EDBT 2026 Demo / reviewers in the wild / expert
Amit Dvir
dblp:79/4531 · also Amit Z. Dvir
· DBLP profile ↗
53ranked-venue papers
11as first author
27since 2021 · last 2026
0000-0002-3670-0784ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 23 · 7 first-author · 13 since 2021Artificial intelligence and machine learning · 7 · 7 since 2021Security and privacy · 5 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Cloudy with a Chance of Anomalies: Dynamic Graph Neural Network for Early Detection of Cloud Services' User AnomaliesabstractIn today’s digital landscape, ensuring the security of cloud environments is critical for organizational resilience, growth, and operational efficiency. As cloud services become more prevalent, so do sophisticated attacks targeting cloud users, making early detection essential. This paper introduces a novel time-based embedding approach for Cloud Services Graph-based Anomaly Detection (CS-GAD) that leverages a Graph Neural Network (GNN) to detect anomalous user behavior. We propose a dynamic tripartite graph to model interactions among users, actions, and cloud services over time. Using behavioral patterns, our GNN generates user embeddings to enable early detection of anomalies. We evaluate this approach on a novel dataset simulating five real-world attacks: cryptojacking, billing abuse, lateral movement, monitor exploitation, and service targeting. The dataset comprises 107,116 Application Programming Interface (API) calls over 32 days, tracking 79 AWS services, with attacks embedded within legitimate cloud traffic. Our results demonstrate that the proposed method achieves a lower false positive rate and higher detection accuracy than a prevailing method, as evidenced by improved accuracy, precision, recall, and F1-score. Revital Marbel, Yanir Cohen, Ran Dubin, Amit Dvir, Chen Hajaj |
CCNC | 4 |
| 2026 | Quality of Experience Prediction for First-Person Shooter Online Gaming: The Case Study of Call of DutyabstractLatency is the most impactful on fairness and Quality of Experience (QoE) in First-Person Shooter (FPS) games. High latency degrades the QoE of players, who may leave the game if unsatisfied with their QoE. Modern FPS games make great efforts to maintain an excellent QoE even under a poor Internet connection with high latency. Those efforts include the wide distribution of game servers and many software optimizations to smooth the effect of lags in the games. This study aims to provide insights into QoE estimation for network-intensive applications by examining one of the most prominent FPS games of the past two decades: Call of Duty. We observed that the game dynamically adjusts its network traffic behavior, including packet size and transmission rate, in response to variations in network quality. However, the ISP does not have this capability since the network traffic is encrypted; observing the game’s network traffic does not expose its nature and most certainly does not expose the game player’s intensity, latency, or QoE. We propose a novel technique for estimating latency and QoE in FPS games from an ISP-level perspective. In our evaluation, the model detected problematic latency in near real-time with 81% accuracy and an 80% F1 on a 10-second window, highlighting a trade-off between responsiveness and predictive performance. The dataset generated for this study is publicly available to support further research. Yehonatan Zion, Eyal Paz, Ran Dubin, Amit Dvir, Chen Hajaj |
CCNC | 4 |
| 2026 | Uncovering Microservice Faults: A Temporal Graph Approach to Root Cause Analysis
Udi Aharon, Amit Dvir, Ran Dubin, Revital Marbel, Chen Hajaj |
ICC | 2 |
| 2026 | GraphMux: A graph-based framework for encrypted traffic classificationabstractThe growing dominance of encrypted network traffic and modern encryption protocols (TLS 1.3, QUIC, DoH) poses significant challenges for accurate network classification, particularly as many existing approaches rely on text- or image-based representations, which fail to adequately capture the inherent structural relationships present in network communication—relationships that are more naturally represented as graphs. In this work, we introduce GraphMux, a graph-based framework that leverages line graph transformations to fuse multiple graph views into a unified representation. We also present three graph-based flow representations (TIG+Chain, StarBurst, and 2Chain) designed to capture both temporal burst dynamics and client–server interaction patterns, using only packet time, direction, and length information, without incorporating any unencrypted statistical features. We evaluate our approach on three datasets: two academic datasets (UTMobileNetTraffic2021 and QUIC PCAP) and a commercial dataset (Flash), using four graph embedding architectures. Across all datasets, GraphMux consistently achieves superior performance, and the proposed graph constructions often yield the best results. Additional experiments examining attribute-selection strategies reveal a strong positive relationship between well-aligned feature assignments and classification accuracy, underscoring the importance of principled attribute design when constructing graph representations for encrypted traffic. Matan Klein, Revital Marbel, Chen Hajaj, Ran Dubin, Amit Dvir |
Comput. Networks | 5 |
