EDBT 2026 Demo / reviewers in the wild / expert
Dinil Mon Divakaran
dblp:87/2495
· DBLP profile ↗
46ranked-venue papers
12as first author
20since 2021 · last 2025
0000-0001-8706-432XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 24 · 9 first-author · 6 since 2021Security and privacy · 11 · 9 since 2021Software engineering, systems software and programming languages · 4 · 3 since 2021Systems, architecture and hardware · 2 · 2 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Benchmarking LLMs and LLM-based Agents in Practical Vulnerability Detection for Code RepositoriesabstractAlperen Yildiz, Sin G Teo, Yiling Lou, Yebo Feng, Chong Wang, Dinil Mon Divakaran. Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2025. Alperen Yildiz, Sin G. Teo, Yiling Lou, Yebo Feng, Chong Wang 0013, Dinil Mon Divakaran |
ACL (1) | 6 |
| 2025 | ProvDP: Differential Privacy for System Provenance Dataset
Kunal Mukherjee, Jonathan Yu, Partha De, Dinil Mon Divakaran |
ACNS (3) | 4 |
| 2024 | ZEST: Attention-based Zero-Shot Learning for Unseen IoT Device ClassificationabstractRecent research works have proposed machine learning models for classifying IoT devices connected to a network. However, there is still a practical challenge of not having all devices (and hence their traffic) available during the training of a model. This essentially means, during the operational phase, we need to classify new devices not seen in the training phase. To address this challenge, we propose ZEST—a ZSL (zero-shot learning) framework based on self-attention for classifying both seen and unseen devices. ZEST consists of i) a self-attention based network feature extractor, termed SANE, for extracting latent space representations of IoT traffic, ii) a generative model that trains a decoder using latent features to generate pseudo data, and iii) a supervised model that is trained on the generated pseudo data for classifying devices. We carry out extensive experiments on real IoT traffic data; our experiments demonstrate i) ZEST achieves significant improvement (in terms of accuracy) over the baselines; ii) SANE is able to better extract meaningful representations than LSTM which has been commonly used for modeling network traffic. Binghui Wu, Philipp Gysel, Dinil Mon Divakaran, Gurusamy Mohan |
NOMS | 3 |
| 2024 | Enhancing LoRa Reception with Generative Models: Channel-Aware Denoising of LoRaPHY SignalsabstractThe proliferation of Internet of Things (IoT) applications relying on Low Power Wide Area Networks (LPWANs) demands robust and energy-efficient communication solutions. Among various LP-WAN technologies, LoRa emerges as a prominent choice due to its long-range capabilities and low energy consumption. However, the practical deployment of LoRa is hindered by significant signal degradation caused by channel and hardware noise, especially in urban environments. We introduce GLoRiPHY, a novel generative framework designed to enhance the reception quality of LoRaPHY signals through a channel-aware denoising mechanism. Utilizing a transformer-based architecture, GLoRiPHY leverages the known preamble of LoRaPHY signals to compensate for channel-induced distortions, thereby generating a clean signal suitable for direct demodulation. The system integrates Convolutional Neural Networks (CNNs) for efficient feature encoding and decoding, maintaining a compact model footprint even at higher Spreading Factors (SFs). Evaluations on real-world and simulated datasets show that in comparison to the current state-of-the-art solution, GLoRiPHY significantly lowers the Symbol Error Rate (SER) by up to 2.85x and demonstrates generalizability in unseen environments, while reducing inference times by up to 5.75x. Kanav Sabharwal, Soundarya Ramesh, Dinil Mon Divakaran, Mun Choon Chan |
SenSys | 4 |
| 2024 | DiffPerf: Toward Performance Differentiation and Optimization With SDN ImplementationabstractThe continuous growth of Internet traffic, especially video content, presents challenges for access providers (APs) who must upgrade their infrastructure to meet increasing demands. Ensuring a high-quality experience (QoE) for end-users and finding ways to monetize network resources are key concerns. Guaranteeing QoE is complex, as it depends not only on link capacity but also on competing traffic flows and shared network data plane buffers. To address these challenges, we proposeDiffPerf, an in-network, online, and dynamic allocation system.DiffPerfoperates at both macroscopic and microscopic levels. At the macroscopic level, it elastically allocates bandwidth to performance-centric service classes defined by APs to accommodate different performance requirements. At the microscopic level,DiffPerfemploys a lightweight data-driven algorithm to statistically differentiate and isolate traffic flows within each class, improving their performance. We implementedDiffPerfprototypes using SDN-based technology, one with OpenDaylight and OpenFlow hardware switches, and the other with programmable Intel Tofino switches. Our evaluation focused on on-demand video streaming. The results demonstrate thatDiffPerfoffers APs a range of allocation choices while ensuring strong performance isolation. Additionally,DiffPerfimproves fairness and enhances overall user-perceived QoE within each class. Notably,DiffPerfconserves bandwidth and delivers a QoE improvement approximately$4.6\times $higher than TCP BBR, the most popular congestion control mechanism on the Internet. Walid Aljoby, Xin Wang 0040, Dinil Mon Divakaran, Tom Z. J. Fu, Richard T. B. Ma, Khaled A. Harras |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | Attacking Logo-Based Phishing Website Detectors with Adversarial Perturbations
Jehyun Lee, Zhe Xin, Melanie Ng Pei See, Kanav Sabharwal, Giovanni Apruzzese, Dinil Mon Divakaran |
ESORICS (3) | 6 |
| 2023 | DySO: Enhancing application offload efficiency on programmable switchesabstractApplication offloads on modern high-speed programmable switches have been proposed in a variety of systems (e.g., key–value store systems and network middleboxes) so as to efficiently scale up the traditional server-oriented deployments. However, they largely achieve sub-optimal offloading efficiency due to the lack of (1) capability to perform control actions at sufficient rates, and (2) adaptability to workload changes. In this paper, we scrutinize the common stumbling blocks of existing frameworks with performance evaluations on real workloads. We present DySO (Dynamic State Offloading), a framework which enables expeditious on-demand control actions and self-tuning of management rules. DySO’s key insight is to perform control actions via a data-path instead of the switch control channel which is the bottleneck to read/write states into data plane. Our software simulations show up to 100% performance improvement compared to existing systems for various real world traces. On top of that, we implement and evaluate DySO on a commodity programmable switch, showing two orders of magnitude faster responsiveness to sudden workload changes compared to the existing systems. Cha Hwan Song, Xin Zhe Khooi, Dinil Mon Divakaran, Mun Choon Chan |
