EDBT 2026 Demo / reviewers in the wild / expert
Artur Hecker
dblp:36/640
· DBLP profile ↗
43ranked-venue papers
2as first author
18since 2021 · last 2025
0000-0003-3604-2686ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 29 · 1 first-author · 15 since 2021Security and privacy · 2Human-computer interaction and ubiquitous computing · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | LLaVA Steering: Visual Instruction Tuning with 500x Fewer Parameters through Modality Linear Representation-SteeringabstractJinhe Bi, Yujun Wang, Haokun Chen, Xun Xiao, Artur Hecker, Volker Tresp, Yunpu Ma. Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2025. Jinhe Bi, Xun Xiao, Artur Hecker, Volker Tresp, Yunpu Ma |
ACL (1) | 5 |
| 2025 | A Scalable and Secure Transaction Attachment Algorithm for DAG-Based BlockchainabstractBlockchain, as an innovative distributed ledger technology, has attracted considerable attention in recent years from both academic circles and industry sectors. Its applications span a diverse range of domains, including finance and the Internet of Things (IoT). However, the scalability of blockchain technology is still a critical limitation with the increasing volume of data. To address this limitation, a directed acyclic graph (DAG) data structure has been proposed to improve scalability by supporting asynchronous process of transactions. IOTA is a well-known DAG-based blockchain that theoretically offers faster confirmation speeds with an increasing number of transactions. However, in practice, IOTA still faces the challenge of balancing scalability and security. In this article, we propose a scalable and secure transaction attachment algorithm for the DAG-based blockchain IOTA. We determine two critical parameters through our experimental analysis: one for calculating the selection probability and the other for setting the threshold for abnormal transactions. First, we calculate the selection probability of unconfirmed transactions. Then, we select abnormal transactions whose selection probability falls below the predefined threshold to maintain the security. Finally, new transactions attach randomly to former transactions with a time computational complexity$O(n)$, ensuring the scalability. Through experiments comparing the proposed algorithm to the current transaction attaching algorithm, we demonstrate the scalability and security of our proposed algorithm. Fengyang Guo, Artur Hecker, Schahram Dustdar |
IEEE Internet Things J. | 2 |
| 2024 | Multi-Agent Deep Reinforcement Learning for Coordinated Multipoint in Mobile NetworksabstractMacrodiversity is a key technique to increase the capacity of mobile networks. It can be realized using coordinated multipoint (CoMP), simultaneously connecting users to multiple overlapping cells. Selecting which users to serve by how many and which cells is NP-hard but needs to happen continuously in real time as users move and channel state changes. Existing approaches often require strict assumptions about or perfect knowledge of the underlying radio system, its resource allocation scheme, or user movements, none of which is readily available in practice. Instead, we propose three novel self-learning and self-adapting approaches using model-free deep reinforcement learning (DRL): DeepCoMP, DD-CoMP, and D3-CoMP. DeepCoMP leverages central control and observations of all users to select cells almost optimally. DD-CoMP and D3-CoMP use multi-agent DRL, which allows distributed, robust, and highly scalable coordination. All three approaches learn from experience and self-adapt to varying scenarios, reaching 2x higher Quality of Experience than other approaches. They have very few built-in assumptions and do not need prior system knowledge, making them more robust to change and better applicable in practice than existing approaches. Stefan Schneider 0008, Holger Karl, Ramin Khalili, Artur Hecker |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2023 | An Efficient Graph-Based IOTA Tangle Generation AlgorithmabstractIOTA is a recent distributed ledger technology that relies on Directed Acyclic Graph (DAG) for its ledger organization. To improve IOTA mechanisms, the state of the art methodology employs graph analysis and, for that, heavily relies on synthetic graph generation. Herein, the most popular generation method simulates IOTA protocol execution. Although this method produces realistic IOTA ledgers, it requires too much memory and time due to repeated random walks on the DAG. In this paper, we propose an alternative Graph Generation and Refinement (GraGR) algorithm designed to generate realistic IOTA ledgers while strongly relaxing memory and timing constraints. The evaluations show that, compared to the state of the art, GraGR can generate a ledger with the same properties with only half of memory and up to 10 times faster. Fengyang Guo, Xun Xiao, Artur Hecker, Schahram Dustdar |
ICC | 3 |
| 2023 | Towards Efficient Provisioning of Dynamic Edge Services in Mobile NetworksabstractEdge computing brings added benefits for different elements in the overall system (e.g., users, operators and service providers). However, currently there are no proper interfaces and mechanisms to instantiate third-party services within the operators' infrastructure (e.g., as a MEC application), thus hindering edge computing to reach its full potential. To fill this gap, this paper presents architectural enhancements, interfaces and mechanisms to enable dynamic and efficient third-party service deployment within the operators' domain. A simulation-based analysis is presented to showcase the relevance of the proposed solution. Results highlighted the benefits of optimal migration of third-party services into a distributed setting, compared to the unveiled drawbacks of a centralized approach. In addition, the key components of the solution are implemented and experimentally validated through a proof-of-concept prototype showcasing the performance impact of the proposed approach as well as the suitability of its implementation. José Quevedo, Daniel Corujo, David Santos, Hao Ran Chi, Ayman Radwan, Rui L. Aguiar, Osama Abboud, Artur Hecker |
ICC | 9 |
