David Zage

dblp:77/196 · also David John Zage · DBLP profile ↗
← Back
12ranked-venue papers
4as first author
0since 2021 · last 2017
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 4 first-authorSystems, architecture and hardware · 3Computer networks · 3Databases, data management, data science and information retrieval · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Databases, data mining, and information retrieval
1 paper
Indexing and storage engines · 100%
Computer networks
3 papers
Network management and operations · 30% Network measurement and analytics · 26% Internet architecture and protocols · 22%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Distributed systems · 100%
Network and information security
3 papers
Network security · 100%
Theoretical computer science
1 paper
Algorithms and data structures · 100%

Topics — the 10 heaviest of 13, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Indexing and storage engines
b-tree
0.212016
Anti-Persistence on Persistent Storage: History-Independent Sparse Tables and Dictionaries · PODS 2016
Distributed systems › fault tolerance
byzantine fault tolerance
0.112010
Steward: Scaling Byzantine Fault-Tolerant Replication to Wide Area Networks · IEEE Trans. Dependable Secur. Comput. 2010
Distributed systems
fault tolerance
0.112010
Steward: Scaling Byzantine Fault-Tolerant Replication to Wide Area Networks · IEEE Trans. Dependable Secur. Comput. 2010
Network security › attack resilience
attack mitigation
0.112008
A framework for mitigating attacks against measurement-based adaptation mechanisms in unstructured multicast overlay networks · IEEE/ACM Trans. Netw. 2008
Algorithms and data structures › memory hierarchy › external memory algorithms
cache-oblivious algorithms
0.112016
Anti-Persistence on Persistent Storage: History-Independent Sparse Tables and Dictionaries · PODS 2016
Network measurement and analytics
network coordinate system
0.112007
On the accuracy of decentralized virtual coordinate systems in adversarial networks · CCS 2007
Network security › intrusion detection and prevention
intrusion detection
0.112007
On the accuracy of decentralized virtual coordinate systems in adversarial networks · CCS 2007
Internet architecture and protocols
multicast
0.112006
Mitigating Attacks Against Measurement-Based Adaptation Mechanisms in Unstructured Multicast Overlay Networks · ICNP 2006
Content delivery and video streaming
overlay multicast
0.112006
Mitigating Attacks Against Measurement-Based Adaptation Mechanisms in Unstructured Multicast Overlay Networks · ICNP 2006
Distributed systems › replication › geo-replication
wide-area replication
0.012010
Steward: Scaling Byzantine Fault-Tolerant Replication to Wide Area Networks · IEEE Trans. Dependable Secur. Comput. 2010

Methods — techniques the papers use, named apart from their topics

packed-memory array · 0.5external-memory skip list · 0.5simulation · 0.1round-trip time measurement · 0.1outlier detection · 0.1emulation · 0.1prototype implementation · 0.1
YearPublicationVenuePosition
2017 An Architectural Vision for a Data-Centric IoT: Rethinking Things, Trust and Clouds
abstract
The Internet of Things (IoT) is producing a tidal wave of data, much of it originating at the network edge, from applications with requirements unmet by the traditional back-end Cloud architecture. To address the disruption caused by the overabundance of data, this paper offers a holistic data-centric architectural vision for the data-centric IoT. It advocates that we rethink our approach to the design and definition of key elements: that we shift our focus from Things to Smart Objects; grow Trust organically; and evolve back-end Clouds toward Edge and Fog clouds, which leverage data-centric networks and enable optimal handling of upstream data flows. Along the way, we wax poetic about several blue-sky topics, assess the status of these elements in the context of related work, and identify known gaps in meeting this vision.
Eve M. Schooler, David Zage, Jeff Sedayao, Hassnaa Moustafa, Moreno Ambrosin
ICDCS2
2016 Anti-Persistence on Persistent Storage: History-Independent Sparse Tables and Dictionaries
abstract
We present history-independent alternatives to a B-tree, the primary indexing data structure used in databases. A data structure is history independent (HI) if it is impossible to deduce any information by examining the bit representation of the data structure that is not already available through the API. We show how to build a history-independent cache-oblivious B-tree and a history-independent external-memory skip list. One of the main contributions is a data structure we build on the way---a history-independent packed-memory array (PMA). The PMA supports efficient range queries, one of the most important operations for answering database queries.
