EDBT 2026 Demo / reviewers in the wild / expert
Riccardo Bettati
dblp:b/RBettati
· DBLP profile ↗
63ranked-venue papers
4as first author
5since 2021 · last 2023
0000-0002-5877-6667ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 25 · 2 first-authorComputer networks · 15 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 1 first-authorSecurity and privacy · 6 · 3 since 2021Human-computer interaction and ubiquitous computing · 4 · 1 first-authorSoftware engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | On Account Association With Assistance From Mobile NetworksabstractIn this paper, we draw attention to the problem of account association attacks designed to determine whether a target mobile phone number is associated with a particular online account. In the case of 4G/LTE, the adversary launches an account association attack by sending SMS messages to the target phone number and analyzing patterns in traffic related to the online account. We evaluate the proposed attacks in both a local 4G/LTE testbed and a major commercial 4G/LTE network. Our extensive experiments show that the proposed attacks can successfully identify account association with near-perfect accuracy. Our experiments also illustrate that the proposed attacks can be launched in a way that the victim receives no indication of being under attack. Sean W. Caldwell, Ye Zhu 0001, Riccardo Bettati |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Breathe-to-Pair (B2P): Respiration-Based Pairing Protocol for Wearable DevicesabstractWe propose Breathe-to-Pair (B2P), a protocol for pairing and shared-key generation for wearable devices that leverages the wearer's respiration activity to ensure that the devices are part of the same body-area network. We assume that the devices exploit different types of sensors to extract and process the respiration signal. We illustrate B2P for the case of two devices that use respiratory inductance plethysmography (RIP) and accelerometer sensors, respectively. Allowing for different types of sensors in pairing allows us to include wearable devices that use a variety of different sensors. In practice, this form of sensor variety creates a number of challenges that limit the ability of the shared-key establishment algorithm to generate matching keys. The two main obstacles are the lack of synchronization across the devices and the need for correct noise-induced mismatches between the generated key bit-strings. Jafar Pourbemany, Ye Zhu 0001, Riccardo Bettati |
WISEC | 3 |
| 2021 | Identifying Account Association with Assistance from Mobile Networks using Cross-Service AttacksabstractIn this paper, we draw attention to the problem of cross-service attacks, that is, attacks that exploit information collected about users from one service to launch an attack on the same users on another service. With the increased deployment and use of what fundamentally are integrated-services networks, such as 4G/LTE networks and now 5G, we expect that cross-service attacks will become easier to stage and therefore more prevalent. As running example to illustrate the effectiveness and the potential impact of cross-service attacks we will use the problem of account association in 4G/LTE networks. Account association attacks aim at determining whether a target mobile phone number is associated with a particular online account. The the case of 4G/LTE, the adversary launches the account association attacks by sending SMS messages to the target phone number and analyzing patterns in traffic related to the online account. We evaluate the proposed attacks in both a local 4G/LTE testbed and a major commercial 4G/LTE network. Our extensive experiments show that the proposed attacks can successfully identify account association with close-to-zero false negative and false positive rates. Our experiments also illustrate that the proposed attacks can be launched in a way that the victim receives no indication of being under attack. Sean W. Caldwell, Ye Zhu 0001, Riccardo Bettati |
ICC | 4 |
| 2021 | Efficient side-channel attacks beyond divide-and-conquer strategy
Shan Jin 0005, Riccardo Bettati |
Comput. Networks | 2 |
| 2021 | Towards Smartphone Operating System IdentificationabstractSmartphone reconnaissance, the first step to launch security attacks to a target smartphone, enables an adversary to tailor attacks by exploiting the known vulnerabilities of the target system. In this paper we investigate smartphone OS identification with encrypted traffic. We propose four algorithms to do that, which are based on the spectral analysis of the encrypted traffic. The algorithms are designed for high identification accuracy by removing noise frequency components and for high efficiency in terms of computation complexity. We evaluate the identification algorithms with smartphone traffic collected over three months. The experiment results show that the algorithms can identify the smartphone OS accurately. The identification accuracy can reach 100% with only 30 seconds of smartphone traffic. Ye Zhu 0001, Nicholas Ruffing, Jonathan Gurary, Riccardo Bettati |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2018 | IoTAegis: A Scalable Framework to Secure the Internet of ThingsabstractThe infamous Mirai attack which hijacked nearly half a million Internet connected devices demonstrated the widespread security vulnerabilities of the Internet-of-Things (IoT). This study employs a set of active and passive observation methods to discover the security vulnerabilities of IoT devices within a university campus. We show that (a) the number of non-compute devices dominates the number of compute devices with open ports in a campus network; (b) 58.9% or more devices do not keep up-to-date firmware and 51.3% or more do not have a user defined password; and (c) the number of devices together with the diversity of device ages and vendors make the protection of IoT devices a difficult problem. We further develop IoTAegis framework which offers device-level protection to automatically manage device configurations and security updates. Our solution is shown to be effective, scalable, lightweight, and deployable in different forms and network types. Allen Webb, A. L. Narasimha Reddy, Riccardo Bettati |
ICCCN | 4 |
| 2016 | Smartphone reconnaissance: Operating system identificationabstractSmartphone reconnaissance, the first step to launch security attacks to a target smartphone, enables an adversary to tailor attacks by exploiting known vulnerabilities of the target system. We investigate OS identification against smartphones that use encrypted traffic. A traffic content agnostic identification algorithm is proposed that is based on the spectral analysis of the encrypted traffic. The identification algorithm is designed for high identification accuracy by removing noise frequency components and for high efficiency in terms of computation complexity. We evaluate the identification algorithm against collected smartphone traffic. The experiment results show that the algorithm can identify the smartphone OS accurately. The identification accuracy can reach 100% with only 30 seconds of smartphone traffic. Nicholas Ruffing, Ye Zhu 0001, Rudy Libertini, Riccardo Bettati |
