Vijay Sivaraman

dblp:63/6049 · DBLP profile ↗
← Back
103ranked-venue papers
16as first author
19since 2021 · last 2026
0000-0001-7985-6765ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 72 · 11 first-author · 15 since 2021Security and privacy · 13 · 1 first-author · 4 since 2021Systems, architecture and hardware · 5 · 2 first-authorGraphics, computer vision, multimedia, augmented reality and games · 2Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 Systematic assessment of cloud game adaptability for network conditions and user experience
abstract
Cloud gaming platforms lower the access barriers to graphics-intensive games by rendering computationally heavy game scenes on cloud GPU servers and streaming them back to players as real-time video, which in turn places significant demands on carrier networks to deliver these video streams with high throughput, low latency and minimal packet loss. To achieve decent user experience, cloud gaming platforms adapt streaming behaviors based on network conditions and allow users to adjust their graphics settings. Knowing the level of game streaming adaptability offered by various cloud gaming providers is helpful for network operators to effectively provision network resources for subscriber satisfaction, and for game development community to incentivize cloud gaming providers to better optimize their streaming techniques. Toward this objective, we develop a systematic framework to assess the adaptability of a cloud gaming platform in reducing network demand for lower client graphics settings; and in adjusting streaming quality under constrained network conditions for smooth gaming experience. Focusing on four popular platforms (NVIDIA GFN, Xbox, PlayStation and Amazon Luna), we begin by empirically profiling and comparing how they adapt game streaming characteristics to various levels of client graphics settings and network conditions. Building on the insights, we develop our systematic assessment framework, which provides quantitative scores for both fine-grained metrics by processing labeled traffic traces, as well as aggregated scores tailored to an assessor’s preference. We showcase our quantitative assessments of the four platforms.
Minzhao Lyu, Yifan Wang 0034, Vijay Sivaraman
Comput. Networks3
2026 A Large-Scale Network Measurement Study of NVIDIA GeForce NOW Cloud Gaming in the Wild
Minzhao Lyu, Vijay Sivaraman
IEEE Trans. Netw.2
2025 Games Are Not Equal: Classifying Cloud Gaming Contexts for Effective User Experience Measurement
abstract
To tap into the growing market of cloud gaming, whereby game graphics is rendered in the cloud and streamed back to the user as a video feed, network operators are creating monetizable assurance services that dynamically provision network resources. However, without accurately measuring cloud gaming user experience, they cannot assess the effectiveness of their provisioning methods. Basic measures such as bandwidth and frame rate by themselves do not suffice, and can only be interpreted in the context of the game played and the player activity within the game. This paper equips the network operator with a method to obtain a real-time measure of cloud gaming experience by analyzing network traffic, including contextual factors such as the game title and player activity stage. Our method is able to classify the game title within the first five seconds of game launch, and continuously assess the player activity stage as being active, passive, or idle. We deploy it in an ISP hosting NVIDIA cloud gaming servers for the region. We provide insights from hundreds of thousands of cloud game streaming sessions over a three-month period into the dependence of bandwidth consumption and experience level on the gameplay contexts.
Yifan Wang 0034, Minzhao Lyu, Vijay Sivaraman
IMC3
2024 Characterizing User Platforms for Video Streaming in Broadband Networks
abstract
Internet Service Providers (ISPs) bear the brunt of being the first port of call for poor video streaming experience. ISPs can benefit from knowing the user's device type (e.g., Android, iOS) and software agent (e.g., native app, Chrome) to troubleshoot platform-specific issues, plan capacity and create custom bundles. Unfortunately, encryption and NAT have limited ISPs' visibility into user platforms across video streaming providers. We develop a methodology to identify user platforms for video streams from four popular providers, namely YouTube, Netflix, Disney, and Amazon, by analyzing network traffic in real-time. First, we study the anatomy of the connection establishment process to show how TCP/QUIC and TLS handshakes vary across user platforms. We then develop a classification pipeline that uses 62 attributes extracted from the handshake messages to determine the user device and software agent of video flows with over 96% accuracy. Our method is evaluated and deployed in a large campus network (mimicking a residential broadband network) serving users including dormitory residents. Analysis of 100+ million video streams over a four-month period reveals insights into the mix of user platforms across the video providers, variations in bandwidth consumption across operating systems and browsers, and differences in peak hours of usage.
Yifan Wang 0034, Minzhao Lyu, Vijay Sivaraman
IMC3
2024 Network Anatomy and Real-Time Measurement of Nvidia GeForce NOW Cloud Gaming
Minzhao Lyu, Sharat Chandra Madanapalli, Arun Vishwanath, Vijay Sivaraman
PAM (1)4
2023 PEDDA: Practical and Effective Detection of Distributed Attacks on enterprise networks via progressive multi-stage inference
Minzhao Lyu, Hassan Habibi Gharakheili, Vijay Sivaraman
Comput. Networks3
2023 Enterprise DNS Asset Mapping and Cyber-Health Tracking via Passive Traffic Analysis
abstract
The Domain Name System (DNS) is a critical service that enables domain names to be converted to IP addresses (or vice versa); consequently, it is generally permitted through enterprise security systems (e.g.,firewalls) with little restriction. This has exposed organizational networks to DDoS, exfiltration, and reflection attacks, inflicting significant financial and reputational damage. Large organizations with loosely federated IT departments (e.g.,Universities and Research Institutes) often are not fully aware of all their DNS assets and vulnerabilities, let alone the attack surface they expose to the outside world. In this paper, we address the “DNS blind spot” by developing methods to passively analyze live DNS traffic, identify organizational DNS assets, and monitor their health on a continuous basis. Our contributions are threefold. First, we perform a comprehensive analysis of all DNS traffic in two large organizations (a University Campus and a Government Research Institute) for over a month, and identify key behavioral profiles for various asset types such as recursive resolvers, authoritative name servers, and mixed DNS servers. Second, we develop an unsupervised clustering method that classifies enterprise DNS assets using the behavioral attributes identified, and demonstrate that our method successfully classifies over 100 DNS assets across the two organizations. Third, our method continuously tracks various health metrics across the organizational DNS assets and identifies several instances of improper configuration, data exfiltration, DDoS, and reflection attacks. We believe the passive analysis methods in this paper can help enterprises monitor organizational DNS health in an automated and risk-free manner.
Minzhao Lyu, Hassan Habibi Gharakheili, Craig Russell, Vijay Sivaraman
IEEE Trans. Netw. Serv. Manag.4
2022 Learning-Based Detection of Malicious Hosts by Analyzing Non-Existent DNS Responses
abstract
DNS Water Torture attack is a type of DDoS attack on authoritative DNS servers and/or open resolvers, whereby the victim is bombarded with random non-existent domains (NXDs) DNS requests, exhausting their entire resources. A famous example of this attack was launched by Mirai botnet on Dyn DNS architecture in 2016. Researchers have proposed solutions to detect these attacks; however, they predominantly apply static thresholds to the count of NXD responses. This method can result in high false positives and needs to be customized to the traffic pattern of victim DNS servers, making it practically challenging for adoption at the source of potential attacks. This paper aims to detect possibly infected hosts of a university campus network that take part in this specific type of DNS-based attacks. Our contributions are threefold: (1) We analyze 120 days' worth of DNS traffic collected from the border of a large university campus network to draw insights into the characteristics of non-existent domain (NXD) responses from incoming DNS packets. We discuss how malicious NXDs differ from benign ones and highlight two attack scenarios based on their requested domain names; (2) We develop a method using multi-staged iForest models to detect malicious internal hosts based on the attributes of their DNS activity; (3) We evaluate the efficacy of our proposed method by applying it to live DNS data streams in our university campus network. We show how our models can detect infected hosts that generate high-volume and low-volume distributed non-existent DNS queries with more than 99% accuracy of correctly classifying legitimate hosts.
Jawad Ahmed, Hassan Habibi Gharakheili, Vijay Sivaraman
GLOBECOM3
2022 Know Thy Lag: In-Network Game Detection and Latency Measurement
Sharat Chandra Madanapalli, Hassan Habibi Gharakheili, Vijay Sivaraman
PAM3
2022 Classifying and tracking enterprise assets via dual-grained network behavioral analysis
Minzhao Lyu, Hassan Habibi Gharakheili, Vijay Sivaraman
Comput. Networks3
2022 Combining Device Behavioral Models and Building Schema for Cybersecurity of Large-Scale IoT Infrastructure
abstract
Modern buildings are increasingly getting connected by adopting a range of IoT devices and applications from video surveillance and lighting to people counting and access control. It has been shown that rich connectivity can make building networks more exposed to cyberattacks and, hence, difficult to manage. Currently, there is no systematic approach for evaluating or enforcing cybersecurity of building systems with a large number of heterogeneous IoT devices. In this article, we aim to enhance cybersecurity of a large-scale IoT infrastructure by formally capturing the expected behavior of the system using the static profile of devices’ intended usage, buildings information, and network configurations (predeployment) along with dynamic diagnosis (post-deployment) of network activity using machine-learning models. Our contributions are threefold: 1) we develop a tool that automatically generates a formal ontology of network communications for a connected infrastructure by taking a description of buildings (in the form of Brick schema), device network behavior (in the form of manufacturer usage description (MUD) specifications, MUD profile), and network configurations (address, port, and VLAN) as inputs. We contribute our tool as opensource, and apply it to a subset of our university smart campus testbed, covering 20 IoT devices of three types deployed in seven different buildings. We translate the formal model into network flow rules and enforce them to the network at runtime using programmable networking techniques; 2) we, then, measure the network activity of device-specific flow rules and diagnose their health using a set of trained anomaly detection models (one-class classifiers) each corresponding to a particular type of device and specific building location, and demonstrate how our method detects attacks with reasonable accuracy of 92.5%; and (3) finally, we demonstrate three types of location-defined network policies (deployment, administrative, and organizational) that can be verified by this formal model.
Ayyoob Hamza, Hassan Habibi Gharakheili, Trevor Pering, Vijay Sivaraman
IEEE Internet Things J.4
2022 Understanding and Reducing HVAC Power Consumption Post-Evacuation Events in Commercial Buildings
abstract
Buildings are required to follow standard operational procedures during emergency evacuation. In addition to people evacuating the building, one of the recommended steps during a fire evacuation is to shut down the air handling units (AHUs) of the heating, ventilation, and air conditioning (HVAC) system to prevent smoke from spreading in the building via the air ducts. Shutting down the AHU will inevitably cut-off cooling, resulting in internal temperatures rising steeply particularly on hot days. This phenomenon imposes considerable power demand on the HVAC to rapidly cool the building down during reoccupation. In this article, we study the energy implications of post-evacuation scenarios. Our contributions are threefold: 1) we quantify power excursion caused in 43 evacuation events across 14 buildings of a university campus using a data-driven building thermal model. We show evacuations during summer season can result in power consumption up to 150% above the power demand threshold; 2) we develop a method to reschedule planned evacuations in order to eliminate the power excursions while adhering to building evacuation standards; and 3) we develop a formal optimization framework to minimize the energy costs during planned and emergency evacuations without compromising the desired thermal comfort temperatures by intelligently cooling the building post evacuation. This is the first study to understand and reduce the HVAC power consumption associated with building evacuation events.
Iresha Pasquel Mohottige, Hassan Habibi Gharakheili, Arun Vishwanath, Salil S. Kanhere, Vijay Sivaraman
IEEE Internet Things J.5
2022 Monetizing Parking IoT Data via Demand Prediction and Optimal Space Sharing
abstract
Transportation is undergoing significant change due to advances in automotive technologies, such as electric and autonomous cars and transportation paradigms, such as car and ridesharing. Coupled with the rapid prevalence of IoT devices, this provides an opportunity for many organizations with large on-premise parking spaces, to better utilize this space, reduce energy footprint, and monetize data generated by IoT systems. This article outlines our efforts to instrument our University’s multistorey parking lot with IoT sensors to monitor real-time usage, and develop a novel dynamic space allocation framework that allows campus manager to redimension the car park to accommodate both car sharing and existing private car users. Our first contribution describes experiences and challenges in measuring car park usage on the university campus and removing noise in the collected data. Our second contribution analyzes data collected during 15 months and draws insights into usage patterns. Our third contribution employs machine learning algorithms to forecast future car park demand in terms of arrival and departure rates, with a mean absolute error of 4.58 cars per hour for a 5-day prediction horizon. Finally, our fourth contribution develops an optimal method for partitioning car park space that aids campus managers in generating revenue from shared cars with minimal impact on private car users.
