Jörg Keller 0001

dblp:k/JorgKeller1 · DBLP profile ↗
← Back
74ranked-venue papers
15as first author
25since 2021 · last 2026
0000-0003-0303-6140ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 22 · 6 first-author · 6 since 2021Security and privacy · 18 · 2 first-author · 11 since 2021Theory of computation · 7 · 4 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 1 since 2021Computer networks · 4 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author
YearPublicationVenuePosition
2026 Parallel Algorithm for Approximate State Graph Exploration With Restricted Memory Footprint
abstract
ABSTRACT We investigate the performance of algorithms that explore large state graphs of finite state machines without input by following paths. To improve on anchor‐based and candidate‐based explorations and to avoid the performance overhead of full anchor lists and the tuning sensitivity of timeout‐based methods, we propose and analyze exploration based on two combinations: two sets of candidate nodes and candidate nodes plus a restricted form of anchors. We confirm our analysis by experiments on a multicore machine: both combinations achieve similar performance, with slight differences depending on the input graph and with respect to accuracy of secondary information like the point of entry into the cycle. The method with two candidate sets provides accurate information also on the tail length, while the method with candidates and restricted anchors often yields best performance.
Jörg Keller 0001, Sebastian Litzinger
Concurr. Comput. Pract. Exp.1
2025 Double Proof-of-Work Scheme for the Key Transfer in the Steganographic Communication
Pawel Rajba, Wojciech Mazurczyk, Jörg Keller 0001
AINA (4)3
2025 Detecting and Attributing Tor-Obfuscated Malware Communications Through Traffic Fingerprinting
abstract
As malware authors increasingly adopt anonymity networks like Tor to obfuscate Command & Control communications and evade detection, defenders face the challenge of distinguishing malicious from benign traffic in an environment designed for privacy.This study investigates whether malware traffic routed through Tor can still be identified despite the network's encryption, packet normalization, and routing obfuscation mechanisms.Using a controlled empirical setup, we executed 13 diverse malware samples spanning 10 families, generating 693 Tor-obfuscated traffic traces.Through feature engineering focusing on statistical, temporal, and burst characteristics, and leveraging machine learning classifiers, we demonstrate that malware retains distinct traffic patterns even within anonymized environments.Our classifiers achieved up to 89.9 % accuracy in identifying malware families, highlighting the persistence of identifiable temporal and statistical characteristics.These findings demonstrate that malware fingerprinting remains feasible even in anonymized environments, providing actionable insights for defenders and privacy-preserving approaches for detecting malicious activity.However, our results also underscore potential fingerprinting risks for anonymity systems like Tor, prompting a need for stronger traffic normalization techniques.This study bridges the gap between malware analysis and anonymity research, offering a foundation to balance user privacy with effective threat detection.
Pascal Tippe, Adrian Tippe, Jörg Keller 0001
IH&MMSec3
2025 Quality-Aware Energy-Efficient Scheduling of Moldable-Parallel Streaming Computations on Heterogeneous Multicore CPUs with DVFS
Sajad Khosravi, Sebastian Litzinger, Christoph W. Kessler, Jörg Keller 0001
JSSPP4
2025 Protocol Design Rules from Hiding Patterns to Avoid Steganographic Channels in Wireless Communication
abstract
Covert channels for the transmission of stegano-graphic messages are not only possible in classic internet protocols but also in wireless communications such as 4G and 5G air interface. Hiding patterns collect the central ideas behind these channels. We therefore derive rules for protocol design, conformance to which disables at least the most frequently used covert channel approaches. Starting from 5G, we investigate where 6G standardization might take such rules into account to better protect 6G protocols against covert channels from the beginning,
Jörg Keller 0001, Daniel Spiekermann, Markus Walter
WCNC1
2025 DYST (Did You See That?): An Amplified Covert Channel That Points To Previously Seen Data
abstract
Covert channels are stealthy communication channels that enable manifold adversary and legitimate scenarios, ranging from stealthy malware communications to the exchange of confidential information by journalists. We present DYST, which represents a new class of covert channels we callhistory covert channelsjointly with the new paradigm of covert channelamplification. All covert channels described until now need to craft seemingly legitimate flows or need to modify third-party flows, mimicking unsuspicious behavior. In contrast, history covert channels can communicate bypointingtounaltered legitimatetraffic created by regular network nodes. Only a negligible fraction of the covert communication process requires the transfer of actual covert channel information by the covert channel's sender. This information can be sent through different protocols/channels. Our methodology allows anamplificationof the covert channel's message size, i.e., minimizing the fraction ofactually transferredsecret data by a covert channel's sender in relation to theoverallsecret data being exchanged. Further, we extend the current taxonomy for covert channels to show how history channels can be categorized. We describe multiple scenarios in which history covert channels can be realized, analyze the characteristics of these channels, and show how their configuration can be optimized.
Steffen Wendzel, Tobias Schmidbauer, Sebastian Zillien, Jörg Keller 0001
IEEE Trans. Dependable Secur. Comput.4
2024 Robust and Homomorphic Covert Channels in Streams of Numeric Data
abstract
A steganographic network storage channel that uses a carrier with a stream of numeric data must consider the possibility that the carrier data is processed before the covert receiver can extract the secret data. A sensor data stream, which we take as an example scenario, may be scaled by multiplication, shifted into a different range by addition, or two streams might be merged by adding their values. This raises the question if the storage channel can be made robust against such carrier modifications. On the other hand, if the pieces of secret data are numeric as well, adding and merging two streams each comprising covert data might be exploited to form a homomorphic covert channel. We investigate both problems as they are related and give positive and negative results. In particular, we present the first homomorphic storage covert channel. Moreover, we show that such type of covert channel is not restricted to sensor data streams, but that very different scenarios are possible.
Jörg Keller 0001, Carina Heßeling, Steffen Wendzel
ARES1
2024 Manipulating the Swap Memory for Forensic Investigation
abstract
Swap memory plays a critical role in modern operating systems’ memory management. This paper explores the potential for manipulating swap memory to alter memory content at runtime and thereby control the behaviour of the target system. While conventional memory security techniques typically focus on preventing runtime manipulation of memory pages, they often overlook the moment when pages are swapped and later reloaded into memory. Therefore, we investigate the feasibility of manipulating swap memory and describe the necessary steps of extracting involved memory areas as well as techniques to force swapping of relevant processes. We verify this theoretical concept with a prototype implementing a manipulation of memory of a given program.
