huang, Gin-Yuan Jai, Han-Chieh Chao |
ICC | 1 |
| 2008 | Hierarchical multi-pattern matching algorithm for network content inspection
Tzu-Fang Sheu, Nen-Fu Huang, Hsiao Ping Lee |
Inf. Sci. | 2 |
| 2007 | Performing Packet Content Inspection by Longest Prefix Matching TechnologyabstractThis article presents a novel mechanism to perform packet content inspection by longest prefix matching (LPM) technology. It is done by transforming the automaton-based state table lookup problem into the famous LPM table lookup problem. Two key features, symbol-wise prefix and magic state are observed on the state table to make it possible to utilize IP lookup techniques for string matching. The proposed mechanism is verified to be effective through Lulea algorithm. Also, the practicability is evaluated by employing realistic attack signatures and traffic traces. The experimental results indicate that a state table constructed from the Snort 2.4 patterns can be converted into a prefix table that requires only 2.5% of the memory utilized in the original state table. Compared with the state-of-the-art researches, the proposed scheme has more than 3 times of efficiency, achieving a better balance between required memory size and throughput rate. Nen-Fu Huang, Yen-Ming Chu, Yen-Min Wu, Chia-Wen Ho |
GLOBECOM | 1 |
| 2007 | Flow Digest: A State Replication Scheme for Stateful High Availability ClusterabstractStateful tracking is a popular technique in firewall filtering and state replication is used to provide reliable connectivity. This paper proposes a new approach for improving existing state replication protocols which ensure state consistency amongst the nodes of a stateful HA cluster. Our goal is to develop a new scheme which reduces the update overhead in the face of both low and high connection loads in order to maximize the capacity and scalability of a high availability cluster. A new representation called flow digest is proposed. Also the ways to use flow digest structures to update state changes, recover the connections after a failover, and solve the state inconsistency are presented. The main advantage of the proposed method is to reduce the bandwidth consumption on state replication. The simulation results show that the proposed scheme reduces the number of update messages and, more importantly, eliminates typically at least 86% of bandwidth consumption compared to current solutions. Yi-Hsuan Feng, Nen-Fu Huang, Rong-Tai Liu, Meng-Huan Wu |
ICC | 2 |
| 2007 | A Deterministic Cost-effective String Matching Algorithm for Network Intrusion Detection SystemabstractNetwork intrusion detection systems (NIDS) are more and more important in today's network security for identifying and preventing malicious attacks over the network. This paper proposes a novel and effective string matching algorithm (named ACMS) with advantages of both compact memory and high performance. By employing the characteristics of magic states observed from the deterministic finite state automata, the proposed ACMS significantly reduces the memory requirement without sacrificing high speed no matter it is implemented in software or hardware. The ACMS algorithm also provides high flexibility that it can be tuned to fit specific performance requirement and resource constraints. The experimental results show that the performance of ACMS is over 3.5 times in hardware implementation and 21 times in software implementation better than that of the state-of-the-art studies. Nen-Fu Huang, Yen-Ming Chu, Chen-Ying Hsieh, Chi-Hung Tsai, Yih-Jou Tzang |
ICC | 1 |
| 2007 | A Novel Algorithm and Architecture for High Speed Pattern Matching in Resource-Limited Silicon SolutionabstractNetwork intrusion detection systems (NIDS) are more and more important for identifying and preventing the malicious attacks over the network. This paper proposes a novel cost-effective high speed pattern matching algorithm (named MSH) for NIDS. By applying the characteristics of magic states, a new observation from the deterministic finite state automata (DFA), the proposed MSH constructs a tiny data structure which can be stored into the on-chip memory of modern cost effective FPGA. Prototype and experimental results show the overall efficiency of the proposed MSH is at least 7 times faster than that of the baseline model. The MSH enables the design of cost effective FPGA-based accelerator to furnish over 1 Gbps throughput. It can also be scaled to multi-gigabit and realized on various silicon implementations. Nen-Fu Huang, Yen-Ming Chu, Chi-Hung Tsai, Chen-Ying Hsieh, Yih-Jou Tzang |
ICC | 1 |
| 2006 | Smart Architecture for High-Speed Intrusion Detection and Prevention Systems
Chih-Chiang Wu, Sung-Hua Wen, Nen-Fu Huang |
CANS | 3 |
| 2006 | A Non-Computational Intensive Pre-filter for Pattern Matching in Network Intrusion Detection SystemsabstractPattern or string matching algorithm is one of the most critical tasks in the design of a high-speed network intrusion detection system (NIDS). In this paper, an efficient pre-filtering algorithm, called Super-Symbol Filter (SSF), is proposed to filter the normal traffic before they are forwarded to a pattern matching algorithm. The proposed SSF algorithm uses a tiny data structure, and is light-computational and cache- resident. It can be implemented efficiently in a software-based platform. Experimental results show that with Snort's patterns, the computation time of the SSF with the AC algorithm to process the Defcon9 trace is only one-third to half of that of a pure AC algorithm. Thus, the speed gain of the proposed scheme is around 100-300 %. Nen-Fu Huang, Yen-Ming Chu, Yih-Jou Tzang, Jian-Lin Chen, Hsien-Wei Hung, Ming-Chang Shih, Chia-Nan Kao |
GLOBECOM | 1 |
| 2006 | A Time- and Memory- Efficient String Matching Algorithm for Intrusion Detection SystemsabstractIntrusion Detection Systems (IDSs) are known as useful tools for identifying malicious attempts over the network. The most essential part to an IDS is the searching engine that inspects every packet through the network. To strictly defend the protectorate, an IDS must be able to inspect packets at line rate and also provide guaranteed performance even under heavy attacks. Therefore, in this paper we propose an efficient string matching algorithm (named ACM) with compact memory as well as high worst-case performance. Using a magic number heuristic based on the Chinese remainder theorem, the proposed ACM significantly reduces the memory requirement without bringing complex processes. Furthermore, the latency of off-chip memory references is drastically reduced. The proposed ACM can be easily implemented in hardware and software. As a result, ACM enables cost-effective and efficient IDSs. Tzu-Fang Sheu, Nen-Fu Huang, Hsiao Ping Lee |