| 2025 | Out-Of-Distribution Is Not Magic: The Clash Between Rejection Rate and Model SuccessabstractRecent advancements in Internet protocols, including DNS over HTTPS (DoH) and Encrypted Service Name Indicators (ESNI), are making traditional Deep Packet Inspection (DPI) engines obsolete.Consequently, there is a growing need for nextgeneration traffic classification using artificial intelligence (AI).While DPI automatically categorizes unknown traffic as 'other,' AI-based models cannot automatically handle unknown or Outof-Distribution (OOD) traffic.AI models must effectively detect and classify OOD traffic to ensure robustness, reliability, and accuracy in real-world applications; however, current research often fails to address the challenges of OOD detection.In this paper, we evaluate various state-of-the-art OOD detection techniques for internet traffic classification and explore the drawbacks and advantages of using different threshold levels for the model's tolerance for OOD.Our findings reveal that varying rejection rates have distinct effects on OOD techniques, leading to a change in the optimal strategy for achieving dependable and precise detection across diverse OOD scenarios.We demonstrate that adjusting rejection rates from 10% to 30% can significantly improve the True Detection Rate (TDR) by up to 50%, while the False Detection Rate (FDR) may increase by less than 10%.Moreover, we emphasize that rejection-rate-based evaluation is pivotal for next-generation flow classification, promising a substantial reduction in FDR through rigorous methodological assessment. Itay Meiri, Ran Dubin, Amit Dvir, Chen Hajaj |
FedCSIS | 3 |
| 2025 | Optimized File Type Detection and One-Shot RetrievalabstractFile type classification is critical in digital forensics, and file carving. However, the increasing diversity of file formats challenges accurate classification. Traditional methods rely on hand-crafted features or compact neural networks but face long training times, limited training data, and lower accuracy. This paper introduces three novel, content-based file-type classification approaches to address these challenges. These approaches improve accuracy and streamline the integration of new file types using pre-trained models, enhancing both speed and reliability. The first approach utilizes Natural Language Processing (NLP) with a transformer architecture, while the second combines statistical features with a pre-trained model via transfer learning. These methods achieved accuracy rates of 72.4 % and 69.2 %, respectively, surpassing state-of-the-art Convolutional Neural Network (CNN) models. The third approach employs one-shot learning, achieving 100 % accuracy in several scenarios, enabling efficient training with minimal data. Simona Lisker, Ayelet Butman, Chen Hajaj, Ran Dubin, Amit Dvir |
ICC | 5 |
| 2025 | PQClass: Classification of Post-Quantum Encryption Applications in Internet TrafficabstractPost-quantum cryptography (PQC) is expected to revolutionize secure communications in next-generation digital ecosystems. Previous and ongoing activities demonstrate that different PQC algorithms significantly impact traffic latency, but they do not yet provide a scheme to assess the existence of the PQC algorithm or its identification when encrypted traffic is analyzed for traffic engineering purposes. Hence, this work is the first to propose a novel PQClass pipeline for classifying encrypted Internet traffic of recently NIST-approved PQC algorithms. Hence, it establishes solid grounds for enabling engineers to optimize their networks and, in parallel, for cybersecurity practitioners to familiarise themselves with PQC algorithmic properties for enhancing or devising security architectures in diverse setups. Our pipeline demonstrates impressive performance on real-world data, achieving 86% accuracy in detecting the presence of a PQC algorithm and 91% and 98% accuracy in identifying the browser and OS, respectively, based on PQC-based traffic. Angelos K. Marnerides, Chen Hajaj, Revital Marbel, Ran Dubin, Amit Dvir |
ICC | 5 |
| 2025 | A New D-MAGIC: Dynamic Model for Cybersecurity Attack Detection Using GNNs into ClusteringabstractThe increasing sophistication and frequency of cyberattacks have made Network Intrusion Detection Systems (NIDS) a critical component of modern cybersecurity. This work presents D-MAGIC, a novel real-time NIDS that leverages zero-shot learning and graph-based dynamic clustering to detect known and unknown threats. Unlike traditional systems that rely on labeled datasets and predefined attack signatures, D-MAGIC operates unsupervised, identifying anomalies by detecting deviations from normal network behavior. By embedding the relationships between network flows into a graph structure and dynamically clustering similar patterns, D-MAGIC can detect coordinated attacks and emerging threats with minimal delay. Experimental results on the CIC-IDS-2017 and CSE-CIC-IDS-2018 datasets demonstrate that D-MAGIC achieves an improvement of up to 12 % based on the standard F1 score compared to state-of-the-art methods, while significantly reducing false positives and ensuring rapid, real-time detection with minimal detection latency. Zohar Simhon, Matan Weiss, Chen Hajaj, Revital Marbel, Ran Dubin, Amit Dvir |
ICC | 6 |
| 2025 | Enhancing Encrypted Internet Traffic Classification Through Advanced Data Augmentation TechniquesabstractThe increasing popularity of online services has made Internet Traffic Classification a critical field of study. However, the rapid development of internet protocols and encryption limits usable data availability. This paper addresses the challenges of classifying encrypted Internet Traffic, focusing on the scarcity of open-source datasets and limitations of existing ones. We propose two Data Augmentation (DA) techniques to synthetically generate data based on real samples: Average augmentation and MTU augmentation. Both augmentations are aimed to improve the performance of the classifier, each from a different perspective: The Average augmentation aims to increase dataset size by generating new synthetic samples, while the$M T U$augmentation enhances classifier robustness to varying Maximum Transmission Units (MTUs). Our experiments, conducted on two well-known academic datasets and a commercial dataset, demonstrate the effectiveness of these approaches in improving model performance and mitigating constraints associated with limited and homogeneous datasets. Our findings underscore the potential of data augmentation in addressing the challenges of modern Internet Traffic classification. Specifically, we show that our augmentation techniques significantly enhance encrypted traffic classification models. This improvement can positively impact user Quality of Experience (QoE) by more accurately classifying traffic as video streaming (e.g., YouTube) or chat (e.g., Google Chat). Additionally, it can enhance Quality of Service (QoS) for file downloading activities (e.g., Google Docs). Yehonatan Zion, Porat Aharon, Ran Dubin, Amit Dvir, Chen Hajaj |