Maximilian Olbort, Daniel Spiekermann, Jörg Keller 0001
ARES3
2024 Look What's There! Utilizing the Internet's Existing Data for Censorship Circumvention with OPPRESSION
abstract
An ongoing challenge in censorship circumvention is optimizing the stealthiness of communications, enabled by covert channels. Recently, a new variant called history covert channels has been proposed. Instead of modifying or mimicking legitimate data, such channels solely point to observed data matching secret information. This approach reduces the amount of secret data a sender explicitly must transfer and thus limits detectability. However, the only published history channel is only suitable for special scenarios due to severe limitations in terms of bandwidth. We propose a significant performance enhancement of history covert channels that allows their use in real-world scenarios through utilizing the content of online social media and online archives. Our approach, which we call OPPRESSION (Open-knowledge Compression), takes advantage of the massive amounts of textual data on the Internet that can be referenced by short pointer messages. Broadly, OPPRESSION can be considered a novel encoding strategy for censorship circumvention.
Sebastian Zillien, Tobias Schmidbauer, Mario Kubek, Jörg Keller 0001, Steffen Wendzel
AsiaCCS4
2024 Error correction and erasure codes for robust network steganography
abstract
Error correction and erasure codes and steganographic channels use related methods, but are investigated separately. We detail an idea from literature for a steganographic channel in a transmission with error correction code and experimentally investigate it with respect to bandwidth, robustness and detectability. We expand this construction to provide an example of multi-level steganography, i.e., a steganographic channel within a steganographic channel. Furthermore, we investigate the advantages on bandwidth and stealthyness that reversibility of such a steganographic channel brings, together with a new proposal for a covert channel in error-corrected data.
Jörg Keller 0001, Saskia Imhof, Peter Sobe
J. Syst. Archit.1
2023 Proof-of-work based new encoding scheme for information hiding purposes
abstract
Steganography techniques often assume that the secret message looks randomly or is encrypted. If encryption is required, it leads to a random-looking message, but key exchange may be problematic and jeopardize covert communication. If encryption is not required, then the question arises of whether other cryptographic solutions that are “cheaper” than encryption can provide the same level of randomness. In this paper, we investigate both questions. First, we propose a proof-of-work-inspired approach to securely transfer the key with the encrypted message, avoiding a previous key exchange. Second, we introduce a scheme that uses T-functions to substitute symmetric encryption algorithms. We implement both proposed solutions, measure the entropy of the resulting messages, and apply the Kolmogorov-Smirnoff tests. The results obtained prove that both schemes are feasible.
Pawel Rajba, Jörg Keller 0001, Wojciech Mazurczyk
ARES2
2023 Network Covert Channels in Routing Protocols
abstract
Computer networks play a key role in everyday lives. To guarantee fail-safe operation, routing protocols are used that enable dynamic routing via redundant paths. Because of this, routing protocols like RIP or OSPF play an important role in modern network infrastructures. The widespread use together with the mostly missing traffic monitoring of these protocols provide a possible base to exploit these protocols for network steganographic channels. In this paper, we present a novel storage covert channel based on the OSPF routing protocol. We analyzed the protocol in detail with the help of hiding patterns to identify protocol fields that might be suitable for covert communication. We provide a proof-of-concept implementation of our covert channel inside a simulated network, which demonstrates the possibility of covert communication in a routing protocol. Our evaluation covers detectability and countermeasures, steganographic bandwidth and robustness. Furthermore, we sketch an application scenario where such a covert channel can be deployed.
Michael Schneider 0013, Daniel Spiekermann, Jörg Keller 0001
ARES3
2023 Reversible Network Covert Channel by Payload Modulation in Streams of Decimal Sensor Values
abstract
We investigate decimal number representations in large data streams. When decimal numbers are encoded in bits, not all possibilities are used. This opens possibilities to establish a covert channel, i.e., to inject secret data into the data stream and transport it hidden in the mass of data, which poses a security risk, as covert channels are mostly used for criminal purposes. We present a novel covert channel approach for streams of decimal data, a field which so far has been neglected. Moreover, we sketch an application scenario and analyze the covert channel's detectability, in particular how detectability and steganographic bandwidth can be traded against each other. The approach and proposals for detection are tested via simulation experiments.
Carina Heßeling, Jörg Keller 0001, Sebastian Litzinger
e-Science2
2022 Network Steganography Through Redundancy in Higher-Radix Floating-Point Representations
abstract
Higher-radix floating-point representations have the potential for higher performance, lower energy footprint, and reduced gate count in embedded systems when compared to traditional binary floating-point numbers. Thus, they might also appear in transmission of sensor data values. However, these number formats introduce redundancies, which can be exploited for steganographic message transfer. We present a covert channel that exploits this redundancy and can trade steganographic bandwidth against introduced error and thus detectability. In the basic variant, the covert channel is fully reversible, i.e., not detectable from the data. Experiments with an implementation illustrate that detectability via compressibility metric, Shannon entropy and bi-grams is possible depending on how aggressive bandwidth is pushed.
Carina Heßeling, Jörg Keller 0001, Sebastian Litzinger
ARES2
2022 Challenging Channels: Encrypted Covert Channels within Challenge-Response Authentication
abstract
Challenge-response authentication is an essential and omnipresent network service. Thus, it is a lucrative target for attackers to transport covert information. We present two covert channels in nonce-based network authentication that allow the encrypted transfer of covert information. Both channels exploit fundamental problems, not contained to the specific implementation or cryptographic mechanisms. We provide implementations and evaluations for hash- and key-based challenge-response authentication. Our implementation achieves hard detectability and acceptable throughput rates. Further, we analyze how the throughput can be maximized by applying compression and codebook techniques. We also describe how the presented approach is suitable for the extraction of sensitive information and performing command-and-control communication, showcased by the exfiltration of three different malware code snippets. Further, we discuss potential countermeasures, that can detect, limit and eliminate the proposed covert channels.
Tobias Schmidbauer, Jörg Keller 0001, Steffen Wendzel
ARES2
2022 Code generation for energy-efficient execution of dynamic streaming task graphs on parallel and heterogeneous platforms
abstract
Summary Streaming task graphs are high‐level specifications for parallel applications operating on streams of data. For a static task graph structure, static schedulers can be used to map the tasks onto a parallel platform to minimize energy consumption for given throughput. We introduce dynamic elements into the task graph structure, thus specifying applications which adapt behavior at runtime, for example, switching from check‐only to active mode. This in turn necessitates a runtime system that can remap tasks and potentially adapt their degree of parallelism in case of a dynamic change of the task structure. We provide a toolchain and evaluate our prototype with streaming task graphs both synthetic and from a real application. We find that we meet throughput requirements with <3.5% energy overhead on average compared with an optimal static scheduler based on integer linear programming. Runtime overhead for remapping is negligible and application runtime and energy are accurately predicted. We also outline how to extend our system to a heterogeneous platform.
