Cees T. A. M. de Laat

dblp:d/CeesTAMdeLaat · also Cees de Laat · DBLP profile ↗
← Back
131ranked-venue papers
2as first author
6since 2021 · last 2025
0009-0009-3025-2974ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 62 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 16Applied, interdisciplinary, general and emerging computing · 14Security and privacy · 12 · 3 since 2021Computer networks · 10Artificial intelligence and machine learning · 4Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2025 COLIBRI: Optimizing Multi-party Secure Neural Network Inference Time for Transformers
Daphnee Chabal, Tim Müller, Eloise Zhang, Dolly Sapra, Cees T. A. M. de Laat, Zoltán Ádám Mann
SEC (1)5
2022 A Bayesian game-enhanced auction model for federated cloud services using blockchain
abstract
Industrial applications often require federated cloud services from multiple providers to improve reliability and flexibility. Traditional selection methods through auctions usually involve a centralized auctioneer to coordinate the auction procedure. Blockchain and smart contracts provide a decentralized mechanism to automate the cloud auction process; however, existing solutions fail in the selection of the most suitable providers and the violation detection of the signed auction agreements, which are also known as service-level agreements (SLAs). To tackle these problems, we propose an integrated auction model using Bayesian game theory and blockchain techniques. The proposed model is enhanced with two Bayesian Nash Equilibriums (BNEs); the first BNE enables the selection of cost-effective providers to construct the federated cloud services, while the second BNE ensures consistent and trustworthy monitoring of federated SLAs. Moreover, a timed message submission (TMS) algorithm is proposed to protect the auction privacy during the message submission phase. This paper validates the equilibrium results of two BNEs and implements the proposed model on the Ethereum blockchain. The analytical and experimental results demonstrate the feasibility, trustworthiness, and cost-effectiveness of our model.
Zeshun Shi, Huan Zhou 0006, Cees T. A. M. de Laat, Zhiming Zhao
Future Gener. Comput. Syst.3
2022 Experimental Evaluation of e.MMC Data Recovery
abstract
In this paper, we explore the data recovery procedures from e∙MMCs. The e∙MMC is one of the “managed” flash memory devices that are popularly used in modern digital devices as their storage media. The e∙MMC, which consists of flash memory and the flash memory controller, optimizes the data input/output between the host device and the non-volatile memory through its standardized protocol. Its standardized structure and protocol makes forensic physical data acquisition simpler than handling the raw flash memory. However, its secure data purging features, such as Secure Erase and Sanitize, make data recovery from e∙MMC a challenging task. In this research, we investigate inside the e∙MMCs, and evaluate advanced data recovery procedures. By reverse engineering the structures of e∙MMCs and accessing the internal flash memory, we discover that securely erased data is still recoverable from the internal flash memory. In some models, more than 99% of the securely erased data can still be recoverable by accessing the flash memory inside the e∙MMCs. The data extraction method, along with experimental data recovery evaluation, will be explored in this paper.
Aya Fukami, Sasha Sheremetov, Francesco Regazzoni 0001, Zeno J. M. H. Geradts, Cees T. A. M. de Laat
IEEE Trans. Inf. Forensics Secur.5
2021 Securing Home Wi-Fi with WPA3 Personal
abstract
Wi-Fi Protected Access 3 (WPA3) became a mandatory part of the Wi-Fi certification on July 1st2020. Therefore, the adoption rate of WPA3 is expected to grow soon. In this paper, we focus on WPA3 personal transition mode, in particular the security of this mode. We argue that transition mode is a requirement in home environments for the foreseeable future. We investigate whether it is possible to secure a WPA3 personal transition mode network in such a way that downgrade attacks are not feasible. We find that even with the security recommendations that the Wi-Fi Alliance recently issued for WPA3, common implementations running in transition mode can still be downgraded to WPA2. In our experiments, we can see that there are differences between WPA3 implementations in terms of security. The Wi-Fi Alliance has already announced upcoming additions to the WPA3 standard. These additions offer essential improvements to the security of WPA3 personal transition mode networks. We believe that the WPA3 certification should be extended to include the recently announced additions to WPA3. In addition to this, we make several recommendations to ensure the safe operation of WPA3. Together these changes will resolve most of the implementation differences we observed. Furthermore, we argue that mutual authentication is an essential stepping stone towards a more secure Wi-Fi ecosystem and discuss two mechanisms.
Erik Lamers, Raoul Dijksman Mensenkamp, Arjan van der Vegt, Mayur Sarode, Cees T. A. M. de Laat
CCNC5
2021 Profiling and Discriminating of Containerized ML Applications in Digital Data Marketplaces (DDM)
abstract
A Digital Data Marketplace (DDM) facilitates secure and trustworthy data sharing among multiple parties. For instance, training a machine learning (ML) model using data from multiple parties normally contributes to higher prediction accuracy. It is crucial to enforce the data usage policies during the execution stage. In this paper, we propose a methodology to distinguish programs running inside containers by monitoring system calls sequence externally. To support container portability and the necessity of retraining ML models, we also investigate the stability of the proposed methodology in 7 typical containerized ML applications over different execution platform OSs and training data sets. The results show our proposed methodology can distinguish between applications over various configurations with an average classification accuracy of 93.85%, therefore it can be integrated as an enforcement component in DDM infrastructures.
Lu Zhang 0046, Reginald Cushing, Ralph Koning, Cees T. A. M. de Laat, Paola Grosso
ICISSP4
2021 Enforcing trustworthy cloud SLA with witnesses: A game theory-based model using smart contracts
abstract
There lacks trust between the cloud customer and provider to enforce traditional cloud SLA (Service Level Agreement) where the blockchain technique seems a promising solution. However, current explorations still face challenges to prove that the off-chain SLO (Service Level Objective) violations really happen before recorded into the on-chain transactions. In this paper, a witness model is proposed implemented with smart contracts to solve this trust issue. The introduced role, "Witness", gains rewards as an incentive for performing the SLO violation report, and the payoff function is carefully designed in a way that the witness has to tell the truth, for maximizing the rewards. This fact that the witness has to be honest is analyzed and proved using the Nash Equilibrium principle of game theory. For ensuring the chosen witnesses are random and independent, an unbiased selection algorithm is proposed to avoid possible collusions. An auditing mechanism is also introduced to detect potential malicious witnesses. Specifically, we define three types of malicious behaviors and propose quantitative indicators to audit and detect these behaviors. Moreover, experimental studies based on Ethereum blockchain demonstrate the proposed model is feasible, and indicate that the performance, ie, transaction fee, of each interface follows the design expectations.
Huan Zhou 0006, Xue Ouyang 0003, Jinshu Su, Cees T. A. M. de Laat, Zhiming Zhao
Concurr. Comput. Pract. Exp.4
2020 μ-Genie: A Framework for Memory-Aware Spatial Processor Architecture Co-Design Exploration
abstract
Spatial processor architectures are essential to meet the increasing demand in performance and energy efficiency of both embedded and high performance computing systems. Due to the growing performance gap between memories and processors, the memory system of ten determines the overall performance and power consumption in silicon. The interdependency between memory system and spatial processor architectures suggests that they should be co-designed. For the same reason, state-of-the-art design methodologies for processor architectures are ineffective for spatial processor architectures because they do not include the memory system. In this paper, we present μ -Genie: an automated framework for co-design-space exploration of spatial processor architecture and the memory system, starting from an application description in a high-level programming language. In addition, we propose a spatial processor architecture template that can be configured at design-time for optimal hardware implementation. To demonstrate the effectiveness of our approach, we show a case study of co-designing a spatial processor using different memory technologies.
Giulio Stramondo, Manil Dev Gomony, Bartek Kozicki, Cees T. A. M. de Laat, Ana Lucia Varbanescu
DSD4
2020 Wi-Fi 6 performance measurements of 1024-QAM and DL OFDMA
abstract
IEEE 802.11ax is the new standard introduced by the IEEE that focuses on improving efficiency of Wireless LANs. Among others, two of the newly introduced features are 1024 Quadrature Amplitude Modulation (QAM) and Orthogonal Frequency Division Multiple Access (OFDMA). In this paper, the expected throughput gain of 25% with the new 1024-QAM and expected latency reduction with downlink (DL) OFDMA are examined with state of the art reference boards of two different Wi-Fi chipset manufacturers. Using three Samsung S10 mobile phones as clients, experiments were performed to measure the expected increase in throughput and decrease in latency.The 25% increase in throughput with 1024-QAM was achieved, albeit with a maximum range of operation of less than 6 meters when using a maximal transmit power for MCS 11. We observed a very low percentage of packets transmitted using DL OFDMA in the traffic profiles used. We conclude that the introduction of DL OFDMA does not have a significant impact on the latency with the test scenarios covered. The performance of DL OFDMA is heavily dependent on the ability of the access point to properly schedule DL OFDMA transmissions. The number of clients, packet size, and buffer size play an essential role in the scheduling process. Based on our measurements the benefit of DL OFDMA is expected to be limited unless the number of clients is substantially higher than the three clients used, as would be the case in a stadium, train, or mall.
Daan Weller, Raoul Dijksman Mensenkamp, Arjan van der Vegt, Jan-Willem van Bloem, Cees T. A. M. de Laat
ICC5
2020 Auditable secure network overlays for multi-domain distributed applications
Reginald Cushing, Ralph Koning, Lu Zhang 0046, Cees T. A. M. de Laat, Paola Grosso
Networking4
2020 Time-critical data management in clouds: Challenges and a Dynamic Real-Time Infrastructure Planner (DRIP) solution
abstract
Summary The increasing volume of data being produced, curated, and made available by research infrastructures in the environmental science domain require services that are able to optimize the delivery and staging of data for researchers and other users of scientific data. Specialized data services for managing data life cycle, for creating and delivering data products, and for customized data processing and analysis all play a crucial role in how these research infrastructures serve their communities, and many of these activities are time‐critical—needing to be carried out frequently within specific time windows. We describe our experiences identifying the time‐critical requirements of environmental scientists making use of computational research support environments. We present a microservice‐based infrastructure optimization suite, the Dynamic Real‐Time Infrastructure Planner, used for constructing virtual infrastructures for research applications on demand. We provide a case study whereby our suite is used to optimize runtime service quality for a data subscription service provided by the Euro‐Argo using EGI Federated Cloud and EUDAT's B2SAFE services, and to consider how such a case study relates to other application scenarios.
Spiros Koulouzis, Paul Martin 0002, Huan Zhou 0006, Yang Hu 0013, Thierry Carval, Baptiste Grenier, Jani Heikkinen, Cees T. A. M. de Laat, Zhiming Zhao
Concurr. Comput. Pract. Exp.9
2020 Designing and building application-centric parallel memories
abstract
Summary Memory bandwidth is a critical performance factor for many applications and architectures. Intuitively, a parallel memory could be a good solution for any bandwidth‐limited application, yet building application‐centric custom parallel memories remains a challenge. In this work, we present a comprehensive approach to tackle this challenge and demonstrate how to systematically design and implement application‐centric parallel memories. Specifically, our approach (1) analyzes the application memory access traces to extract parallel accesses, (2) configures our parallel memory for maximum performance, and (3) builds the actual application‐centric memory system. We further provide a simple performance prediction model for the constructed memory system. We evaluate our approach with two sets of experiments. First, we demonstrate how our parallel memories provide performance benefits for a broad range of memory access patterns. Second, we prove the feasibility of our approach and validate our performance model by implementing and benchmarking the designed parallel memories using FPGA hardware and a sparse version of the STREAM benchmark.
Giulio Stramondo, Catalin Bogdan Ciobanu, Cees T. A. M. de Laat, Ana Lucia Varbanescu
Concurr. Comput. Pract. Exp.3
2020 Concurrent container scheduling on heterogeneous clusters with multi-resource constraints
abstract
By effectively virtualizing operating systems and encapsulating necessary runtime contexts of software components and services, container technologies can significantly improve portability and efficiency for distributed application deployment. It flexibly extends virtual machine based cloud (Infrastructure-as-a-Service) as a much lighter virtual environment (container cluster) for agile application management. However, existing container management systems are not capable of handling concurrent requests efficiently, particularly for the underlying clusters with heterogeneous machines and the requested containers with multi-resource demands. In this paper, we propose an Enhanced Container Scheduler (ECSched) for efficiently scheduling concurrent container requests on heterogeneous clusters with multi-resource constraints. We formulate the container scheduling problem as a minimum cost flow problem (MCFP), and represent the container requirements using a specific graph data structure (flow network). ECSched affords flexibility in constructing the flow network based on a batch of concurrent requests, and performs the MCFP algorithm to schedule the concurrent requests in an online manner. We evaluate ECSched in different testbed clusters, and measure the scheduling overhead with large-scale simulations. The experimental results show that ECSched outperforms state-of-the-art container schedulers in container performance and resource efficiency, and only introduces a small and acceptable scheduling overhead in large-scale clusters.