| 2023 | A Theoretical Model Characterizing Tangle Evolution in IOTA Blockchain NetworkabstractIOTA blockchain system is lightweight without heavy proof-of-work mining phases, which is considered a promising service platform of Internet of Things applications. IOTA organizes ledger data in a directed acyclic graph (DAG), called Tangle, rather a chain structure as in traditional blockchains. With arriving messages, IOTA tangle grows in a special way, as multiple messages can be attached to the tangle at different locations in parallel. Hence, the network dynamics of an operational IOTA system would justify a thorough study, which is currently unexplored in the literature. In this article, we present the first theoretical modeling for the evolving IOTA tangle based on stochastic analysis. After analyzing snapshots of the real-world IOTA ledger data, our key finding suggests that IOTA tangle follows a rather atypical double Pareto Lognormal (dPLN) degree distribution. In contrast, typical power-law and exponential distributions do not accurately reflect the fact. For model parameter estimation, we further realize that using generic optimization solvers cannot yield quality fitting results. Thus, we design an alternative algorithm based on expectation-maximization (EM) framework. We evaluate the proposed model and fitting algorithm with official data provided by the IOTA Foundation. Quantitative comparisons confirm the fitting quality of our proposed model and algorithm. The whole analysis reveals a deeper understanding of the internal mechanism of the IOTA network. Fengyang Guo, Xun Xiao, Artur Hecker, Schahram Dustdar |
IEEE Internet Things J. | 3 |
| 2023 | Accelerating Industrial IoT Acoustic Data Separation With In-Network ComputingabstractAcoustic data from the Industrial Internet of Things (IIoT) are widely used in anomaly detection because audio information reflects richer internal statuses of monitored working machines than the video does. Since multiple acoustic data sources interfere with each other by nature, source data estimation is a prerequisite of subsequent anomaly detection. Existing schemes often use a centralized manner to separate full data on a remote node in clouds. However, such a centralized manner may delay reactions to anomalies due to data transmission delay and the complexity of solving data separation problems. This article shows that the data separation phase can be substantially accelerated with an in-network computing approach. The key idea is to offload data processing jobs to intermediate network nodes along the forwarding path. We first propose a distributed algorithm so that the data separation jobs can be done in a progressive manner; likewise, we modify the forwarding layer in order to eliminate hop-by-hop data transmission delay that hurts the performance of using in-network computing. We further derive theoretical upper and lower bounds of the required number of intermediate nodes that achieve the maximum acceleration. We also implement our proposed solution in a full-stack network emulator. Based on an open and professional data set, evaluation results justify the feasibility and advantages of our idea with nearly 32.18% acceleration on total processing time. This work exemplifies the convergence of IIoT, edge, and clouds. Huanzhuo Wu, Yunbin Shen, Xun Xiao, Giang T. Nguyen 0002, Artur Hecker, Frank H. P. Fitzek |
IEEE Internet Things J. | 5 |
| 2023 | Multi-Criteria Dynamic Service Migration for Ultra-Large-Scale Edge Computing NetworksabstractMultiaccess edge computing (MEC) service migration is a technology whose key objective is to support ultralow-latency access to services. However, the complex ultralarge-scale edge service migration problem requires extensive research efforts, regarding the foreseen ultradensified edge nodes in 5G and beyond. In this article, we propose a novel dynamic service migration optimization architecture for ultralarge-scale MEC networks. We develop a new multicriteria decision-making algorithm: Technique for order of preference by similarity to ideal solution with attribute-based Niche count, named TOPANSIS, which showcases its strength to provide an optimal solution for service migration in large-scale deployments towards optimal data rate, latency, and load balancing. We further decentralize the operation of TOPANSIS to release the traffic burden from central datacenters by leveraging local decision making by edge nodes, while relying on central cloud coordination to account for the overall network information. Simulation results showcase that the proposed architecture outperforms the selected benchmarks with an average improvement of 39.41% for latency, 2.92% for data rate, as well as 10.53% and 6.26% for RAM and CPU load balancing, respectively. Moreover, the feasibility of the proposed solution is validated by means of a proof-of-concept implementation and experimental assessments. Hao Ran Chi, David Santos, José Quevedo, Daniel Corujo, Osama Abboud, Ayman Radwan, Artur Hecker, Rui L. Aguiar |
IEEE Trans. Ind. Informatics | 8 |
| 2023 | Runtime Verification for Programmable SwitchesabstractWe introduce a runtime verification framework for programmable switches that complements static analysis. To evaluate our approach, we design and developP6, a runtime verification system that automatically detects, localizes, and patches software bugs in P4 programs. Bugs are reported via a violation of pre-specified expected behavior that is captured byP6.P6is based on machine learning-guided fuzzing that tests P4 switch non-intrusively, i.e., without modifying the P4 program for detecting runtime bugs. This enables an automated and real-time localization and patching of bugs. We used aP6prototype to detect and patch existing bugs in various publicly available P4 application programs deployed on two different switch platforms, namely, behavioral model (bmv2) and Tofino. Our evaluation shows thatP6significantly outperforms bug detection baselines while generating fewer packets and patches bugs in large P4 programs, e.g.,switch.p4without triggering any regressions. Apoorv Shukla, Kevin Nico Hudemann, Zsolt Vági, Lily Hügerich, Georgios Smaragdakis, Artur Hecker, Stefan Schmid 0001, Anja Feldmann |
IEEE/ACM Trans. Netw. | 6 |