Sebastian Litzinger, Jörg Keller 0001
Concurr. Comput. Pract. Exp.2
2022 Systematic search space design for energy-efficient static scheduling of moldable tasks
abstract
Static scheduling of independent, moldable tasks on parallel machines with frequency scaling comprises decisions on core allocation, assignment, frequency scaling and ordering, to meet a deadline and minimize energy consumption. Constraining some of these decisions reduces the solution space, i.e. may increase energy consumption, but may also open the path to new, near-optimal approaches. We investigate how constraints of different steps influence energy consumption, starting with an unrestricted scheduler for moldable tasks. The constraints are partly derived from existing schedulers, but also generalized in a systematic way. We present integer linear programs for all scheduling variants. We compare energy consumption of schedules for a benchmark suite of synthetic task sets of different sizes and for task sets derived from real applications. In addition, we check how close the results are to the optimum results when the ILP solver meets a timeout. Our results indicate that constraints on task execution order, which avoid explicit representation of task order in ILPs, are mostly responsible for near-optimal energy consumption among large task sets. Furthermore, we find that for all steps except allocation, non-optimal fast heuristics can be used without sacrificing too much energy for the resulting schedule. Finally, we can show that an ILP for a new scheduler, for which also a heuristic version exists, is comparable in quality to more complicated schedulers.
Jörg Keller 0001, Sebastian Litzinger
J. Parallel Distributed Comput.1
2022 Improving cryptanalytic applications with stochastic runtimes on GPUs and multicores
Lena Oden, Jörg Keller 0001
Parallel Comput.2
2021 Chaotic Pseudo Random Number Generators: A Case Study on Replication Study Challenges
abstract
Chaotic Pseudo Random Number Generators have been seen as a promising candidate for secure random number generation. Using the logistic map as state transition function, we perform number generation experiments that illustrate the challenges when trying to do a replication study. Those challenges range from uncertainties about the rounding mode in arithmetic hardware over chosen number representations for variables to compiler or programmer decisions on evaluation order for arithmetic expressions. We find that different decisions lead to different streams with different security properties, where we focus on period length, but descriptions in articles often are not detailed enough to deduce all decisions unambiguously. Similar problems might, to some extent, appear in other types of replication studies for security applications. Therefore we propose recommendations for descriptions of numerical experiments on security applications to avoid the above challenges.
Jörg Keller 0001
ARES1
2021 A Revised Taxonomy of Steganography Embedding Patterns
abstract
Steganography embraces several hiding techniques which spawn across multiple domains. However, the related terminology is not unified among the different domains, such as digital media steganography, text steganography, cyber-physical systems steganography, network steganography (network covert channels), local covert channels, and out-of-band covert channels. To cope with this, a prime attempt has been done in 2015, with the introduction of the so-called hiding patterns, which allow to describe hiding techniques in a more abstract manner. Despite significant enhancements, the main limitation of such a taxonomy is that it only considers the case of network steganography.
Steffen Wendzel, Luca Caviglione, Wojciech Mazurczyk, Aleksandra Mileva, Jana Dittmann, Christian Krätzer, Kevin Lamshöft, Claus Vielhauer, Laura Hartmann, Jörg Keller 0001, Tom Neubert
ARES10
2021 Temperature-Aware Energy-Optimal Scheduling of Moldable Streaming Tasks onto 2D-Mesh-Based Many-Core CPUs with DVFS
Christoph W. Kessler, Jörg Keller 0001, Sebastian Litzinger
JSSPP2
2021 Encapcap: Transforming Network Traces to Virtual Networks
abstract
Valid and complete network captures are a valuable source when detecting network based attacks and adversarial data exfiltration techniques like covert channels or performing network forensic investigation Also in training, testing, benchmarking and algorithm development, the availability of prerecorded, entire packet captures is eminent. Such a packet capture contains the entire packet stream with all incoming and outgoing network packets recorded over a defined period of time. Whereas a large number of recorded packet captures with well-known protocols from physical networks exists, the number of available files focused on virtual networks is low. Yet, virtual networks are taking on an ever greater role in modern environments. The creation of such network traces is a time-consuming and error-prone task, and the inherent behaviour of virtual networks eradicates a straight-forward automation of trace generation in comparison to common networks. In this paper we analyze relevant conditions of modern networks which hamper the generation of valid test captures and propose Encapcap, a tool that transforms given network packets stored in a capture file to virtual network packets. This improves the process of generating real-life packet captures for testing or training in virtual networks. We evaluate Encapcap with several experiments to demonstrate its correctness, usefulness and applicability.
Daniel Spiekermann, Jörg Keller 0001
NetSoft2
2021 Unsupervised packet-based anomaly detection in virtual networks
abstract
The enormous number of network packets transferred in modern networks together with the high speed of transmissions hamper the implementation of successful IT security mechanisms. In addition, virtual networks create highly dynamic and flexible environments which differ widely from well-known infrastructures of the past decade. Network forensic investigation that aims at the detection of covert channels, malware usage or anomaly detection is faced with new problems and is thus a time-consuming, error-prone and complex process. Machine learning provides advanced techniques to perform this work faster, more precise and, simultaneously, with fewer errors. Depending on the learning technique, algorithms work nearly without any interaction to detect relevant events in the transferred network packets. Current algorithms work well in static environments, but the highly dynamic environments of virtual networks create additional events which might confuse anomaly detection algorithms. This paper analyzes highly flexible networks and their inherent on-demand changes like the migration of virtual machines, SDN-programmability or user customization and the resulting effect on the detection rate of anomalies in the environment. Our research shows the need for adapted pre-processing of the network data and improved cooperation between IT security and IT administration departments.
Daniel Spiekermann, Jörg Keller 0001
Comput. Networks2
2021 Preface
abstract
co-located with the 40th International Conference on Application and Theory of Petri Nets and Concurrency (Petri Nets 2019).Both conferences were organized by the Process and
Jörg Keller 0001, Wojciech Penczek
Fundam. Informaticae1
2021 Crown-scheduling of sets of parallelizable tasks for robustness and energy-elasticity on many-core systems with discrete dynamic voltage and frequency scaling
abstract
Crown scheduling is a static scheduling approach for sets of parallelizable tasks with a common deadline, aiming to minimize energy consumption on parallel processors with frequency scaling. We demonstrate that crown schedules are robust, i. e. that the runtime prolongation of one task by a moderate percentage does not cause a deadline transgression by the same fraction. In addition, by speeding up some tasks scheduled after the prolonged task, the deadline can still be met at a moderate additional energy consumption. We present a heuristic to perform this re-scaling online and explore the tradeoff between additional energy consumption in normal execution and limitation of deadline transgression in delay cases. We evaluate our approach with scheduling experiments on synthetic and application task sets. Finally, we consider influence of heterogeneous platforms such as ARM’s big.LITTLE on robustness.
