Vyas Sekar

dblp:45/4044 · DBLP profile ↗
← Back
136ranked-venue papers
9as first author
42since 2021 · last 2026
0000-0001-5452-8976ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 91 · 7 first-author · 18 since 2021Security and privacy · 23 · 1 first-author · 13 since 2021Systems, architecture and hardware · 8 · 2 first-authorArtificial intelligence and machine learning · 5 · 5 since 2021Software engineering, systems software and programming languages · 5 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 1 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 since 2021
YearPublicationVenuePosition
2026 AHA: Scalable Alternative History Analysis for Operational Timeseries Applications
Harshavardhan Kamarthi, Harshil Shah, Henry Milner, Sayan Sinha, B. Aditya Prakash, Vyas Sekar
KDD (1)7
2026 MoCE: A Mixture-of-Context Aware Experts Framework for Troubleshooting Internet-scale Services
Vipul Harsh, Sayan Sinha, Henry Milner, B. Aditya Prakash, Vyas Sekar, Hui Zhang 0001
NSDI5
2026 ASAPQuery: A Drop-in Sketch-based Query Accelerator for Netflow Analytics
abstract
Network operators rely on NetFlow [2] telemetry to monitor attacks, diagnose performance, and analyze traffic. To do so, they run SQL queries over recent time windows to detect heavy hitters, anomalies, and tail metrics, served through analytics databases and dashboards. These NetFlow records are typically stored in databases like ClickHouse [12], which are well-tuned for full-scan analytical queries through column compression, vectorized execution, and time-based partitioning. Even so, every query remains bound by the cost of scanning each row in its window, a cost that increases with the ingestion rate. As data volumes and field cardinality (e.g., IP addresses) grow, these scans slow dashboards during traffic spikes, precisely when timely insight matters most.
Akanksha Akkihal, Milind Srivastava, Vyas Sekar
SIGCOMM3
2026 POSTER: DeePCAP: Enabling High-Fidelity and Cost-Efficient Archival Packet Trace Storage
abstract
Long-term network packet traces (e.g., pcaps), if available, can enable and inform lots of management tasks. However, storing packet data at scale is very expensive, forcing operators to choose between coarse historical summaries or short retention windows. In this context, deep generative compression (DGC) offers a new hope to store compact model parameters and regenerate structurally accurate traces on demand. We evaluate the suitability of recent deep generative approaches [21, 24] for packet trace modeling and generation. We find that their fidelity metrics are disconnected from the domain-specific queries/use cases, and they have bad cost-fidelity trade-off. We propose DeePCAP, an end-to-end trace storage system to close this gap. DeePCAP introduces a query-driven fidelity framework spanning packet- and flow-level queries to tackle the fidelity disconnection, and proposes a novel dimensionality reduction approach using frequency domain encoding to improve cost-fidelity trade-off. Our preliminary results show that DeePCAP achieves the best fidelity on the 100+ query suite and the strongest cost-fidelity trade-off.
Fenghao Dong, Yucheng Yin, Peilin Xin, Shinan Liu, Vyas Sekar
SIGCOMM6
2026 Incalmo: an Autonomous Llm-Assisted System for Red Teaming Multi-Host Networks
Brian Singer, Keane Lucas, Lakshmi Adiga, Meghna Jain, Lujo Bauer, Vyas Sekar
SP6
2025 Automatically Surfacing Opportunities for Improvements In Internet-Scale Applications
abstract
Modern Internet services generate massive volumes of observability data, yet identifying opportunities for business performance improvements remains elusive. In many cases, such insights manifest only within sub-populations defined by derived attributes that cannot be predefined, might evolve over time, and often cannot be exhaustively enumerated ahead of time. Unfortunately, existing commercial and research systems fall short in one or more aspects of generating such improvement opportunities: expressiveness, automation, and scalability. We present a vision for automatically surfacing opportunities for improvements to tackle these seemingly conflicting and intractable requirements. We highlight the early promise from a proof-of-concept system, showing evaluation on three real-world services and discuss open challenges for future work.
Vipul Harsh, Sayan Sinha, Henry Milner, Haijie Wu, B. Aditya Prakash, Vyas Sekar, Hui Zhang 0001
HotNets6
2025 SPIDER: Fuzzing for Stateful Performance Issues in the ONOS Software-Defined Network Controller
abstract
Performance issues in software-defined network (SDN) controllers can have serious impacts on the performance and availability of networks. In this paper, we consider a special class of SDN vulnerabilities called stateful performance issues (SPIs), where a sequence of initial input messages drives the controller into a state such that its performance degrades pathologically when processing subsequent messages. Uncovering SPIs in large complex software such as the widely used ONOS SDN controller is challenging because of the large state space of input sequences and the complex software architecture of inter-dependent network services. We present SPIDER, a practical fuzzing framework for identifying SPIs in this setting. The key contribution in our work is to leverage the event-driven modular software architecture of the SDN controller to (a) separately target each network service for SPIs and (b) use static analysis to identify all services whose event handlers can affect the state of the target service directly or indirectly. SPIDER implements this novel dependency-aware modular performance fuzzing approach for 157 network services in ONOS and successfully identifies 10 new performance issues. We present an evaluation of SPIDER against prior work, a sensitivity analysis of design decisions, and case studies of two uncovered SPIs.
Ao Li 0009, Rohan Padhye, Vyas Sekar
ICST3
2025 Heimdall: Towards Risk-Aware Network Management Outsourcing
Yuejie Wang, Qiutong Men, Yongting Chen, Jiajin Liu, Gengyu Chen, Ying Zhang 0022, Guyue Liu, Vyas Sekar
NDSS8
2025 Perry: A High-level Framework for Accelerating Cyber Deception Experimentation
abstract
Cyber deception aims to distract, delay, and detect network attackers with fake assets such as honeypots, decoy credentials, or decoy files. However, today, it is difficult for operators to experiment, explore, and evaluate deception approaches. Existing tools and platforms have non-portable and complex implementations that are difficult to modify and extend. We address this pain point by introducing Perry, a highlevel framework that accelerates the design and exploration of deception what-if scenarios. Perry has two components: a highlevel abstraction layer for security operators to specify attackers and deception strategies and an experimentation module to run these attackers and defenders in realistic emulated networks. To translate these high-level specifications into low-level primitives, we design four key modules in Perry: 1) an action planner that translates high-level actions into low-level implementations, 2) an observability module to translate low-level telemetry into highlevel observations, 3) an environment state service that enables environment agnostic strategies, and 4) an attack graph service to reason how attackers could explore an environment. We illustrate that Perry’s abstractions reduce the implementation effort across a wide variety of deception defenses, attackers, and environments. We demonstrate the value of Perry by emulating 55 unique deception what-if scenarios, illustrating how these experiments enable operators to shed light on subtle tradeoffs.
Brian Singer, Yusuf Saquib, Lujo Bauer, Vyas Sekar
RAID4
2025 Analyzing the Benefits of Optical Topology Programming for Mitigating Link-Flood DDoS Attacks
abstract
Link-flood attacks (LFAs) overwhelm bandwidth on links in a network using traffic from many sources, which is indistinguishable from benign traffic. Unfortunately, traditional DDoS defenses are incapable of stopping such attacks and recently proposed software-defined solutions are ineffective. In this work, we observe a new opportunity for mitigating LFAs using optical networking advances. In essence, we envision new capabilities fortopology programming, to scale capacity on-demand to avoid congestion and add new links to the network to create new paths for traffic during LFA incidents. Realizing these benefits of optical topology programming raises unique challenges; the search space for candidate topology configurations is very large and joint optimization of topology and routing is NP-hard. We present ONSET—a framework that tackles these challenges to lay a practical foundation for topology programming-based defenses against LFAs. We show that ONSET complements existing programmable network defenses and amplifies their benefits. We perform awhat-ifstyle analysis of ONSET by simulating a wide-ranging set of attacks, including terabit-scale attacks against every single link, on five networks with two different routing capabilities and observe that ONSET provides the means to mitigate congestion loss in more than 90% of the hundreds of diverse attack scenarios considered.
Matthew Nance Hall, Zaoxing Liu, Vyas Sekar, Ramakrishnan Durairajan
IEEE Trans. Dependable Secur. Comput.3
2024 SEAM-EZ: Simplifying Stateful Analytics through Visual Programming
abstract
Across many domains (e.g., media/entertainment, mobile apps, finance, IoT, cybersecurity), there is a growing need for stateful analytics over streams of events to meet key business outcomes. Stateful analytics over event streams entails carefully modeling the sequence, timing, and contextual correlations of events to dynamic attributes. Unfortunately, existing frameworks and languages (e.g., SQL, Flink, Spark) entail significant code complexity and expert effort to express such stateful analytics because of their dynamic and stateful nature. Our overarching goal is to simplify and democratize stateful analytics. Through an iterative design and evaluation process including a foundational user study and two rounds of formative evaluations with 15 industry practitioners, we created SEAM-EZ, a no-code visual programming platform for quickly creating and validating stateful metrics. SEAM-EZ features a node-graph editor, interactive tooltips, embedded data views, and auto-suggestion features to facilitate the creation and validation of stateful analytics. We then conducted three real-world case studies of SEAM-EZ with 20 additional practitioners. Our results suggest that practitioners who previously could not or had to spend significant effort to create stateful metrics using traditional tools such as SQL or Spark can now easily and quickly create and validate such metrics using SEAM-EZ.
Zhengyan Yu, Hun Namkung, Henry Milner, Joel Goldfoot, Yang Wang 0005, Vyas Sekar
CHI7
2024 Raising the Level of Abstraction for Sketch-Based Network Telemetry with SketchPlan
abstract
While sketch-based network telemetry is attractive, realizing its potential benefits has been elusive in practice. Existing sketch solutions offer low-level interfaces and impose high effort on operators to satisfy telemetry intents with required accuracies. Extending these approaches to reduce effort results in inefficient deployments with poor accuracy-resource tradeoffs. We present SketchPlan, an abstraction layer for sketch-based telemetry to reduce effort and achieve high efficiency. SketchPlan takes an ensemble view across telemetry intents and sketches, instead of existing approaches that consider each intent-sketch pair in isolation. We show that SketchPlan improves accuracy-resource tradeoffs by up-to 12x and up-to 60x vs. baselines, in single-node and network-wide settings. SketchPlan is open-sourced at: https://github.com/milindsrivastava1997/SketchPlan.
Milind Srivastava, Shao-Tse Hung, Hun Namkung, Kate Ching-Ju Lin, Zaoxing Liu, Vyas Sekar
IMC6
2024 TrustSketch: Trustworthy Sketch-based Telemetry on Cloud Hosts
Maria Apostolaki, Zaoxing Liu, Vyas Sekar
NDSS4
2024 ExChain: Exception Dependency Analysis for Root Cause Diagnosis
Ao Li 0009, Shan Lu 0001, Suman Nath, Rohan Padhye, Vyas Sekar
NSDI5
2024 Pryde: A Modular Generalizable Workflow for Uncovering Evasion Attacks Against Stateful Firewall Deployments
abstract
Stateful firewalls (SFW) play a critical role in securing our network infrastructure. Incorrect implementation of the intended stateful semantics can lead to evasion opportunities, even if firewall rules are configured correctly. Uncovering these opportunities is challenging due to the (1) black-box and proprietary nature of firewalls; (2) diversity of deployments; and (3) complex stateful semantics. To tackle these challenges, we present Pryde. Pryde uses a modular model-guided workflow that generalizes across black-box firewall implementations and deployment-specific settings to generate evasion attacks. Pryde infers a behavioral model of the stateful firewall in the presence of potentially non-TCP-compliant packet sequences. It uses this model in conjunction with attacker capabilities and victim behavior to synthesize custom evasion attacks. Using Pryde, we identify more than 6,000 unique attacks against 4 popular firewalls and 4 host networking stacks, many of which cannot be uncovered by prior work on censorship circumvention and black-box fuzzing.
Soo-Jin Moon, Milind Srivastava, Yves Bieri, Ruben Martins, Vyas Sekar
SP5
2023 Raising the Level of Abstraction for Time-State Analytics With the Timeline Framework
Henry Milner, Yihua Cheng, Jibin Zhan, Hui Zhang 0001, Vyas Sekar, Junchen Jiang, Ion Stoica
CIDR5
2023 ExoPlane: An Operating System for On-Rack Switch Resource Augmentation
Daehyeok Kim, Vyas Sekar, Srinivasan Seshan
NSDI2
2023 Sketchovsky: Enabling Ensembles of Sketches on Programmable Switches
Hun Namkung, Zaoxing Liu, Daehyeok Kim, Vyas Sekar, Peter Steenkiste
NSDI4
2023 A First Look at Third-Party Service Dependencies of Web Services in Africa
Aqsa Kashaf, Jiachen Dou, Margarita Belova, Maria Apostolaki, Yuvraj Agarwal, Vyas Sekar
PAM6
2023 Shedding Light on Inconsistencies in Grid Cybersecurity: Disconnects and Recommendations
abstract
The operational, academic, and policy communities disagree on which threats against the power grid are likely and what damage would ensue. For instance, the feasibility and impact of MadIoT-style attacks is being actively debated. By surveying grid experts (N=18) we find that disagreements are not unique to MadIoT attacks but occur across multiple well-studied grid threats. Based on prior work and our survey, we hypothesize that the disagreements stem from inconsistencies in how grid threats are modeled. We identify five likely causes of modeling inconsistencies: 1) using unrealistic grid topologies, 2) assuming unrealistic capabilities for attackers, 3) exploring too few grid scenarios, 4) using incomplete simulators that omit relevant grid processes, and 5) using simulators that incorrectly model key grid processes. To check these hypotheses, we create a modeling framework and examine how these factors change our understanding of the feasibility and impact of grid threats. We use four diverse grid threats as case studies: MadIoT, False Data Injection Attacks, Substation Circuit Breaker Takeover, and Power Plant Takeover. We find that each of our hypothe-sized causes of modeling inconsistencies has a significant effect on modeling the outcomes of attacks. For example, we find that MadIoT attacks are much less feasible and require significantly more high-wattage IoT devices on realistic topologies than on topologies previously used to model them. In contrast, we find that Substation Circuit Breaker Takeover attacks are much more feasible in emergency scenarios and may require significantly fewer substations for failure than previous modeling suggested. We conclude with actionable recommendations for accurately assessing the impact of threats against the grid.