GLOBECOM | 2 |
| 2006 | A Scalable Architecture for High Available Security SwitchesabstractThis paper proposes a scalable and high available (HA) architecture for implementing cost effective security switches. In this architecture, each "security switch" consists of a traditional layer-2 switch and a "security switch engine (SSE)" which provides packet content inspection service. These two components are connected via a Gigabit Ethernet link. A mechanism is proposed to interconnect a group of "security switches" to provide the HA feature. A system of four security switches is implemented and the experimental results show that the HA function works successfully even only one SSE is active. The SSE is implemented with full intrusion prevention function on a standard high performance Industrial PC with the performance of 1.2Gbps for UDP packets and 400Mbps for TCP flows. Therefore the proposed security switch architecture can be realized in a very cost effective mechanism to provide Intranet protection. Nen-Fu Huang, Chih-Hao Chen, Yuang-Fang Huang, Yi-Hsuan Feng, Chia-Nan Kao, Hsien-Wei Hung, Ming-Chang Shih |
ICC | 1 |
| 2005 | Fast and Scalable Multi-TCAM Classification Engine for Wide Policy Table LookupabstractWith the explosive growth of Internet traffic, the next generation switches are designed to provide forwarding speed up to 10 Gbps or above. To meet the challenges of delivering wire-speed deep packet inspection for various QoS requirements that making classification becomes the bottleneck of next generation high-speed switches. Ternary content addressable memory (TCAM) provides high-speed parallel comparison operations and is one of the best candidates to implement next-generation hardware-based packet classifiers. Single-TCAM-based solution with ultra-high density has the advantage of simple architecture, but may not be feasible due to the scalability issue; also it may not be fast enough to fulfill the wide-policy-rule classifications, especial for the IPv6-based packets. To provide scalable and deep packet inspection, this paper proposes the pipeline architecture with multiple TCAMs to obtain wire-speed classification for IPv6 and multimedia applications. An algorithm to solve ambiguous cases among the rules is also proposed. Based on the proposed mechanisms, the packet classification engine capable of handling multiple QoS requirements at ultra-high speed is presented. Nen-Fu Huang, Kwei-Bor Chen, Whai-En Chen |
AINA | 1 |
| 2005 | Apply Data Mining to Defense-in-Depth Network Security SystemabstractThis paper proposes a defense in depth network security architecture and applies the data mining technologies to analyze the alerts collected from distributed intrusion detection and prevention systems (IDS/IPS). The proposed defense in depth architecture consists of a global policy server (GPS) to manage the scattered intrusion detection and prevention systems, each of which is managed by a local policy server (LPS). The key component of the GPS is the security information management (SIM) module where data mining technology is employed to analyze the events (alerts) collected from the LPSs. Once a DDoS attack is recognized by the SIM module, the GPS informs the LPS (IDS/IPS) to adjust the thresholds immediately to block the attack from the sources. To evaluate the effectiveness of the proposed defense in depth architecture, a prototyping is implemented, where three different data mining tools are employed. Experiment results demonstrate that for detecting the DDOS attacks, the proposed data mining-based defense in depth architecture performs very well on attack detection rate and false alarm rate. Nen-Fu Huang, Chia-Nan Kao, Hsien-Wei Hung, Gin-Yuan Jai, Chia-Lin Lin |
AINA | 1 |
| 2005 | A Fast URL Lookup Engine for Content-Aware Multi-Gigabit SwitchesabstractCluster-based servers are one of the best solutions to build high-performance, scalable, and reliable Internet Web servers. A number of researches have been done about enabling the dispatcher in cluster-based Web servers to route the users requests based on higher layer information, such as URLs. Hashing functions and tree structure are often used to achieve the goal of URL lookup, but they may cause the problem of collision and result in unacceptable performance. This paper presents a fast scalable URL lookup mechanism that uses content addressable memory (CAM) as the basic hardware components. Our scheme not only supports exact matching of URL lookup, but also provides prefix-matching lookup ability so that it is very practically for URL content-filtering like systems. The proposed scheme takes constant time to lookup a URL and furnishes a rate of 100 million lookups per second. By applying the entry reuse concept, the expensive CAM space can be used in a more efficient way to store more URLs. With this fast URL lookup engine, the performance of content dispatchers or URL content filters can be greatly improved. Nen-Fu Huang, Rong-Tai Liu, Chih-Hao Chen, Ying-Tsuen Chen, Li-Wen Huang |
AINA | 1 |
| 2005 | On the design of a cost effective network security switch architectureabstractThis paper proposes a cost effective architecture for network security switch to deep inspect the traffic among switching ports. A security service engine (SSE) with packet deep inspection ability is also designed to accompany with manageable L2 switches. By properly configuring the VLAN parameters, packets from switch ports of the L2 switch are forwarded to the SSE, via the gigabit Ethernet interface, for deeply inspection. For security reason, abnormal/malicious packets are dropped by the SSE directly while normal packets are forwarded back to the switch to the correct output port. To evaluate the performance and latency of the proposed architecture, a cost effective P4-based SSE is also implemented as an intrusion detection and prevention system (IPS) with layer-7 content inspection function. The obtained measurements show that the proposed architecture is practical with high throughput and low latency. With IPC-based SSE implementation, the traditional L2 switches can now provide content security service in a very cost effective way. Nen-Fu Huang, Chih-Hao Chen, Rong-Tai Liu, Chia-Nan Kao, Chih-Chiang Wu |
