Sándor Laki

dblp:78/8261 · DBLP profile ↗
← Back
41ranked-venue papers
7as first author
24since 2021 · last 2026
0000-0002-8875-5330ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 27 · 6 first-author · 15 since 2021Software engineering, systems software and programming languages · 8 · 8 since 2021Artificial intelligence and machine learning · 2Systems, architecture and hardware · 1Theory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2026 Energy-Efficient Resource Management Optimization Using Programmable Switches
Károly Kecskeméti, Jorge Andrés Brito, Gergo Gombos, Sándor Laki, José Ignacio Moreno, Luis M. Contreras 0001
ICC4
2026 A QoE-Assessment Middlebox for Real-Time Video Stream Monitoring
Asif Abaidullah, Sándor Laki
NetSoft2
2026 Edge-Assisted Trust Establishment and Pre-Authentication for 6G Networks
abstract
6G network is expected to support a high number of devices, which require adopting decentralized architectures and lightweight protocols, to allow the systems to effectively meet the demands of such networks. However, the authentication is performed only after an initial connection has already been established, leaving the network exposed to unauthenticated devices during the initial phase. In this paper, we propose an edge-assisted trust establishment scheme for B5G/6G networks that shifts the pre-authentication process closer to the edge, particularly when establishing end-to-end communication with an external Application Function. It starts the trust establishment process from the initial access request sent by the User Equipment (UE). This enables the gNB to verify UE attributes before engaging in full authentication procedures. Such an approach will reduce the attack surface and unnecessary resource usage. The proposed scheme has been evaluated, and the results demonstrated that the proposed approach is both secure and efficient in edge nodes. A formal verification of the scheme has also been conducted using the TAMARIN prover, which confirmed its security guarantees.
Mohammed B. Alshawki, Janneke Van Oosterhout, Yehao Zhou, Daniel Hindemburg de Miranda Marques, Sándor Laki, Péter Ligeti, Dalton C. G. Valadares, Shahid Raza
NetSoft5
2026 GraphXDP: Programmable In-Kernel Packet Dispatching via Dynamic Network Function Graphs
Károly Kecskeméti, Sándor Laki, Géza Szabó
NetSoft2
2026 EnergyTracer: Energy Analysis of Packet Processing Events in DPDK-based Applications
Mohsen Memarian, Andreas Kassler, Karl-Johan Grinnemo, Sándor Laki, Gergely Pongrácz, Johan Forsman
NetSoft4
2026 End-to-end latency assurance for distributed augmented reality over programmable 6G networks: A DESIRE6G demonstration
abstract
6G networks are expected to deliver ultra-low latency, high reliability, and real-time intelligence for emerging services such as interactive Augmented Reality (AR), autonomous robotics, and digital twins. Achieving these requirements in practice demands tight coordination between networking, computing, and control domains, spanning RAN, transport, edge, and cloud. However, current 5G deployments lack pervasive telemetry, fine-grained observability, and automated control mechanisms capable of reacting at the time scales required by latency-sensitive applications. This paper presents a full integrated demonstration of DESIRE6G, a cloud-native 6G-ready architecture that leverages programmable data planes with P4 for flexible routing and telemetry using an implementation of novel data plane protocols, achieves distributed optimization of service deployment and runtime monitoring and reconfiguration via secure multi-agent systems (MAS), combined with intent-based orchestration layer for end-to-end service assurance. The system is validated on the federated ARNO testbed using a real distributed AR application involving a remotely-controlled drone as a User-Equipment that is equipped with a camera streaming a live video through the DESIRE6G network to a Kubernetes edge cluster that executes serverless inference functions for object detection and recognition, the video is then augmented with object information and shown on a Quest 3 AR headset. The MAS monitors the end-to-end latency in real time through P4 Telemetry and responds to changes in network conditions by reconfiguring the affected segments, while the Kubernetes monitoring provides real-time visibility and scalability across different segments. Overall, three hierarchical service assurance loops are demonstrated: (i) In-Network Control (INC) executing microsecond-scale congestion recovery in the P4 data plane, (ii) Infrastructure Management Layer (IML) performing millisecond-scale function migration and scaling, and (iii) MAS-driven cross-domain optimization operating at sub-second time scales to resolve RAN latency anomalies. Evaluation results show stable end-to-end latency in the 15–25 ms range in steady-state conditions, with fast recovery during induced congestion ≤ 1 . 5 ms data plane reroute via P4 INC.