ICC | 4 |
| 2025 | Achieving manet protection without the use of superfluous fictitious nodes
Nadav Schweitzer, Liad Cohen, Tirza Hirst, Amit Dvir, Ariel Stulman |
Comput. Commun. | 4 |
| 2025 | A classification-by-retrieval framework for few-shot anomaly detection to detect API injection
Udi Aharon, Ran Dubin, Amit Dvir, Chen Hajaj |
Comput. Secur. | 3 |
| 2024 | Hidden in Time, Revealed in Frequency: Spectral Features and Multiresolution Analysis for Encrypted Internet Traffic ClassificationabstractIn recent years, privacy and security concerns have led to the wide adoption of encrypted protocols, making encrypted traffic a major portion of overall communications online. The transition into more secure protocols poses significant challenges for internet service providers to utilize traditional traffic classification techniques in order to guarantee the Quality of Service (QoS), Quality of Experience (QoE), and cyber-security of their customers. In this work, we introduce two methods, namely STFT-TC and DWT-TC, leveraging compact time-series representation coupled with well-known techniques from the field of Digital Signal Processing (DSP): the short-time Fourier transform (STFT) and the discrete wavelet transform (DWT). The STFT-TC method extracts a suite of statistical and spectral features from the magnitude spectrogram, offering a fresh perspective on interpreting and classifying encrypted traffic. The DWT-TC method extracts statistical features from the wavelet coefficients and incorporates unique characteristics that describe the signal's shape and energy distribution. Evaluating our methods on two public QUIC datasets demonstrated improvements in accuracy of up to 5.7%. Similarly, the F1-scores also showed enhancements, with increments of up to 5.9% for the same datasets. Nathan Dillbary, Roi Yozevitch, Amit Dvir, Ran Dubin, Chen Hajaj |
CCNC | 3 |
| 2024 | OSF-EIMTC: An open-source framework for standardized encrypted internet traffic classification
Ofek Bader, Adi Lichy, Amit Dvir, Ran Dubin, Chen Hajaj |
Comput. Commun. | 3 |
| 2024 | Extending limited datasets with GAN-like self-supervision for SMS spam detection
Or Haim Anidjar, Revital Marbel, Ran Dubin, Amit Dvir, Chen Hajaj |
Comput. Secur. | 4 |
| 2024 | The art of time-bending: Data augmentation and early prediction for efficient traffic classification
Chen Hajaj, Porat Aharon, Ran Dubin, Amit Dvir |
Expert Syst. Appl. | 4 |
| 2024 | SPRINKLER: A Multi-RPL Man-in-the-Middle Identification Scheme in IoT NetworksabstractCyber-threat protection is one of the most challenging research branches of Internet-of-Things (iot). With the exponential increase of tiny connected devices, the battle between friend and foe intensifies. Unfortunately,iotdevices offer very limited security features, laying themselves wide open to new attacks, inhibiting the expected global adoption ofiottechnologies. Moreover, existing prevention and mitigation techniques and intrusion detection systems handle attack anomalies rather than the attack itself while using a significant amount of the network resources.rpl, the de-facto routing protocol foriot, proposes minimal security features that cannot handle internal attacks. Hence, in this paper, we proposesprinkler, which identifies the specificthingthat is under attack by an adversarial Man-in-The-Middle.sprinkleruses the multi-instance feature ofrplto identify the adversary. The proposed solution adheres to two basic principles: it only uses pre-existing standard routing protocols and does not rely on a centralized or trusted third-party node such as a certificate authority. All information must be gleaned by each node using only primitives that already exist in the underlying communication protocol, which excludes any training dataset. Simulations show thatsprinkleradds minimal maintenance and energy expenditure while pinpointing deterministically the attacker in the network. In particular,sprinklerhas a message delivery rate and detection rate of 100%. Aviram Zilberman, Amit Dvir, Ariel Stulman |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | Identifying a Malicious Node in a UAV NetworkabstractWith the emergence of new and exciting wireless technologies and capabilities, Unmanned Aerial Vehicles (UAVs) and the services they allow, stand to be a major influencer in our daily lives. Unfortunately, they are also prone to a plethora of security issues. Existing studies propose both prevention and identification schemes for various routing attacks. They do not, however, preclude future malicious attempts. Hence, in this work we identify the specific UAV that is compromising the network, with the specific purpose of flushing it out. The proposed solution combines secret sharing and cheating identification schemes with multi-path routing protocols, to deterministically pinpoint the compromised node that is cheating the UAV flock. It assures a quiet identification of the adversary creating new opportunities for its attack, even when facing a sophisticated adversary that selectively modifies data messages or re-routes them in within the network. We took special care to allow for applicability