Comput. Networks | 3 |
| 2023 | iPET: Privacy Enhancing Traffic Perturbations for Secure IoT CommunicationsabstractIoT devices constantly communicate with servers over the Internet, allowing an attacker to extract sensitive information by passively monitoring the network traffic. Recent research works have shown that a network attacker with a trained machine learning (ML) model can accurately fingerprint IoT devices learned from the (encrypted) traffic flows of the devices. Such fingerprinting attacks are capable of revealing the make and model of the devices, which can further be used to extract detailed user activities. In this work, we develop and propose iPET, a novel adversarial perturbation-based traffic modification system that defends against fingerprinting attacks. iPET design employs GAN (Generative Adversarial Networks) in a tuneable way, allowing users to specify the maximum bandwidth overhead they are willing to tolerate for the defense. A fundamental idea of iPET is to deliberately introduce stochasticity between model instances. This approach limits a counter attack, as it inhibits an attacker from recreating an identical perturbation model and using it for fingerprinting. We evaluate the effectiveness of our defense against state-of-the-art fingerprinting models and with three different attacker capabilities. Our evaluations on synthetic and real-world datasets demonstrate that iPET decreases the accuracy of even the potent attackers. We also show that the traffic perturbations generated by iPET generalize well to different fingerprinting schemes that an attacker may deploy. Akshaye Shenoi, Prasanna Karthik Vairam, Kanav Sabharwal, Dinil Mon Divakaran |
Proc. Priv. Enhancing Technol. | 5 |
| 2022 | Markov Chain Monte Carlo-Based Machine Unlearning: Unlearning What Needs to be ForgottenabstractAs the use of machine learning (ML) models is becoming increasingly popular in many real-world applications, there are practical challenges that need to be addressed for model maintenance. One such challenge is to "undo" the effect of a specific subset of dataset used for training a model. This specific subset may contain malicious or adversarial data injected by an attacker, which affects the model performance. Another reason may be the need for a service provider to remove data pertaining to a specific user to respect the user's privacy. In both cases, the problem is to "unlearn" a specific subset of the training data from a trained model without incurring the costly procedure of retraining the whole model from scratch. Towards this goal, this paper presents a Markov chain Monte Carlo-based machine unlearning (MCU) algorithm. MCU helps to effectively and efficiently unlearn a trained model from subsets of training dataset. Furthermore, we show that with MCU, we are able to explain the effect of a subset of a training dataset on the model prediction. Thus, MCU is useful for examining subsets of data to identify the adversarial data to be removed. Similarly, MCU can be used to erase the lineage of a user's personal data from trained ML models, thus upholding a user's "right to be forgotten". We empirically evaluate the performance of our proposed MCU algorithm on real-world phishing and diabetes datasets. Results show that MCU can achieve a desirable performance by efficiently removing the effect of a subset of training dataset and outperform an existing algorithm that utilizes the remaining dataset. Quoc Phong Nguyen, Ryutaro Oikawa, Dinil Mon Divakaran, Mun Choon Chan, Kian Hsiang Low |
AsiaCCS | 3 |
| 2022 | SIERRA: Ranking Anomalous Activities in Enterprise NetworksabstractAn enterprise today deploys multiple security middleboxes such as firewalls, IDS, IPS, etc. in its network to collect different kinds of events related to threats and attacks. These events are streamed into a SIEM (Security Information and Event Management) system for analysts to investigate and respond quickly with appropriate actions. However, the number of events collected for a single enterprise can easily run into hundreds of thousands per day, much more than what analysts can investigate under a given budget constraint (time). In this work, we look into the problem of prioritizing suspicious events or anomalies to analysts for further investigation. We develop SIERRA, a system that processes event logs from multiple and diverse middleboxes to detect and rank anomalous activities. SIERRA takes an unsupervised approach and therefore has no dependence on ground truth data. Different from other works, SIERRA defines contexts, that help it to provide visual explanations of highly-ranked anomalous points to analysts, despite employing unsupervised models. We evaluate SIERRA using months of logs from multiple security middleboxes of an enterprise network. The evaluations demonstrate the capability of SIERRA to detect top anomalies in a network while outperforming naive application of existing anomaly detection algorithms as well as a state-of-the-art SIEM-based anomaly detection solution. Jehyun Lee, Farren Tang, Phyo May Thet, Desmond Yeoh, Mitch Rybczynski, Dinil Mon Divakaran |
EuroS&P | 6 |
| 2022 | APEX: Characterizing Attack Behaviors from Network AnomaliesabstractNetworks regularly face various threats and attacks that manifest in their communication traffic. Recent works proposed unsupervised approaches, e.g., using a variational autoencoder, that are not only effective in detecting anomalies in network traffic, but also practical as they do not require ground truth or labeled data. However, the problem of characterizing anomalies into different attack behaviors is still less explored; in this work, we study this specific problem. We develop APEX, a framework that employs data mining approaches in a semisupervised way to extract the attack patterns from anomalous traffic and links them to specific attack types. APEX comprises two levels of mining: the first level extracts patterns in anomalous network flows, and the second level characterizes behaviors in the extracted patterns into different attack classes. We carry out extensive experiments on real network traces obtained from the MAWI traffic archive. The evaluations demonstrate that APEX is effective in extracting distinguishable behaviors of network attacks from anomalous traffic, and provide useful insights to security analysts investigating the anomalies. Kushan Sudheera Kalupahana Liyanage, Zixu Tian, Dinil Mon Divakaran, Mun Choon Chan, Gurusamy Mohan |