Brian Singer, Amritanshu Pandey, Shimiao Li, Lujo Bauer, Craig Miller, Lawrence T. Pileggi, Vyas Sekar
SP7
2022 RareGAN: Generating Samples for Rare Classes
abstract
We study the problem of learning generative adversarial networks (GANs) for a rare class of an unlabeled dataset subject to a labeling budget. This problem is motivated from practical applications in domains including security (e.g., synthesizing packets for DNS amplification attacks), systems and networking (e.g., synthesizing workloads that trigger high resource usage), and machine learning (e.g., generating images from a rare class). Existing approaches are unsuitable, either requiring fully-labeled datasets or sacrificing the fidelity of the rare class for that of the common classes. We propose RareGAN, a novel synthesis of three key ideas: (1) extending conditional GANs to use labelled and unlabelled data for better generalization; (2) an active learning approach that requests the most useful labels; and (3) a weighted loss function to favor learning the rare class. We show that RareGAN achieves a better fidelity-diversity tradeoff on the rare class than prior work across different applications, budgets, rare class fractions, GAN losses, and architectures.
Zinan Lin 0001, Giulia Fanti, Vyas Sekar
AAAI4
2022 Lumen: a framework for developing and evaluating ML-based IoT network anomaly detection
abstract
The rise of IoT devices brings a lot of security risks. To mitigate them, researchers have introduced various promising network-based anomaly detection algorithms, which oftentimes leverage machine learning. Unfortunately, though, their deployment and further improvement by network operators and the research community are hampered. We believe this is due to three key reasons. First, known ML-based anomaly detection algorithms are evaluated -in the best case- on a couple of publicly available datasets, making it hard to compare across algorithms. Second, each ML-based IoT anomaly-detection algorithm makes assumptions about attacker practices/classification granularity, which reduce their applicability. Finally, the implementation of those algorithms is often monolithic, prohibiting code reuse. To ease deployment and promote research in this area, we present Lumen. Lumen is a modular framework paired with a benchmarking suite that allows users to efficiently develop, evaluate, and compare IoT ML-based anomaly detection algorithms. We demonstrate the utility of Lumen by implementing state-of-the-art anomaly detection algorithms and faithfully evaluating them on various datasets. Among other interesting insights that could inform real-world deployments and future research, using Lumen, we were able to identify what algorithms are most suitable to detect particular types of attacks. Lumen can also be used to construct new algorithms with better performance by combining the building blocks of competing efforts and improving the training setup.
Rahul Anand Sharma, Ishan Sabane, Maria Apostolaki, Anthony Rowe 0001, Vyas Sekar
CoNEXT5
2022 Rethinking data-driven networking with foundation models: challenges and opportunities
abstract
Foundational models have caused a paradigm shift in the way artificial intelligence (AI) systems are built. They have had a major impact in natural language processing (NLP), and several other domains, not only reducing the amount of required labeled data or even eliminating the need for it, but also significantly improving performance on a wide range of tasks. We argue foundation models can have a similar profound impact on network traffic analysis, and management. More specifically, we show that network data shares several of the properties that are behind the success of foundational models in linguistics. For example, network data contains rich semantic content, and several of the networking tasks (e.g., traffic classification, generation of protocol implementations from specification text, anomaly detection) can find similar counterparts in NLP (e.g., sentiment analysis, translation from natural language to code, out-of-distribution). However, network settings also present unique characteristics and challenges that must be overcome. Our contribution is in highlighting the opportunities and challenges at the intersection of foundation models and networking.
Franck Le, Mudhakar Srivatsa, Raghu K. Ganti, Vyas Sekar
HotNets4
2022 SketchLib: Enabling Efficient Sketch-based Monitoring on Programmable Switches
Hun Namkung, Zaoxing Liu, Daehyeok Kim, Vyas Sekar, Peter Steenkiste
NSDI4
2022 Breaking Edge Shackles: Infrastructure-Free Collaborative Mobile Augmented Reality
abstract
Collaborative AR applications are gaining popularity, but have heavy computing requirements for identifying and tracking AR devices and objects in the ecosystem. Prior AR frameworks typically rely on edge infrastructure to offload AR's compute-heavy tasks. However, such infrastructure may not always be available, and continuously running AR computations on user devices can rapidly drain battery and impact application longevity. In this work, we enable infrastructure-free mobile AR with a low energy footprint, by using collaborative time slicing to distribute compute-heavy AR tasks across user devices. Realizing this idea is challenging because distributed execution can result in inconsistent synchronization of the AR virtual overlays. Our framework, FreeAR, tackles this with novel lightweight techniques for tightly synchronized virtual overlay placements across user views, and low latency recovery upon disruptions. We prototype FreeAR on Android and show that it can improve the virtual overlay positioning accuracy (with respect to the IOU metric) by up to 78%, relative to state-of-the-art collaborative AR systems, while also reducing power by up to 60% relative to a direct application of those prior solutions.
Kittipat Apicharttrisorn, Jiasi Chen, Vyas Sekar, Anthony Rowe 0001, Srikanth V. Krishnamurthy
SenSys3
2022 Practical GAN-based synthetic IP header trace generation using NetShare
abstract
We explore the feasibility of using Generative Adversarial Networks (GANs) to automatically learn generative models to generate synthetic packet- and flow header traces for networking tasks (e.g., telemetry, anomaly detection, provisioning). We identify key fidelity, scalability, and privacy challenges and tradeoffs in existing GAN-based approaches. By synthesizing domain-specific insights with recent advances in machine learning and privacy, we identify design choices to tackle these challenges. Building on these insights, we develop an end-to-end framework, NetShare. We evaluate NetShare on six diverse packet header traces and find that: (1) across all distributional metrics and traces, it achieves 46% more accuracy than baselines and (2) it meets users' requirements of downstream tasks in evaluating accuracy and rank ordering of candidate approaches.
Yucheng Yin, Zinan Lin 0001, Minhao Jin, Giulia Fanti, Vyas Sekar
SIGCOMM5
2022 Lumos: Identifying and Localizing Diverse Hidden IoT Devices in an Unfamiliar Environment
Rahul Anand Sharma, Elahe Soltanaghai, Anthony Rowe 0001, Vyas Sekar
USENIX Security Symposium4
2022 On the Security of Thread Networks: Experimentation with OpenThread-Enabled Devices
abstract
The Thread networking protocol is expected to be utilized by a plethora of smart home devices as one of the IP-based networking technologies that will be supported by the Matter standard that is being developed by members of the Connectivity Standards Alliance. Thread has been developed by the Thread Group as an application-agnostic protocol that builds on top of the IEEE 802.15.4 standard to enable IPv6-based low-power wireless mesh networking. However, unlike other IEEE 802.15.4-based protocols like Zigbee, the security of Thread networks has been relatively less analyzed in the literature. Given that commercial Thread devices are expected to interact with the physical world, vulnerabilities in their communication protocols could impact the physical security of end users. In this work we analyze the security of Thread networks by repurposing hardware and software tools that have been used for the security analysis of Zigbee networks. We used development boards that were flashed with OpenThread binaries to gain insight into the nature of Thread traffic and to study their susceptibility to a set of energy depletion attacks and online password guessing attacks. Lastly, we are publicly releasing our software enhancements as well as our dataset of captured Thread packets.
Dimitrios-Georgios Akestoridis, Vyas Sekar, Patrick Tague
WISEC2
2022 Enabling Efficient and General Subpopulation Analytics in Multidimensional Data Streams
abstract
Today's large-scale services ( e.g. , video streaming platforms, data centers, sensor grids) need diverse real-time summary statistics across multiple subpopulations of multidimensional datasets. However, state-of-the-art frameworks do not offer general and accurate analytics in real time at reasonable costs. The root cause is the combinatorial explosion of data subpopulations and the diversity of summary statistics we need to monitor simultaneously. We present Hydra, an efficient framework for multidimensional analytics that presents a novel combination of using a "sketch of sketches" to avoid the overhead of monitoring exponentially-many subpopulations and universal sketching to ensure accurate estimates for multiple statistics. We build Hydra as an Apache Spark plugin and address practical system challenges to minimize overheads at scale. Across multiple real-world and synthetic multidimensional datasets, we show that Hydra can achieve robust error bounds and is an order of magnitude more efficient in terms of operational cost and memory footprint than existing frameworks (e.g., Spark, Druid) while ensuring interactive estimation times.
Antonis Manousis, Ran Ben-Basat, Zaoxing Liu, Vyas Sekar
Proc. VLDB Endow.5
2021 On the Privacy Properties of GAN-generated Samples
abstract
The privacy implications of generative adversarial networks (GANs) are a topic of great interest, leading to several recent algorithms for training GANs with privacy guarantees. By drawing connections to the generalization properties of GANs, we prove that under some assumptions, GAN-generated samples inherently satisfy some (weak) privacy guarantees. First, we show that if a GAN is trained on m samples and used to generate n samples, the generated samples are (epsilon, delta)-differentially-private for (epsilon, delta) pairs where delta scales as O(n/m). We show that under some special conditions, this upper bound is tight. Next, we study the robustness of GAN-generated samples to membership inference attacks. We model membership inference as a hypothesis test in which the adversary must determine whether a given sample was drawn from the training dataset or from the underlying data distribution. We show that this adversary can achieve an area under the ROC curve that scales no better than O(m^{-1/4}).
Zinan Lin 0001, Vyas Sekar, Giulia Fanti
AISTATS2
2021 Watching the watchmen: Least privilege for managed network services
abstract
Many enterprises outsource network management (e.g., troubleshooting failures, monitoring performance) to third-party managed service providers (MSPs) to reduce cost. Unfortunately, recent incidents show that MSPs themselves have become an attractive launchpad to gain access to customer networks. In this work, we argue that such incidents arise due to a violation of the least privilege principle. We revisit the MSP outsourcing problem through this least-privilege view, identify key challenges in realizing this framework, and present initial ideas toward this goal. In particular, we propose providing the MSP provider an isolated "digital twin" environment to resolve problems and prevent providers from directly accessing the customer production network. Changes are verified before importing them into the production network, ensuring there are no privilege violations. Our preliminary experiments show that our approach can resolve practical problems (e.g., misconfigurations) and is effective in reducing the attack surfaces for MSP customers.
Guyue Liu, Ao Li 0009, Christopher Canel, Vyas Sekar
HotNets4
2021 Pareto GAN: Extending the Representational Power of GANs to Heavy-Tailed Distributions
abstract
Generative adversarial networks (GANs) are often billed as "universal distribution learners", but precisely what distributions they can represent and learn is still an open question. Heavy-tailed distributions are prevalent in many different domains such as financial risk-assessment, physics, and epidemiology. We observe that existing GAN architectures do a poor job of matching the asymptotic behavior of heavy-tailed distributions, a problem that we show stems from their construction. Additionally, common loss functions produce unstable or near-zero gradients when faced with the infinite moments and large distances between outlier points characteristic of heavy-tailed distributions. We address these problems with the Pareto GAN. A Pareto GAN leverages extreme value theory and the functional properties of neural networks to learn a distribution that matches the asymptotic behavior of the marginal distributions of the features. We identify issues with standard loss functions and propose the use of alternative metric spaces that enable stable and efficient learning. Finally, we evaluate our proposed approach on a variety of heavy-tailed datasets.
Todd Huster, Jeremy E. J. Cohen, Zinan Lin 0001, Kevin S. Chan, Charles A. Kamhoua, Nandi Leslie, C. Jason Chiang, Vyas Sekar
ICML8
2021 The shape of view: an alert system for video viewership anomalies
abstract
Internet video providers rely on alerting workflows to identify and remedy incidents that can impact users (e.g., outages or buggy players). There is growing evidence for the need for viewership-based analytics---detecting and diagnosing incidents that manifest through changes in viewership patterns but not in other (e.g., QoE) metrics. However, both detection and diagnosis of viewership anomalies is challenging due to the contextual nature of anomalies, non-stationarity of viewership, and complex dependencies between the structure of events and how they impact different subpopulations of viewers. We present Proteas, an alerting framework for video viewership anomalies that tackles these challenges. Proteas builds on key spatiotemporal structural insights. First, across different sub-populations of viewers and days of the week, we find that the shape of the viewership curve remains invariant over multiple weeks, thus enabling anomaly detection. Second, we use the hierarchy of viewership groups to produce compact alerts. Finally, we find that common anomalies manifest with spatiotemporal signatures, which enables us to classify anomalies to produce actionable alerts. We evaluate Proteas using 3 months of real viewership data (including the onset of the COVID-19 pandemic) and show that Proteas is accurate with over 80% True Positive Rate, average precision of over 86% (i.e., few false positives) and doesn't miss any major events. In addition, we find that approximately half of Proteas's alerts refer to events not caught by other alerting workflows, thus adding value to operators' existing toolkit.
Antonis Manousis, Harshil Shah, Henry Milner, Hui Zhang 0001, Vyas Sekar
Internet Measurement Conference6
2021 Revisiting TCP congestion control throughput models & fairness properties at scale
abstract
Much of our understanding of congestion control algorithm (CCA) throughput and fairness is derived from models and measurements that (implicitly) assume congestion occurs in the last mile. That is, these studies evaluated CCAs in "small scale" edge settings at the scale of tens of flows and up to a few hundred Mbps bandwidths. However, recent measurements show that congestion can also occur at the core of the Internet on inter-provider links, where thousands of flows share high bandwidth links. Hence, a natural question is: Does our understanding of CCA throughput and fairness continue to hold at the scale found in the core of the Internet, with 1000s of flows and Gbps bandwidths?