Thanchanok Sutjarittham, Hassan Habibi Gharakheili, Salil S. Kanhere, Vijay Sivaraman
IEEE Internet Things J.4
2022 Verifying and Monitoring IoTs Network Behavior Using MUD Profiles
abstract
IoT devices are increasingly being implicated in cyber-attacks, raising community concern about the risks they pose to critical infrastructure, corporations, and citizens. In order to reduce this risk, the IETF is pushing IoT vendors to develop formal specifications of the intended purpose of their IoT devices, in the form of a Manufacturer Usage Description (MUD), so that their network behavior in any operating environment can be locked down and verified rigorously. This article aims to assist IoT manufacturers in developing and verifying MUD profiles, while also helping adopters of these devices to ensure they are compatible with their organizational policies and track device network behavior using their MUD profile. Our first contribution is to develop a tool that takes the traffic trace of an arbitrary IoT device as input and automatically generates the MUD profile for it. We contribute our tool as open source, apply it to 28 consumer IoT devices, and highlight insights and challenges encountered in the process. Our second contribution is to apply a formal semantic framework that not only validates a given MUD profile for consistency, but also checks its compatibility with a given organizational policy. We apply our framework to representative organizations and selected devices, to demonstrate how MUD can reduce the effort needed for IoT acceptance testing. Finally, we show how operators can dynamically identify IoT devices using known MUD profiles and monitor their behavioral changes in their network.
Ayyoob Hamza, Dinesha Ranathunga, Hassan Habibi Gharakheili, Theophilus Benson, Matthew Roughan, Vijay Sivaraman
IEEE Trans. Dependable Secur. Comput.6
2021 ReCLive: Real-Time Classification and QoE Inference of Live Video Streaming Services
abstract
Social media, professional sports, and video games are driving rapid growth in live video streaming, on platforms such as Twitch and YouTube Live. Live streaming experience is very susceptible to short-time-scale network congestion since client playback buffers are often no more than a few seconds. Unfortunately, identifying such streams and measuring their QoE for network management is challenging, since content providers largely use the same delivery infrastructure for live and video-on-demand (VoD) streaming, and packet inspection techniques (including SNI/DNS query monitoring) cannot always distinguish between the two. In this paper, we design and develop ReCLive: a machine learning method for live video detection and QoE measurement based on network-level behavioral characteristics.
Sharat Chandra Madanapalli, Alex Mathai, Hassan Habibi Gharakheili, Vijay Sivaraman
IWQoS4
2021 FlowFormers: Transformer-based Models for Real-time Network Flow Classification
abstract
Internet Service Providers (ISPs) often perform network traffic classification (NTC) to dimension network bandwidth, forecast future demand, assure the quality of experience to users, and protect against network attacks. With the rapid growth in data rates and traffic encryption, classification has to increasingly rely on stochastic behavioral patterns inferred using deep learning (DL) techniques. The two key challenges arising pertain to (a) high-speed and fine-grained feature extraction, and (b) efficient learning of behavioural traffic patterns by DL models. To overcome these challenges, we propose a novel network behaviour representation called FlowPrint that extracts per-flow time-series byte and packet-length patterns, agnostic to packet content. FlowPrint extraction is real-time, fine-grained, and amenable for implementation at Terabit speeds in modern P4-programmable switches. We then develop FlowFormers, which use attention-based Transformer encoders to enhance FlowPrint representation and thereby outperform conventional DL models on NTC tasks such as application type and provider classification. Lastly, we implement and evaluate FlowPrint and FlowFormers on live university network traffic, and achieve a 95% f1-score to classify popular application types within the first 10 seconds, going up to 97% within the first 30 seconds and achieve a 95+% f1-score to identify providers within video and conferencing traffic flows.
Rushi Babaria, Sharat Chandra Madanapalli, Himal Kumar, Vijay Sivaraman
MSN4
2021 Optimal Witnessing of Healthcare IoT Data Using Blockchain Logging Contract
abstract
Verification of data generated by wearable sensors is increasingly becoming of concern to health service providers and insurance companies. These devices are typically vulnerable to a wide range of cybersecurity attacks, attempting to manipulate sensing data. Most of these disastrous attacks would remain undetected since neither healthcare servers nor Internet-of-Things (IoT) sensors are aware of the existence of attackers in the middle of communication. Thus, there is a need for a verification framework that various authorities can request a verification service for the local network data of a target IoT device. In this article, we leverage blockchain as a distributed platform to realize an on-demand verification scheme. This allows authorities to automatically transact with connected devices for witnessing services. A public request is made for witness statements on the data of a target IoT that is transmitted on its local network, and subsequently, devices (in close vicinity of the target IoT) offer witnessing service. Our contributions are threefold: 1) we develop a system architecture based on blockchain and smart contract that enables authorities to dynamically avail a verification service for data of a subject device from a distributed set of witnesses which are willing to provide (in a privacy-preserving manner) their local wireless measurement in exchange of monetary return; 2) we then develop a method to optimally select witnesses in such a way that the verification error is minimized subject to monetary cost constraints; and 3) finally, we evaluate the efficacy of our scheme using real Wi-Fi session traces collected from a five-storeyed building with more than thirty access points, representative of a hospital. According to the current pricing schedule of the Ethereum public blockchain, our scheme enables healthcare authorities to verify data transmitted from a typical wearable device with the verification error of the order 0.01% at cost of less than $ 2 for 1-hr witnessing service.
Mohammad Hossein Chinaei, Hassan Habibi Gharakheili, Vijay Sivaraman
IEEE Internet Things J.3
2021 Secure Opportunistic Contextual Logging for Wearable Healthcare Sensing Devices
abstract
Wearable technology is increasingly being used for medical applications such as continuous monitoring of chronically ill patients in homes and hospitals. The various stakeholders (patients, doctors, insurers) have an interest in ensuring not only that the data is untampered, but also that the context is verifiable (e.g., correct time and location can be associated with the data collected). Prior works have studied these aspects in isolation, typically using cryptographic techniques. In this paper, we develop a new solution that leverages the density of wireless devices in the vicinity of the transaction to create witness records ensuring data is tamper-protected and bound to its time and location context. Our first contribution is to develop a secure logging architecture that compacts witness records using Bloom filters and hash-chains them to bind them to the data, allowing fast and reliable forensic verification. Our second contribution is to identify the various configuration parameters influencing the performance of our scheme in terms of storage, processing, and transmission efficiency, and to quantify their effect on verification accuracy. Our third contribution implements and demonstrates the feasibility of our scheme, and quantifies its efficacy via simulation using real trace data from a multi-storey building representing a hospital environment.
Muhammad Siddiqi, Syed Taha Ali, Vijay Sivaraman
IEEE Trans. Dependable Secur. Comput.3
2021 Hierarchical Anomaly-Based Detection of Distributed DNS Attacks on Enterprise Networks
abstract
Domain Name System (DNS) is a critical service for enterprise operations, and is often made openly accessible across firewalls. Malicious actors use this fact to attack organizational DNS servers, or use them as reflectors to attack other victims. Further, attackers can operate with little resources, can hide behind open recursive resolvers, and can amplify their attack volume manifold. The rising frequency and effectiveness of DNS-based DDoS attacks make this a growing concern for organizations. Solutions available today, such as firewalls and intrusion detection systems, use combinations of black-lists of malicious sources and thresholds on DNS traffic volumes to detect and defend against volumetric attacks, which are not robust to attack sources that morph their identity or adapt their rates to evade detection. We propose a method for detecting distributed DNS attacks that uses a hierarchical graph structure to track DNS traffic at three levels of host, subnet, and autonomous system (AS), combined with machine learning that identifies anomalous behaviors at various levels of the hierarchy. Our method can detect distributed attacks even with low rates and stealthy patterns. Our contributions are three-fold: (1) We analyze real DNS traffic over a week (nearly 400M packets) from the edges of two large enterprise networks to highlight various types of incoming DNS queries and the behavior of malicious entities generating query scans and floods; (2) We develop a hierarchical graph structure to monitor DNS activity, identify key attributes, and train/tune/evaluate anomaly detection models for various levels of the hierarchy, yielding more than 99% accuracy at each level; and (3) We apply our scheme to a month's worth of DNS data from the two enterprises and compare the results against blacklists and firewall logs to demonstrate its ability in detecting distributed attacks that might be missed by legacy methods while maintaining a decent real-time performance.
Minzhao Lyu, Hassan Habibi Gharakheili, Craig Russell, Vijay Sivaraman
IEEE Trans. Netw. Serv. Manag.4
2020 Forensic Verification of Health Data From Wearable Devices Using Anonymous Witnesses
abstract
The use of wearable devices, such as smartwatches, glasses, clothes, and fitness bracelets is increasing at an ever-growing pace. Major corporations and insurance companies have started mandating their use for their employees and clients. Data from such devices have begun to feature in settlement claims and as evidence in courts as well, requiring it to be irrefutable and tamper-proof. Lack of protection for personal data as well as the contextual information such as location tracking and its use by law enforcement agencies is raising serious privacy concerns among the general public and civil liberty advocates. In this article, we propose a novel scheme to secure the wearable sensor's communication through its crowdsourced logging by neighboring wearable and smart devices called witnesses preserving the contextual information (such as time and location) as well. To ensure witness privacy, gateway and witness devices use the reciprocity property of wireless medium between them to generate pairs of closely matching link signatures, which not only provide the proof of presence for the witnesses in the vicinity but also act as their time-varying pseudonyms. We demonstrate the feasibility and efficacy of our scheme through the prototype implementation using real wireless devices, and via simulation and experimental results.
Muhammad Siddiqi, Syed Taha Ali, Vijay Sivaraman
IEEE Internet Things J.3
2020 Detecting Behavioral Change of IoT Devices Using Clustering-Based Network Traffic Modeling
abstract
The Internet of Things (IoT) is increasingly becoming a major challenge for network administrators to manage connected devices and sensors ranging from smart lights to smoke alarms and security cameras, at scale. IoT devices use an extensive variety of firmware and provide little (or no) access for the management of their operating systems and configurations. Operators of the IoT infrastructure, therefore, need to employ traffic classification models (trained by historical data) to automatically detect their assets on the network and ensure the health of devices against cyber attacks by monitoring their network behavior. On the other hand, IoT manufacturers often automatically perform firmware upgrades from cloud servers to devices that are operational in the field. This can potentially lead to a change of device behavior which makes it difficult for network operators to maintain classification models (incorporating changes without retraining the entire model). In this article, we develop a modular device classification architecture that allows operators to automatically detect IoT devices by their network activity and dynamically accommodate legitimate changes in assets (either addition of new device profile or upgrade of existing profiles). Our contributions are threefold: 1) we identify key traffic attributes that can be obtained from flow-level network telemetry to characterize the behavior of various IoT device types. We develop an unsupervised one-class clustering method for each device to detect their normal network behavior; 2) we tune device-specific clustering models and use them to classify IoT devices from their network traffic in real time. We enhance our classification by developing methods for automatic conflict resolution and noise filtering; and 3) we evaluate the efficacy of our scheme by applying it to traffic traces (benign and attack) from ten real IoT devices and demonstrate its ability to detect behavioral changes with an overall accuracy of more than 94%.
Arunan Sivanathan, Hassan Habibi Gharakheili, Vijay Sivaraman
IEEE Internet Things J.3
2020 Monitoring Enterprise DNS Queries for Detecting Data Exfiltration From Internal Hosts
abstract
Enterprise networks constantly face the threat of valuable and sensitive data being stolen by cyber-attackers. Sophisticated attackers are increasingly exploiting the Domain Name System (DNS) service for exfiltrating data as well as maintaining tunneled command and control communications for malware. This is because DNS traffic is usually allowed to pass through enterprise firewalls without deep inspection or state maintenance, thereby providing a covert channel for attackers to encode low volumes of data without fear of detection. This paper develops and evaluates a real-time mechanism for detecting exfiltration and tunneling of data over DNS. Unlike prior solutions that operate off-line or in the network core, ours works in real-time at the enterprise edge. Our first contribution is to collect and analyze real DNS traffic from two organizations (a large University and a mid-sized Government Research Institute) over several days and extract numerous stateless attributes of DNS messages that can distinguish malicious from legitimate queries. Our second contribution is to develop, tune, and train a machine-learning algorithm to detect anomalies in DNS queries using a benign dataset of top rank primary domains. To achieve this, we have used 14 days-worth of DNS traffic from each organization. For our third contribution, we implement our scheme on live 10 Gbps traffic streams from the network borders of the two organizations, inject more than three million malicious DNS queries generated by two exfiltration tools, and show that our solution can identify them with high accuracy. We compare our solution with the two-class classifier used in prior work. We draw insights into anomalous DNS queries of two enterprise networks by their anomaly scores, the trace of query count over time, enterprise hosts querying them, and TTL and Type fields of their corresponding responses. Our tools and datasets are made available to the public for validation and further research.