IPCCC | 3 |
| 2022 | Inferring Phishing Intention via Webpage Appearance and Dynamics: A Deep Vision Based Approach
Yun Lin 0001, Xianglin Yang, Siang Hwee Ng, Dinil Mon Divakaran, Jin Song Dong 0001 |
USENIX Security Symposium | 5 |
| 2021 | Privacy of DNS-over-HTTPS: Requiem for a Dream?abstractThe recently proposed DNS-over-HTTPS (DoH) protocol is becoming increasingly popular in addressing the privacy concerns of exchanging plain-text DNS messages over potentially malicious transit networks (e.g., mass surveillance at ISPs). By employing HTTPS to encrypt DNS communications, DoH traffic inherently becomes indistinguishable from regular encrypted Web traffic, rendering active disruption (e.g., downgrading to the plain-text DNS) by transit networks extremely hard. In this work, we investigate whether DoH traffic is indeed indistinguishable from encrypted Web traffic. To this end, we collect several DoH traffic traces corresponding to 25 resolvers (including major ones, e.g., Google and Cloudftare) by visiting thousands of domains in Alexa's list of top-ranked websites at different geographical locations and environments. Based on the collected traffic, we train a machine learning model to classify HTTPS traffic as either Web or DoH. With our DoH identification model in place, we show that an authoritarian ISP can identify ∼97.4% (∼90%) of the DoH packets correctly in a closed-world (open-world) setting while only misclassifying 1 in 10,000 Web packets. To counter this DoH identification model, we propose an effective mitigation technique, making the identification model impractical for ISPs to filter and consequently downgrade DoH to plain-text DNS communications. Levente Csikor, Min Suk Kang, Dinil Mon Divakaran |
EuroS&P | 4 |
| 2021 | D-Fence: A Flexible, Efficient, and Comprehensive Phishing Email Detection SystemabstractPhishing continues to be a major security concern for organizations around the globe. Past works proposed classifiers to detect phishing emails; however many of them are based on rules, whereas others are typically standalone models focusing on one specific component of emails (say, URL strings). In this work, we take a different approach and propose a multi-modular and comprehensive phishing email detection system, called D-Fence. The different modules of D-Fence — structure module, text module, and URL module — detect phishing attempts in different components of an email. This allows D-Fence to cover larger attack surfaces while also offering flexible (model) configurations with reduced computational overhead. We carry out experiments on a large-scale real-world email dataset comprising mails from multiple enterprises. Our evaluations demonstrate the effectiveness of D-Fence in detecting phishing emails that do not have malicious intentions manifesting in all email components; D-Fence achieves a high recall of 0.99 at a low false-positive rate of 1 in 10K. Furthermore, we perform systematic evaluations to find and evaluate cost-efficient model configurations for D-Fence; the results reveal that D-Fence maintains high detection capability while bringing significant savings in computational time. Jehyun Lee, Farren Tang, Pingxiao Ye, Fahim Abbasi, Phil Hay, Dinil Mon Divakaran |
EuroS&P | 6 |
| 2021 | DiffPerf: An In-Network Performance Optimization for Improving User-Perceived QoEabstractContinuing the current trend, Internet traffic is expected to grow significantly over the coming years, with video traffic consuming the biggest share. Despite numerous optimizations of the transport congestion control, and the switch butter sizing and management algorithms; however, the complex interaction among all of them still leads to uncertain user performance and thus degrades user-perceived quality, under various network and traffic conditions. The culprit is the difficulty to dynamically control the amount of bandwidth allocated to each of the competing flows under bottleneck due to the algorithms lack of visibility of butter content where the flows reside. We address this bandwidth allocation problem by proposing DiffPerf, an in-network system that relies on a lightweight learning algorithm to statistically differentiate and isolate user flows to help them achieve better performance in an online and dynamic manner. We built two SDN-based prototypes of DiffPerf; one on OpenDaylight with OpenFlow Brocade switch and the other with programmable data plane Barefoot Tofino switch. We evaluate it from an application perspective for ABR video streaming as it accounts for a majority of the Internet traffic. Our evaluations demonstrate the practicality and flexibility that DiffPerf assists users in achieving better fairness and improving overall user-perceived quality. On average DiffPerf yields a quality improvement of about $4.6\times$ and $1.2\times$ higher than TCP BBR and TCP CUBIC, respectively. Walid Aljoby, Xin Wang 0040, Dinil Mon Divakaran, Tom Z. J. Fu, Richard T. B. Ma |
NetSoft | 3 |
| 2021 | In-Network Applications: Beyond Single Switch PipelinesabstractThe emergence of commodity programmable switches have spawned a series of innovations in the network data plane. By making the traditionally stateless network architectures to be stateful, we can realize a diverse set of applications, e.g., networking monitoring, load-balancing, firewalls, entirely in the data plane. On the other hand, many existing in-network applications assume that the underlying switch is single-pipelined, however, in reality, commodity programmable switches are designed with multiple pipelines in mind. While this approach enables high scalability, it has introduced a serious disadvantage: maintaining states across the pipelines is non-trivial. For instance, without involving the control plane it is infeasible to keep track of a request and its response in different pipelines, thereby rendering many in-network proposals impractical.In this paper, we highlight this fundamental limitation that holds back the practical widespread adoption of stateful applications in today’s multi-pipeline switches. By scrutinizing recent in-network approaches, we identify that majority of them cannot operate as they are proposed on multi-pipeline switches. After raising awareness of this inevitable consequence, we discuss a set of possible workarounds for in-network applications to overcome this issue on multi-pipeline switches. Xin Zhe Khooi, Levente Csikor, Jialin Li 0001, Dinil Mon Divakaran |