CCNC | 5 |
| 2012 | Subversion Impedance in Covert Communication NetworksabstractA covert communications network is a connected, overlay peer-to-peer network used to support communications within a group in which the survival of the group depends on: (1) anonymity of communications; and (2) concealment of network membership to both other members of the group and external eavesdroppers. These requirements are much more stringent than for typical privacy and anonymity systems. We consider the topologies of resilient covert communications networks that: (1) minimize the impact on the network in the event of a subverted node; and (2) maximize the connectivity of the survivor network with the removal of the subverted node and its closed neighborhood. We analyze the properties of resilient covert networks, propose a measurement for determining the suitability of a topology for use in a covert communication network, determine the properties of an optimal covert network topology, and analyze several optimal topologies. Timothy Nix, Riccardo Bettati |
TrustCom | 2 |
| 2011 | A Mixed-initiative Intelligent Tutoring System - Based on Learning from Demonstration
Omar Álvarez-Xochihua, Riccardo Bettati, Lauren Cifuentes, René Mercer |
CSEDU (1) | 2 |
| 2010 | Cyber-defense Training in the Real - Design Principles and Architecture of the VNEL Cyber-training Platform
Riccardo Bettati, Lauren Cifuentes, Willis F. Marti, René Mercer, Youngwoo Ahn, Omar Álvarez-Xochihua |
CSEDU (1) | 1 |
| 2010 | Schedulability analysis in hard real-time systems under thermal constraints
Shengquan Wang, Youngwoo Ahn, Riccardo Bettati |
Real Time Syst. | 3 |
| 2010 | Localization Attacks to Internet Threat Monitors: Modeling and CountermeasuresabstractAbstract—Internet Threat Monitoring (ITM) systems are a widely deployed facility to detect, analyze, and characterize dangerous Internet threats such as worms and distributed denial-of-service (DDoS) attacks. Nonetheless, an ITM system can also become the target of attacks. In this paper, we address localization attacks against ITM systems in which an attacker impairs the effectiveness of an ITM system by identifying the locations of ITM monitors. We propose an information-theoretic framework that models localization attacks as communication channels. Based on this model, we generalize all existing attacks as “temporal attacks”, derive closed formulae of their performance, and propose an effective attack detection approach. The information-theoretic model also inspires a new attack called a spatial attack and motivates the corresponding detection approach. We show simulation results that support our theoretic findings. Wei Yu 0002, Nan Zhang 0004, Xinwen Fu, Riccardo Bettati, Wei Zhao 0001 |
IEEE Trans. Computers | 4 |
| 2010 | Correlation-Based Traffic Analysis Attacks on Anonymity NetworksabstractIn this paper, we address attacks that exploit the timing behavior of TCP and other protocols and applications in low-latency anonymity networks. Mixes have been used in many anonymous communication systems and are supposed to provide countermeasures to defeat traffic analysis attacks. In this paper, we focus on a particular class of traffic analysis attacks, flow-correlation attacks, by which an adversary attempts to analyze the network traffic and correlate the traffic of a flow over an input link with that over an output link. Two classes of correlation methods are considered, namely time-domain methods and frequency-domain methods. Based on our threat model and known strategies in existing mix networks, we perform extensive experiments to analyze the performance of mixes. We find that all but a few batching strategies fail against flow-correlation attacks, allowing the adversary to either identify ingress and egress points of a flow or to reconstruct the path used by the flow. Counterintuitively, some batching strategies are actually detrimental against attacks. The empirical results provided in this paper give an indication to designers of Mix networks about appropriate configurations and mechanisms to be used to counter flow-correlation attacks. Ye Zhu 0001, Xinwen Fu, Bryan Graham, Riccardo Bettati, Wei Zhao 0001 |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2009 | Efficient calibration of thermal models based on application behaviorabstractWith increasing power densities, raising operating temperatures in chips threaten system reliability. Thermal control therefore has emerged as an important issue in system design and management. For dynamic thermal control to be effective, predictive thermal models of the system are needed. Such models typically use power as input, which renders them difficult to use in practical systems, where power monitoring is not available at processor or chip level. In this paper, we describe a methodology to infer the thermal model based on the monitoring of existing temperature sensors and of instruction counter registers. This allows the thermal model to be easily established, calibrated, and recalibrated at runtime to account for different thermal behavior due to either variations in fabrication or to varying environmental parameters. We validate the proposed methodology through a series of experiments. We also propose and validate an extension of the model and associated methodology for multicore processors. Youngwoo Ahn, Inchoon Yeo, Riccardo Bettati |
ICCD | 3 |
| 2009 | Use of competition detection in TCP for simple topology networks
SooHyun Cho, Riccardo Bettati |
Comput. Networks | 2 |
| 2009 | Compromising anonymous communication systems using blind source separationabstractWe propose a class of anonymity attacks to both wired and wireless anonymity networks. These attacks are based on the blind source separation algorithms widely used to recover individual signals from mixtures of signals in statistical signal processing. Since the philosophy behind the design of current anonymity networks is to mix traffic or to hide in crowds, the proposed anonymity attacks are very effective. The flow separation attack proposed for wired anonymity networks can separate the traffic in a mix network. Our experiments show that this attack is effective and scalable. By combining the flow separation method with frequency spectrum matching, a passive attacker can derive the traffic map of the mix network. We use a nontrivial network to show that the combined attack works. The proposed anonymity attacks for wireless networks can identify nodes in fully anonymized wireless networks using collections of very simple sensors. Based on a time series of counts of anonymous packets provided by the sensors, we estimate the number of nodes with the use of principal component analysis. We then proceed to separate the collected packet data into traffic flows that, with help of the spatial diversity in the available sensors, can be used to estimate the location of the wireless nodes. Our simulation experiments indicate that the estimators show high accuracy and high confidence for anonymized TCP traffic. Additional experiments indicate that the estimators perform very well in anonymous wireless networks that use traffic padding. Ye Zhu 0001, Riccardo Bettati |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2009 | Information Leakage as a Model for Quality of Anonymity NetworksabstractMeasures for anonymity in systems must be on one hand simple and concise, and on the other hand reflect the realities of real systems. Such systems are heterogeneous, as are the ways they are used, the deployed anonymity measures, and finally the possible attack methods. Implementation quality and topologies of the anonymity measures must be considered as well. We therefore propose a new measure for the anonymity degree, that takes into account these various. We model the effectiveness of single mixes or of mix networks in terms of information leakage, and we measure it in terms of covert channel capacity. The relationship between the anonymity degree and information leakage is described, and an example is shown. Ye Zhu 0001, Riccardo Bettati |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2008 | On localization attacks to Internet Threat Monitors: An information-theoretic frameworkabstractInternet threat monitoring (ITM) systems are a widely deployed facility to detect, analyze, and characterize dangerous Internet threats such as worms and distributed denial-of-service (DDoS) attacks. Nonetheless, an ITM system can also become the target of attack. In this paper, we address localization attacks against ITM systems in which an attacker impairs the effectiveness of ITM systems by identifying the locations of ITM monitors. We propose an information-theoretic framework for the modeling of localization attacks as communication channels. Based on the information-theoretic model, we generalize all existing attacks as ldquotemporal attacksrdquo, derive closed formulae of their performance, and propose an effective detection approach. The information-theoretic model also inspires a new attack called a spatial attack and motivates the corresponding detection approach. We show simulation results that support our theoretic findings. Wei Yu 0002, Nan Zhang 0004, Xinwen Fu, Riccardo Bettati, Wei Zhao 0001 |
DSN | 4 |
| 2008 | Transient Overclocking for Aperiodic Task Execution in Hard Real-Time SystemsabstractIn this paper we study the design of aperiodic servers in thermally constrained real-time systems. We start by illustrating how naive slack stealing leads to missed deadlines in the presence of speed-control-based dynamic thermal management. We then proceed to describe a design time execution-budget allocation scheme that takes advantage of the predictable thermal behavior of the system to control the execution of aperiodic workload. We introduce the transient overclocking server, which safely reduces the response time for aperiodic jobs in the presence of hard real-time periodic tasks and thermal constraints. We show by simulation that the transient overclocking server works well under thermal constraints of the system, and that there is an optimal budget allocation that depends on the temporal characteristics of the aperiodic tasks. Youngwoo Ahn, Riccardo Bettati |
ECRTS | 2 |
| 2008 | Reactive speed control in temperature-constrained real-time systems
Shengquan Wang, Riccardo Bettati |
Real Time Syst. | 2 |
| 2007 | Compromising Location Privacy inWireless Networks Using Sensors with Limited InformationabstractWe propose a methodology to identify nodes in fully anonymized wireless networks using collections of very simple sensors. Based on time series of counts of anonymous packets provided by the sensors, we estimate the number of nodes using principal component analysis. We then proceed to separate the collected packet data into traffic flows that, with help of the spatial diversity in the available sensors, can be used to estimate the location of the wireless nodes. Our simulation experiments indicate that the estimators show high accuracy and high confidence for anonymized TCP traffic. Additional experiments indicate that the estimators perform very well in anonymous wireless networks that use traffic padding. Ye Zhu 0001, Riccardo Bettati |
ICDCS | 2 |
| 2007 | Privacy of encrypted voice-over-IPabstractIn this paper, we present an early study on how timing-based traffic analysis attacks can be used to reconstruct the communication on end-to-end VOIP systems by taking advantage of the reduction or suppression of the generation of traffic whenever the sender detects a voice inactivity period. We describe a simple Bayesian classifier to identify simple voice signals from the pattern of packet timings. We then proceed to incorporate context awareness by using a Hidden Markov model. Experiments with very simple symbols show that the effectiveness to reconstruct the voice signal depends significantly on the quality of collected silence suppression information. We conclude by identifying a number of problems that need to be further studied in order to effectively assess the danger of silence suppression based attacks on VOIP systems. Tuneesh Leila, Riccardo Bettati |
SMC | 2 |
| 2006 | Communications quality of service for ad-hoc mobile optical free-space networksabstractMobile Optical Free Space networks are an emerg- ing technology that will offer low-delay and high speed con- nectivity using air-borne and ground wireless laser terminals. The time-variable link capacity and dynamic topology make Quality of Service provisioning a difficult problem. We present an architecture for end-to-end statistical delay guarantees. We describe a delay model that uses the concept of virtual traffic to accommodate link capacity variations and transient outages. A mechanism for deploying dependable TCP services is imple- mented in this QoS-enabled network. The primary-backup TCP replication mechanism is supported by the routing infrastructure and allows transparent server replication. We illustrate perfor- mance improvements with simulation results. Ionut Cardei, Allalaghatta Pavan, Riccardo Bettati |
CCNC | 3 |
| 2006 | Reactive Speed Control in Temperature-Constrained Real-Time SystemsabstractIn this paper, we study temperature-constrained real-time systems, where real-time guarantees must be met without exceeding safe temperature levels within the processor. We give a short review on temperature issues in processors and describe how speed control can be used to trade-off task delays against processor temperature. In this paper, we describe how traditional worst-case execution scenarios do not apply in temperature-constrained situations. As example, we adopt a simple reactive speed control technique. We show how this simple reactive scheme can improve the processor utilization compared with any constant-speed scheme. Shengquan Wang, Riccardo Bettati |
ECRTS | 2 |
| 2006 | Use of Competition Detection in TCP for Fair and Effective Utilization of Network BandwidthabstractThe fairness (or TCP-friendliness) of recent highspeed TCP proposals for high bandwidth-delay product networks is generally poor. We believe that the lack of TCP-friendliness of high-speed TCP proposals stems from their ineffectiveness in detecting competing TCP flows. We suggest a competition detection mechanism for a single TCP flow to detect the presence of competing TCP flows and propose a new TCP, called adaptive TCP (A-TCP), which uses the competition detection mechanism to control its aggressiveness: If it does not detect competing flows, a single A-TCP flow increases its sending rate aggressively in order to highly utilize the network. Otherwise, it behaves like a standard TCP flow to fairly share network resources with competing flows. We implemented A-TCP as part of Linux as well as in ns-2. Experimental results show that A-TCP achieves better fairness than existing high-speed TCP proposals. SooHyun Cho, Riccardo Bettati |