Francesco Paolucci, Emilio Paolini, Faris Alhamed, Massimo Satler, Domenico Uomo, Michelangelo Guaitolini, Pol González, Marc Ruiz 0001, Luis Velasco 0001, Sándor Laki, Dávid Kis, Gergely Pongrácz, Attila Mihály, Anestis Dalgkitsis, Chrysa Papagianni, Anastassios Nanos, Stephen Parker, Vincent Lefebvre, M. Angoustures, Juan Jose Vegas Olmos, Andrea Sgambelluri
Comput. Networks10
2025 Power Efficiency of a Hybrid 5G gNB Data Plane Combining SmartNICs and Commodity Servers
abstract
Power efficiency is a growing concern in softwarized 5G gNBs due to increasing energy costs and carbon emissions. While SmartNICs offer low-power acceleration for packet processing, they struggle with complex operations, often requiring offloading to servers, which raises power usage. This study evaluates the performance and power consumption when dividing 5G gNB data plane tasks between SmartNICs and a DPDK-enabled host, comparing flow-based and function-based task allocation methods. We introduce an adaptive CPU power management strategy that adjusts CPU power states based on traffic. Results show that deploying five SmartNICs with function-based partitioning, which retains packet buffering on the host and offloads header decapsulation, insertion, and lookup-table operations to the SmartNICs, delivers a throughput of 109 MPPS, which is 173% more than a SmartNIC-only setup and reduces latency by 70% compared with a host-only setup. Adaptive power management lowers total power consumption by 12.5% in the optimal partitioning while preserving high throughput and low latency.
Mohsen Memarian, Andreas Kassler, Karl-Johan Grinnemo, Sándor Laki, Gergely Pongrácz, Johan Forsman
MSWiM4
2025 Ensemble Graph Attention Networks for Cellular Network Analytics: From Model Creation to Explainability
abstract
In automated radio network control, understanding the effect of different factors on network performance is crucial. Although there are machine learning (ML) solutions that can reliably anticipate network performance expressed as key performance indicator (KPI) values, these models are typically black-box or provide only partial explanations. Most approaches are based on flat data structures and cannot exploit the graph nature of the data, being unable to quantify neighbors’ impact. In this paper, we propose a new graph neural network-based model called Ensemble Graph Attention Network (Ensemble GAT) for network KPI prediction. We show that the proposed model results in better or comparable KPI prediction performance to the state-of-the-art while also carrying information about links between neighboring cells. In addition to model creation, we investigate how explainable AI solutions can be used to provide root-cause explanations for network KPI degradation. To generate feature attributions, we introduce an adapted version of GraphLime that works with ensemble models. In addition, we propose a new technique called Neighbor Perturbation to identify the neighboring cells that have the most significant impact on KPI prediction. We demonstrate the effectiveness of these models on both synthetic and real-world datasets.
Katalin Hajdú-Szücs, Péter Vaderna, Zsófia Kallus, Péter Kersch, János M. Szalai-Gindl, Sándor Laki
IEEE Trans. Netw. Serv. Manag.6
2024 P4-MTAGG - a Framework for Multi-Tenant P4 Network Devices
abstract
The current P4 programmability model assumes that a P4 programmable device is owned and controlled by a single tenant. However, in typical NFV scenarios, support for multiple tenants is desirable. When each tenant may want to deploy their own P4 pipeline offering different network functions (NF), supporting multiple co-existing tenant pipelines on a single platform is difficult because it requires pipeline merging, control plane support, and resource management of the platform. In this paper, we present P4-MTAGG, a novel framework for flexibly deploying multiple P4 programmable NFs on a programmable match-action pipeline while supporting multiple tenants. P4-MTAGG consists of i) novel compiler-add-ons for automatic merging multiple P4-pipelines, ii) p4runtime-proxy to allow for control plane access of the aggregated pipelines together with policy-based resource management for the P4 target, and iii) orchestrator to automate the provisioning of a network node utilizing aggregation either in a simulated or real hardware environment. In this demo, we show how P4-MTAGG aggregates multiple NFs of varying complexity in Mininet. The user can orchestrate the aggregation process through a GUI. The per-tenant traffic is routed through the set of NFs using segment routing. Through the GUI, the user can instruct the p4runtime-proxy to enforce per-tenant bandwidth limits, which configure the per-tenant available resources in the data plane.
Fabian Brisch, Andreas Kassler, Sándor Laki, Péter Hudoba
CNSM3
2024 Extensible FRER Security Testbed in a Box
abstract
Time-Sensitive Networking (TSN) is expected to provide reliable, low-latency communication for critical systems. Leveraging the Frame Replication and Elimination for Reliability (FRER) protocol, it protects against packet loss by replicating individual packets and delivering them on disjoint forwarding paths. FRER does not contain any in-built security solutions, and several FRER-related security vulnerabilities have recently been identified that could undermine TSN’s ultimate goal of providing extreme reliability. In this paper, we introduce a comprehensive security-focused testbed for analyzing FRER vulnerabilities. Our self-contained setup employs open and adaptable components, runnable on a single server, ensuring flexibility and accessibility. Leveraging eBPF/XDP, it efficiently implements FRER’s data plane functionalities, accommodating both fast-path and slow-path attacks. Parameters like delay, jitter, loss rate, and bandwidth are easily customizable. We validate the testbed’s effectiveness with various attack scenarios.