NetSoft | 4 |
| 2021 | Revisiting Heavy-Hitter Detection on Commodity Programmable SwitchesabstractExisting in-network heavy-hitter detection algorithms suffer from several shortcomings. On the one hand, most of the algorithms perform monitoring in intervals and reset the data structures in between; consequently, a notable amount of heavy hitters (HH) spanning across the intervals go undetected. On the other hand, the algorithms consume substantial hardware resources, potentially hindering other data plane functionalities to be integrated on the same device.In this work, we revisit the state-of-the-art in-network approaches in this regard and identify that they fall short in over-coming the aforementioned issues. In particular, we investigate whether it is possible to design a heavy-hitter detection algorithm that provides high accuracy without consuming substantial re-sources, thereby making it feasible to integrate with concurrent applications. To this end, we propose dSketch, a time-decaying algorithm for in-network heavy-hitter detection. Trace-driven simulations and evaluations on the Intel Tofino-based commodity switches show that dSketch significantly improves the detection rate of HHs by 5–10% while being resource- and operation-efficient in contrast to state-of-the-art approaches. Moreover, we show that dSketch can be integrated with standard switch functionalities such as switch. p4 with additional resources spared, offering itself as a compelling solution for switch data plane designers. Xin Zhe Khooi, Levente Csikor, Jialin Li 0001, Min Suk Kang, Dinil Mon Divakaran |
NetSoft | 5 |
| 2021 | Phishpedia: A Hybrid Deep Learning Based Approach to Visually Identify Phishing Webpages
Yun Lin 0001, Dinil Mon Divakaran, Jun Yang Ng, Qing Zhou Chan, Yuxuan Si, Jin Song Dong 0001 |
USENIX Security Symposium | 3 |
| 2021 | Cost-Aware Feature Selection for IoT Device ClassificationabstractThe classification of Internet-of-Things (IoT) devices into different types is of paramount importance, from multiple perspectives, including security and privacy aspects. Recent works have explored machine learning techniques for fingerprinting (or classifying) IoT devices, with promising results. However, the existing works have assumed that the features used for building the machine learning models are readily available or can be easily extracted from the network traffic; in other words, they do not consider the costs associated with feature extraction. In this work, we take a more realistic approach, and argue that feature extraction has a cost, and the costs are different for different features. We also take a step forward from the current practice of considering the misclassification loss as a binary value, and make a case for different losses based on the misclassification performance. Thereby, and more importantly, we introduce the notion of risk for IoT device classification. We define and formulate the problem of cost-aware IoT device classification. This being a combinatorial optimization problem, we develop a novel algorithm to solve it in a fast and effective way using the cross-entropy (CE)-based stochastic optimization technique. Using traffic of real devices, we demonstrate the capability of the CE-based algorithm in selecting features with minimal risk of misclassification while keeping the cost for feature extraction within a specified limit. Biswadeep Chakraborty, Dinil Mon Divakaran, Ido Nevat, Gareth W. Peters, Gurusamy Mohan |
IEEE Internet Things J. | 2 |
| 2021 | ADEPT: Detection and Identification of Correlated Attack Stages in IoT NetworksabstractThe fast-growing Internet-of-Things (IoT) market has opened up a large threat landscape, given the wide deployment of IoT devices in both consumer and commercial spaces. Attacks on IoT devices generally consist of multiple stages and are dispersed spatially and temporally. These characteristics make it challenging to detect and identify the attack stages using solutions that tend to be localized in space and time. In this work, we present Adept, a distributed framework to detect and identify the individual attack stages in a coordinated attack. Adept works in three phases. First, network traffic of IoT devices is processed locally for detecting anomalies with respect to their benign profiles. Any alert corresponding to a potential anomaly is sent to a security manager, where aggregated alerts are mined, using frequent itemset mining (FIM), for detecting patterns correlated across both time and space. Finally, using both alert-level and pattern-level information as features, we employ a machine learning approach to identify individual attack stages in the generated alerts. We carry out extensive experiments, with emulated and realistic network traffic; the results demonstrate the effectiveness of the proposed framework in terms of its ability in attack-stage detection and identification. Kushan Sudheera Kalupahana Liyanage, Dinil Mon Divakaran, Rhishi Pratap Singh, Gurusamy Mohan |
IEEE Internet Things J. | 2 |
| 2020 | DIDA: Distributed In-Network Defense Architecture Against Amplified Reflection DDoS AttacksabstractWith each new DDoS attack potentially becoming a higher intensity attack than the previous ones, current ISP measures of over-provisioning or employing a scrubbing service are becoming ineffective and inefficient. We argue that we need an in-network solution (i.e., entirely in the data plane), to detect DDoS attacks, identify the corresponding traffic and mitigate promptly. In this paper, we propose the first distributed in-network defense architecture, DIDA, to cope with the sophisticated amplified reflection DDoS (AR-DDoS) attacks. We leverage programmable stateful data planes and efficient data structures and show that it is possible to keep track of per-user connections in an automated and distributed manner without overwhelming the network controller. Building on top of this data, DIDA can easily detect if unsolicited attack packets are sent towards a victim within an ISP network. Once an attack is detected, the routers at the network edge automatically block the malicious sources. We prototype DIDA in P4. Our preliminary experiments show that DIDA can detect and mitigate 99.8% of amplification attacks containing 7, 000 different sources while requiring less than 1% of the memory of current programmable switches. Xin Zhe Khooi, Levente Csikor, Dinil Mon Divakaran, Min Suk Kang |
NetSoft | 3 |