Adithya Abraham Philip, Ranysha Ware, Rukshani Athapathu, Justine Sherry, Vyas Sekar
Internet Measurement Conference5
2021 Sketchy With a Chance of Adoption: Can Sketch-Based Telemetry Be Ready for Prime Time?
abstract
Sketching algorithms or sketches have emerged as a promising alternative to the traditional packet sampling-based network telemetry solutions. At a high level, they are attractive because of their high resource efficiency and provable accuracy guarantees. While there have been significant recent advances in various aspects of sketching for networking tasks, many fundamental challenges remain unsolved that are likely stumbling blocks for adoption. Our contribution in this paper is in identifying and formulating these research challenges across the ecosystem encompassing network operators, platform vendors/developers, and algorithm designers. We hope that these serve as a necessary fillip for the community to enable the broader adoption of sketch-based telemetry.
Zaoxing Liu, Hun Namkung, Anup Agarwal, Antonis Manousis, Peter Steenkiste, Srinivasan Seshan, Vyas Sekar
NetSoft7
2021 Why Spectral Normalization Stabilizes GANs: Analysis and Improvements
abstract
Spectral normalization (SN) is a widely-used technique for improving the stability and sample quality of Generative Adversarial Networks (GANs). However, current understanding of SN's efficacy is limited. In this work, we show that SN controls two important failure modes of GAN training: exploding and vanishing gradients. Our proofs illustrate a (perhaps unintentional) connection with the successful LeCun initialization. This connection helps to explain why the most popular implementation of SN for GANs requires no hyper-parameter tuning, whereas stricter implementations of SN have poor empirical performance out-of-the-box. Unlike LeCun initialization which only controls gradient vanishing at the beginning of training, SN preserves this property throughout training. Building on this theoretical understanding, we propose a new spectral normalization technique: Bidirectional Scaled Spectral Normalization (BSSN), which incorporates insights from later improvements to LeCun initialization: Xavier initialization and Kaiming initialization. Theoretically, we show that BSSN gives better gradient control than SN. Empirically, we demonstrate that it outperforms SN in sample quality and training stability on several benchmark datasets.
Zinan Lin 0001, Vyas Sekar, Giulia Fanti
NeurIPS2
2021 Don't Yank My Chain: Auditable NF Service Chaining
Guyue Liu, Hugo Sadok, Anne Kohlbrenner, Bryan Parno, Vyas Sekar, Justine Sherry
NSDI5
2021 Formalizing an Architectural Model of a Trustworthy Edge IoT Security Gateway‡
abstract
Today’s edge networks continue to see an increasing number of deployed IoT devices. These IoT devices aim to increase productivity and efficiency; however, they are plagued by a myriad of vulnerabilities. Industry and academia have proposed protecting these devices by deploying a “bolt-on” security gateway to these edge networks. The gateway applies security protections at the network level. While security gateways are an attractive solution, they raise a fundamental concern: Can the bolt-on security gateway be trusted? This paper identifies key challenges in realizing this goal and sketches a roadmap for providing trust in bolt-on edge IoT security gateways. Specifically, we show the promise of using a micro-hypervisor driven approach for delivering practical (deployable today) trust that is catered to both end-users and gateway vendors alike in terms of cost, generality, capabilities, and performance. We describe the challenges in establishing trust on today’s edge security gateways, formalize the adversary and trust properties, describe our system architecture, encode and prove our architecture trust properties using the Alloy formal modeling language. We foresee our trustworthy security gateway architecture becoming a practical and extensible formal foundation towards realizing robust trust properties on today’s edge security gateway implementations.
Matt McCormack, Amit Vasudevan, Guyue Liu, Vyas Sekar
RTCSA4
2021 RedPlane: enabling fault-tolerant stateful in-switch applications
abstract
Many recent efforts have demonstrated the performance benefits of running datacenter functions (\emph{e.g.,} NATs, load balancers, monitoring) on programmable switches. However, a key missing piece remains: fault tolerance. This is especially critical as the network is no longer stateless and pure endpoint recovery does not suffice. In this paper, we design and implement RedPlane, a fault-tolerant state store for stateful in-switch applications. This provides in-switch applications consistent access to their state, even if the switch they run on fails or traffic is rerouted to an alternative switch. We address key challenges in devising a practical, provably correct replication protocol and implementing it in the switch data plane. Our evaluations show that RedPlane incurs negligible overhead and enables end-to-end applications to rapidly recover from switch failures.
Daehyeok Kim, Jacob Nelson 0001, Dan R. K. Ports, Vyas Sekar, Srinivasan Seshan
SIGCOMM4
2021 CANNON: Reliable and Stealthy Remote Shutdown Attacks via Unaltered Automotive Microcontrollers
abstract
Electronic Control Units (ECUs) in modern vehicles have recently been targets for shutdown attacks, which can disable safety-critical vehicle functions and be used as means to launch more dangerous attacks. Existing attacks operate either by physical manipulation of the bus signals or message injection. However, we argue that these cannot simultaneously be remote, stealthy, and reliable. For instance, message injection is detected by modern Intrusion Detection System (IDS) proposals and requires strict synchronization that cannot be realized remotely. In this work, we introduce a new class of attacks that leverage the peripheral clock gating feature in modern automotive microcontroller units (MCUs). By using this capability, a remote adversary with purely software control can reliably "freeze" the output of a compromised ECU to insert arbitrary bits at any time instance. Utilizing on this insight, we develop the CANnon attack for remote shutdown. Since the CANnon attack produces error patterns indistinguishable from natural errors and does not require message insertion, detecting it with current techniques is difficult. We demonstrate this attack on two automotive MCUs used in modern passenger vehicle ECUs. We discuss potential mitigation strategies and countermeasures for such attacks.
Sekar Kulandaivel, Shalabh Jain, Jorge Guajardo, Vyas Sekar
SP4
2021 Jaqen: A High-Performance Switch-Native Approach for Detecting and Mitigating Volumetric DDoS Attacks with Programmable Switches
Zaoxing Liu, Hun Namkung, Georgios Nikolaidis, Jeongkeun Lee, Changhoon Kim, Xin Jin 0008, Vladimir Braverman, Minlan Yu, Vyas Sekar
USENIX Security Symposium9
2021 Accurately Measuring Global Risk of Amplification Attacks using AmpMap
Soo-Jin Moon, Yucheng Yin, Rahul Anand Sharma, Jonathan M. Spring, Vyas Sekar
USENIX Security Symposium6
2020 Using GANs for Sharing Networked Time Series Data: Challenges, Initial Promise, and Open Questions
abstract
Limited data access is a longstanding barrier to data-driven research and development in the networked systems community. In this work, we explore if and how generative adversarial networks (GANs) can be used to incentivize data sharing by enabling a generic framework for sharing synthetic datasets with minimal expert knowledge. As a specific target, our focus in this paper is on time series datasets with metadata (e.g., packet loss rate measurements with corresponding ISPs). We identify key challenges of existing GAN approaches for such workloads with respect to fidelity (e.g., long-term dependencies, complex multidimensional relationships, mode collapse) and privacy (i.e., existing guarantees are poorly understood and can sacrifice fidelity). To improve fidelity, we design a custom workflow called DoppelGANger (DG) and demonstrate that across diverse real-world datasets (e.g., bandwidth measurements, cluster requests, web sessions) and use cases (e.g., structural characterization, predictive modeling, algorithm comparison), DG achieves up to 43% better fidelity than baseline models. Although we do not resolve the privacy problem in this work, we identify fundamental challenges with both classical notions of privacy and recent advances to improve the privacy properties of GANs, and suggest a potential roadmap for addressing these challenges. By shedding light on the promise and challenges, we hope our work can rekindle the conversation on workflows for data sharing.
Zinan Lin 0001, Alankar Jain, Chen Wang 0039, Giulia Fanti, Vyas Sekar
Internet Measurement Conference5
2020 Analyzing Third Party Service Dependencies in Modern Web Services: Have We Learned from the Mirai-Dyn Incident?
abstract
Many websites rely on third parties for services (e.g., DNS, CDN, etc.). However, it also exposes them to shared risks from attacks (e.g., Mirai DDoS attack [24]) or cascading failures (e.g., GlobalSign revocation error [21]). Motivated by such incidents, we analyze the prevalence and impact of third-party dependencies, focusing on three critical infrastructure services: DNS, CDN, and certificate revocation checking by CA. We analyze both direct (e.g., Twitter uses Dyn) and indirect (e.g., Netflix uses Symantec as CA which uses Verisign for DNS) dependencies. We also take two snapshots in 2016 and 2020 to understand how the dependencies evolved. Our key findings are: (1) 89% of the Alexa top-100K websites critically depend on third-party DNS, CDN, or CA providers i.e., if these providers go down, these websites could suffer service disruption; (2) the use of third-party services is concentrated, and the top-3 providers of CDN, DNS, or CA services can affect 50%-70% of the top-100K websites; (3) indirect dependencies amplify the impact of popular CDN and DNS providers by up to 25X; and (4) some third-party dependencies and concentration increased marginally between 2016 to 2020. Based on our findings, we derive key implications for different stakeholders in the web ecosystem.
Aqsa Kashaf, Vyas Sekar, Yuvraj Agarwal
Internet Measurement Conference2
2020 All that GLITTERs: Low-Power Spoof-Resilient Optical Markers for Augmented Reality
abstract
One of the major challenges faced by Augmented Reality (AR) systems is linking virtual content accurately on physical objects and locations. This problem is amplified for applications like mobile payment, device control or secure pairing that requires authentication. In this paper, we present an active LED tag system called GLITTER that uses a combination of Bluetooth Low-Energy (BLE) and modulated LEDs to anchor AR content with no a priori training or labeling of an environment. Unlike traditional optical markers that encode data spatially, each active optical marker encodes a tag’s identifier by blinking over time, improving both the tag density and range compared to AR tags and QR codes.We show that with a low-power BLE-enabled micro-controller and a single 5 mm LED, we are able to accurately link AR content from potentially hundreds of tags simultaneously on a standard mobile phone from as far as 30 meters. Expanding upon this, using active optical markers as a primitive, we show how a constellation of active optical markers can be used for full 3D pose estimation, which is required for many AR applications, using either a single LED on a planar surface or two or more arbitrarily positioned LEDs. Our design supports 108 unique codes in a single field of view with a detection latency of less than 400 ms even when held by hand.
Rahul Anand Sharma, Adwait Dongare, John Miller 0002, Nicholas Wilkerson, Vyas Sekar, Prabal Dutta, Anthony Rowe 0001
IPSN6
2020 Joltik: enabling energy-efficient "future-proof" analytics on low-power wide-area networks
abstract
Wireless sensors have enabled a number of key applications. Due to their energy constraints, wireless sensors today communicate occasional short samples or pre-determined summary statistics of the data they collect. This means that computing every additional statistic at high fidelity incurs additional communication and energy overhead. This paper presents Joltik, a framework enabling general, future-proof, and energy-efficient analytics for low power wireless sensors. Joltik is general in that it summarizes sensed data from low-power devices without making assumptions on which specific statistical metric(s) are desired at the cloud and is future-proof, meaning it supports new, unforeseen metrics. Joltik is built upon recent theoretical advances in universal sketching, which can enable a Joltik sensor node to report a compact summary of observed data to enable a large class of statistical summaries. We address key system design and implementation challenges with respect to communication, memory, and computation bottlenecks that arise in practically realizing the potential benefits of universal sketching in the low-power regime. We present a proof-of-concept testbed evaluation of Joltik in LoRaWAN NUCLEO-L476RG boards and sensors. Across a range of realistic datasets, Joltik provides up to a 24.6× reduction in energy cost compared to transmitting raw data and outperforms many natural alternatives (e.g., sub-sampling, custom sketches, compressed sensing, and lossy compression) in terms of energy-accuracy trade-offs.
Mingran Yang, Junbo Zhang 0001, Akshay Gadre, Zaoxing Liu, Swarun Kumar, Vyas Sekar
MobiCom6
2020 NetSMC: A Custom Symbolic Model Checker for Stateful Network Verification
Soo-Jin Moon, Sahil Uppal, Limin Jia 0001, Vyas Sekar
NSDI5
2020 Achieving 100Gbps Intrusion Prevention on a Single Server
Hugo Sadok, Nirav Atre, James C. Hoe, Vyas Sekar, Justine Sherry
OSDI5
2020 TEA: Enabling State-Intensive Network Functions on Programmable Switches
abstract
Programmable switches have been touted as an attractive alternative for deploying network functions (NFs) such as network address translators (NATs), load balancers, and firewalls. However, their limited memory capacity has been a major stumbling block that has stymied their adoption for supporting state-intensive NFs such as cloud-scale NATs and load balancers that maintain millions of flow-table entries. In this paper, we explore a new approach that leverages DRAM on servers available in typical NFV clusters. Our new system architecture, called TEA (Table Extension Architecture), provides a virtual table abstraction that allows NFs on programmable switches to look up large virtual tables built on external DRAM. Our approach enables switch ASICs to access external DRAM purely in the data plane without involving CPUs on servers. We address key design and implementation challenges in realizing this idea. We demonstrate its feasibility and practicality with our implementation on a Tofino-based programmable switch. Our evaluation shows that NFs built with TEA can look up table entries on external DRAM with low and predictable latency (1.8-2.2 μs) and the lookup throughput can be linearly scaled with additional servers (138 million lookups per seconds with 8 servers).