in existing networks by adhering to two basic principles: only using pre-existing standard routing protocols and not relying on a centralized or trusted third party node such as a base station. All information must be gleaned by each node using only primitives which already exist in the underlying communication protocols. We provide a rigorous mathematical proof of the cost bounds, and run simulations to prove feasibility. Moreover, the simulations show a 100% detection rate and message delivery rate. The communication overhead varies, on average, between$0.4\cdot 10^{6}-0.8\cdot 10^{6}$bytes, depending on various parameters such as the network size and the reception rate of network nodes. The time required varies between 0.2–0.4 seconds, depending mainly on the network size. Aviram Zilberman, Ariel Stulman, Amit Dvir |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | Persuasive: A node isolation attack variant for OLSR-based MANETs and its mitigation
Nadav Schweitzer, Liad Cohen, Amit Dvir, Ariel Stulman |
Ad Hoc Networks | 3 |
| 2023 | Network wormhole attacks without a traditional wormhole
Nadav Schweitzer, Amit Dvir, Ariel Stulman |
Ad Hoc Networks | 2 |
| 2023 | When a RF beats a CNN and GRU, together - A comparison of deep learning and classical machine learning approaches for encrypted malware traffic classification
Adi Lichy, Ofek Bader, Ran Dubin, Amit Dvir, Chen Hajaj |
Comput. Secur. | 4 |
| 2023 | Speech and multilingual natural language framework for speaker change detection and diarization
Or Haim Anidjar, Yannick Estève, Chen Hajaj, Amit Dvir, Itshak Lapidot |
Expert Syst. Appl. | 4 |
| 2023 | Breaking the structure of MaMaDroid
Harel Berger, Amit Dvir, Enrico Mariconti, Chen Hajaj |
Expert Syst. Appl. | 2 |
| 2022 | MalDIST: From Encrypted Traffic Classification to Malware Traffic Detection and ClassificationabstractThe world of malware is shifting towards using encrypted traffic. While encryption improves the privacy of users, it brings challenges in the fields of QoS, QoE, and cybersecurity. Recent state-of-the-art Deep-Learning architectures for encrypted traffic classifications demonstrated superb results in tasks of traffic categorization over encrypted traffic. In this paper, we leverage the feasibility to use such architectures for the tasks of malware detection and classification to gain insights into how well these architectures perform in the domain of malware traffic. Specifically, we present a Deep-Learning model for malware traffic detection and classification (MalDIST), which outperforms both classical ML and DL malware traffic classification models both in terms of detection and classification. Ofek Bader, Adi Lichy, Chen Hajaj, Ran Dubin, Amit Dvir |
CCNC | 5 |
| 2022 | Word embedding dimensionality reduction using dynamic variance thresholding (DyVaT)
Avraham Treistman, Dror Mughaz, Ariel Stulman, Amit Dvir |
Expert Syst. Appl. | 4 |
| 2021 | A Thousand Words are Worth More Than One Recording: Word-Embedding Based Speaker Change Detection
Or Haim Anidjar, Itshak Lapidot, Chen Hajaj, Amit Dvir |
Interspeech | 4 |
| 2021 | Heterogeneous SDN controller placement problem - The Wi-Fi and 4G LTE-U case
Aviram Zilberman, Yoram Haddad 0001, Sefi Erlich, Yossi Peretz, Amit Dvir |
Comput. Networks | 5 |
| 2021 | Hybrid Speech and Text Analysis Methods for Speaker Change DetectionabstractSpeaker Change Detection (SCD) is the task of segmenting an input audio-recording according to speaker interchanges. Nowadays, many applications, such as Speaker Diarization (SD) or automatic vocal transcription, depend on this segmentation task. In this paper, we focus on the essential task of the SD problem, the audio segmenting process, and suggest a solution for the SCD problem, as well as the assignment of clustered speaker labels for the extracted segments, and applying the solution over two datasets: a commercial dataset in Hebrew and the ICSI Meeting Corpus. As such, we propose a hybrid framework for the SCD problem that is learned by textual information and speech signals and the meta-data features that can be extracted from them. Moreover, we demonstrate the negative correlation between an increase in the number of speakers in the training dataset and the influence on the overall diarization system's performance, which is improved using our efficient SCD component. Finally, we show how our proposed hybrid framework remains robust compared to the ICSI Meeting Corpus, as the experimental evaluation's training and testing is based on two languages. Or Haim Anidjar, Itshak Lapidot, Chen Hajaj, Amit Dvir, Issachar Gilad |
IEEE ACM Trans. Audio Speech Lang. Process. | 4 |
| 2020 | Encrypted video traffic clustering demystified
Amit Dvir, Angelos K. Marnerides, Ran Dubin, Nehor Golan, Chen Hajaj |
Comput. Secur. | 1 |
| 2019 | A fair server adaptation algorithm for HTTP adaptive streaming using video complexity
Ran Dubin, Raffael Shalala, Amit Dvir, Ofir Pele, Ofer Hadar |
Multim. Tools Appl. | 3 |
| 2019 | MiSAL - A minimal quality representation switch logic for adaptive streaming
Amit Dvir, Nissim Harel, Ran Dubin, Refael Barkan, Raffael Shalala, Ofer Hadar |
Multim. Tools Appl. | 1 |
| 2019 | The controller placement problem for wireless SDN
Amit Dvir, Yoram Haddad 0001, Aviram Zilberman |
Wirel. Networks | 1 |