| 2019 | Tuple space explosion: a denial-of-service attack against a software packet classifierabstractEfficient and highly available packet classification is fundamental for various security primitives. In this paper, we evaluate whether the de facto Tuple Space Search (TSS) packet classification algorithm used in popular software networking stacks such as the Open vSwitch is robust against low-rate denial-of-service attacks. We present the Tuple Space Explosion (TSE) attack that exploits the fundamental space/time complexity of the TSS algorithm. Levente Csikor, Dinil Mon Divakaran, Min Suk Kang, Attila Korösi, Balázs Sonkoly, Dávid Haja, Dimitrios P. Pezaros, Stefan Schmid 0001, Gábor Rétvári |
CoNEXT | 2 |
| 2019 | DEFT: A Distributed IoT Fingerprinting TechniqueabstractIdentifying IoT devices connected to a network has multiple security benefits, such as deployment of behavior-based anomaly detectors, automated vulnerability patching of specific device types, dynamic attack mitigation, etc. In this paper, we look into the problem of IoT device identification at network level, in particular from an ISP's perspective. The simple solution of deploying a supervised machine learning algorithm at a centralized location in the network neither scales well nor can identify new devices. To tackle these challenges, we propose and develop a distributed device fingerprinting technique (DEFT), a distributed fingerprinting solution that addresses and exploits the presence of common devices, including new devices, across smart homes and enterprises in a network. A DEFT controller develops and maintains classifiers for fingerprinting, while gateways located closer to the IoT devices at homes perform device classification. Importantly, the controller and gateways coordinate to identify new devices in the network. DEFT is designed to be scalable and dynamic-it can be deployed, orchestrated, and controlled using software-defined networking and network function virtualization. DEFT is able to identify new device types automatically, while achieving high accuracy and low false positive rate. We demonstrate the effectiveness of DEFT by experimenting on data obtained from real-world IoT devices. Vijayanand Thangavelu, Dinil Mon Divakaran, Rishi Sairam, Suman Sankar Bhunia, Gurusamy Mohan |
IEEE Internet Things J. | 2 |
| 2018 | Anomaly Detection and Attribution in Networks With Temporally Correlated TrafficabstractAnomaly detection in communication networks is the first step in the challenging task of securing a network, as anomalies may indicate suspicious behaviors, attacks, network malfunctions, or failures. In this paper, we address the problem of not only detecting the anomalous events but also of attributing the anomaly to the flows causing it. To this end, we develop a new statistical decision theoretic framework for temporally correlated traffic in networks via Markov chain modeling. We first formulate the optimal anomaly detection problem via the generalized likelihood ratio test (GLRT) for our composite model. This results in a combinatorial optimization problem which is prohibitively expensive. We then develop two low-complexity anomaly detection algorithms. The first is based on the cross entropy (CE) method, which detects anomalies as well as attributes anomalies to flows. The second algorithm performs anomaly detection via GLRT on the aggregated flows transformation - a compact low-dimensional representation of the raw traffic flows. The two algorithms complement each other and allow the network operator to first activate the flow aggregation algorithm in order to quickly detect anomalies in the system. Once an anomaly has been detected, the operator can further investigate which specific flows are anomalous by running the CE-based algorithm. We perform extensive performance evaluations and experiment our algorithms on synthetic and semi-synthetic data, as well as on real Internet traffic data obtained from the MAWI archive, and finally make recommendations regarding their usability. Ido Nevat, Dinil Mon Divakaran, Sai Ganesh Nagarajan, Pengfei Zhang 0001, Le Su, Li Ling Ko, Vrizlynn L. L. Thing |
IEEE/ACM Trans. Netw. | 2 |
| 2017 | Analysis of Privacy Leak on TwitterabstractMicro-blogging services like Twitter which allow users to post messages and follow activities are gaining in popularity. The content of the posted tweets is wide ranging, and sometimes includes private information like email addresses, physical addresses, birthdays and medical history. Such private data, if leaked through public posts, could be used by stalkers, foes, or unintended parties. Detecting the presence of private data in tweets is a first step towards analyzing the privacy risk associated with it. In this context, the purpose of our work is twofold. First, we categorize the tweets into private and non-private, based on whether they reveal any private information or not. Second, we try to gain more insights into categorized private tweets by identifying the type of private data being revealed. We train the model on novel features extracted from the labeled tweets and perform supervised classification. Our results show that detection of leak of private data can be achieved with an accuracy of about 80% and false positive rate of 18%. Furthermore, we are able to differentiate between private tweets by classifying them into different categories with high accuracy. Leena Deodhar, Dinil Mon Divakaran, Gurusamy Mohan |
GLOBECOM | 2 |
| 2017 | REX: Resilient and efficient data structure for tracking network flows
Dinil Mon Divakaran, Li Ling Ko, Le Su, Vrizlynn L. L. Thing |
Comput. Networks | 1 |
| 2017 | FACT: A Framework for Authentication in Cloud-Based IP TracebackabstractIP traceback plays an important role in cyber investigation processes, where the sources and the traversed paths of packets need to be identified. It has a wide range of applications, including network forensics, security auditing, network fault diagnosis, and performance testing. Despite a plethora of research on IP traceback, the Internet is yet to see a large-scale practical deployment of traceback. Some of the major challenges that still impede an Internet-scale traceback solution are, concern of disclosing Internet Service Provider (ISP's) internal network topologies (in other words, concern of privacy leak), poor incremental deployment, and lack of incentives for ISPs to provide traceback services. In this paper, we argue that cloud services offer better options for the practical deployment of an IP traceback system. We first present a novel cloud-based traceback architecture, which possesses several favorable