Srikanth V. Krishnamurthy

dblp:k/SrikanthVKrishnamurthy · DBLP profile ↗
← Back
221ranked-venue papers
3as first author
30since 2021 · last 2026
0000-0002-6533-4381ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 161 · 1 first-author · 9 since 2021Security and privacy · 23 · 10 since 2021Artificial intelligence and machine learning · 9 · 8 since 2021Systems, architecture and hardware · 9Graphics, computer vision, multimedia, augmented reality and games · 8 · 7 since 2021Human-computer interaction and ubiquitous computing · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 What Do They Fix? LLM-Aided Categorization of Security Patches for Critical Memory Bugs
Juefei Pu, Xiaochen Zou, Shitong Zhu, Qiushi Wu, Zheng Zhang 0058, Joshua Hsu, Zhiyun Qian, Kangjie Lu, Trent Jaeger, Michael J. De Lucia, Srikanth V. Krishnamurthy
NDSS14
2026 AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi Networks
Xin'an Zhou, Juefei Pu, Zhutian Liu 0002, Zhiyun Qian, Zhaowei Tan, Srikanth V. Krishnamurthy, Mathy Vanhoef
NDSS6
2026 Efficient Lightweight Coordinated Sampling for Dynamic Flows: Theory and Implementation
abstract
As cyber-attacks on networks become stealthier, monitoring techniques relying on low-rate packet sampling may prove insufficient to detect attacks. While various methods, such as truncating packets, flow-based sampling, and adaptive sampling rates, have been proposed to enhance detection rates and ease capability limitations, it remains challenging to perform sufficient sampling at line speed and high rates at a single sampling point due to limited CPU or bandwidth capacity and fluctuating network traffic. To address these challenges, we propose CoordSamp, a system that distributes the sampling workload across multiple sampling points and coordinates their actions to avoid duplicate sampling of the same packet. This design enables scalable, resource-aware monitoring—particularly suited for dynamic, agentless cloud-based environments—relying solely on network-level deployment that can be dynamically assigned and adjusted by the provider. We develop a coordinated sampling algorithm on multiple P4-programmable switches and show that the algorithm ensures coordination among multiple sampling points for each flow, preventing duplicate samples, with negligible network overhead and real-time configurability. At its core, CoordSamp separatesoffline placement—the budgeted selection of sampling points—fromonline allocation—the capacity-aware assignment of sampling tasks—allowing practical deployment in hybrid networks that combine programmable and legacy switches. We formulate sampling point placement as budgeted maximum multi-coverage problems, solving them optimally in pseudo-polynomial time. Our system far outperforms those based on greedy placement along many key dimensions.
Mingming Chen 0001, Thomas La Porta, Trent Jaeger, Srikanth V. Krishnamurthy
IEEE Trans. Netw.4
2025 AdMiT: Adaptive Multi-Source Tuning in Dynamic Environments
abstract
Incorporating transformer models into edge devices poses a significant challenge due to the computational demands of adapting these large models across diverse applications. Parameter-efficient tuning (PET) methods (e.g. LoRA, Adapter, Visual Prompt Tuning, etc.) allow for targeted adaptation by modifying only small parts of the transformer model. However, adapting to dynamic unlabeled target distributions at the test time remains complex. To address this, we introduce AdMiT: Adaptive Multi-Source Tuning in Dynamic Environments. AdMiT innovates by pre-training a set of PET modules, each optimized for different source distributions or tasks, and dynamically selecting and integrating a sparse subset of relevant modules when encountering a new, few-shot, unlabeled target distribution. This integration leverages Kernel Mean Embedding (KME)-based matching to align the target distribution with relevant source knowledge efficiently, without requiring additional routing networks or hyperparameter tuning. AdMiT achieves adaptation with a single inference step, making it particularly suitable for resource-constrained edge deployments. Furthermore, AdMiT preserves privacy by performing an adaptation locally on each edge device, without the need for data exchange. Our theoretical analysis establishes guarantees for AdMiT’s generalization, while extensive benchmarks demonstrate that AdMiT consistently outperforms other PET methods across a range of tasks, achieving robust and efficient adaptation.
Xiangyu Chang, Fahim Faisal Niloy, Sk Miraj Ahmed, Srikanth V. Krishnamurthy, Basak Guler, Ananthram Swami, Samet Oymak, Amit K. Roy-Chowdhury
CVPR4
2025 Gradient Inversion Attacks on Parameter-Efficient Fine-Tuning
abstract
Federated learning (FL) allows multiple data-owners to collaboratively train machine learning models by exchanging local gradients, while keeping their private data on-device. To simultaneously enhance privacy and training efficiency, recently parameter-efficient fine-tuning (PEFT) of large-scale pretrained models has gained substantial attention in FL. While keeping a pretrained (backbone) model frozen, each user fine-tunes only a few lightweight modules to be used in conjunction, to fit specific downstream applications. Accordingly, only the gradients with respect to these lightweight modules are shared with the server. In this work, we investigate how the privacy of the fine-tuning data of the users can be compromised via a malicious design of the pretrained model and trainable adapter modules. We demonstrate gradient inversion attacks on a popular PEFT mechanism, the adapter, which allow an attacker to reconstruct local data samples of a target user, using only the accessible adapter gradients. Via extensive experiments, we demonstrate that a large batch of fine-tuning images can be retrieved with high fidelity. Our attack highlights the need for privacy-preserving mechanisms for PEFT, while opening up several future directions. Our code is available at https://github.com/info-ucr/PEFTLeak.
Hasin Us Sami, Swapneel Sen, Amit K. Roy-Chowdhury, Srikanth V. Krishnamurthy, Basak Guler
CVPR4
2025 FedBand: Adaptive Federated Learning Under Strict Bandwidth Constraints
abstract
Federated Learning (FL) enables model training across decentralized clients while preserving data privacy. However, bandwidth constraints limit the volume of information exchanged, making communication efficiency a critical challenge. In addition, non-IID data distributions require fairness-aware mechanisms to prevent performance degradation for certain clients. Existing sparsification techniques often apply fixed compression ratios uniformly, ignoring variations in client importance and bandwidth. We propose Fed-Band, a dynamic bandwidth allocation framework that prioritizes clients based on their contribution to the global model. Unlike conventional approaches, FedBand does not enforce uniform client participation in every communication round. Instead, it allocates more bandwidth to clients whose local updates deviate significantly from the global model, enabling them to transmit a greater number of parameters. Clients with less impactful updates contribute proportionally less or may defer transmission, reducing unnecessary overhead while maintaining generalizability. By optimizing the trade-off between communication efficiency and learning performance, FedBand substantially reduces transmission costs while preserving model accuracy. Experiments on non-IID CIFAR-10 and UTMobileNet2021 datasets, demonstrate that FedBand achieves up to 99.81% bandwidth savings per round while maintaining accuracies close to that of an unsparsified model (80% on CIFAR-10, 95% on UTMobileNet), despite transmitting less than 1% of the model parameters in each round. Moreover, FedBand accelerates convergence by 37.4%, further improving learning efficiency under bandwidth constraints. Mininet emulations further show a 42.6% reduction in communication costs and a 65.57% acceleration in convergence compared to baseline methods, validating its real-world efficiency. These results demonstrate that adaptive bandwidth allocation can significantly enhance the scalability and communication efficiency of federated learning, making it more viable for real-world, bandwidth-constrained networking environments.