GLOBECOM | 2 |
| 2006 | Adaptive Aggregated Aggressiveness Control on Parallel TCP Flows Using Competition DetectionabstractWe present a competition detection mechanism for parallel TCP flows and use this to propose a new parallel TCP congestion control scheme called adaptive TCP-P (A-TCP-P). A-TCP-P automatically controls the aggregated aggressiveness of parallel TCP flows to fairly share network bandwidth with single TCP flows independently from the number of the parallel TCP flows while effectively utilizing available bandwidth when it does not detect competition. A-TCP-P realizes this by adaptively adjusting the aggregated aggressiveness of parallel TCP flows according to network situations in a self-managed way. We implement A-TCP-P as a part of Linux kernel and the experimental results show that the proposed parallel TCP scheme improves per-host fairness and effectively utilize available bandwidth with reduced packet loss when it does not detect competing TCP flows from other hosts. SooHyun Cho, Riccardo Bettati |
ICCCN | 2 |
| 2006 | Delay Analysis in Temperature-Constrained Hard Real-Time Systems with General Task ArrivalsabstractIn this paper, we study temperature-constrained hard real-time systems, where real-time guarantees must be met without exceeding safe temperature levels within the processor. Dynamic speed scaling is one of the major techniques to manage power so as to maintain safe temperature levels. As example, we adopt a simple reactive speed control technique in our work. We design a methodology to perform delay analysis for general task arrivals under reactive speed control with first-in-first-out (FIFO) scheduling and static-priority (SP) scheduling. As a special case, we obtain a close-form delay formula for the leaky-bucket task arrival model. Our data show how simple reactive speed control can decrease the delay of tasks compared with any constant-speed scheme Shengquan Wang, Riccardo Bettati |
RTSS | 2 |
| 2005 | Anonymity analysis of mix networks against flow-correlation attacksabstractMix networks are designed to provide anonymity for users in a variety of applications, including anonymous Web browsing and numerous E-commerce systems. Such networks have been shown to be susceptible to flow correlation attacks empirically. In this paper, we model the effectiveness of flow correlation attacks. Our results illustrate the quantitative relationship among system parameters such as sample size, noise level, payload flow rate, and detection rate. Our analysis quantitatively predicts how existing flow-based anonymous systems would fail under flow-correlation attacks, thus providing useful guidelines for the design of future anonymous systems. Ye Zhu 0001, Xinwen Fu, Riccardo Bettati, Wei Zhao 0001 |
GLOBECOM | 3 |
| 2005 | Collaborative congestion control in parallel TCP flowsabstractWe suggest a new congestion control scheme in parallel TCP flows and compare it with single-flow based congestion control approaches in the Internet. When a node opens multiple connections that are going to the same or nearby destinations, we can assume that there is a significant correlation of congestion events among the flows. In this paper, we leverage this relationship to improve the performance provided to parallel TCP flows by having TCP senders of the related connections exchange congestion information. The usefulness of our scheme is shown by augmenting a measurement-based TCP congestion control mechanism to utilize congestion measurement information from other TCP flows at the sender. Furthermore, we compare our scheme with ECN-based TCP congestion control. Our measurement show improvements over single-flow based approaches. In terms of packet loss and delay jitter, we show that collaborative congestion control is comparable with architecturally significantly more intensive schemes, such as ECN-based TCP. SooHyun Cho, Riccardo Bettati |
ICC | 2 |
| 2005 | On Flow Marking Attacks in Wireless Anonymous Communication NetworksabstractThis paper studies the degradation of anonymity in a flow-based wireless mix network under flow marking attacks, in which an adversary embeds a recognizable pattern of marks into wireless traffic flows by electromagnetic interference. We find that traditional mix technologies are not effective in defeating flow marking attacks, and it may take an adversary only a few seconds to recognize the communication relationship between hosts by tracking such artificial marks. Flow marking attacks utilize frequency domain analytical techniques and convert time domain marks into invariant feature frequencies. To counter flow marking attacks, we propose a new countermeasure based on digital filtering technology, and show that this filter-based counter-measure can effectively defend a wireless mix network from flow marking attacks. Xinwen Fu, Ye Zhu 0001, Bryan Graham, Riccardo Bettati, Wei Zhao 0001 |
ICDCS | 4 |
| 2005 | Anonymity vs. Information Leakage in Anonymity SystemsabstractMeasures for anonymity in systems must be on one hand simple and concise, and on the other hand reflect the realities of real systems. Such systems are heterogeneous, as are the ways they are used, the deployed anonymity measures, and finally the possible attack methods. Implementation quality and topologies of the anonymity measures must be considered as well. We therefore propose a new measure for the anonymity degree, which takes into account possible heterogeneity. We model the effectiveness of single mixes or of mix networks in terms of information leakage and measure it in terms of covert channel capacity. The relationship between the anonymity degree and information leakage is described, and an example is shown. Ye Zhu 0001, Riccardo Bettati |
ICDCS | 2 |
| 2005 | Architecture for delay-sensitive communications in mobile optical free-space networksabstractMobile optical free space networks are an emerging architecture that can provide high speed connectivity between a ground-based backbone network and mobile users in challenging environments. In such a network traffic could be relayed by airborne or ground routers using wireless optical links. The variable nature of the wireless optical channel complicates support for real-time distributed applications demanding bounds on communication delay. In this paper we present an architecture for provisioning end-to-end statistical delay guarantees in MOFS networks. We describe a delay model that uses a concept of virtual traffic to accommodate link capacity variation. The link delay estimation is integrated with a population-insensitive utilization based flow admission control technique and IP differentiated services. The models and architecture for QoS are presented and the system performance is analyzed Ionut Cardei, Allalaghatta Pavan, Riccardo Bettati |