Christoph W. Kessler, Sebastian Litzinger, Jörg Keller 0001
J. Syst. Archit.3
2020 Impact of Virtual Networks on Anomaly Detection with Machine Learning
abstract
The enormous number of network packets transferred in modern networks together with the high-speed transmissions hamper the implementation of successful IT security mechanisms. In addition to this, virtual networks create highly dynamic and flexible environments, which differ widely from well-known infrastructures of the past decade. Network forensic investigation aiming at the detection of covert channels, malware usage or anomaly detection is faced with new problems and gets a time-consuming, error-prone and complex process. Machine learning provides advanced techniques to perform this work faster with a lower error rate. Depending on the learning technique, algorithms work nearly without any necessary interaction to detect relevant events in the transferred network packets. Occurring changes are noticed and additional processes might be started. Current algorithms work well in static environments, but the highly-dynamic environments of virtual networks create additional events, which might irritate the anomaly detection algorithms. This paper analyses virtual network protocols like VXLAN, GRE and GENVE and their impact of the detection rate of anomalies in the environment. Our research shows the need for adapted pre-processing of the network data, in the worst case on demand if changes are detected.
Daniel Spiekermann, Jörg Keller 0001
NetSoft2
2020 Robustness and Energy-elasticity of Crown Schedules for Sets of Parallelizable Tasks on Many-core Systems with DVFS
abstract
Croivn scheduling is a static scheduling approach for sets of parallelizable tasks with a common deadline, aiming to minimize energy consumption on parallel processors with frequency scaling. We demonstrate that crown schedules are robust, i.e. that the runtime prolongation of one task by a moderate percentage does not cause a deadline transgression by the same fraction. In addition, by speeding up some tasks scheduled after the prolonged task, the deadline can still be met at a moderate additional energy consumption. We present a heuristic to perform this re-scaling online. We evaluate our approach with scheduling experiments on synthetic task sets.
Christoph W. Kessler, Sebastian Litzinger, Jörg Keller 0001
PDP3
2020 Maximizing Profit in Energy-Efficient Moldable Task Execution with Deadline
abstract
We consider static scheduling of parallelizable tasks onto machines with frequency scaling for the case that not all tasks can be executed prior to a deadline. We model this scenario from a HPC cluster operator's perspective. We solve the combinatorial optimization problem to maximize the operator's profit by integer linear programming and by a heuristic. We evaluate the heuristic with synthetic benchmark task sets and demonstrate that it achieves at most 20 % less profit than the solution via linear programming, so that it can be used for large task sets where the latter is not feasible anymore.
Sebastian Litzinger, Jörg Keller 0001, Christoph W. Kessler
PDP2
2020 Voltage Island-Aware Energy-Efficient Scheduling of Parallel Streaming Tasks on Many-Core CPUs
abstract
For multi- and many-core CPUs, dynamic voltage and frequency scaling (DVFS) for individual cores provides an effective way for energy-efficient execution of applications. However, this requires additional hardware within the chip that regulates voltage and frequency for each hardware sub-component that can be scaled separately. Because of the significant cost of this control hardware, it is often not realistic to provide such a regulator for each individual core. Instead, chip manufacturers group cores into islands consisting of multiple cores with a common regulator, and energy optimizing solutions must take this constraint into account when assigning frequencies to jobs and cores. Crown Scheduling is a technique for the combined resource allocation, mapping and discrete DVFS-level selection for actor networks consisting of moldable parallel streaming tasks for energy efficient execution given a throughput constraint. We extend crown scheduling to compute correct schedules also in the presence of DVFS islands constraints. We find that, for most task sets, the crown scheduler computes almost equally good schedules for target architectures with and without island constraints.
Nicolas Melot, Christoph W. Kessler, Jörg Keller 0001
PDP3
2020 Comparing optimal and heuristic taskgraph scheduling on parallel machines with frequency scaling
abstract
Summary We investigate static scheduling of taskgraphs onto parallel machines where the frequency of processors can be scaled at runtime. Given a deadline until which execution of the resulting schedule must be completed, we aim at minimizing the energy consumed by the parallel processors during execution. We present optimal and heuristic solutions to this problem and partial problems. We quantify the increase in energy consumption when switching from a globally optimal solution via a combination of optimal partial solutions to heuristic solutions. We find that, on our set of benchmark taskgraphs, the increase is 32.56% on average for a combination of heuristic solutions and thus tolerable.
Patrick Eitschberger, Jörg Keller 0001
Concurr. Comput. Pract. Exp.2
2020 VoIP network covert channels to enhance privacy and information sharing
abstract
Information hiding is increasingly used to implement covert channels, to exfiltrate data or to perform attacks in a stealthy manner. Another important usage deals with privacy, for instance, to bypass limitations imposed by a regime, to prevent censorship or to share information in sensitive scenarios such as those dealing with cyber defense. In this perspective, the paper investigates how VoIP communications can be used as a methodology to enhance privacy. Specifically, we propose to hide traffic into VoIP conversations in order to prevent the disclosure, exposure and revelation to an attacker or blocking the ongoing exchange of information. To this aim, we exploit the voice activity detection feature available in many client interfaces to produce fake silence packets, which can be used as the carrier where to hide data. Results indicate that the proposed approach can be suitable to enforce the privacy in real use cases, especially for file transfers. As interactive services (e.g., web browsing) may experience too many delays due to the limited bandwidth, some form of optimization or content scaling may be advisable for such scenarios.
Jens Saenger, Wojciech Mazurczyk, Jörg Keller 0001, Luca Caviglione
Future Gener. Comput. Syst.3
2020 Static Scheduling of Moldable Streaming Tasks With Task Fusion for Parallel Systems With DVFS
abstract
We consider the problem of statically scheduling a task graph of moldable streaming tasks (i.e., the actor network) to a multicore or many-core CPU with discrete dynamic voltage and frequency scaling (DVFS). We employ an integer linear programming (ILP) approach that combines allocating cores to tasks, mapping tasks to core subsets, selecting a DVFS level for each task, and considering all options for task fusion as provided by a cost model, given data throughput and latency requirements and targeting low energy consumption. We also propose a partly decoupled approach that applies greedy prefusion before running an ILP-based scheduler considering the other three subproblems together. We use microbenchmarking on an ARM big.LITTLE architecture to quantify the advantage of task fusion in the above setting, and evaluate the use of task fusion in terms of energy savings, latency improvement, and scheduling time for three real-world applications. We confirm the scheduling results by running the applications with and without task fusions on the ARM big.LITTLE. Results indicate that streaming applications can profit from task fusion, as we achieve a significant reduction of energy consumption in most cases, while scheduling time is only moderately increased.