| 2022 | Modeling Ledger Dynamics in IOTA BlockchainabstractIOTA blockchain is a new type of distributed ledger systems that is lightweight without mining and feeless-of-using. Rather than using a chain structure as in traditional blockchains, IOTA organizes ledger records with a directed acyclic graph (DAG), called Tangle. When message entries are committed into the ledger, the ledger tangle grows in a special way where multiple messages could be attached by different processing nodes in parallel. Such a unique evolution process motivates us to study the ledger tangle dynamics, which is unexplored so far. In this paper, we present the first generative modeling for IOTA tangle based on stochastic analysis. A key finding is that IOTA tangle renders a double Pareto Lognormal (dPLN) distribution, rather not typical network models (e.g., Power-Law and Exponential distributions). Quantitative comparisons show that the fitting quality of our model outperforms existing popular models on official real world datasets published by IOTA Foundation. Estimated model parameters are provided, which is immediately instrumental for a more realistic IOTA network generator design. The proposed generative model also provides a deeper understanding of the internal mechanics of IOTA network. Fengyang Guo, Xun Xiao, Artur Hecker, Schahram Dustdar |
GLOBECOM | 3 |
| 2022 | Multi-Criteria Modeled Live Service Migration for Heterogeneous Edge ComputingabstractIn this paper, we modeled the emerging edge-computing-enabled live service migration as a multi-criteria problem optimization, tackling migration costs and benefits, as well as discussion of service providers' data privacy, simultaneously. Based on the optimization formulation, we conducted a small-scale analytical feasibility test, considering widely-utilized multi-criteria decision making algorithms, based on which we proposed a new TOPSIS based service migration algorithm. The algorithm was evaluated using simulations, whose results show that the proposed algorithm is sufficient to support live service migration for heterogeneous edge computing, while outperforming benchmarks in with respect to reducing migration costs and increasing achieved benefits, by 34.52% and 60.21%, respectively. Ayman Radwan, Hao Ran Chi, Daniel Corujo, José Quevedo, David Santos, Rui L. Aguiar, Osama Abboud, Artur Hecker |
GLOBECOM | 9 |
| 2022 | Fast Tip Selection for Burst Message Arrivals on A DAG-based Blockchain Processing Node at EdgeabstractWith the rapid evolution of blockchain technology, a clear trend is that new blockchain systems (e.g., IOTA) tend to use a Directed Acyclic Graph (DAG) rather a chain structure to organize ledger records. Such a DAG-based blockchain system shows higher scalability as multiple locations are available in the ledger for new message attachment. To decide an attachment location, a popular type of tip selection algorithms follow an approach using weighted random walks on the DAG ledger. In a burst message arrival scenario, however, a processing node deployed at edge using such a method may become a bottleneck because sequentially repeating random walks significantly increases processing delay. In this paper, we propose a new tip selection algorithm for the burst message arrival scenario on an edge node. Our solution abandons the weighted random walk approach, instead, with similar efforts we transfer to calculate in advance the tip selection probability distribution of the DAG ledger. Such a new scheme reduces tip selection to a probability distribution sampling task, which can be done extremely fast. We implement our solution and demonstrate the benefits of our approach by comparing with the random walk approach. We believe our attempt can effectively mitigate the congestion at the edge node and inspire tip selection algorithm design with a new vision for DAG-based blockchain systems. Xun Xiao, Fengyang Guo, Artur Hecker, Schahram Dustdar |
GLOBECOM | 3 |
| 2022 | Multi-Agent Distributed Reinforcement Learning for Making Decentralized Offloading DecisionsabstractWe formulate computation offloading as a decentralized decision-making problem with autonomous agents. We design an interaction mechanism that incentivizes agents to align private and system goals by balancing between competition and cooperation. The mechanism provably has Nash equilibria with optimal resource allocation in the static case. For a dynamic environment, we propose a novel multi-agent online learning algorithm that learns with partial, delayed and noisy state information, and a reward signal that reduces information need to a great extent. Empirical results confirm that through learning, agents significantly improve both system and individual performance, e.g., 40% offloading failure rate reduction, 32% communication overhead reduction, up to 38% computation resource savings in low contention, 18% utilization increase with reduced load variation in high contention, and improvement in fairness. Results also confirm the algorithm’s good convergence and generalization property in significantly different environments. Ramin Khalili, Holger Karl, Artur Hecker |
INFOCOM | 4 |
| 2022 | mobile-env: An Open Platform for Reinforcement Learning in Wireless Mobile NetworksabstractRecent reinforcement learning approaches for continuous control in wireless mobile networks have shown impressive results. But due to the lack of open and compatible simulators, authors typically create their own simulation environments for training and evaluation. This is cumbersome and time-consuming for authors and limits reproducibility and comparability, ultimately impeding progress in the field.To this end, we propose mobile-env, a simple and open platform for training, evaluating, and comparing reinforcement learning and conventional approaches for continuous control in mobile wireless networks. mobile-env is lightweight and implements the common OpenAI Gym interface and additional wrappers, which allows connecting virtually any single-agent or multi-agent reinforcement learning framework to the environment. While mobile-env provides sensible default values and can be used out of the box, it also has many configuration options and is easy to extend. We therefore believe mobile-env to be a valuable platform for driving meaningful progress in autonomous coordination of wireless mobile networks. Stefan Schneider 0008, Ramin Khalili, Artur Hecker, Holger Karl |