MASS | 3 |
| 2005 | On the Effectiveness of Continuous-Time Mixes under Flow-Correlation Based Anonymity AttacksabstractIn flow-based mix networks, so-called flow correlation attacks have been proposed earlier and have been shown empirically to seriously degrade mix-based anonymous communication systems. In this paper, we theoretically analyze the effectiveness of a mix network under flow correlation attacks. Our formulae clearly show how a mix network will ultimately fail when an adversary has access to sufficiently long flow samples, independently of the type of flows (TCP or UDP). We illustrate the analysis methodology by modeling a continuous-time mix, which randomly delays each incoming packet. Our queuing-model-based analysis captures the essence of flow correlation attacks and can provide useful guidelines for designers who develop and deploy anonymity systems Ye Zhu 0001, Xinwen Fu, Riccardo Bettati |
NCA | 3 |
| 2005 | Aggregated Aggressiveness Control on Groups of TCP Flows
SooHyun Cho, Riccardo Bettati |
NETWORKING | 2 |
| 2005 | Real-Time Component-Based SystemsabstractComponent technology has become a central focus of software engineering in research and development. Reusability is a key factor that contributes to its success. The reuse of components can lead to a shortening of software development cycles and savings in software development costs. However, existing component models provide no support for real-time services and some real-time extensions of component models lack of consideration for reusability of components in providing real-time services. In this work, we develop a real-time component-based system that maintains the reusability of components. Shengquan Wang, Sangig Rho, Zhibin Mai, Riccardo Bettati, Wei Zhao 0001 |
IEEE Real-Time and Embedded Technology and Applications Symposium | 4 |
| 2004 | Providing Statistical Delay Guarantees in Wireless NetworksabstractWe study the delay performance of policed traffic to provide real-time guarantees over wireless networks. A number of models have been presented in the literature to describe wireless (radio or optical) networks in terms of the wireless channel and the underlying error control mechanisms. We describe a general framework to incorporate such models into delay guarantee computations for real-time traffic. Static-priority scheduling is considered, and two different admission control mechanisms are used to achieve the trade-off between resource utilization and admission overhead. Shengquan Wang, Ripal Nathuji, Riccardo Bettati, Wei Zhao 0001 |
ICDCS | 3 |
| 2004 | Fast Software Component Migration for Applications Survivability in Distributed Real-Time SystemsabstractIn this paper we propose and evaluate a methodology for run-time fast software component migration for application survivability in distributed real-time systems. For fast migration we focus on the two dominant factors; lightweight migration and proactive resource discovery. The former is to minimize the absolute amount of time required for migration and the latter is to provide a destination host information at the time of migration decision. The run-time software component is implemented as Java object whose class is defined by extending the unicast remote server class. The proactive resource discovery consists of Community protocol and associated algorithms. These two ideas have been implemented as a middleware that also provides a real-time job scheduler in JVM (Java Virtual Machine), and a naming server. Our analysis and simulation in a cluster computing environment show that the proactive resource discovery requires very low communication overhead while maintaining high effectiveness in finding available CPU resources. Our implementation and measurement show that run-time component migration based on our approach takes much less time compared to the approach based on reactive resource discovery Byung Kyu Choi, Sangig Rho, Riccardo Bettati |
ISORC | 3 |
| 2004 | Providing absolute differentiated services for real-time applications in static-priority scheduling networksabstractIn this paper, we propose and analyze a methodology for providing absolute differentiated services for real-time applications. We develop a method that can be used to derive delay bounds without specific information on flow population. With this new method, we are able to successfully employ a utilization-based admission control approach for flow admission. This approach does not require explicit delay computation at admission time and, hence, is scalable to large systems. We assume the underlying network to use static-priority schedulers. We design and analyze several priority assignment algorithms and investigate their ability to achieve higher utilization bounds. Traditionally, schedulers in differentiated services networks assign priorities on a class-by-class basis, with the same priority for each class on each router. In this paper, we show that relaxing this requirement, that is, allowing different routers to assign different priorities to classes, achieves significantly higher utilization bounds. Shengquan Wang, Dong Xuan, Riccardo Bettati, Wei Zhao 0001 |
IEEE/ACM Trans. Netw. | 3 |
| 2004 | A quantitative analysis of anonymous communicationsabstractThis paper quantitatively analyzes anonymous communication systems (ACS) with regard to anonymity properties. Various ACS have been designed & implemented. However, there are few formal & quantitative analyzes on how these systems perform. System developers argue the security goals which their systems can achieve. Such results are vague & not persuasive. This paper uses a probabilistic method to investigate the anonymity behavior of ACS. In particular, this paper studies the probability that the true identity of a sender can be discovered in an ACS, given that some nodes have been compromised. It is through this analysis that design guidelines can be identified for systems aimed at providing communication anonymity. For example, contrary to what one would intuitively expect, these analytic results show that the probability that the true identity of a sender can be discovered might not always decrease as the length of communication path increases. Xinwen Fu, Riccardo Bettati, Wei Zhao 0001 |
IEEE Trans. Reliab. | 3 |
| 2003 | On Effectiveness of Link Padding for Statistical Traffic Analysis AttacksabstractTraffic analysis attacks aim at deriving mission critical information from the analysis of the traffic transmitted over a network. Countermeasures for such attacks are usually realized by properly "padding" the payload traffic so that the statistics of the overall traffic become significantly different from that of the payload traffic. In this paper, we propose a analytical framework for traffic analysis attacks based on statistical pattern recognition techniques. We study the effectiveness of countermeasures for traffic analysis attacks within our proposed framework. Two basic countermeasure strategies are (a) to pad the traffic with constant interarrival times of packets (CIT) or (b) to pad the traffic with variable interarrival times (VIT). Our experiments show that CIT countermeasures fail when the adversary uses sample variance or sample entropy of packet interarrival times for statistical analysis. On the other hand, VIT countermeasures are effective regardless of which sample statistics are used by the adversary. These observations are validated by analysis of detection rates based on sample distributions of packet interarrival times. Xinwen Fu, Bryan Graham, Riccardo Bettati, Wei Zhao 0001 |