Taghreed Alanazi, Abdulrahman Fahim, Muntaka Ibnath, Basak Guler, Amit K. Roy-Chowdhury, Ananthram Swami, Evangelos E. Papalexakis, Srikanth V. Krishnamurthy
ICCCN8
2025 Beyond the Horizon: Uncovering Hosts and Services Behind Misconfigured Firewalls
abstract
Public IP addresses can expose devices and services to risks such as port scanning and subsequent cyberattacks. Therefore, firewalls are extensively deployed and play a critical role in enforcing security policies and preventing unauthorized access. However, vulnerabilities can allow firewalls to be by-passed, effectively nullifying the protection. In this paper, we present the first comprehensive study of a previously understudied attack surface: firewall misconfigurations that inadvertently expose protected services to the public Internet. Specifically, we demonstrate flawed firewall rules that allow inbound connections from special source ports to bypass the firewall, and explore the prevalence and security implications thereof. To this end, we scan the IPv4 space for 15 commonly high-risk TCP and UDP services from two special source ports. Our measurement reveals the widespread existence of such misconfigurations and identified over 2,000,000 otherwise unreachable services spread over 15,837 autonomous systems, expanding the “observable Internet” for various protocols by up to 12.60%. More importantly, the affected services generally exhibit higher security risks than the publicly accessible ones, like outdated software versions and weak configurations. Despite the severity of this vulnerability, our honeypot experiment provides little evidence of active exploitation in the wild. Our findings offer insights for better security posture and network administration, helping researchers and organizations anticipate and mitigate potential cyber threats emanating from the Internet.
Qing Deng, Juefei Pu, Zhaowei Tan, Zhiyun Qian, Srikanth V. Krishnamurthy
SP5
2024 Untangling the Knot: Breaking Access Control in Home Wireless Mesh Networks
abstract
Home wireless mesh networks (WMNs) are increasingly gaining popularity for their superior extensibility and signal coverage compared to traditional single-AP wireless networks. In particular, there is a single gateway node and multiple extender nodes that cooperate to provide wireless coverage. We observe that there is no comprehensive research conducted on the security aspects of the control plane of such networks. For example, this decentralized architecture enables each extender node to independently authenticate wireless clients by synchronizing access control policies from the gateway node. However, this synchronization unexpectedly opens an attack surface which has not been scrutinized.
Xin'an Zhou, Qing Deng, Juefei Pu, Keyu Man, Zhiyun Qian, Srikanth V. Krishnamurthy
CCS6
2024 DNS Exfiltration Guided by Generative Adversarial Networks
abstract
Today, DNS exfiltration attacks are detected by checking for anomalies present in the traffic, such as unusu-ally high transmission rates to a single domain and/or DNS query patterns that are very different from those in benign queries. While such approaches are seemingly robust, we show in this paper that our carefully designed and novel DNS exfiltration attack, Dolos, that uses a generative adversarial network (GAN), can guide the encoding of sensitive data in a manner that both evades these detectors and significantly speeds up the exfiltration rate compared to prior methods. At its core, Dolos divides the exfiltration data into smaller chunks, and projects each chunk into a representation that is very similar to benign queries. In addition, Dolosadaptively tunes its exfiltration rate to conform with benign DNS traffic from the compromised host, and introduces proper levels of spurious traffic to reduce entropy. Importantly, Dolos evades machine learning (ML) based detectors with no prior knowledge of their architectures or training sets (i.e., it is a blackbox exfiltration). We perform extensive evaluations using multiple datasets and also have a real im-plementation of DOLOS. Our evaluations show that DOLOS has a 12% detection probability even if 6 out of the 9 state-of-the-art defenses that we consider, are jointly used to detect exfiltration; if any of today's baseline exfiltration techniques try to achieve the same rate as Dolos in this setting, they are almost surely detected. If we reduce the rates of the baselines to achieve even a low albeit slightly higher detection probability than Dolos (0.15), we see that they take 25 x longer to achieve the exfiltration. With the other three defenses, we find that baselines are almost surely detected while Dolos remains relatively unaffected regardless of the rate of exfiltration.
Abdulrahman Fahim, Shitong Zhu, Zhiyun Qian, Chengyu Song, Evangelos E. Papalexakis, Supriyo Chakraborty, Kevin S. Chan, Paul L. Yu, Trent Jaeger, Srikanth V. Krishnamurthy
EuroS&P10
2024 Lightweight Coordinated Sampling for Dynamic Flows under Budget Constraints
abstract
As cyber-attacks on networks become more stealthy, monitoring techniques relying on low-rate packet sampling may prove insufficient to detect attacks. While various sampling methods have been proposed to address capacity limitations and enhance detection rates, achieving sampling at line speed at a single point remains challenging due to limited CPU or bandwidth capacity at sampling points. In this paper, we propose harnessing coordinating sampling across switches to create a unified system that can dynamically activate sampling points to meet sampling rate needs. We introduce and implement a coordinated sampling algorithm on multiple P4-programmable switches and show that the algorithm ensures coordination among multiple sampling points for each flow, preventing duplicate samples, with negligible network overhead and real-time configurability. We formulate sampling point placement as budgeted maximum multi-coverage problems, solving them optimally in pseudo-polynomial time. We show our system far outperforms those based on greedy algorithms along many key dimensions.
Mingming Chen 0001, Thomas La Porta, Trent Jaeger, Srikanth V. Krishnamurthy
ICCCN4
2024 M2HO: Mitigating the Adverse Effects of 5G Handovers on TCP
abstract
The advent of 5G promises high bandwidth with the introduction of mmWave technology recently, paving the way for throughput-sensitive applications. However, our measurements in commercial 5G networks show that frequent handovers in 5G, due to physical limitations of mmWave cells, introduce significant under-utilization of the available bandwidth. By analyzing 5G link-layer and TCP traces, we uncover that improper interactions between these two layers causes multiple inefficiencies during handovers. To mitigate these, we propose M2HO, a novel device-centric solution that can predict and recognize different stages of a handover and perform state-dependent mitigation to markedly improve throughput. M2HO is transparent to the firmware, base stations, servers, and applications. We implement M2HO and our extensive evaluations validate that it yields significant improvements in TCP throughput with frequent handovers.
Zhutian Liu 0002, Qing Deng, Zhaowei Tan, Zhiyun Qian, Xinyu Zhang 0003, Ananthram Swami, Srikanth V. Krishnamurthy
MobiCom7
2024 Don't Waste My Efforts: Pruning Redundant Sanitizer Checks by Developer-Implemented Type Checks
Yizhuo Zhai, Zhiyun Qian, Chengyu Song, Manu Sridharan, Trent Jaeger, Paul L. Yu, Srikanth V. Krishnamurthy
USENIX Security Symposium7
2024 Priza: Throughput-Efficient DAS Clustering of WiFi-PLC Extenders in Enterprises
abstract
WiFi-enabled Power Line Communications (PLC) range extenders can extend coverage in homes and enterprises. However, a dense deployment of a large number of PLC extenders in enterprise settings can cause an inefficient sharing of the PLC capacity, where many extenders contend for a share of access to the backhaul network comprising of the electrical wiring (power lines), thereby drastically impacting any gains from using these extenders on the wireless part of the network. In this paper, we address this issue by developing a framework, Priza, for clustering the WiFi-PLC extenders to intelligently form a DAS (distributed antenna system) to mitigate the inefficiency of sharing the PLC backhaul. By appropriately managing clustering and reuse, Priza improves the PLC backhaul sharing, while at the same time, harnessing the power pooling and diversity gains from DAS on the wireless part of the network, to boost user throughputs. We evaluate Priza via real testbed experiments and high-fidelity simulations and demonstrate that it can increase the aggregate throughput by up to 131.5% over the non-DAS reuse baseline, 74% over the best DAS baseline that constructs equally-sized DAS cells based on extender proximity, and 331.3% over a greedy DAS baseline that creates as large DAS cells as possible.