Yang Hu 0013, Huan Zhou 0006, Cees T. A. M. de Laat, Zhiming Zhao
Future Gener. Comput. Syst.3
2019 Multi-objective Container Deployment on Heterogeneous Clusters
abstract
Operating system (OS) containers are becoming increasingly popular in cloud computing for improving productivity and code portability. However, existing deployment scheduling solutions mainly treat each container deployment as an independent request, and focus on the single aspect of resource utilization or load balancing, or work on homogeneous clusters. In this paper, we propose a new container deployment algorithm to satisfy multiple objectives on heterogeneous clusters. We analyze the deployment requirements of container-based infrastructure and formulate the deployment problem as a vector bin packing problem with heterogeneous bins. We focus on three objectives: multi-resource guarantee, load balancing, and dependency awareness. The goal of the proposed algorithm is to improve the tradeoff between load balancing and dependency awareness with multi-resource guarantees. Based on the algorithm, we implement a prototype scheduler to deploy containers on heterogeneous clusters. We evaluate our scheduler over a wide range of workload scenarios by simulation, which shows that our scheduler significantly outperforms existing schedulers of the container orchestration platforms.
Yang Hu 0013, Cees T. A. M. de Laat, Zhiming Zhao
CCGRID2
2019 An Automated Customization and Performance Profiling Framework for Permissioned Blockchains in a Virtualized Environment
abstract
The permissioned blockchains have demonstrated their potential to provide trustworthy and security services in various industrial scenarios, especially in the Cloud-based virtualized environments. To customize the configuration of a blockchain application, an operator needs the performance characteristics of a blockchain network in different Cloud environments. However, manually profiling the performance characteristics of a blockchain network is very time-consuming. Therefore, in this paper, we propose a BlockchaIn-infRAstructure CustomIzation and Auto-profiLing (BIRACIAL) framework to automate the whole process of blockchain deployment and performance profiling. Based on the profile and performance requirements of a blockchain application, the framework aims to plan the virtual infrastructure for permissioned blockchain, to automate the provision of the required infrastructure, to deploy the customized permissioned blockchain, and to enable continuous monitoring of blockchain performance. Our evaluation results show that the proposed framework can achieve automated deployment of different permissioned blockchain networks under certain overheads. The performance profiling results can be used to compare and select the appropriate blockchain platforms and consensus algorithms.
Zeshun Shi, Huan Zhou 0006, Jayachander Surbiryala, Yang Hu 0013, Cees T. A. M. de Laat, Zhiming Zhao
CloudCom5
2019 Towards a New Paradigm for Programming Scientific Workflows
abstract
Applications and infrastructures are increasingly becoming more complex. Infrastructures have several layers of virtualisation, programmability and management while scientific applications are diverse in their computing model archetypes. Mapping these two opposing ends of the stack is a non-trivial task. Here we propose a new programming paradigm and architecture that takes into account the different layers of the stack in an effort to create isolated, portable and scalable application micro-infrastructures.
Reginald Cushing, Onno Valkering, Adam Belloum, Cees T. A. M. de Laat
eScience4
2019 Modeling and Matching Digital Data Marketplace Policies
abstract
Recently, Digital Data Marketplaces (DDMs) are gaining wide attention as a sharing platform among different organizations. That is due to the fact that sharing the information and participating in research collaborations play an important role in addressing multiple scientific challenges. To increase trust among participating organizations multiple contracts and agreements should be established in order to determine regulations and policies about who has access to what. Describing these agreements in a general model to be applicable in different DDMs is of utmost importance. In this paper, we present a semantic model for describing the access policies by means of semantic web technologies. In particular, we use and extend the Open Digital Rights Language (ODRL) to describe the pre-established agreements in a DDM.
Sara Shakeri, Valentina Maccatrozzo, Lourens E. Veen, Rena Bakhshi, Leon Gommans, Cees T. A. M. de Laat, Paola Grosso
eScience6
2019 A Blockchain based Witness Model for Trustworthy Cloud Service Level Agreement Enforcement
abstract
Traditional cloud Service Level Agreement (SLA) suffers from lacking a trustworthy platform for automatic enforcement. The emerging blockchain technique brings in an immutable solution for tracking transactions among business partners. However, it is still very challenging to prove the credibility of possible violations in the SLA before recording them onto the blockchain. To tackle this challenge, we propose a witness model using game theory and the smart contract techniques. The proposed model extends the existing service model with a new role called “witness” for detecting and reporting service violations. Witnesses gain revenue as an incentive for performing these duties, and the payoff function is carefully designed in a way that trustworthiness is guaranteed: in order to get the maximum profit, the witness has to always tell the truth. This is analyzed and proved through game theory using the Nash equilibrium principle. In addition, an unbiased sortition algorithm is proposed to ensure the randomness of the independent witnesses selection from the decentralized witness pool, to avoid possible unfairness or collusion. An auditing mechanism is also introduced in the paper to detect potential irrational or malicious witnesses. We have prototyped the system leveraging the smart contracts of Ethereum blockchain. Experimental results demonstrate the feasibility of the proposed model and indicate good performance in accordance with the design expectations.
Huan Zhou 0006, Xue Ouyang 0003, Zhijie Ren, Jinshu Su, Cees T. A. M. de Laat, Zhiming Zhao
INFOCOM5
2019 Operating Permissioned Blockchain in Clouds: A Performance Study of Hyperledger Sawtooth
abstract
With ever more IoT (Internet of Things) and bigdata applications, the emerging blockchain techniques provide fundamental supports to credibly track the transactions of digital assets. Public blockchains, e.g., bitcoin, are often energy-consuming and low efficient. Therefore, an empirical study of operating permissioned blockchains in clouds is urgently needed. In this paper, we study the performance of Sawtooth, a well-known permissioned blockchain platforms from Hyperledger, in cloud environments. Our results provide insights for blockchain operators to optimize the performance of Sawtooth through adjusting the two configuration parameters, i.e., Scheduler and Maximum Batches Per Block. Our approach can be used to test other blockchain platforms.
Zeshun Shi, Huan Zhou 0006, Yang Hu 0013, Jayachander Surbiryala, Cees T. A. M. de Laat, Zhiming Zhao
ISPDC5
2019 Learning Workflow Scheduling on Multi-Resource Clusters
abstract
Workflow scheduling is one of the key issues in the management of workflow execution. Typically, a workflow application can be modeled as a Directed-Acyclic Graph (DAG). In this paper, we present GoDAG, an approach that can learn to well schedule workflows on multi-resource clusters. GoDAG directly learns the scheduling policy from experience through deep reinforcement learning. In order to adapt deep reinforcement learning methods, we propose a novel state representation, a practical action space and a corresponding reward definition for workflow scheduling problem. We implement a GoDAG prototype and a simulator to simulate task running on multi-resource clusters. In the evaluation, we compare the GoDAG with three state-of-the-art heuristics. The results show that GoDAG outperforms the baseline heuristics, leading to less average makespan to different workflow structures.
Yang Hu 0013, Cees T. A. M. de Laat, Zhiming Zhao
NAS2
2019 Measuring the efficiency of SDN mitigations against attacks on computer infrastructures
Ralph Koning, Ben de Graaff, Gleb Polevoy, Robert J. Meijer, Cees T. A. M. de Laat, Paola Grosso
Future Gener. Comput. Syst.5
2019 Profiling the scheduling decisions for handling critical paths in deadline-constrained cloud workflows
abstract
In this paper, we study the scheduling decisions for handling deadline-constrained workflows in the context of planning customized virtual infrastructures in the cloud. We specifically focus on the effects of using different types of greediness in selecting cost-effective virtual machines for the tasks in an application’s workflow graph. The profiling procedure followed demonstrates that for the widely used approach of the partial critical path algorithm a greedy version is preferred to a more stringent version under different stress conditions, from tight to loose deadlines. Representative topologies of workflow applications are used to generate sets of task graph scheduling problems. Monitoring the performance of the partial critical path algorithm with different types of greediness reveals which of the topologies tested are difficult to solve under various stress conditions. It turns out that an invalid outcome of a greedy version of the partial critical path algorithm is more susceptible to become valid via a final refinement cycle than a less greedy version. The procedure outlined in this paper will allow for a systematic study of a specific heuristic in a workflow scheduling method to increase its success in infrastructure planning under different deadline conditions and is proposed to be part of a general profiling framework.
Arie Taal, Cees T. A. M. de Laat, Zhiming Zhao
Future Gener. Comput. Syst.3
2019 CloudsStorm: A framework for seamlessly programming and controlling virtual infrastructure functions during the DevOps lifecycle of cloud applications
abstract
Summary The infrastructure‐as‐a‐service (IaaS) model of cloud computing provides virtual infrastructure functions (VIFs), which allow application developers to flexibly provision suitable virtual machines' (VM) types and locations, and even configure the network connection for each VM. Because of the pay‐as‐you‐go business model, IaaS provides an elastic way to operate applications on demand. However, in current cloud applications DevOps (software development and operations) lifecycle, the VM provisioning steps mainly rely on manually leveraging these VIFs. Moreover, these functions cannot be programmatically embedded into the application logic to control the infrastructure at runtime. Especially, the vendor lock‐in issue, which different clouds provide different VIFs, also enlarges this gap between the cloud infrastructure management and application operation. To mitigate this gap, we designed and implemented a framework, CloudsStorm, which enables developers to easily leverage VIFs of different clouds and program them into their cloud applications. To be specific, CloudsStorm empowers applications with infrastructure programmability at design‐level, infrastructure‐level, and application‐level. CloudsStorm also provides two infrastructure controlling modes, ie, active and passive mode, for applications at runtime. Besides, case studies about operating task‐based and big data applications on clouds show that the monetary cost is significantly reduced through the seamless and on‐demand infrastructure management provided by CloudsStorm. Finally, the scaling and recovery operation evaluations of CloudsStorm are performed to show its controlling performance. Compared with other tools, ie, “jcloud” and “cloudinit.d”, the scaling and provisioning performance evaluations demonstrate that CloudsStorm can achieve at least 10% efficiency improvement in our experiment settings.
Huan Zhou 0006, Yang Hu 0013, Xue Ouyang 0003, Jinshu Su, Spiros Koulouzis, Cees T. A. M. de Laat, Zhiming Zhao
Softw. Pract. Exp.6
2018 Empowering Dynamic Task-Based Applications with Agile Virtual Infrastructure Programmability
abstract
The IaaS (Infrastructure-as-a-Service) offered by Clouds provides applications with the capability of customizing VMs and configuring their network. Compared to traditional service-based IaaS applications such as persistent web services, most task-based applications have a relatively short duration but are triggered on demand. A typical way to support such kinds of application is to provision a shared and fixed virtual infrastructure based on pre-estimated size in advance, and then perform all the processing tasks. However, due to unpredictable workloads, this solution can lead to either cost inefficiency caused by over-provisioning, or failure to deliver the performance required by applications. CloudsStorm is a dynamic control framework proposed to provide applications with agile programmability and flexibility in controlling the virtual infrastructure. With its front end, applications can design their networked infrastructure and program that infrastructure with our interpreted infrastructure code language. With the back-end engine, the infrastructure code can be executed to provision the networked infrastructure, deploy and execute the application to obtain results, and release resources. Moreover, we adopt multi-threading to support parallel operation. Finally, we conduct experiments in an assumed scenario to demonstrate functionalities of CloudsStorm. The evaluation results prove CloudsStorm is efficient for task-based applications that need to exploit Clouds but reduce the monetary cost.