Daehyeok Kim, Zaoxing Liu, Yibo Zhu 0001, Changhoon Kim, Jeongkeun Lee, Vyas Sekar, Srinivasan Seshan
SIGCOMM6
2020 Contention-Aware Performance Prediction For Virtualized Network Functions
abstract
At the core of Network Functions Virtualization lie Network Functions (NFs) that run co-resident on the same server, contend over its hardware resources and, thus, might suffer from reduced performance relative to running alone on the same hardware. Therefore, to efficiently manage resources and meet performance SLAs, NFV orchestrators need mechanisms to predict contention-induced performance degradation. In this work, we find that prior performance prediction frameworks suffer from poor accuracy on modern architectures and NFs because they treat memory as a monolithic whole. In addition, we show that, in practice, there exist multiple components of the memory subsystem that can separately induce contention. By precisely characterizing (1) the pressure each NF applies on the server's shared hardware resources (contentiousness) and (2) how susceptible each NF is to performance drop due to competing contentiousness (sensitivity), we develop SLOMO, a multivariable performance prediction framework for Network Functions. We show that relative to prior work SLOMO reduces prediction error by 2-5x and enables 6-14% more efficient cluster utilization. SLOMO's codebase can be found at https://github.com/cmu-snap/SLOMO.
Antonis Manousis, Rahul Anand Sharma, Vyas Sekar, Justine Sherry
SIGCOMM3
2019 Towards Oblivious Network Analysis using Generative Adversarial Networks
abstract
Modern systems across diverse application domains (e.g., IoT, automotive) have many black-box devices whose internal structures and/or protocol formats are unknown. We currently lack the tools to systematically understand the behavior and learn the security weaknesses of these black-box devices. Such tools could enable many use cases, such as: 1) identifying input packets that lead to network attacks; and 2) inferring the format of unknown protocols. Our goal is to enable oblivious network analysis which can perform the aforementioned tasks for black-box devices. In this work, we explore the use of a recent machine learning tool called generative adversarial networks (GANs) [16] to enable this vision. Unlike other competing approaches, GANs can work in a truly black-box setting and can infer complex dependencies between protocol fields with little to no supervision. We leverage GANs to show the preliminary use cases of our approaches using two case studies: 1) generating synthetic protocol messages given only samples of messages; and 2) generating attack inputs for a black-box system. While there are still many open challenges, our results suggest the early promise of GANs to enable "oblivious" analysis of networked elements.
Zinan Lin 0001, Soo-Jin Moon, Carolina Zarate, Ritika Mulagalapalli, Sekar Kulandaivel, Giulia Fanti, Vyas Sekar
HotNets7
2019 Practical Verifiable In-network Filtering for DDoS Defense
abstract
In light of ever-increasing scale and sophistication of modern distributed denial-of-service (DDoS) attacks, recent proposals show that in-network filtering of DDoS traffic at a handful of transit networks can handle volumetric attacks effectively. In this paper, we identify a subtle but important security risk in existing in-network filtering proposals. That is, a transit network may use the in-network filtering services as an excuse for any arbitrary packet drops made for its own benefit. For example, a malicious transit network may execute any filtering rules to discriminate against some of its neighboring networks based on its business preference while claiming that it is for the purpose of DDoS defense. We argue that this is due to the lack of verifiable filtering-i.e., no single party can check if a transit network executes the filter rules correctly as requested by the DDoS victims. To make in-network filtering a more robust defense primitive, we propose a verifiable in-network filtering system, called VIF, that exploits emerging hardware-based trusted execution environments (TEEs) and offers filtering verifiability to DDoS victims and neighboring networks. Our proof of concept demonstrates that a VIF filter implementation on commodity servers with TEE support can handle traffic at line rate (e.g., 10 Gb/s) and execute up to 3,000 filter rules. We show that VIF can scale to handle larger traffic volume (e.g., 500 Gb/s) and more complex filtering operations (e.g., 150,000 filter rules) by parallelizing the TEE-based filters. As a practical deployment model, we suggest that Internet exchange points (IXPs) are the good candidates to be early adopters of our verifiable filters due to their central locations and flexible software-defined architecture. Our large-scale simulations of two realistic attacks (i.e., DNS amplification, Mirai-based flooding) show that adopting VIF filtering service at only a small number (e.g., 5-25) of large IXPs is sufficient to handle the majority (e.g., up to 80-90%) of DDoS traffic.
Deli Gong, Muoi Tran, Shweta Shinde, Vyas Sekar, Prateek Saxena, Min Suk Kang
ICDCS5
2019 FreeFlow: Software-based Virtual RDMA Networking for Containerized Clouds
Daehyeok Kim, Tianlong Yu, Hongqiang Harry Liu, Yibo Zhu 0001, Jitendra Padhye, Shachar Raindel, Chuanxiong Guo, Vyas Sekar, Srinivasan Seshan
NSDI8
2019 Alembic: Automated Model Inference for Stateful Network Functions
Soo-Jin Moon, Jeffrey Helt, Yves Bieri, Sujata Banerjee, Vyas Sekar, Wenfei Wu, Mihalis Yannakakis, Ying Zhang 0022
NSDI6
2019 Nitrosketch: robust and general sketch-based monitoring in software switches
abstract
Software switches are emerging as a vital measurement vantage point in many networked systems. Sketching algorithms or sketches, provide high-fidelity approximate measurements, and appear as a promising alternative to traditional approaches such as packet sampling. However, sketches incur significant computation overhead in software switches. Existing efforts in implementing sketches in virtual switches make sacrifices on one or more of the following dimensions: performance (handling 40 Gbps line-rate packet throughput with low CPU footprint), robustness (accuracy guarantees across diverse workloads), and generality (supporting various measurement tasks).
Zaoxing Liu, Ran Ben-Basat, Gil Einziger, Yaron Kassner, Vladimir Braverman, Roy Friedman 0001, Vyas Sekar
SIGCOMM7
2019 CANvas: Fast and Inexpensive Automotive Network Mapping
Sekar Kulandaivel, Tushar Goyal, Arnav Kumar Agrawal, Vyas Sekar
USENIX Security Symposium4
2018 Intent-driven composition of resource-management SDN applications
abstract
As software-defined networking deployments mature, operators need to manage and compose multiple resource-management applications, such as traffic engineering and service chaining. Today such applications' resource management algorithms run separately and composition approaches are output-driven, e.g., running each application on a statically provisioned slice of the network and then combining the flow rules output for each slice. Such approaches result in inefficient resource utilization and unfairness. Instead, we argue for intent-driven composition, where a unified resource optimization formulation is composed from applications' high-level intents and the solution to this problem formulation is realized in the network. We design Chopin1, an intent-driven framework for composing SDN resource-management applications. Chopin's design addresses key robustness challenges with regard to efficiency and fairness that arise in realizing such an intent-driven approach. We have integrated Chopin with the ONOS controller and show that it substantially improves efficiency and fairness over existing composition approaches.
Victor Heorhiadi, Sanjay Chandrasekaran, Michael K. Reiter, Vyas Sekar
CoNEXT4
2018 How to Catch when Proxies Lie: Verifying the Physical Locations of Network Proxies with Active Geolocation
Zachary Weinberg, Shinyoung Cho, Nicolas Christin, Vyas Sekar, Phillipa Gill
Internet Measurement Conference4
2018 Efficient and Correct Test Scheduling for Ensembles of Network Policies
Sanjay Chandrasekaran, Limin Jia 0001, Vyas Sekar
NSDI4
2018 Rethinking Virtual Network Embedding in Reconfigurable Networks
abstract
The virtual network embedding (VNE) problem of mapping virtual network (VN) requests to a substrate network is a key component of network virtualization in datacenters. In a bid to improve datacenter network's performance and cost, there has been recent interest in "reconfigurable" network architectures, wherein the network topology can be changed at runtime to better handle current traffic patterns. Such reconfigurable networks seem naturally well-suited for efficient network virtualization- as networks can be "tailored" to accommodate the incoming VN requests. Motivated by the above, in this paper, we address the problem of virtual network embedding in reconfigurable networks; to the best of our knowledge, this has not been addressed before. In particular, we address the VNE problem in reconfigurable networks under two different models of VN link demands: fixed-bandwidth and stochastic-bandwidth demands. The former is the traditional model, while we propose the the latter to improve network utilization and leverage the runtime reconfiguration capability of reconfigurable networks. For the stochastic demand model, we employ a novel concept of embedding with "runtime-binding", wherein the embedding of a VN link is "configured" at runtime (via network reconfiguration) depending on the prevailing network state and traffic. We evaluate the efficiency of our proposed models and techniques via simulation using real VN requests and traffic statistics from large datacenters, and show that our proposed models and techniques offer significant performance advantages (up to 30-40%) over traditional models.
Max Curran, Md. Shaifur Rahman, Himanshu Gupta 0001, Vyas Sekar
SECON4
2018 Hyperloop: group-based NIC-offloading to accelerate replicated transactions in multi-tenant storage systems
abstract
Storage systems in data centers are an important component of large-scale online services. They typically perform replicated transactional operations for high data availability and integrity. Today, however, such operations suffer from high tail latency even with recent kernel bypass and storage optimizations, and thus affect the predictability of end-to-end performance of these services. We observe that the root cause of the problem is the involvement of the CPU, a precious commodity in multi-tenant settings, in the critical path of replicated transactions. In this paper, we present HyperLoop, a new framework that removes CPU from the critical path of replicated transactions in storage systems by offloading them to commodity RDMA NICs, with non-volatile memory as the storage medium. To achieve this, we develop new and general NIC offloading primitives that can perform memory operations on all nodes in a replication group while guaranteeing ACID properties without CPU involvement. We demonstrate that popular storage applications can be easily optimized using our primitives. Our evaluation results with microbenchmarks and application benchmarks show that HyperLoop can reduce 99th percentile latency ≈ 800X with close to 0% CPU consumption on replicas.
Daehyeok Kim, Amir Saman Memaripour, Anirudh Badam, Yibo Zhu 0001, Hongqiang Harry Liu, Jitendra Padhye, Shachar Raindel, Steven Swanson, Vyas Sekar, Srinivasan Seshan
SIGCOMM9
2017 Biases in Data-Driven Networking, and What to Do About Them
abstract
Recent efforts highlight the promise of data-driven approaches to optimize network decisions. Many such efforts use trace-driven evaluation; i.e., running offline analysis on network traces to estimate the potential benefits of different policies before running them in practice. Unfortunately, such frameworks can have fundamental pitfalls (e.g., skews due to previous policies that were used in the data collection phase and insufficient data for specific subpopulations) that could lead to misleading estimates and ultimately suboptimal decisions. In this paper, we shed light on such pitfalls and identify a promising roadmap to address these pitfalls by leveraging parallels in causal inference, namely the Doubly Robust estimator.
Mihovil Bartulovic, Junchen Jiang, Sivaraman Balakrishnan, Vyas Sekar, Bruno Sinopoli
HotNets4
2017 Flow Reconnaissance via Timing Attacks on SDN Switches
abstract
When encountering a packet for which it has no matching forwarding rule, a software-defined networking (SDN) switch requests an appropriate rule from its controller; this request delays the routing of the flow until the controller responds. We show that this delay gives rise to a timing side channel in which an attacker can test for the recent occurrence of a target flow by judiciously probing the switch with forged flows and using the delays they encounter to discern whether covering rules were previously installed in the switch. We develop a Markov model of an SDN switch to permit the attacker to select the best probe (or probes) to infer whether a target flow has recently occurred. Our model captures practical challenges related to rule evictions to make room for other rules; rule timeouts due to inactivity; the presence of multiple rules that apply to overlapping sets of flows; and rule priorities. We show that our model enables detection of target flows with considerable accuracy in many cases.
Michael K. Reiter, Vyas Sekar
ICDCS3
2017 PSI: Precise Security Instrumentation for Enterprise Networks
Tianlong Yu, Seyed Kaveh Fayaz, Michael P. Collins, Vyas Sekar, Srinivasan Seshan
NDSS4
2017 Pytheas: Enabling Data-Driven Quality of Experience Optimization Using Group-Based Exploration-Exploitation
Junchen Jiang, Vyas Sekar, Hui Zhang 0001
NSDI3
2017 A High Performance Packet Core for Next Generation Cellular Networks
abstract
Cellular traffic continues to grow rapidly making the scalability of the cellular infrastructure a critical issue. However, there is mounting evidence that the current Evolved Packet Core (EPC) is ill-suited to meet these scaling demands: EPC solutions based on specialized appliances are expensive to scale and recent software EPCs perform poorly, particularly with increasing numbers of devices or signaling traffic.
Zafar Ayyub Qazi, Melvin Walls, Aurojit Panda, Vyas Sekar, Sylvia Ratnasamy, Scott Shenker
SIGCOMM4
2017 Tradeoffs Between Cost and Performance for CDN Provisioning Based on Coordinate Transformation
abstract
Today's content delivery is characterized by key trends such as converged media delivery over HTTP, increasing volumes of multimedia content delivered over IP, and elevated user expectations on quality-of-experience. In this respect, server provisioning is a critical phase of CDN management, which affects both incumbent and entrant CDN operators as well as internet service providers. However, existing tools and approaches to solve server placement problems have serious shortcomings: they offer only coarse tuning knobs and limit servers to a set of candidate sites givena priori. Our conversations with CDN operators reveal that a new provisioning mechanism is necessary to take advantage of emerging opportunities such as faster speed to roll out new locations and more access networks. In this paper, we present the design of DISC, a decision support system to help CDN operators systematically investigate different design tradeoffs and evaluate what-if scenarios. The key enabler underlying DISC is a network coordinate-based data analysis workflow that can flexibly embed different cost, performance, and workload characteristics without sacrificing the fidelity. We describe practical use cases and experiences in applying DISC to a large country-wide deployment. The results show that DISC significantly reduces average latency, deployment cost, and interdomain traffic.