Jawad Ahmed, Hassan Habibi Gharakheili, Qasim Raza, Craig Russell, Vijay Sivaraman
IEEE Trans. Netw. Serv. Manag.5
2020 Managing IoT Cyber-Security Using Programmable Telemetry and Machine Learning
abstract
Cyber-security risks for Internet of Things (IoT) devices sourced from a diversity of vendors and deployed in large numbers, are growing rapidly. Therefore, management of these devices is becoming increasingly important to network operators. Existing network monitoring technologies perform traffic analysis using specialized acceleration on network switches, or full inspection of packets in software, which can be complex, expensive, inflexible, and unscalable. In this paper, we use SDN paradigm combined with machine learning to leverage the benefits of programmable flow-based telemetry with flexible data-driven models to manage IoT devices based on their network activity. Our contributions are three-fold: (1) We analyze traffic traces of 17 real consumer IoT devices collected in our lab over a six-month period and identify a set of traffic flows (per-device) whose time-series attributes computed at multiple timescales (from a minute to an hour) characterize the network behavior of various IoT device types, and their operating states (i.e., booting, actively interacted with user, or being idle); (2) We develop a multi-stage architecture of inference models that use flow-level attributes to automatically distinguish IoT devices from non-IoTs, classify individual types of IoT devices, and identify their states during normal operations. We train our models and validate their efficacy using real traffic traces; and (3) We quantify the trade-off between performance and cost of our solution, and demonstrate how our monitoring scheme can be used in operation for detecting behavioral changes (firmware upgrade or cyber attacks).
Arunan Sivanathan, Hassan Habibi Gharakheili, Vijay Sivaraman
IEEE Trans. Netw. Serv. Manag.3
2019 Real-Time Detection of DNS Exfiltration and Tunneling from Enterprise Networks
Jawad Ahmed, Hassan Habibi Gharakheili, Qasim Raza, Craig Russell, Vijay Sivaraman
IM5
2019 Demo Abstract: A Tool to Detect and Visualize Malicious DNS Queries for Enterprise Networks
Jawad Ahmed, Hassan Habibi Gharakheili, Qasim Raza, Craig Russell, Vijay Sivaraman
IM5
2019 Modeling and Monitoring Wi-Fi Calling Traffic in Enterprise Networks Using Machine Learning
abstract
Many enterprise campuses have poor signal coverage indoors from one or more mobile operators, and thus are increasingly embracing carrier Wi-Fi calling services, allowing their users to make and receive mobile phone calls over the enterprise Wi-Fi connection. Mobile carriers employ IPSec tunnels to secure user calls and messages that traverse untrusted enterprise networks and possibly the public Internet. These encrypted connections from user handsets are seen as potential security threats in enterprise networks. In this paper, we develop a machine learning-based system for monitoring encrypted traffic of IPSec tunnels on the network to distinguish Wi-Fi calling traffic from anomalies. Our contributions are as follows: (1) We analyze traffic traces consisting of carrier Wi-Fi calls made over four mobile networks to highlight network behavioral characteristics of this enterprise application. We develop a set of models using one-class and multi-class classification algorithms to determine if Wi-Fi calling application is present on the IPSec tunnel (if so, to classify its state), otherwise generate a notification to block the non Wi-Fi calling flow, and (2) We evaluate the efficacy of our system in detecting real calls and their states (initiation, heartbeat, and actual call) as well as raising true alarms in case of anomalous traffic.
Sharat Chandra Madanapalli, Arunan Sivanathan, Hassan Habibi Gharakheili, Vijay Sivaraman, Santosh Patil, Byju Pularikkal
LCN4
2019 Inferring IoT Device Types from Network Behavior Using Unsupervised Clustering
abstract
The Internet-of-Things (IoT) is increasingly becoming a major challenge for network administrators to monitor and manage connected devices and sensors, ranging from smart-lights to smoke-alarms and security-cameras. In addition to new device offerings, manufacturers tend to automatically perform firmware upgrade from their cloud servers to change functionalities of existing devices that are operational in the field. This makes it difficult to re-train device classification models in order to capture legitimate changes dynamically. In this paper, we develop a modular device classification architecture that allows us to dynamically accommodate legitimate changes in network IoT assets, either addition of a new device type or upgrades of existing types, without replacing the entire set of models. Our contributions are twofold: (1) We identify key traffic attributes that can be obtained from flow-level network telemetry to characterize individual IoT devices. We develop an unsupervised one-class clustering method for each device to detect its normal network behavior. (2) We tune individual device-specific clustering models and use them to classify IoT devices in real-time. We enhance our classification by developing methods for automatic conflict resolution and noise filtering. We evaluate the efficacy of our scheme by applying it to traffic traces of ten real IoT devices, and demonstrate its ability to achieve overall accuracy of more than 94%.
Arunan Sivanathan, Hassan Habibi Gharakheili, Vijay Sivaraman
LCN3
2019 Mapping an Enterprise Network by Analyzing DNS Traffic
Minzhao Lyu, Hassan Habibi Gharakheili, Craig Russell, Vijay Sivaraman
PAM4
2019 Measuring and Modeling Car Park Usage: Lessons Learned from a Campus Field-Trial
abstract
Transportation is undergoing significant change due to the growth of ride-sharing, electric cars, car-sharing, and self-driving cars. Organizations that have significant real-estate dedicated to on-premise employee car parking are therefore looking to adapt the use of this space, motivated by the opportunity to become greener, improve sharing, and pursue new revenue opportunities. In this paper, we outline our experiences from instrumenting, measuring, and analyzing car-park usage in our University's multi-storey parking lot, and building a model that explores its use for multiple purposes in the near future. Our specific contributions are as follows: (1)We begin by describing experiences and challenges in measuring car-park usage on our campus and cleaning the collected data; (2)We analyze data collected over 23 weeks (covering teaching and non-teaching periods)and draw insights into the usage patterns, including occupancy patterns by times-of-day and days-of-week, and identifying various user groups based on attributes such as arrival time and duration of stay; (3)We develop a queuing model to optimize the use of parking space for generating revenue from shared cars with minimal impact on private car users. We believe our study guides campus managers wanting to generate more value from their existing parking resources.
Thanchanok Sutjarittham, Gary Chen, Hassan Habibi Gharakheili, Vijay Sivaraman, Salil S. Kanhere
WOWMOM4
2019 Experiences With IoT and AI in a Smart Campus for Optimizing Classroom Usage
abstract
Increasing demand for university education is putting pressure on campuses to make better use of their real-estate resources. Evidence indicates that enrollments are rising, yet attendance is falling due to diverse demands on student time and easy access to online content. This paper outlines our efforts to address classroom under-utilization in a real university campus arising from the gap between enrollment and attendance. We do so by instrumenting classrooms with Internet of Things (IoT) sensors to measure real-time usage, using AI to predict attendance, and performing optimal allocation of rooms to courses so as to minimize space wastage. Our first contribution undertakes an evaluation of several IoT sensing approaches for measuring class occupancy, and comparing them in terms of cost, accuracy, privacy, and ease of deployment/operation. Our second contribution instruments nine lecture halls of varying capacity across campus, collects and cleans live occupancy data spanning about 250 courses over two sessions, and draws insights into attendance patterns, including identification of canceled lectures and class tests, while also releasing our data openly to the public. Our third contribution is to use AI techniques for predicting classroom attendance, applying them to real data, and accurately predicting future attendance with an root-mean-square error as low as 0.16. Our final contribution is to develop an optimal allocation of classes to rooms based on predicting attendance rather than enrollment, resulting in over 10% savings in room costs with very low risk of room overflows.
Thanchanok Sutjarittham, Hassan Habibi Gharakheili, Salil S. Kanhere, Vijay Sivaraman
IEEE Internet Things J.4
2019 Classifying IoT Devices in Smart Environments Using Network Traffic Characteristics
abstract
The Internet of Things (IoT) is being hailed as the next wave revolutionizing our society, and smart homes, enterprises, and cities are increasingly being equipped with a plethora of IoT devices. Yet, operators of such smart environments may not even be fully aware of their IoT assets, let alone whether each IoT device is functioning properly safe from cyber-attacks. In this paper, we address this challenge by developing a robust framework for IoT device classification using traffic characteristics obtained at the network level. Our contributions are fourfold. First, we instrument a smart environment with 28 different IoT devices spanning cameras, lights, plugs, motion sensors, appliances, and health-monitors. We collect and synthesize traffic traces from this infrastructure for a period of six months, a subset of which we release as open data for the community to use. Second, we present insights into the underlying network traffic characteristics using statistical attributes such as activity cycles, port numbers, signalling patterns, and cipher suites. Third, we develop a multi-stage machine learning based classification algorithm and demonstrate its ability to identify specific IoT devices with over 99 percent accuracy based on their network activity. Finally, we discuss the trade-offs between cost, speed, and performance involved in deploying the classification framework in real-time. Our study paves the way for operators of smart environments to monitor their IoT assets for presence, functionality, and cyber-security without requiring any specialized devices or protocols.
Arunan Sivanathan, Hassan Habibi Gharakheili, Franco Loi, Adam Radford, Chamith Wijenayake, Arun Vishwanath, Vijay Sivaraman
IEEE Trans. Mob. Comput.7
2019 iTeleScope: Softwarized Network Middle-Box for Real-Time Video Telemetry and Classification
abstract
Video continues to dominate network traffic, yet operators today have poor visibility into the number, duration, and resolutions of the video streams traversing their domain. Current monitoring approaches are inaccurate, expensive, or unscalable, as they rely on statistical sampling, middle-box hardware, or packet inspection software. We present iTelescope, the first intelligent, inexpensive, and scalable softwarized network middle-box solution for identifying and classifying video flows in realtime. Our solution is novel in combining dynamic flow rules with telemetry and machine learning, and is built on commodity OpenFlow switches and open-source software. We develop a fully functional system, train it in the lab using multiple machine learning algorithms, and validate its performance to show over 95% accuracy in identifying and classifying video streams from many providers, including YouTube and Netflix. Lastly, we conduct tests to demonstrate its scalability to tens of thousands of concurrent streams, and deploy it live on a campus network serving several hundred real users. Our traffic monitoring system gives unprecedented fine-grained real-time visibility of video streaming performance to operators of enterprise and carrier networks at very low cost.
Hassan Habibi Gharakheili, Minzhao Lyu, Yu Wang 0131, Himal Kumar, Vijay Sivaraman
IEEE Trans. Netw. Serv. Manag.5
2019 Enhancing Security Management at Software-Defined Exchange Points
abstract
Distributed Denial-of-Service (DDoS) attacks continue to escalate in size and scale, and there is growing need for security management at network-level that can restrict a service to a geography (aka geo-blocking) and prevent the victim's IP address from being faked (aka IP-spoof protection). The former reduces the attack surface on the victim, while the latter reduces liability on the organization from which the attack originates. Unfortunately, these solutions are hard to implement in today's networks, requiring expensive hardware appliances and/or manual configuration. This was exemplified in the recent attack on the Australian government census website, which had to be brought down for weeks in order for security configurations to be applied. In this paper, we first argue that an Internet Exchange Point (IXP) is an appropriate place for managing security of an enterprise, and then design, implement, and evaluate a geo-blocking and IP-spoofing protection solution for a Software Defined IXP. Our first contribution is to define a grammar for operators to specify their high-level security intents, and a compiler that automatically synthesizes these to low-level flow rules for insertion to the interconnect fabric. Our second contribution is to develop a mixed integer linear program optimization framework for distributing flow rules across switches with limited table size, while minimizing carriage costs of malicious and extraneous traffic. Finally, we evaluate the cost benefits of our scheme via simulation of a large IXP network, and demonstrate its practical utility in blocking attacks via implementation over the open-source ONOS controller and experimentation in an SDN testbed.
Himal Kumar, Hassan Habibi Gharakheili, Craig Russell, Vijay Sivaraman
IEEE Trans. Netw. Serv. Manag.4
2018 A tool to access and visualize classroom attendance data from a smart campus: demo abstract
abstract
This demo presents our web-tool to access and visualize student attendance data obtained from instrumenting a pilot set of classrooms with people counting sensors in a large university campus in Sydney, Australia. We showcase two aspects: (1) how to access and process our open data-set containing time-stamped occupancy counts for 9 lecture rooms of varying size in which over 250 courses are conducted over a 12-week semester; and (2) visualizing occupancy at multiple spatial (per-room and per-course) and temporal (over a day, week, or semester) granularities, enabling new insights into student attendance and room usage patterns.
Thanchanok Sutjarittham, Hassan Habibi Gharakheili, Salil S. Kanhere, Vijay Sivaraman
IPSN4
2018 Data-driven monitoring and optimization of classroom usage in a smart campus
abstract
Student enrollments world-wide are increasing each year, while lecture attendance continues to fall, due to diverse demands on student time and easy access to online content. The resulting underutilization of classrooms entails cost penalties, especially in campuses where real-estate is at a premium. This paper outlines our efforts to instrument a University campus with sensors to measure classroom attendance, in a cost-effective and scalable manner without endangering student privacy. We begin by undertaking a lab evaluation of several approaches to measuring class occupancy, and compare them in terms of cost, accuracy, and ease of deployment and operation. We then instrument 9 lecture halls of varying capacity across campus, collect and clean live data on occupancy spanning about 250 courses over 12 weeks during session, and draw insights into attendance patterns, including identification of canceled lectures and class tests; our occupancy data is released openly to the public. Lastly, we show how classroom allocation can be optimized based on attendance rather than enrollments, resulting in potential savings of 52% in room costs.