Károly Kecskeméti, Csaba Györgyi, Peter Vörös, Géza Szabó, Sándor Laki
NetSoft5
2023 Optimizing Asynchronous Extern Execution in Programmable Software Data Planes
abstract
P4 has gained a significant attention as a programming language for describing target-independent packet processing. It supports a diverse hardware and software targets through various architecture models that declare external functions called externs representing target-specific functionalities. These externs may require specific or dedicated resources (e.g., cryptography co-processor, FPGA, etc.) for increased processing speed. In order to process tasks in bulk mode, packet processing may need to be temporarily suspended, while waiting for the function to return. Linear execution of the packet processing pipeline implemented by most P4 software targets cannot efficiently handle such situations. Asynchronous packet processing has been proposed to solve this issue by enabling to serve incoming packets while others are processed by an extern. In this paper, we explore existing approaches for extern execution in software data planes and propose a new lightweight asynchronous method for offloading extern execution to dedicated resources, such as cryptography coprocessors, which perform the extern computations. Our analysis show that the propose method can significantly improve the performance of extern execution in various use cases like IPsec, simple encryption and other small tasks and has negligible overhead compared to a prior solution. We also demonstrate that our method has clear benefits on constrained hardware (PcEngines APU single board computer) where the overhead of extern execution has bigger impact on the overall performance and prior approaches are not practical.
Péter Hudoba, Róbert Kitlei, Sándor Laki, Peter Vörös
GLOBECOM3
2023 In-Network Quality Control of IP Camera Streams
abstract
Manufacturing processes are often monitored by IP cameras. The generated video streams can be transferred via a wireless link to be processed and used by remote industrial controllers that manage and configure the industrial task in real-time. However, the link has limited bandwidth and is not capable of transmitting the aggregated traffic of all the IP cameras. Moreover, the platform provider of the remote controller (e.g., cloud) might charge extra fees for high volumes of network traffic. To optimize the data transport, we propose an in-network video quality control method for IP camera streams that drops non-essential frames from temporally irrelevant IP camera streams even when bandwidth is available. Our solution introduces a high-level API through which the operator can define which camera streams are needed with high quality at which actuator positions/states of the industrial process. Our method assumes an aggregation point that monitors the actuators' states and reduces the quality of camera streams that are not important for the control process, selectively dropping a set of video frames. We have implemented a P4-based prototype of the aggregation point and show that the remote controller can be fed with high-quality video streams while meeting bandwidth limitations and potentially saving data transfer costs without modifying the end-points.
Csaba Györgyi, Károly Kecskeméti, Peter Vörös, Sándor Laki, Géza Szabó
MobiHoc4
2023 In-Network Security Applications with P4RROT
abstract
Computer networks have become a key infrastructure for many different business domains. Ensuring the security of such interoperable systems is essential in many areas. The emergence of in-network computing and data plane programmability has opened the door to novel security approaches. Although the logic behind most novel solutions is simple, their implementation in P4 is often complex for a non-domain expert or requires problem-specific languages and code generators. Existing in-network approaches only solve specific subproblems and are not general purpose. In this paper, we show how the open-source P4 code generator called P4RROT can simplify the implementation of various in-network security applications. To demonstrate its applicability, we reproduce three recent P4-based security methods. During the implementation, we extended P4RROT with new primitives needed for such applications and also added support for Intel Tofino ASICs. The complexity of the corresponding P4RROT codes is a magnitude lower than the investigated original P4 programs.
Károly Kecskeméti, Csaba Györgyi, Peter Vörös, Sándor Laki
MobiHoc4
2023 Towards extreme network KPIs with programmability in 6G
abstract
6G's superpower must be simplicity, which should not be viewed as a constraint, but rather as the organic outcome of using the most advanced technologies at our disposal. Programmability in the data plane, cloud-native features like automatic scaling and failover, transparent acceleration of both network functions and applications and AI-driven optimizations are already present. We only need to integrate these different innovations into a consistent architecture and offer a simple yet powerful solution for the very different applications that would use future mobile networks. The application space is getting more and more heterogeneous, e.g., legacy Internet-based services still using the good old TCP protocol, future media services relying on multipath transport - always utilizing the best available connection, or control applications of robots or drones requiring extreme low and stable latency. The different applications will require very different Key Performance Indicators (KPIs) from the network. In this paper, we present a novel architecture called DESIRE6G (D6G) architecture that aims to fulfill these requirements by integrating the key technological innovations mentioned above. Besides supporting the diverse KPIs of future applications, the novel architecture should also simplify the mobile network itself by promoting modularity and service-based network function selection which can replace traditional control plane centric solutions, e.g., for handover.