Xu Zhang 0006, Shuoyao Zhao, Yan Luo 0001, Chen Tian 0001, Vyas Sekar
IEEE Trans. Multim.6
2016 CICADAS: Congesting the Internet with Coordinated and Decentralized Pulsating Attacks
abstract
This study stems from the premise that we need to break away from the "reactive" cycle of developing defenses against new DDoS attacks (e.g., amplification) by proactively investigating the potential for new types of DDoS attacks. Our specific focus is on pulsating attacks, a particularly debilitating type that has been hypothesized in the literature. In a pulsating attack, bots coordinate to generate intermittent pulses at target links to significantly reduce the throughput of TCP connections traversing the target. With pulsating attacks, attackers can cause significantly greater damage to legitimate users than traditional link flooding attacks. To date, however, pulsating attacks have been either deemed ineffective or easily defendable for two reasons: (1) they require a central coordinator and can thus be tracked; and (2) they require tight synchronization of pulses, which is difficult even in normal non-congestion scenarios. This paper argues that, in fact, the perceived drawbacks of pulsating attacks are in fact not fundamental. We develop a practical pulsating attack called CICADAS using two key ideas: using both (1) congestion as an implicit signal for decentralized implementation, and (2) a Kalman-filter-based approach to achieve tight synchronization. We validate CICADAS using simulations and wide-area experiments. We also discuss possible countermeasures against this attack.
Yu-Ming Ke, Chih-Wei Chen, Hsu-Chun Hsiao, Adrian Perrig, Vyas Sekar
AsiaCCS5
2016 Enabling Software-Defined Network Security for Next-Generation Networks
abstract
The state of network security today is quite abysmal. Security breaches and downtime of critical infrastructures continue to be the norm rather than the exception, despite the dramatic rise in spending on network security.
Vyas Sekar
CoNEXT1
2016 FreeFlow: High Performance Container Networking
abstract
With the tremendous popularity gained by container technology, many applications are being containerized: splitting into numerous containers connected by networks. However, current container networking solutions have either bad performance or poor portability, which undermines the advantages of containerization. In this paper, we propose FreeFlow, a container networking solution which achieves both high performance and good portability. FreeFlow is designed according to the observation that strict isolations are unnecessary among containers trusting each other, and it can significantly boost the communication quality of containers by compromising isolation a little bit. Specifically, we enable containers on the same physical machine to communicate via shared-memory and the ones on different physical machines communicate via high performance networking options, e.g. RDMA and DPDK. Naively wrapping up all the solutions together will result in poor potability of containers and huge complexity in application development. Instead, FreeFlow leverages a network abstraction which supports all common network APIs and a centralized network orchestrator which decides how to deliver data transparently to applications in the containers.
Tianlong Yu, Shadi A. Noghabi, Shachar Raindel, Hongqiang Harry Liu, Jitendra Padhye, Vyas Sekar
HotNets6
2016 Gremlin: Systematic Resilience Testing of Microservices
abstract
Modern Internet applications are being disaggregated into a microservice-based architecture, with services being updated and deployed hundreds of times a day. The accelerated software life cycle and heterogeneity of language runtimes in a single application necessitates a new approach for testing the resiliency of these applications in production infrastructures. We present Gremlin, a framework for systematically testing the failure-handling capabilities of microservices. Gremlin is based on the observation that microservices are loosely coupled and thus rely on standard message-exchange patterns over the network. Gremlin allows the operator to easily design tests and executes them by manipulating inter-service messages at the network layer. We show how to use Gremlin to express common failure scenarios and how developers of an enterprise application were able to discover previously unknown bugs in their failure-handling code without modifying the application.
Victor Heorhiadi, Shriram Rajagopalan, Hani Jamjoom, Michael K. Reiter, Vyas Sekar
ICDCS5
2016 SPIFFY: Inducing Cost-Detectability Tradeoffs for Persistent Link-Flooding Attacks
Min Suk Kang, Virgil D. Gligor, Vyas Sekar
NDSS3
2016 BUZZ: Testing Context-Dependent Policies in Stateful Networks
Seyed Kaveh Fayaz, Tianlong Yu, Yoshiaki Tobioka, Sagar Chaki, Vyas Sekar
NSDI5
2016 Simplifying Software-Defined Network Optimization Using SOL
Victor Heorhiadi, Michael K. Reiter, Vyas Sekar
NSDI3
2016 CFA: A Practical Prediction System for Video QoE Optimization
Junchen Jiang, Vyas Sekar, Henry Milner, Davis Shepherd, Ion Stoica, Hui Zhang 0001
NSDI2
2016 Efficient Network Reachability Analysis Using a Succinct Control Plane Representation
Seyed Kaveh Fayaz, Ari Fogel, Ratul Mahajan, Todd D. Millstein, Vyas Sekar, George Varghese
OSDI6
2016 Via: Improving Internet Telephony Call Quality Using Predictive Relay Selection
abstract
Interactive real-time streaming applications such as audio-video conferencing, online gaming and app streaming, place stringent requirements on the network in terms of delay, jitter, and packet loss. Many of these applications inherently involve client-to-client communication, which is particularly challenging since the performance requirements need to be met while traversing the public wide-area network (WAN). This is different from the typical situation of cloud-to-client communication, where the WAN can often be bypassed by moving a communication end-point to a cloud “edge”, close to the client. Can we nevertheless take advantage of cloud resources to improve the performance of real-time client-to-client streaming over the WAN?
Junchen Jiang, Rajdeep Das, Ganesh Ananthanarayanan, Philip A. Chou, Venkat N. Padmanabhan, Vyas Sekar, Esbjorn Dominique, Marcin Goliszewski, Dalibor Kukoleca, Renat Vafin, Hui Zhang 0001
SIGCOMM6
2016 One Sketch to Rule Them All: Rethinking Network Flow Monitoring with UnivMon
abstract
Network management requires accurate estimates of metrics for traffic engineering (e.g., heavy hitters), anomaly detection (e.g., entropy of source addresses), and security (e.g., DDoS detection). Obtaining accurate estimates given router CPU and memory constraints is a challenging problem. Existing approaches fall in one of two undesirable extremes: (1) low fidelity general-purpose approaches such as sampling, or (2) high fidelity but complex algorithms customized to specific application-level metrics. Ideally, a solution should be both general (i.e., supports many applications) and provide accuracy comparable to custom algorithms. This paper presents UnivMon, a framework for flow monitoring which leverages recent theoretical advances and demonstrates that it is possible to achieve both generality and high accuracy. UnivMon uses an application-agnostic data plane monitoring primitive; different (and possibly unforeseen) estimation algorithms run in the control plane, and use the statistics from the data plane to compute application-level metrics. We present a proof-of-concept implementation of UnivMon using P4 and develop simple coordination techniques to provide a ``one-big-switch'' abstraction for network-wide monitoring. We evaluate the effectiveness of UnivMon using a range of trace-driven evaluations and show that it offers comparable (and sometimes better) accuracy relative to custom sketching solutions.
Zaoxing Liu, Antonis Manousis, Gregory Vorsanger, Vyas Sekar, Vladimir Braverman
SIGCOMM4
2016 CS2P: Improving Video Bitrate Selection and Adaptation with Data-Driven Throughput Prediction
abstract
Bitrate adaptation is critical in ensuring good users’ quality-of-experience (QoE) in Internet video delivery system. Several efforts have argued that accurate throughput prediction can dramatically improve (1) initial bitrate selection for low startup delay and high initial resolution; (2) midstream bitrate adaptation for high QoE. However, prior ef- forts did not systematically quantify real-world throughput predictability or develop good prediction algorithms. To bridge this gap, this paper makes three key technical contributions: First, we analyze the throughput characteristics in a dataset with 20M+ sessions. We find: (a) Sessions sharing similar key features (e.g., ISP, region) present similar initial values and dynamical patterns; (b) There is a natural “stateful” dynamical behavior within a given session. Second, building on these insights, we develop CS2P, a better throughput prediction system. CS2P leverages data-driven approach to learn (a) clusters of similar sessions, (b) an initial throughput predictor, and (c) a Hidden-Markov-Model based midstream predictor modeling the stateful evolution of throughput. Third, we develop a prototype system and show by trace-driven simulation and real-world experiments that CS2P outperforms state-of-art by 40% and 50% median pre- diction error respectively for initial and midstream through- put and improves QoE by 14% over buffer-based adaptation algorithm.
Yi Sun 0004, Xiaoqi Yin, Junchen Jiang, Vyas Sekar, Fuyuan Lin, Nanshu Wang, Bruno Sinopoli
SIGCOMM4
2016 Enhancing Video Accessibility and Availability Using Information-Bound References
abstract
Users are often frustrated when they cannot view video links shared via blogs, social networks, and shared bookmark sites on their devices or suffer performance and usability problems when doing so. While other versions of the same content better suited to their device and network constraints may be available on other third-party hosting sites, these remain unusable because users cannot efficiently discover these and verify that these variants match the content publisher's original intent. Our vision is to enable consumers to leverage verifiable alternatives from different hosting sites that are best suited to their constraints to deliver a high quality of experience and enable content publishers to reach a wide audience with diverse operating conditions with minimal upfront costs. To this end, we make a case for information-bound references or IBRs that bind references to video content to the underlying information that a publisher wants to convey, decoupled from details such as protocols, hosts, file names, or the underlying bits. This paper addresses key challenges in the design and implementation of IBR generation and resolution mechanisms, and presents an evaluation of the benefits IBRs offer.
Ashok Anand, Athula Balachandran, Aditya Akella, Vyas Sekar, Srinivasan Seshan
IEEE/ACM Trans. Netw.4
2015 Nomad: Mitigating Arbitrary Cloud Side Channels via Provider-Assisted Migration
abstract
Recent studies have shown a range of co-residency side channels that can be used to extract private information from cloud clients. Unfortunately, addressing these side channels often requires detailed attack-specific fixes that require significant modifications to hardware, client virtual machines (VM), or hypervisors. Furthermore, these solutions cannot be generalized to future side channels. Barring extreme solutions such as single tenancy which sacrifices the multiplexing benefits of cloud computing, such side channels will continue to affect critical services. In this work, we present Nomad, a system that offers vector-agnostic defense against known and future side channels. Nomad envisions a provider-assisted VM migration service, applying the moving target defense philosophy to bound the information leakage due to side channels. In designing Nomad, we make four key contributions: (1) a formal model to capture information leakage via side channels in shared cloud deployments; (2) identifying provider-assisted VM migration as a robust defense for arbitrary side channels; (3) a scalable online VM migration heuristic that can handle large datacenter workloads; and (4) a practical implementation in OpenStack. We show that Nomad is scalable to large cloud deployments, achieves near-optimal information leakage subject to constraints on migration overhead, and imposes minimal performance degradation for typical cloud applications such as web services and Hadoop MapReduce.
Soo-Jin Moon, Vyas Sekar, Michael K. Reiter
CCS2
2015 Enabling a "RISC" Approach for Software-Defined Monitoring using Universal Streaming
abstract
Network management relies on an up-to-date and accurate view of many traffic metrics for tasks such as traffic engineering (e.g., heavy hitters), anomaly detection (e.g., entropy of source addresses), and security (e.g., DDoS detection). Obtaining an accurate estimate of these metrics while using little router CPU and memory is challenging. This in turn has inspired a large body of work in data streaming devoted to developing optimized algorithms for individual monitoring tasks, as well as recent approaches to make it simpler to implement these algorithms (e.g., OpenSketch). While this body of work has been seminal, we argue that this trajectory of crafting special purpose algorithms is untenable in the long term. We make a case for a "RISC" approach for flow monitoring analogous to a reduced instruction set in computer architecture---a simple and generic monitoring primitive from which a range of metrics can be computed with high accuracy. Building on recent theoretical advances in universal streaming, we show that this "holy grail" for flow monitoring might be well within our reach.
Zaoxing Liu, Gregory Vorsanger, Vladimir Braverman, Vyas Sekar
HotNets4
2015 Handling a trillion (unfixable) flaws on a billion devices: Rethinking network security for the Internet-of-Things
abstract
The Internet-of-Things (IoT) has quickly moved from the realm of hype to reality with estimates of over 25 billion devices deployed by 2020. While IoT has huge potential for societal impact, it comes with a number of key security challenges---IoT devices can become the entry points into critical infrastructures and can be exploited to leak sensitive information. Traditional host-centric security solutions in today's IT ecosystems (e.g., antivirus, software patches) are fundamentally at odds with the realities of IoT (e.g., poor vendor security practices and constrained hardware). We argue that the network will have to play a critical role in securing IoT deployments. However, the scale, diversity, cyberphysical coupling, and cross-device use cases inherent to IoT require us to rethink network security along three key dimensions: (1) abstractions for security policies; (2) mechanisms to learn attack and normal profiles; and (3) dynamic and context-aware enforcement capabilities. Our goal in this paper is to highlight these challenges and sketch a roadmap to avoid this impending security disaster.
Tianlong Yu, Vyas Sekar, Srinivasan Seshan, Yuvraj Agarwal, Chenren Xu
HotNets2
2015 Klotski: Reprioritizing Web Content to Improve User Experience on Mobile Devices
Michael Butkiewicz, Daimeng Wang, Zhe Wu 0003, Harsha V. Madhyastha, Vyas Sekar
NSDI5
2015 C3: Internet-Scale Control Plane for Video Quality Optimization
Aditya Ganjam, Faisal Siddiqui, Jibin Zhan, Ion Stoica, Junchen Jiang, Vyas Sekar, Hui Zhang 0001
NSDI7
2015 Internet Outages, the Eyewitness Accounts: Analysis of the Outages Mailing List
Ritwik Banerjee, Abbas Razaghpanah, Luis Chiang, Akassh Mishra, Vyas Sekar, Yejin Choi 0001, Phillipa Gill
PAM5
2015 A Control-Theoretic Approach for Dynamic Adaptive Video Streaming over HTTP
abstract
User-perceived quality-of-experience (QoE) is critical in Internet video applications as it impacts revenues for content providers and delivery systems. Given that there is little support in the network for optimizing such measures, bottlenecks could occur anywhere in the delivery system. Consequently, a robust bitrate adaptation algorithm in client-side players is critical to ensure good user experience. Previous studies have shown key limitations of state-of-art commercial solutions and proposed a range of heuristic fixes. Despite the emergence of several proposals, there is still a distinct lack of consensus on: (1) How best to design this client-side bitrate adaptation logic (e.g., use rate estimates vs. buffer occupancy); (2) How well specific classes of approaches will perform under diverse operating regimes (e.g., high throughput variability); or (3) How do they actually balance different QoE objectives (e.g., startup delay vs. rebuffering). To this end, this paper makes three key technical contributions. First, to bring some rigor to this space, we develop a principled control-theoretic model to reason about a broad spectrum of strategies. Second, we propose a novel model predictive control algorithm that can optimally combine throughput and buffer occupancy information to outperform traditional approaches. Third, we present a practical implementation in a reference video player to validate our approach using realistic trace-driven emulations.