properties encouraging ISPs to deploy traceback services on their networks. While this makes the traceback service more accessible, regulating access to traceback service in a cloud-based architecture becomes an important issue. Consequently, we address the access control problem in cloud-based traceback. Our design objective is to prevent illegitimate users from requesting traceback information for malicious intentions (such as ISPs topology discovery). To this end, we propose a temporal token-based authentication framework, called FACT, for authenticating traceback service queries. FACT embeds temporal access tokens in traffic flows, and then delivers them to end-hosts in an efficient manner. The proposed solution ensures that the entity requesting for traceback service is an actual recipient of the packets to be traced. Finally, we analyze and validate the proposed design using real-world Internet data sets. Long Cheng 0005, Dinil Mon Divakaran, Aloysius Wooi Kiak Ang, Wee-Yong Lim, Vrizlynn L. L. Thing |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2016 | Proportional bandwidth sharing using Bayesian inference in SDN-based data centersabstractWith the evolution of software-defined networking (SDN) paradigm, traffic management in data center networks has become flexible and scalable. The existing solution using OpenFlow, the rate-guaranteeing mechanism, is inefficient as it limits the rate of the flows by dropping batches of packets to achieve the desired throughput. In this paper, we propose BASIS, a solution based on Bayesian inference for providing proportional Quality of Service (QoS) guarantees to tenants in a datacenter network. With BASIS, the bandwidth of an outgoing congested link will be shared among the competing flows in proportion to the weights chosen by them. We use Bayesian inference to capture the history of flow arrival rates and their offered load using a single queue, and estimate the differential drop probabilities of flows in a way that respects the weights assigned to them on arrival. Unlike the rate-limiting approach, BASIS proactively drops a packet of a flow probabilistically to achieve the desired throughput and avoids dropping batches of packets. We evaluate the proposed solution in an emulated SDN platform and show that BASIS achieves the desired throughput with lesser number of packet drops than the existing approaches. Purnima Murali Mohan, Dinil Mon Divakaran, Gurusamy Mohan |
ICC | 2 |
| 2016 | Opportunistic Piggyback Marking for IP TracebackabstractIP traceback is a solution for attributing cyber attacks, and it is also useful for accounting user traffic and network diagnosis. Marking-based traceback (MBT) has been considered a promising traceback approach, and has received considerable attention. However, we find that the traceback message delivery problem in MBT, which is important to the successful completion of a traceback, has not been adequately studied in the literature. To address this issue, we present the design, analysis, and evaluation of opportunistic piggyback marking (OPM) for IP traceback in this paper. The OPM distinguishes itself from the existing works by decoupling the traceback message content encoding and delivery functions in MBT, and efficiently achieves expedited and robust traceback message delivery by exploiting piggyback marking opportunities. Based on the proposed OPM scheme, we then present the flexible marking-based traceback framework, which is a novel design paradigm for IP traceback and has several favorable features for practical deployment of IP traceback. Through the numerical analysis and the comprehensive simulation evaluations, we demonstrate that our design effectively reduces the traceback completion delay and router processing overhead, and increases the message delivery ratio compared with other baseline approaches. Long Cheng 0005, Dinil Mon Divakaran, Wee-Yong Lim, Vrizlynn L. L. Thing |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2015 | SLIC: Self-Learning Intelligent Classifier for network traffic
Dinil Mon Divakaran, Le Su, Yung Siang Liau, Vrizlynn L. L. Thing |
Comput. Networks | 1 |
| 2015 | Dynamic resource allocation in hybrid optical-electrical datacenter networks
Dinil Mon Divakaran, Soumya Hegde, Raksha Srinivas, Gurusamy Mohan |
Comput. Commun. | 1 |
| 2015 | Towards Flexible Guarantees in Clouds: Adaptive Bandwidth Allocation and PricingabstractThis article focuses on the problem of bandwidth allocation to users of Cloud data centers. An interesting approach is to use advance bandwidth reservation. Such systems usually assume all requests demand either bandwidth-guarantee (BG) or time-guarantee (TG), but not both. Hence the solutions are tailored for one type of requests. A BG request demands guarantee on bandwidth; whereas a TG request demands guarantee on time for transfer of data of specified volume. We define a new model that allows users to not only submit both kinds of requests, but also specify flexible demands. We tie up the problem of bandwidth allocation with differential pricing, that gives discounts to users based on the flexibility in their requests. We propose a two-phase, adaptive and flexible bandwidth allocator (A-FBA) that, in one phase admits and allocates minimal bandwidth to dynamically arriving user requests, and in another phase, allocates additional bandwidth for accepted requests maximizing revenue. The problem formulated in first phase is${\cal NP}$-hard, while the second phase can be solved in polynomial time. We show that, in comparison to a traditional deterministic model, the A-FBA not only increases the number of accepted requests significantly, but also does so by generating higher revenues. Dinil Mon Divakaran, Gurusamy Mohan |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2014 | Virtual Network Embedding in Hybrid Datacenters with Dynamic Wavelength GroupingabstractWith ever increasing traffic demands, data enter networks are envisioned to be a hybrid of both optical and electrical networks. In this context, we consider the recently proposed dynamic wavelength grouping (DWG) architecture for the optical network. This architecture can dynamically group wavelengths from different ports onto a single fiber carrying fixed number of wavelength groups. We focus on the joint problem of VM-placement and bandwidth allocation in such a hybrid optical-electrical data enter network with DWG capability. There are multiple challenges: (i) the number of edge-switches that can be simultaneously reached using optical paths from an edge-switch is limited by cost, and (ii) wavelength-group continuity constraint. Abstracting the requests of tenants as virtual networks, we study the novel problem of embedding virtual networks on this hybrid datacenter, which translates to the joint problem of bandwidth allocation and placement such that the requirements of virtual networks are satisfied. We develop and analyse two algorithms for embedding dynamically arriving virtual network demands on a hybrid datacenter with DWG capability. The performance studies demonstrate the effectiveness of exploiting existing optical paths as well as using electrical links in the face of multiple constraints to accept higher number of requests. Raksha Srinivas, Soumya Hegde, Dinil Mon Divakaran, Gurusamy Mohan |