Huan Zhou 0006, Yang Hu 0013, Jinshu Su, Mingmin Chi, Cees T. A. M. de Laat, Zhiming Zhao
IEEE CLOUD5
2018 Information Centric Networking for Sharing and Accessing Digital Objects with Persistent Identifiers on Data Infrastructures
abstract
Persistent identifiers (PIDs) such as Digital Object Identifiers (DOIs) provide a unique and persistent way to identify and cite digital objects such as publications, media content and research data. They are widely used by data producers to catalogue and publish digital assets and research data. Nowadays, research infrastructures (RIs) offer services not only for accessing and publishing data objects, but also for processing data based on user demands, e.g., via scientific workflows or third party virtual research environments. However, efficiently retrieving and sharing digital objects in a shared data processing environment requires knowledge of application access patterns as well as the underlying network level distribution. As the number and size of data objects increases, optimizing data discovery and access among distributed partners on shared infrastructure emerges as an important challenge for infrastructure operators to maintain quality of service and user experience. In this paper, we propose a novel approach that utilizes Information Centric Networking (ICN) to retrieve content based on PIDs while optimizing data access on shared infrastructure.
Spiros Koulouzis, Rahaf Mousa, Andreas Karakannas, Cees T. A. M. de Laat, Zhiming Zhao
CCGrid4
2018 Trustworthy Cloud Service Level Agreement Enforcement with Blockchain Based Smart Contract
abstract
Cloud Service Level Agreement (SLA) is challengeable due to lacking a trustworthy platform. This paper presents a witness model to credibly enforce the cloud service level agreement. Through introducing the witness role and using the blockchain based smart contract, we solve the trust issues about who can detect the service violation, how the violation is confirmed and the compensation is guaranteed. In this model, a verifiable consensus sortition algorithm proposed by us is firstly leveraged to select independent witnesses to form a witness committee. They are responsible for a specific service level agreement and get paid by monitoring and detecting service violation. Through carefully designing the witness' payoff function in the agreement, we further leverage game theory to analyze and prove that it is not the witness itself is trustworthy. Instead, the witness has to tell the truth because of its greedy nature, which is the desire to maximize its own revenue. As long as the service violation is confirmed by the witness committee, the compensation is automatically transferred to the customer by the smart contract. Finally, we implement a proof-of-concept prototype with the smart contract of Ethereum blockchain. It demonstrates the feasibility of our model.
Huan Zhou 0006, Cees T. A. M. de Laat, Zhiming Zhao
CloudCom2
2018 Removing Undesirable Flows by Edge Deletion
Gleb Polevoy, Stojan Trajanovski, Paola Grosso, Cees T. A. M. de Laat
COCOA4
2018 ECSched: Efficient Container Scheduling on Heterogeneous Clusters
Yang Hu 0013, Huan Zhou 0006, Cees T. A. M. de Laat, Zhiming Zhao
Euro-Par3
2018 A Normative Agent-based Model for Sharing Data in Secure Trustworthy Digital Market Places
abstract
Norms are driving forces in social systems and governing many aspects of individual and group decision-making. Various scholars use agent based models for modeling such social systems, however, the normative component of these models is often neglected or relies on oversimplified probabilistic models. Within the multi-agent research community, the study of norm emergence, compliance and adoption has resulted in new architectures and standards for normative agents. We propose the N-BDI* architecture by extending the Belief-Desire and Intention (BDI) agents’ control loop, for constructing normative agents to model social systems; the aim of our research to create a better basis for studying the effects of norms on a society of agents. In this paper, we focus on how norms can be used to create so-called Secure Trustworthy Digital Marketplaces (STDMPs). We also present a case study showing the usage of our architecture for monitoring the STDMP-members’ behavior. As a concrete resu lt, a preliminary implementation of the STDMP framework has been implemented in multi-agent systems based on Jadex.
Ameneh Deljoo, Tom M. van Engers, Robert van Doesburg, Leon Gommans, Cees T. A. M. de Laat
ICAART (1)5
2018 Editorial INDIS special section FGCS
abstract
Nowadays, the cyber, social and physical worlds are increasingly integrating and merging. Especially, combining the strengths of humans and machines helps tackle increasing hard tasks that neither can be done alone. Following this trend, this paper designs a Quality aware Truthful Incentive mechanism for cyber–physical enabled Geographic crowdsensing called Geo-QTI. Different from existing work, Geo-QTI appropriately accommodates the utilities of various stakeholders: requesters, participants and the crowdsourcing platform, and explicitly takes the requesters’ quality requirements, and participants’ quality provision into account. Geo-QTI explicitly includes four components: requester selection, participant selection, pricing and allocation. Requester selection with feasible analysis removes the requesters whose job cannot be completed by all participants or suffers from the monopoly participant (without the participant’s contribution, others cannot cover requesters’ requirement), obtains winning requesters set and determines actual payments. In participant selection phase, the platform aggregates the requested tasks (submitted by all winning requesters) in the sensed geographic area, and chooses the appropriate participants satisfying the winning requesters’ quality requirements with total cost as low as possible. Pricing phase determines the payments to winning participants. The phase of allocation assigns the specific participants to minimally cover the quality requirements of those winning requesters. Rigid theoretical analysis demonstrates Geo-QTI can achieve both requesters’ and participants’ individual rationality and truthfulness, computational efficiency and budget balance for the platform. Furthermore, the extensive simulations confirm our theoretical analysis, and illustrate that Geo-QTI can reduce requesters’ expenses greatly and ensure the fairness of allocation.
Paola Grosso, Malathi Veeraraghavan, Brian Tierney, Cees T. A. M. de Laat
Future Gener. Comput. Syst.4
2018 CoreFlow: Enriching Bro security events using network traffic monitoring data
Ralph Koning, Nick Buraglio, Cees T. A. M. de Laat, Paola Grosso
Future Gener. Comput. Syst.3
2017 Defining Intercloud Security Framework and Architecture Components for Multi-Cloud Data Intensive Applications
abstract
This paper presents results of the ongoing development of the Intercloud Security Framework (ICSF), that is a part of the Intercloud Architecture Framework (ICAF), and provides an architectural basis for building security infrastructure services for multi-cloud applications. The paper refers to general use case of the data intensive applications that indicate need for multi-cloud applications platforms that will require corresponding multi-cloud security services. The paper presents analysis of the general multi-cloud use case that helps eliciting the general requirement to ICSF and identifying the security infrastructure functional components that would allow using distributed cloud based resources and data sets. The paper defines the main ICSF services and functional components, and explains importance of consistent implementation of the Security Services Lifecycle Management in cloud based applications. The paper provides overview of the cloud compliance standards and their role in cloud security. The paper refers to the security infrastructure development in the CYCLONE project that implements federated identify management, secure logging service, and multi-domain Attribute Based Access Control, security services lifecycle management. The paper discusses implementation of the Trust Bootstrapping Protocol as an important mechanism to ensure consistent security in the virtualised inter-cloud environment.
Yuri Demchenko, Fatih Turkmen, Cees T. A. M. de Laat, Mathias Slawik
CCGrid3
2017 Customisable Data Science Educational Environment: From Competences Management and Curriculum Design to Virtual Labs On-Demand
abstract
Data Science is an emerging field of science, which requires a multi-disciplinary approach and is based on the Big Data and data intensive technologies that both provide a basis for effective use of the data driven research and economy models. Modern data driven research and industry require new types of specialists that are capable to support all stages of the data lifecycle from data production and input to data processing and actionable results delivery, visualisation and reporting, which can be jointly defined as the Data Science professions family. The education and training of Data Scientists currently lacks a commonly accepted, harmonized instructional model that reflects all multi-disciplinary knowledge and competences that are required from the Data Science practitioners in modern, data driven research and the digital economy. The educational model and approach should also solve different aspects of the future professionals that includes both theoretical knowledge and practical skills that must be supported by corresponding education infrastructure and educational labs environment. In modern conditions with the fast technology change and strong skills demand, the Data Science education and training should be customizable and delivered in multiple form, also providing sufficient data labs facilities for practical training. This paper discussed both aspects: building customizable Data Science curriculum for different types of learners and proposing a hybrid model for virtual labs that can combine local university facility and use cloud based Big Data and Data analytics facilities and services on demand. The proposed approach is based on using the EDISON Data Science Framework (EDSF) developed in the EU funded Project EDISON and CYCLONE cloud automation systems being developed in another EU funded project CYCLONE.
Yuri Demchenko, Adam Belloum, Cees T. A. M. de Laat, Charles Loomis, Tomasz Wiktorski, Erwin Spekschoor
CloudCom3
2017 CYCLONE: The Multi-cloud Middleware Stack for Application Deployment and Management
abstract
DevOps teams have to consider many technology and platform aspects when developing, deploying and operating cloud based applications: application deployments need to work everywhere on different cloud platforms, identities need to come from anywhere, and networks need to connect to anyone. The CYCLONE middleware is a holistic middleware stack that allows deploying and managing cloud based applications on multiple clouds and multiple cloud platforms. It includes a deployment manager, a practical identity federation, as well as a network manager that connects VMs independent of any specific infrastructure. This article explains the CYCLONE middleware stack, and what it can offer for application developers and operators. The paper describes in details the main bioinformatics use cases that evolve from a single VM installation for simple microbial research to multicloud infrastructure for advanced genomic resource. The paper also describes the CYCLONE federated identity management and access control infrastructure that significantly simplifies access for institutional users.
Mathias Slawik, Christophe Blanchet, Yuri Demchenko, Fatih Turkmen, Alexy Ilyushkin, Cees T. A. M. de Laat, Charles Loomis
CloudCom6
2017 Deadline-Aware Coflow Scheduling in a DAG
abstract
Data-intensive applications usually need to deal with huge volumes of data within their deadlines. These applications can be modelled as DAGs and require parallel computation frameworks such as MapReduce and Spark to enhance the performance. The network communication has a crucial impact on the performance of an application. Coflow is intended to address the application-specific network level Quality-of-Service (QoS) requirements in cloud-based data centres. However, existing works mainly focus on scheduling coflows in a single stage. How to schedule coflows in multi-stage applications (represented as DAGs) remains to be an open problem. In this paper we study the problem of scheduling coflows in a DAG to meet its deadline requirement. Single stage coflow scheduling has been proven to be NP-hard. Multiple stages in a DAG make our problem even more complex. Owing to the complexity of the problem, we propose a genetic algorithm-based method for solving the problem. The effectiveness of our solution is verified through numerical evaluation. Experimental results show that our solution can effectively guarantee the deadline of the DAGs compared with existing single stage coflow scheduling algorithms.
Huan Zhou 0006, Yang Hu 0013, Cees T. A. M. de Laat, Zhiming Zhao
CloudCom4
2017 Filtering Undesirable Flows in Networks
Gleb Polevoy, Stojan Trajanovski, Paola Grosso, Cees T. A. M. de Laat
COCOA (1)4
2017 Deadline-Aware Deployment for Time Critical Applications in Clouds
Yang Hu 0013, Huan Zhou 0006, Paul Martin 0002, Arie Taal, Cees T. A. M. de Laat, Zhiming Zhao
Euro-Par6
2017 QoS-aware virtual SDN network planning
abstract
Software Defined Networking (SDN) technologies provide applications opportunities to manipulate underlying network flows and topologies via network controllers during runtime. In cloud environments, networked virtual machines can be enhanced by SDN by providing applications with controllable infrastructures to meet system-level quality requirements; however, customizing a suitable network topology with optimally placed controller(s) for given quality requirements and workload characteristics is often not an easy task. We call such problem virtual SDN network planning problem. In this paper, a Topology-Controller planner (TCPlanner) is proposed for customizing the network topology and placing the controllers. Experiments with different scales of network show that our approach can effectively plan virtual SDN networks to meet the various QoS requirements and reduce costs.
Cees T. A. M. de Laat, Zhiming Zhao
IM2
2017 Automatic Collector for Dynamic Cloud Performance Information
abstract
When deploying an application in the cloud, a developer often wants to know which of the wide variety of cloud resources is best to use. Most cloud providers only provide static information about different cloud resources which is often not enough because static information does not take into account the hardware and software that is being used or the policy that has been applied by the cloud provider. Therefore, dynamic benchmarking of cloud resources is needed to find out how a certain workload is going to behave on a certain instance. However, benchmarking various cloud resources is a time consuming process. Thus, using a tool which automatically benchmarks various cloud resources will be of great use. In this paper, we present the Cloud Performance Collector, a modular cloud benchmarking tool aimed to automatically benchmark a wide variety of applications. To demonstrate the benefit of the tool, we did three experiments with three synthetic benchmark applications and one real-world application using the ExoGENI testbed.