NOMS | 4 |
| 2022 | Multi-agent reinforcement learning for long-term network resource allocation through auction: A V2X application
Ramin Khalili, Holger Karl, Artur Hecker |
Comput. Commun. | 4 |
| 2021 | In-Network Processing Acoustic Data for Anomaly Detection in Smart FactoryabstractModern manufacturing is now deeply integrating new technologies such as 5G, Internet-of-things (IoT), and cloud/edge computing to shape manufacturing to a new level – Smart Factory. Autonomic anomaly detection (e.g., malfunctioning machines and hazard situations) in a factory hall is on the list and expects to be realized with massive IoT sensor deployments. In this paper, we consider acoustic data-based anomaly detection, which is widely used in factories because sound information reflects richer internal states while videos cannot; besides, the capital investment of an audio system is more economically friendly. However, a unique challenge of using audio data is that sounds are mixed when collecting thus source data separation is inevitable. A traditional way transfers audio data all to a centralized point for separation. Nevertheless, such a centralized manner (i.e., data transferring and then analyzing) may delay prompt reactions to critical anomalies. We demonstrate that this job can be transformed into an in-network processing scheme and thus further accelerated. Specifically, we propose a progressive processing scheme where data separation jobs are distributed as microservices on intermediate nodes in parallel with data forwarding. Therefore, collected audio data can be separated 43.75% faster with even less total computing resources. This solution is comprehensively evaluated with numerical simulations, compared with benchmark solutions, and results justify its advantages. Huanzhuo Wu, Yunbin Shen, Xun Xiao, Artur Hecker, Frank H. P. Fitzek |
GLOBECOM | 4 |
| 2021 | Fix with P6: Verifying Programmable Switches at RuntimeabstractWe design, develop, and evaluate P6, an automated approach to (a) detect, (b) localize, and (c) patch software bugs in P4 programs. Bugs are reported via a violation of pre-specified expected behavior that is captured by P6. P6 is based on machine learning-guided fuzzing that tests P4 switch non-intrusively, i.e., without modifying the P4 program for detecting runtime bugs. This enables an automated and real-time localization and patching of bugs. We used a P6 prototype to detect and patch existing bugs in various publicly available P4 application programs deployed on two different switch platforms: behavioral model (bmv2) and Tofino. Our evaluation shows that P6 significantly outperforms bug detection baselines while generating fewer packets and patches bugs in large P4 programs such as switch.p4 without triggering any regressions. Apoorv Shukla, Kevin Nico Hudemann, Zsolt Vági, Lily Hügerich, Georgios Smaragdakis, Artur Hecker, Stefan Schmid 0001, Anja Feldmann |
INFOCOM | 6 |
| 2021 | Self-Learning Multi-Objective Service Coordination Using Deep Reinforcement LearningabstractModern services consist of interconnected components, e.g., microservices in a service mesh or machine learning functions in a pipeline. These services can scale and run across multiple network nodes on demand. To process incoming traffic, service components have to be instantiated and traffic assigned to these instances, taking capacities, changing demands, and Quality of Service (QoS) requirements into account. This challenge is usually solved with custom approaches designed by experts. While this typically works well for the considered scenario, the models often rely on unrealistic assumptions or on knowledge that is not available in practice (e.g., a priori knowledge). We propose DeepCoord, a novel deep reinforcement learning approach that learns how to best coordinate services and is geared towards realistic assumptions. It interacts with the network and relies on available, possibly delayed monitoring information. Rather than defining a complex model or an algorithm on how to achieve an objective, our model-free approach adapts to various objectives and traffic patterns. An agent is trained offline without expert knowledge and then applied online with minimal overhead. Compared to a state-of-the-art heuristic, DeepCoord significantly improves flow throughput (up to 76%) and overall network utility (more than 2x) on real-world network topologies and traffic traces. It also supports optimizing multiple, possibly competing objectives, learns to respect QoS requirements, generalizes to scenarios with unseen, stochastic traffic, and scales to large real-world networks. For reproducibility and reuse, our code is publicly available. Stefan Schneider 0008, Ramin Khalili, Adnan Manzoor, Haydar Qarawlus, Rafael Schellenberg, Holger Karl, Artur Hecker |
IEEE Trans. Netw. Serv. Manag. | 7 |
| 2020 | Self-Driving Network and Service Coordination Using Deep Reinforcement LearningabstractModern services comprise interconnected components, e.g., microservices in a service mesh, that can scale and run on multiple nodes across the network on demand. To process incoming traffic, service components have to be instantiated and traffic assigned to these instances, taking capacities and changing demands into account. This challenge is usually solved with custom approaches designed by experts. While this typically works well for the considered scenario, the models often rely on unrealistic assumptions or on knowledge that is not available in practice (e.g., a priori knowledge). We propose a novel deep reinforcement learning approach that learns how to best coordinate services and is geared towards realistic assumptions. It interacts with the network and relies on available, possibly delayed monitoring information. Rather than defining a complex model or an algorithm how to achieve an objective, our model-free approach adapts to various objectives and traffic patterns. An agent is trained offline without expert knowledge and then applied online with minimal overhead. Compared to a state-of-the-art heuristic, it significantly improves flow throughput and overall network utility on real-world network topologies and traffic traces. It also learns to optimize different objectives, generalizes to scenarios with unseen, stochastic traffic patterns, and scales to large real-world networks. Stefan Schneider 0008, Adnan Manzoor, Haydar Qarawlus, Rafael Schellenberg, Holger Karl, Ramin Khalili, Artur Hecker |