Michael A. Bender, Jonathan W. Berry, Rob Johnson 0001, Tom M. Kroeger, Samuel McCauley, Cynthia A. Phillips, Bertrand Simon 0001, Shikha Singh 0002, David Zage
PODS9
2013 Improving supply chain security using big data
abstract
Previous attempts at supply chain risk management are often non-technical and rely heavily on policies/procedures to provide security assurances. This is particularity worrisome as there are vast volumes of data that must be analyzed and data continues to grow at unprecedented rates. In order to mitigate these issues and minimize the amount of manual inspection required, we propose the development of mathematically-based automated screening methods that can be incorporated into supply chain risk management. In particular, we look at methods for identifying deception and deceptive practices that may be present in the supply chain. We examine two classes of constraints faced by deceivers, cognitive/computational limitations and strategic tradeoffs, which can be used to developed graph-based metrics to represent entity behavior. By using these metrics with novel machine learning algorithms, we can robustly detect deceptive behavior and identify potential supply chain issues.
David Zage, Kristin Glass, Richard Colbaugh
ISI1
2011 Applying game theory to analyze attacks and defenses in virtual coordinate systems
abstract
Virtual coordinate systems provide an accurate and efficient service that allows hosts on the Internet to determine latency to arbitrary hosts based on information provided by a subset of participating nodes. Unfortunately, the accuracy of the service can be severely impacted by compromised nodes providing misleading information. We define and use a game theory framework in order to identify the best attack and defense strategies assuming that the attacker is aware of the defense mechanisms. Our approach leverages concepts derived from the Nash equilibrium to model more powerful adversaries. We consider attacks that target the latency estimation (inflation, deflation, oscillation) and defense mechanisms that combine outlier detection with control theory to deter adaptive adversaries. We apply the game theory framework to demonstrate the impact and efficiency of these attack and defense strategies using a well-known virtual coordinate system and real-life Internet data sets.
Sheila Becker, Jeff Seibert, David Zage, Cristina Nita-Rotaru, Radu State
DSN3
2011 Removing the blinders: Using information to mitigate adversaries in adaptive overlays
abstract
The proliferation of peer-to-peer systems has led to the increasing deployment of dynamic, adaptive overlay networks that are designed to preserve application performance goals. While such networks provide increased performance and resiliency to benign faults, they are susceptible to attacks conducted by compromised overlay nodes, especially those targeting the adaptation mechanisms. In this work, we propose a lightweight, general solution to increase the resiliency of adaptive overlay networks. By locally aggregating and correlating network topology with system performance metrics such as latency and bandwidth, each node can check the consistency of the reported information and constrain the attacker's ability to lie about system metrics. As a result, each node can make better adaptation decisions. We demonstrate the susceptibility of adaptation mechanisms to malicious attacks and the utility of our solution through real-life deployments of mature, adaptive overlay-based systems.
David Zage, Chip Killian, Cristina Nita-Rotaru
NSS1
2010 Steward: Scaling Byzantine Fault-Tolerant Replication to Wide Area Networks
abstract
This paper presents the first hierarchical byzantine fault-tolerant replication architecture suitable to systems that span multiple wide-area sites. The architecture confines the effects of any malicious replica to its local site, reduces message complexity of wide-area communication, and allows read-only queries to be performed locally within a site for the price of additional standard hardware. We present proofs that our algorithm provides safety and liveness properties. A prototype implementation is evaluated over several network topologies and is compared with a flat byzantine fault-tolerant approach. The experimental results show considerable improvement over flat byzantine replication algorithms, bringing the performance of byzantine replication closer to existing benign fault-tolerant replication techniques over wide area networks.
Yair Amir, Claudiu Danilov 0001, Danny Dolev, Jonathan Kirsch, John Lane, Cristina Nita-Rotaru, Josh Olsen, David Zage
IEEE Trans. Dependable Secur. Comput.8
2010 Robust Decentralized Virtual Coordinate Systems in Adversarial Environments
abstract
Virtual coordinate systems provide an accurate and efficient service that allows hosts on the Internet to determine the latency to arbitrary hosts without actively monitoring all of the nodes in the network. Many of the proposed systems were designed with the assumption that all of the nodes are altruistic. However, this assumption may be violated by compromised nodes acting maliciously to degrade the accuracy of the coordinate system. As numerous peer-to-peer applications come to rely on virtual coordinate systems to achieve good performance, it is critical to address the security of such systems. In this work, we demonstrate the vulnerability of decentralized virtual coordinate systems to insider (or Byzantine) attacks. We propose techniques to make the coordinate assignment robust to malicious attackers without increasing the communication cost. We use both spatial and temporal correlations to perform context-sensitive outlier analysis to reject malicious updates and prevent unnecessary and erroneous adaptations. We demonstrate the attacks and mitigation techniques in the context of a well-known virtual coordinate system using simulations based on three representative, real-life Internet topologies of hosts and corresponding Round Trip Times (RTT). We show the effects of the attacks and the utility of the mitigation techniques on the virtual coordinate system as seen by higher-level applications, elucidating the utility of deploying robust virtual coordinate systems as network services.