Christoph W. Kessler, Sebastian Litzinger, Jörg Keller 0001
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.3
2019 A Study of Network Forensic Investigation in Docker Environments
abstract
Cyber-criminals harness more and more techniques like virtual machines or container-based infrastructures for their malicious activities. The inherent dynamic of these virtual environments simplifies the fast creation of vicious services and hide the involved systems like no other technology before. The primary use of virtualisation and especially containers facilitates software developers and administrators to create new applications, perform tests, debug their code and install pre-defined services based on provided container images. Docker as the most notable container technique provides a great variety of existing container templates, which pave the way for implementing highly dynamic environments. As virtual machines, container-based environments are mostly a short-living on-demand infrastructure, which might be used by cyber-criminals to perform their malicious activities. Especially the virtual layer and the ephemeral nature of the container impede any kind of digital investigation or forensic analysis. In this paper we analyze different methods for network forensic investigation in Docker environments. The virtualisation demands for adapted techniques of packet capture like iptables-manipulation, accessing the internal network bridges or vNICs and the use of software-based techniques. We propose the use of further monitoring processes in Docker swarms to implement a valid packet capture and to collect all relevant network packets. As a result, we define appropriate techniques of packet captures based on parameters of the related container.
Daniel Spiekermann, Tobias Eggendorfer, Jörg Keller 0001
ARES3
2019 Countering adaptive network covert communication with dynamic wardens
Wojciech Mazurczyk, Steffen Wendzel, Mehdi Chourib, Jörg Keller 0001
Future Gener. Comput. Syst.4
2018 Towards Utilization of Covert Channels as a Green Networking Technique
abstract
Network covert channels are currently typically seen as a security threat which can result in e.g. confidential data leakage or in a hidden data exchange between malicious parties. However, in this paper we want to investigate network covert channels from a less obvious angle i.e. we want to verify whether it is possible to use them as a green networking technique. Our observation is that usually covert channels utilize various redundant "resources" in network protocols e.g. unused/reserved fields that would have been transmitted anyway. Therefore, using such "resources" for legitimate transmissions can increase the total available bandwidth without sending more packets and thus offering potential energy savings. However, it must be noted that embedding and extracting processes related to data hiding consumes energy, too. That is why, in this paper we try to establish whether the potentially saved energy due to covert channels utilization exceeds the effort needed to establish and maintain covert data transmission. For this purpose, a proof-of-concept implementation has been created to experimentally measure the impact of network covert channels on resulting energy consumption. The obtained results show that the approach can be useful mostly under specific circumstances, i.e., when the total energy consumption of the network devices is already relatively high. Furthermore, the impact of different types of network covert channels on the energy consumption is examined to assess their usefulness from the green networking perspective.
Daniel Geisler, Wojciech Mazurczyk, Jörg Keller 0001
ARES3
2018 Exploiting IP telephony with silence suppression for hidden data transfers
Sabine S. Schmidt, Wojciech Mazurczyk, Radoslaw Kulesza, Jörg Keller 0001, Luca Caviglione
Comput. Secur.4
2017 A New Data-Hiding Approach for IP Telephony Applications with Silence Suppression
abstract
Even if information hiding can be used for licit purposes, it is increasingly exploited by malware to exfiltrate data or to coordinate attacks in a stealthy manner. Therefore, investigating new methods for creating covert channels is fundamental to completely assess the security of the Internet. Since the popularity of the carrier plays a major role, this paper proposes to hide data within VoIP traffic. Specifically, we exploit Voice Activity Detection (VAD), which suspends the transmission during speech pauses to reduce bandwidth requirements. To create the covert channel, our method transforms a VAD-activated VoIP stream into a non-VAD one. Then, hidden information is injected into fake RTP packets generated during silence intervals. Results indicate that steganographically modified VAD-activated VoIP streams offer a good trade-off between stealthiness and steganographic bandwidth.
Sabine S. Schmidt, Wojciech Mazurczyk, Jörg Keller 0001, Luca Caviglione
ARES3
2017 Workload Type-Aware Scheduling on big.LITTLE Platforms
Simon Holmbacka, Jörg Keller 0001
ICA3PP2
2017 Tweaking cryptographic primitives with moderate state space by direct manipulation
abstract
Cryptographic primitives such as hash chains or pseudo-random number generators (PRNGs) work for some time without input. State space in embedded applications is often moderate because of resource restrictions, so that state repetitions might occur too soon and may compromise security. We investigate the question whether it is possible to change the transition function of such a primitive only for a very small number of states and still achieve a notable increase in cycle length. We present a greedy algorithm that searches those states, and give an implementation that only marginally increases the effort per state transition. We evaluate the algorithm with a chaotic PRNG and hash chains based on MD5 and SHA-3 with promising results.
Jörg Keller 0001, Gabriele Spenger
ICC1
2017 Secure genomic data evaluation in cloud environments
abstract
Security in clouds often focuses on preventing unauthorized access to confidential information. However, cloud providers might also be a source for loss of confidentiality and are generally considered in risk models as honest but curious (HBC). The wide availability and high volume of genomic data improves advances in biomedical research, but outsourcing genomic data processing to cloud providers presents new challenges and risks due to the confidentiality of such data and the critical consequences of a possible loss. We present techniques to securely delegate Genome-Wide Association Study (GWAS) data into clouds using encrypted data. The protocol is based on homomorphic properties of well known encryption algorithms. The protocol can also be used to amend existing applications by software patches of binaries. In the present paper we introduce some practical extensions to our algorithm to improve its efficiency. Additionally we extend the algorithm to support novel optimizations, including Single Operation Multiple Data (SIMD) while preserving its homomorphic properties. We evaluate the protocol by a proof-of-concept implementation of minor allele frequency and chi-squared statistics computations on real-life genomic data to investigate practicability, and discuss variants and extensions to increase the prototype's efficiency.
Adil Bouti, Jörg Keller 0001
ISNCC2
2017 Towards Covert Channels in Cloud Environments: A Study of Implementations in Virtual Networks
Daniel Spiekermann, Jörg Keller 0001, Tobias Eggendorfer
IWDW2
2017 Inter-Protocol Steganography for Real-Time Services and Its Detection Using Traffic Coloring Approach
abstract
Due to improvements in defensive systems, network threats are becoming increasingly sophisticated and complex as cybercriminals are using various methods to cloak their actions. This, among others, includes the application of network steganography e.g. to hide the communication between an infected host and a malicious control server by embedding commands into innocent-looking traffic. Currently, a new subtype of such methods called inter-protocol steganography emerged. It utilizes relationships between two or more overt protocols to hide data. In this paper, we present new inter-protocol hiding techniques which are suitable for real-time services. Afterwards, we introduce and present preliminary results of a novel steganography detection approach which relies on network traffic coloring.