CNSM | 7 |
| 2020 | Characterizing IOTA Tangle with Empirical DataabstractIOTA organizes transactions in the ledger as a Directed Acyclic Graph (DAG) called Tangle, instead of a hash chain of transaction blocks used by most of traditional blockchains. IOTA is considered a promising platform to support Internet-of-Things (IoT) applications with its key features such as micropayment support and absence of transaction fees. While prior art shows extensive analysis based on synthetic data generated through simulations, an analysis based on empirical data from a deployed IOTA network is still missing. In this paper, we provide the first comprehensive analysis by using real transaction data officially published by IOTA Foundation. Our key finding is that neither the tangle's topological features nor the actual observed performance is consistent with the main conclusions from the literature. In particular, most of transactions take roughly 10 minutes to be officially confirmed, which is not exactly instant as commonly assumed; yet, what is arguably worse is that there is a certain amount (5%) of transactions experiencing exceptionally long confirmation time. This shows that IOTA still has gaps to meet the stringent requirements of IoT applications that are delay sensitive. Fengyang Guo, Xun Xiao, Artur Hecker, Schahram Dustdar |
GLOBECOM | 3 |
| 2020 | P4Consist: Toward Consistent P4 SDNsabstractThe prevailing wisdom is that a software-defined network (SDN) operates under the premise that the logically centralized control plane has an accurate representation of the actual data plane state. Unfortunately, bugs, misconfigurations, faults or attacks can introduce inconsistencies between the network control and the data plane that can undermine the correct operation at runtime. Through our experiments, we realize that P4 SDNs are no exception, and are prone to similar problems. With the aim to verify the control-data plane inconsistency, we present the design and implementation of P4Consist, a system to detect the inconsistency between control and data plane in P4 SDNs. P4Consist generates active probe-based traffic continuously or periodically as an input to the P4 SDNs to check whether the actual behavior on the data plane corresponds to the expected control plane behavior. In P4Consist, the control plane and the data plane generate independent reports which are later, compared to verify the control-data plane consistency. The previous works in the field of monitoring and verification mostly aim to test the P4 programs through static analysis and thus, are insufficient to verify the network consistency at runtime. Experiments with our prototype implementation of P4Consist are promising and show that P4Consist can verify the control-data plane consistency in the complex datacenter 4-ary fat-tree (20 switches) and multipath grid (4, 9 and 16 switches) topologies with 60k rules per switch within a minimum time of 4 minutes. At the same time, P4Consist scales to multiple source-destination pairs to detect control-data plane inconsistency. Apoorv Shukla, Seifeddine Fathalli, Thomas Zinner, Artur Hecker, Stefan Schmid 0001 |
IEEE J. Sel. Areas Commun. | 4 |
| 2018 | Flow Setup Latency in SDN NetworksabstractIn software-defined networking, the typical switch-controller cycle, from generating a network event notification at the controller until the flow rules are installed at the switches, is not an instantaneous activity. Our measurement results show that this has serious implications on the performance of flow setup procedure, specifically for larger networks: we observe that, even with software switches, the flow setup latency for networks of around 500 switches is in the order of 50 ms, with 99th percentile exhibiting 10× higher latencies. To reduce both the latency and the variance of the flow setup, we propose path aggregation strategies, which turn the network into a set of pre-configured pipes that connect any pair of nodes. Our approach radically simplifies the flow setup procedure by minimizing the set of switches to be updated for new user-initiated flows to a constant number. We implement our solution in our testbed and study its performance through measurements. The results show that in similar settings, it reduces the median and 99-percentile latencies to 5.9 and 7 ms, respectively, significantly improving the performance, especially in the tail. Ramin Khalili, Zoran Despotovic, Artur Hecker |
IEEE J. Sel. Areas Commun. | 3 |
| 2017 | Towards Location Management in SDN-based MCNabstractOne of the key functionalities in EPC (Evolved packet Core) is Mobility Management (MM), which provides procedures for service continuity as the mobile devices (UE) move across the network. In a quest for more flexibility of MM, recent studies suggested to map MM procedures to SDN applications in an SDN controller. So far, these proposals investigated and showed how path switching during handover, one of the procedures of MM, is achieved in such an SDN-based Mobile Core Network (MCN). However, Location Management (LM) procedures, such as paging, are equally important. In this paper, we address this gap. We notably design and implement SDN-based UE state management and paging procedure for MCN. Our design only uses the data from the SDN controller, such as UE connectivity and flow information, and defines a new set of UE states: deregistered, idle, and active. We introduce new, dynamically configurable UE inactivity timers that regulate the transitions among these states. With this, we implement a purely SDN-based paging procedure capable of bringing a UE into a connected state on request, e.g. to deliver the downlink traffic. The experiments with our implementation on Floodlight SDN controller under different network loads and configuration settings for UE inactivity timers in Mininet demonstrate the practical feasibility of an SDN-based LM. Further, we show how different UE inactivity timer values can flexibly regulate the amount of paging. All in all, our results suggest that, leveraging the programmability provided by SDN, operators can flexibly install and use LM SDN apps with different settings to tailor the amount of paging according to the specific UE or user application activity patterns and its needs. Maja Sulovic, Clarissa Cassales Marquezan, Artur Hecker |