Hisham Alhulayyil, Jiasi Chen, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy
IEEE Trans. Wirel. Commun.4
2023 Leveraging Local Patch Differences in Multi-Object Scenes for Generative Adversarial Attacks
abstract
State-of-the-art generative model-based attacks against image classifiers overwhelmingly focus on single-object(i.e., single dominant object) images. Different from such settings, we tackle a more practical problem of generating adversarial perturbations using multi-object (i.e., multiple dominant objects) images as they are representative of most real-world scenes. Our goal is to design an attack strategy that can learn from such natural scenes by leveraging the local patch differences that occur inherently in such images (e.g. difference between the local patch on the object ‘person’ and the object ‘bike’ in a traffic scene). Our key idea is to misclassify an adversarial multi-object image by confusing the victim classifier for each local patch in the image. Based on this, we propose a novel generative attack (called Local Patch Difference or LPD-Attack) where a novel contrastive loss function uses the aforesaid local differences in feature space of multi-object scenes to optimize the perturbation generator. Through various experiments across diverse victim convolutional neural networks, we show that our approach outperforms baseline generative attacks with highly transferable perturbations when evaluated under different white-box and black-box settings.
Abhishek Aich, Shasha Li 0002, Chengyu Song, Muhammad Salman Asif, Srikanth V. Krishnamurthy, Amit K. Roy-Chowdhury
WACV5
2023 AcTrak: Controlling a Steerable Surveillance Camera using Reinforcement Learning
abstract
Steerable cameras that can be controlled via a network, to retrieve telemetries of interest have become popular. In this paper, we develop a framework called AcTrak , to automate a camera’s motion to appropriately switch between (a) zoom ins on existing targets in a scene to track their activities, and (b) zoom out to search for new targets arriving to the area of interest. Specifically, we seek to achieve a good trade-off between the two tasks, i.e., we want to ensure that new targets are observed by the camera before they leave the scene, while also zooming in on existing targets frequently enough to monitor their activities. There exist prior control algorithms for steering cameras to optimize certain objectives; however, to the best of our knowledge, none have considered this problem, and do not perform well when target activity tracking is required. AcTrak automatically controls the camera’s PTZ configurations using reinforcement learning (RL ), to select the best camera position given the current state. Via simulations using real datasets, we show that AcTrak detects newly arriving targets 30% faster than a non-adaptive baseline and rarely misses targets, unlike the baseline which can miss up to 5% of the targets. We also implement AcTrak to control a real camera and demonstrate that in comparison with the baseline, it acquires about 2× more high resolution images of targets.
Abdulrahman Fahim, Evangelos E. Papalexakis, Srikanth V. Krishnamurthy, Amit K. Roy-Chowdhury, Lance M. Kaplan, Tarek F. Abdelzaher
ACM Trans. Cyber Phys. Syst.3
2022 Context-Aware Transfer Attacks for Object Detection
abstract
Blackbox transfer attacks for image classifiers have been extensively studied in recent years. In contrast, little progress has been made on transfer attacks for object detectors. Object detectors take a holistic view of the image and the detection of one object (or lack thereof) often depends on other objects in the scene. This makes such detectors inherently context-aware and adversarial attacks in this space are more challenging than those targeting image classifiers. In this paper, we present a new approach to generate context-aware attacks for object detectors. We show that by using co-occurrence of objects and their relative locations and sizes as context information, we can successfully generate targeted mis-categorization attacks that achieve higher transfer success rates on blackbox object detectors than the state-of-the-art. We test our approach on a variety of object detectors with images from PASCAL VOC and MS COCO datasets and demonstrate up to 20 percentage points improvement in performance compared to the other state-of-the-art methods.
Zikui Cai, Xinxin Xie, Shasha Li 0001, Mingjun Yin, Chengyu Song, Srikanth V. Krishnamurthy, Amit K. Roy-Chowdhury, Muhammad Salman Asif
AAAI6
2022 Zero-Query Transfer Attacks on Context-Aware Object Detectors
abstract
Adversarial attacks perturb images such that a deep neural network produces incorrect classification results. A promising approach to defend against adversarial attacks on natural multi-object scenes is to impose a context-consistency check, wherein, if the detected objects are not consistent with an appropriately defined context, then an attack is suspected. Stronger attacks are needed to fool such context-aware detectors. We present the first approach for generating context-consistent adversarial attacks that can evade the context-consistency check of black-box object detectors operating on complex, natural scenes. Unlike many black-box attacks that perform repeated attempts and open themselves to detection, we assume a “zero-query” setting, where the attacker has no knowledge of the classification decisions of the victim system. First, we derive multiple attack plans that assign incorrect labels to victim objects in a context-consistent manner. Then we design and use a novel data structure that we call the perturbation success probability matrix, which enables us to filter the attack plans and choose the one most likely to succeed. This final attack plan is implemented using a perturbation-bounded adversarial attack algorithm. We compare our zero-query attack against a few-query scheme that repeatedly checks if the victim system is fooled. We also compare against state-of-the-art context-agnostic attacks. Against a context-aware defense, the fooling rate of our zero-query approach is significantly higher than context-agnostic approaches and higher than that achievable with up to three rounds of the fewquery scheme.
Zikui Cai, Shantanu Rane, Alejandro E. Brito, Chengyu Song, Srikanth V. Krishnamurthy, Amit K. Roy-Chowdhury, Muhammad Salman Asif
CVPR5
2022 Progressive Scrutiny: Incremental Detection of UBI bugs in the Linux Kernel
Yizhuo Zhai, Yu Hao 0006, Zheng Zhang 0058, Weiteng Chen, Guoren Li, Zhiyun Qian, Chengyu Song, Manu Sridharan, Srikanth V. Krishnamurthy, Trent Jaeger, Paul L. Yu
NDSS9
2022 GAMA: Generative Adversarial Multi-Object Scene Attacks
abstract
The majority of methods for crafting adversarial attacks have focused on scenes with a single dominant object (e.g., images from ImageNet). On the other hand, natural scenes include multiple dominant objects that are semantically related. Thus, it is crucial to explore designing attack strategies that look beyond learning on single-object scenes or attack single-object victim classifiers. Due to their inherent property of strong transferability of perturbations to unknown models, this paper presents the first approach of using generative models for adversarial attacks on multi-object scenes. In order to represent the relationships between different objects in the input scene, we leverage upon the open-sourced pre-trained vision-language model CLIP (Contrastive Language-Image Pre-training), with the motivation to exploit the encoded semantics in the language space along with the visual space. We call this attack approach Generative Adversarial Multi-object Attacks (GAMA). GAMA demonstrates the utility of the CLIP model as an attacker's tool to train formidable perturbation generators for multi-object scenes. Using the joint image-text features to train the generator, we show that GAMA can craft potent transferable perturbations in order to fool victim classifiers in various attack settings. For example, GAMA triggers ~16% more misclassification than state-of-the-art generative approaches in black-box settings where both the classifier architecture and data distribution of the attacker are different from the victim. Our code is available here: https://abhishekaich27.github.io/gama.html
Abhishek Aich, Calvin-Khang Ta, Akash Gupta 0001, Chengyu Song, Srikanth V. Krishnamurthy, Muhammad Salman Asif, Amit K. Roy-Chowdhury
NeurIPS5
2022 Blackbox Attacks via Surrogate Ensemble Search
abstract
Blackbox adversarial attacks can be categorized into transfer- and query-based attacks. Transfer methods do not require any feedback from the victim model, but provide lower success rates compared to query-based methods. Query attacks often require a large number of queries for success. To achieve the best of both approaches, recent efforts have tried to combine them, but still require hundreds of queries to achieve high success rates (especially for targeted attacks). In this paper, we propose a novel method for Blackbox Attacks via Surrogate Ensemble Search (BASES) that can generate highly successful blackbox attacks using an extremely small number of queries. We first define a perturbation machine that generates a perturbed image by minimizing a weighted loss function over a fixed set of surrogate models. To generate an attack for a given victim model, we search over the weights in the loss function using queries generated by the perturbation machine. Since the dimension of the search space is small (same as the number of surrogate models), the search requires a small number of queries. We demonstrate that our proposed method achieves better success rate with at least $30\times$ fewer queries compared to state-of-the-art methods on different image classifiers trained with ImageNet (including VGG-19, DenseNet-121, and ResNext-50). In particular, our method requires as few as 3 queries per image (on average) to achieve more than a $90\%$ success rate for targeted attacks and 1--2 queries per image for over a $99\%$ success rate for untargeted attacks. Our method is also effective on Google Cloud Vision API and achieved a $91\%$ untargeted attack success rate with 2.9 queries per image. We also show that the perturbations generated by our proposed method are highly transferable and can be adopted for hard-label blackbox attacks. Furthermore, we argue that BASES can be used to create attacks for a variety of tasks and show its effectiveness for attacks on object detection models. Our code is available at https://github.com/CSIPlab/BASES.