GLOBECOM | 1 |
| 2005 | A novel hierarchical matching algorithm for intrusion detection systemsabstractAs more and more network security threats are emerging today, the network-based intrusion detection system (NIDS) is one of the most important systems to protect the network from attacks and intrusions without modifying end-user software. Searching through entire packet headers and payloads, NIDSs can identify and classify the packets that contain malicious patterns. The most essential technology to the NIDS is an efficient multiple-pattern matching algorithm, which performs exact string matching between packets and a large set of patterns. This paper proposes a novel hierarchical multiple-pattern matching algorithm (HMA) for intrusion detection, which is a two-tier and cluster-wise matching algorithm. HMA drastically reduces the amount of external memory access as well as required memory space, enabling an efficient and cost-effective real-time IDS. The simulations show that HMA significantly improves the matching performance in both the average and the worst cases (about 1.7-63 times better than the state-of-the-art algorithms). Tzu-Fang Sheu, Nen-Fu Huang, Hsiao Ping Lee |
GLOBECOM | 2 |
| 2005 | A pattern matching coprocessor for deep and large signature set in network security systemabstractAs the network is growing fast and the viruses are spreading around the network more frequently, network intrusion prevention system (NIPS) is becoming more and more important. The traditional way for intrusion prevention is done by pure software solution with high performance CPU. However, this method is out of date, when gigabit network is booming and the high performance throughput is required. In recent years, the programmable hardware solutions have been proposed but they cannot deal with deep and large amount of pattern matching and are lack of flexibility when signatures are growing up. In this paper, we propose a novel pattern-matching coprocessor that overcomes the difficulties in TCAM implementation when pattern length is deep and signature set is large. Since patterns are all stored in TCAM, it is a scalable and flexible system. Chih-Chiang Wu, Sung-Hua Wen, Nen-Fu Huang, Chia-Nan Kao |
GLOBECOM | 3 |
| 2005 | FTSE: The FNP-Like TCAM Searching EngineabstractAs the Internet grows at a very rapid pace, so does the incidence of attack events and documented unlawful intrusions. The network intrusion detection systems (NIDSes) are designed to identify attacks against networks or a host that are invisible to firewalls, thus providing an additional layer of security. NIDSes detect and filter the malicious packets by inspecting packet payloads to find worm signatures. The payload inspection operation dominates the throughput of an NIDS since every byte of packet payload needs to be examined. At network speeds of 1 Gbps or above, it can be difficult to keep up with intrusion detection in software, and hardware systems or software with hardware assist are normally required. This paper presents FTSE, a ternary content addressable memory (TCAM) based pattern matching engine. In this paper we show how FTSE can be used effectively to perform string matching for thousands of strings at multiple-Gigabit speed. We also describe how FTSE can be implemented feasibly with an FPGA/ASIC, a 2.25 Mb TCAM, and a small SSRAM. Our analysis shows that this approach for string matching is very effective and the throughput of our design can achieve up to 8 Gbps for 2,085 snort rules. Rong-Tai Liu, Chia-Nan Kao, Hung-Shen Wu, Ming-Chang Shih, Nen-Fu Huang |
ISCC | 5 |
| 2004 | WKeeper: A Distributed Web Filtering System for IPv6 Home NetworksabstractWe propose a distributed architecture of Web filtering system focused on its operation and implementation for IPv6 home networks. The realized system, called WKeeper, employs the feature of IPv6 anycast to achieve distributed load balance. WKeeper has been proven to be functioning well in both IPv4 and IPv6 networks even with mobility support. In a home network environment, WKeeper efficiently and precisely maintains the URL-block-list database with enormous amount of entries, as well as its operation is robust and with low cost. Besides, experimental result shows that the delay of query response is bounded significantly even if heavy load. Chao-Ping Yu, Hsien-Wei Hung, Canaan Kao, Nen-Fu Huang, Ko-Shung Chen, Rong-Tai Liu, Yi-Chung Chen |
AINA (2) | 4 |
| 2004 | A fast pattern matching algorithm for network processor-based intrusion detection systemabstractNetwork intrusion detection systems (NIDS) monitor packets on the network and attempts to discover if a hacker is attempting to break into a system. The matching of packet strings against collected signatures dominates signature-based NIDS performance. Network processors are one of the fastest growing segments of the semiconductor market, because they are designed to provide scalable and flexible solutions that can accommodate change quickly and economically. This work presents a fast string matching algorithm (called FNP) over the network processor platform that conducts matching sets of patterns in parallel. FNP needs less number of memory accesses against conventional pattern-matching algorithms. Another contribution of this work is to highlight that, besides total number of searching patterns, shortest pattern length is also a major influence on NIDS multi-pattern matching algorithm performance. Rong-Tai Liu, Nen-Fu Huang, Chia-Nan Kao, Chih-Hao Chen |
IPCCC | 2 |
| 2004 | Provisioning multicast QoS for WDM-based optical wireless networks
Ko-Shung Chen, Chao-Ping Yu, Chiao Yu, Nen-Fu Huang |
Comput. Commun. | 4 |
| 2004 | Multicast traffic scheduling in single-hop WDM networks with arbitrary tuning latenciesabstractTo accommodate the demands of quality of service (QoS) and multicast applications, a multicast QoS traffic-scheduling algorithm with tuning latency consideration in wavelength-division multiplexing star-coupled networks is provided in this paper. To furnish different levels of QoS, two classes of traffic are considered: constant bit rate and available bit rate (ABR). An effective bandwidth-normalization scheme for ABR traffic is also derived. We define the slot scanning problem in the connection-setup process as the maximum assignable slots (MAS) problem. We prove that the optimal solution of the MAS problem can be obtained in polynomial time. Owing to its high-order time complexity, we also propose two heuristics for the MAS problem. The performance of these strategies are evaluated and compared by simulations under different system parameters, such as number of wavelengths, traffic load, and tuning latency. Ching-Fang Hsu 0002, Te-Lung Liu, Nen-Fu Huang |