IM | 3 |
| 2016 | Reducing State of OpenFlow Switches in Mobile Core Networks by Flow Rule AggregationabstractWhile bringing many advantages, Software-Defined Networking (SDN) is accompanied by potential scalability issues that should be considered in the design of SDN-based networks. Specifically, SDN hardware switches based on Ternary Content-Addressable Memory (TCAM) can only store a few thousands of rules, imposing thus severe limits on the number of flows they can serve/process. Current proposals to deal with this problem mainly focus on optimal placement of flows that complies with the given constraints on TCAM size. We argue in this paper that flow routing not only should be but also can be independent of TCAM size constraints. We introduce two flow rule aggregation algorithms: One performs the "per-outport'' aggregation of the paths between access nodes in the network. It is optimal in that it holds the flow table sizes at the minimum, but has a drawback that it produces long identifiers of the path endpoints (access nodes), which cannot fit the IP address size. The other algorithm is its approximation under the constraint that the generated identifiers fit the limit imposed by the addressing scheme (e.g., IPv4). We study the performance of our algorithms analytically and through a set of experiments. While the optimal solution always keeps the flow table sizes at the minimum, we show that the approximate algorithm reduces the flow table sizes by a factor of 2 to 10 compared to the state of the art solution, under a reasonable constraint on the address length (e.g., 32 bits in case of IPv4). Ramin Khalili, Wint Yi Poe, Zoran Despotovic, Artur Hecker |
ICCCN | 4 |
| 2016 | Identifying latency factors in SDN-based Mobile Core NetworksabstractSoftware Defined Networking (SDN) is considered one of the major driving factors to bring radical changes on Mobile Core Networks (MCN) design. There are many proposals on how to advocate SDN methodology, however, most of them stop at “vision” level without providing details about key performance contributors. In this paper, we tackle this gap and present a study of latency in SDN based MCN. We identify the major factors and elements in an SDN MCN that contribute to the overall latency. Two types of latency are considered: the processing delay inside the SDN control plane and the transmission delay of SDN control messages between controller and the managed switches. We use a realistic system setup with implementations of SDN controller and SDN application, as well as in-band transfer of control messages among switches and controller. We compare the latency obtained from SDN based MCN with the Evolved Packet Core (EPC). The observed overall latency in our experiments for SDN based MCN is within the EPC requirements. The direct comparison of the SDN versus EPC based MCN in the proposed scenarios show the first can reduce the overall latency. We also identified that the calls to controller APIs can be the major key contributors to the overall latency in SDN MCN, but the act of transmitting more control messages from the controller to the switches to setup longer flowpaths is not a key contributor for the overall latency. Clarissa Cassales Marquezan, Xueli An, Zoran Despotovic, Ramin Khalili, Artur Hecker |
ISCC | 5 |
| 2016 | Dispatching PACKET_INs to the right SDN control application via context interpretation in Mobile Core NetworksabstractTelco operators started to apply the SDN technologies also in the design of Mobile Core Networks (MCNs). In this change towards SDNized Mobile Core Network, it is crucial to understand how conventional interfaces among different mobile network entities should evolve. The issues derived from this change have not been tackled by current research approaches. This paper presents the first initiative to close this research gap. We tackle the key problem of how to identify which mobile SDN applications (APPs) should be invoked once a PACKET_IN (the OpenFlow message that transport information from the data plane to the control plane) is received at the control level. We propose data structures, a model, and detailed examples of three important PACKET_IN context interpretation for MCNs. Initial experiments, based on Floodlight controller and Mininet emulation environment were carried out. The results indicate that it is feasible to use our proposed approach to dispatch PACKET_INs to the right SDN APP. The delay introduced due to invocation of such mechanism to interpret the context of the PACKET_IN and activate the appropriate mobile SDN APPs is only in the order of microseconds. Our proposal can be used to simplify current Mobile Core Network interface design by exploiting the SDN mechanisms. We believe, this work helps to pave the way towards fully SDNized Mobile Core Networks. Clarissa Cassales Marquezan, Xueli An, Zoran Despotovic, Ramin Khalili, Artur Hecker |
NOMS | 5 |
| 2016 | Understanding processing latency of SDN based mobility management in mobile core networksabstractCurrent solutions to evolve mobility management in Mobile Core Networks (MCN) based on SDN have showed the gain in flexibility and how to reduce control signaling. However, these works neglect the problems of describing the design choices of SDN Mobility Management Applications (MMA) and identifying where and what are the critical processing latency contributors for such design. Our paper addresses these problems. We study the internal mechanisms and interactions of MMA and controller, to determine the contributors to the overall processing latency. We implemented two MMA solutions (based on reactive and proactive designs) as modules of Floodlight, and we run experiments using Mininet and OpenFlow. The proactive MMA design can guarantee that the overall processing latency in the 95th percentile can be kept near the median value, given available CPU capacity at the SDN controller. One key lesson learned with our study is that only optimizing control signaling of MMA is not enough to provide better overall processing latency. Clarissa Cassales Marquezan, Zoran Despotovic, Ramin Khalili, David Pérez-Caparrós, Artur Hecker |