CloudCom | 3 |
| 2014 | Uniform price auction for allocation of dynamic cloud bandwidthabstractWith the ubiquitous adoption of Cloud services by both companies and consumers alike, lack of an efficient system to explicitly price and allocate limited bandwidth has severely impacted the performance of Cloud user-applications. In this context, we consider a two-tier pricing model — consisting of Reservation Phase and Dynamic Phase — that caters to the needs of different kinds of applications. While the Reservation Phase can be used by Cloud users to obtain guarantees on minimum bandwidth well ahead in time, Dynamic Phase can be used to demand and obtain (possibly) additional bandwidth dynamically. Bandwidth being a limited resource, we develop a unique multi-stage uniform price auction with supply uncertainty to dynamically allocate bandwidth to users in the Dynamic Phase. We study the proposed model using a game theoretical approach. Our results prove that proposed auction mechanism is a promising approach for bandwidth allocation. We show that the model promotes the dual advantage of market efficiency and maximum revenue for the Cloud provider. We also demonstrate the price stability using numerical simulations. We argue that for rational, payoff-maximizing tenants of Cloud, the price is stable over the long run which makes the mechanism suitable for practical use. Wee Kim Tan, Dinil Mon Divakaran, Gurusamy Mohan |
ICC | 2 |
| 2014 | Dynamic embedding of virtual networks in hybrid optical-electrical datacentersabstractA promising development in the design of datacenters is the hybrid network architecture consisting of both optical and electrical elements. In this context, the joint problem of bandwidth allocation and VM-placement, a problem that only recently received attention in all-electrical datacenter networks, poses new and different challenges not addressed yet in hybrid datacenters. In particular, we foresee two issues: (i) the number of edge-switches that can be simultaneously reached using optical paths from an edge-switch is limited by the switch size, (ii) the dynamic creation of optical paths can potentially establish a constrained optical network topology leading to poor performance. We abstract the requests of tenants as virtual networks, and study the problem of embedding virtual networks on a hybrid datacenter, which translates to the joint problem of bandwidth allocation and placement such that the topology constraints of virtual networks are satisfied. We develop and analyse two algorithms for embedding dynamically arriving virtual network demands on a hybrid optical-electrical datacenter. Through simulations, we demonstrate the effectiveness of not only exploiting the already established optical paths, but also of using electrical network in embedding requests of virtual networks. Soumya Hegde, Raksha Srinivas, Dinil Mon Divakaran, Gurusamy Mohan |
ICCCN | 3 |
| 2014 | Bandwidth allocation with differential pricing for flexible demands in data center networks
Dinil Mon Divakaran, Gurusamy Mohan, Mathumitha Sellamuthu |
Comput. Networks | 1 |
| 2014 | An Online Integrated Resource Allocator for Guaranteed Performance in Data CentersabstractAs bandwidth is shared in a best-effort way in today's data centers, traffic generated between a set of VMs (virtual machines) affect the traffic between another set of VMs (possibly belonging to another tenant) sharing the same physical links, leading to unpredictable performance of applications running on these VMs. This article addresses the problem of allocation of not only server resources (computational and storage) but also network bandwidth, to provide performance guarantees in multi-tenant data centers. Bandwidth being a critical shared-resource, we formulate the problem as an optimization problem that minimizes bandwidth demand between clusters of VMs of a tenant; and we prove it as NP-hard. We develop fast online heuristics as an integrated resource allocator (IRA) that decides on the admission of dynamically arriving requests, and allocates resources for the accepted ones. We also present a modified version of IRA, called B-IRA that bounds the cost of bandwidth allocation, while exploring smaller search space for solution. We demonstrate that, IRA accommodates significantly higher number of requests in comparison to a load-balancing resource allocator (LBRA) that does not consider reducing bandwidth between clusters of VMs. IRA also outperforms B-IRA when traffic demands of VMs in an input are not localized. Dinil Mon Divakaran, Tho Ngoc Le, Gurusamy Mohan |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2013 | Probabilistic-bandwidth guarantees with pricing in data-center networksabstractBandwidth-sharing in data-center networks is an important problem that affects the growth of multi-tenant datacenters. A promising solution approach is the use of advance reservations. Such systems are usually based on deterministic models, assuming users to have precise knowledge of bandwidth they require, which is unlikely. This work takes a deviation and proposes a probabilistic model, where bandwidth requirements are specified along with some probabilities. As user-estimate of bandwidth depends on the cost they incur, we tie up the model with differential pricing; and formulate bandwidth allocation as a two-phase - static and dynamic - optimization problem. We show that the problem in each phase is NP-hard. We develop a bandwidth-allocator that processes requests and defines bandwidth profiles for accepted requests by solving the optimization problems. Numerical studies show that, in comparison to the deterministic model, our model brings down the number of rejected requests significantly, while allocating more bandwidth and thereby increasing revenue for providers. Dinil Mon Divakaran, Gurusamy Mohan |
ICC | 1 |