Gergely Pongrácz, Attila Mihály, István Gódor, Sándor Laki, Anastassios Nanos, Chrysa Papagianni
MobiHoc4
2023 Toward Highly Reliable Programmable Data Planes: Verification of P4 Code Generation
abstract
Data plane programming gained much attention in the past years, having a fast-growing community both in academia and industry. Many tools have emerged to simplify and/or help the development of reliable data plane programs, including fuzzing, formal verification, and different code generators. However, even the tools themselves must be verified to meet the most stringent dependability requirements. In this paper, we investigate various tools and methods to verify code generators leveraging P4 through the example of P4RROT (an open source code generator focusing on the application layer). We show that our approach is efficient and can indeed successfully find bugs. We identify two bugs and propose reusable ideas, such as the use of ghost code.
Csaba Györgyi, Sándor Laki, Stefan Schmid 0001
NetSoft2
2023 Hybrid P4 Programmable Pipelines for 5G gNodeB and User Plane Functions
abstract
This paper focuses on hybrid pipeline designs for User Plane Function and next-generation NodeB leveraging target-specific features and an insightful discussion of P4 and target challenges and limitations. The entire or disaggregated UPF runs on P4 targets and allocates packet processing data paths in P4 hardware or DPDK/x86 software based on flow characteristics (e.g., heavy hitters) and QoS requirements (e.g., low-latency slices). For the hybrid gNodeB, most packet processing is executed in commodity Tofino hardware, while unsupported functions such as Automatic Repeat Request and cryptography are performed in DPDK/x86. We show that our hybrid UPF improves the scalability by 18× and reduces latency up to 50%. The results also suggest that careful traffic allocation to pipeline targets is required to optimize each target's strength and avoid processing delays. Finally, we demonstrate a QoS-oriented application of the hybrid UPF and present gNodeB buffer service benchmarks.
Suneet Kumar Singh, Christian Esteve Rothenberg, Jonatan Langlet, Andreas Kassler, Peter Vörös, Sándor Laki, Gergely Pongrácz
IEEE Trans. Mob. Comput.6
2022 Active Queue Management on the Tofino programmable switch: The (Dual)PI2 case
abstract
The excess buffering of packets in network elements, also referred to as bufferbloat, results in high latency. Considering the requirements of traffic generated by video conferencing systems like Zoom, cloud rendered gaming platforms like Google Stadia, or even video streaming services such as Netflix, Amazon Prime and YouTube, timeliness of such traffic is important. Ensuring low latency to IP flows with a high throughput calls for the application of Active Queue Management (AQM) schemes. This introduces yet another problem as the co-existence of scalable and classic congestion controls leads to the starvation of classic TCP flows. Technologies such as Low Latency Low Loss Scalable Throughput (L4S) and the corresponding dual queue coupled AQM, DualPI2, provide a robust solution to these problems. However, their deployment on hardware targets such as programmable switches is quite challenging due to the complexity of algorithms and architectural constraints of switching ASICs. In this study, we provide proof of concept implementations of two AQMs that enable the co-existence of scalable and traditional TCP traffic, namely DualPI2 and the preceding single-queue PI2 AQM, on an Intel Tofino switching ASIC. Given the fixed operation of the switch’s traffic manager, we investigate to what extent it is possible to implement a fully RFC-compliant version of the two AQMs on the Tofino ASIC. The study shows that an appropriate split between control and data plane operations is required while we also exploit fixed functionality of the traffic manager to support such solutions.
Gergo Gombos, Maurice Mouw, Sándor Laki, Chrysa Papagianni, Koen De Schepper
ICC3
2022 NETREACT: Distributed Event Detection in Sensor Data Streams with Disaggregated Packet Processing Pipelines
abstract
A new phenomenon called in-network computing has recently emerged with the aim of offloading calculations beyond the traditional task of packet forwarding to network switches. One of the most studied in-network computing applications is processing of sensor data streams. Existing works such as FastReact focus on solving this problem using flexible SmartNICs. In this paper, we propose NETREACT: an improved ASIC-oriented design for distributed event detection in sensor data streams to achieve a disaggregated processing pipeline. In contrast to existing approaches, NETREACT distributes the event detection task among a set of switches while leveraging the capabilities of the Intel Tofino platform in terms of boosting throughput and reducing latency. The proposed event-rule disaggregation method has the advantage of overcoming the hardware resource constraints and improving the overall network performance.