IEEE Trans. Commun. | 3 |
| 2004 | A fast string-matching algorithm for network processor-based intrusion detection systemabstractNetwork intrusion detection systems (NIDSs) are one of the latest developments in security. The matching of packet strings against collected signatures dominates signature-based NIDS performance. Network processors are also one of the fastest growing segments of the semiconductor market, because they are designed to provide scalable and flexible solutions that can accommodate change quickly and economically. This work presents a fast string-matching algorithm (called FNP) over the network processor platform that conducts matching sets of patterns in parallel. This design also supports numerous practical features such as case-sensitive string matching, signature prioritization, and multiple-content signatures. This efficient multiple-pattern matching algorithm utilizes the hardware facilities provided by typical network processors instead of employing the external lookup co-processors. To verify the efficiency and practicability of the proposed algorithm, it was implemented on the Vitesse IQ2000 network processor platform. The searching patterns used in the present experiments are derived from the well-known Snort ruleset cited by most open-source and commercial NIDSs. This work shows that combining our string-matching methodology, hashing engine supported by most network processors, and characteristics of current Snort signatures frequently improves performance and reduces number of memory accesses compared to conventional string-matching algorithms. Another contribution of this work is to highlight that, besides total number of searching patterns, shortest pattern length is also a major influence on NIDS multipattern matching algorithm performance. Rong-Tai Liu, Nen-Fu Huang, Chih-Hao Chen, Chia-Nan Kao |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2003 | RSVP Extensions for Real-Time Services in Hierarchical Mobile IPv6
Nen-Fu Huang, Whai-En Chen |
Mob. Networks Appl. | 1 |
| 2002 | Migrating constrained optical tree in wireless WDM systemsabstractAs WDM-based optical networks are becoming the right choice for the next-generation Internet networks to transport high-speed IP traffic, the leading role of wireless ATM (WATM) networks will be undoubtedly replaced with wireless WDM (WWDM) networks for providing high quality of services to mobile users. Meanwhile, multicasting has played an increasingly important role in many conventional and emerging applications, such as teleconferencing and distributed games. In this paper, a constrained optical tree migration scheme (COTMS) is proposed to support multicast services in WWDM networks. COTMS is an enhancement of our previous work, called CTMS, for adapting to the characteristic of WDM-based backbone networks. CTMS can properly deal with the constrained tree migration problem for generic wireless networks, and COTMS inherits the efficiencies of CTMS entirely. Simulation results show that COTMS can markedly reduce the resources used per multicast tree, thus achieving both low handoff-dropping/join-blocking rate and high resource utilization. More importantly, we demonstrate how COTMS incorporating crossover optical switch discovery can be used to support real-time traffic for heterogeneous (i.e., unicast and multicast) connections in a uniform and unified manner. The proposed scheme is also suitable for routing over fully mobile (ad hoc) networks in which multiple frequencies are used for data communications. Ko-Shung Chen, Chao-Ping Yu, Nen-Fu Huang |
GLOBECOM | 3 |
| 2002 | On the deflection routing in QoS supported optical burst-switched networksabstractGenerally speaking, buffer requirement is not vital for JET-based optical burst switching (OBS). However, if deflection routing is enabled, optical buffers are necessary to solve the insufficient offset time problem. Another solution, which can alleviate buffering, is to lengthen offset time in the beginning. As previous work indicated, a burst with extra offset time has higher priority than that without extra offset time and quality of service (QoS) can be accomplished in this way. Therefore, we investigate the performance of deflection routing in prioritized JET-based optical burst-switched networks. A queuing model is proposed to approximate loss probability. We also evaluate the impact of deflection routing in Arpanet-2 topology by simulation. Ching-Fang Hsu 0002, Te-Lung Liu, Nen-Fu Huang |
ICC | 3 |
| 2002 | An adaptive routing strategy for wavelength-routed networks with wavelength conversion capabilityabstractWe investigate adaptive routing in wavelength-routed networks. Exploiting the concept of load balancing, we propose an adaptive routing strategy named weighted-shortest-cost-path (WSCP). The salient feature of WSCP is that it seeks the path that minimizes the resource cost while simultaneously maintaining the traffic load as balanced as possible. We compare the blocking probability and average hops of WSCP with those of the traditional shortest-cost-path (SCP) strategy, fixed routing, and alternate routing. The numerical results show that WSCP can enhance blocking performance and lengthen hop distances just a little. The improvement is more significant in denser networks or with more wavelengths. We also develop an analytical model to estimate blocking performance of WSCP. Ching-Fang Hsu 0002, Te-Lung Liu, Nen-Fu Huang |
ICC | 3 |
| 2002 | Multicast QoS traffic scheduling with arbitrary tuning latencies in single-hop WDM networksabstractTo accommodate the demands of QoS and multicast applications, a multicast QoS traffic scheduling algorithm with tuning latency consideration in a WDM star-coupled network is provided in this paper. We define the slot scanning problem in the connection setup process as the maximum assignable slots (MAS) problem. We prove that the optimal solution of the MAS problem can be obtained in polynomial time. Owing to its high-order time-complexity, we also propose two heuristics for the MAS problem. The performance of these strategies is evaluated and compared by simulations under different system parameters, such as traffic load and tuning latency. Te-Lung Liu, Ching-Fang Hsu 0002, Nen-Fu Huang |