Florian Lehner, Wojciech Mazurczyk, Jörg Keller 0001, Steffen Wendzel
LCN3
2017 Hardware and Software Support for Transposition of Bit Matrices in High-Speed Encryption
Patrick Eitschberger, Jörg Keller 0001, Simon Holmbacka
NSS2
2017 Fault-Tolerant Parallel Execution of Workflows with Deadlines
abstract
Workflows of dependent tasks are a widespread model for parallel applications, often statically scheduled prior to application. Static schedules can tolerate processor failures due to permanent faults by placing duplicate tasks during the scheduling process. Schedules for workflows with deadlines can be extended to include frequency scaling information to optimize energy consumption. Frequency scaling can also be used in case of a fault to minimize its effects on the schedule makespan, however for the price of additional energy consumption. We investigate the interplay between these two parameters and quantify the energy increase to be expected in case of a fault and a given makespan increase. This knowledge enables the user to inform the scheduler about the makespan increase that is tolerable in case of a fault, where tolerable includes both the related performance aspects and the expected increase in energy. To achieve this, we model small taskgraphs from a benchmark suite as integer linear programs and determine with the help of a solver energy-optimal schedules for the fault-free case and for all possible fault positions with several levels of makespan increase. We present averages and distribution depending on makespan increase for a processor with hypothetical power profile. Additionally, we present two heuristics to modify task frequency settings in case of a fault, to restrict the makespan increase to a given value. Comparison with optimal frequency settings from the benchmark suite indicate that the heuristics only incur a small energy overhead.
Patrick Eitschberger, Jörg Keller 0001
PDP2
2017 Asymmetric Crown Scheduling
abstract
Streaming applications are often used for embedded and high-performance multi and manycore processors. Achieving high throughput without wasting energy can be achieved by static scheduling of parallelizable tasks with frequency scaling. We present asymmetric crown scheduling, which improves on the static crown scheduling approach by allowing flexible split ratios when subdividing processor groups. We formulate the scheduler as an integer linear program and evaluate it with synthetic task sets. The results demonstrate that a small number of split ratios improves energy efficiency of crown schedules by up to 12% with slightly higher scheduling time.
Manfred Torggler, Jörg Keller 0001, Christoph W. Kessler
PDP2
2016 Energy-Optimized Static Scheduling for Many-Cores with Task Parallelization, DVFS and Core Consolidation
abstract
We demonstrate how static, energy-efficient, compiler-generated schedules for independent, parallelizable tasks on parallel machines can be improved by modeling idle power. We assume that the static power consumption of a core comprises a notable fraction of the core's total power, which is more and more often the case. The improvement is achieved by optimally packing cores when deciding about core allocation, mapping and DVFS for each task so that all unused cores can be switched off and overall energy usage is minimized. We evaluate our proposal with a benchmark suite of task collections, and compare the resulting schedules with an optimal scheduler that does not take idle power and core switch-off into account. We find that we can reduce energy consumption by 66% for mostly sequential tasks on many cores and by up to 91% for a realistic multicore processor model.
Nicolas Melot, Christoph W. Kessler, Jörg Keller 0001
SCOPES3
2016 Micro protocol engineering for unstructured carriers: on the embedding of steganographic control protocols into audio transmissions
abstract
Abstract Network steganography conceals the transfer of sensitive information within unobtrusive data in computer networks. So‐called micro protocols are communication protocols placed within the payload of a network steganographic transfer. They enrich this transfer with features such as reliability, dynamic overlay routing, or performance optimization — just to mention a few. We present different design approaches for the embedding of hidden channels with micro protocols in digitized audio signals under consideration of different requirements. On the basis of experimental results, our design approaches are compared and introduced into a protocol engineering approach for micro protocols. Copyright © 2016 John Wiley & Sons, Ltd.
Matthias Naumann, Steffen Wendzel, Wojciech Mazurczyk, Jörg Keller 0001
Secur. Commun. Networks4
2015 Energy-Efficient Task Scheduling in Manycore Processors with Frequency Scaling Overhead
abstract
We investigate deadline scheduling of independent tasks on parallel processors with discrete frequency levels, when the latency for frequency scaling cannot be neglected. This situation frequently occurs in applications, e.g. streaming applications with soft real-time requirements. We demonstrate that previous algorithms for energy-optimal static scheduling of independent tasks are non-optimal in this setting. We present a scheduling heuristic based on bin packing with a cost function that takes latency for frequency scaling into account. We evaluate our heuristic against previous approaches with benchmark task sets and achieve energy reductions between 3% and 13%. We further demonstrate that for a concrete embedded multicore processor, the power curves vary over the identical cores, so that the processor looks heterogeneous from a power perspective. We adapt our bin packing heuristic and demonstrate that for the benchmark task sets, further energy reductions up to 4% can be achieved.
Patrick Eitschberger, Jörg Keller 0001
PDP2
2015 Accurate Energy Modelling for Many-Core Static Schedules
abstract
Static schedules can be a preferable alternative for applications with timing requirements and predictable behavior since the processing resources can be more precisely allocated for the given workload. Unused resources are handled by power management systems to either scale down or shut off parts of the chip to save energy. In order to efficiently implement power management, especially in many-core systems, an accurate model is important in order to make the appropriate power management decisions at the right time. For making correct decisions, practical issues such as latency for controlling the power saving techniques should be considered when deriving the system model, especially for fine timing granularity. In this paper we present an accurate energy model for many-core systems which includes switching latency of modern power saving techniques. The model is used when calculating an optimal static schedule for many-core task execution on systems with dynamic frequency levels and sleep state mechanisms. We create the model parameters for an embedded processor, and we validate it in practice with synthetic benchmarks on real hardware.
Simon Holmbacka, Jörg Keller 0001, Patrick Eitschberger, Johan Lilius
PDP2
2015 Fast Crown Scheduling Heuristics for Energy-Efficient Mapping and Scaling of Moldable Streaming Tasks on Many-Core Systems
abstract
Exploiting effectively massively parallel architectures is a major challenge that stream programming can help to face. We investigate the problem of generating energy-optimal code for a collection of streaming tasks that include parallelizable or moldable tasks on a generic manycore processor with dynamic discrete frequency scaling. In this paper we consider crown scheduling, a novel technique for the combined optimization of resource allocation, mapping and discrete voltage/frequency scaling for moldable streaming task collections in order to optimize energy efficiency given a throughput constraint. We present optimal off-line algorithms for separate and integrated crown scheduling based on integer linear programming (ILP) and heuristics able to compute solution faster and for bigger problems. We make no restricting assumption about speedup behavior.