Csaba Györgyi, Károly Kecskeméti, Hiba Mallouhi, Peter Vörös, Sándor Laki
NetSoft5
2022 In-Network Velocity Control of Industrial Robot Arms
Sándor Laki, Csaba Györgyi, József Peto, Peter Vörös, Géza Szabó
NSDI1
2022 DeepQoS: Core-Stateless Hierarchical QoS in Programmable Switches
abstract
Novel applications and network scenarios challenge existing traffic management strategies. Hierarchical Quality of Service (HQoS) provides a fine control of resource sharing and delay, but traditional HQoS solutions have challenging complexity that prevents their deployment in the traffic management engine of high-speed switches. Programmable switches have emerged to make the packet processing pipelines flexible and reconfigurable, but their traffic management capabilities still rely on fixed functions that cannot handle the complexity of traditional HQoS approaches. In this paper, we show how the extended programmability can help in addressing this challenge by the application of a fundamentally different algorithm. To emulate HQoS behavior we extend our core-stateless resource sharing framework called Per Packet Value (PPV) with a HQoS-packet marker architecture called DeepQoS. DeepQoS can be used to mark resource sharing policies of different layers simultaneously and effectively at a single point, e.g., ensuring the fair share of a household’s traffic within an access aggregation network, while also controlling the shares of its subflows. In the PPV framework, bottleneck scheduling is very simple and is unaware of flows and policies, which are encoded to Packet Values. DeepQoS can use these existing simple PPV schedulers without any change. To demonstrate the deployability of the proposed method, we have created the DeepQoS marker implementation in DPDK while redesigned and implemented our packet scheduler called Virtual Dual Queue Core Stateless Active Queue Management (VDQ-CSAQM) on a P4-programmable switch. Using extensive measurements we demonstrate the unique capabilities of DeepQoS to realize rich and deep HQoS.
Ferenc Fejes, Szilveszter Nádas, Gergo Gombos, Sándor Laki
IEEE Trans. Netw. Serv. Manag.4
2021 Building an Internet Router with P4Pi
abstract
Building an Internet Router is a popular, hands-on project used to teach computer networks. However, there is currently no hardware target that allows students to develop the project in P4 without incurring significant cost or encountering FPGA knowledge barriers. This paper presents P4Pi as a target for the Building an Internet Router project. P4Pi is a platform for developing, testing, and evaluating P4 programs on a Raspberry Pi device. We describe the architecture of the router project on P4Pi, and discuss the practical aspects of running it as a class project. The P4Pi-based router project is low-cost and easy to adopt, enabling students to focus on their P4 programming skills and to evaluate their designs on a physical target through interoperability tests with their colleagues.
Radostin Stoyanov, Adam Wolnikowski, Robert Soulé, Sándor Laki, Noa Zilberman
ANCS4
2021 In-network Solution for Network Traffic Reduction in Industrial Data Communication
abstract
Industrial networks rely on standard real-time communication protocols like ProfiNet. These protocols are used for cyclic data exchange between IO devices and controllers. Since continuous monitoring of IO devices is important, a large number of data packets can be observed in such field networks between the IO devices and controllers. Each IO device cyclically reports its data or internal state to a controller at a predefined frequency. However, the reported data of most IO devices are not changing all the time, and thus the same bytes are transmitted multiple times. The majority of data packets is only used for checking the availability of such devices. In this paper, we consider an industrial environment where IO devices are located in an industrial site while controllers are running remotely (e.g., a software PLC in a private or edge cloud), and there is a radio link (e.g., 5G radio) between the two sides. We propose an in-network traffic reduction method that filters out the unnecessary data traffic at the two ends of the radio link, detects failure of devices and the radio link fast, and does not require any modification in the IO devices and controllers. Our solution is based on the cooperation of two P4-programmable networking elements deployed at the two sides of the radio link. Our preliminary measurements with P4-programmable hardware switches and emulated ProfiNet devices show that the method can significantly reduce the load on the radio link, while it could seamlessly be deployed in existing industrial environments.
Csaba Györgyi, Károly Kecskeméti, Peter Vörös, Géza Szabó, Sándor Laki
NetSoft5
2021 Toward In-Network Event Detection and Filtering for Publish/Subscribe Communication Using Programmable Data Planes
abstract
Industrial Internet of Things (I-IoT) applications require a large number of sensor data to be processed under tight delay and jitter constraints. In such applications, flexible event detection and fast reaction to critical events is an important building block. Traditional approaches use either proprietary networks and dedicated hardware or transmit sensor data towards processing elements in the Cloud or at the Network Edge, using distributed stream processing frameworks. For scalability, a large number of servers are needed and processing on commodity CPUs typically involves high and unpredictable latency. In this article, we explore how programmable data planes can be used to detect events flexibly and trigger customized and programmable actions directly from the switch program or the programmable network interface card (SmartNIC). We present FastReact-PS, an event-based publish/subscribe I-IoT processing framework in P4 language, which can be flexibly customized from the control plane. Together with stateful processing, FastReact-PS supports windowed time series analysis as well as complex event detection and processing based on Boolean logic directly in the data plane of newly emerging programmable networking devices. The logic can be adjusted dynamically from the control plane without the need for recompilation. We implement FastReact-PS in P4 and evaluate it on both a SmartNIC and a DPDK-based software switch running in user space. Our evaluation shows that the latency is reduced by one order of magnitude compared to end-host based approaches at significantly lower jitter while being scalable to processing up to 11 million events per second.