Thanchanok Sutjarittham, Hassan Habibi Gharakheili, Salil S. Kanhere, Vijay Sivaraman
IPSN4
2018 Real-time detection, isolation and monitoring of elephant flows using commodity SDN system
abstract
Operators of enterprise and carrier networks in-creasingly require real-time visibility into traffic patterns in their network, so they can do better resource management (congestion detection, dynamic routing, capacity scheduling) and security protection (detection of intrusions and volumetric attacks). Of particular interest are elephant flows that transfer large volumes, since they demand most resources and can inflict most damage. Today's techniques for detecting and monitoring elephant flows are based on software-based packet analysis or hardware-based inspection, which are either unscalable or expensive. In this paper we design, implement, and evaluate an SDN-based solution that is scalable (to tens of Gigabits-per-second) and inexpensive (built using commodity OpenFlow switches). We first develop a system architecture that judiciously combines software packet inspection with hardware flow-table counters to identify and monitor heavy flows. We then use real traffic traces taken from a campus network to tune our algorithm parameters for desired trade-off between software load and hardware table size. Finally, we prototype our solution on a commodity OpenFlow hardware switch together with open-source controller and packet inspection software, and demonstrate operation at 10Gbps in a real campus network.
Sharat Chandra Madanapalli, Minzhao Lyu, Himal Kumar, Hassan Habibi Gharakheili, Vijay Sivaraman
NOMS5
2018 Responsive high throughput congestion control for interactive applications over SDN-enabled networks
Aous Thabit Naman, Yu Wang 0131, Hassan Habibi Gharakheili, Vijay Sivaraman, David S. Taubman
Comput. Networks4
2017 A Novel Algorithm for Secret Key Generation in Passive Backscatter Communication Systems
Mohammad Hossein Chinaei, Diethelm Ostry, Vijay Sivaraman
CANS3
2017 Quantifying the reflective DDoS attack capability of household IoT devices
abstract
Distributed Denial-of-Service (DDoS) attacks are increasing in frequency and volume on the Internet, and there is evidence that cyber-criminals are turning to Internet-of-Things (IoT) devices such as cameras and vending machines as easy launchpads for large-scale attacks. This paper quantifies the capability of consumer IoT devices to participate in reflective DDoS attacks. We first show that household devices can be exposed to Internet reflection even if they are secured behind home gateways. We then evaluate eight household devices available on the market today, including lightbulbs, webcams, and printers, and experimentally profile their reflective capability, amplification factor, duration, and intensity rate for TCP, SNMP, and SSDP based attacks. Lastly, we demonstrate reflection attacks in a real-world setting involving three IoT-equipped smart-homes, emphasising the imminent need to address this problem before it becomes widespread.
Minzhao Lyu, Daniel Sherratt, Arunan Sivanathan, Hassan Habibi Gharakheili, Adam Radford, Vijay Sivaraman
WISEC6
2017 An experimental study of secret key generation for passive Wi-Fi wearable devices
abstract
Passive Wi-Fi is a technology to generate 802.11b transmissions using backscatter communication, with power consumption 10000× lower than existing Wi-Fi chipsets. Since wearable devices are typically limited in resources such as power and storage, classical cryptographic security schemes are problematic for them. We instead propose to use wireless channel characteristics to secure data transfer. It has been shown that communicating wireless transceivers are able to generate shared secret keys by measuring channel characteristics at a single frequency. These methods are not applicable to passive Wi-Fi, which uses two different frequencies. In this paper, we describe a method to generate a shared secret key based on wireless channel characteristics in the passive Wi-Fi scenario where the two parties are using dual frequencies.
Mohammad Hossein Chinaei, Vijay Sivaraman, Diethelm Ostry
WoWMoM2
2017 Enabling Fast and Slow Lanes for Content Providers Using Software Defined Networking
abstract
Residential broadband consumption is growing rapidly, increasing the gap between Internet service provider (ISP) costs and revenues. Meanwhile, proliferation of Internet-enabled devices is congesting access networks, degrading end-user experience, and affecting content provider monetization. In this paper, we propose a new model whereby the content provider explicitly signals fast- and slow-lane requirements to the ISP on a per-flow basis, using open APIs supported through software defined networking (SDN). Our first contribution is to develop an architecture that supports this model, presenting arguments on why this benefits consumers (better user experience), ISPs (two-sided revenue), and content providers (fine-grained control over peering arrangement). Our second contribution is to evaluate our proposal using a real trace of over 10 million flows to show that video flow quality degradation can be nearly eliminated by the use of dynamic fast-lanes, and web-page load times can be hugely improved by the use of slow-lanes for bulk transfers. Our third contribution is to develop a fully functional prototype of our system using open-source SDN components (Openflow switches and POX controller modules) and instrumented video/file-transfer servers to demonstrate the feasibility and performance benefits of our approach. Our proposal is a first step towards the long-term goal of realizing open and agile access network service quality management that is acceptable to users, ISPs, and content providers alike.
Hassan Habibi Gharakheili, Vijay Sivaraman, Tim Moors, Arun Vishwanath, John Matthews, Craig Russell
IEEE/ACM Trans. Netw.2
2016 A Host-Based Intrusion Detection and Mitigation Framework for Smart Home IoT Using OpenFlow
abstract
Smart devices are gaining popularity in our homes with the promise to make our lives easier and more comfortable. However, the increased deployment of such smart devices brings an increase in potential security risks. In this work, we propose an intrusion detection and mitigation framework, called IoT-IDM, to provide a network-level protection for smart devices deployed in home environments. IoT-IDM monitors the network activities of intended smart devices within the home and investigates whether there is any suspicious or malicious activity. Once an intrusion is detected, it is also capable of blocking the intruder in accessing the victim device on the fly. The modular design of IoT-IDM gives its users the flexibility to employ customized machine learning techniques for detection based on learned signature patterns of known attacks. Software-defined networking technology and its enabling communication protocol, OpenFlow, are used to realise this framework. Finally, a prototype of IoT-IDM is developed and the applicability and efficiency of proposed framework demonstrated through a real IoT device: a smart light bulb.
Mehdi Nobakht, Vijay Sivaraman, Roksana Boreli
ARES2
2016 Managing home routers from the cloud using Software Defined Networking
abstract
Software Defined Networking (SDN) is increasingly being applied to the management and orchestration of data center networks, wide-area networks, and enterprise networks. In this work we demonstrate the benefits of cloud-based SDN management of home routers. We install open-source firmware (OpenWRT and OpenVSiwtch) on off-the-shelf gateways, and deliver new services to consumers via our software in the cloud. Our service allows users to see their household devices and respective bandwidth usage in real-time, impose a download quota on a per-device basis, and impose time-based parental controls on specific household devices. By removing control from the home gateway to the cloud, we show that new services can be delivered rapidly via easy-to-use interfaces suitable for technically unsophisticated users.
Hassan Habibi Gharakheili, Luke Exton, Vijay Sivaraman
CCNC3
2016 Vulnerability analysis of iPhone 6
abstract
Apple claims that iPhone 6, which is equipped with iOS 8.0 and later version, is secure enough to prevent a user's private data from law enforcement or malicious intruders. In pre-iOS 8.0 operating systems, a user's data were only encrypted by hardware-based keys, which can be obtained by Apple. But in iOS 8.0 and later version, the private data on the iPhone are protected by a secret key that is protected by the user's passcode, which the Apple does not hold. In this paper, supported by real-life experiments, we demonstrate that several vulnerabilities of iPhone 6 with iOS 8, which are brought by ordinary user operations, can lead to the leakage of the private data. Then we conduct vulnerability analysis and give the reasons that cause these vulnerabilities from a technical perspective. Meanwhile, experiments of forging attack aiming at iPhone 6 Touch ID are conducted.
Wencheng Yang, Jiankun Hu, Clinton Fernandes, Vijay Sivaraman, Qianhong Wu
PST4
2016 Smart-Phones Attacking Smart-Homes
abstract
The explosion in Internet-connected household devices, such as light-bulbs, smoke-alarms, power-switches, and webcams, is creating new vectors for attacking "smart-homes" at an unprecedented scale. Common perception is that smart-home IoT devices are protected from Internet attacks by the perimeter security offered by home routers. In this paper we demonstrate how an attacker can infiltrate the home network via a doctored smart-phone app. Unbeknownst to the user, this app scouts for vulnerable IoT devices within the home, reports them to an external entity, and modifies the firewall to allow the external entity to directly attack the IoT device. The ability to infiltrate smart-homes via doctored smart-phone apps demonstrates that home routers are poor protection against Internet attacks and highlights the need for increased security for IoT devices.
Vijay Sivaraman, Dominic Chan, Dylan Earl, Roksana Boreli
WISEC1
2016 Greening Router Line-Cards via Dynamic Management of Packet Memory
abstract
Continued scaling of switching capacity in the Internet core is threatened by power considerations. Internet service providers face increased carbon footprint and operational costs, while router manufacturers encounter upper limits on switching capacity per rack. This paper studies the role of packet buffer memory on the power consumption of backbone routers. Our first contribution is to estimate from published datasheets the energy costs of static RAM/dynamic RAM packet-buffer memory, showing that it accounts for over 10% of power consumption in a typical router line-card; we then show, using empirical data from core and enterprise networks, that much of this memory is used for only a small fraction of time. Our second contribution is to develop a simple yet practical algorithm for putting much of the memory components to sleep and waking them as needed, while being able to control resulting traffic performance degradation in the form of packet loss during transient congestion. Finally, we conduct a comprehensive evaluation of our scheme, via analytical models pertaining to long-range-dependent traffic, using simulations of offline traffic traces taken from carrier/enterprise networks as well as online Transmission Control Protocol flows in ns2, and by implementing our scheme on a programmable-router test bed. This paper is the first to show the feasibility of, and energy savings from, dynamic management of packet buffer memory in core routers in the market today.
Vijay Sivaraman, Arun Vishwanath, Diethelm Ostry, Marina Thottan
IEEE J. Sel. Areas Commun.1
2016 SDN APIs and Models for Two-Sided Resource Management in Broadband Access Networks
abstract
Access networks, largely based on DSL or cable links, continue to be the bandwidth bottleneck between device-rich households and high-speed core networks, causing frustration for both end-users and content service providers (CSPs). In this paper, we advocate that the scarce bandwidth resource on the access link be managed jointly, under software control, by the Internet service provider (ISP), consumer, and CSP. Our first contribution is to develop software defined networking (SDN) APIs for bandwidth control at fine-grain (per-flow) by the CSP and at coarse-grain (per-device) by the consumer, and highlight the benefits of such an architecture for all entities. Second, we develop an economic model to guide the ISP in determining bandwidth allocation that balances the needs of the CSP against those of the consumer, and demonstrate its utility via simulation of trace data comprising over 10 million flows. Finally, we prototype our system using commodity home routers and open-source SDN platforms, and conduct experiments in a campus-scale network to demonstrate how our scheme permits proactive and reactive improvement in end-user experience.
Hassan Habibi Gharakheili, Vijay Sivaraman, Arun Vishwanath, Luke Exton, John Matthews, Craig Russell
IEEE Trans. Netw. Serv. Manag.2
2015 Broadband fast-lanes with two-sided control: Design, evaluation, and economics
abstract
Enhancing quality-of-service (QoS) for specific traffic streams by assigning them to "fast-lanes" on the broadband Internet service is a subject of intense ongoing debate. While Internet Service Providers (ISPs) have clear economic imperatives for fast-lanes paid by content service providers (CSPs), proponents of net-neutrality argue that consumer interest will be ignored in the selection of traffic thus prioritized. In this paper we propose a new solution in which ISP fast-lanes have "two-sided" control, i.e. by both consumers and CSPs. Our contributions are two-fold: (1) We develop an architecture in which ISP-operated fast-lanes can be controlled at fine-grain (per-flow) by the CSP and at coarse-grain (per-device) by the consumer, and argue why we think such an architecture can meet the needs of all three parties; and (2) We develop an economic model to guide the ISP in determining fast-lane allocation that balances the needs of the CSP against those of the consumer, and evaluate our model via simulation of trace data comprising over 10 million flows.
Hassan Habibi Gharakheili, Vijay Sivaraman, Arun Vishwanath, Luke Exton, John Matthews, Craig Russell
IWQoS2
2015 Network-level security and privacy control for smart-home IoT devices
abstract
The increasing uptake of smart home appliances, such as lights, smoke-alarms, power switches, baby monitors, and weighing scales, raises privacy and security concerns at unprecedented scale, allowing legitimate and illegitimate entities to snoop and intrude into the family's activities. In this paper we first illustrate these threats using real devices currently available in the market. We then argue that as more such devices emerge, the attack vectors increase, and ensuring privacy/security of the house becomes more challenging. We therefore advocate that device-level protections be augmented with network-level security solutions, that can monitor network activity to detect suspicious behavior. We further propose that software defined networking technology be used to dynamically block/quarantine devices, based on their network activity and on the context within the house such as time-of-day or occupancy-level. We believe our network-centric approach can augment device-centric security for the emerging smart-home.