Zikui Cai, Chengyu Song, Srikanth V. Krishnamurthy, Amit K. Roy-Chowdhury, Salman Asif
NeurIPS3
2022 Breaking Edge Shackles: Infrastructure-Free Collaborative Mobile Augmented Reality
abstract
Collaborative AR applications are gaining popularity, but have heavy computing requirements for identifying and tracking AR devices and objects in the ecosystem. Prior AR frameworks typically rely on edge infrastructure to offload AR's compute-heavy tasks. However, such infrastructure may not always be available, and continuously running AR computations on user devices can rapidly drain battery and impact application longevity. In this work, we enable infrastructure-free mobile AR with a low energy footprint, by using collaborative time slicing to distribute compute-heavy AR tasks across user devices. Realizing this idea is challenging because distributed execution can result in inconsistent synchronization of the AR virtual overlays. Our framework, FreeAR, tackles this with novel lightweight techniques for tightly synchronized virtual overlay placements across user views, and low latency recovery upon disruptions. We prototype FreeAR on Android and show that it can improve the virtual overlay positioning accuracy (with respect to the IOU metric) by up to 78%, relative to state-of-the-art collaborative AR systems, while also reducing power by up to 60% relative to a direct application of those prior solutions.
Kittipat Apicharttrisorn, Jiasi Chen, Vyas Sekar, Anthony Rowe 0001, Srikanth V. Krishnamurthy
SenSys5
2022 ADC: Adversarial attacks against object Detection that evade Context consistency checks
abstract
Deep Neural Networks (DNNs) have been shown to be vulnerable to adversarial examples, which are slightly perturbed input images which lead DNNs to make wrong predictions. To protect from such examples, various defense strategies have been proposed. A very recent defense strategy for detecting adversarial examples, that has been shown to be robust to current attacks, is to check for intrinsic context consistencies in the input data, where context refers to various relationships (e.g., object-to-object co-occurrence relationships) in images. In this paper, we show that even context consistency checks can be brittle to properly crafted adversarial examples and to the best of our knowledge, we are the first to do so. Specifically, we propose an adaptive framework to generate examples that subvert such defenses, namely, Adversarial attacks against object Detection that evade Context consistency checks (ADC). In ADC, we formulate a joint optimization problem which has two attack goals, viz., (i) fooling the object detector and (ii) evading the context consistency check system, at the same time. Experiments on both PASCAL VOC and MS COCO datasets show that examples generated with ADC fool the object detector with a success rate of over 85% in most cases, and at the same time evade the recently proposed context consistency checks, with a "bypassing" rate of over 80% in most cases. Our results suggest that "how to robustly model con- text and check its consistency," is still an open problem.
Mingjun Yin, Shasha Li 0001, Chengyu Song, Muhammad Salman Asif, Amit K. Roy-Chowdhury, Srikanth V. Krishnamurthy
WACV6
2022 BigEye: Detection and Summarization of Key Global Events From Distributed Crowdsensed Data
abstract
Social media postings using smartphones (referred to as crowd-sensed data) can often facilitate real-time detection of key physical events in applications like disaster recovery or in smart cities. These postings also often contain visual content (e.g., images) that can be used to obtain zoomed-in views of such events. These crowd-sensed data are likely to be of large volume and distributed across a plurality of producers (e.g., cloudlets). Blindly transferring this large volume of raw data from the producers to a consumer will induce information overload and consume very high bandwidth. The problem is exacerbated in scenarios with limited bandwidth (e.g., after a disaster). In this article, we designBigEye, a novel framework that only transfers very limited data from the distributed producers to a central summarizer, and yet supports: 1) highly accurate detection and 2) concise visual summarization of key events of global interest. In realizingBigEye, we address several challenges including: 1) identifying events that have the highest global interest via the transfer of appropriate limited metadata from the producers to the summarizer; 2) reconciling metadata that could be inconsistent across the producers; and 3) the timely retrieval of visual summaries of the key events given bandwidth constraints. We show thatBigEyeachieves the same accuracy in detecting key events, as a system, where all data are available centrally while transferring only 1% of the raw data volume. Compared to the baseline approaches,BigEye’s parallelized transfer of visual content reduces the average delay by 67%.
Abdulrahman Fahim, Ajaya Neupane, Evangelos E. Papalexakis, Lance M. Kaplan, Srikanth V. Krishnamurthy, Tarek F. Abdelzaher
IEEE Internet Things J.5
2021 Eluding ML-based Adblockers With Actionable Adversarial Examples
abstract
Online advertisers have been quite successful in circumventing traditional adblockers that rely on manually curated rules to detect ads. As a result, adblockers have started to use machine learning (ML) classifiers for more robust detection and blocking of ads. Among these, AdGraph which leverages rich contextual information to classify ads, is arguably, the state of the art ML-based adblocker. In this paper, we present a4, a tool that intelligently crafts adversarial ads to evade AdGraph. Unlike traditional adversarial examples in the computer vision domain that can perturb any pixels (i.e., unconstrained), adversarial ads generated by a4 are actionable in the sense that they preserve the application semantics of the web page. Through a series of experiments we show that a4 can bypass AdGraph about 81% of the time, which surpasses the state-of-the-art attack by a significant margin of 145.5%, with an overhead of <20% and perturbations that are visually imperceptible in the rendered webpage. We envision that a4’s framework can be used to potentially launch adversarial attacks against other ML-based web applications.