Olaf Elzinga, Spiros Koulouzis, Arie Taal, Yang Hu 0013, Huan Zhou 0006, Paul Martin 0002, Cees T. A. M. de Laat, Zhiming Zhao
NAS8
2017 Measuring the effectiveness of SDN mitigations against cyber attacks
abstract
To address increasing problems caused by cyber attacks, we leverage Software Defined networks and Network Function Virtualisation governed by a SARNET-agent to enable autonomous response and attack mitigation. A Secure Autonomous Response Network (SARNET) uses a control loop to constantly assess the security state of the network by means of observables. Using a prototype we introduce the metrics impact and effectiveness and show how they can be used to compare and evaluate countermeasures. These metrics become building blocks for self learning SARNET which exhibit true autonomous response.
Ralph Koning, Ben de Graaff, Robert J. Meijer, Cees T. A. M. de Laat, Paola Grosso
NetSoft4
2017 Planning virtual infrastructures for time critical applications with multiple deadline constraints
Arie Taal, Paul Martin 0002, Yang Hu 0013, Huan Zhou 0006, Jianmin Pang, Cees T. A. M. de Laat, Zhiming Zhao
Future Gener. Comput. Syst.7
2016 Fast Resource Co-provisioning for Time Critical Applications Based on Networked Infrastructures
abstract
Resource provisioning is a key step in the deployment of applications onto clouds. When some datacenter is not accessible or some part of the infrastructure is crashed, the provisioning mechanism is therefore essential for these applications to recover quickly from sudden failures, especially for time critical applications. However, most current solutions focus on the cloud provider's hardware to achieve the fast provisioning of cloud resources. This paper proposes a co-provisioning mechanism to partition the customer's cloud resource requests while preserving their connectivity. This mechanism uses a brokering approach that is totally transparent to both the customer and the cloud provider, specifically considering the network topology. We carry out experiments on an NIaaS (networked infrastructure-as-a-service) platform, called ExoGENI. Experimental results and data analysis show that this mechanism is feasible and can dramatically improve the speed of resource provisioning.
Huan Zhou 0006, Yang Hu 0013, Jinshu Su, Paul Martin 0002, Cees T. A. M. de Laat, Zhiming Zhao
CLOUD6
2016 An Agent-based Framework for Multi-domain Service Networks - Eduroam Case Study
abstract
This paper introduces a methodology for the acquisition of the computational model of a service provider group and its transformation into agent-based model. The methodology is as follows. First, we analyze the case at the signal layer, i.e. the message exchange between actors, and model them with the components of “belief, desire and intention (BDI)” agent architecture. In the next step, we identify the implicit actions, intentions, and conditions which are necessary for the story to occur. These steps correspond to descriptions of agent-roles observed in the case study. As a concrete result, a preliminary implementation of the framework has been developed with Groovy.
Ameneh Deljoo, Leon Gommans, Tom M. van Engers, Cees T. A. M. de Laat
ICAART (1)4
2016 Fast and Dynamic Resource Provisioning for Quality Critical Cloud Applications
abstract
As many quality critical applications are migrating to clouds, Quality of Service (QoS) and Quality of Experience (QoE) have become vital properties for cloud applications. Therefore, the provisioning mechanism, which aims to make the virtual infrastructure recover from sudden failures quickly or adapt dynamic properties of applications, is essential. However, most current provisioning mechanisms focus on the cloud provider and are developed for specific hardware. This paper proposes a mechanism to partition a customer's cloud resource requests efficiently across multiple domains or clouds, while ensuring that the partitions are still connected with each other. This mechanism exploits networked infrastructure to make dynamic cloud resource provisioning as fast as possible. It works using a broker-based model that is transparent both to the customer and to the cloud provider. It is easy for customers to use and does not force providers to make any changes to their services. Moreover, the dynamic property makes the provisioned infrastructure better able to recover from failures quickly. We implement the mechanism and carry out experiments on ExoGENI, a networked infrastructure-as-a-service (NIaaS) platform. Comprehensive experimental results and theoretical analysis demonstrate that the mechanism we propose is feasible and can dramatically improve the speed of resource provisioning.
Huan Zhou 0006, Yang Hu 0013, Paul Martin 0002, Cees T. A. M. de Laat, Zhiming Zhao
ISORC5
2016 Towards a data processing plane: An automata-based distributed dynamic data processing model
Reginald Cushing, Adam Belloum, Marian Bubak, Cees T. A. M. de Laat
Future Gener. Comput. Syst.4
2016 SDN-aware federation of distributed data
Spiros Koulouzis, Adam Belloum, Marian Bubak, Zhiming Zhao, Miroslav Zivkovic, Cees T. A. M. de Laat
Future Gener. Comput. Syst.6
2016 Special section on high-performance networking for distributed data-intensive science
Brian Tierney, Mehmet Balman, Cees T. A. M. de Laat
Future Gener. Comput. Syst.3
2016 CineGrid, high quality media streaming and processing on advanced photonic networks
Jeffrey D. Weekley, Cees T. A. M. de Laat
Future Gener. Comput. Syst.2
2016 Multi-tenant attribute-based access control for cloud infrastructure services
Canh Ngo, Yuri Demchenko, Cees T. A. M. de Laat
J. Inf. Secur. Appl.3
2016 Joint flow routing-scheduling for energy efficient software defined data center networks: A prototype of energy-aware network management platform
Xiangke Liao, Cees T. A. M. de Laat, Paola Grosso
J. Netw. Comput. Appl.3
2016 The landscape of GPGPU performance modeling tools
Souley Madougou, Ana Lucia Varbanescu, Cees T. A. M. de Laat, Rob van Nieuwpoort
Parallel Comput.3
2015 A Software Workbench for Interactive, Time Critical and Highly Self-Adaptive Cloud Applications (SWITCH)
abstract
Time critical applications have very high requirements on network and computing services, in particular on well-tuned software architecture with sophisticated optimisation on data communication. Their development is often customised to dedicated infrastructure, and system performance is difficult to maintain when infrastructure changes. This fatal weakness in existing architecture and software tools causes very high development costs, and makes it difficult to fully utilise the virtualised, programmable and quality-on-demand services provided by networked Clouds to improve the system productivity. The Software Workbench for Interactive, Time Critical and Highly self-adaptive Cloud applications (SWITCH) is a newly funded project by EU H2020 to address this urgent industrial need, it aims at improving the existing development and execution model of time critical applications by introducing a novel conceptual model called application-infrastructure co-programming and control model, in which application QoS/QoE together with the programmability and controllability of Cloud environments can be all included in the complete lifecycle of applications.
Zhiming Zhao, Arie Taal, Andrew C. Jones, Ian J. Taylor, Vlado Stankovski, Ignacio Garcia Vega, Francisco Jesus Hidalgo, George Suciu, Alexandre Ulisses, Cees T. A. M. de Laat
CCGRID11
2015 Open Information Linking for Environmental Research Infrastructures
abstract
Environmental research infrastructures (RIs) support data-intensive research by integrating large-scale sensor/observer networks with dedicated data curation services and analytical tools. However the diversity of scientific disciplines coupled with the lack of an accepted methodology for constructing new RIs inevitably leads to incompatibilities between the data models, metadata standards and service descriptions used by different RIs, inhibiting their usefulness for interdisciplinary research. In the absence of a common global ontology of science and infrastructure, these inconsistencies may best be counteracted by selectively bridging the semantics of the various vocabularies, standards and models used by the RIs at present. Open Information Linking for Environmental RIs (OIL-E) was developed within the FP7 project ENVRI to provide a framework for semantic linking of knowledge resources used by different environmental RIs. Built around a multi-viewpoint reference model ENVRI-RM, OIL-E is intended to act as a central exchange for linking information fragments and identifying gaps in the conceptual models of RIs.
Paul Martin 0002, Paola Grosso, Barbara Magagna, Herbert Schentz, Yin Chen 0004, Alex R. Hardisty, Wouter Los, Keith G. Jeffery, Cees T. A. M. de Laat, Zhiming Zhao
e-Science9
2015 Reference Model Guided System Design and Implementation for Interoperable Environmental Research Infrastructures
abstract
Environmental research infrastructures (RIs) support their respective research communities by integrating large-scale sensor/observation networks with data curation services, analytical tools and common operational policies. These RIs are developed as pillars of intra-and interdisciplinary research, however comprehension of the complex, pathologically interconnected aspects of the Earth's ecosystem increasingly requires that researchers conduct their experiments across infrastructure boundaries. Consequently, almost all data-related activities within these infrastructures, from data capture to data usage, needs to be designed to be broadly interoperable in order to enable real interdisciplinary innovation. The Data for Science theme in the EU Horizon 2020 project ENVRIPLUSintends to address this interoperability challenge as it relates to the design, implementation and operation of environmental science RIs, the theme focuses on key issues of data identification and citation, curation, cataloguing, processing, optimization, and provenance, supported by a generic cross-infrastructure reference model.
Zhiming Zhao, Paul Martin 0002, Paola Grosso, Wouter Los, Cees T. A. M. de Laat, Keith Jeffrey, Alex R. Hardisty, Alex Vermeulen, Donatella Castelli, Yannick Legré, Werner Kutsch
e-Science5
2015 Open Cloud eXchange (OCX): A Pivot for Intercloud Services Federation in Multi-provider Cloud Market Environment
abstract
This paper presents results of the ongoing development of the Open Cloud eXchange (OCX) that has been proposed in the framework of the GN3plus project. Its aim is to provide cloud aware network infrastructure to power and support modern data intensive research at European universities and research organisations. The paper describes the OCX concept, architecture, design and implementation options. OCX includes 3 major components: distributed L0-L2 (optionally L3) network infrastructure that includes OCX points of presence (OCXP) interconnected with GEANT backbone; the Trusted Third Party (TTP) for building dynamic trust federations; and the marketplace to enable publishing and discovery of cloud services. OCX intends to be neutral to actual cloud services provisioning and limits its services to Layer 0 through Layer 2 in order to remain transparent to current cloud services model. The recent developments include an architectural update, API definition, integration with higher-level applications and workflow control, signaling and intercloud topology modelling and visualization. The paper reports about results and experiences learnt from the recent OCX demonstrations at the SC14 Exhibition in November 2014 that demonstrated the benefits of an OCX enabled Intercloud infrastructure for running data intensive real-time cloud applications on top of the advanced GEANT multi-gigabit network. The implemented OCX functionality allowed applications to control the network path for data transfer and service delivery connectivity between multiple Cloud Service Providers (CSPs). It was used in combination with a multi-cloud workflow management and planning application (Vampire) that enables data processing performance monitoring and migration of VMs and processes to an alternative location based on performance predictions.
Yuri Demchenko, Cosmin Dumitru, Ralph Koning, Cees T. A. M. de Laat, Taras Matselyukh, Sonja Filiposka, Migiel de Vos, Daniel Arbel, Damir Regvart, Tasos Karaliotas, Kurt Baumann
IC2E4
2015 Can Portability Improve Performance?: An Empirical Study of Parallel Graph Analytics
abstract
Due to increasingly large datasets, graph analytics - traversals, all-pairs shortest path computations, centrality measures, etc. - are becoming the focus of high-performance computing (HPC). Because HPC is currently dominated by many-core architectures (both CPUs and GPUs), new graph processing solutions have to be defined to efficiently use such computing resources. Prior work focuses on platform-specific performance studies and on platform-specific algorithm development, successfully proving that algorithms highly tuned to GPUs or multi-core CPUs can provide high performance graph analytics. However, the portability of such algorithms remains an important concern for many users, especially the many companies without the resources to invest in HPC or concerned about lock-in in single-use parallel techniques.