Vijay Sivaraman, Hassan Habibi Gharakheili, Arun Vishwanath, Roksana Boreli, Olivier Mehani
WiMob1
2015 Comparing edge and host traffic pacing in small buffer networks
Hassan Habibi Gharakheili, Arun Vishwanath, Vijay Sivaraman
Comput. Networks3
2015 Greening Residential Wi-Fi Networks under Centralized Control
abstract
Residential broadband gateways (comprising modem, router, and Wi-Fi access point), though individually consuming only 5-10 Watts of power, are significant contributors to overall network energy consumption due to large deployment numbers. Moreover, home gateways are typically always on, so as to provide continuous online presence to household devices for VoIP, smart metering, security surveillance, medical monitoring, etc. A natural solution for reducing the energy consumption of home gateways is to leverage the overlap of Wi-Fi networks common in urban environments and aggregate user traffic on to fewer gateways, thus putting the remaining to sleep. In this paper we propose, evaluate, and prototype an architecture that overcomes significant challenges in making this solution feasible at large-scale. We advocate a centralized approach, whereby a single authority co-ordinates the home gateways to maximize energy savings in a fair manner. Our solution can be implemented across heterogeneous ISPs, avoids client-side modifications (thus encompassing arbitrary user devices and operating systems), and permits explicit control of session migrations. We apply our solution to Wi-Fi traces collected in a building with 30 access points and 25,000 client connections, and evaluate via simulation the tradeoffs between energy savings, session disruptions, and fairness. We then prototype our system on commodity Wi-Fi access points, test it in a two-storey building emulating 6 residences, and demonstrate radio energy reduction of over 60 percent with little impact on user experience.
Vijay Sivaraman, John Matthews, Craig Russell, Syed Taha Ali, Arun Vishwanath
IEEE Trans. Mob. Comput.1
2015 A Survey of Securing Networks Using Software Defined Networking
abstract
Software Defined Networking (SDN) is rapidly emerging as a new paradigm for managing and controlling the operation of networks ranging from the data center to the core, enterprise, and home. The logical centralization of network intelligence presents exciting challenges and opportunities to enhance security in such networks, including new ways to prevent, detect, and react to threats, as well as innovative security services and applications that are built upon SDN capabilities. In this paper, we undertake a comprehensive survey of recent works that apply SDN to security, and identify promising future directions that can be addressed by such research.
Syed Taha Ali, Vijay Sivaraman, Adam Radford, Sanjay K. Jha
IEEE Trans. Reliab.2
2014 PrivacyCanary: Privacy-Aware Recommenders with Adaptive Input Obfuscation
abstract
Recommender systems are widely used by online retailers to promote products and content that are most likely to be of interest to a specific customer. In such systems, users often implicitly or explicitly rate products they have consumed, and some form of collaborative filtering is used to find other users with similar tastes to whom the products can be recommended. While users can benefit from more targeted and relevant recommendations, they are also exposed to greater risks of privacy loss, which can lead to undesirable financial and social consequences. The use of obfuscation techniques to preserve the privacy of user ratings is well studied in the literature. However, works on obfuscation typically assume that all users uniformly apply the same level of obfuscation. In a heterogeneous environment, in which users adopt different levels of obfuscation based on their comfort level, the different levels of obfuscation may impact the users in the system in a different way. In this work we consider such a situation and make the following contributions: (a) using an offline dataset, we evaluate the privacy-utility trade-off in a system where a varying portion of users adopt the privacy preserving technique. Our study highlights the effects that each user's choices have, not only on their own experience but also on the utility that other users will gain from the system, and (b) we propose Privacy Canary, an interactive system that enables users to directly control the privacy-utility trade-off of the recommender system to achieve a desired accuracy while maximizing privacy protection, by probing the system via a private (i.e., undisclosed to the system) set of items. We evaluate the performance of our system with an off-line recommendations dataset, and show its effectiveness in balancing a target recommender accuracy with user privacy, compared to approaches that focus on a fixed privacy level.
Thivya Kandappu, Arik Friedman, Roksana Boreli, Vijay Sivaraman
MASCOTS4
2014 Personalizing the home network experience using cloud-based SDN
abstract
Home networks are becoming increasingly rich in devices and applications, but continue to share the broadband link in a neutral way. We believe the time is ripe to personalize the home network experience, allowing a household to differentiate its users (e.g. father's laptop prioritized over kid's iPad) and services (e.g. video streaming prioritized over downloading). In this paper we argue that SDN provides a way to automate self-customization by households, while cloud-based delivery simplifies subscriber management. We develop an architecture comprising a cloud-based front-end portal and SDN-based back-end APIs, and show how these can be used by the subscriber to improve streaming-video (YouTube) quality and video conferencing (Skype) experience, and to permit device-specific parental controls (e.g. Facebook access). We prototype and validate our solution in a platform comprising the Floodlight controller and OVS switches. Lastly, we evaluate our solutions via experiments of realistic scenarios to quantify the benefits in terms of improved quality of experience and new features for the user.
Hassan Habibi Gharakheili, Jacob Bass, Luke Exton, Vijay Sivaraman
WoWMoM4
2014 Comparison of the energy, carbon and time costs of videoconferencing and in-person meetings
Dennis Ong, Tim Moors, Vijay Sivaraman
Comput. Commun.3
2014 An experimental power profile of Energy Efficient Ethernet switches
Vijay Sivaraman, Pedro Reviriego, Alfonso Sánchez-Macián, Arun Vishwanath, Juan Antonio Maestro, Craig Russell
Comput. Commun.1
2014 Authentication of lossy data in body-sensor networks for cloud-based healthcare monitoring
Syed Taha Ali, Vijay Sivaraman, Diethelm Ostry
Future Gener. Comput. Syst.2
2014 Securing First-Hop Data Provenance for Bodyworn Devices Using Wireless Link Fingerprints
abstract
Wireless bodyworn sensing devices are fast becoming popular for fitness, sports training, and personalized healthcare applications. Securing data generated by these devices is essential if they are to be integrated into the current health infrastructure and employed in medical applications. In this paper, we propose a mechanism to secure the data provenance for these devices by exploiting spatio-temporal characteristics of the wireless channel that these devices use for communication. Our solution enables two parties to generate closely matching link fingerprints, which uniquely associate a data session with a wireless link such that a third party can later verify the details of the transaction, particularly the wireless link on which the data was transmitted. These fingerprints are very hard for an eavesdropper to forge; they are lightweight compared with traditional provenance mechanisms and enable interesting security properties such as accountability, nonrepudiation, and resist man-in-the-middle attacks. We validate our technique with experiments using bodyworn sensors in scenarios approximating actual device deployment and present some extensions, which reduce energy consumption. We believe this is a promising first step toward using wireless-link characteristics for the data provenance in body area networks.
Syed Taha Ali, Vijay Sivaraman, Diethelm Ostry, Gene Tsudik, Sanjay K. Jha
IEEE Trans. Inf. Forensics Secur.2
2014 Eliminating Reconciliation Cost in Secret Key Generation for Body-Worn Health Monitoring Devices
abstract
Medical data collected by wearable wireless sensor devices must be adequately secured. A prerequisite for mass deployment of these secure systems is the ability to periodically renew cryptographic keys without user involvement. Recent work has shown that two communicating devices can generate secret keys directly from measurements of their common wireless channel, which is symmetric but cannot be inferred in detail by an eavesdropper. These schemes may, however, yield mismatching keys at the two ends, requiring reconciliation mechanisms with high implementation and energy costs, unsuitable for resource-poor body-worn devices. In this work, we demonstrate a scheme for secret-key generation able to construct shared keys with near-perfect agreement, thereby avoiding reconciliation costs. Our specific contributions are: (1) we identify non-simultaneous probing of the channel by the link end-points as the dominant cause of channel measurement disagreement; (2) we develop a practical filtering scheme to reduce this disagreement, dramatically improving signal correlation between the two ends without affecting key entropy; and (3) we show that by restricting key generation to periods of significant channel fluctuation, we achieve near-perfect key agreement. We demonstrate in several representative body-worn settings that our scheme can generate secret bits with 99.8% agreement, and so yield near-perfect matching 128-bit keys approximately every half hour.
Syed Taha Ali, Vijay Sivaraman, Diethelm Ostry
IEEE Trans. Mob. Comput.2
2013 Virtualizing the access network via open APIs
abstract
Residential broadband consumption is growing rapidly, increasing the gap between ISP costs and revenues. Meanwhile, proliferation of Internet-enabled devices is congesting access networks, frustrating end-users and content providers. We propose that ISPs virtualize access infrastructure, using open APIs supported through SDN, to enable dynamic and controlled sharing amongst user streams. Content providers can programmatically provision capacity to user devices to ensure quality of experience, users can match the degree of virtualization to their usage pattern, and ISPs can realize per-stream revenues by slicing their network resources. Using video streaming and bulk transfers as examples, we develop an architecture that specifies the interfaces between the ISP, content provider, and user. We propose an algorithm for optimally allocating network resources, leveraging bulk transfer time elasticity and access path space diversity. Simulations using real traces show that virtualization can reduce video degradation by over 50%, for little extra bulk transfer delay. Lastly, we prototype our system and validate it in a test-bed with real video streaming and file transfers. Our proposal is a first step towards the long-term goal of realizing open and agile access network service quality management that is acceptable to users, ISPs and content providers alike.
Vijay Sivaraman, Tim Moors, Hassan Habibi Gharakheili, Dennis Ong, John Matthews, Craig Russell
CoNEXT1
2013 Edge versus host pacing of TCP traffic in small buffer networks
Hassan Habibi Gharakheili, Arun Vishwanath, Vijay Sivaraman
Networking3
2013 Securing data provenance in body area networks using lightweight wireless link fingerprints
abstract
Wireless bodyworn sensing devices are becoming popular for fitness, sports training and personalized healthcare applications. In this paper, we demonstrate a mechanism to secure data provenance for these devices by exploiting symmetric spatio-temporal characteristics of the wireless link between two communicating parties. Our solution enables both parties to generate closely matching 'link' fingerprints which uniquely associate a data session with a wireless link such that a third party, at a later date, can verify the links the data was communicated on. These fingerprints are unique, they are very hard for an eavesdropper to forge, lightweight compared to traditional provenance mechanisms, and allow for certain interesting security properties such as system accountability and non-repudiation.
Syed Taha Ali, Vijay Sivaraman, Diethelm Ostry, Sanjay K. Jha
SenSys2
2013 An experimental study of wireless connectivity and routing in ad hoc sensor networks for real-time soccer player monitoring
Vijay Sivaraman, Ashay Dhamdhere, Alexander Kurusingal, Sarthak Grover
Ad Hoc Networks1
2013 Enabling a Bufferless Core Optical Network Using Edge-to-Edge Packet-Level FEC
abstract
To cope with the phenomenal growth of the Internet over the next decade, core networks are expected to scale to capacities of terabits-per-second and beyond. Increasing the role of optics for switching and transmission inside the core network seems to be the most promising way forward to accomplish this capacity scaling. Unfortunately, unlike electronic memory, it remains a formidable challenge to build even a few packets of integrated all-optical buffers. In this context, we envision a bufferless (or near-zero buffer) core optical network and make three contributions: First, we propose a novel edge-to-edge based packet-level forward error correction (FEC) scheme that combats packet loss in the bufferless core, and characterise the impact of FEC strength on loss at a single link. Second, we develop a global optimisation framework for multi-hop networks, and propose a heuristic algorithm that adjusts FEC strength to achieve fairness amongst the different single- and multi-hop flows. Finally, we evaluate the performance of our FEC scheme for realistic mixes of short- and long-lived TCP flows, and show that edge-to-edge packet-level FEC can be tuned to effectively mitigate contention losses in the core, thus opening the doors to bufferless optical networks in the near future.