Jonathan Vestin, Andreas Kassler, Sándor Laki, Gergely Pongrácz
IEEE Trans. Netw. Serv. Manag.3
2021 Core-Stateless Forwarding With QoS Revisited: Decoupling Delay and Bandwidth Requirements
abstract
Network QoS, fairness and resource sharing control are not completely solved problems. Available solutions lack scalability due to maintaining flow state, require re-tuning if traffic changes, focus on a limited set of networking scenarios or require complex, centralized controllers and feedback loops. In this paper, we propose a core-stateless solution for closed network domains like access, enterprise and data center networks that handles resource sharing and provides guarantees for per-hop latency, independently. The proposed method enables controlled resource sharing by encoding the utility function of flows to Packet Value markings. This allows expressing resource sharing policies for all possible congestion situations, while operation is completely flow unaware inside the network. In addition, it also satisfies per-hop delay requirements for traffic flows independently. The separation of the delay requirements of the packets from their importance has not generally been possible by existing methods so far. The performance of the proposed method has thoroughly been analyzed by large number of simulations covering both static and dynamic scenarios and was implemented in a cloud-native virtual router implementing all the policies needed for a Broadband Network Gateway, showing good performance and better scalability than existing weighted queuing-based solutions.
Sándor Laki, Szilveszter Nádas, Gergo Gombos, Ferenc Fejes, Péter Hudoba, Zoltán Richard Turányi, Zoltán Kiss, Csaba Keszei
IEEE/ACM Trans. Netw.1
2020 On the Incompatibility of Scalable Congestion Controls over the Internet
Ferenc Fejes, Gergo Gombos, Sándor Laki, Szilveszter Nádas
Networking3
2019 Asynchronous Extern Functions in Programmable Software Data Planes
abstract
Target-independent packet processing languages support diverse hardware and software targets by generalizing over the set of primitive operations (extern-functions)available on the target. In P4, the language specification does not specify whether the invocation of an extern function is synchronous or asynchronous - supposedly synchronous by default. However, in some use cases, it makes more sense to invoke such functions in an asynchronous way and let the thread keep processing packets while the extern operation is being performed by a dedicated resource or accelerator device. In this paper, we propose a method for transparent description and efficient implementation of asynchronous extern function calls in P4-programmable software data planes. Our DPDK - based early prototype relies on the concept of coroutines used for saving packet contexts and manual switching between them. The overhead of the proposed solution is analyzed with a packet encryption case study.
Dániel Horpácsi, Sándor Laki, Peter Vörös, Máté Tejfel, Gergely Pongrácz, László Molnár
ANCS2
2019 Stateless Resource Sharing in Networks with Multi-Layer Virtualization
abstract
Network QoS, fairness and resource sharing control are open challenges of network slicing and virtualization in 5G and future networks providing ultra-high speed Internet access. Traditional stateful solutions either employ the one-size-fits-all approach to provide services to end-users, regardless of the requirements of vertical services, or require real-time network monitoring and complex feedback loops for ensuring appropriate resource allocation at any time. In the past years, different core-stateless resource sharing solutions as scalable alternatives to traditional stateful approaches have recently emerged for closed networking domains like access, enterprise and data center networks. In this paper, we extend the core-stateless Per Packet Value (PPV) framework with the support of resource sharing policies across multiple layers of virtualization where policies defined by both physical and virtual network operators should be taken into account at the same time. To this end, we propose a re-marking mechanism that re-calculates packet markings during the transition from one virtualization layer to another, ensuring the desired resource sharing among end-users, network slices and physical networks without the need of real-time monitoring and complex feedback loops in the network core. To the best of our knowledge, this is the first core-stateless proposal that offers resource sharing for multiple layers of virtualization.