Ana Lucia Varbanescu, Merijn Verstraaten, Cees T. A. M. de Laat, Ate Penders, Alexandru Iosup, Henk J. Sips
ICPE3
2015 Decision Diagrams for XACML Policy Evaluation and Management
Canh Ngo, Yuri Demchenko, Cees T. A. M. de Laat
Comput. Secur.3
2015 A user-centric execution environment for CineGrid workloads
Cosmin Dumitru, Paola Grosso, Cees T. A. M. de Laat
Future Gener. Comput. Syst.3
2015 The Service Provider Group framework: A framework for arranging trust and power to facilitate authorization of network services
Leon Gommans, John R. Vollbrecht, Betty Gommans-de Bruijn, Cees T. A. M. de Laat
Future Gener. Comput. Syst.4
2015 The NOVI information models
Jeroen van der Ham, József Stéger, Sándor Laki, Yiannos Kryftis, Basil S. Maglaris, Cees T. A. M. de Laat
Future Gener. Comput. Syst.6
2014 Experience of Profiling Curricula on Cloud Computing Technologies and Engineering for Different Target Groups
abstract
This paper presents results and experience by the authors based on the few delivered courses on Cloud Computing for different target groups of students, specialists and trainees. The developed courses implement the proposed by the authors instructional methodology integrating the two major concepts of effective learning: the Bloom's Taxonomy of cognitive learning processes and Andragogy as the adult learning methodology. The central part of the proposed approach is the Common Body of Knowledge in Cloud Computing (CBK-CC) that defines the professional level of knowledge in the selected domain and allows consistent curricula structuring and profiling. The paper presents the structure of the courses and explains the principles used for developing course materials, such as Bloom's Taxonomy applied for technical education, and andragogy instructional model for professional education and training. The developed courses are based on the well-defined Cloud Computing architecture, service and operational model, and stakeholder roles/responsibilities. The paper provides a short description of the developed education and training courses on Cloud Computing that illustrate how the proposed CBK-CC and instructional methodologies are used in different learning environments and for different learners' groups.
Yuri Demchenko, Adam Belloum, David Bernstein, Cees T. A. M. de Laat
CloudCom4
2014 A Queueing Theory Approach to Pareto Optimal Bags-of-Tasks Scheduling on Clouds
Cosmin Dumitru, Ana-Maria Oprescu, Miroslav Zivkovic, Robert D. van der Mei, Paola Grosso, Cees T. A. M. de Laat
Euro-Par6
2014 Federated Access Control in Heterogeneous Intercloud Environment: Basic Models and Architecture Patterns
abstract
This paper presents on-going research to define the basic models and architecture patterns for federated access control in heterogeneous (multi-provider) multi-cloud and inter-cloud environment. The proposed research contributes to the further definition of Intercloud Federation Framework (ICFF) which is a part of the general Intercloud Architecture Framework (ICAF) proposed by authors in earlier works. ICFF attempts to address the interoperability and integration issues in provisioning on-demand multi-provider multi-domain heterogeneous cloud infrastructure services. The paper describes the major inter-cloud federation scenarios that in general involve two types of federations: customer-side federation that includes federation between cloud based services and customer campus or enterprise infrastructure, and provider-side federation that is created by a group of cloud providers to outsource or broker their resources when provisioning services to customers. The proposed federated access control model uses Federated Identity Management (FIDM) model that can be also supported by the trusted third party entities such as Cloud Service Broker (CSB) and/or trust broker to establish dynamic trust relations between entities without previously existing trust. The research analyses different federated identity management scenarios, defines the basic architecture patterns and the main components of the distributed federated multi-domain Authentication and Authorisation infrastructure.
Yuri Demchenko, Canh Ngo, Cees T. A. M. de Laat, Craig A. Lee
IC2E3
2014 Internet factories: Creating application-specific networks on-demand
Rudolf J. Strijkers, Marc X. Makkes, Cees T. A. M. de Laat, Robert J. Meijer
Comput. Networks3
2013 Dynamic Optimization of SLA-Based Services Scaling Rules
abstract
Current advanced cloud infrastructure management solutions allow scheduling actions for dynamically changing the number of running virtual machines (VMs). This approach, however, does not guarantee that the scheduled number of VMs will properly handle the actual user generated workload, especially if the user utilization patterns will change. We propose using a dynamically generated scaling model for the VMs containing the services of the distributed applications, which is able to react to the variations in the number of application users. We answer the following question: How to dynamically decide how many services of each type are needed in order to handle a larger workload within the same time constraints? We describe a mechanism for dynamically composing the SLAs for controlling the scaling of distributed services by combining data analysis mechanisms with application benchmarking using multiple VM configurations. Based on processing of multiple application benchmarks generated data sets we discover a set of service monitoring metrics able to predict critical Service Level Agreement (SLA) parameters. By combining this set of predictor metrics with a heuristic for selecting the appropriate scaling-out paths for the services of distributed applications, we show how SLA scaling rules can be inferred and then used for controlling the runtime scale-in and scale-out of distributed services. We validate our architecture and models by performing scaling experiments with a distributed application representative for the enterprise class of information systems. We show how dynamically generated SLAs can be successfully used for controlling the management of distributed services scaling.
Alexandru-Florian Antonescu, Ana-Maria Oprescu, Yuri Demchenko, Cees T. A. M. de Laat, Torsten Braun
CloudCom (1)4
2013 New Instructional Models for Building Effective Curricula on Cloud Computing Technologies and Engineering
abstract
This paper presents ongoing work to develop advanced education and training course on the Cloud Computing technologies foundation and engineering by a cooperating group of universities and the professional education partners. The central part of proposed approach is the Common Body of Knowledge in Cloud Computing (CBK-CC) that defines the professional level of knowledge in the selected domain and allows consistent curricula structuring and profiling. The paper presents the structure of the course and explains the principles used for developing course materials, such as Bloom's Taxonomy applied for technical education, and andragogy instructional model for professional education and training. The paper explains the importance of using the strong technical foundation to build the course materials that can address interests of different categories of stakeholders and roles/responsibilities in the Cloud Computing services provisioning and operation. The paper provides a short description of summary of the used Cloud Computing related architecture concepts and models that allow consistent mapping between CBK-CC, stakeholder roles/responsibilities and required skills, explaining also importance of the requirements engineering stage that provides a context for cloud based services design. The paper refers to the ongoing development of the educational course on Cloud Computing at the University of Amsterdam, University of Stavanger and provides suggestions for building advanced online training course for IT professionals.
Yuri Demchenko, David Bernstein, Adam Belloum, Ana-Maria Oprescu, Tomasz Wiktor Wlodarczyk, Cees T. A. M. de Laat
CloudCom (2)6
2013 Open Cloud eXchange (OCX): Architecture and Functional Components
abstract
This paper presents the concept of Open Cloud eXchange (OCX) that has been proposed to bridge the gap between two major components of the cloud services provisioning infrastructure: Cloud Service Provider (CSP) infrastructure, and cloud services delivery infrastructure which in many cases requires dedicated local infrastructure and quality of services that cannot be delivered by the public Internet infrastructure. In both cases there is a need for interconnecting the CSP infrastructure and local access network infrastructure, in particular, to solve the "last mile" problem in delivering cloud services to customer locations and individual (end-)users. The OCX remains neutral to actual cloud services provisioning and limit its services to Layer 0 through Layer 2 to remain transparent to current cloud services model. The proposed document identifies the initial set of requirements to OCX, that can be run by NRENs, as a part of the G&201;ANT network, or jointly, and provides suggestions about OCX implementation. The proposed OCX concept will leverage the existing Internet eXchange (IX) and GLIF Open Light path Exchange (GOLE) solutions and practices, adding specific functionality that will simplify inter-CSP and customer infrastructure integration when supporting basic cloud services provisioning models, in particular Trusted Third Party (TTP) services to allow federated infrastructure and access control, commonly used by NRENs. The paper also describes trusted/secured topology exchange protocol and dynamic trust establishment protocol as a part of the OCX services.
Yuri Demchenko, Jeroen van der Ham, Canh Ngo, Taras Matselyukh, Sonja Filiposka, Cees T. A. M. de Laat, Eduard Escalona
CloudCom (2)6
2013 ICOMF: Towards a Multi-cloud Ecosystem for Dynamic Resource Composition and Scaling
abstract
Modern cloud-based applications and infrastructures may include resources and services (components) from multiple cloud providers, are heterogeneous by nature and require adjustment, composition and integration. The specific application requirements can be met with difficulty by the current static predefined cloud integration architectures and models. In this paper, we propose the Intercloud Operations and Management Framework (ICOMF) as part of the more general Intercloud Architecture Framework (ICAF) that provides a basis for building and operating a dynamically manageable multi-provider cloud ecosystem. The proposed ICOMF enables dynamic resource composition and decomposition, with a main focus on translating business models and objectives to cloud services ensembles. Our model is user-centric and focuses on the specific application execution requirements, by leveraging incubating virtualization techniques. From a cloud provider perspective, the ecosystem provides more insight into how to best customize the offerings of virtualized resources.
Ana-Maria Oprescu, Alexandru-Florian Antonescu, Yuri Demchenko, Cees T. A. M. de Laat
CloudCom (1)4
2013 Towards an Operating System for Intercloud
abstract
Cyber physical systems, such as intelligent dikes and smart energy systems, require scalable and flexible computing infrastructures to process data from instruments and sensor networks. Infrastructure as a Service clouds provide a flexible way to allocate remote distributed resources, but lack mechanisms to dynamically configure software (dependencies) and manage application execution. This paper describes the design and implementation of the Intercloud Operating System (ICOS), which acts between applications and distributed clouds, i.e., the Intercloud. ICOS schedules, configures, and executes applications in the Intercloud while taking data dependencies, budgets, and deadlines into account. Based on our experiences with the prototype, we present considerations and additional research challenges. The research on ICOS clarifies essential concepts needed to realize a flexible and scalable on-demand execution platform for distributed applications over distributed cloud providers.
Rudolf J. Strijkers, Reginald Cushing, Marc X. Makkes, Pieter Meulenhoff, Adam Belloum, Cees T. A. M. de Laat, Robert J. Meijer
CloudCom (2)6
2013 Beyond Scientific Workflows: Networked Open Processes
abstract
The multitude of scientific services and processes being developed brings about challenges for future in silico distributed experiments. Choosing the correct service from an expanding body of processes means that the the task of manually building workflows is becoming untenable. In this paper we propose a framework to tackle the future of scientific collaborative distributed computing. We introduce the notion of Networked Open Processes whereby processes are exposed, published, and linked using semantics in the same way as is done with Linked Open Data. As part of the framework we introduce several novel concepts including Process Object Identifiers, Semantic Function Templates, and TReQL, a SQL-like language for querying networked open process graphs.
Reginald Cushing, Marian Bubak, Adam Belloum, Cees T. A. M. de Laat
e-Science4
2013 An Autonomous Security Storage Solution for Data-Intensive Cooperative Cloud Computing
abstract
In order to reduce untrustworthy between cloud users and the underlying cloud storage platform, a novel cloud security storage solution is proposed based on autonomous data storage, management, and access control. The roles of users are re-evaluated, and the knowledge provided by the users is incorporated into the cloud storage model. Both the superiority of the public cloud in large scale data storage and the advantages of the private cloud in privacy preserving can be obtained. The main advantages of our approach include avoiding the superposition of complex security policies and overcoming the mistrust between the users and the platform. Furthermore, our security storage service can be easily integrated into the cooperative cloud computing environment. A prototype system is developed, and a use case is also presented.
Wenchao Jiang, Zhiming Zhao, Cees T. A. M. de Laat
e-Science3
2013 Dynamic Workflow Planning on Programmable Infrastructure
abstract
The Network Service Interface (NSI) has been created as a result of collaborative development of network and application engineers primarily associated with the Research and Education (R&E) community. The NSI allows workflow systems not only to check available service points for a workflow engine to schedule executions, but also to reserve and provide network connections among those service points. The Open Flow technology provides programmability on the network Flow and allows software to define dynamically behaviour of the network. These new features offer data intensive applications new opportunities to optimize the mapping between data Flow patterns and the infrastructure yielding better system level quality. However, they also require the computing support systems effectively capture not only the characteristics of the application workflow but also the controllability of the underlying network. In this paper we discussed the extension of our previous system called Network QoS Planner (NEWQoSPlanner) and investigated how reservation based connection services can be enhanced by dynamic network Flow control. We also discusse how NEWQoSPlanner invokes network services to achieve connection reservation and provisioning, and includes Open Flow to realize dynamic Flow optimization for data intensive workflows.