Arun Vishwanath, Vijay Sivaraman, Marina Thottan, Constantinos Dovrolis
IEEE Trans. Commun.2
2013 PET Protection Optimization for Streaming Scalable Videos With Multiple Transmissions
abstract
This paper investigates priority encoding transmission (PET) protection for streaming scalably compressed video streams over erasure channels, for the scenarios where a small number of retransmissions are allowed. In principle, the optimal protection depends not only on the importance of each stream element, but also on the expected channel behavior. By formulating a collection of hypotheses concerning its own behavior in future transmissions, limited-retransmission PET (LR-PET) effectively constructs channel codes spanning multiple transmission slots and thus offers better protection efficiency than the original PET. As the number of transmission opportunities increases, the optimization for LR-PET becomes very challenging because the number of hypothetical retransmission paths increases exponentially. As a key contribution, this paper develops a method to derive the effective recovery-probability versus redundancy-rate characteristic for the LR-PET procedure with any number of transmission opportunities. This significantly accelerates the protection assignment procedure in the original LR-PET with only two transmissions, and also makes a quick and optimal protection assignment feasible for scenarios where more transmissions are possible. This paper also gives a concrete proof to the redundancy embedding property of the channel codes formed by LR-PET, which allows for a decoupled optimization for sequentially dependent source elements with convex utility-length characteristic. This essentially justifies the source-independent construction of the protection convex hull for LR-PET.
Ruiqin Xiong, David S. Taubman, Vijay Sivaraman
IEEE Trans. Image Process.3
2012 Decorrelating secret bit extraction via channel hopping in body area networks
abstract
Recent research has demonstrated that two communicating parties can generate shared secret keys by exploiting characteristics of the wireless fading channel between them. These channel characteristics are symmetric, dependent on position and orientation, highly sensitive to motion, and cannot be deduced in detail by an eavesdropper. One problem with this approach, however, is that over small channel sampling intervals, successively sampled values are correlated in time, which therefore yields keys with reduced entropy. In this paper, we undertake experiments to determine the efficacy of using channel hopping to increase diversity and improve secret key entropy, in the context of body area networks. We conduct extensive experiments using off-the-shelf IEEE 802.15.4 devices, mounted on the human body, in a real indoor environment. Our experimental results show that: (i) channel hopping increases frequency diversity and effectively decorre-lates successive channel samples, significantly increasing entropy (at minimum approximately 20%) and thereby improving the strength of the secret key, (ii) the benefit can be maximized by devising a hopping strategy that takes into account the number of channels available, the spacing between them, and the activity of the user.
Linjia Yao, Syed Taha Ali, Vijay Sivaraman, Diethelm Ostry
PIMRC3
2012 Authentication of lossy data in body-sensor networks for healthcare monitoring
abstract
Growing pressures on healthcare costs are spurring development of lightweight bodyworn sensors for real-time and continuous physiological monitoring. Data from these sensors is streamed wirelessly to a handheld device such as a mobile phone, and then archived over the Internet at a central database. Authenticating the data is vital to ensure proper diagnosis, traceability, and validation of claims. Digital signatures at the packet-level are too resource-intensive for bodyworn devices, while block-level signatures are not robust to loss. In this paper we propose, analyse, and validate a practical, lightweight robust authentication scheme suitable for health-monitoring. We make three specific contributions: (a) We develop an authentication scheme that is both low-cost (using a Merkle hash tree to amortise digital signature costs), and loss-resilient (using network coding to recover strategic nodes within the tree). (b) We develop a framework for optimising placement of network coding within the tree to maximise data verifiability for a given overhead and loss environment. (c) We validate our scheme using experimental traces of typical operating conditions to show that it achieves high success (over 99% of the medical data can be authenticated) at very low overheads (as low as 5% extra transmissions) and at very low cost (the bodyworn device has to perform a digital signature operation no more than once per hour). We believe our novel authentication scheme can be a key ingredient in the integration of wearable medical monitoring devices into current healthcare systems.
Syed Taha Ali, Vijay Sivaraman, Diethelm Ostry
SECON2
2012 A novel unbalanced tree structure for low-cost authentication of streaming content on mobile and sensor devices
abstract
We consider stored content being streamed to a resource-poor device (such as a sensor node or a mobile phone), and address the issue of authenticating such content in realtime at the receiver. Per-packet digital signatures incur high computational cost, while per-block signatures impose high delays. A Merkle hash tree combines the benefits of the two by having a single signature per-block (at the root of the tree), while allowing immediate per-packet verification by following a hash-path logarithmic in the number of packets. In this paper we explore how the structure of the Merkle tree can be adapted to improve playback performance for streaming content. We make three specific contributions: First, we develop a new unbalanced authentication tree structure called the α-leaf tree that is a generalisation of the Merkle tree. We derive several key properties of this tree, highlighting the impact of the imbalance parameter α. Second, we present a theoretical model to quantify the benefits of our unbalanced tree structure in reducing startup delays for streaming applications by optimally readjusting the burden of authentication across packets. Third, we validate via simulation the suitability of our scheme to two representative applications, namely audio streaming to a low-cost sensor device and video streaming to a mobile phone, and demonstrate that startup delays can be reduced without affecting stall rates. We believe our authentication tree structure is of importance both theoretically, as a generalisation of the Merkle hash tree, as well as practically, for applications requiring real-time verification of streaming content.
Thivya Kandappu, Vijay Sivaraman, Roksana Boreli
SECON2
2012 Zero reconciliation secret key generation for body-worn health monitoring devices
abstract
Wearable wireless sensor devices are key components in the emerging technology of personalized healthcare monitoring. Medical data collected by these devices must be secured, especially on the wireless link to the gateway equipment. However, it is difficult to manage the required cryptographic keys, as users may lack the awareness or requisite skills for this task. Alternatively, recent work has shown that two communicating devices can generate secret keys derived directly from symmetrical properties of the wireless channel between them. This channel is also strongly dependent on positioning and movement and cannot be inferred in detail by an eavesdropper. Existing schemes, however, yield keys with mismatching bits at the two ends, requiring reconciliation mechanisms with high implementation and energy costs that are unsuitable for resource-poor body-worn devices.
Syed Taha Ali, Vijay Sivaraman, Diethelm Ostry
WISEC2
2012 Improving the efficiency of anonymous routing for MANETs
Jiefeng Chen 0002, Roksana Boreli, Vijay Sivaraman
Comput. Commun.3
2011 Adapting router buffers for energy efficiency
abstract
Reducing the power consumption of core Internet routers is important for both Internet Service Providers (ISPs) and router vendors. ISPs can reduce their Carbon footprint and operational costs, while router manufacturers can achieve higher switching capacity per rack space. In this work, we examine the impact of packet buffers on the power consumption of backbone router line-cards. We argue that Gigabytes of always-on SRAM and DRAM buffers account for around 10% of the power, but are actively used only during transient periods of congestion. We propose a simple and practical algorithm for activating buffers incrementally as needed and putting them to sleep when not in use. We evaluate our algorithm on traffic traces from carrier and enterprise networks, via simulations in ns2, and by implementing it on a programmable-router test-bed. Our study shows that much of the energy associated with off-chip packet buffers can be eliminated with negligible impact on traffic performance. Dynamic adjustment of active router buffer size provides a low-complexity low-risk mechanism of saving energy that is amenable for incremental deployment in networks today.
Arun Vishwanath, Vijay Sivaraman, Craig Russell, Marina Thottan
CoNEXT2
2011 Environmental context aware trust in mobile P2P networks
abstract
With the growing popularity and capabilities of mobile devices, peer-to-peer networking among such devices is increasingly of interest for mobile content sharing. One of the major challenges in practical use of Mobile Peer-to-Peer networks (MP2P) is the trust among peers. Traditionally, solutions in the state of the art have focused on a peer's past experience in evaluating trust of other peers, based on direct interactions. Previously unknown peers (with no history of direct interactions) are assessed based on third party recommendations, yet again requiring a peer to evaluate and find trustworthy recommenders. This reveals the fundamental need to find peers with honest intentions before any interaction. It becomes challenging when no known peers are in the vicinity, which is highly likely in an MP2P scenario. For a general mobile user, the probability of encountering trustworthy peers in particular situations or environmental contexts may be higher than in other contexts, e.g. in office than on the road while traveling. Further, observed peers which are co-located over a number of environmental contexts may have more in common and thus resulting a higher mutual trust. These facts can be utilized to enrich the trust derivation process in a decentralized manner. In this paper, we propose a generalized and a novel distributed mechanism to estimate the trust for peers using their encounter history in different environmental contexts, and a way to prioritize contexts depending on the level of association with them. When evaluated against real user data of the reality mining dataset, the results of the proposed mechanism show a significantly improved accuracy of trust evaluation compared to the state of the art.
Upendra Rathnayake, Vijay Sivaraman, Roksana Boreli
LCN2
2011 Anomalous loss performance for mixed real-time and TCP traffic in routers with very small buffers
abstract
In the past few years there has been vigorous debate regarding the size of buffers required at core Internet routers. Recent arguments supported by theory and experimentation show that under certain conditions, core router buffer sizes of a few tens of packets suffice for realizing acceptable end-to-end TCP throughputs. This is a significant step toward the realization of optical packet switched (OPS) networks, which are inherently limited in their ability to buffer optical signals. However, prior studies have largely ignored the presence of real-time traffic, which is increasing in importance as a source of revenue for Internet service providers. In this paper, we study the interaction that happens between real-time (open-loop) and TCP (closed-loop) traffic when they multiplex at buffers of very small size (few tens of packets) and make a significant discovery - namely that in a specific range of buffer size, real-time traffic losses increase as buffer size becomes larger. Our contributions pertaining to this anomalous behavior are threefold. First, we exhibit this anomalous loss performance for real-time traffic via extensive simulations using synthetic traffic and real video traces. Second, we develop quantitative models that reveal the dynamics of buffer sharing between real-time and TCP traffic that lead to this behavior. Third, we show how various factors such as the nature of real-time traffic, mixture of long-lived and short-lived TCP flows, and packet sizes impact the severity of the anomaly. Our study is the first to consider interactions between real-time and TCP traffic in very small (potentially all-optical) buffers and informs router manufacturers and network operators of the factors to consider when dimensioning such small buffer sizes for desired performance balance between real-time and TCP traffic.
Arun Vishwanath, Vijay Sivaraman, George N. Rouskas
IEEE/ACM Trans. Netw.2
2010 Secret Key Generation Rate vs. Reconciliation Cost Using Wireless Channel Characteristics in Body Area Networks
abstract
In this paper, we investigate the feasibility of real time derivation of cryptographic keys in body area networks using unique characteristics of the underlying wireless channel. We perform experiments to confirm that motion does indeed provide significant highly correlated randomness on either end of the wireless link between base station and mobile mote to enable real-time key generation. Furthermore, we demonstrate that channel characteristics for a dynamic body area network consist of two different components, a fast and a slow component, each of which make a qualitatively different contribution to key generation. These components can be isolated to address specific needs of the application scenario: the fast component can yield high entropy keys at a fast rate between base station and mobile mote with some bit disagreement between the two devices, the slow component generates keys at a lower rate but with very high level of bit agreement. Our experimental results highlight this tradeoff, and our key generation protocol details the key extraction process.
Syed Taha Ali, Vijay Sivaraman, Diethelm Ostry
EUC2
2010 TARo: Trusted Anonymous Routing for MANETs
abstract
The currently proposed anonymous routing mechanisms for Mobile Ad hoc Networks enable network entities to anonymously and securely communicate with each other. However, protocols that provide a high level of anonymity generally have poor scalability due to delays and overhead introduced by cryptographic operations, while other approaches sacrifice anonymity to achieve better performance. In this paper, we propose a novel anonymous routing protocol that provides improved anonymity and security while achieving similar or better performance, as compared to existing proposals. Our proposal achieves anonymity using a novel efficient solution for invisible implicit addressing based on keyed hash chain and security via a novel application of one-to-many Diffie-Hellman mechanism, used to exchange keys for symmetric encryption. The final contribution includes a mechanism to facilitate selection of a trusted route by verifying connections between intermediate nodes. We demonstrate the benefits of our proposal in comparison with previous approaches using analysis and simulation.
Jiefeng Chen 0002, Roksana Boreli, Vijay Sivaraman
EUC3
2010 Enabling a Bufferless Core Network Using Edge-to-Edge Packet-Level FEC
abstract
Internet traffic is expected to grow phenomenally over the next five to ten years, and to cope with such large traffic volumes, core networks are expected to scale to capacities of terabits-per-second and beyond. Increasing the role of optics for switching and transmission inside the core network seems to be the most promising way forward to accomplish this capacity scaling. Unfortunately, unlike electronic memory, it remains a formidable challenge to build even a few packets of integrated all-optical buffers. In the context of envisioning a bufferless (or near-zero buffer) core network, our contributions are threefold: First, we propose a novel edge-to-edge based packet-level forward error correction (FEC) framework as a means of combating high core losses, and investigate via analysis and simulation the appropriate FEC strength for a single core link. Second, we consider a realistic multi-hop network and develop an optimisation framework that adjusts the FEC strength on a per-flow basis to ensure fairness between single-and multi-hop flows. Third, we study the efficacy of FEC for various system parameters such as relative mixes of short-lived and long-lived TCP flows, and average offered link loads. Our study is the first to show that packet-level FEC, when tuned properly, can be very effective in mitigating high core losses, thus opening the doors to a bufferless core network in the future.