Shitong Zhu, Zhongjie Wang 0002, Shasha Li 0001, Keyu Man, Umar Iqbal 0002, Zhiyun Qian, Kevin S. Chan, Srikanth V. Krishnamurthy, Zubair Shafiq, Yu Hao 0006, Guoren Li, Zheng Zhang 0058, Xiaochen Zou
ACSAC9
2021 Themis: Ambiguity-Aware Network Intrusion Detection based on Symbolic Model Comparison
abstract
Network intrusion detection systems (NIDS) can be evaded by carefully crafted packets that exploit implementation-level discrepancies between how they are processed on the NIDS and at the endhosts. These discrepancies arise due to the plethora of endhost implementations and evolutions thereof. It is prohibitive to proactively employ a large set of implementations at the NIDS and check incoming packets against all of those. Hence, NIDS typically choose simplified implementations that attempt to approximate and generalize across the different endhost implementations. Unfortunately, this solution is fundamentally flawed since such approximations are bound to have discrepancies with some endhost implementations. In this paper, we develop a lightweight system Themis, which empowers the NIDS in identifying these discrepancies and reactively forking its connection states when any packets with "ambiguities" are encountered. Specifically, Themis incorporates an offline phase in which it extracts models from various popular implementations using symbolic execution. During runtime, it maintains a nondeterministic finite automaton to keep track of the states for each possible implementation. Our extensive evaluations show that Themis is extremely effective and can detect all evasion attacks known to date, while consuming extremely low overhead. En route, we also discovered multiple previously unknown discrepancies that can be exploited to bypass current NIDS.
Zhongjie Wang 0002, Shitong Zhu, Keyu Man, Pengxiong Zhu, Yu Hao 0006, Zhiyun Qian, Srikanth V. Krishnamurthy, Thomas La Porta, Michael J. De Lucia
CCS7
2021 Exploiting Multi-Object Relationships for Detecting Adversarial Attacks in Complex Scenes
abstract
Vision systems that deploy Deep Neural Networks (DNNs) are known to be vulnerable to adversarial examples. Recent research has shown that checking the intrinsic consistencies in the input data is a promising way to detect adversarial attacks (e.g., by checking the object co-occurrence relationships in complex scenes). However, existing approaches are tied to specific models and do not offer generalizability. Motivated by the observation that language descriptions of natural scene images have already captured the object co-occurrence relationships that can be learned by a language model, we develop a novel approach to perform context consistency checks using such language models. The distinguishing aspect of our approach is that it is independent of the deployed object detector and yet offers very high accuracy in terms of detecting adversarial examples in practical scenes with multiple objects. Experiments on the PASCAL VOC and MS COCO datasets show that our method can outperform state-of-the-art methods in detecting adversarial attacks.
Mingjun Yin, Shasha Li 0001, Zikui Cai, Chengyu Song, Muhammad Salman Asif, Amit K. Roy-Chowdhury, Srikanth V. Krishnamurthy
ICCV7
2021 Boosting Home WiFi Throughputs via Adaptive DAS Clustering of PLC Extenders
abstract
WiFi-capable PLC (Poiver Line Communications) plug-and-play extenders are becoming popular to improve WiFi range and coverage in homes and enterprises. As shown in prior work, unlike an Ethernet backhaul, the PLC backhaul may not support high data rates. In addition, clients (users) that are either far or partially occluded from the WiFi-PLC extender they associate with can experience fading and shadowing, which degrades the throughput on the wireless link. Thus, both the PLC and WiFi backhauls will influence a user’s end-to-end throughput. In this paper, we seek to exploit the presence of multiple PLC extenders that may be plugged in, by combining their transmissions in a distributed antenna system (DAS), to boost client throughputs in a home setting. Specifically, we design PLC-DAS to determine which PLC extenders are the best candidates for forming a joint DAS transmitter cluster to each client. PLC-DAS is designed based on a real measurement study and not only accounts for the WiFi link qualities from the extenders to the users, but also the PLC link qualities from each extender to a master router which is typically deployed in homes. PLC-DAS is flexible and can maximize the throughput under different fairness objectives. We evaluate PLC-DAS via extensive simulations and show that it can increase the aggregate throughput by up to 4.5x compared to blindly using all WiFi PLC extenders to form a DAS transmitter, while maintaining a fairness Jain’s index value of at least 0.97 with proportional and max-min fairness models.
Hisham Alhulayyil, Jiasi Chen, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy
MASS4
2021 Adversarial Attacks on Black Box Video Classifiers: Leveraging the Power of Geometric Transformations
abstract
When compared to the image classification models, black-box adversarial attacks against video classification models have been largely understudied. This could be possible because, with video, the temporal dimension poses significant additional challenges in gradient estimation. Query-efficient black-box attacks rely on effectively estimated gradients towards maximizing the probability of misclassifying the target video. In this work, we demonstrate that such effective gradients can be searched for by parameterizing the temporal structure of the search space with geometric transformations. Specifically, we design a novel iterative algorithm GEOmetric TRAnsformed Perturbations (GEO-TRAP), for attacking video classification models. GEO-TRAP employs standard geometric transformation operations to reduce the search space for effective gradients into searching for a small group of parameters that define these operations. This group of parameters describes the geometric progression of gradients, resulting in a reduced and structured search space. Our algorithm inherently leads to successful perturbations with surprisingly few queries. For example, adversarial examples generated from GEO-TRAP have better attack success rates with ~73.55% fewer queries compared to the state-of-the-art method for video adversarial attacks on the widely used Jester dataset. Overall, our algorithm exposes vulnerabilities of diverse video classification models and achieves new state-of-the-art results under black-box settings on two large datasets.
Shasha Li 0001, Abhishek Aich, Shitong Zhu, Muhammad Salman Asif, Chengyu Song, Amit K. Roy-Chowdhury, Srikanth V. Krishnamurthy
NeurIPS7
2021 SyzVegas: Beating Kernel Fuzzing Odds with Reinforcement Learning
Daimeng Wang, Zheng Zhang 0058, Hang Zhang 0012, Zhiyun Qian, Srikanth V. Krishnamurthy, Nael B. Abu-Ghazaleh
USENIX Security Symposium5
2021 MLSNet: A Policy Complying Multilevel Security Framework for Software Defined Networking
abstract
Ensuring that information flowing through a network is secure from manipulation and eavesdropping by unauthorized parties is an important task for network administrators. Many cyber attacks rely on a lack of network-level information flow controls to successfully compromise a victim network. Once an adversary exploits an initial entry point, they can eavesdrop and move laterally within the network (e.g., scan and penetrate internal nodes) to further their malicious goals. In this article, we propose a novel multilevel security (MLS) framework to enforce a secure inter-node information flow policy within the network and therein vastly reduce the attack surface available to an adversary who has penetrated it. In contrast to prior work on multilevel security in computer networks which relied on enforcing the policy at network endpoints, we leverage the centralization of software-defined networks (SDNs) by moving the task to the controller and providing this service transparently to all network nodes. Our framework, MLSNet, formalizes the generation of a policy compliant network configuration (i.e., set of flow rules on the SDN switches) as network optimization problems, with the objectives of (1) maximizing the number of flows satisfying all security constraints and (2) minimizing the security cost of routing any remaining flows to guarantee availability. We demonstrate that MLSNet can securely and efficiently route flows that satisfy the security constraints and route the remaining flows with a minimal security cost (e.g., route >85% of flows, where the heuristic achieves 89% and 87% of the optimal solutions for the optimization problems).