ICDCS | 3 |
| 2003 | Analytical and Empirical Analysis of Countermeasures to Traffic Analysis AttacksabstractWe study countermeasures to traffic analysis attacks. A common strategy for such countermeasures is link padding. We consider systems where payload traffic is padded so that packets have either constant inter-arrival times or variable inter-arrival times. The adversary applies statistical recognition techniques to detect the payload traffic rates by using statistical measures like sample mean, sample variance, or sample entropy. We evaluate quantitatively the ability of the adversary to make a correct detection and derive closed-form formulas for the detection rate based on analytical models. Extensive experiments were carried out to validate the system performance predicted by the analytical method. Based on the systematic evaluations, we develop design guidelines for the proper configuration of a system in order to minimize the detection rate Xinwen Fu, Bryan Graham, Riccardo Bettati, Wei Zhao 0001, Dong Xuan |
ICPP | 3 |
| 2003 | A Study of Providing Statistical QoS in a Differentiated Sevices NetworkabstractIn this paper, we propose and analyze a methodology for providing statistical guarantees within the diffserv model in a network, that uses static-priority schedulers. We extend the previous work on statistical delay analysis and develop a method that can be used to derive delay bounds without specific information on flow population. With this new method, we are able to successfully employ a utilization-based admission control approach for flow admission. This approach does not require explicit delay computation at admission time and hence is scalable to large systems. We systematically analyze the performance of our approaches in terms of system utilization. As expected, our experimental data show that statistical services can achieve much higher utilization than deterministic services. Shengquan Wang, Dong Xuan, Riccardo Bettati, Wei Zhao 0001 |
NCA | 3 |
| 2003 | Utilization-Based Admission Control for Scalable Real-Time Communication
Byung Kyu Choi, Dong Xuan, Riccardo Bettati, Wei Zhao 0001, Chengzhi Li |
Real Time Syst. | 3 |
| 2002 | An Optimal Strategy for Anonymous Communication ProtocolsabstractFor many Internet applications, the ability to protect the identity of participants in a distributed applications is critical. For such applications, a number of anonymous communication systems have been realized over the recent years. The effectiveness of these systems relies greatly on the way messages are routed among the participants. (We call this the route selection strategy.) In this paper we describe how to select routes so as to maximize the ability of the anonymous communication systems to protect anonymity To measure this ability, we define a metric (anonymity degree), and we design and evaluate an optimal route selection strategy that maximizes the anonymity degree of a system. Our analytical and experimental data shows that the anonymity degree may not always monotonically increase as the length of communication paths increase. We also found that variable path-length strategies perform better than fixed-length strategies. Xinwen Fu, Riccardo Bettati, Wei Zhao 0001 |
ICDCS | 3 |
| 2001 | Endpoint Admission Control: Network Based ApproachabstractProposes a network-based endpoint admission control system for scalable QoS-guaranteed real-time communication services. This system is based on a sink tree-based resource management strategy and is particularly well-suited for differentiated services-based architectures. By performing the admission decision at the endpoints, the flow setup latency and the signaling overhead are kept to a minimum. In addition, the proposed system integrates routing and resource reservation along the routes, and therefore displays higher admission probability and better link resource utilization. This approach achieves a low overall admission control overhead because much of the delay computation is done during system configuration, and so resources can effectively be pre-allocated before run time. We investigate a number of resource-sharing approaches that allow resources to be efficiently re-allocated at run time with minimized additional overhead. We provide simulation experiments that illustrate the benefits of using sink tree-based resource management for resource pre-allocation and for routing, both with and without resource sharing. Byung Kyu Choi, Riccardo Bettati |
ICDCS | 2 |
| 2001 | Providing Absolute Differentiated Services for Real-Time Application in Static-Priority Scheduling NetworksabstractWe propose and analyze a methodology for providing absolute differentiated services for real-time applications in networks that use static-priority schedulers. We extend previous work on worst-case delay analysis and develop a method that can be used to derive delay bounds without specific information on flow population. With this new method, we are able to successfully employ a utilization-based admission control approach for flow admission. This approach does not require explicit delay computation at admission time and hence is scalable to large systems. We assume the underlying network to use static-priority schedulers. We design and analyze several priority assignment algorithms, and investigate their ability to achieve higher utilization bounds. Traditionally, schedulers in differentiated services networks assign priorities on a class-by-class basis, with the same priority for each class on each router. We show that relaxing this requirement, that is, allowing different routers to assign different priorities to classes, achieves significantly higher utilization bounds. Shengquan Wang, Dong Xuan, Riccardo Bettati, Wei Zhao 0001 |
INFOCOM | 3 |
| 2001 | Differentiated Services with Statistical Real-Time Guarantees in Static-Priority Scheduling NetworksabstractWe propose and analyze a methodology for providing absolute differentiated services with statistical performance guarantees for real-time applications in networks that use class-based (as opposed to flow-aware) static priority schedulers. We develop a method that can be used to derive statistical delay guarantees in a flow-unaware fashion. Traditionally, both deterministic and statistical delay analysis methods either depend on schedulers that keep per-flow state information, or require detailed information about flow population at delay analysis time. The fact that no such information is needed for delay analysis allows us to perform deadline tests during system (re-)configuration time. We are so able to reduce the runtime admission control to a simple utilization test. No explicit delay computation is necessary at admission time, making this approach scalable to large systems. Shengquan Wang, Dong Xuan, Riccardo Bettati, Wei Zhao 0001 |