PIMRC | 5 |
| 2015 | On optimal hierarchical SDNabstractTo address scalability concerns, hierarchical control plane organization has been proposed for SDN. However, an open question is how such a hierarchy should look like. In this paper, we model the impact of hierarchies on control plane performance and derive an expression for an optimal hierarchical organization for a given network scale. We then show that using a 4-layer SDN is sufficient for practical network scales, suggesting feasibility and relevance of this approach. Finally, we illustrate the elasticity of hierarchical SDN, which enables a more flexible cost evolution of the SDN control plane. Yalin Liu, Artur Hecker, Riccardo Guerzoni, Zoran Despotovic, Sergio Beker |
ICC | 2 |
| 2014 | VNetMapper: A fast and scalable approach to virtual networks embeddingabstractVirtual network embedding is considered an important problem to solve in order to make infrastructure virtual-ization economically reasonable. The most efficient algorithms proposed so far define link and node mappings as optimal solutions of Integer Programming (IP) problems. They exhibit reasonably good performance only for small problem instance sizes, including few tens of nodes and links per physical substrate, few nodes and links per virtual request and a dozen of virtual requests to handle in parallel. However, we find these instances too small to be of any practical use. To address this scalability issue, we propose VNetMapper, an algorithm to solve the virtual network embedding problem based on an integer program formulation with appropriately selected objective function, variables and the set of constraints tuned to give an optimal performance. We show through simulations that VNetMapper can quickly, within seconds, solve large problem instances, involving physical substrates with hundreds of nodes and thousands of links and batches of hundreds of virtual network requests. By identifying exact properties that make VNetMapper so fast and scalable, we present guidelines for designing scalable integer programs. Zoran Despotovic, Artur Hecker, Ahsan Naveed Malik, Riccardo Guerzoni, Ishan Vaishnavi, Riccardo Trivisonno, Sergio Beker |
ICCCN | 2 |
| 2014 | A novel approach to virtual networks embedding for SDN management and orchestrationabstractThe development of methodologies to manage and orchestrate virtualised resources and network functions is a fundamental enabler for optimally utilising physical ICT infrastructures. Algorithms for optimal location (embedding) of network functions, IT and CT resources, services and corresponding states, especially at the network edge, will enable new business models and provide a key competitive advantage to network administrators. This paper introduces a novel Mixed Integer Programming (MIP) formulation for a coordinated node and link mapping onto the underlying network infrastructure. Extensive simulation results show that the proposed algorithm outperforms prior art formulations: two digit gains were attained in terms of resources utilisation, embedding, revenues and, especially convergence time. The proposed methodology is applicable to a number of relevant use cases, as constraints and objective functions can be flexibly defined by network operators. Riccardo Guerzoni, Riccardo Trivisonno, Ishan Vaishnavi, Zoran Despotovic, Artur Hecker, Sergio Beker, David Soldani |
NOMS | 5 |
| 2011 | A new approach to evaluating security assuranceabstractThis paper first analyzes the current gap in the literature in security assurance. It then proposes new metrics for the appraisal of security assurance at runtime. Our metrics are based on key concepts pertinent to gaining confidence on a security mechanism to meet its functions. Such parameters include: security correctness; security effectiveness and the quality of the security verification process. Validation of our approach has been achieved through tool implementation, and application to another of security components including firewall, DNS and antivirus. Moussa Ouedraogo, Haralambos Mouratidis, Artur Hecker, Cédric Bonhomme, Djamel Khadraoui, Eric Dubois 0001, David Preston 0001 |
IAS | 3 |
| 2011 | Operational Security Assurance Evaluation in Open InfrastructuresabstractMeasuring and evaluating cyber security is of primary importance in IT systems. The fundamental need to assess security choices validity and effectiveness is growing. One of the main accepted approaches to this problem is a standardized offline security assurance evaluation. But, this method is static, time consuming and does not scale well to complex and dynamic Telco systems. As such, it does not apply to a continuous security assurance assessment for today's complex operational systems. In this paper, we present a methodology together with the required tools for the operational security assurance assessment of Telco services. Our methodology enables (i) the definition and instantiation of a security Assurance Profile, and (ii) the use of a flexible measurement framework and a security cockpit for operational assurance metrics evaluation. The Assurance Profile provides a framework to the security expert community in order to collect descriptions and architectures of typical security mechanisms, and establish best practices on operational security assurance requirements and measurements for these architectures. The distributed dedicated measurement framework and the security assurance cockpit, as integral parts of the operational assurance assessment process, provide specifically adapted tools to evaluate operational security assurance on targeted systems. Sammy Haddad, Samuel Dubus, Artur Hecker, Teemu Kanstrén, Bertrand Marquet, Reijo Savola |
CRiSIS | 3 |
| 2011 | VIRCONEL: A Network VirtualizerabstractIn this paper we present VIRCONEL, a new, open source (LGPL) tool that we developed to run experiments and do research in networked ICT environments built from real software. VIRCONEL features an integrated graphical user interface to model, deploy, launch, runtime-control and measure a target system with an arbitrary network topology. Based on Open VZ, the current version of VIRCONEL combines ease of use and efficiency by ensuring rapid and easy deployment of potentially large target systems across multiple physical machines. Yacine Benchaïb, Artur Hecker |