Stefan Achleitner, Quinn Burke 0002, Patrick D. McDaniel, Trent Jaeger, Thomas La Porta, Srikanth V. Krishnamurthy
IEEE Trans. Netw. Serv. Manag.6
2020 You do (not) belong here: detecting DPI evasion attacks with context learning
abstract
As Deep Packet Inspection (DPI) middleboxes become increasingly popular, a spectrum of adversarial attacks have emerged with the goal of evading such middleboxes. Many of these attacks exploit discrepancies between the middlebox network protocol implementations, and the more rigorous/complete versions implemented at end hosts. These evasion attacks largely involve subtle manipulations of packets to cause different behaviours at DPI and end hosts, to cloak malicious network traffic that is otherwise detectable. With recent automated discovery, it has become prohibitively challenging to manually curate rules for detecting these manipulations. In this work, we propose CLAP, the first fully-automated, unsupervised ML solution to accurately detect and localize DPI evasion attacks. By learning what we call the packet context, which essentially captures inter-relationships across both (1) different packets in a connection; and (2) different header fields within each packet, from benign traffic traces only, CLAP can detect and pinpoint packets that violate the benign packet contexts (which are the ones that are specially crafted for evasion purposes). Our evaluations with 73 state-of-the-art DPI evasion attacks show that CLAP achieves an Area Under the Receiver Operating Characteristic Curve (AUCROC) of 0.963, an Equal Error Rate (EER) of only 0.061 in detection, and an accuracy of 94.6% in localization. These results suggest that CLAP can be a promising tool for thwarting DPI evasion attacks.
Shitong Zhu, Shasha Li 0001, Zhongjie Wang 0002, Zhiyun Qian, Srikanth V. Krishnamurthy, Kevin S. Chan, Ananthram Swami
CoNEXT6
2020 Connecting the Dots: Detecting Adversarial Perturbations Using Context Inconsistency
Shasha Li 0001, Shitong Zhu, Sudipta Paul 0007, Amit K. Roy-Chowdhury, Chengyu Song, Srikanth V. Krishnamurthy, Ananthram Swami, Kevin S. Chan
ECCV (23)6
2020 WOLT: Auto-Configuration of Integrated Enterprise PLC-WiFi Networks
abstract
Power Line Communication (PLC) based WiFi extenders can improve WiFi coverage in homes and enterprises. Unlike in traditional WiFi networks which use an underlying high data rate Ethernet backhaul, a PLC backhaul may not support high data rates. Specifically, our measurements show that arbitrarily affiliating users to PLC-WiFi extenders or based on their WiFi channel qualities alone may lead to poor network performance due to the differences in PLC link capacities. Thus, in this paper we build a framework, WOLT, to solve the problem of assigning users to the appropriate PLC-WiFi extenders to increase the aggregate network throughput in an enterprise setting, where one may expect a relatively large number of power outlets. WOLT accounts for both the qualities of the two concatenated links viz., the PLC and WiFi links. It hinges on estimating the best capacity offered by the PLC links, and accounting for these while assigning users. It incorporates a polynomial-time algorithm that assigns only a subset of the users to maximize the aggregate throughput on the PLC links, and then assigns the remaining users such that the degradation in the aggregate throughput is minimized. WOLT is evaluated through simulations and real testbed experiments with commodity PLCWiFi extenders, and improves aggregate throughput by more than 2.5× compared to a greedy user association baseline.
Hisham Alhulayyil, Kittipat Apicharttrisorn, Jiasi Chen, Karthikeyan Sundaresan, Samet Oymak, Srikanth V. Krishnamurthy
ICDCS6
2020 DeepTrack: Grouping RFID Tags Based on Spatio-temporal Proximity in Retail Spaces
abstract
RFID applications for taking inventory and processing transactions in point-of-sale (POS) systems improve operational efficiency but are not designed to provide insights about customers' interactions with products. We bridge this gap by solving the proximity grouping problem to identify groups of RFID tags that stay in close proximity to each other over time. We design DeepTrack, a framework that uses deep learning to automatically track the group of items carried by a customer during her shopping journey. This unearths hidden purchase behaviors helping retailers make better business decisions and paves the way for innovative shopping experiences such as seamless checkout (`a la Amazon Go). DeepTrack employs a recurrent neural network (RNN) with the attention mechanism, to solve the proximity grouping problem in noisy settings without explicitly localizing tags. We tailor DeepTrack's design to track not only mobile groups (products carried by customers) but also flexibly identify stationary tag groups (products on shelves). The key attribute of DeepTrack is that it only uses readily available tag data from commercial off-the-shelf RFID equipment. Our experiments demonstrate that, with only two hours training data, DeepTrack achieves a grouping accuracy of 98.18% (99.79%) when tracking eight mobile (stationary) groups.
Shasha Li 0001, Mustafa Y. Arslan, Mohammad Ali Amir Khojastepour, Srikanth V. Krishnamurthy, Sampath Rangarajan
INFOCOM4
2020 SymTCP: Eluding Stateful Deep Packet Inspection with Automated Discrepancy Discovery
Zhongjie Wang 0002, Shitong Zhu, Yue Cao 0003, Zhiyun Qian, Chengyu Song, Srikanth V. Krishnamurthy, Kevin S. Chan, Tracy D. Braun
NDSS6
2020 Characterization of Multi-User Augmented Reality over Cellular Networks
abstract
Augmented reality (AR) apps where multiple users interact within the same physical space are gaining in popularity (e.g., shared AR mode in Pokemon Go, virtual graffiti in Google's Just a Line). However, multi-user AR apps running over the cellular network can experience very high end-to-end latencies (measured at 12.5 s median on a public LTE network). To characterize and understand the root causes of this problem, we perform a first-of-its-kind measurement study on both public LTE and industry LTE testbed for two popular multi-user AR applications, yielding several insights: (1) The radio access network (RAN) accounts for a significant fraction of the end-to-end latency (31.2%, or 3.9 s median), resulting in AR users experiencing high, variable delays when interacting with a common set of virtual objects in off-the-shelf AR apps; (2) AR network traffic is characterized by large intermittent spikes on a single uplink TCP connection, resulting in frequent TCP slow starts that can increase user-perceived latency; (3) Applying a common traffic management mechanism of cellular operators, QoS Class Identifiers (QCI), can help by reducing AR latency by 33% but impacts non-AR users. Based on these insights, we propose network-aware and network-agnostic AR design optimization solutions to intelligently adapt IP packet sizes and periodically provide information on uplink data availability, respectively. Our solutions help ramp up network performance, improving the end-to-end AR latency and goodput by ~40-70%.
Kittipat Apicharttrisorn, Bharath Balasubramanian, Jiasi Chen, Rajarajan Sivaraj, Yi-Zhen Tsai, Rittwik Jana, Srikanth V. Krishnamurthy, Tuyen X. Tran
SECON7
2020 UBITect: a precise and scalable method to detect use-before-initialization bugs in Linux kernel
abstract
Use-before-Initialization (UBI) bugs in the Linux kernel have serious security impacts, such as information leakage and privilege escalation. Developers are adopting forced initialization to cope with UBI bugs, but this approach can still lead to undefined behaviors (e.g., NULL pointer dereference). As it is hard to infer correct initialization values, we believe that the best way to mitigate UBI bugs is detection and manual patching. Precise detection of UBI bugs requires path-sensitive analysis. The detector needs to track an associated variable’s initialization status along all the possible program execution paths to its uses. However, such exhaustive analysis prevents the detection from scaling to the whole Linux kernel. This paper presents UBITect, a UBI bug finding tool which combines flow-sensitive type qualifier analysis and symbolic execution to perform precise and scalable UBI bug detection. The scalable qualifier analysis guides symbolic execution to analyze variables that are likely to cause UBI bugs. UBITect also does not require manual effort for annotations and hence, it can be directly applied to the kernel without any source code or intermediate representation (IR) change. On the Linux kernel version 4.14, UBITect reported 190 bugs, among which 78 bugs were deemed by us as true positives and 52 were confirmed by Linux maintainers.