| 2018 | Wireless controller placement problemabstractSoftware Defined Networking decouples the control and data planes. The response time and quality of service of the controllers is a key aspect in implementing the Software Defined Networking paradigm. A wireless Software Defined Networking control plane is even more challenging. Many radio communication problems arise in modeling the wireless east west bound and southbound interfaces. Wireless networks feature many unique components and metrics that often do not exist in wired networks: separate control transport may intensify on the latency within the wireless data plain with additional interference. Obviously, Wi-Fi based control plane has its implications, e.g., higher packet loss and hidden or exposed terminals. Moreover, wireless links can be operated in a number of different wireless characteristics, e.g., transmission rates and power settings. In this paper we define and solve the known Controllers Placement Problem, but for a Wi-Fi based control plane: the Wireless Control Placement Problem. We define the metrics for an effective wireless controllers placement and propose a multi-objective optimization for the Wireless Controller Placement Problem. Then we evaluate the influence of the variant metrics on the number of controllers and their locations. Amit Dvir, Yoram Haddad 0001, Aviram Zilberman |
CCNC | 1 |
| 2018 | Securing Road Traffic Congestion Detection by Incorporating V2I CommunicationsabstractIn this paper, we address the security properties of automated road congestion detection systems. SCATS, SCOOT and InSync are three examples of Adaptive Traffic Control Systems (ATCSs) widely deployed today. ATCSs minimize the unused green time and reduce traffic congestion in urban areas using different methods such as induction loops and camcorders installed at intersections. The main drawback of these system is that they cannot capture incidents outside the range of these camcorders or induction loops. To overcome this hurdle, theoretical concepts for automated road congestion alarm systems including the system architecture, communication protocol, and algorithms are proposed. These concepts incorporate secure wireless vehicle-to-infrastructure (V2I) communications. The security properties of this new system are presented and then analyzed using the ProVerif protocol verification tool. Ta Vinh Thong 0001, Amit Dvir, Yalin Arie |
WOWMOM | 2 |
| 2018 | Adaptation logic for HTTP dynamic adaptive streaming using geo-predictive crowdsourcing for mobile users
Ran Dubin, Amit Dvir, Ofir Pele, Ofer Hadar, Itay Katz, Ori Mashiach |
Multim. Syst. | 2 |
| 2017 | Analyzing HTTPS encrypted traffic to identify user's operating system, browser and applicationabstractDesktops and laptops can be maliciously exploited to violate privacy. There are two main types of attack scenarios: active and passive. In this paper, we consider the passive scenario where the adversary does not interact actively with the device, but he is able to eavesdrop on the network traffic of the device from the network side. Most of the internet traffic is encrypted and thus passive attacks are challenging. In this paper, we show that an external attacker can identify the operating system, browser and application of HTTP encrypted traffic (HTTPS). To the best of our knowledge, this is the first work that shows this. We provide a large data set of more than 20000 examples for this task. Additionally, we suggest new features for this task.We run a through a set of experiments, which shows that our classification accuracy is 96.06%. Jonathan Muehlstein, Yehonatan Zion, Maor Bahumi, Itay Kirshenboim, Ran Dubin, Amit Dvir, Ofir Pele |
CCNC | 6 |
| 2017 | I Know What You Saw Last Minute - Encrypted HTTP Adaptive Video Streaming Title ClassificationabstractDesktops can be exploited to violate privacy. There are two main types of attack scenarios: active and passive. We consider the passive scenario where the adversary does not interact actively with the device, but is able to eavesdrop on the network traffic of the device from the network side. In the near future, most Internet traffic will be encrypted and thus passive attacks are challenging. Previous research has shown that information can be extracted from encrypted multimedia streams. This includes video title classification of non HTTP adaptive streams. This paper presents algorithms for encrypted HTTP adaptive video streaming title classification. We show that an external attacker can identify the video title from video HTTP adaptive streams sites, such as YouTube. To the best of our knowledge, this is the first work that shows this. We provide a large data set of 15000 YouTube video streams of 2100 popular video titles that was collected under real-world network conditions. We present several machine learning algorithms for the task and run a thorough set of experiments, which shows that our classification accuracy is higher than 95%. We also show that our algorithms are able to classify video titles that are not in the training set as unknown and some of the algorithms are also able to eliminate false prediction of video titles and instead report unknown. Finally, we evaluate our algorithm robustness to delays and packet losses at test time and show that our solution is robust to these changes. Ran Dubin, Amit Dvir, Ofir Pele, Ofer Hadar |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2015 | Novel ad insertion technique for MPEG-DASHabstractDynamic Adaptive Streaming over HTTP (DASH) is a new and promising streaming protocol, based on the Media Presentation Description (MPD) specification. With the increasing demand for Internet video streaming, methods for profiting from video services are gaining increased interest. In this paper, we propose a novel algorithm for server side video ad insertion over the DASH standard. The proposed method is compatible with DASH and does not require any modifications at the client side, such as dedicated players, or any modification in the MPD definitions. Furthermore, the algorithm enables the client to always receive the advertisements regardless of his player software. Our novel approach considers the MPD URLs as encrypted URLs for pointer mapping. This will allow for deciding in real time whether a specific URL will point to an ad or to the original video stream segment. Therefore, the solution enables us to consider VOD ad insertion as similar to live ad insertion. In a comparison between the DASH video streaming server with ad insertion, as define in the standard, and our ad insertion solution, the results showed that our solution provide a dynamic ad insertion system while only slightly increasing the CPU load. As far as we know, this is the first DASH server side ad insertion solution for the ISO Base Media File Format (MPEG-4 part 12) container. Ran Dubin, Amit Dvir, Ofer Hadar, Tomer Frid, Alex Vesker |