ICC | 3 |
| 2002 | Performance Analysis of Deflection Routing in Optical Burst-Switched NetworksabstractThis paper concerns itself with the performance of deflection routing in optical burst-switched networks based on just-enough-time (JET) signaling. Generally speaking, buffer requirement is not vital for JET-based optical burst switching (OBS). However, if deflection routing is enabled, optical buffers are necessary to solve the insufficient offset time problem. A variant of priority queuing model is proposed to approximate burst loss probability and the results show that the model provides an accurate estimation. We also evaluate the performance of deflection routing in Arpanet-2 topology. Simulation results indicate that deflection routing evidently brings significant blocking performance gain, especially with fewer wavelengths and under lighter load. In addition, we notice that excessive deflection will cause longer end-to-end delay and reduce the blocking performance. Therefore, it is necessary to control the maximum allowed deflection occurrences of a burst. Ching-Fang Hsu 0002, Te-Lung Liu, Nen-Fu Huang |
INFOCOM | 3 |
| 2001 | Design of multi-field IPv6 packet classifiers using ternary CAMsabstractTypically, high-end routers/switches classify a packet by looking for multiple fields of the IP/TCP headers and recognize which flow the packet belongs to. Several packet classification algorithms to accelerate packet processing and reduce the memory requirement have been proposed. But it is not easy to implement these algorithms in hardware to lookup these multiple fields in the same time. This paper intends to design a novel packet classification engine capable of simultaneously processing multi-field searching, especially for the IPv6 packets with relative longer addresses (128 bits). To classify the IPv6 packets in wire-speed, the CLM (CAM-Like Memory)-based hardware architecture is considered and five fields (source IPv6 address, destination IPv6 address, source port, destination port, and protocol) are designed as the searching key. Evaluation results indicate that compared with the typical market leading delivering search engines, the proposed hardware architecture provides a 30% speed-up performance. A compact method is also provided to compress the bit-width required to represent the multi-field of an IPv6 packet. This saves the memory space required for the IPv6 rule table for about 20%. Nen-Fu Huang, Whai-En Chen, Jiau-Yu Luo, Jun-Min Chen |
GLOBECOM | 1 |
| 2001 | Providing multicast short message services over self-routing mobile cellular backbone networkabstractThe short message service (SMS), a bidirectional service for short alphanumeric (up to 160 bytes) messages, is a unique feature of GSM, not found in older analog systems. We propose a multicast short message service architecture over a backbone network. We demonstrate some approaches to maintain the location information of the short message service center consistent to the home location register and illustrate our scheme for mobile-terminated short message transfer. Finally, we simulate and evaluate this architecture. Our simulation indicates that the proposed strong consistency approach has optimal efficiency by adjusting parameters. Also, the proposed architecture efficiently provides a self-routing capability and multicast functionality in the cellular backbone network. This study also provides a further insight on the issues of a multicast wireless cellular backbone network and demonstrates a referable methodology to propose and analyze a multicast cellular backbone network, which can promote the technology of personal communication networks. Jen-Yi Pan, Wei-Tsong Lee, Nen-Fu Huang |
GLOBECOM | 3 |
| 2001 | A novel routing algorithm for WDM-based micro-cellular wireless system
Jen-Yi Pan, Wei-Tsong Lee, Nen-Fu Huang |
Comput. Commun. | 3 |
| 2001 | CTMS: a novel constrained tree migration scheme for multicast services in generic wireless systemsabstractThis study considers the multicasting problem over mobile wireless systems in the context of generic wireless systems. Specifically, a novel constrained tree migration scheme (CTMS) is created to support multicast services in mobile wireless networks. The salient features of the novel CTMS include: (1) automatically recognizing the inefficiency of the multicast trees, then migrating them to better ones, while maintaining the QoS guarantees specified by mobile users; (2) conserving network resources by maintaining a low-cost multicast tree, thus accommodating more users; (3) operating efficiently in a truly distributed manner through event driven and diffusing computations, thus increasing the degree of scalability; (4) synchronizing data transmission flow for transparency during the tree migration, and thus providing seamless handoff control. Finally, the novel CTMS also handles the concurrent migration problem effectively within the wireless system, thus eliminating the oscillation paradox. Extensive simulation results show that CTMS can significantly reduce the resources used per multicast tree, thus achieving both low handoff-dropping/join-blocking rate and high resource utilization. Ko-Shung Chen, Nen-Fu Huang, Bo Li 0001 |
IEEE J. Sel. Areas Commun. | 2 |
| 2001 | Intelligent Handoff for Mobile Wireless Internet
Jon Chiung-Shien Wu, Chieh-Wen Cheng, Nen-Fu Huang, Gin-Kou Ma |
Mob. Networks Appl. | 3 |
| 2000 | QoS supported dynamic traffic scheduling in WDM/TDM networks with arbitrary tuning latenciesabstractThis paper proposes a dynamic traffic scheduling algorithm in single-hop WDM/TDM networks with arbitrary tuning latencies to support guaranteed QoS. To furnish different levels of QoS, two classes of traffic are considered: constant bit rate (CBR) and available bit rate (ABR). An effective bandwidth normalization scheme for ABR traffic is also derived. By applying distinct normalization schemes to CBR and ABR traffic individually, the bandwidth can be allocated more accurately and meanwhile the QoS is also guaranteed. Two slot allocation policies are also suggested to allocate the time slots to connections. The performance of proposed algorithm is evaluated and compared by simulations under different system parameters, such as wavelength number, traffic load, and tuning latency. Nen-Fu Huang, Te-Lung Liu, Ching-Fang Hsu 0002 |
GLOBECOM | 1 |