| 2013 | Evolution of TCP's initial window sizeabstractRecognizing the upper bound of TCP initial window (IW) size-four segments-too small, researchers have been proposing to increase this. In this context, we observed that given the mice-elephant phenomenon, small flows benefit more from larger IW-size than large flows. This work proposes a simple but effective function to set IW-size for each flow, and investigates a scenario where the decentralized nature of Internet may enforce users to strategically choose right value for some parameter V in function, for improving performance of flows. We develop an evolutionary non-cooperative game-theoretic model to evaluate equilibria points and evolutionary stable strategy that are reached by users. Our game-theoretic results reveal that, there exists an optimal value for V for which small flows achieve better performance. Further our experiments on a testbed confirm that the performance attained by small flows using the proposed function is considerably improved, while not affecting the performance of large flows. Runa Barik, Dinil Mon Divakaran |
LCN | 2 |
| 2012 | An integrated resource allocation scheme for multi-tenant data-centerabstractThe success of multi-tenant data-centers depends on the ability to provide performance guarantees in terms of the resources provisioned to the tenants. As bandwidth is shared in a best-effort way in today's data-centers, traffic generated between a set of VMs affect the traffic between another set of VMs sharing the same physical links. This paper proposes an integrated resource allocation scheme that considers not only server-resources, but also network-resource, to decide the mapping of VMs onto servers. We present a three-phase mechanism that finds the right set of servers for the requested VMs, with an aim of reducing the bandwidth on shared links. This mechanism provisions the required bandwidth for the tenants, besides increasing the number of tenants that can cohabit in a data-center. We demonstrate, using simulations, that the proposed scheme accommodates 10%–23% more requests in comparison to a load-balancing allocator that does not consider bandwidth requirements of VMs. Gurusamy Mohan, Tho Ngoc Le, Dinil Mon Divakaran |
LCN | 3 |
| 2012 | A spike-detecting AQM to deal with elephants
Dinil Mon Divakaran |
Comput. Networks | 1 |
| 2011 | Using spikes to deal with elephantsabstractAmong the various strategies proposed for reducing or eliminating bias against small flows (in the presence of large flows), most require to identify and distinguish between small and large flows, besides having to track the ongoing sizes of all flows. Though these solutions do improve the response times of small flows (with negligible affect on the response times of large flows), they are not scalable with increasing traffic. In this context, we propose a new spike-detecting AQM that exploits TCP property in detecting large `spikes', and hence large flows, from which packets are dropped, and importantly, only at times of congestion. We discuss two such AQM policies using spike-detection for improving the performance of small flows: one that drops packets deterministically, and other that drops packets randomly. We show, using simulations, by comparing a number of metrics, that these new policies, in particular the one that drops packets randomly, out-performs not only the traditional drop-tail buffer with FCFS server, but also the RED policy as well as a size-based scheduler (proposed specifically for improving the response time of small flows). The improvement in performance becomes more revealing in scenario where the router buffer is small (less than one-tenth of the bandwidth-delay-product). Dinil Mon Divakaran |
IPCCC | 1 |
| 2010 | A virtual switch architecture for hosting virtual networks on the InternetabstractThe future Internet is envisioned to host a large number of virtual networks managed by different operators sharing the same physical infrastructure. In such a scenario, an operator may not even own physical resources as such, but lease virtual resources to have their own virtual networks. While control-plane virtualization with several routing instances becomes common in equipments, the data plane is generally shared relying on logical isolation or resource segmentation, lacking in efficient sharing with performance guarantees. This makes it necessary to look into layer 2, and virtualize the switching fabric to have control over the sharing of the most critical resources for packet switching. In this article, we come up with a flexible architectural design for virtualizing a switching fabric. This new architecture enables a multitude of choices to customize virtual switches as needed. Our simulations show the relative loss in performance brought by virtualization, and demonstrate how the offered flexibility can help in exploiting the resources in a new way, satisfying independent virtual switch requirements. Fabienne Anhalt, Dinil Mon Divakaran, Pascale Vicat-Blanc Primet |
HPSR | 2 |
| 2010 | Size-based flow scheduling in a CICQ switchabstractSize-based (SB) scheduling policies have been shown to improve response times of small flows, without degrading the performance of large flows. But these differentiating policies are designed for Output-queued switch architecture, which is known to have scalability issues. On the other hand, the buffered-crossbar (BX) switch architecture is currently being pursued as a potential next-generation scalable switch architecture. This work looks into the problem of performing SB scheduling in BX switches. In particular, the design goals, w.r.t each output port, are (i) to transmit high-priority packet(s) as long as there is at least one present, and (ii) to respect the FIFO order among high-priority packets. In this direction, we propose to use PIFO queue at each crosspoint of a CICQ switch. The initial design presented as pCICQ-1 switch is simple and guarantees that packet-priorities are respected once they are in the crosspoint queues. But it does not maintain the FIFO order of high-priority packets, besides letting a bounded number low-priority packets to depart through an output, when there are one or more high-priority packets for the same output. To solve this, we propose an enhancement, as pCICQ-2 switch, that achieves both the design goals. Dinil Mon Divakaran, Fabienne Anhalt, Eitan Altman, Pascale Vicat-Blanc Primet |
HPSR | 1 |
| 2010 | A Flow Scheduler Architecture
Dinil Mon Divakaran, Giovanna Carofiglio, Eitan Altman, Pascale Vicat-Blanc Primet |
Networking | 1 |
| 2009 | Analysis of the Effects of XLFrames in a Network
Dinil Mon Divakaran, Eitan Altman, Georg Post, Ludovic Noirie, Pascale Vicat-Blanc Primet |
Networking | 1 |