CCNC | 2 |
| 2015 | Video complexity hybrid traffic shaping for HTTP Adaptive StreamingabstractThe increasing demand for video content and the fast adoption of HTTP Adaptive Streaming (HAS) has led to the need for sophisticated streaming optimization solutions. One of the main drawbacks of HAS is that the user is responsible for deciding which video quality to request without taking into account the server load, the number of users, fairness and more. Therefore, traffic shaping server, which takes these factors into account is needed. In this paper we present a HAS traffic shaping algorithm that in one hand tries to maximize user experience by providing the quality which is the closest to the one that the user requested while in other hand takes into account the server constrains. Simulation results show that the proposed solution effectively serves up to a 28% more users when the network is congested, while the users experienced an average bit-rate decreased up to 12% and the average PSNR decrease was 0.26 dB. Ran Dubin, Amit Dvir, Ofer Hadar, Raffael Shalala, Ofir Ahark |
CCNC | 2 |
| 2014 | GNSS Accuracy Improvement Using Rapid Shadow TransitionsabstractReceiver modules in Global Navigation Satellite Systems (GNSS) are capable of providing positioning and velocity estimations that are sufficiently accurate for the purpose of road navigation. However, even in optimal open-sky conditions, GNSS-based positioning carries an average error of 2-4 m. This imposes an effective limitation on GNSS-based vehicle lane detection, a desired functionality for various navigation and safety applications. In this paper, we present a novel framework for lane-level accuracy using GNSS devices and 3-D shadow matching. The suggested framework is based on detection and analysis of rapid changes in navigation satellites' signal strength, which are caused by momentary blockages due to utility and light poles. A method for detecting such momentary changes between line of sight and non line of sight is presented, followed by a geometric algorithm that improves location accuracy of commercial GNSS devices. We have tested the framework's applicability using both simulations and field experiments. We provide the results of these tests and discuss receiver-side sampling rate requirements for high-performance lane-level positioning. Roi Yozevitch, Boaz Ben-Moshe, Amit Dvir |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2013 | SDTP+: Securing a distributed transport protocol for WSNs using Merkle trees and Hash chainsabstractTransport protocols for Wireless Sensor Networks (WSNs) are designed to fulfill both reliability and energy efficiency requirements. Distributed Transport for Sensor Networks (DTSN) [1] is one of the most promising transport protocols designed for WSNs because of its effectiveness; however, it does not address any security issues, hence it is vulnerable to many attacks. The first secure transport protocol for WSN was the secure distributed transport protocol (SDTP) [2], which is a security extension of DTSN. Unfortunately, it turns out that the security methods provided by SDTP are not sufficient; some tricky attacks get around the protection mechanism. In this paper, we describe the security gaps in the SDTP protocol, and we introduce SDTP+for patching the weaknesses. We show that SDTP+resists attacks on reliability and energy efficiency of the protocol, and also present an overhead analysis for showing its effectiveness. Amit Dvir, Levente Buttyán, Ta Vinh Thong 0001 |
ICC | 1 |
| 2013 | Performance monitoring framework for Wi-Fi MANETabstractMobile Ad-Hoc Networks (MANET) are known for their rapid deployment and self-organizing capabilities. Those qualities are making MANET a candidate communication infrastructure for rescue forces in emergency events. However, existing Wi-Fi MANET implementations are exhibiting unsatisfactory performance, and the dynamic multi-hop topology of the network makes it difficult to identify the bottlenecks. This paper1 suggests a performance monitoring model for Wi-Fi MANET, incorporating concepts of a Geographic Information and Monitoring System (GIMS), that passively monitors the MANET deployment, thus enabling to optimize and fine-tune the network. Specifically, our monitoring model addresses the known Wi-Fi problems of hidden node and exposed node that are intensified in MANET. We provide a theoretical solution, deriving from the field of conflict graphs, which assists to identify and locate such situations. Experimental results from a real-life testbed that emulates such problems confirm that the suggested approach can effectively detects cases of hidden and exposed nodes in MANET. Boaz Ben-Moshe, Eyal Berliner, Amit Dvir |
WCNC | 3 |