MASCOTS | 2 |
| 2009 | A Construction Scheme for Scale Free DHT-Based NetworksabstractIn this paper, we propose PowerDHT, a novel scheme to extend the classic DHT-based overlay to a network with scale free-like properties. PowerDHT has a distributed rewiring method to improve the structure of the overlay network to a power-law-like graph. Our scheme is characterized through minimal, typically local-only, changes. Through simulations, we show that our proposal constructs an overlay network with an extended peer's neighborhood knowledge and a reduced network diameter at no additional cost and that it supports a more effective flooding e.g. for generic search. Salma Ktari, Artur Hecker, Houda Labiod |
GLOBECOM | 2 |
| 2009 | Exploiting routing unfairness in DHT overlaysabstractPeer-to-Peer overlays have become a popular paradigm for building distributed systems, aiming to provide resource localization and sharing in large-scale networks. To design an overlay network, the first step is to choose an overlay topology connecting all the overlay nodes. Many proposed distributed hash table schemes for peer-to-peer network are based on some traditional calculated interconnection topologies. In this paper, we propose to extend the DHT topology to a bidirectional graph to provide a super-peer based lookup algorithm and a scalable resource localization support. We consider bidirectional routing algorithms and show how the resulting unfair routing structure extends the search region and provides an efficient resource lookup service at a very little additional cost. Salma Ktari, Artur Hecker, Houda Labiod |
ISCC | 2 |
| 2008 | Power-law chord architecture in P2P overlaysabstractIn this paper, we propose to extend the topology of Chord to a bidirectional graph to provide a super-peer based lookup algorithm and an efficient resource localization service at a very little additional cost. Salma Ktari, Artur Hecker, Houda Labiod |
CoNEXT | 2 |
| 2008 | Symmetric replication for efficient flooding in DHTsabstractTo support complex queries and broadcast in DHTs, we propose an algorithm for an effective flooding that we implement and compare in a Chord DHT. We use flooding and replication that exploit structural constraints to achieve lower overhead and higher reliability. Salma Ktari, Mathieu Zoubert, Artur Hecker, Houda Labiod |
MobiHoc | 3 |
| 2007 | Performance evaluation of replication strategies in DHTs under churnabstractThis paper presents a comparative analysis of replication algorithms for DHT (Distributed Hash Table) architectures. These algorithms are applicable to all existing structured peer-to-peer systems, and can be implemented on top of any DHT. The performance of these algorithms is examined using emulation through virtualization. Significant differences are identified in terms of delays, control overhead, success rate, and overlay route length. Salma Ktari, Mathieu Zoubert, Artur Hecker, Houda Labiod |
MUM | 3 |
| 2007 | Fast Re-Authentication Protocol for Inter-Domain RoamingabstractIn this paper we introduce the Fast re-Authentication protocol (FAP) for inter-domain roaming, which aims to reduce authentication delay of a mobile user in a visited administrative domain. The approach eliminates the need of communication between the target and the user's home networks for credentials verification and uses a short-living lightweight re-authentication ticket that does not require revocation mechanism. The proposed approach does not depend on the nature of roaming agreements between different networks. Maryna Komarova, Michel Riguidel, Artur Hecker |
PIMRC | 3 |
| 2006 | Armature for Critical InfrastructuresabstractCritical infrastructures have elevated requirements on security and availability. However, where security and availability are issues, security assurance evaluation becomes crucial. Evaluating security assurance is a non-trivial problem. In this paper, we discuss several security assurance aspects and the role of modeling in this context. We then introduce a novel, non-intrusive approach to security assurance evaluation. This approach comprises a modeling technique for the targeted infrastructure, the additional, non-intrusive evaluation infrastructure, and the implied evaluation methodology. We discuss possible implementations in an existing network. Michel Riguidel, Artur Hecker, Véronique Simon |
SMC | 2 |
| 2004 | Pre-authenticated signaling in wireless LANs using 802.1X access controlabstractIn this paper, we propose a generalization of the 802.1X architecture using an extensible authentication protocol (EAP) for more general signaling data transport purposes. We develop EAP/SIG, an effective and easy-to-implement generic signaling protocol for future wireless LANs. We discuss the advantages of this approach and show how it can be implemented. Artur Hecker, Houda Labiod |
GLOBECOM | 1 |
| 2004 | An efficient micromobility implementation for 802.1X WLANsabstractWe analyze the implications of the integration of the current IP micromobility concepts with the 802.1X access control. We show that the independent user location tracking of IP micromobility and 802.1X provokes a significant additional handover delay and signaling load degrading the overall performance. To overcome these difficulties, we propose a system architecture which uses EAP as a general signaling protocol. We then discuss the new opportunities of our approach. Finally, we show that our system architecture can be applied in almost all access networks by exploiting the generality of the 802.1X approach. Artur Hecker, Houda Labiod |
PIMRC | 1 |
| 2003 | A novel authentication model based on secured IP smart cardsabstractAn authentication model using secured smart cards implementing IP services is presented. In this model, some authentication functions usually found in the access network are moved inside the smart card. This innovative architecture simplifies current authentication schemes and helps to design new services. Bachar Zouari, Hossam Afifi, Artur Hecker, Houda Labiod, Guy Pujolle, Pascal Urien |
ICC | 3 |