Szilveszter Nádas, Zoltán Richard Turányi, Gergo Gombos, Sándor Laki
ICC4
2019 On Activity Identification Pipelines for a Low-Accuracy EEG Device
abstract
Analyzing EEG signals can help us make implications about the user's activities or even thoughts which can result in a myriad of applications. However, clinical EEG monitoring tools are expensive, often immobile and in need of professional supervision. Lately a couple of companies started the production of relatively cheap, easy-to-use, and mobile devices with significantly lower accuracy. In this paper we intend to investigate the usability of these devices in recognizing concrete activities e.g. winking, raising a hand etc. To this end, we provide a comprehensive analysis by applying several signal processing and machine learning methods to the time series recorded by the EMOTIV Epoc+. In addition to the usability analysis of these devices, we also propose a flexible and general pipeline for processing and classifying time series of EEG signals. We hope that this pipeline will make a contribution to researchers' work on this field.
Ákos Rudas, Sándor Laki
ICMLA2
2018 T4P4S: A Target-independent Compiler for Protocol-independent Packet Processors
abstract
Although the programmability of control planes has been thoroughly examined in the past years, only a limited number of studies go beyond the consideration that the data plane is only a collection of simple packet forwarding devices. Even OpenFlow, a popular, very expressive data plane programming language, is still restricted to supporting a subset of existing protocol headers. To overcome such limitations, new data plane programming models have recently emerged. One of the them is P4, a high-level language for programming packet processors that enables great flexibility in the description of packet structures and processing pipelines. In this paper, we propose T4P4S1, a multi-target compiler generating high performance switch programs from P4 descriptions. To support multiple targets, a networking hardware abstraction layer (NetHAL) is defined; the compiler generates a core switch code which is then linked with a target-specific NetHAL implementation. To avoid performance degradation, the boundaries of this separation should be chosen carefully, since the core program is only responsible for target-independent optimization, while the implementation of NetHAL should cover target-dependent enhancements. To analyze the performance, thorough measurements have been carried out, showing that the switch generated by T4P4S can easily scale beyond 100 Gbps.
Peter Vörös, Dániel Horpácsi, Róbert Kitlei, Dániel Leskó, Máté Tejfel, Sándor Laki
HPSR6
2018 The Price for Programmability in the Software Data Plane: The Vendor Perspective
abstract
The killer features of the next-generation 5G mobile standard, including mobile edge computing and network slicing, will be very difficult to support with traditional fixed-function network appliances. Rather, the 5G core will depend on programmable switches, which allow packet processing functionality to be reconfigured on the fly in order to deploy virtualized network functions and service chains instantaneously. With 5G on the close horizon, it has become crucial to identify the price for programmability in the software data plane, considering the expected complexity and scale of the next-generation mobile core. In this paper, we report on a multi-year data-plane scalability study we have conducted for a large mobile vendor. Our results paint a rather pessimistic picture on the current landscape of the programmable software data plane. We find that the prominent programmable switches either do not provide all the features necessary to implement 5G telco pipelines efficiently or struggle to meet the scale, and the performance operators have come to expect from conventional fixed-function appliances. The only exception, ESwitch, remains proprietary. We call for further work on data-plane scalability and sketch some directions for future research.
Tamás Lévai, Gergely Pongrácz, Péter Megyesi, Peter Vörös, Sándor Laki, Felician Németh, Gábor Rétvári
IEEE J. Sel. Areas Commun.5
2017 A Profile-Based Fast Port Scan Detection Method
Katalin Hajdú-Szücs, Sándor Laki, Attila Kiss 0001
ICCCI (1)2
2016 High speed packet forwarding compiled from protocol independent data plane specifications
abstract
P4 is a high level language for programming network switches that allows for great flexibility in the description of packet structure and processing, independent of the specifics of the underlying hardware. In this demo, we present our prototype P4 compiler in which the hardware independent and hardware specific functionalities are separated. We have identified the requisites of the latter, which form the interface of our target specific Hardware Abstraction Library (HAL); the compiler turns P4 code into a target independent core program that is linked to this library and invokes its operations. The two stage separation improves portability: to support a new architecture, only the hardware dependent library has to be implemented. In the demo, we demonstrate the flexibility of our compiler with a HAL for Intel DPDK, and show the packet processing and forwarding performance of compiled switches in different scenarios.
Sándor Laki, Dániel Horpácsi, Peter Vörös, Róbert Kitlei, Dániel Leskó, Máté Tejfel
SIGCOMM1
2015 The NOVI information models
Jeroen van der Ham, József Stéger, Sándor Laki, Yiannos Kryftis, Basil S. Maglaris, Cees T. A. M. de Laat
Future Gener. Comput. Syst.3
2014 Efficient Methods for Early Protocol Identification
abstract
To manage and monitor their networks in a proper way, network operators are often interested in automatic methods that enable them to identify applications generating the traffic traveling through their networks as fast (i.e., from the first few packets) as possible. State-of-the-art packet-based traffic classification methods are either based on costly inspection of the payload of several packets in each flow or on basic flow statistics without taking into account the packet content. In this paper, we consider an intermediate approach of analyzing only the first few bytes of the first (or first few) packet(s) of each flow and propose automatic, machine-learning-based methods with very low computational complexity and memory footprint. The performance of these techniques are thoroughly analyzed, showing that outstanding early classification accuracy can be achieved on traffic traces generated by a diverse set of applications (including P2P TV and file sharing) in a laboratory environment as well as on a real-world data set collected in the network of a large European ISP.