David Zage, Cristina Nita-Rotaru
ACM Trans. Inf. Syst. Secur.1
2008 Experimental comparison of peer-to-peer streaming overlays: An application perspective
abstract
We compare two representative streaming systems using mesh-based and multiple tree-based overlay routing through deployments on the PlanetLab wide-area experimentation platform. To the best of our knowledge, this is the first study to compare streaming overlay architectures in real Internet settings, considering not only intuitive aspects such as scalability and performance under churn, but also less studied factors such as bandwidth and latency heterogeneity of overlay participants. Overall, our study indicates that mesh-based systems are superior for nodes with high bandwidth capabilities and low round trip times, while multi-tree based systems currently cope better with stringent real time deadlines under heterogeneous conditions.
Jeff Seibert, David Zage, Sonia Fahmy, Cristina Nita-Rotaru
LCN2
2008 A framework for mitigating attacks against measurement-based adaptation mechanisms in unstructured multicast overlay networks
Aaron Walters, David Zage, Cristina Nita-Rotaru
IEEE/ACM Trans. Netw.2
2007 On the accuracy of decentralized virtual coordinate systems in adversarial networks
abstract
Virtual coordinate systems provide an accurate and efficient service that allows hosts on the Internet to determine the latency to arbitrary hosts without actively monitoring all nodes in the network. Many of the proposed virtual coordinate systems were designed with the assumption that all of the nodes in the system are altruistic. However, this assumption may be violated by compromised nodes acting maliciously to degrade the accuracy of the coordinate system. As numerous peer-to-peer applications rely on virtual coordinate systems to achieve good performance, it is critical to address the security of such systems. In this work, we demonstrate the vulnerability of decentralized virtual coordinate systems to insider (or Byzantine) attacks. We propose techniques to make the coordinate assignment robust to malicious attackers without increasing the communication cost. We demonstrate the attacks and mitigation techniques in the context of a well-known distributed virtual coordinate system using simulations based on three representative, real-life Internet topologies of hosts and corresponding round trip times (RTT).
David Zage, Cristina Nita-Rotaru
CCS1
2006 Scaling Byzantine Fault-Tolerant Replication toWide Area Networks
abstract
This paper presents the first hierarchical Byzantine fault-tolerant replication architecture suitable to systems that span multiple wide area sites. The architecture confines the effects of any malicious replica to its local site, reduces message complexity of wide area communication, and allows read-only queries to be performed locally within a site for the price of additional hardware. A prototype implementation is evaluated over several network topologies and is compared with a flat Byzantine fault-tolerant approach
Yair Amir, Claudiu Danilov 0001, Jonathan Kirsch, John Lane, Danny Dolev, Cristina Nita-Rotaru, Josh Olsen, David Zage
DSN8
2006 Mitigating Attacks Against Measurement-Based Adaptation Mechanisms in Unstructured Multicast Overlay Networks
abstract
Many multicast overlay networks maintain application-specific performance goals such as bandwidth, latency, jitter and loss rate by dynamically changing the overlay structure using measurement-based adaptation mechanisms. This results in an unstructured overlay where no neighbor selection constraints are imposed. Although such networks provide resilience to benign failures, they are susceptible to attacks conducted by adversaries that compromise overlay nodes. Previous defense solutions proposed to address attacks against overlay networks rely on strong organizational constraints and are not effective for unstructured overlays. In this work, we identify, demonstrate and mitigate insider attacks against measurement-based adaptation mechanisms in unstructured multicast overlay networks. The attacks target the overlay network construction, maintenance, and availability and allow malicious nodes to control significant traffic in the network, facilitating selective forwarding, traffic analysis, and overlay partitioning. We propose techniques to decrease the number of incorrect or unnecessary adaptations by using outlier detection. We demonstrate the attacks and mitigation techniques in the context of a mature, operationally deployed overlay multicast system, ESM, through real-life deployments and emulations conducted on the PlanetLab and DETER testbeds, respectively.
Aaron Walters, David Zage, Cristina Nita-Rotaru
ICNP2