| 2000 | The shortest path computation in MOSPF protocol using an annealed Hopfield neural network with a new cooling schedule
Jzau-Sheng Lin, Mingshou Liu, Nen-Fu Huang |
Inf. Sci. | 3 |
| 2000 | A novel all-optical transport network with time-shared wavelength channelsabstractHigh-speed and high-capacity transport networks are necessary for providing future broadband services and multimedia applications. Optical networks, such as wavelength-routed networks and optical switching networks, are the most popular solutions. However, the limited electronic switching capability constrains the scalability of the multihop wavelength routed networks, while the difficulty and complexity of implementing efficient optical buffers and optical contention resolution schemes constrains the development of optical switching networks. This paper proposes a new architecture for the optical transport networks based on time-wavelength-space routers (TWSRs). The TWSR is equipped without optical buffers and optical contention resolution devices. A connection is established by constructing a time-slot based lightpath (ts-lightpath) between source TWSR and destination TWSR. The paper also proposes a heuristic algorithm for the problem of establishing the set of efficient ts-lightpaths for a given set of connection requests. The effectiveness of the proposed network architecture with the heuristic algorithm is demonstrated by simulation. Nen-Fu Huang, Guan-Hsiung Liaw, Chuan-Pwu Wang |
IEEE J. Sel. Areas Commun. | 1 |
| 1999 | A Fast IP Routing Lookup Scheme for Gigabit Switching RoutersabstractOne of the key design issues for the new generation IP routers is the route lookup mechanism. For each incoming IP packet, the IP routing requires to perform a longest prefix matching on the address lookup in order to determine the packet's next hop. This paper presents a fast route lookup mechanism that only needs tiny SRAM and can be implemented in a pipelined skill in hardware. Based on the proposed scheme, the forwarding table is tiny enough to fit in SRAM with very low cost. For example, a large routing table with 40,000 routing entries can be compacted to a forwarding table of 450-470 Kbytes. In the worst case, the number of memory accesses for a lookup is three. When implemented in a pipeline skill in hardware, the proposed mechanism can achieve one routing lookup every memory access. With current 10 ns SRAM, this mechanism furnishes approximately 100 million routing lookups per second. This is much faster than any current commercially available routing lookup schemes. Nen-Fu Huang, Shi-Ming Zhao, Jen-Yi Pan, Chi-An Su |
INFOCOM | 1 |
| 1999 | A novel IP-routing lookup scheme and hardware architecture for multigigabit switching routersabstractOne of the pertinent design issues for new generation IP routers is the route-lookup mechanism. For each incoming IP packet, the IP routing is required to perform a longest-prefix matching on the route lookup in order to determine the packet's next hop. This study presents a fast unicast route-lookup mechanism that only needs tiny SRAM and can be implemented using a hardware pipeline. The forwarding table, based on the proposed scheme, is small enough to fit into a faster SRAM with low cost. For example, a large routing table with 40000 routing entries can be compacted into a forwarding table of 450-470 kbytes costing less than US$30. Most route lookups need only one memory access; no lookup needs more than three memory accesses. When implemented using a hardware pipeline, the proposed mechanism can achieve one routing lookup every memory access. With current 10-ns SRAMs, this mechanism furnishes approximately 100/spl times/10/sup 6/ routing lookups/s, which is much faster than any current commercially available routing-lookup scheme. Nen-Fu Huang, Shi-Ming Zhao |
IEEE J. Sel. Areas Commun. | 1 |
| 1998 | PDMRP: a programmable distributed multicast routing protocolabstractOne of the most critical task for group communications lies in the establishment of multicast trees on the network. Two famous multicast trees are the shortest path-based trees and the Steiner-based trees. The former is suitable for those applications (such as video conferences) which wish to have a low propagation delay between the source (chairman site) to each of the receivers (member sites). The latter is well-suited for those (such as VoD services) which tend to consume as small as possible network resources (bandwidth). So far the routers have to implement separate routing protocols in order to support the construction of different kinds of multicast trees. This paper proposes a programmable distributed multicast routing protocol (PDMRP) for the routers so that different multicast trees can be established easily by only tuning a cost parameter. Nen-Fu Huang, Chien-Yu Yeh, Chung-Ching Chiou |
ICC | 1 |
| 1998 | Architectures and Handoff Schemes for CATV-Based Personal Communications NetworkabstractThe initial cost to provide personal communications services (PCS) based on the conventional networks is relative high. As the radio cells move toward smaller size, the traditional procedures for call setup and control are not suitable well due to the high handoff frequency. The cable TV (CATV) network is one of the most attractive backbones for PCS due to its prevalent and broadcast nature. This significantly reduces the implementation costs and the handoff overheads. This paper proposes two architectures for the CATV-based PCS system. In the first architecture, each base station is equipped with multiple fixed receivers to provide fast and seamless handoffs for mobile terminals. Nevertheless, it suffers from the expensive hardware cost. In the second architecture, each base station is only equipped with one tunable receiver. This simple and economic architecture suffers from the possibility of offset conflict when mobile terminals handoff between the cells. Three channel allocation algorithms are proposed to resolve the offset conflict problem. Simulation results indicate the one with the concept of clustering performs much better than the other two schemes in terms of offset conflict probability. Nen-Fu Huang, Chi-An Su, Han-Chieh Chao |
INFOCOM | 1 |