Yizhuo Zhai, Yu Hao 0006, Hang Zhang 0012, Daimeng Wang, Chengyu Song, Zhiyun Qian, Mohsen Lesani, Srikanth V. Krishnamurthy, Paul L. Yu
ESEC/SIGSOFT FSE8
2020 Packet Header Obfuscation Using MIMO
abstract
Eavesdroppers can exploit exposed packet headers towards attacks that profile clients and their data flows. In this paper, we propose FOG, a framework for effective full and partial header blinding using MIMO, to thwart eavesdroppers. FOG effectively tracks header bits as they traverse physical (PHY) layer sub-systems that perform functions like scrambling and interleaving. It combines multiple blinding signals for more effective and less predictable obfuscation, as compared to using a fixed blinding signal. We implement FOG on the WARP platform and demonstrate via extensive experiments that it yields better obfuscation than prior schemes that deploy full packet blinding. It causes a bit error rate (BER) of > 40 % at an eavesdropper if two blinding streams are sent during header transmissions. Furthermore, even with full header blinding, FOG incurs a very small throughput hit of ≈5% with one blinding stream (and 9 % with two streams). Full packet blinding incurs much higher throughput hits (25 % with one stream and 50 % with two streams).
Yue Cao 0003, Ahmed Atya, Shailendra Singh 0004, Zhiyun Qian, Srikanth V. Krishnamurthy, Thomas La Porta, Prashant Krishnamurthy, Lisa M. Marvel
IEEE/ACM Trans. Netw.5
2019 Principled Unearthing of TCP Side Channel Vulnerabilities
abstract
Recent work has showcased the presence of subtle TCP side channels in modern operating systems, that can be exploited by off-path adversaries to launch pernicious attacks such as hijacking a connection. Unfortunately, most work to date is on the manual discovery of such side-channels, and patching them subsequently. In this work we ask "Can we develop a principled approach that can lead to the automated discovery of such hard-to-find TCP side-channels?" We identify that the crux of why such side-channels exist is the violation of the non-interference property between simultaneous TCP connections i.e., there exist cases wherein a change in state of one connection implicitly leaks some information to a different connection (controlled possibly by an attacker). To find such non-interference property violations, we argue that model-checking is a natural fit. However, because of limitations with regards to its scalability, there exist many challenges in using model checking. Specifically, these challenges relate to (a) making the TCP code base self-contained and amenable to model checking and (b) limiting the search space of model checking and yet achieving reasonable levels of code coverage. We develop a tool that we call SCENT (for Side Channel Excavation Tool) that addresses these challenges in a mostly automated way. At the heart of SCENT is an automated downscaling component that transforms the TCP code base in a consistent way to achieve both a reduction in the state space complexity encountered by the model checker and the number and types of inputs needed for verification. Our extensive evaluations show that SCENT leads to the discovery of 12 new side channel vulnerabilities in the Linux and FreeBSD kernels. In particular, a real world validation with one class of vulnerabilities shows that an off-path attacker is able to infer whether two arbitrary hosts are communicating with each other, within slightly more than 1 minute, on average.
Yue Cao 0003, Zhongjie Wang 0002, Zhiyun Qian, Chengyu Song, Srikanth V. Krishnamurthy, Paul L. Yu
CCS5
2019 PAPP: Prefetcher-Aware Prime and Probe Side-channel Attack
abstract
CPU memory prefetchers can substantially interfere with prime and probe cache side-channel attacks, especially on in-order CPUs which use aggressive prefetching. This interference is not accounted for in previous attacks. In this paper, we propose PAPP, a Prefetcher-Aware Prime Probe attack that can operate even in the presence of aggressive prefetchers. Specifically, we reverse engineer the prefetcher and replacement policy on several CPUs and use these insights to design a prime and probe attack that minimizes the impact of the prefetcher. We evaluate PAPP using Cache Side-channel Vulnerability (CSV) metric and demonstrate the substantial improvements in the quality of the channel under different conditions.
Daimeng Wang, Zhiyun Qian, Nael B. Abu-Ghazaleh, Srikanth V. Krishnamurthy
DAC4
2019 Edge-Assisted Detection and Summarization of Key Global Events from Distributed Crowd-Sensed Data
abstract
This paper introduces a novel service for distributed detection and summarization of crowd-sensed events. The work is motivated by the proliferation of microblogging media, such as Twitter, that can be used to detect and describe events in the physical world, such as protests, disasters, or civil unrest. Since crowd-sensed data is likely to be distributed, we consider an architecture, where the data first accumulates across a plurality of edge servers (e.g. cloudlets or repositories) and is then summarized, rather than being shipped directly to its ultimate destination (e.g., in a remote cloud). The architecture allows graceful handling of overload and bandwidth limitations (e.g., in scenarios where capacity is impaired, as the case might be after a disaster). When bandwidth is scarce, our service, BigEye, only transfers very limited metadata from the distributed edge repositories to the central summarizer and yet supports highly accurate detection and concise summarization of key events of global interest. These summaries can then be sent to consumers (e.g., rescue personnel). Our emulations show that BigEye achieves the same precision and recall values in detecting key events as a system where all data is available centrally, while consuming only 1% of the bandwidth needed to transmit all raw data.
Abdelrahman Fahim, Ajaya Neupane, Evangelos E. Papalexakis, Lance M. Kaplan, Srikanth V. Krishnamurthy, Tarek F. Abdelzaher
IC2E5
2019 Figment: Fine-grained Permission Management for Mobile Apps
abstract
Today's Android systems do not allow users to manage the permissions granted to applications (apps) in a flexible and dynamic way. Recent studies show that apps often misuse these permissions to access private information, or have trapdoors via which other malicious apps can do the same. In this paper, we develop a framework Figment, which consists of set of libraries that developers can easily use to build in fine-grained dynamic permission management capabilities. The users of their apps can readily invoke these capabilities during execution. The apps would potentially run with reduced functionalities if the user does not wish to allow certain permissions. Figment also allows either the developer or a user to specify context aware permissions, which cause different permissions to be granted to the app in different functional modes (contexts). We believe that Figment reduces the attack surface exposed to potentially malicious apps and offers a significant step in preserving user privacy. While the rudimentary version of Figment uses aspect-oriented programming and does not need rooting of the phone or changes to the Android sub-system, we also provide an optional root-level fail safe implementation that facilitates the embedding of dynamic permission management functions in old applications not built by using Figment libraries. We show that Figment offers significant benefits over the Android Marshmallow permission management system with lower runtime overheads; the main penalty is a one time higher compilation overhead.