Xiaoqi Yin, Abhishek Jindal, Vyas Sekar, Bruno Sinopoli
SIGCOMM3
2015 Bohatei: Flexible and Elastic DDoS Defense
Seyed Kaveh Fayaz, Yoshiaki Tobioka, Vyas Sekar, Michael D. Bailey
USENIX Security Symposium3
2014 Trace-Driven Analysis of ICN Caching Algorithms on Video-on-Demand Workloads
abstract
Even though a key driver for Information-Centric Networking (ICN) has been the rise in Internet video traffic, there has been surprisingly little work on analyzing the interplay between ICN and video ? which ICN caching strategies work well on video work- loads and how ICN helps improve video-centric quality of experience (QoE). In this work, we bridge this disconnect with a trace- driven study using 196M video requests from over 16M users on a country-wide topology with 80K routers. We evaluate a broad space of content replacement (e.g., LRU, LFU, FIFO) and content placement (e.g., leave a copy everywhere, probabilistic) strategies over a range of cache sizes. We highlight four key findings: (1) the best placement and re- placement strategies depend on the cache size and vary across improvement metrics; that said, LFU+probabilistic caching [37] is a close-to-optimal strategy overall; (2) video workloads show considerable caching-related benefits (e.g., -- 10% traffic reduction) only with very large cache sizes (≥ 100GB); (3) the improvement in video QoE is low (≥ 12%) if the content provider already has a substantial geographical presence; and (4) caches in the middle and the edge of the network, requests from highly populated regions and without content servers, and requests for popular content contribute most to the overall ICN-induced improvements in video QoE.
Yi Sun 0004, Seyed Kaveh Fayaz, Vyas Sekar, Yun Jin, Mohamed Ali Kâafar, Steve Uhlig
CoNEXT4
2014 EONA: Experience-Oriented Network Architecture
abstract
There is a growing recognition among researchers, industry practitioners, and service providers of the need to optimize user-perceived application experience. Network infrastructure owners (i.e., ISPs) have traditionally been left out of this equation, leading to repeated tussles between content providers and ISPs. In parallel, application providers have to deploy complex workarounds that reverse engineer the network's impact on application-level metrics. In this work, we make the case for EONA, a new network paradigm where application providers and network providers can collaborate meaningfully to improve application experience. We observe a confluence of technology trends that are enablers for EONA: the ability to collect large volumes of client-side application measurements, the emergence of novel "big data" platforms for real-time analytics, and new control plane capabilities for ISPs (e.g., SDN, IXPs, NFV). We highlight the challenges and opportunities in designing suitable EONA interfaces between infrastructure and application providers and EONA-enhanced control loops that leverage these interfaces to optimize user experience.
Junchen Jiang, Vyas Sekar, Ion Stoica, Hui Zhang 0001
HotNets3
2014 Using Video-Based Measurements to Generate a Real-Time Network Traffic Map
abstract
We envision a real-time network traffic map for the Internet, where each network link is annotated with its capacity and its current utilization, with an interface that networked applications can query to inform their control decisions. While this goal is simple to state, it has been out of our reach due to concerns over measurement overhead and coverage. Our insight is that the rise of Internet video and the availability of measurements from video players present an unprecedented opportunity to address these issues. We outline a preliminary roadmap to build on this opportunity to realize a global traffic map.
Yi Sun 0004, Junchen Jiang, Vyas Sekar, Hui Zhang 0001, Fuyuan Lin, Nanshu Wang
HotNets3
2014 Toward a Principled Framework to Design Dynamic Adaptive Streaming Algorithms over HTTP
abstract
Client-side bitrate adaptation algorithms play a critical role in delivering a good quality of experience for Internet video. Many studies have shown that current solutions perform suboptimally, and despite the proliferation of several proposals in this space, both from commercial providers and researchers, there is still a distinct lack of clarity and consensus w.r.t. several natural questions: (1) What objectives does/should such an algorithm optimize? (2) What environment signals such as buffer occupancy or throughput estimates should an algorithm use in its control loop? (3) How sensitive is an algorithm to operating conditions (e.g., bandwidth stability, buffer size, available bitrates)? This work attempts to bring clarity to this discussion by casting adaptive bitrate streaming as a model-based predictive control problem. We demonstrate the initial promise of shedding light on these questions using this control-theoretic abstraction.
Xiaoqi Yin, Vyas Sekar, Bruno Sinopoli
HotNets2
2014 A First Look at Performance in Mobile Virtual Network Operators
abstract
Recent industry trends suggest a new phenomenon in the mobile market: mobile virtual network operators or MVNOs that operate on top of existing cellular infrastructures. While MVNOs have shown significant growth in the US and elsewhere in the past two years and have been successful in attracting customers, there is anecdotal evidence that users are concerned about cellular performance when choosing MVNOs over traditional cellular operators. In this paper, we present the first systematic measurement study to shed light on this emerging phenomenon. We study the performance of 3 key applications: web access, video streaming and voice, in 2 popular MVNO families (a total of 8 carriers) in the US, where each MVNO family consists of a major base carrier and 3 MVNOs running on top of it. We observe that some MVNOs do indeed exhibit significant performance degradation and that there are key differences between the two MVNO families.
Fatima Zarinni, Ayon Chakraborty, Vyas Sekar, Samir Ranjan Das, Phillipa Gill
Internet Measurement Conference3
2014 Enforcing Network-Wide Policies in the Presence of Dynamic Middlebox Actions using FlowTags
Seyed Kaveh Fayaz, Luis Chiang, Vyas Sekar, Minlan Yu, Jeffrey C. Mogul
NSDI3
2014 FireFly: a reconfigurable wireless data center fabric using free-space optics
abstract
Conventional static datacenter (DC) network designs offer extreme cost vs. performance tradeoffs---simple leaf-spine networks are cost-effective but oversubscribed, while "fat tree"-like solutions offer good worst-case performance but are expensive. Recent results make a promising case for augmenting an oversubscribed network with reconfigurable inter-rack wireless or optical links. Inspired by the promise of reconfigurability, this paper presents FireFly, an inter-rack network solution that pushes DC network design to the extreme on three key fronts: (1) all links are reconfigurable; (2) all links are wireless; and (3) non top-of-rack switches are eliminated altogether. This vision, if realized, can offer significant benefits in terms of increased flexibility, reduced equipment cost, and minimal cabling complexity. In order to achieve this vision, we need to look beyond traditional RF wireless solutions due to their interference footprint which limits range and data rates. Thus, we make the case for using free-space optics (FSO). We demonstrate the viability of this architecture by (a) building a proof-of-concept prototype of a steerable small form factor FSO device using commodity components and (b) developing practical heuristics to address algorithmic and system-level challenges in network design and management.
Navid Hamed Azimi, Zafar Ayyub Qazi, Himanshu Gupta 0001, Vyas Sekar, Samir Ranjan Das, Jon P. Longtin, Himanshu Shah, Ashish Tanwer
SIGCOMM4
2014 Characterizing Web Page Complexity and Its Impact
abstract
Over the years, the Web has evolved from simple text content from one server to a complex ecosystem with different types of content from servers spread across several administrative domains. There is anecdotal evidence of users being frustrated with high page load times. Because page load times are known to directly impact user satisfaction, providers would like to understand if and how the complexity of their Web sites affects the user experience. While there is an extensive literature on measuring Web graphs, Web site popularity, and the nature of Web traffic, there has been little work in understanding how complex individual Web sites are, and how this complexity impacts the clients' experience. This paper is a first step to address this gap. To this end, we identify a set of metrics to characterize the complexity of Web sites both at a content level (e.g., number and size of images) and service level (e.g., number of servers/origins). We find that the distributions of these metrics are largely independent of a Web site's popularity rank. However, some categories (e.g., News) are more complex than others. More than 60% of Web sites have content from at least five non-origin sources, and these contribute more than 35% of the bytes downloaded. In addition, we analyze which metrics are most critical for predicting page render and load times and find that the number of objects requested is the most important factor. With respect to variability in load times, however, we find that the number of servers is the best indicator.
Michael Butkiewicz, Harsha V. Madhyastha, Vyas Sekar
IEEE/ACM Trans. Netw.3
2014 Improving Fairness, Efficiency, and Stability in HTTP-Based Adaptive Video Streaming With Festive
abstract
Modern video players today rely on bit-rate adaptation in order to respond to changing network conditions. Past measurement studies have identified issues with today's commercial players when multiple bit-rate-adaptive players share a bottleneck link with respect to three metrics: fairness, efficiency, and stability. Unfortunately, our current understanding of why these effects occur and how they can be mitigated is quite limited. In this paper, we present a principled understanding of bit-rate adaptation and analyze several commercial players through the lens of an abstract player model consisting of three main components: bandwidth estimation, bit-rate selection, and chunk scheduling. Using framework, we identify the root causes of several undesirable interactions that arise as a consequence of overlaying the video bit-rate adaptation over HTTP. Building on these insights, we develop a suite of techniques that can systematically guide the tradeoffs between stability, fairness, and efficiency and thus lead to a general framework for robust video adaptation. We pick one concrete instance from this design space and show that it significantly outperforms today's commercial players on all three key metrics across a range of experimental scenarios.
Junchen Jiang, Vyas Sekar, Hui Zhang 0001
IEEE/ACM Trans. Netw.2
2013 Enhancing video accessibility and availability using information-bound references
abstract
Users are often frustrated when they cannot view video links shared via blogs, social networks, and shared bookmark sites on their devices or suffer performance and usability problems when doing so. While other versions of the same content better suited to their device and network constraints may be available on other third-party hosting sites, these remain unusable because users cannot efficiently discover these and verify that these variants match the content publisher's original intent. Our vision is to enable consumers to leverage verifiable alternatives from different hosting sites that are best suited to their constraints to deliver a high quality of experience and enable content publishers to reach a wide audience with diverse operating conditions with minimal upfront costs. To this end, we make a case for information-bound references or IBRs that bind references to video content to the underlying information that a publisher wants to convey, decoupled from details such as protocols, hosts, file names, or the underlying bits. This paper addresses key challenges in the design and implementation of IBR generation and resolution mechanisms, and presents an evaluation of the benefits IBRs offer.
Ashok Anand, Athula Balachandran, Aditya Akella, Vyas Sekar, Srinivasan Seshan
CoNEXT4
2013 Shedding light on the structure of internet video quality problems in the wild
abstract
The key role that video quality plays in impacting user engagement, and consequently providers' revenues, has motivated recent efforts in improving the quality of Internet video. This includes work on adaptive bitrate selection, multi-CDN optimization, and global control plane architectures. Before we embark on deploying these designs, we need to first understand the nature of video of quality problems to see if this complexity is necessary, and if simpler approaches can yield comparable benefits.
Junchen Jiang, Vyas Sekar, Ion Stoica, Hui Zhang 0001
CoNEXT2
2013 Patch panels in the sky: a case for free-space optics in data centers
abstract
We explore the vision of an all-wireless inter-rack datacenter fabric. Such a fabric, if realized, can offer operator the ability to dynamically reconfigure the network topology to adapt to future traffic demands while eliminating concerns related to cabling complexity. A key enabler for our vision is the use of free space optical (FSO) technology which, in contrast to traditional wireless/RF technologies, has lower interference footprint, can support longer range, and offers higher bandwidths. While FSO is an enabler, there are several significant practical challenges that need to be addressed before this vision turns into reality. We demonstrate the early promise of addressing these challenges and the potential benefits that this offers in comparison to state-of-the-art datacenter architectures.
Navid Hamed Azimi, Himanshu Gupta 0001, Vyas Sekar, Samir Ranjan Das
HotNets3
2013 Analyzing the potential benefits of CDN augmentation strategies for internet video workloads
abstract
Video viewership over the Internet is rising rapidly, and market predictions suggest that video will comprise over 90\% of Internet traffic in the next few years. At the same time, there have been signs that the Content Delivery Network (CDN) infrastructure is being stressed by ever-increasing amounts of video traffic. To meet these growing demands, the CDN infrastructure must be designed, provisioned and managed appropriately. Federated telco-CDNs and hybrid P2P-CDNs are two content delivery infrastructure designs that have gained significant industry attention recently. We observed several user access patterns that have important implications to these two designs in our unique dataset consisting of 30 million video sessions spanning around two months of video viewership from two large Internet video providers. These include partial interest in content, regional interests, temporal shift in peak load and patterns in evolution of interest. We analyze the impact of our findings on these two designs by performing a large scale measurement study. Surprisingly, we find significant amount of synchronous viewing behavior for Video On Demand (VOD) content, which makes hybrid P2P-CDN approach feasible for VOD and suggest new strategies for CDNs to reduce their infrastructure costs. We also find that federation can significantly reduce telco-CDN provisioning costs by as much as 95%.
Athula Balachandran, Vyas Sekar, Aditya Akella, Srinivasan Seshan
Internet Measurement Conference2
2013 Developing a predictive model of quality of experience for internet video
abstract
Improving users' quality of experience (QoE) is crucial for sustaining the advertisement and subscription based revenue models that enable the growth of Internet video. Despite the rich literature on video and QoE measurement, our understanding of Internet video QoE is limited because of the shift from traditional methods of measuring video quality (e.g., Peak Signal-to-Noise Ratio) and user experience (e.g., opinion scores). These have been replaced by new quality metrics (e.g., rate of buffering, bitrate) and new engagement centric measures of user experience (e.g., viewing time and number of visits). The goal of this paper is to develop a predictive model of Internet video QoE. To this end, we identify two key requirements for the QoE model: (1) it has to be tied in to observable user engagement and (2) it should be actionable to guide practical system design decisions. Achieving this goal is challenging because the quality metrics are interdependent, they have complex and counter-intuitive relationships to engagement measures, and there are many external factors that confound the relationship between quality and engagement (e.g., type of video, user connectivity). To address these challenges, we present a data-driven approach to model the metric interdependencies and their complex relationships to engagement, and propose a systematic framework to identify and account for the confounding factors. We show that a delivery infrastructure that uses our proposed model to choose CDN and bitrates can achieve more than 20\% improvement in overall user engagement compared to strawman approaches.