Wenchao Jiang, Zhiming Zhao, Adianto Wibisono, Paola Grosso, Cees T. A. M. de Laat
NAS5
2013 Multi-data-types interval decision diagrams for XACML evaluation engine
abstract
XACML policy evaluation efficiency is an important factor influencing the overall system performance, especially when the number of policies grows. Some existing approaches on high performance XACML policy evaluation can support simple policies with equality comparisons and handle requests with well defined conditions. Such mechanisms do not provide the semantic correctness of combining algorithms in cases with indeterminate and not-applicable states. They ignore the critical attribute setting, a mandatory property in XACML, leading to potential missing attribute attacks. In this paper, we present a solution using data interval partition aggregation together with new decision diagram combinations, that not only optimizes the performance but also provides correctness and completeness of XACML 3.0 features, including complex logical expressions, correctness in indeterminate states processing, critical attribute setting, obligations and advices as well as complex comparison functions for multiple data types.
Canh Ngo, Marc X. Makkes, Yuri Demchenko, Cees T. A. M. de Laat
PST4
2013 OIntEd: online ontology instance editor enabling a new approach to ontology development
abstract
SUMMARY Ontology development involves people with different background knowledge and expertise. It is an elaborate process, where sophisticated tools for experienced knowledge engineers are available. However, domain experts need simple tools that they can use to focus on ontology instantiation. In this paper, we propose a methodology with a separation of concern between domain experts and knowledge engineers. This separation allows domain experts to focus on information processing and ontology instantiation while providing immediate feedback to the knowledge engineers on usability of the ontology being developed. We have designed and implementedOINTED, an adaptive online ontology instance editor that supports this methodology. We present usage examples ofOINTEDthat highlight three main features: the intuitive visualization of concepts, instances, and relationships within an ontology; the seamless integration in pre‐existing problem solving environment; and the assistance in ontology evolution.OINTEDcomplements existing tools suited for knowledge engineers by enabling immediate feedback and a shorter ontology development life cycle. Copyright © 2012 John Wiley & Sons, Ltd.
Adianto Wibisono, Ralph Koning, Paola Grosso, Adam Belloum, Marian Bubak, Cees T. A. M. de Laat
Softw. Pract. Exp.6
2012 Trusted Virtual Infrastructure Bootstrapping for On Demand Services
abstract
As cloud computing continues to gain traction, a great deal of effort is being expended in researching the most effective ways to build and manage secure and trustworthy clouds. Providing consistent security services in on-demand provisioned Cloud infrastructure services is of primary importance due to the multi-tenant and potentially multi-provider nature of Cloud Infrastructure. Cloud security infrastructure should address two aspects of the IaaS operation and dynamic security services provisioning: (1) provide security infrastructure for secure Cloud IaaS operation; (2) provisioning dynamic security services. Although the first task is a traditional task in security engineering, dynamic provisioning of managed security services in virtualized environment remains a problem and requires additional research. Entire frameworks have been proposed and demonstrated but although successful, there is a tendency to see such solutions as integrated 'all in one' infrastructures. This paper describes a light-weight mechanism and protocol for building trust between two machines that takes advantage of the Trusted Platform Module (TPM) to handle a key exchange and remote trusted deployment of a bootstrapping tool (referred to as the Bootstrapping Initiator (BI)). Once deployed, the BI can execute any arbitrary software required which could be (but is not limited to) solutions for advanced architecture management such as the Dynamic Access Control Infrastructure (DACI). The proposed solution provides a light-weight layer of trust backed by a TPM that additional systems can build upon as required by the individual use case without the requirement for a specific management or security infrastructure to be deployed along with it.
Peter Membrey, Keith C. C. Chan, Canh Ngo, Yuri Demchenko, Cees T. A. M. de Laat
ARES5
2012 Policy and Context Management in Dynamically Provisioned Access Control Service for Virtualized Cloud Infrastructures
abstract
Cloud computing is developing as a new wave of ICT technologies, offering a common approach to on-demand provisioning of computation, storage and network resources which are generally referred to as infrastructure services. Most of currently available commercial Cloud services are built and organized reflecting simple relations between a single provider and multiple customers with simple security and trust model. New architectural models should allow multi-provider heterogeneous service environment that can be delivered to organizational customers representing multiple user groups. These models should be supported by new security approaches for multi-provider, multi-tenant environment crossing multiple security domains to create consistent and dynamically configurable security services for virtualized infrastructures. This paper proposes an on-demand provisioned access control infrastructure with dynamic trust establishment for entities in a Cloud IaaS architecture model. It applies XACML-based RBAC model for the flexible authorization policy configuration and management. It uses authorization ticket as a security session management mechanism to solve the security context synchronization and exchange between multiple Cloud providers. The paper describes practical implementation of the proposed Dynamic Access Control Infrastructure as the part of a complex infrastructure services provisioning system.
Canh Ngo, Peter Membrey, Yuri Demchenko, Cees T. A. M. de Laat
ARES4
2012 Intercloud Architecture for interoperability and integration
abstract
This paper presents on-going research to develop the Intercloud Architecture Framework (ICAF) that addresses problems in multi-provider multi-domain heterogeneous cloud based infrastructure services and applications integration and interoperability. The paper refers to existing standards in Cloud Computing, in particular, recently published NIST Cloud Computing Reference Architecture (CCRA). The proposed ICAF defines four complementary components addressing Intercloud integration and interoperability: multilayer Cloud Services Model that combines commonly adopted cloud service models, such as IaaS, PaaS, SaaS, in one multilayer model with corresponding inter-layer interfaces; Intercloud Control and Management Plane that supports cloud based applications interaction; Intercloud Federation Framework, and Intercloud Operation Framework. The paper briefly describes the architectural framework for cloud based infrastructure services provisioned on-demand being developed in the framework of the GEYSERS project that is used as a basis for building multilayer cloud services integration framework that allows optimized provisioning of both computing, storage and networking resources. The proposed architecture is intended to provide an architectural model for developing Intercloud middleware and in this way will facilitate clouds interoperability and integration.
Yuri Demchenko, Marc X. Makkes, Rudolf J. Strijkers, Cees T. A. M. de Laat
CloudCom4
2012 Addressing Big Data challenges for Scientific Data Infrastructure
abstract
This paper discusses the challenges that are imposed by Big Data Science on the modern and future Scientific Data Infrastructure (SDI). The paper refers to different scientific communities to define requirements on data management, access control and security. The paper introduces the Scientific Data Lifecycle Management (SDLM) model that includes all the major stages and reflects specifics in data management in modern e-Science. The paper proposes the SDI generic architecture model that provides a basis for building interoperable data or project centric SDI using modern technologies and best practices. The paper explains how the proposed models SDLM and SDI can be naturally implemented using modern cloud based infrastructure services provisioning model.
Yuri Demchenko, Zhiming Zhao, Paola Grosso, Adianto Wibisono, Cees T. A. M. de Laat
CloudCom5
2012 Toward a Dynamic Trust Establishment approach for multi-provider Intercloud environment
abstract
In cloud computing, data are managed by different entities, not only by the actual data owner but also by many cloud providers. Sophisticated clouds collaboration scenarios may require that the data objects are distributed at cloud providers and accessed remotely, while still being under the control of the data owners. This brings security challenges for distributed authorization and trust management that existing proposed schemes have not fully solved. In this paper, we propose a Dynamic Trust Establishment approach which can be incorporated into cloud services provisioning life-cycles for the multi-provider Intercloud environment. It relies on attribute-based policies as the mechanism for trust evaluation and delegation. The paper proposes a practical implementation approach for attribute-based policies evaluation using Multi-type Interval Decision Diagrams extended from Integer Decision Diagrams which is more efficient in terms of evaluation complexity than other evaluation approaches.
Canh Ngo, Yuri Demchenko, Cees T. A. M. de Laat
CloudCom3
2012 Towards an Infrastructure Description Language for Modeling Computing Infrastructures
abstract
This paper describes the Infrastructure and Network Description Language (INDL). The aim of INDL is to provide technology independent descriptions of computing infrastructures. These descriptions include the physical resources and the network infrastructure that connects these resources. The description language also provides the necessary vocabulary to describe virtualization of resources and the services offered by these resources. Furthermore, the language can be easily extended to describe federation of different existing computing infrastructures, specific types of (optical) equipment and also behavioral aspects of resources, for example, their energy consumption. Before we introduce INDL we first discuss a number of modeling efforts that have lead to the development of INDL, namely the Network Description Language, the Network Markup Language and the CineGrid Description Language. We also show current applications of INDL in two EU-FP7 projects: NOVI and GEYSERS. We demonstrate the flexibility and extensibility of INDL to cater the specific needs of these two projects.
Mattijs Ghijsen, Jeroen van der Ham, Paola Grosso, Cees T. A. M. de Laat
ISPA4
2012 OEIRM: An Open Distributed Processing Based Interoperability Reference Model for e-Science
Zhiming Zhao, Paola Grosso, Cees T. A. M. de Laat
NPC3
2011 Defining Generic Architecture for Cloud IaaS Provisioning Model
Yuri Demchenko, Cees T. A. M. de Laat, Aleksej Mavrin
CLOSER2
2011 Security Infrastructure for On-demand Provisioned Cloud Infrastructure Services
abstract
Providing consistent security services in on-demand provisioned Cloud infrastructure services is of primary importance due to multi-tenant and potentially multi-provider nature of Clouds Infrastructure as a Service (IaaS) environment. Cloud security infrastructure should address two aspects of the IaaS operation and dynamic security services provisioning: (1) provide security infrastructure for secure Cloud IaaS operation, (2) provisioning dynamic security services, including creation and management of the dynamic security associations, as a part of the provisioned composite services or virtual infrastructures. The first task is a traditional task in security engineering, while dynamic provisioning of managed security services in virtualised environment remains a problem and requires additional research. In this paper we discuss both aspects of the Cloud Security and provide suggestions about required security mechanisms for secure data management in dynamically provisioned Cloud infrastructures. The paper refers to the architectural framework for on-demand infrastructure services provisioning, being developed by authors, that provides a basis for defining the proposed Cloud Security Infrastructure. The proposed SLA management solution is based on the WS-Agreement and allows dynamic SLA management during the whole provisioned services lifecycle. The paper discusses conceptual issues, basic requirements and practical suggestions for dynamically provisioned access control infrastructure (DACI). The paper proposes the security mechanisms that are required for consistent DACI operation, in particular security tokens used for access control, policy enforcement and authorisation session context exchange between provisioned infrastructure services and Cloud provider services. The suggested implementation is based on the GAAA Toolkit Java library developed by authors that is extended with the proposed Common Security Services Interface (CSSI) and additional mechanisms for binding sessions and security context between provisioned services and virtualised platform.
Yuri Demchenko, Canh Ngo, Cees T. A. M. de Laat, Tomasz Wiktor Wlodarczyk, Chunming Rong, Wolfgang Ziegler
CloudCom3
2011 Security Framework for Virtualised Infrastructure Services Provisioned On-demand
abstract
Cloud computing is developing as a new wave of ICT technologies, offering a common approach to on-demand provisioning computation, storage and network resources which are generally referred to as infrastructure services. Most of currently available commercial Cloud services are built and organized reflecting simple relations between single provider and single customer with simple security and trust model. New architectural models should allow multi-provider heterogeneous services environment that can be delivered to organizational customers representing multiple user groups. These models should be supported by new security approaches to create consistent security services in virtualised multi-provider Cloud environment and incorporate complex access control and trust relations among Cloud actors. The paper analyzes basis use cases in Cloud services provisioning and defines a security infrastructure reference model which is used to define other security infrastructure aspects such as dynamic trust management, distributed access control, policy and security context management. It also provides information about ongoing implementation of the proposed Dynamic Access Control Infrastructure based on Enterprise Service Bus as a part of complex infrastructure services provisioning system.
Canh Ngo, Peter Membrey, Yuri Demchenko, Cees T. A. M. de Laat
CloudCom4
2011 Profiling Energy Consumption of VMs for Green Cloud Computing
abstract
The Green Clouds project in the Netherlands investigates a system-level approach towards greening High-Performance Computing (HPC) infrastructures and clouds. In this paper we present our initial results in profiling virtual machines with respect to three power metrics, i.e. power, power efficiency and energy, under different high performance computing workloads. We built a linear power model that represents the behavior of a single work node and includes the contribution from individual components, i.e. CPU, memory and HDD, to the total power consumption of a single work node. Our results could be part of a power characterization module integrated into clusters' monitoring systems, future Green Clouds energy-savvy scheduler would use this monitoring system to support system-level optimization.