| 1998 | A study of isochronous channel reuse in DQDB metropolitan area networksabstractThis paper investigates the isochronous channel reuse problem (ICRP) on the IEEE 802.6 distributed-queue dual-bus (DQDB) metropolitan area network (MAN). Given a set of established isochronous connections and a set of isochronous connections requests, using a minimal number of isochronous bandwidth to service all of the connections is attempted. On the other hand, given a limited isochronous bandwidth, establishing a maximal number of isochronous connections is of primary concern. Our previous study demonstrates that the ICRP is NP-complete by showing that the simplified ICRP (SICRP), in which all of the established isochronous connections and the isochronous requests are of the same bandwidth, is NP-complete. We recommend using a tight lower bound on the number of required isochronous channels for the SICRP. An efficient isochronous channel scheduling algorithm (ICSA), capable of providing a solution close to the lower bound, is also proposed. Simulation results indicate that for a limited isochronous bandwidth, the number of isochronous connections successfully established by the ICSA is significantly more than that of the isochronous channels allocation scheme in the DQDB standard. Nen-Fu Huang, Huey-Ing Liu |
IEEE/ACM Trans. Netw. | 1 |
| 1997 | Virtual LAN Internetworking over ATM Networks for Mobile StationsabstractOne of the most attractive features of the virtual LAN (VLAN) is the capability to group users into broadcast domains, which are independent of their locations on the physical network. This paper deals with the VLAN services using ATM LAN emulation technology which operates on a client/server model. The focuses are on the issues of supporting transparent VLAN services and internetworking among VLANs for mobile stations. A mobile VLAN (MVLAN) architecture is proposed, perhaps for the first time, to efficiently maintain multiple VLAN broadcast domains over a single ATM network even when the VLANs contain mobile stations. The proposed solution (1) ensures that layer 2 frames between a mobile station and any station, either static or mobile, that belongs to the original registered VLAN can be exchanged transparently, (2) provides transparent communications between VLANs using the layer 2 bridging approach, and (3) handles excessive server-to-server traffic efficiently, including the broadcast/multicast frames. The proposed MVLAN architecture moves one step closer towards facilitating the mobility management in an ATM network while conforming to the emerging LAN emulation standard. Nen-Fu Huang, Yao-Tzung Wang, Bo Li 0001, Te-Lung Liu |
INFOCOM | 1 |
| 1997 | A waste-free congestion control scheme for dual bus high-speed networks
Nen-Fu Huang, Shiann-Tsong Sheu |
Comput. Networks ISDN Syst. | 1 |
| 1996 | The Design and Implementation of a Multicast Real-Time Multimedia ProtocolabstractMany multimedia applications require guaranteed quality of service (QoS) in communication networks. Typically, the QoS includes bandwidth, delay, and delay jitter. This paper presents a real-time protocol to support multimedia communications in which the connections are established with efficient resource reservation and proper admission control. During data transmission, the rate, jitter control, and packet scheduling techniques are employed to fulfil the performance contract. The protocol also incorporates a multicast function to provide group communications. This protocol is implemented on a high-speed network which consists of interconnected ATM switches, FDDI networks, routers, and hosts. Experiments have been carried out to evaluate the effectiveness of the QoS guaranteed protocol. Measured results indicate that the proposed protocol performs well to guarantee the QoS in terms of the bandwidth, delay, and delay jitter. Nen-Fu Huang, Chi-An Su, Chieh-Wen Cheng, Chuan-Pwu Wang, Jer-Han Fang, Yi-Jang Wu |
LCN | 1 |
| 1995 | DTCAP - A Distributed Tunable-Channel Access Protocol for Multi-Channel Photonic Dual Bus Networks
Nen-Fu Huang, Shiann-Tsong Sheu |
INFOCOM | 1 |
| 1995 | Hot-Spot Spanning Tree Algorithm for a Bridged LAN/MAN
Nen-Fu Huang, Gin-Kou Ma, Yi-Jang Wu |
Comput. Commun. | 1 |
| 1994 | A Study of Isochronous Channel Reuse in DQDB Metropolitan Area NetworksabstractThe isochronous channel reuse problem (ICRP) on DQDB metropolitan area networks is investigated. Given a set of established isochronous connections and a set of isochronous requests, the goal is to use a minimal number of isochronous channels to service these requests. On the other hand, given a limited isochronous bandwidth, the goal is to establish a maximal number of isochronous connections. In the paper, the authors show that the ICRP is NP-complete. For the simplified ICRP (SICRP), in which all the established isochronous connections as well as the isochronous requests are of the same bandwidth, the authors suggest a tight lower bound and propose an efficient isochronous channel reuse algorithm (ICRA). Simulation results show that for the SICRP, the solutions obtained by the ICRA are very close to the lower bound which implies the proposed ICRA is very attractive. For a limited isochronous bandwidth, the number of successful established isochronous connections obtained by the ICRA is much more than that of the original DQDB isochronous channels allocation scheme.> Nen-Fu Huang, Huey-Ing Liu, Gin-Kuo Ma |
INFOCOM | 1 |
| 1994 | A Time-Wavelength Scheduling Algorithm for Interconnected WDM Star NetworksabstractAlthough WDM-based single-hop star networks are attractive owing to their all-optical communication features, the throughput of such lightwave networks is limited due to the small number of available wavelengths. In this paper, a wavelength-reusable local lightwave network which consists of interconnected WDM star networks is proposed. Based on this architecture, the lower bound for the problems of minimizing the switching duration is derived. A transmission scheduling algorithm for this architecture to efficiently reuse the wavelengths is also proposed. The analytical result shows that the proposed scheduling algorithm always produces solutions no greater than twice of the lower bounds. Simulation results show that given the same number of users and available wavelengths, the solutions (in terms of the average switching duration and the average number of switching matrices) obtained by the proposed scheduling algorithm on the interconnected WDM networks are better than the optimal solution on a single-star WDM network. In most cases, the performance improvement achieves 20% to 45%.> Nen-Fu Huang, Jon Chiung-Shien Wu, Gin-Kou Ma |
INFOCOM | 1 |