| 2013 | The effect of client buffer and MBR consideration on DASH Adaptation LogicabstractDASH is new ISO/IEC MPEG and 3GPP standard for HTTP multimedia streaming that begins to be widely accepted in the industry. DASH is design to be flexible and support various multimedia formats. DASH unify the proprietary adaptive streaming solutions and suggests differing between them by using different behavioral approaches, each one best suited for the specific streaming application. Each behavior is determined by Adaptation Logic (AL), which decides according to the estimation of the network conditions and buffer state what is the best suitable segment to be requested from the streaming server. This work presents the drawback of current DASH standard and its vulnerability to variable bit rate stream encoding. We have found that the advertised bit rate for each quality layer that was dictated by the Media Presentation Description (MPD) isn't accurate for VBR streaming. Moreover, we suggest an Adaptive Buffer Moving Median (ABMM) buffer sensitive adaptation logic that will support its bandwidth estimation decisions based on the client buffer redundancy. The new method was found to be suitable for mobile network traffic which is characterized with large fluctuations with network bandwidth. Our proposed solution showed more than 20 percent better average PSNR improvement compared to the original VLC plug-in rate adaptation logic. Ran Dubin, Ofer Hadar, Amit Dvir |
WCNC | 3 |
| 2011 | A joint framework of passive monitoring system for complex wireless networksabstractMonitoring and analyzing wireless networks for network structure and behavior is a complex task. Such monitoring often requires creating extra traffic, dedicated hardware and a prior knowledge of the network components and structure. In this paper we present a novel approach for monitoring large and complex wireless networks, fast deployed which operate seamlessly and in real time. The suggested framework uses few passive sniffers in order to sample the WiFi communication in the "air" per packet and have an extended cover range due to overhearing abilities. This monitoring system requires no prior knowledge of the network structure. We have designed, implemented and deployed such a passive monitoring system and used it to monitor the campus WLAN network (Wi-Fi). Experimental results show that the suggested framework is highly applicable for unmanaged and partly managed wireless networks such as Ad-hoc, first responders, self deployed and any highly dynamic network. Boaz Ben-Moshe, Eyal Berliner, Amit Dvir, Aharon Gorodischer |
CCNC | 3 |
| 2011 | Development and optimization of cache element for access layerabstractVideo on the Internet has become an integral part of the user content consuming behavior. The use of High Definition (HD) video content increases the present bandwidth limitations of Internet infrastructure providers. Moreover, the rapid raise in Over the Top (OTT) Internet video bandwidth consumption presents major implications on current Internet Service Providers' (ISP) business models. In order to supply the ever-growing demand for IP-based video a major technology is used: Multi Layer Cache (MLC) for fully stored video content. The low level of the MLC hierarchy is the Access node. In this paper, we explore the influence of a memory device in the access and choose the best memory device to fulfill the HD requirements. Boaz Ben-Moshe, Amit Dvir, Adi Rotman |
CCNC | 2 |
| 2011 | Analysis and optimization of live streaming for over the top videoabstractVideo has become an integral part of the Internet user content. The use of High Definition (HD) video content increases the bandwidth requirements of the Internet infrastructure. Moreover, rapid increase in the Over-the-Top (OTT) Internet video bandwidth consumption has major impact on the business models of the Internet Service Providers (ISP). To support the ever-growing demand for IP-based video, two major technologies are used: Peer-to-Peer (P2P) for live video and Multi-Layer Cache (MLC) for fully-stored video content. In this paper we focus on partial streaming, which is a `semi-live' form of video delivery of live events such as sports, concerts, and news in the Video-on-Demand (VOD) format. The VOD supports user control features such as Start Over, Pause, Rewind, and Forward. We suggest a new framework for optimizing partial streaming using MLC, which allows storing partial video content in the time-based chunks of data (that is, data packets) while forwarding these data chunks to the users at various levels of ISP networks. The suggested framework may be helpful for solving the OTT bottleneck caused be video streaming. Boaz Ben-Moshe, Amit Dvir, Akiv Solomon |
CCNC | 2 |
| 2011 | VeRA - Version Number and Rank Authentication in RPLabstractDesigning a routing protocol for large low-power and lossy networks (LLNs), consisting of thousands of constrained nodes and unreliable links, presents new challenges. The IPv6 Routing Protocol for Low-power and Lossy Networks (RPL), have been developed by the IETF ROLL Working Group as a preferred routing protocol to provide IPv6 routing functionality in LLNs. RPL provides path diversity by building and maintaining directed acyclic graphs (DAG) rooted at one (or more) gateway. However, an adversary that impersonates a gateway or has compromised one of the nodes close to the gateway can divert a large part of network traffic forward itself and/or exhaust the nodes' batteries. Therefore in RPL, special security care must be taken when the Destination Oriented Directed Acyclic Graph (DODAG) root is updating the Version Number by which reconstruction of the routing topology can be initiated. The same care also must be taken to prevent an internal attacker (compromised DODAG node) to publish decreased Rank value, which causes a large part of the DODAG to connect to the DODAG root via the attacker and give it the ability to eavesdrop a large part of the network traffic forward itself. Unfortunately, the currently available security services in RPL will not protect against a compromised internal node that can construct and disseminate fake messages. In this paper, a new security service is described that prevents any misbehaving node from illegitimately increasing the Version Number and compromise illegitimate decreased Rank values. Amit Dvir, Tamás Holczer, Levente Buttyán |