Qingwen Chen, Paola Grosso, Karel van der Veldt, Cees T. A. M. de Laat, Rutger F. H. Hofman, Henri E. Bal
DASC4
2011 Managing federations of virtualized infrastructures: A semantic-aware policy based approach
abstract
This paper presents our work toward organizing and managing various forms of federations of virtualized infrastructures. We adopt the Ponder2 policy framework and the SMC architecture as a powerful engineering approach, which we apply to semantic-aware management of federations of Future Internet (FI) virtualized infrastructures. To cater for context-awareness, we plan for a common information model, based on the Network Description Language (NDL), capturing a common set of abstractions of virtualized resources and services, nodes, routers and switches, custom network topologies with specific bandwidth demands, etc. To handle management of generic complex federated environments, we employ structural patterns to model federations as graphs, whose vertices represent SMCs and edges denote the type of relationship between them. We give an illustration of such structures corresponding to existing FI experimental platforms in the US and Europe and we provide examples containing inter-domain management responsibilities as missions. Finally, we propose to augment the Ponder2 framework with single & multi-domain resource provisioning capabilities, enabling efficient sharing of virtualized networked facilities among federation users.
Leonidas Lymberopoulos, Paola Grosso, Chrysa Papagianni, Dimitrios Kalogeras, Georgios Androulidakis, Jeroen van der Ham, Cees T. A. M. de Laat, Basil S. Maglaris
Integrated Network Management7
2011 Resource Discovery in Large Scale Network Infrastructure
abstract
Semantic web technologies provide a standardised mechanism for describing and accessing the services of underlying infrastructure. These technologies facilitate the inclusion of the quality of network services in the control loop of high level applications and allow applications to tune the system level performance with additional quality dimensions. However, the descriptions of a large infrastructure are often composed and maintained by different parties and can have different levels of details because of the administration policies. These facts make the development of high level applications unnecessarily difficult. We present a preprocessing framework to hide these difficulties from high level application developers by transforming, integrating, and filtering raw descriptions of the infrastructure into proper information content that these applications need.
Zhiming Zhao, Arie Taal, Paola Grosso, Cees T. A. M. de Laat
NAS4
2011 CineGrid: Super high definition media over optical networks
Paola Grosso, Laurin Herr, Naohisa Ohta, Paul Hearty, Cees T. A. M. de Laat
Future Gener. Comput. Syst.5
2011 Using ontologies for resource description in the CineGrid Exchange
Ralph Koning, Paola Grosso, Cees T. A. M. de Laat
Future Gener. Comput. Syst.3
2011 High Performance Digital Media Network (HPDMnet): An advanced international research initiative and global experimental testbed
Joe Mambretti, Mathieu Lemay, Scott Campbell, Hervé Guy, Thomas Tam, Eric Bernier, Bobby Ho, Michel Savoie, Cees T. A. M. de Laat, Ronald van der Pol, Jim Hao Chen, Fei Yeh, Sergi Figuerola, Pau Minoves, Dimitra Simeonidou, Eduard Escalona, Norberto Amaya, Admela Jukan, Wolfgang Bziuk, Dongkyun Kim, Kwangjong Cho, Hui-Lan Lee, Te-Lung Liu
Future Gener. Comput. Syst.9
2010 Security Services Lifecycle Management in On-Demand Infrastructure Services Provisioning
abstract
Modern e-Science and high technology industry require high-performance and complicated network and computer infrastructure to support distributed collaborating groups of researchers and applications that should be provisioned on-demand. The effective use and management of the dynamically provisioned services can be achieved by using the Service Delivery Framework (SDF) proposed by TeleManagement Forum that provides a good basis for defining the whole services life cycle management and supporting infrastructure services. The paper discusses conceptual issues, basic requirements and practical suggestions for provisioning consistent security services as a part of the general e-Science infrastructure provisioning, in particular Grid and Cloud based. The proposed Security Services Lifecycle Management (SSLM) model extends the existing frameworks with additional stages such as “Reservation Session Binding” and “Registration and Synchronisation” that specifically target such security issues as the provisioned resources restoration, upgrade or migration and provide a mechanism for remote executing environment and data protection by binding them to the session context. The paper provides a short overview of the existing standards and technologies and refers to the on-going projects and experience in developing dynamic distributed security services.
Yuri Demchenko, Cees T. A. M. de Laat, Diego R. López, Joan Antoni García Espín
CloudCom2
2010 AMOS: Using the Cloud for On-Demand Execution of e-Science Applications
abstract
The amount of computing resources currently available on Clouds is large and easily available with pay per use cost model. E-Science applications that need on-demand execution benefit from Clouds, because no permanent computing resources to support peak demand has to be acquired. In this paper, we present AMOS, a system that automates creation and management of temporary Grids on a Cloud to execute (parts of) application workflows. We performed experiments with AMOS and a representative e-Science application on a research Grid and on the Amazon EC2 Cloud. The results show that AMOS is a viable approach to manage and execute e-Science applications in a flexible Grid environment and to explore novel mechanisms that allow optimal utilization of Cloud resources. Furthermore, we consider AMOS as a step towards an operating system for (virtual) infrastructures that enables Grid applications to control their computational resources at run-time.
Rudolf J. Strijkers, Willem Toorop, Alain van Hoof, Paola Grosso, Adam Belloum, Dmitry Vasuining, Cees T. A. M. de Laat, Robert J. Meijer
eScience7
2010 Network Resource Control for Grid Workflow Management Systems
abstract
Grid workflow management systems automate the orchestration of scientific applications with large computational and data processing needs, but lack control over network resources. Consequently, the management system cannot prevent multiple communication intensive applications to compete for network resources, which leads to unpredictable performance. Currently, the lack of control over network resources may prevent certain applications, i.e. applications that need high capacity and Quality of Service, to utilize Grids. Hence, such applications would use dedicated infrastructures. Because the costs to build dedicated infrastructures may far exceed the cost of using existing Grids, the Grid needs to support mechanisms to optimize the interworking between networks and applications. In this paper, we present the architecture and proof of concept to control network resources from Grid workflow management system and to manage network resources from workflow-enabled applications at run-time. Depending on the current network infrastructure capabilities or future advances, applications may employ existing QoS mechanisms or use application-specific ones to provide the desired network service. We believe that our approach leads to performance improvements in communication intensive applications and enables novel Grid applications, which require optimal interworking between networks and applications.
Rudolf J. Strijkers, Mihai Cristea, Vladimir Korkhov, Damien Marchal, Adam Belloum, Cees T. A. M. de Laat, Robert J. Meijer
SERVICES6
2009 Introduction
Cees T. A. M. de Laat, Chris Develder, Admela Jukan, Joe Mambretti
Euro-Par1
2009 Supporting communities in programmable grid networks: gTBN
abstract
This paper presents the generalised token based networking (gTBN) architecture, which enables dynamic binding of communities and their applications to specialised network services. gTBN uses protocol independent tokens to provide decoupling of authorisation from time of usage as well as identification of network traffic. The tokenised traffic allows specialised software components uploaded into network elements to execute services specific to communities. A reference implementation of gTBN over IPv4 is proposed as well as the presentation of our experiments. These experiments include validation tests of our test bed with common grid applications such as GridFTP, OpenMPI, and VLC. In addition, we present a firewalling use case based on gTBN.
Mihai-Lucian Cristea, Rudolf J. Strijkers, Damien Marchal, Leon Gommans, Cees T. A. M. de Laat, Robert J. Meijer
Integrated Network Management5
2009 Assessing the impact of future reconfigurable optical networks on application performance
abstract
The introduction of optical private networks (lightpaths) has significantly improved the capacity of long distance network links, making it feasible to run large parallel applications in a distributed fashion on multiple sites of a computational grid. Besides offering bandwidths of 10 Gbit/s or more, lightpaths also allow network connections to be dynamically reconfigured. This paper describes our experiences with running data-intensive applications on a grid that offers a (manually) reconfigurable optical wide-area network. We show that the flexibility offered by such a network is useful for applications and that it is often possible to estimate the necessary network configuration in advance.
Jason Maassen, Kees Verstoep, Henri E. Bal, Paola Grosso, Cees T. A. M. de Laat
IPDPS5
2009 A path finding implementation for multi-layer networks
Freek Dijkstra, Jeroen van der Ham, Paola Grosso, Cees T. A. M. de Laat
Future Gener. Comput. Syst.4
2009 Multi-domain lightpath authorization, using tokens
Leon Gommans, Yuri Demchenko, Alfred Wan, Mihai Cristea, Robert J. Meijer, Cees T. A. M. de Laat
Future Gener. Comput. Syst.7
2009 Dynamic photonic lightpaths in the StarPlane network
Paola Grosso, Damien Marchal, Jason Maassen, Eric Bernier, Cees T. A. M. de Laat
Future Gener. Comput. Syst.6
2009 Special section: OptIPlanet - The OptIPuter global collaboratory
Larry Smarr, Maxine D. Brown, Cees T. A. M. de Laat
Future Gener. Comput. Syst.3
2008 A Trusted Data Storage Infrastructure for Grid-Based Medical Applications
abstract
Most existing Grid technology has been foremost designed with performance and scalability in mind. When using Grid infrastructure for medical applications, privacy and security considerations become paramount. This leads to a re-thinking of implementation and deployment aspects of common components of the current Grid architecture. This paper describes the impact of privacy and security considerations on the Grid infrastructure design, and enumerates trust aspects which must underpin the design of Grid technology to support medical applications. We propose a novel security framework for securely handling privacy sensitive information on the Grid.
Guido van 't Noordende, Sílvia Delgado Olabarriaga, Matthijs R. Koot, Cees T. A. M. de Laat
CCGRID4
2008 Re-thinking Grid Security Architecture
abstract
The security models used in Grid systems today strongly bear the marks of their diverse origin. Historically retrofitted to the distributed systems they are designed to protect and control, the security model is usually limited in scope and applicability, and its implementation tailored towards a few specific deployment scenarios. A common approach towards even the "basic" elements such as authentication to resources is only now emerging, whereas for more complex issues such as community organization, integration of site access control with operating systems, cross-domain resource provisioning, or overlay community Grids ("late authentication" for pilot job frameworks or community-based virtual machines) there is no single coherent and consistent "security" view. Via this paper we aim to share some observations on current security models and solutions found in Grid architectures and deployments today and identify architectural limitations in solving complex access control and policy enforcement scenarios in distributed resource management. The paper provides a short overview of the OGSA security services and other security solutions used in Grid middleware and operations practice. However, it is becoming clear that further development in Grid requires a fresh look at the concepts, both operationally and security-wise. This paper analyses the security aspects of different types of Grids and a set of use cases that may require extended security functionality, such as dynamic security context management, and management of stateful services. Recent developments in open systems security, and revisiting basic security concepts in networking and computing including the OSI security architecture and the concepts used in the trusted computing base provide interesting examples on how some of the conceptual security problems in Grid can be addressed, and on how the shortcomings of current systems and the frequently proposed "ad-hoc" stop-gaps for what are in fact complex security manageability problems may be avoided. This paper is thus intended to initiate and stimulate the wider discussion on the concepts of Grid security, thereby setting the scene for and providing input to a Grid security taxonomy leading to a more consistent Grid security architecture.
Yuri Demchenko, Cees T. A. M. de Laat, Oscar Koeroo, David L. Groep
eScience2
2008 A multi-layer network model based on ITU-T G.805
Freek Dijkstra, Bert Andree, Karst Koymans, Jeroen van der Ham, Paola Grosso, Cees T. A. M. de Laat
Comput. Networks6
2008 Dynamic security context management in Grid-based applications
Yuri Demchenko, Olle Mulmo, Leon Gommans, Cees T. A. M. de Laat, Alfred Wan
Future Gener. Comput. Syst.4
2007 Using SAML and XACML for Complex Authorisation Scenarios in Dynamic Resource Provisioning
abstract
This paper presents ongoing research and current results on the development of flexible access control infrastructures for complex resource provisioning in grid-based collaborative applications and on-demand network services provisioning. The paper identifies basic resource provisioning models and specifies major requirements to authorisation (AuthZ) service infrastructure to support these models and focus on two main issues - AuthZ session support and policy expression for complex resource models. For the practical implementation, we investigate the use of two popular standards SAML and XACML for complex authorisation scenarios in dynamic resource provisioning across multiple administrative and security domains. The paper describes a proposed XML based AuthZ ticket format that is capable of supporting extended AuthZ session context. Additionally, the paper discusses what specific functionality should be added to existing grid-oriented authorization frameworks to handle dynamic domain-related security context including AuthZ session support. The paper is based on experiences gained from major grid based and grid oriented projects such as EGEE, NextGrid, Phosphorus and GigaPort research on network
Yuri Demchenko, Leon Gommans, Cees T. A. M. de Laat
ARES3
2007 Using Jade agent framework to prototype an e-Science workflow bus
abstract
Most of the existing scientific workflow management systems (SWMS) are driven by applications from specific domains and are developed in academic projects. It is challenging to introduce an existing SWMS to a new domain; not only the workflow model and description language do not easily fit in new problem domains, but also the unstable development state of existing systems does not provide all functionality required by the new applications and thus gives high risk for the development. Aggregating different workflow systems as one generic environment enables the sharing on both components and processes between experiments, and promotes the knowledge transfer between domains. A workflow bus approach is to integrate different e-science workflow engines via a software bus. In this paper, we present the basic idea of workflow bus, and discuss how Jade agent framework can be used to prototype the runtime infrastructure of a workflow bus.