Arun Vishwanath, Vijay Sivaraman, Marina Thottan, Constantinos Dovrolis
INFOCOM2
2010 Experiments with wireless sensor networks for real-time athlete monitoring
abstract
Real-time physiological monitoring of athletes during sporting events has tremendous potential for maximizing player performance while preventing burn-out and injury, and also enabling exciting new applications such as referee-assist services and enhanced television broadcast. Emerging advanced monitoring devices have the right combination of light weight and unobtrusive size to allow truly non-intrusive monitoring during competition. However their small battery capacities, limited wireless ranges and susceptibility to body effects make real-time data extraction a challenge, particularly in sports with a large playing area. In this work we present the novel application of body area sensor networks to monitoring soccer players in a soccer field. We begin by outlining the challenges in experimental data collection and elaborate on the design choices we have made. Secondly, we show that the inherent characteristics of the operating environment lead to unacceptably high delays for direct transmissions from the players to the base stations. This leads to our third contribution, namely a multi-hop routing protocol that balances between the competing objectives of resource consumption and delay.
Ashay Dhamdhere, Alexander Kurusingal, Vijay Sivaraman, Alison J. Burdett
LCN4
2010 Modeling signal strength of body-worn devices
abstract
Body-wearable devices for physiological monitoring are fast becoming a reality-by 2014, 420 million wearable wireless devices are expected to be in use, of which 90% will be for sports and fitness applications. We envisage the use of ultra-lightweight wearable devices for monitoring athletes in field sports such as soccer for quantifying, assessing and improving game performance. To this end, in this paper we present an empirical characterization of the radio signal strength of sensor devices mounted on an athlete's body. We fit simple analytical models to our empirical data, highlighting how the signal degrades with distance as well as orientation of the body. Our model aids in improved protocol design and locationing services that take into account propagation effects of the human body.
Alexander Kurusingal, Ashay Dhamdhere, Vijay Sivaraman
LCN3
2010 Experimental study of mobility in the soccer field with application to real-time athlete monitoring
abstract
Live monitoring of athletes during sporting events can help maximise performance while preventing injury, and enable new applications such as referee-assist and enhanced television broadcast services. A major challenge is the extraction of athlete physiological data in real-time, since the radio range of body-worn sensor devices is limited, necessitating multi-hop routing mechanisms. However, little is known about the highly dynamic operating conditions on a soccer field under which communication protocols need to operate. In this work we conduct field experiments in which we outfit first-division soccer players with sensor devices and record their inter-connectivity during a real game. Our first contribution profiles the key properties of the dynamic wireless topologies arising in the soccer field, and highlights the consequences for routing mechanisms. We show that the topology is in general sparse, with short encounters and power-law distributed inter-encounters. Importantly, the co-ordinated movement of players in the field gives rise to significant correlations amongst links, an aspect that can potentially be exploited by routing. Our second contribution develops a model for generating synthetic topologies that mirror connectivity in a real soccer game, and can be used for simulation studies of routing mechanisms. Its novelty lies in explicitly modelling the underlying auto-correlation and cross-correlation properties of the links, from which derived measures such as inter-encounter times and neighbourhood distributions follow. Our study is an important first step towards understanding and modelling dynamic topologies associated with sports monitoring, and paves the way for the design of real-time routing algorithms for such environments.
Vijay Sivaraman, Sarthak Grover, Alexander Kurusingal, Ashay Dhamdhere, Alison J. Burdett
WiMob1
2010 Secure key loss recovery for network broadcast in single-hop wireless sensor networks
Syed Taha Ali, Vijay Sivaraman, Ashay Dhamdhere, Diethelm Ostry
Ad Hoc Networks2
2010 Optimal PET Protection for Streaming Scalably Compressed Video Streams With Limited Retransmission Based on Incomplete Feedback
abstract
For streaming scalably compressed video streams over unreliable networks, Limited-Retransmission Priority Encoding Transmission (LR-PET) outperforms PET remarkably since the opportunity to retransmit is fully exploited by hypothesizing the possible future retransmission behavior before the retransmission really occurs. For the retransmission to be efficient in such a scheme, it is critical to get adequate acknowledgment from a previous transmission before deciding what data to retransmit. However, in many scenarios, the presence of a stochastic packet delay process results in frequent late acknowledgements, while imperfect feedback channels can impair the server's knowledge of what the client has received. This paper proposes an extended LR-PET scheme, which optimizes PET-protection of transmitted bitstreams, recognizing that the received feedback information is likely to be incomplete. Similar to the original LR-PET, the behavior of future retransmissions is hypothesized in the optimization objective of each transmission opportunity. As the key contribution, we develop a method to efficiently derive the effective recovery probability versus redundancy rate characteristic for the extended LR-PET communication process. This significantly simplifies the ultimate protection assignment procedure. This paper also demonstrates the advantage of the proposed strategy over several alternative strategies.
Ruiqin Xiong, David S. Taubman, Vijay Sivaraman
IEEE Trans. Image Process.3
2009 Rate and End-to-End Delay Control for Multicast and Unicast Flows
abstract
There is growing evidence that a new generation of potentially high-revenue applications are emerging that can benefit from widespread multicast support in large IP networks. These applications, such as streaming video and interactive games, have inherent quality of service (QoS) requirements. Current methods of QoS provisioning have either scalability concerns or cannot guarantee end-to-end delay with acceptable packet loss unless bandwidth is over-provisioned. While low jitter guarantee is sufficient for streaming applications, maximum end-to-end delay is also required for interactive games. Previously, we presented a new holistic architecture for end-to-end QoS guarantee for unicast flows only in the core network based on several novel combined rate and end-to-end delay control algorithms. We also demonstrated the viability of this architecture and its advantage over Differentiated Services by implementing it in edge and core routers and monitoring the rate, end-to-end delay and packet loss of all flows in a six-node core network with long delay links. Here, we extend the architecture to include multicast flows and demonstrate that network operators can tune the architectural configuration parameters so as to fairly share the excess bandwidth between multicast and unicast flows.
Zvi Rosberg, Craig Russell, Vijay Sivaraman
ICC3
2009 Considerations for Sizing Buffers in Optical Packet Switched Networks
abstract
Optical packet switches of the foreseeable future are expected to have severely limited buffering capability, since storage of optical signals remains a difficult and expensive operation. Our observations in simulation of TCP and real-time traffic in networks with such small buffers have revealed regions of anomalous performance in which losses for real-time traffic become higher as buffers get larger. The detrimental impact of larger optical buffers is studied in this paper and three new contributions are made. First, we develop a Markov chain model that allows analytical computation of loss. Our model validates observations from simulation, and opens the doors to an analytical understanding of how various factors affect the anomaly. Second, we study the anomaly under realistic traffic mixes containing persistent and non-persistent TCP flows, and show that the traffic mix does not significantly alter the anomaly. Third, we show that larger diversity in packet size between TCP and real-time traffic increases the severity of the anomaly, and is an important consideration when sizing optical switch buffers, particularly since real-time and TCP ACK packets are significantly smaller than the TCP data packets. Our study informs switch manufacturers and network operators of factors to consider when selecting optical buffer sizes in order to achieve desired performance balance between TCP and real-time traffic.
Arun Vishwanath, Vijay Sivaraman, George N. Rouskas
INFOCOM2
2009 A Per-Hop Security Scheme for Highly Dynamic Wireless Sensor Networks
abstract
Certain popular wireless sensor network applications, including disaster recovery, battlefield communication and athlete monitoring, are characterized by extensive node mobility, intermittent contact between nodes and a highly dynamic network topology. Traditional routing protocols and security schemes are designed for essentially static networks and do not perform well in this case. This has given rise to a new multi-hop routing paradigm, that of ldquomobility-assistedrdquo routing in which nodes make strategic data store-and-forward decisions on a per-hop basis. In this paper we discuss the security challenges relevant to mobility-assisted routing and propose a scheme to secure data communication between nodes in highly mobile sensor networks. Our solution utilizes symmetric-key encryption to ensure data confidentiality and varies encryption key in a verifiable, non-forgeable manner to allow easy authentication. This scheme also provides data freshness, semantic security and per-hop encryption to enable secure data aggregation. To validate our basic assumptions and fine-tune our scheme, we collect and analyze link connectivity statistics from a dynamic sensor network application, athlete monitoring during a first-division university soccer club match. We show that our scheme is well-suited for certain dynamic environments and serves as an effective first step towards securing communications for mobile sensor networks.
Syed Taha Ali, Vijay Sivaraman, Ashay Dhamdhere
MASS2
2009 Transmission Power Control in Body Area Sensor Networks for Healthcare Monitoring
abstract
This paper investigates the opportunities and challenges in the use of dynamic radio transmit power control for prolonging the lifetime of body-wearable sensor devices used in continuous health monitoring. We first present extensive empirical evidence that the wireless link quality can change rapidly in body area networks, and a fixed transmit power results in either wasted energy (when the link is good) or low reliability (when the link is bad). We quantify the potential gains of dynamic power control in body-worn devices by benchmarking off-line the energy savings achievable for a given level of reliability.We then propose a class of schemes feasible for practical implementation that adapt transmit power in real-time based on feedback information from the receiver. We profile their performance against the offline benchmark, and provide guidelines on how the parameters can be tuned to achieve the desired trade-off between energy savings and reliability within the chosen operating environment. Finally, we implement and profile our scheme on a MicaZ mote based platform, and also report preliminary results from the ultra-low-power integrated healthcare monitoring platform we are developing at Toumaz Technology.
Shuo Xiao, Ashay Dhamdhere, Vijay Sivaraman, Alison J. Burdett
IEEE J. Sel. Areas Commun.3
2009 Packet pacing in small buffer optical packet switched networks
Vijay Sivaraman, Hossam A. ElGindy, David Moreland, Diethelm Ostry
IEEE/ACM Trans. Netw.1
2008 Algorithms for Transmission Power Control in Biomedical Wireless Sensor Networks
abstract
Wireless sensor networks are increasingly being used for continuous monitoring of patients with chronic health conditions such as diabetes and heart problems. As biomedical sensor nodes become more wearable, their battery sizes diminish, necessitating very careful energy management. This paper proposes feedback-based closed-loop algorithms for dynamically adjusting radio transmit power in body-worn devices, and evaluates their performance in terms of energy savings and reliability as the data periodicity and feedback time-scales vary. Using experimental trace data from body worn devices, we first show that the performance of dynamic power control is adversely affected at long data periods. Next for a given data period we show that modifying the transmit power at too long timescales (around a minute) reduces the efficacy of dynamic power control, while too short a time-scale (few seconds or less) incurs a high feedback signaling overhead. We therefore advocate an intermediate range of time-scales (when permitted by the data periodicity), typically in the few tens of seconds, at which the control algorithms should adapt transmit power in order to achieve maximal energy savings in body-worn sensor devices used for medical monitoring.
Ashay Dhamdhere, Vijay Sivaraman, Vidit Mathur, Shuo Xiao
APSCC2
2008 Experiments in Adaptive Power Control for Truly Wearable Biomedical Sensor Devices
abstract
Emerging body-wearable devices for continuous health monitoring are severely energy constrained and yet required to offer high communication reliability under fluctuating channel conditions. Such devices require very careful management of their energy resources in order to prolong their lifetime. In our earlier work we had proposed dynamic power control as a means of saving precious energy in off the-shelf sensor devices. In this work we experiment with a real body-wearable device to assess the power savings possible in a realistic setting. We quantify the power consumption against the packet loss and establish the feasibility of dynamic power control for saving energy in a truly-body-wearable setting.
Ashay Dhamdhere, Vijay Sivaraman, Alison J. Burdett
ISPA2
2008 Routers With Very Small Buffers: Anomalous Loss Performance for Mixed Real-Time and TCP Traffic
abstract
The past few years have seen researchers debate the size of buffers required at core Internet routers. Much of this debate has focused on TCP throughput, and recent arguments supported by theory and experimentation suggest that few tens of packets of buffering suffice at bottleneck routers for TCP traffic to realise acceptable link utilisation. This paper introduces a small fraction of real-time (i.e. open-loop) traffic into the mix, and discovers an anomalous behaviour: In this specific regime of very small buffers, losses for real-time traffic do not fall monotonically with buffer size, but instead exhibit a region where larger buffers cause higher losses. Our contributions pertaining to this phenomenon are threefold: First, we demonstrate this anomalous loss performance for real-time traffic via extensive simulations including real video traces. Second, we provide qualitative explanations for the anomaly and develop a simple analytical model that reveals the dynamics of buffer sharing between TCP and real-time traffic leading to this behaviour. Third, we show how various factors such as traffic characteristics and link rates impact the severity of this anomaly. Our study particularly informs all-optical packet router designs (envisaged to have buffer sizes in the few tens of packets) and network service providers who operate their buffer sizes in this regime, of the negative impact investment in larger buffers can have on the quality of service performance.