| 1994 | Interconnection of Large-Scale LANs Via a Two-Stage Switching HUB for Multimedia ApplicationsabstractAs broadband multimedia applications to the desk top are becoming popular today, the high-speed bandwidth demand from a single user will occupy large shares of the LAN's channel capacity. Therefore, the evolution of LAN technologies has shifted from shared to dedicated media. More and more LANs are being installed and their interconnection will require parallel switching techniques such as a high-speed switching hub. The ATM small cell-size switching approach is intended to accommodate the mixed media such as voice, data and video. To fulfil the switching cost, bandwidth and latency criteria, a two-stage switching hub for LAN interconnection is designed and presented in this paper. The packet switching technique is used in the first stage switching to efficiently interconnect the local LANs. For the second stage design, the ATM cell switching is adopted to accommodate multimedia traffic and internetworking among LANs and WANs. The switching architecture including both the packet and cell switching units is thoroughly described. The message flow and routing mechanism are presented in the paper. This architecture has been proved to have the advantages of very low latency, flexible scalability and easy routing management with two-way learning.> Tzung-Pao Lin, Yao-Tzung Wang, Nen-Fu Huang |
LCN | 3 |
| 1994 | Some Routing Problems on Broadband ISDN
Nen-Fu Huang, Jon Chiung-Shien Wu, Yi-Jang Wu |
Comput. Networks ISDN Syst. | 1 |
| 1994 | Reservation scheme for CRMA high-speed networks
Nen-Fu Huang, Chung-Ching Chiou |
Comput. Commun. | 1 |
| 1994 | A Sweepline Algorithm to Solve the Two-Center Problem
Nen-Fu Huang, Ching-Ho Huang, Yue-Li Wang |
Inf. Process. Lett. | 1 |
| 1994 | A distributed paths migration scheme for IEEE 802.6 based personal communication networksabstractWireless personal communications will be provided via the usage of microcells in urban areas. The current centralized architecture may be unsuitable with the increased processing load and handoff rate associated with microcells. Some distributed architectures based upon interconnected IEEE 802.6 MAN'S for wireless personal communications have been proposed recently. The IEEE 802.6 MAN is attractive since it also provides isochronous services which are quite suitable for voice communications. In such a network, a communication path between two mobile terminals may be inefficient due to the lack of better paths when the path is established or become inefficient due to the mobility of terminals, e.g., the path elongates and consumes too much isochronous channels. In this paper, a distributed paths migration scheme is proposed for the IEEE 802.6 based personal communication networks. This distributed scheme automatically recognizes inefficient paths and migrates them to better ones, if any. During the migration, the property of isochronous services is also preserved. The performance of this scheme is evaluated by simulations. Simulation results show that the proposed paths migration scheme dramatically reduces the number of isochronous channels consumed per path. As a result, the call blocking rate is reduced and the number of successful established paths is increased significantly.> Nen-Fu Huang, Ko-Shung Chen |
IEEE J. Sel. Areas Commun. | 1 |
| 1993 | A Slot Interleaved Multiple Access Scheme for DQDB Metropolitan Area NetworksabstractA slot interleaved multiple access (SIMA) scheme for distributed-queue dual-bus (DQDB) metropolitan area networks is proposed. In this scheme, all the active nodes will access the slots in an interleaved fashion. This scheme is very efficient for solving the bandwidth domination problem and the priority domination problem, which cannot be solved readily by the DQDB medium access control (MAC) protocol with a bandwidth balancing mechanism. An enhanced SIMA (ESIMA) scheme is proposed to solve the bandwidth allocation problem, which cannot be solved by the DQDB MAC protocol. Simulation results show that SIMA and ESIMA perform much better than the DQDB MAC on throughput as well as the access delay.> Nen-Fu Huang, Shiann-Tsong Sheu |
INFOCOM | 1 |
| 1993 | Solving bandwidth and priority domination problems of DQDB MANs
Nen-Fu Huang, Shiann-Tsong Sheu |
Comput. Commun. | 1 |
| 1993 | On the Complexity of two Circle Connecting Problems
Nen-Fu Huang |
Discret. Appl. Math. | 1 |
| 1992 | On the Complexity of Two Circle Strongly Connecting ProblemsabstractGiven n demand points in the plane, the circle strongly connecting problem (CSCP) is to locate n circles in the plane, each with its center in a different demand point, and determine the radius of each circle such that the corresponding digraph G=(V, E), in which a vertex nu /sub 1/ in V stands for the point p/sub i/, and a directed edge ( nu /sub i/, nu /sub j/) in E, if and only if p/sub j/ located within the circle of p/sub i/, is strongly connected, and the sum of the radii of these n circles is minimal. The constrained circle strongly connecting problem is similar to the CSCP except that the points are given in the plane with a set of obstacles and a directed edge ( nu /sub i/, nu /sub j/) in E, if and only if p/sub j/ is located within the circle of p/sub i/ and no obstacles exist between them. It is proven that both these geometric problems are NP-hard. An O(n log n) approximation algorithm that can produce a solution no greater than twice an optimal one is also proposed.> Nen-Fu Huang |
IEEE Trans. Computers | 1 |
| 1991 | Complexity of the Repeaters Allocating Problem
Nen-Fu Huang, Ching-Ho Huang |
Inf. Process. Lett. | 1 |
| 1990 | An Optimal Algorithm for Constructing Oriented Voronoi Diagrams and Geographic Neighborhood Graphs
Maw-Shang Chang, Nen-Fu Huang, Chuan Yi Tang |
Inf. Process. Lett. | 2 |
| 1989 | The strongly connecting problem on multihop packet radio networksabstractThe problem of strongly connecting a multihop packet radio network by using a minimal total amount of transmission power is investigated. This problem is shown to be NP-complete. An approximation algorithm with the same computational complexity as that of finding a minimum spanning tree is given. It is also shown that the approximation algorithm can find a solution no greater than twice that of the optimal solution. Experimental results show that the approximation solution may be close to the optimal solution.> Wen-Tsuen Chen, Nen-Fu Huang |
IEEE Trans. Commun. | 2 |