Nicolas Melot, Christoph W. Kessler, Jörg Keller 0001, Patrick Eitschberger
SCOPES3
2014 H2rs: Deducing evolutionary and functionally important residue positions by means of an entropy and similarity based analysis of multiple sequence alignments
abstract
BACKGROUND: The identification of functionally important residue positions is an important task of computational biology. Methods of correlation analysis allow for the identification of pairs of residue positions, whose occupancy is mutually dependent due to constraints imposed by protein structure or function. A common measure assessing these dependencies is the mutual information, which is based on Shannon's information theory that utilizes probabilities only. Consequently, such approaches do not consider the similarity of residue pairs, which may degrade the algorithm's performance. One typical algorithm is H2r, which characterizes each individual residue position k by the conn(k)-value, which is the number of significantly correlated pairs it belongs to. RESULTS: To improve specificity of H2r, we developed a revised algorithm, named H2rs, which is based on the von Neumann entropy (vNE). To compute the corresponding mutual information, a matrix A is required, which assesses the similarity of residue pairs. We determined A by deducing substitution frequencies from contacting residue pairs observed in the homologs of 35 809 proteins, whose structure is known. In analogy to H2r, the enhanced algorithm computes a normalized conn(k)-value. Within the framework of H2rs, only statistically significant vNE values were considered. To decide on significance, the algorithm calculates a p-value by performing a randomization test for each individual pair of residue positions. The analysis of a large in silico testbed demonstrated that specificity and precision were higher for H2rs than for H2r and two other methods of correlation analysis. The gain in prediction quality is further confirmed by a detailed assessment of five well-studied enzymes. The outcome of H2rs and of a method that predicts contacting residue positions (PSICOV) overlapped only marginally. H2rs can be downloaded from http://www-bioinf.uni-regensburg.de. CONCLUSIONS: Considering substitution frequencies for residue pairs by means of the von Neumann entropy and a p-value improved the success rate in identifying important residue positions. The integration of proven statistical concepts and normalization allows for an easier comparison of results obtained with different proteins. Comparing the outcome of the local method H2rs and of the global method PSICOV indicates that such methods supplement each other and have different scopes of application.
Jan-Oliver Janda, Ajmal Popal, Jochen Bauer, Markus Busch, Michael Klocke, Wolfgang Spitzer, Jörg Keller 0001, Rainer Merkl
BMC Bioinform.7
2014 Fast Crown Scheduling Heuristics for Energy-Efficient Mapping and Scaling of Moldable Streaming Tasks on Manycore Systems
abstract
Exploiting effectively massively parallel architectures is a major challenge that stream programming can help facilitate. We investigate the problem of generating energy-optimal code for a collection of streaming tasks that include parallelizable or moldable tasks on a generic manycore processor with dynamic discrete frequency scaling. Streaming task collections differ from classical task sets in that all tasks are running concurrently, so that cores typically run several tasks that are scheduled round-robin at user level in a data-driven way. A stream of data flows through the tasks and intermediate results may be forwarded to other tasks, as in a pipelined task graph. In this article, we consider crown scheduling , a novel technique for the combined optimization of resource allocation, mapping, and discrete voltage/frequency scaling for moldable streaming task collections in order to optimize energy efficiency given a throughput constraint. We first present optimal offline algorithms for separate and integrated crown scheduling based on integer linear programming (ILP). We make no restricting assumption about speedup behavior. We introduce the fast heuristic Longest Task, Lowest Group (LTLG) as a generalization of the Longest Processing Time (LPT) algorithm to achieve a load-balanced mapping of parallel tasks, and the Height heuristic for crown frequency scaling. We use them in feedback loop heuristics based on binary search and simulated annealing to optimize crown allocation. Our experimental evaluation of the ILP models for a generic manycore architecture shows that at least for small and medium-sized streaming task collections even the integrated variant of crown scheduling can be solved to optimality by a state-of-the-art ILP solver within a few seconds. Our heuristics produce makespan and energy consumption close to optimality within the limits of the phase-separated crown scheduling technique and the crown structure. Their optimization time is longer than the one of other algorithms we test, but our heuristics consistently produce better solutions.
Nicolas Melot, Christoph W. Kessler, Jörg Keller 0001, Patrick Eitschberger
ACM Trans. Archit. Code Optim.3
2010 Optimized On-Chip-Pipelined Mergesort on the Cell/B.E
Rikard Hultén, Christoph W. Kessler, Jörg Keller 0001
Euro-Par (2)3
2009 Guiding performance tuning for grid schedules
abstract
Grid jobs often consist of a large number of tasks. If the performance of a statically scheduled grid job is unsatisfactory, one must decide which code of which task should be improved. We propose a novel method to guide grid users as to which tasks of their grid job they should accelerate in order to reduce the makespan of the complete job. The input we need is the task schedule of the grid job, which can be derived from traces of a previous run of the job. We provide several algorithms depending on whether only one or several tasks can be improved, or whether task improvement is achieved by improvement of one processor.
Jörg Keller 0001, Wolfram Schiffmann
IPDPS1
2009 Storage architecture with integrity, redundancy and encryption
abstract
We propose a storage system that treats confidentiality, integrity and availability of data in a unified manner. Extending RAID6, it allows for failures of multiple disks, encrypts data on disk, and stores checksums to detect faulty data without disks failing, which occurs e.g. in solid state disks due to wear out of cells. By handling encryption and integrity check together, the probability of undetected faulty data is reduced further. We provide an implementation, i.e. a driver, which encapsulates all these features and uses parallel algorithms exploiting multicore processor performance to match the bandwidth available from multiple disks. We present performance figures of our experiments.
Henning Klein, Jörg Keller 0001
IPDPS2
2008 Fault-tolerant static scheduling for grids
abstract
While fault-tolerance is desirable for grid applications because of the distributed and dynamic nature of grid resources, it has seldom been considered in static scheduling. We present a fault-tolerant static scheduler for grid applications that uses task duplication and combines the advantages of static scheduling, namely no overhead for the fault-free case, and of dynamic scheduling, namely low overhead in case of a fault. We also give preliminary experimental results on our scheme.
Bernhard Fechner, Udo Hönig, Jörg Keller 0001, Wolfram Schiffmann
IPDPS3
2008 An Efficient Algorithm for Computing the Reliability of Consecutive-k-Out-Of-n: F Systems
abstract
Many algorithms for computing the reliability of linear or circular consecutive-k-out-of-n:F systems appeared in this Transactions. The best complexity estimate obtained for solving this problem is O(k3log(n/k)) operations in the case of i.i.d. components. Using fast algorithms for computing a selected term of a linear recurrence with constant coefficients, we provide an algorithm having arithmetic complexity O(k log (k) log(log(k)) log(n)+komega) where 2<omega< 3 is the exponent of linear algebra. This algorithm holds generally for linear, and circular consecutive-k-out-of-n:F systems with independent but not necessarily identical components.