RTSS | 3 |
| 2001 | NetCamo: camouflaging network traffic for QoS-guaranteed mission critical applicationsabstractThis paper presents the general approach, design, implementation, and evaluation of NetCamo, which is a system to prevent traffic analysis in systems with real-time requirements. Integrated support for both security and real-time is becoming necessary for computer networks that support mission critical applications. This study focuses on how to integrate both the prevention of traffic analysis and guarantees for worst-case delays in an internetwork. We propose and analyze techniques that efficiently camouflage network traffic and correctly plan and schedule the transmission of payload traffic so that both security and real-time requirements are met. The performance evaluation shows that our NetCamo system is effective and efficient. By using the error between target camouflaged traffic and the observed (camouflaged) traffic as metric to measure the quality of the camouflaging, we show that NetCamo achieves very high levels of camouflaging without compromising real-time requirements. Xinwen Fu, Dong Xuan, P. U. Shenoy, Riccardo Bettati, Wei Zhao 0001 |
IEEE Trans. Syst. Man Cybern. Part A | 5 |
| 2000 | Scalable QoS Guaranteed Communication Services for Real-Time ApplicationsabstractWe propose an approach to flow-unaware admission control which is a combination with an aggregate packet forwarding scheme, improving scalability of networks while guaranteeing end-to-end deadlines for real-time applications. We achieve this by using an off-line delay computation and verification step, which allows to reduce the overhead at admission control while keeping admission probability and resource utilization high. Our evaluation data show that our system's admission probabilities are very close to those of significantly more expensive flow-aware approaches. At the same time, the admission control overhead during flow establishment is very low. Our results therefore support the claim from the DS architecture literature that scalability can be achieved through flow aggregation without sacrificing resource utilization and with significant reduction in run time overhead. Byung Kyu Choi, Dong Xuan, Chengzhi Li, Riccardo Bettati, Wei Zhao 0001 |
ICDCS | 4 |
| 2000 | HYDRANET-FT: Network Support for Dependable ServicesabstractWith the Internet increasingly being used as the access medium for a variety of critical services, there is a growing need to provide fault-tolerant (FT) services over internetworks, in a completely client-transparent fashion. We present HydraNet-FT, an infrastructure to dynamically replicate services across an internetwork and have the replicas provide a single fault-tolerant service access point to clients. HydraNet-FT uses the TCP communication protocol with a few modifications on the server side to allow one-to-many message delivery from a client to service replicas and many-to-one message delivery from the replicas to the client. A communication channel between the replicas provides atomicity and message ordering. A low-latency failure estimator is used to detect failures of servers in the system and to initiate fail-over mechanisms. An implementation and measurements on a local testbed show that the overhead of our scheme is reasonably small. Gurudatt Shenoy, Suresh K. Satapati, Riccardo Bettati |
ICDCS | 3 |
| 2000 | Utilization-Based Admission Control for Real-Time ApplicationsabstractIn this paper, we present a methodology to use utilization-based admission control in guaranteed real-time communication in a scalable fashion. We make admission control scalable by using a configuration-time test to determine a safe utilization level of servers. Admission control at run-time then is reduced to simple utilization tests on the servers along the path of the new flow. Furthermore, we discuss how appropriate route selection improve utilization levels, design a safe route selection heuristic algorithm to achieve high utilization of resources, and derive two bounds on the maximum utilization level for given traffic in a network. We compare the results of our route selection heuristics with that of a shortest-path based algorithm, and find that our heuristics can achieve a much higher maximum utilization level than that of the shortest-path based algorithm. Dong Xuan, Chengzhi Li, Riccardo Bettati, Jianer Chen, Wei Zhao 0001 |
ICPP | 3 |
| 1999 | New Delay Analysis in High Speed NetworksabstractThe implementation of bounded-delay services over integrated services networks relies admission control mechanisms that in turn use end-to-end delay computation algorithms. For guaranteed-rate scheduling algorithms such as fair queueing, delay computation based on Cruz's service curve model performs very well. Many currently deployed networks, be they packet-switched or ATM based, rely on non-guaranteed-rate disciplines, most prominently FIFO and static-priority disciplines. We show that for this class of disciplines the service curve model performs poorly. We propose the Integrated Approach as alternative to the service curve model to cluster servers for delay computation purposes, and show in a series of evaluations that this new approach outperforms approaches based on the service curve model as well as other currently used approaches. Chengzhi Li, Riccardo Bettati, Wei Zhao 0001 |
ICPP | 2 |
| 1999 | HydraNet: Network support for scaling of large-scale services
Hamesh Chawla, Geoff Dillon, Riccardo Bettati |
J. Netw. Comput. Appl. | 3 |
| 1998 | HYDRANET : Network Support for Scaling of Large-Scale ServicesabstractWith the explosive growth of demand for services on the Internet, the networking infrastructure (routers, protocols, servers) is under considerable stress. Mechanisms are needed for current and future IP services to scale in a client-transparent way. We present HYDRANET, an infrastructure that allows to dynamically distribute IP services by placing service agents (caching agents, mirrors, replicas) that are under the server's control at strategic points in the internetwork. HYDRANET is based on replicating transport-level service access points for transparent distribution or replication of IP services. Measurements on a local testbed show that the overhead of our scheme is small. This replication scheme is widely applicable. We use HYDRANET to implement HYDRAWEB, a system for active, push based, and client-transparent Web caching. Similarly, HYDRANET can be used to implement highly fault-tolerant servers or application-level gateways. Hamesh Chawla, Geoff Dillon, Riccardo Bettati |
ICCCN | 3 |
| 1998 | Response Time Analysis for Distributed Real-Time Systems with Bursty Job ArrivalsabstractThis paper presents a new schedulability analysis methodology for distributed hard real-time systems with bursty job arrivals. The schedulability is analyzed by comparing worst-case response times of jobs with their timing constraints. We compute response times with a new method, which uses the amount of received service time to determine the response time of instances of a job. We illustrate how this method can be applied to exactly determine worst-case response times for processors with preemptive static priority schedulers, and how it gives a good approximation on the response times for processors with non-preemptive static-priority scheduling or first-come-first-served scheduling. Our schedulability analysis method is the first to support systems with arbitrary job arrival patterns. Nevertheless, it performs better than other known approaches used for systems with periodic job arrivals. Chengzhi Li, Riccardo Bettati, Wei Zhao 0001 |