Athula Balachandran, Vyas Sekar, Aditya Akella, Srinivasan Seshan, Ion Stoica, Hui Zhang 0001
SIGCOMM2
2013 Less pain, most of the gain: incrementally deployable ICN
abstract
Information-Centric Networking (ICN) has seen a significant resurgence in recent years. ICN promises benefits to users and service providers along several dimensions (e.g., performance, security, and mobility). These benefits, however, come at a non-trivial cost as many ICN proposals envision adding significant complexity to the network by having routers serve as content caches and support nearest-replica routing. This paper is driven by the simple question of whether this additional complexity is justified and if we can achieve these benefits in an incrementally deployable fashion. To this end, we use trace-driven simulations to analyze the quantitative benefits attributed to ICN (e.g., lower latency and congestion). Somewhat surprisingly, we find that pervasive caching and nearest-replica routing are not fundamentally necessary---most of the performance benefits can be achieved with simpler caching architectures. We also discuss how the qualitative benefits of ICN (e.g., security, mobility) can be achieved without any changes to the network. Building on these insights, we present a proof-of-concept design of an incrementally deployable ICN architecture.
Seyed Kaveh Fayaz, Yin Lin, Amin Tootoonchian, Ali Ghodsi 0002, Teemu Koponen, Bruce M. Maggs, K. C. Ng, Vyas Sekar, Scott Shenker
SIGCOMM8
2013 SIMPLE-fying middlebox policy enforcement using SDN
abstract
Networks today rely on middleboxes to provide critical performance, security, and policy compliance capabilities. Achieving these benefits and ensuring that the traffic is directed through the desired sequence of middleboxes requires significant manual effort and operator expertise. In this respect, Software-Defined Networking (SDN) offers a promising alternative. Middleboxes, however, introduce new aspects (e.g., policy composition, resource management, packet modifications) that fall outside the purvey of traditional L2/L3 functions that SDN supports (e.g., access control or routing).
Zafar Ayyub Qazi, Cheng-Chun Tu, Luis Chiang, Rui Miao 0001, Vyas Sekar, Minlan Yu
SIGCOMM5
2013 Understanding internet video viewing behavior in the wild
abstract
Over the past few years video viewership over the Internet has risen dramatically and market predictions suggest that video will account for more than 50% of the traffic over the Internet in the next few years. Unfortunately, there has been signs that the Content Delivery Network (CDN) infrastructure is being stressed with the increasing video viewership load. Our goal in this paper is to provide a first step towards a principled understanding of how the content delivery infrastructure must be designed and provisioned to handle the increasing workload by analyzing video viewing behaviors and patterns in the wild. We analyze various viewing behaviors using a dataset consisting of over 30 million video sessions spanning two months of viewership from two large Internet video providers. In these preliminary results, we observe viewing patterns that have significant impact on the design of the video delivery infrastructure.
Athula Balachandran, Vyas Sekar, Aditya Akella, Srinivasan Seshan
SIGMETRICS2
2013 Towards verifiable resource accounting for outsourced computation
abstract
Outsourced computation services should ideally only charge customers for the resources used by their applications. Unfortunately, no verifiable basis for service providers and customers to reconcile resource accounting exists today. This leads to undesirable outcomes for both providers and consumers-providers cannot prove to customers that they really devoted the resources charged, and customers cannot verify that their invoice maps to their actual usage. As a result, many practical and theoretical attacks exist, aimed at charging customers for resources that their applications did not consume. Moreover, providers cannot charge consumers precisely, which causes them to bear the cost of unaccounted resources or pass these costs inefficiently to their customers.
Chen Chen 0013, Petros Maniatis, Adrian Perrig, Amit Vasudevan, Vyas Sekar
VEE5
2012 New opportunities for load balancing in network-wide intrusion detection systems
abstract
As traffic volumes and the types of analysis grow, network intrusion detection systems (NIDS) face a continuous scaling challenge. Management realities, however, limit NIDS hardware upgrades to occur typically once every 3-5 years. Given that traffic patterns can change dramatically, this leaves a significant scaling challenge in the interim. This motivates the need for practical solutions that can help administrators better utilize and augment their existing NIDS infrastructure. To this end, we design a general architecture for network-wide NIDS deployment that leverages three scaling opportunities: on-path distribution to split responsibilities, replicating traffic to NIDS clusters, and aggregating intermediate results to split expensive NIDS processing. The challenge here is to balance both the compute load across the network and the total communication cost incurred via replication and aggregation. We implement a backwards-compatible mechanism to enable existing NIDS infrastructure to leverage these benefits. Using emulated and trace-driven evaluations on several real-world network topologies, we show that our proposal can substantially reduce the maximum computation load, provide better resilience under traffic variability, and offer improved detection coverage.
Victor Heorhiadi, Michael K. Reiter, Vyas Sekar
CoNEXT3
2012 Improving fairness, efficiency, and stability in HTTP-based adaptive video streaming with FESTIVE
abstract
Many commercial video players rely on bitrate adaptation logic to adapt the bitrate in response to changing network conditions. Past measurement studies have identified issues with today's commercial players with respect to three key metrics---efficiency, fairness, and stability---when multiple bitrate-adaptive players share a bottleneck link. Unfortunately, our current understanding of why these effects occur and how they can be mitigated is quite limited.
Junchen Jiang, Vyas Sekar, Hui Zhang 0001
CoNEXT2
2012 A quest for an Internet video quality-of-experience metric
abstract
An imminent challenge that content providers, CDNs, third-party analytics and optimization services, and video player designers in the Internet video ecosystem face is the lack of a single "gold standard" to evaluate different competing solutions. Existing techniques that describe the quality of the encoded signal or controlled studies to measure opinion scores do not translate directly into user experience at scale. Recent work shows that measurable performance metrics such as buffering, startup time, bitrate, and number of bitrate switches impact user experience. However, converting these observations into a quantitative quality-of-experience metric turns out to be challenging since these metrics are interrelated in complex and sometimes counter-intuitive ways, and their relationship to user experience can be unpredictable. To further complicate things, many confounding factors are introduced by the nature of the content itself (e.g., user interest, genre). We believe that the issue of interdependency can be addressed by casting this as a machine learning problem to build a suitable predictive model from empirical observations. We also show that setting up the problem based on domain-specific and measurement-driven insights can minimize the impact of the various confounding factors to improve the prediction performance.
Athula Balachandran, Vyas Sekar, Aditya Akella, Srinivasan Seshan, Ion Stoica, Hui Zhang 0001
HotNets2
2012 CARE: content aware redundancy elimination for challenged networks
abstract
This paper presents the design of a novel architecture called CARE (Content-Aware Redundancy Elimination) that enables maximizing the informational value that challenged networks offer their users. We focus on emerging applications for situational awareness in disaster affected regions. Motivated by advances in computer vision algorithms, we propose to incorporate image similarity detection algorithms in the forwarding path of these networks. The purpose is to handle the large generation of redundant content. We outline the many issues involved in such a vision. With a Delay-Tolerant Network (DTN) setup, our simulations demonstrate that CARE can substantially boost the number of unique messages that escape the disaster zone, and it can also deliver them faster. These benefits are achieved despite the energy overhead needed by the similarity detectors.
Udi Weinsberg, Qingxi Li, Nina Taft, Athula Balachandran, Vyas Sekar, Gianluca Iannaccone, Srinivasan Seshan
HotNets5
2012 Evolution of social-attribute networks: measurements, modeling, and implications using google+
abstract
Understanding social network structure and evolution has important implications for many aspects of network and system design including provisioning, bootstrapping trust and reputation systems via social networks, and defenses against Sybil attacks. Several recent results suggest that augmenting the social network structure with user attributes (e.g., location, employer, communities of interest) can provide a more fine-grained understanding of social networks. However, there have been few studies to provide a systematic understanding of these effects at scale.
Neil Zhenqiang Gong, Wenchang Xu, Ling Huang 0001, Prateek Mittal, Emil Stefanov, Vyas Sekar, Dawn Song
Internet Measurement Conference6
2012 Design and Implementation of a Consolidated Middlebox Architecture
Vyas Sekar, Norbert Egi, Sylvia Ratnasamy, Michael K. Reiter, Guangyu Shi
NSDI1
2012 Multi-resource fair queueing for packet processing
abstract
Middleboxes are ubiquitous in today's networks and perform a variety of important functions, including IDS, VPN, firewalling, and WAN optimization. These functions differ vastly in their requirements for hardware resources (e.g., CPU cycles and memory bandwidth). Thus, depending on the functions they go through, different flows can consume different amounts of a middlebox's resources. While there is much literature on weighted fair sharing of link bandwidth to isolate flows, it is unclear how to schedule multiple resources in a middlebox to achieve similar guarantees. In this paper, we analyze several natural packet scheduling algorithms for multiple resources and show that they have undesirable properties. We propose a new algorithm, Dominant Resource Fair Queuing (DRFQ), that retains the attractive properties that fair sharing provides for one resource. In doing so, we generalize the concept of virtual time in classical fair queuing to multi-resource settings. The resulting algorithm is also applicable in other contexts where several resources need to be multiplexed in the time domain.
Ali Ghodsi 0002, Vyas Sekar, Matei Zaharia, Ion Stoica
SIGCOMM2
2012 A case for a coordinated internet video control plane
abstract
Video traffic already represents a significant fraction of today's traffic and is projected to exceed 90% in the next five years. In parallel, user expectations for a high quality viewing experience (e.g., low startup delays, low buffering, and high bitrates) are continuously increasing. Unlike traditional workloads that either require low latency (e.g., short web transfers) or high average throughput (e.g., large file transfers), a high quality video viewing experience requires sustained performance over extended periods of time (e.g., tens of minutes). This imposes fundamentally different demands on content delivery infrastructures than those envisioned for traditional traffic patterns. Our large-scale measurements over 200 million video sessions show that today's delivery infrastructure fails to meet these requirements: more than 20% of sessions have a rebuffering ratio ≥ 10% and more than 14% of sessions have a video startup delay ≥ 10s. Using measurement-driven insights, we make a case for a video control plane that can use a global view of client and network conditions to dynamically optimize the video delivery in order to provide a high quality viewing experience despite an unreliable delivery infrastructure. Our analysis shows that such a control plane can potentially improve the rebuffering ratio by up to 2× in the average case and by more than one order of magnitude under stress.
Florin Dobrian, Henry Milner, Junchen Jiang, Vyas Sekar, Ion Stoica, Hui Zhang 0001
SIGCOMM5
2012 Making middleboxes someone else's problem: network processing as a cloud service
abstract
Modern enterprises almost ubiquitously deploy middlebox processing services to improve security and performance in their networks. Despite this, we find that today's middlebox infrastructure is expensive, complex to manage, and creates new failure modes for the networks that use them. Given the promise of cloud computing to decrease costs, ease management, and provide elasticity and fault-tolerance, we argue that middlebox processing can benefit from outsourcing the cloud. Arriving at a feasible implementation, however, is challenging due to the need to achieve functional equivalence with traditional middlebox deployments without sacrificing performance or increasing network complexity.
Justine Sherry, Shaddi Hasan, Colin Scott, Arvind Krishnamurthy, Sylvia Ratnasamy, Vyas Sekar
SIGCOMM6
2012 Measuring user confidence in smartphone security and privacy
abstract
In order to direct and build an effective, secure mobile ecosystem, we must first understand user attitudes toward security and privacy for smartphones and how they may differ from attitudes toward more traditional computing systems. What are users' comfort levels in performing different tasks? How do users select applications? What are their overall perceptions of the platform? This understanding will help inform the design of more secure smartphones that will enable users to safely and confidently benefit from the potential and convenience offered by mobile platforms.
Erika Chin, Adrienne Porter Felt, Vyas Sekar, David A. Wagner 0001
SOUPS3
2011 The middlebox manifesto: enabling innovation in middlebox deployment
abstract
Most network deployments respond to changing application, workload, and policy requirements via the deployment of specialized network appliances or "middleboxes". Despite the critical role that middleboxes play in introducing new network functionality, they have been surprisingly ignored in recent efforts for designing networks that are amenable to innovation. We make the case that enabling innovation in middleboxes is at least as important, if not more important, as that for traditional switches and routers. To this end, our vision is a world with software-centric middlebox implementations running on general-purpose hardware platforms that are managed via open and extensible management APIs. While these principles have been applied in other contexts, they introduce unique opportunities and challenges in the context of middleboxes that we highlight in this paper.
Vyas Sekar, Sylvia Ratnasamy, Michael K. Reiter, Norbert Egi, Guangyu Shi
HotNets1
2011 Understanding website complexity: measurements, metrics, and implications
abstract
Over the years, the web has evolved from simple text content from one server to a complex ecosystem with different types of content from servers spread across several administrative domains. There is anecdotal evidence of users being frustrated with high page load times or when obscure scripts cause their browser windows to freeze. Because page load times are known to directly impact user satisfaction, providers would like to understand if and how the complexity of their websites affects the user experience.
Michael Butkiewicz, Harsha V. Madhyastha, Vyas Sekar
Internet Measurement Conference3
2011 Understanding the impact of video quality on user engagement
abstract
As the distribution of the video over the Internet becomes main- stream and its consumption moves from the computer to the TV screen, user expectation for high quality is constantly increasing. In this context, it is crucial for content providers to understand if and how video quality affects user engagement and how to best invest their resources to optimize video quality. This paper is a first step towards addressing these questions. We use a unique dataset that spans different content types, including short video on demand (VoD), long VoD, and live content from popular video con- tent providers. Using client-side instrumentation, we measure quality metrics such as the join time, buffering ratio, average bitrate, rendering quality, and rate of buffering events.