Béla Hullár, Sándor Laki, András György 0001
IEEE J. Sel. Areas Commun.2
2013 Balanced Neighbor Selection for BitTorrent-Like Networks
Sándor Laki, Tamás Lukovszki
ESA1
2013 On a balanced neighbor selection strategy for tracker-based peer-to-peer networks
abstract
In this paper we introduce a novel neighbor selection strategy for tracker-based peer-to-peer systems like BitTorrent that can uniformly distribute the load among peers in the network. Our method is based on a balanced multiple choice algorithm which takes into account not only the actual load of a peer, but the possibility as well that it will be selected in the future. We first analyze the properties of the constructed overlay topology theoretically, proving that, the maximum degree in the constructed graph is O(1) while the diameter remains O(ln n), with high probability, where n is the number of nodes. Considering a randomized upload policy, we show that the full distribution of b blocks on the network generated by our neighbor selection strategy takes O(b + ln n) phases only, with high probability, which is optimal up to a constant factor. This result improves the previous upper bound of O(b+(ln n)2) by Arthur and Panigrahy (SODA'06). In order to adapt our algorithm in real BitTorrent networks only a slight modification of the tracker is necessary without any change in the clients. Besides theoretical analysis, thorough simulations have been done to validate our algorithm and show its applicability in real BitTorrent networks. To this end, we have extended the BitTorrent implementation of the PeerSim simulation framework with a new tracker using our balanced neighbor selection strategy and demonstrated that it can speed up the file-sharing process in heavy loaded situations.
Sándor Laki, Tamás Lukovszki
P2P1
2012 On the spatial properties of internet routes
Péter Mátray, Péter Hága, Sándor Laki, Gábor Vattay, István Csabai
Comput. Networks3
2011 Early Identification of Peer-to-Peer Traffic
abstract
To manage and monitor their networks in a proper way, network operators are often interested in identifying the applications generating the traffic traveling through their networks, and doing it as fast (i.e., from as few packets) as possible. State-of-the-art packet-based traffic classification methods are either based on the costly inspection of the payload of several packets of each flow or on basic flow statistics that do not take into account the packet content. In this paper we consider the intermediate approach of analyzing only the first few bytes of the first (or first few) packets of each flow. We propose automatic, machine-learning-based methods achieving remarkably good early classification performance on real traffic traces generated from a diverse set of applications (including several versions of P2P TV and file sharing), while requiring only limited computational and memory resources.
Béla Hullár, Sándor Laki, András György 0001
ICC2
2011 Spotter: A model based active geolocation service
abstract
The localization of Internet hosts opens space for a wide scope of applications, from targeted, location aware content provision to localizing illegal content. In this paper we present a novel probabilistic approach, called Spotter, for estimating the geographic position of Internet devices with remarkable precision. While the existing methods use landmark specific calibration for building their internal models we show that the delay-distance data follow a generic distribution for each landmark. Hence, instead of describing the delay-distance space in a landmark specific manner our proposed method handles all the calibration points together and derives a common delay-distance model. This fundamental discovery indicates that, in contrast to prior techniques, Spotter is less prone to measurement errors and other anomalies such as indirect routing. To demonstrate the robustness and the accuracy of Spotter we test the performance on PlanetLab nodes as well as on a more realistic reference set collected by CAIDA explicitly for geolocation comparison purposes. To the best of our knowledge, we are the first to use this novel ground truth containing over 23000 network routers with their geographic locations.
Sándor Laki, Péter Mátray, Péter Hága, Tamas Sebok, István Csabai, Gábor Vattay
INFOCOM1
2011 On the network geography of the Internet
abstract
The geographic layout of the physical Internet inherently determines important network properties and traffic characteristics. To give insight into the geography of the Internet, we examine the spatial properties of the topology and routing. To represent the network we conducted a geographically dispersed traceroute campaign, and embedded the extracted topology into the geographic space by applying a novel IP geolocalization service, called Spotter. In this paper we present the frequency analysis of link lengths, quantify path circuitousness and explore the symmetry of end-to-end Internet routes.
Péter Mátray, Péter Hága, Sándor Laki, István Csabai, Gábor Vattay
INFOCOM3
2010 A model based approach for improving router geolocation
Sándor Laki, Péter Mátray, Péter Hága, István Csabai, Gábor Vattay
Comput. Networks1