ICPP | 2 |
| 1997 | Distributed Connection Management for Real-Time Communication over Wormhole-Routed NetworksabstractWormhole networks provide a very-high-speed communication medium that is well suited for a large number of bandwidth demanding applications. Unfortunately, the lack of buffering in the switches causes blocked packets to transiently monopolize arbitrary large portions of the network, thus making it difficult to give real-time guarantees when connections contend for communication links. We present an efficient, fully distributed admission control scheme for time-critical connections over wormhole networks. In comparison to a corresponding centralized scheme, such a distributed scheme offers advantages in terms of scalability and easy integration into hybrid networks. We compare this scheme to a centralized algorithm in a suite of simulation experiments and show that its performance is encouraging. Sharad Sundaresan, Riccardo Bettati |
ICDCS | 2 |
| 1997 | Static priority scheduling for ATM networksabstractStatic priority scheduling is popular for traffic scheduling in ATM switches because it is less costly than dynamic priority scheduling while being sensitive to the delay constraints of connections. We study delay computation and priority assignment problems in an ATM network with static priority scheduling. Given an ATM network with arbitrary topology, it is possible that the traffic on it may become unstable (i.e., packet delays become unbounded) due to the potential cyclic dependency of the traffic. An unstable network is definitely unacceptable for many delay sensitive applications. We start by formally deriving a simple condition under which the network is guaranteed to be stable. We then develop a numerical method to compute worst case end to end delays in an ATM network with arbitrary topology. Convergence of the method is formally proved and a closed form for the computing error is obtained. Despite its advantages, static priority scheduling remains sensitive to proper priority assignment. We describe two simple priority assignment methods, which we show to outperform other commonly used methods. Chengzhi Li, Riccardo Bettati, Wei Zhao 0001 |
RTSS | 2 |
| 1996 | Dynamic Resource Allocation Migration for Multiparty Real-Time CommunicationsabstractWith long-lived multi-party connections, resource allocation subsystems in distributed real-time systems or communication networks must be aware of dynamically changing network load in order to reduce call-blocking probabilities. We describe a distributed mechanism to dynamically reallocate ("migrate") resources without adversely affecting the performance that established connections receive. In addition to allowing systems to dynamically adapt to load, this mechanism allows for distributed relaxation of resources (i.e. the adjustment of overallocation of resources due to conservative assumptions at connection establishment time) for multicast connections. We describe how dynamic resource migration is incorporated in the Tenet Scheme 2 protocols for multiparty real-time communication. Riccardo Bettati, Amit Gupta 0001 |
ICDCS | 1 |
| 1996 | Perts: a Prototyping Environment for Real-Time SystemsabstractThis paper describes PERTS, a prototyping environment for real-time systems. PERTS provides a comprehensive set of design, validation, and simulation tools that are built on recent theoretical advances. It also provides software modules that implement wellknown and novel real-time scheduling algorithms, task and resource assignment algorithms, and resource access control protocols. Together, the tools and software modules support the systematic and rigorous evaluation of new designs, experimentation with alternative scheduling and resource management strategies, and the evaluation and validation of the resultant real-time system. Jane W.-S. Liu, Chung Laung Liu, Zhong Deng, Too-Seng Tia, Jun Sun 0002, Matthew F. Storch, David Hull, J. L. Redondo, Riccardo Bettati, A. Silberman |
Int. J. Softw. Eng. Knowl. Eng. | 9 |
| 1995 | Connection Establishment for Multi-Party Real-Time Communication
Riccardo Bettati, Domenico Ferrari, Amit Gupta 0001, W. Heffner, Wingwai Howe, Mark Moran, Quyen Nguyen, R. Yavatkar |
NOSSDAV | 1 |
| 1994 | Imprecise computationsabstractThe imprecise computation technique has been proposed as a way to handle transient overload and to enhance fault tolerance of real-time systems. In a system based on this technique, each time-critical task is designed in such a way that it can produce a usable, approximate result in time whenever a failure or overload prevents it from producing the desired, precise result. This paper describes ways to implement imprecise computations, models to characterize them and algorithms for scheduling them. An imprecise mechanism for the generation and use of approximate results can be integrated in a natural way with a traditional fault-tolerance mechanism. An architectural framework for this integration is described.> Jane W.-S. Liu, Wei-Kuan Shih, Kwei-Jay Lin, Riccardo Bettati, Jen-Yao Chung |
Proc. IEEE | 4 |
| 1993 | PERTS: A prototyping environment for real-time systemsabstractPERTS is a prototyping environment for real-time systems. It contains schedulers and resource access protocols for time-critical applications, together with a comprehensive set of tools for the analysis, validation, and evaluation of real-time systems built on the scheduling paradigms supported by these building blocks. This paper describes the underlying models of real-time systems supported by PERTS, as well as its capabilities and intended use. A key component is the schedulability analyzer. The basic version of this system of tools supports the validation and evaluation of real-time systems built on the framework of the periodic-task model. This system of tools is now available.> Jane W.-S. Liu, J. L. Redondo, Zhong Deng, Too-Seng Tia, Riccardo Bettati, A. Silberman, Matthew F. Storch, Rhan Ha, Wei-Kuan Shih |
RTSS | 5 |
| 1992 | End-to-End Scheduling to Meet Deadlines in Distributed SystemsabstractAlgorithms for scheduling a class of systems in which all the tasks execute on different processors in turn in the same order are described. This end-to-end scheduling problem is known as the flow-shop problem. Two cases in which the problem is tractable are presented, and a heuristic for the NP-hard general case is evaluated. The traditional flow-shop model is generalized in two directions. First, an algorithm for scheduling flow shops in which tasks can be serviced more than once by some processors is presented. Second, a heuristic algorithm for scheduling flow shops with periodic tasks is described. Scheduling systems with more than one flow shop are considered.> Riccardo Bettati, Jane W.-S. Liu |
ICDCS | 1 |