Florin Dobrian, Vyas Sekar, Asad Awan, Ion Stoica, Dilip Antony Joseph, Aditya Ganjam, Jibin Zhan, Hui Zhang 0001
SIGCOMM2
2010 Network-wide deployment of intrusion detection and prevention systems
abstract
Traditional efforts for scaling network intrusion detection (NIDS) and intrusion prevention systems (NIPS) have largely focused on a single-vantage-point view. In this paper, we explore an alternative design that exploits spatial, network-wide opportunities for distributing NIDS and NIPS functions. For the NIDS case, we design a linear programming formulation to assign detection responsibilities to nodes while ensuring that no node is overloaded. We describe a prototype NIDS implementation adapted from the Bro system to analyze traffic per these assignments, and demonstrate the advantages that this approach achieves. For NIPS, we show how to maximally leverage specialized hardware (e.g., TCAMs) to reduce the footprint of unwanted traffic on the network. Such hardware constraints make the optimization problem NP-hard, and we provide practical approximation algorithms based on randomized rounding.
Vyas Sekar, Ravishankar Krishnaswamy, Anupam Gupta 0001, Michael K. Reiter
CoNEXT1
2010 A case for information-bound referencing
abstract
Links and content references form the foundation of the way that users interact today. Unfortunately, the links used today (URLs) are fragile since they tightly specify a protocol, host, and filename. Some past efforts have decoupled this binding to a certain degree; e.g., creating links that bind to byte-level data. We argue that these systems do not go far enough. Our key observation is that users really care about the intent of the referenced link and are relatively agnostic to the byte-level representation. Based on this observation, we argue that references should be bound to the underlying information associated with the referenced content. We call such references Information-Bound References (IBR). In this paper, we focus on the challenges of creating IBRs for multimedia data, since these form a dominant fraction of Internet traffic today. We explore the trade-offs of various alternatives for generating and using IBRs. We identify that it is possible to adapt multimedia fingerprinting algorithms in the literature to generate IBRs.
Ashok Anand, Aditya Akella, Vyas Sekar, Srinivasan Seshan
HotNets3
2010 Revisiting the case for a minimalist approach for network flow monitoring
abstract
Network management applications require accurate estimates of a wide range of flow-level traffic metrics. Given the inadequacy of current packet-sampling-based solutions, several application-specific monitoring algorithms have emerged. While these provide better accuracy for the specific applications they target, they increase router complexity and require vendors to commit to hardware primitives without knowing how useful they will be to meet the needs of future applications. In this paper, we show using trace-driven evaluations that such complexity and early commitment may not be necessary. We revisit the case for a "minimalist" approach in which a small number of simple yet generic router primitives collect flow-level data from which different traffic metrics can be estimated. We demonstrate the feasibility and promise of such a minimalist approach using flow sampling and sample-and-hold as sampling primitives and configuring these in a network-wide coordinated fashion using cSamp. We show that this proposal yields better accuracy across a collection of application-level metrics than dividing the same memory resources across metric-specific algorithms. Moreover, because a minimalist approach enables late binding to what application level metrics are important, it better insulates router implementations and deployments from changing monitoring needs.
Vyas Sekar, Michael K. Reiter, Hui Zhang 0001
Internet Measurement Conference1
2010 Flexible multimedia content retrieval using InfoNames
abstract
Multimedia content is a dominant fraction of Internet usage today. At the same time, there is significant heterogeneity in video presentation modes and operating conditions of Internet-enabled devices that access such content. Users are often interested in the content, rather than the specific sources or the formats. The host-centric format of the current Internet does not support these requirements naturally. Neither do the recent data-centric naming proposals, since they rely on naming content based on raw byte-level hashing schemes. We argue that to meet these requirements, enabling content retrieval mechanisms to name and query directly for the underlying information is a good way forward. In addition to decoupling content from available sources and transfer protocols, these "information-aware names" or InfoNames explicitly decouple the information from content presentation factors as well. We envision an InfoName Resolution System (IRS) to resolve location based on InfoNames, while taking into account the operating conditions of devices. In this demo, we present an application to show how InfoNames can serve as presentation-invariant and portable names to fetch video content independent of device capabilities and resource constraints.
Ashok Anand, Aditya Akella, Athula Balachandran, Vyas Sekar, Srinivasan Seshan
SIGCOMM5
2010 LiveSky: Enhancing CDN with P2P
abstract
We present the design and deployment experiences with LiveSky , a commercial hybrid CDN-P2P live streaming system, which inherits the best of both CDN and P2P. We address several key challenges, including: 1) ease of integration with existing CDN infrastructure, 2) dynamic resource scaling while guaranteeing quality-of-service, 3) providing good user experience, ensuring network friendliness and upload fairness. LiveSky has been used for several large-scale live streaming events in China. Our evaluation results from real-world indicate that such a hybrid CDN-P2P system provides quality and performance comparable to a CDN and effectively scales the system capacity.
Xuening Liu, Tongyu Zhan, Vyas Sekar, Chuang Lin 0002, Hui Zhang 0001, Bo Li 0001
ACM Trans. Multim. Comput. Commun. Appl.4
2009 Inside the bird's nest: measurements of large-scale live VoD from the 2008 olympics
abstract
The 2008 Beijing Olympics was an interesting event from a VoD perspective because it involved near real-time video delivery at massive scales over multiple days of a high-profile event. We present some measurement-driven insights into this event through a unique dataset obtained from ChinaCache, the largest CDN in China. The dataset is unique in three respects. First, it gives a "white-box" view into user access patterns which would otherwise be impossible. Second, since the CDN serves different content providers, it allows to compare and contrast the effects of different presentation models on end users. Third, the nature of the content itself is vastly different from traditional VoD systems in terms of the real-time and event-driven nature, which gives rise to unique effects. The dataset allows us to investigate a wide range of interesting issues: (1) how the live nature of the events causes differences in access patterns compared to traditional VoD and User-Generated Content (UGC) systems, (2) how the presentation models affect user behavior, and (3) flash-crowd phenomena. Based on these observations, we discuss implications for future live VoD systems.
Xuening Liu, Ning Xia, Chuang Lin 0002, Hui Zhang 0001, Vyas Sekar, Geyong Min
Internet Measurement Conference7
2009 Design and deployment of a hybrid CDN-P2P system for live video streaming: experiences with LiveSky
abstract
We present our design and deployment experiences with LiveSky, a commercially deployed hybrid CDN-P2P live streaming system. CDNs and P2P systems are the common techniques used for live streaming, each having its own set of advantages and disadvantages. LiveSky inherits the best of both worlds: the quality control and reliability of a CDN and the inherent scalability of a P2P system. We address several key challenges in the system design and implementation including (a) dynamic resource scaling while guaranteeing stream quality, (b) providing low startup latency, (c) ease of integration with existing CDN infrastructure, and (d) ensuring network-friendliness and upload fairness in the P2P operation. LiveSky has been commercially deployed and used for several large-scale live streaming events serving more than ten million users in China. We evaluate the performance of LiveSky using data from these real-world deployments. Our results indicate that such a hybrid CDN-P2P system provides quality and user performance comparable to a CDN and effectively scales the system capacity when the user volume exceeds the CDN capacity.
Xuening Liu, Tongyu Zhan, Vyas Sekar, Chuang Lin 0002, Hui Zhang 0001, Bo Li 0001
ACM Multimedia4
2009 SmartRE: an architecture for coordinated network-wide redundancy elimination
abstract
Application-independent Redundancy Elimination (RE), or identifying and removing repeated content from network transfers, has been used with great success for improving network performance on enterprise access links. Recently, there is growing interest for supporting RE as a network-wide service. Such a network-wide RE service benefits ISPs by reducing link loads and increasing the effective network capacity to better accommodate the increasing number of bandwidth-intensive applications. Further, a networkwide RE service democratizes the benefits of RE to all end-to-end traffic and improves application performance by increasing throughput and reducing latencies.
Ashok Anand, Vyas Sekar, Aditya Akella
SIGCOMM2
2008 An empirical evaluation of entropy-based traffic anomaly detection
abstract
Entropy-based approaches for anomaly detection are appealing since they provide more fine-grained insights than traditional traffic volume analysis. While previous work has demonstrated the benefits of entropy-based anomaly detection, there has been little effort to comprehensively understand the detection power of using entropy-based analysis of multiple traffic distributions in conjunction with each other. We consider two classes of distributions: flow-header features (IP addresses, ports, and flow-sizes), and behavioral features (degree distributions measuring the number of distinct destination/source IPs that each host communicates with). We observe that the timeseries of entropy values of the address and port distributions are strongly correlated with each other and provide very similar anomaly detection capabilities. The behavioral and flow size distributions are less correlated and detect incidents that do not show up as anomalies in the port and address distributions. Further analysis using synthetically generated anomalies also suggests that the port and address distributions have limited utility in detecting scan and bandwidth flood anomalies. Based on our analysis, we discuss important implications for entropy-based anomaly detection.
George Nychis, Vyas Sekar, David G. Andersen, Hyong S. Kim 0001, Hui Zhang 0001
Internet Measurement Conference2
2008 cSamp: A System for Network-Wide Flow Monitoring
Vyas Sekar, Michael K. Reiter, Walter Willinger, Hui Zhang 0001, Ramana Rao Kompella, David G. Andersen
NSDI1
2008 Remote Profiling of Resource Constraints of Web Servers Using Mini-Flash Crowds
Pratap Ramamurthy, Vyas Sekar, Aditya Akella, Balachander Krishnamurthy, Anees Shaikh
USENIX ATC2
2006 A Multi-Resolution Approach for Worm Detection and Containment
abstract
Despite the proliferation of detection and containment techniques in the worm defense literature, simple threshold-based methods remain the most widely deployed and most popular approach among practitioners. This popularity arises out of the simplistic appeal, ease of use, and independence from attack-specific properties such as scanning strategies and signatures. However, such approaches have known limitations: they either fail to detect low-rate attacks or incur very high false positive rates. We propose a multi-resolution approach to enhance the power of threshold-based detection and rate-limiting techniques. Using such an approach we can not only detect fast attacks with low latency, but also discover low-rate attacks - several orders of magnitude less aggressive than today’s fast propagating attacks with low false positive rates. We also outline a multi-resolution rate limiting mechanism for throttling the number of new connections a host can make, to contain the spread of worms. Our trace analysis and simulation experiments demonstrate the benefits of a multiresolution approach for worm defense.
Vyas Sekar, Yinglian Xie, Michael K. Reiter, Hui Zhang 0001
DSN1
2006 Forensic Analysis for Epidemic Attacks in Federated Networks
abstract
We present the design of a Network Forensic Alliance (NFA), to allow multiple administrative domains (ADs) to jointly locate the origin of epidemic spreading attacks. ADs in the NFA collaborate in a distributed protocol for post-mortem analysis of worm-like attacks. Information exchange between any two participating ADs is limited to traffic records that are known to both sides, maintaining the privacy of participants. Such an architecture is incentive-compatible - participants benefit by gaining better local investigative capabilities, even with partial deployment. Further, we show that by sharing local investigation results, ADs can achieve global investigative capabilities that are comparable to a centralized implementation with access to global traffic records. Our evaluation demonstrates that it is feasible for large-scale attack investigation to be incrementally deployed in an Internet-like federation.
Yinglian Xie, Vyas Sekar, Michael K. Reiter, Hui Zhang 0001
ICNP2
2006 LADS: Large-scale Automated DDoS Detection System
Vyas Sekar, Nick G. Duffield, Oliver Spatscheck, Jacobus E. van der Merwe, Hui Zhang 0001
USENIX ATC, General Track1
2005 Sparse Approximations for High Fidelity Compression of Network Traffic Data
William Aiello, Anna Gilbert 0001, Brian Rexroad, Vyas Sekar
Internet Measurement Conference4
2005 Worm Origin Identification Using Random Moonwalks
abstract
We propose a novel technique that can determine both the host responsible for originating a propagating worm attack and the set of attack flows that make up the initial stages of the attack tree via which the worm infected successive generations of victims. We argue that knowledge of both is important for combating worms: knowledge of the origin supports law enforcement, and knowledge of the causal flows that advance the attack supports diagnosis of how network defenses were breached. Our technique exploits the "wide tree" shape of a worm propagation emanating from the source by performing random "moonwalks" backward in time along paths of flows. Correlating the repeated walks reveals the initial causal flows, thereby aiding in identifying the source. Using analysis, simulation, and experiments with real world traces, we show how the technique works against both today's fast propagating worms and stealthy worms that attempt to hide their attack flows among background traffic.
Yinglian Xie, Vyas Sekar, David A. Maltz, Michael K. Reiter, Hui Zhang 0001
S&P2
2003 Routing for a single interface MCN architecture and pricing schemes for data traffic in multihop cellular networks
abstract
Multihop cellular networks (MCNs) have been proposed as a throughput enhancement alternative for traditional cellular networks. In MCNs, as opposed to traditional cellular networks, both the base station (BS) and the mobile stations (MSs) play a significant role in forwarding data. In this paper, we propose an efficient routing protocol for single interface MCNs and compare it with an existing routing protocol. The primary motivation for exploring this single interface mechanism is to provide low cost and low power consumption mobile devices. Since pricing in packet-based data traffic for MCNs is a key issue which is not addressed so far, we proposed a set of incentive-based pricing schemes for packet based traffic that are not bound by mobility or load constraints. We also suggest reimbursement based schemes that take into account the retransmission attempts made by the intermediate nodes. We compare our routing protocol single interface MCN routing protocol (SMRP) with base driven multihop bridging protocol (BMBP) and study a set of incentive-based pricing schemes for data traffic in MCNs using extensive simulation using GloMoSim.
Vyas Sekar, B. S. Manoj 0001, C. Siva Ram Murthy
ICC1