MASS | 1 |
| 2010 | Backpressure-based routing protocol for DTNsabstractIn this paper we consider an alternative, highly agile In this paper we consider an alternative, highly agile approach called backpressure routing for Delay Tolerant Networks (DTN), in which routing and forwarding decisions are made on a per-packet basis. Using information about queue backlogs, random walk and data packet scheduling nodes can make packet routing and forwarding decisions without the notion of end-to-end routes. To the best of our knowledge, this is the first ever implementation of dynamic backpressure routing in DTNs. Simulation results show that the proposed approach has advantages in terms of DTN networks. Amit Dvir, Athanasios V. Vasilakos |
SIGCOMM | 1 |
| 2010 | Centdian Computation for Sensor Networks
Boaz Ben-Moshe, Amit Dvir, Michael Segal 0001, Arie Tamir |
TAMC | 2 |
| 2010 | Placing and maintaining a core node in wirelessad hoc networksabstractAbstract Wirelessad hocnetworks are characterized by several performance metrics, such asbandwidth, transport, delay, power, etc. These networks are examined by constructing a tree network. A core node is usually chosen to be themedianorcenterof the multicast tree network with a tendency to minimize a performance metric, such as delay or transport. In this paper, we present a new efficient strategy for constructing and maintaining a core node in a multicast tree for wirelessad hocnetworks undergoing dynamic changes, based on local information. The new core (centdian) function is defined by a convex combination signifying total transport and delay metrics. We provide two bounds ofO(d) andO(d+l) time for maintaining the centdian using local updates, wherelis the hop count between the new center and the new centdian, anddis the diameter of the tree network. We also show anO(n log n) time solution for finding the centdian in the Euclidian complete network. Finally, an extensive simulation for the construction algorithm and the maintenance algorithm is presented along with an interesting observation. Copyright © 2009 John Wiley & Sons, Ltd. Amit Dvir, Michael Segal 0001 |
Wirel. Commun. Mob. Comput. | 1 |
| 2009 | Power-aware recovery for geographic routingabstractMaintaining low power consumption is critical in wireless ad hoc and sensor networks. With packet transmissions and retransmissions consuming much of the energy resources in wireless networks, it becomes important to minimize the number of transmissions associated with the end-to-end delivery of packets. Power-aware routing algorithms must balance the advantages and disadvantages of selecting to forward packets over shorter high-quality links against selecting longer and less reliable links. This paper proposes a new power-aware geographic routing technique that combines geographic greedy routing with probabilistic random walks to recover from local minima (i.e., cases when the forwarding node is not aware of any neighboring node providing "greedy" progress towards the destination). Building upon previous power-aware protocols without recovery mechanisms, our protocol uses simple distance metrics that combine information about the individual reception rates between node pairs and the relative forward progress candidate nodes provide towards the target destination. The combined metrics are used to make greedy choices (when at least one node provides progress) and probabilistic choices (when the packet recovers from a local minimum). Using simulations we show that power-aware routing significantly reduces the energy consumption in the network, and our probabilistic recovery mechanism can significantly increase the delivery rates with only a small decrease in energy efficiency. Amit Dvir, Niklas Carlsson |
WCNC | 1 |
| 2007 | Placing and Maintaining a Core Node in Wireless Ad Hoc Sensor Networks
Amit Dvir, Michael Segal 0001 |
Networking | 1 |
| 2006 | Automated antenna positioning for wireless networksabstractThis article addresses a real-life problem - obtaining communication links between multiple base stations sites, by positioning a minimal set of fixed-access relay antenna sites on a given terrain. Reducing the number of relay antenna sites is considered critical due to substantial installation and maintenance costs. Despite the potential significant cost saving by eliminating even a single antenna site, a hardly optimal manual approach is employed due to the computation complexity of the problem. We suggest several alternative automated heuristics, relying on terrain preprocessing to find educated potential points for positioning relay stations. A large-scale experiment was conducted showing that the saving potential increases when more BSs are required to be interconnected and in any case is better than the one obtained by ah uman expert. Amit Dvir, Yehuda Ben-Shimol, Yoav Ben-Yehezkel, Michael Segal 0001 |
CCNC | 1 |
| 2004 | SPLAST: a novel approach for multicasting in mobile wireless ad hoc networksabstractTrees of special properties are required to provide efficient network management of group communications in mobile ad hoc networks. Usually, such trees try to balance between the requirements to minimize the total tree cost and the requirement to minimize the maximal shortest path. This work presents a novel solution for efficient multicast trees that fulfill both requirements called SPLAST. The following discussion covers the development process, starting from centralized static solution, through distributed implementation to a complete distributed algorithm that cope with various scenarios that are relevant to wireless ad hoc networks by efficient management and maintenance of the underlying components of the algorithm. Simulation inquiry shows that the average performance of SPLAST is attractive as well. Yehuda Ben-Shimol, Amit Dvir, Michael Segal 0001 |
PIMRC | 2 |