Arun Vishwanath, Vijay Sivaraman
IWQoS2
2008 A key loss recovery scheme for secure broadcasts in wireless sensor networks
abstract
Authenticity and secrecy of broadcast message content is important in wireless sensor networks deployed for battlefield control, emergency response, and natural resource management. Encryption of broadcast data requires the key to vary in time, typically via a key chain, so that a key compromised at a receiver does not compromise broadcast security for the entire network. An unfortunate consequence of time-varying keys is that a receiver that misses (due to packet loss) one or more keys from the chain cannot decrypt subsequent messages, thereby getting excluded from all broadcasts. In this paper we develop a scheme that allows receivers to recover from one or a few lost keys by having the transmitter probabilistically reuse old keys from the chain. Our scheme makes the broadcast system more robust to packet loss, at the expense of increasing vulnerability to compromised old keys. Analysis of our scheme shows how the trade-off can be controlled by tuning parameters, and a prototype implementation on a MicaZ mote testbed demonstrates the feasibility of our scheme in real sensor network platforms.
Syed Taha Ali, Vijay Sivaraman, Ashay Dhamdhere, Diethelm Ostry
PIMRC2
2008 Secure multi-hop network programming with multiple one-way key chains
abstract
Current network programming protocols provide an efficient way to update the program image running on sensor nodes without physical access to them. However, given the open environment in which sensor nodes are deployed, securing network programming is a challenging task. Existing work addressing this issue either lack consideration of securing multi-hop network programming protocols, or are not cost-efficient. To our knowledge, none of them have evaluated the power consumption. In this paper, we propose a novel scheme to secure multi-hop network programming protocols using multiple one-way hash chains. This scheme is resilient to malicious program image injection by the compromised nodes and it secures multi-hop propagation of program images for sensor nodes. Based on the most popular network programming protocol, Deluge, an overhead analysis on this schemes is given. In addition, our scheme is implemented in TinyOS and a performance evaluation in terms of latency and energy consumption is presented.
Hailun Tan, Sanjay K. Jha, Diethelm Ostry, John Zic, Vijay Sivaraman
WISEC5
2007 A Dynamic Stateful Multicast Firewall
abstract
Enterprises are faced with the challenge of enabling IP multicast applications without exposing their network to multicast denial-of-service attacks. Current practice is to use firewalls and manually configure them on a per-multicast-session basis. This imposes a high work-load on the network administrator, and severely reduces flexibility for end-users. In this paper, we propose and demonstrate a simple yet powerful multicast firewall algorithm that can, under most conditions, automatically distinguish unsolicited multicast packets and drop them to protect the network from denial-of-service attacks. Inspired by the "stateful" operation of unicast firewalls, our multicast firewall blocks unsolicited multicast packets by maintaining state information on multicast group membership and unicast interactions. We prototype our algorithm as a plug-in to Linux NetFilter, and present performance and scalability results from testing on a high-quality multicast video platform coupled with synthetic traffic from a network tester. Based on the prototype, we believe that it is feasible to build multicast firewalls that can, without manual intervention, and with minimal performance impact, protect the network against multicast attacks.
Vijay Sivaraman, Alex Krumm-Heller, Craig Russell
ICC2
2007 Confidential and Secure Broadcast in Wireless Sensor Networks
abstract
Wireless sensor networks need broadcast for operations such as software updates, network queries, and command dissemination. Alongside ensuring authenticity of the source and data, keeping the broadcast data secret is vital in certain applications such as battlefield control, emergency response, and natural resource management. In this paper we propose and prototype a mechanism for ensuring confidentiality and authenticity of broadcast data in single-hop networks, and discuss possible extensions to multi-hop settings. Our scheme uses known low-complexity symmetric encryption techniques for confidentiality, while changing the encryption key on a per-packet basis in a verifiable but non-forgeable way to ensure authenticity. Message integrity, freshness, and semantic security are also provided, and the broadcast data can be dynamic and incrementally processed. We incorporate our security scheme into Deluge, the de facto network programming protocol in TinyOS, and quantify the cost in terms of broadcast data transfer time and node memory space on a TelosB mote based platform.
Jaleel Shaheen, Diethelm Ostry, Vijay Sivaraman, Sanjay K. Jha
PIMRC3
2006 Packet Pacing in Short Buffer Optical Packet Switched Networks
abstract
Abstract — In the absence of a cost-effective technology for storing optical signals, emerging optical packet switched (OPS) networks are expected to have severely limited buffering capability. This paper investigates the resulting impact on end-to-end loss and throughput, and proposes that the optical edge switches “pace ” packets into the OPS core to improve performance without adversely affecting end-to-end delays. In this context, our contributions are three-fold. We first evaluate the impact of short buffers on the performance of real-time and TCP traffic. This helps us identify short-time-scale burstiness as the major contributor to performance degradation, so we propose that the optical edge switches pace the transmission of packets into the OPS core while respecting their delay-constraints. Our second contribution develops algorithms of poly-logarithmic complexity that can perform optimal real-time pacing of high data rate traffic. Lastly, we show via simulations of a realistic network carrying real-time traffic that pacing can significantly reduce losses at the expense of a bounded increase in end-to-end delay. The loss-delay trade-off mechanism provided by pacing can help achieve desired OPS network performance. I.
Vijay Sivaraman, Hossam A. ElGindy, David Moreland, Diethelm Ostry
INFOCOM1
2006 Deterministic end-to-end delay guarantees with rate controlled EDF scheduling
Vijay Sivaraman, Fabio M. Chiussi, Mario Gerla
Perform. Evaluation1
2001 End-to-End Statistical Delay Service under GPS and EDF Scheduling: A Comparison Study
abstract
Generalized processor sharing (GPS) has gained much popularity as a simple and effective scheduling mechanism for the provisioning of quality of service (QoS) in emerging high-speed networks. For supporting deterministic end-to-end delay guarantees, GPS is known to be sub-optimal in comparison to the earliest deadline first (EDF) scheduling discipline; nevertheless it is often prefered over EDF due to its simplicity. In this paper, using analytical frameworks developed in the literature, we reassess the merits of GPS as compared to EDF in the setting of statistical delay service. Our contributions are threefold. The statistical frameworks in the literature enable the aggregate losses (i.e., delay bound violations) at an EDF scheduler to be estimated-our first contribution, therefore, is to develop a mechanism that allows the aggregate losses to translate to per-flow guarantees. This is achieved by means of a simple packet discard scheme that drops packets fairly then delay violations are imminent at the EDF scheduler. The discard mechanism has a constant complexity and is feasible for implementation in current packet switches. The ability to derive the per-flow guarantees from the aggregate allows a direct comparison between EDF and GPS-our next contribution, therefore, is to show for various traffic mixes with given per-flow loss constraints that EDF offers consistently larger schedulable regions than GPS, both in the single-hop and multi-hop setting. As our final contribution, we argue that the use of GPS for statistical delay support is inherently problematic. We demonstrate that achieving the maximal schedulable regions under GPS could necessitate dynamic resynchronization of the GPS weights, an operation considered infeasible for practical implementation.
Vijay Sivaraman, Fabio M. Chiussi, Mario Gerla
INFOCOM1
2000 Providing End-to-End Statistical Delay Guarantees with Earliest Deadline First Scheduling and Per-Hop Traffic Shaping
abstract
This paper develops a framework for statistically guaranteeing end-to-end delay bounds to leaky-bucket-constrained flows transporting real-time traffic in a network of switches using earliest deadline first (EDF) packet scheduling and per-hop traffic shaping. We first analyze the delay-bound violation probabilities at an isolated EDF scheduler fed by fluid source processes generating extremal dual-leaky-bucket-regulated traffic. We compute a close upper bound by applying the Benes approach to an equivalent hypothetical system derived from the real one. We then extend the analysis to the end-to-end scenario in the presence of traffic re-shaping at each node in the network. We compare the analytical results with simulations, and show that the match is very close. We also investigate the advantages of smoothing the traffic at the ingress to the network, and propose a simple choice of smoothing parameters, which perform very well. Using realistic traffic parameters, we compare the schedulable region of our statistical framework with that of the corresponding deterministic framework, and demonstrate that the statistical framework allows tremendous improvements in network utilization, even for very low delay-violation probabilities. The framework developed in this paper is therefore highly useful in practical packet networks to provide quality of service to real-time applications in the form of statistical, rather than deterministic, end-to-end delay bounds.
Vijay Sivaraman, Fabio M. Chiussi
INFOCOM1
2000 A reservation protocol for broadcast WDM networks and stability analysis
Vijay Sivaraman, George N. Rouskas
Comput. Networks1
1999 Statistical Analysis of Delay Bound Violations at an Earliest Deadline First (EDF) Scheduler
Vijay Sivaraman, Fabio M. Chiussi
Perform. Evaluation1
1998 Controlled Multimedia Wireless Link Sharing via Enhanced Class-Based Queueing with Channel-State-Dependent Packet Scheduling
abstract
A key problem in transporting multimedia traffic across wireless networks is a controlled sharing of the wireless link by different packet streams. So far this problem has been treated as that of providing support for quality of service in time division multiplexing based medium access control protocols (MAC). Adopting a different perspective to the problem, this paper describes an approach based on extending the class-based queueing (CBQ) based controlled hierarchical link sharing model proposed for the Internet. Our scheme enhances CBQ, which works well in wired links such as point-to-point wires of fixed bandwidth, to also work well with wireless links based on radio channels that are (i) inherently shared on-demand among multiple radios, and (ii) are subject to highly dynamic bandwidth variations due to spatially and temporally varying fading with accompanying burst errors. The proposed scheme is based on combining a modified version of CBQ with channel-state dependent packet scheduling.
Christina Fragouli, Vijay Sivaraman, Mani Srivastava 0001
INFOCOM2
1997 HiPeR-l: High Performance Reservation Protocol with look-Ahead for Broadcast WDM Networks
abstract
We consider the problem of coordinating access to the various channels of a single-hop WDM network. We present HiPeR-l, a new reservation protocol specifically designed to overcome the potential inefficiencies of operating in environments with non-negligible processing, tuning, and propagation delays. HiPeR-l differs from previous reservation protocols in that each control packet makes reservations for all data packets waiting in a node's queues, thus significantly reducing the control overhead. Packets are scheduled for transmission using algorithms that can effectively mask the tuning times. HiPeR-l also uses pipelining to mask the processing times and propagation delays. We use Markov chain theory to obtain a necessary and sufficient condition for the stability of the protocol. The stability condition provides insight into the factors affecting the operation of the protocol, such as the degree of load balancing across the various channels, and the quality of the scheduling algorithms. The analysis is fairly general, as it holds for MMBP-like arrival processes with any number of states, and for non-uniform destinations.
Vijay Sivaraman, George N. Rouskas
INFOCOM1
1997 Packet scheduling in broadcast WDM networks with arbitrary transceiver tuning latencies
abstract
We consider the problem of scheduling packet transmissions in a broadcast, single-hop wavelength-division multiplexing (WDM) network, with tunability provided only at one end. Our objective is to design schedules of minimum length to satisfy a set of traffic requirements given in the form of a demand matrix. We address a fairly general version of the problem as we allow arbitrary traffic demands and arbitrary transmitter tuning latencies. The contribution of our work is twofold, First we define a special class of schedules which permit an intuitive formulation of the scheduling problem. Based on this formulation we present algorithms which construct schedules of length equal to the lower bound provided that the traffic requirements satisfy certain optimality conditions. We also develop heuristics which, in the general case, give schedules of length equal or very close to the lower bound. Secondly, we identify two distinct regions of network operation. The first region is such that the schedule length is determined by the tuning requirements of transmitters; when the network operates within the second region however, the length of the schedule is determined by the traffic demands, not the tuning latency. The point at which the network switches between the two regions is identified in terms of system parameters such as the number of nodes and channels and the tuning latency. Accordingly, we show that it is possible to appropriately dimension the network to minimize the effects of even large values of the tuning latency.
George N. Rouskas, Vijay Sivaraman
IEEE/ACM Trans. Netw.2
1996 On the Design of Optimal TDM Schedules for Broadcast WDM Networks
abstract
We consider the problem of scheduling packet transmissions in single-hop WDM networks, with tunability provided only at one end. Our objective is to design schedules of minimum length for a given traffic demand matrix. The contribution of our work is twofold. First we define a special class of schedules which permit an intuitive formulation of the scheduling problem. We then present algorithms which construct schedules of length equal to the lower bound provided that certain optimality conditions are satisfied. We also develop heuristics which, in the general case, give schedules of length equal or very close to the lower bound. Secondly, we identify two distinct regions of network operation. In the first region the schedule length is determined by the tuning requirements, while in the second it is determined by the traffic demands. The point at which the network switches between the two regions is identified in terms of the number of nodes and channels, and the tuning latency. Accordingly, we show that it is possible to appropriately dimension the network to offset the effects of even large values of tuning latency.
George N. Rouskas, Vijay Sivaraman
INFOCOM2