Zhiming Zhao, Adam Belloum, Cees T. A. M. de Laat, Pieter W. Adriaans, Louis O. Hertzberger
CCGRID3
2007 Security and dynamics in customer controlled virtual workspace organisation
abstract
This paper proposes the security infrastructure for user-controlled Virtual Workspace Service (VWSS-UC) that comprises of three layers: trusted computing platform, secure virtualised workspace, and user aplication. The suggestions on the technology selection are provided for the first two layers: industry adopted Trusted Computing (TCG) platform, and Virtual Workspace Service (VWSS) developed in the framework of the Globus Toolkit. Solutions and implementation are proposed and discussed for the application authorisation session security context management. The paper is based on experiences gained from major Grid based projects such as EGEE, Globus Toolkit, and Phosphorus.
Yuri Demchenko, Frank Siebenlist, Leon Gommans, Cees T. A. M. de Laat, David L. Groep, Oscar Koeroo
HPDC4
2007 Using the Network Description Language in Optical Networks
abstract
Current research networks allow end users to build their own application-specific connections (lightpaths) and optical private networks (OPNs). This requires a clear communication between the requesting application and the network. The network description language (NDL) is a vocabulary designed to describe optical networks based on the resource description framework (RDF). These descriptions aid applications in querying the capabilities of the network and allow them to clearly express requests to the network. This article introduces NDL and shows its current applications in optical research networks.
Jeroen van der Ham, Paola Grosso, Ronald van der Pol, Andree Toonk, Cees T. A. M. de Laat
Integrated Network Management5
2007 Extending Role Based Access Control Model for Distributed Multidomain Applications
Yuri Demchenko, Leon Gommans, Cees T. A. M. de Laat
SEC3
2006 Improving Automatic Data Structure Generation for e-Science Applications
abstract
The usage of ontologies to develop a semantically rich experiment models promises to be a key advantage of scientific applications over earlier alternatives. Whilst it is often recognized that information gathered for the ontology modeling process can describe naturally the scientific knowledge and can be used for interoperation among heterogeneous systems (by establishing a global schema, for instance), it may also be used to create data structures, including database schema and initial code signatures, containing metadata and semantics for their applications. The aspects involved in the translation of ontology models into suited metadata, however, can render in wasted efforts and useless schemas for scientific applications. This paper explores an approach to generate semiautomatically appropriate data structures for handling scientific information. Based on this approach, we developed a tool that let scientists to develop canonical models and automatically generate the related database schema. This tool supports a wide range of scientific use cases for complex models within the VL-e project. This project carries out concerted research along the complete e-science technology chain, ranging from applications to networking, focusing on new methodologies and re-usable components
Víctor Guevara-Masís, Hakan Yakali, Adam Belloum, Cees T. A. M. de Laat, Louis O. Hertzberger
CollaborateCom4
2006 Domain Based Access Control Model for Distributed Collaborative Applications
abstract
This paper describes the design and development of a flexible domain-based access control infrastructure for distributed Collaborative Environments. The paper proposes extensions to classical RBAC models to address typical problems and tasks in the distributed hierarchical resource organisation that came from the practical experience in developing industry oriented virtual laboratories infrastructure, particular: hierarchical resources policy administration, user roles management, dynamic security context and authorisation session management. The paper provides implementation details on the use of XACML for finegrained access control policy definition for domain based resources and roles organisation. The paper analyses the required functionality and suggests extensions to the major service-oriented access generic framework such as Acegi, Globus Toolkit Authorisation framework, and GAAA Authorisation framework in order to support complex resource organisation and collaboration scenarios in dynamic virtualised environments. The paper is based on experiences gained from the industry funded project Collaboratory.nl and other major Grid-based and Grid-oriented projects in collaborative applications and complex resource provisioning.
Yuri Demchenko, Cees T. A. M. de Laat, Leon Gommans, René van Buuren
e-Science2
2006 Interactive Workflows in a Virtual Laboratory for e-Bioscience: The SigWin-Detector Tool for Gene Expression Analysis
abstract
Explorative research is a vital part of biological sciences. Biologists frequently have to examine and compare multiple (large) sets of biological data in an interactive and explorative manner. Exploring alternative ways of examining the data and managing the necessary resources often require substantial (manual) effort and time. In this paper, we present a concrete example of how VLAM, a grid-based workflow management system, can enhance experimentation. We discuss in detail the process of developing the SigWin-detector, an application in the domain of bioinformatics. We show that SigWin-detector can promptly identify regions of increased gene expression in transcriptome maps and periodicity in weather data. We also show that the workflow can be extended or partially modified. The individual modules can also be used to compose different experiments. SigWin-detector fulfills the requirements of interactive and explorative experimentation.
Márcia A. Inda, Adam Belloum, Marco Roos, Dmitry Vasunin, Cees T. A. M. de Laat, Louis O. Hertzberger, Timo M. Breit
e-Science5
2006 User Programmable Virtualized Networks
abstract
This paper introduces the concept of a User Programmable Virtualized Network, which allows networks to deliver application specific services using network element components that developers can program as part of a users application. The use of special tokens in data or control packets is the basis of a practical, yet powerful security and AAA framework. This framework allows for implementations with a low footprint that can operate in a multi domain network operator environment. We demonstrate the ease with which one can build applications and address networking problems as they appear for example in sensor networks.
Robert J. Meijer, Rudolf J. Strijkers, Leon Gommans, Cees T. A. M. de Laat
e-Science4
2006 VLE-WFBus: A Scientific Workflow Bus for Multi e-Science Domains
abstract
In e-Science, a Grid environment enables data and computing intensive tasks and provides a new supporting infrastructure for scientific experiments. Scientific workflow management systems (SWMS) hide the integration details among Grid resources and allow scientists to prototype an experimental computing system at a high level of abstraction. However, the development of an effective SWMS requires profound knowledge on both application domains and the network programming, and is often time consuming and domain specific. Integrating mature implementations of domain specific SWMS improves reusability of workflow resources and promotes a generic framework for different e-Science domains. In this paper, we discuss different options to derive a generic workflow management system from domain specific implementations, and propose a workflow bus based solution, called VLE-WFBus. Legacy SWMSs are wrapped as federated components and are loosely coupled as one workflow system via a runtime infrastructure. An agent based prototype is presented; the integration among different workflow management systems has been demonstrated.
Zhiming Zhao, Suresh Booms, Adam Belloum, Cees T. A. M. de Laat, Louis O. Hertzberger
e-Science4
2006 Poster reception - Semantics for hybrid networks using the network description language
abstract
Several research networks around the world are implementing hybrid networks, that provide end-users with traditional routed IP together with lightpaths. These paths are dynamically configured at user request and network provisioning systems must have topology information, both intra- and inter-domain.We developed the Network Description Language (NDL), based on RDF, a semantic web technique. This language can be used to describe hybrid networks, so that different administrative domains can share and correlate topology information. It supports the end-user to express a lightpath reservation request, and helps the service provider to validate the feasibility of requests. It facilitates generation and exchange of network maps by allowing automatic correlation of information across domains.Our first application ground is GLIF, a collaboration promoting co-operation for Lambda Networking. Several tools for automatic provisioning are in development. However, these tools lack a common network description, which NDL can provide.
Jeroen van der Ham, Paola Grosso, Freek Dijkstra, Cees T. A. M. de Laat
SC4
2006 Using VO Concept for Managing Dynamic Security Associations
Yuri Demchenko, Leon Gommans, Cees T. A. M. de Laat
SEC3
2006 Using zero configuration technology for IP addressing in optical networks
Freek Dijkstra, Jeroen van der Ham, Cees T. A. M. de Laat
Future Gener. Comput. Syst.3
2006 Token based networking: Experiment NL-101
Leon Gommans, Bas van Oudenaarde, Alfred Wan, Cees T. A. M. de Laat, Robert J. Meijer, Franco Travostino, Inder Monga
Future Gener. Comput. Syst.4
2006 Using RDF to describe networks
Jeroen van der Ham, Freek Dijkstra, Franco Travostino, Hubertus M. A. Andree, Cees T. A. M. de Laat
Future Gener. Comput. Syst.5
2006 Highly interactive distributed visualization
Michael Scarpa, Robert G. Belleman, Peter M. A. Sloot, Cees T. A. M. de Laat
Future Gener. Comput. Syst.4
2006 Special section: iGrid 2005: The Global Lambda Integrated Facility
Larry Smarr, Thomas A. DeFanti, Maxine D. Brown, Cees T. A. M. de Laat
Future Gener. Comput. Syst.4
2006 Seamless live migration of virtual machines over the MAN/WAN
Franco Travostino, Paul Daspit, Leon Gommans, Chetan Jog, Cees T. A. M. de Laat, Joe Mambretti, Inder Monga, Bas van Oudenaarde, Satish Raghunath, Phil Yonghui Wang
Future Gener. Comput. Syst.5
2005 Exploring practical limitations of TCP over transatlantic networks
Antony Antony, Johan Blom, Cees T. A. M. de Laat, Jason Lee 0001
Future Gener. Comput. Syst.3
2005 Teraflows over Gigabit WANs with UDT
Robert L. Grossman, Yunhong Gu, Xinwei Hong, Antony Antony, Johan Blom, Freek Dijkstra, Cees T. A. M. de Laat
Future Gener. Comput. Syst.7
2005 Native 10 Gigabit Ethernet experiments over long distances
Catalin Meirosu, Piotr Golonka, Andreas Hirstius, Stefan Stancu, Bob Dobinson, Erik Radius, Antony Antony, Freek Dijkstra, Johan Blom, Cees T. A. M. de Laat
Future Gener. Comput. Syst.10
2005 Dynamic paths in multi-domain optical networks for grids
Bas van Oudenaarde, Zeger W. Hendrikse, Freek Dijkstra, Leon Gommans, Cees T. A. M. de Laat, Robert J. Meijer
Future Gener. Comput. Syst.5
2003 Microscopic examination of TCP flows over transatlantic links
Antony Antony, Johan Blom, Cees T. A. M. de Laat, Jason Lee 0001, Wim Sjouw
Future Gener. Comput. Syst.3
2003 VLAM-G: a grid-based virtual laboratory
Adam Belloum, David L. Groep, Zeger W. Hendrikse, Louis O. Hertzberger, Vladimir Korkhov, Cees T. A. M. de Laat, Dmitry Vasunin
Future Gener. Comput. Syst.6
2003 iGrid 2002: The International Virtual Laboratory
Thomas A. DeFanti, Maxine D. Brown, Cees T. A. M. de Laat
Future Gener. Comput. Syst.3
2003 Authorization of a QoS path based on generic AAA
Leon Gommans, Cees T. A. M. de Laat, Bas van Oudenaarde, Arie Taal
Future Gener. Comput. Syst.2
2003 Evaluating the VLAM-G toolkit on the DAS-2
Zeger W. Hendrikse, Adam Belloum, Philip M. R. Jonkergouw, Gert B. Eijkel, Ron M. A. Heeren, Louis O. Hertzberger, Vladimir Korkhov, Cees T. A. M. de Laat, Dmitry Vasunin
Future Gener. Comput. Syst.8
2003 The rationale of the current optical networking initiatives
Cees T. A. M. de Laat, Erik Radius, Steven Wallace
Future Gener. Comput. Syst.1