Thomas Cluzeau, Jörg Keller 0001, Winfrid G. Schneeweiss
IEEE Trans. Reliab.2
2007 Hirschberg's Algorithm on a GCA and Its Parallel Hardware Implementation
Johannes Jendrsczok, Rolf Hoffmann 0001, Jörg Keller 0001
Euro-Par3
2007 Implementing Hirschberg's PRAM-Algorithm for Connected Components on a Global Cellular Automaton
abstract
The GCA (global cellular automata) model consists of a collection of cells which change their states synchronously depending on the states of their neighbors like in the classical CA model. In differentiation to the CA model the neighbors are not fixed and local, they are variable and global. The GCA model is applicable to a wide range of parallel algorithms, and it can be implemented on reconfigurable hardware. We discuss the GCA implementation of PRAM algorithms, exemplified by the algorithm of Hirschberg et al, which determines the connected components of a given undirected graph. Insights are that efficient mappings of PRAM algorithms onto GCA exist, and that PRAM and GCA optimality criteria differ because the latter takes memory consumption into account. This makes the GCA a parallel computational model and an implementation platform, thus narrowing the gap between theory and practice.
Johannes Jendrsczok, Rolf Hoffmann 0001, Jörg Keller 0001
IPDPS3
2007 Parallel-External Computation of the Cycle Structure of Invertible Cryptographic Functions
abstract
We present an algorithm to compute the cycle structure of large directed graphs where each node has exactly one outgoing edge. Such graphs appear as state diagrams of finite state machines such as pseudorandom number generators in cryptography. The size of the graphs necessitates that the adjacency list is kept on hard disks. Our algorithm uses multiple processing units, so that a parallel storage system has to be employed to store the graph. We present experimental results for randomly chosen graphs, and for the graph of the A5/1 generator used in GSM mobile phones
Andreas Beckmann, Jörg Keller 0001
PDP2
2006 A Collaborative Virtual Computer Security Lab
abstract
The necessity of a lab course on computer security arises from the students' need to complement course work by hands-on experience. In order to meet the distance teaching demands of our institution, we designed an internet-based laboratory. We sketch the types of tasks the students are to perform, and our approach to check immediately whether students have completed a task. Yet, the typical tasks in labs only cover work done alone, while security engineering often comprises tasks involving several independent parties. This in turn calls for collaborative tasks, which we sketch. As students operate in larger groups, and the server hosting the lab machines can only run a finite number of them simultaneously, a reservation scheme is employed to guarantee fair access for all participants.
Jörg Keller 0001, Ralf Naues
e-Science1
2006 Web server protection by customized instruction set encoding
abstract
We present a novel technique to secure the execution of a processor against the execution of malicious code (trojans, viruses). The main idea is to permute parts of the opcode values so that it gets a different semantic meaning. A virus which does not know the permutation is not able to execute and will cause a failure such as segmentation violation, whereby the execution of malicious code is prevented. The permutation is realized by a lookup table. We develop several variants that require only small changes to microprocessors. We sketch how to bootstrap a system such that all intended applications (including operating system) are reversely permuted, and can execute as intended. While this will be cumbersome for typical personal computers, it will work for Web servers, because the number of applications and frequency of installation is lower. Furthermore, Web servers are particularly endangered: they cannot be protected as good as personal computers, because by the very nature of their duty they are more openly connected with the Internet than any other computer in an organization's network.
Bernhard Fechner, Jörg Keller 0001, Andreas Wohlfeld
IPDPS2
2006 A System for Secure IP Telephone Conferences
abstract
We present a system for secure telephone conferences (stc) over the internet. The system ensures participant authentication via x.509 certificates, such that every participant of a conference is informed about every other participant. Also, all signaling and media data are encrypted, to ensure confidentiality. The system builds upon the open source telephone server asterisk and standard IP softphones. Those software products are used unaltered. Stc client and server processes reside with softphones and server, respectively, to realize secure conferences. Experiments with our prototype show that the additional network and processor load is low, and that the system scales well for more than 10 participants.
Axel Treßel, Jörg Keller 0001
NCA2
2006 A Distributed Query Structure to Explore Random Mappings in Parallel
abstract
We explore the possibilities to organize a query data structure in the main memories or hard disks of a cluster computer. The query data structure serves to improve the performance of a parallel algorithm for the computation of the structure of a graph induced by a random function. Tradeoffs between different organizations using main memory or hard disks are developed and quantified with parameters. Thus, for concrete cluster systems with concrete parameter values, the best organization can be selected.
Jan Heichler, Jörg Keller 0001
PDP2
2004 Performance Estimation of Virtual Duplex Systems on Simultaneous Multithreaded Processors
abstract
Summary form only given. Virtual duplex systems provide detection of transient as well as most permanent hardware faults by executing two versions of a program on a single processor in a time-shared manner. Previous studies on virtual duplex systems have focussed on either improving fault coverage or reducing overhead. We build upon this work and investigate the positive influence of an underlying processor architecture that supports parallelism in the form of multiple threads in hardware. Such processor architectures are just entering the market, with a die area only slightly larger than that of a conventional processor. A performance prediction shows that those processors allow faster fault detection than conventional processors of the same speed. Moreover, the parallelism can be utilized for a recovery that extends the concept of virtual duplex systems. Additionally, we present a technique that further increases the above mentioned gain by using prediction of the faulty version in a manner similar to branch prediction.
Bernhard Fechner, Jörg Keller 0001, Peter Sobe
IPDPS2
2002 A heuristic to accelerate in-situ permutation algorithms
Jörg Keller 0001
Inf. Process. Lett.1
2001 Beyond External Computing: Analysis of the Cycle Structure of Permutations
Jörg Keller 0001, Jop F. Sibeyn
Euro-Par1
1999 On the Cost-Effectiveness of PRAMs
Ferri Abolhassan, Jörg Keller 0001, Wolfgang J. Paul
Acta Informatica2
1996 Fast Rehashing in PRAM Emulations
Jörg Keller 0001
Theor. Comput. Sci.1
1995 Generalized Fisheye Views of Graphs
Arno Formella, Jörg Keller 0001
GD2
1995 A Note on Implementing Combining Networks
Jörg Keller 0001, Thomas Walle
Inf. Process. Lett.1
1994 Regular layouts of butterfly networks
Jörg Keller 0001
Integr.1
1993 On the Physical Design of PRAMs
abstract
We sketch the physical design of a prototype of a PRAM architecture based on Ranade’s Fluent Machine. We describe a specially developed processor chip with several instruction streams and a fast butterfly connection network. For the realization of the network we consider alternatively optoelectronic and electric transmission. We also discuss some basic software issues.
Ferri Abolhassan, Reinhard Drefenstedt, Jörg Keller 0001, Wolfgang J. Paul, Dieter Scheerer
Comput. J.3
1993 Reduction of Network Cost and Wiring in Ranade's Butterfly Routing
David Cross, Reinhard Drefenstedt, Jörg Keller 0001
Inf. Process. Lett.3