Ioannis Gasparis, Zhiyun Qian, Chengyu Song, Srikanth V. Krishnamurthy, Rajiv Gupta 0001, Paul L. Yu
INFOCOM4
2019 Stealthy Adversarial Perturbations Against Real-Time Video Classification Systems
Shasha Li 0001, Ajaya Neupane, Sujoy Paul, Chengyu Song, Srikanth V. Krishnamurthy, Amit K. Roy-Chowdhury, Ananthram Swami
NDSS5
2019 Unveiling your keystrokes: A Cache-based Side-channel Attack on Graphics Libraries
Daimeng Wang, Ajaya Neupane, Zhiyun Qian, Nael B. Abu-Ghazaleh, Srikanth V. Krishnamurthy, Edward Colbert, Paul L. Yu
NDSS5
2019 Employing attack graphs for intrusion detection
abstract
Intrusion detection systems are a commonly deployed defense that examines network traffic, host operations, or both to detect attacks. However, more attacks bypass IDS defenses each year, and with the sophistication of attacks increasing as well, we must examine new perspectives for intrusion detection. Current intrusion detection systems focus on known attacks and/or vulnerabilities, limiting their ability to identify new attacks, and lack the visibility into all system components necessary to confirm attacks accurately, particularly programs. To change the landscape of intrusion detection, we propose that future IDSs track how attacks evolve across system layers by adapting the concept of attack graphs. Attack graphs were proposed to study how multi-stage attacks could be launched by exploiting known vulnerabilities. Instead of constructing attacks reactively, we propose to apply attack graphs proactively to detect sequences of events that fulfill the requirements for vulnerability exploitation. Using this insight, we examine how to generate modular attack graphs automatically that relate adversary accessibility for each component, called its attack surface, to flaws that provide adversaries with permissions that create threats, called attack states, and exploit operations from those threats, called attack actions. We evaluate the proposed approach by applying it to two case studies: (1) attacks on file retrieval, such as TOCTTOU attacks, and (2) attacks propagated among processes, such as attacks on Shell-shock vulnerabilities. In these case studies, we demonstrate how to leverage existing tools to compute attack graphs automatically and assess the effectiveness of these tools for building complete attack graphs. While we identify some research areas, we also find several reasons why attack graphs can provide a valuable foundation for improving future intrusion detection systems.
Frank Capobianco, Rahul George, Kaiming Huang, Trent Jaeger, Srikanth V. Krishnamurthy, Zhiyun Qian, Mathias Payer, Paul L. Yu
NSPW5
2019 Frugal following: power thrifty object detection and tracking for mobile augmented reality
abstract
Accurate tracking of objects in the real world is highly desirable in Augmented Reality (AR) to aid proper placement of virtual objects in a user's view. Deep neural networks (DNNs) yield high precision in detecting and tracking objects, but they are energy-heavy and can thus be prohibitive for deployment on mobile devices. Towards reducing energy drain while maintaining good object tracking precision, we develop a novel software framework called MARLIN. MARLIN only uses a DNN as needed, to detect new objects or recapture objects that significantly change in appearance. It employs lightweight methods in between DNN executions to track the detected objects with high fidelity. We experiment with several baseline DNN models optimized for mobile devices, and via both offline and live object tracking experiments on two different Android phones (one utilizing a mobile GPU), we show that MARLIN compares favorably in terms of accuracy while saving energy significantly. Specifically, we show that MARLIN reduces the energy consumption by up to 73.3% (compared to an approach that executes the best baseline DNN continuously), and improves accuracy by up to 19× (compared to an approach that infrequently executes the same best baseline DNN). Moreover, while in 75% or more cases, MARLIN incurs at most a 7.36% reduction in location accuracy (using the common IOU metric), in more than 46% of the cases, MARLIN even improves the IOU compared to the continuous, best DNN approach.
Kittipat Apicharttrisorn, Xukan Ran, Jiasi Chen, Srikanth V. Krishnamurthy, Amit K. Roy-Chowdhury
SenSys4
2019 Catch Me if You Can: A Closer Look at Malicious Co-Residency on the Cloud
abstract
VM migration is an effective countermeasure against attempts at malicious co-residency. In this paper, our overarching objectives are: (a) to get an in-depth understanding of the ways and effectiveness with which an attacker can launch attacks toward achieving co-residency and (b) to design migration policies that are very effective in thwarting malicious co-residency, but are thrifty in terms of the bandwidth and downtime costs that are incurred with live migration. Toward achieving our goals, we first undertake an experimental study on Amazon EC2 to obtain an in-depth understanding of the side-channels, through which an attacker can use to ascertain co-residency with a victim. Here, in this paper, we identify a new set of stealthy side-channel attacks which we show to be more effective than the currently available attacks toward verifying co-residency. We also build a simple model that can be used for estimating co-residency times based on very few measurements on a given cloud platform, to account for varying attacker capabilities. Based on the study, we develop a set of guidelines to determine under what conditions the victim VM migrations should be triggered, given the performance costs in terms of bandwidth and downtime, which a user is willing to bear. Through extensive experiments on our private in-house cloud, we show that the migrations, using our guidelines, can limit the fraction of the time that an attacker VM co-resides with a victim VM to about 1% of the time with the bandwidth costs of a few MB and downtimes of a few seconds per day per VM migrated.
Ahmed Atya, Zhiyun Qian, Srikanth V. Krishnamurthy, Thomas La Porta, Patrick D. McDaniel, Lisa M. Marvel
IEEE/ACM Trans. Netw.3
2018 Droid M+: Developer Support for Imbibing Android's New Permission Model
abstract
In Android 6.0, Google revamped its long criticized permission model to prompt the user during runtime, and allow her to dynamically revoke granted permissions. Towards steering developers to this new model and improve user experience, Google also provides guidelines on (a) how permission requests should be formulated (b) how to educate users on why a permission is needed and (c) how to provide feedback when a permission is denied. In this paper we perform, to the best of our knowledge, the first measurement study on the adoption of Android's new model on recently updated apps from the official Google Play Store. We find that, unfortunately, (1) most apps have not been migrated to this new model and (2) for those that do support the model, many do not adhere to Google's guidelines. We attribute this unsatisfying status quo to the lack of automated transformation tools that can help developers refactor their code; via an IRB approved study we find that developers felt that there was a non-trivial effort involved in migrating their apps to the new model. Towards solving this problem, we develop Droid M+, a system that helps developers to easily retrofit their legacy code to support the new permission model and adhere to Google's guidelines. We believe that Droid M+ offers a significant step in preserving user privacy and improving user experience.
Ioannis Gasparis, Azeem Aqil, Zhiyun Qian, Chengyu Song, Srikanth V. Krishnamurthy, Rajiv Gupta 0001, Edward Colbert
AsiaCCS5
2018 IotSan: fortifying the safety of IoT systems
abstract
Today's IoT systems include event-driven smart applications (apps) that interact with sensors and actuators. A problem specific to IoT systems is that buggy apps, unforeseen bad app interactions, or device/communication failures, can cause unsafe and dangerous physical states. Detecting flaws that lead to such states, requires a holistic view of installed apps, component devices, their configurations, and more importantly, how they interact. In this paper, we design IotSan, a novel practical system that uses model checking as a building block to reveal "interaction-level" flaws by identifying events that can lead the system to unsafe states. In building IotSan, we design novel techniques tailored to IoT systems, to alleviate the state explosion associated with model checking. IotSan also automatically translates IoT apps into a format amenable to model checking. Finally, to understand the root cause of a detected vulnerability, we design an attribution mechanism to identify problematic and potentially malicious apps. We evaluate IotSan on the Samsung SmartThings platform. From 76 manually configured systems, IotSan detects 147 vulnerabilities. We also evaluate IotSan with malicious SmartThings apps from a previous effort. IotSan detects the potential safety violations and also effectively attributes these apps as malicious.
Dang Tu Nguyen, Chengyu Song, Zhiyun Qian, Srikanth V. Krishnamurthy, Edward Colbert, Patrick D. McDaniel
CoNEXT4
2018 On the Detection of Adaptive Side-Channel Attackers in Cloud Environments
abstract
Malicious coresidency is a precursor to side-channel attacks that target information leakage. In this paper, we seek to understand the interactions between a defender (the cloud service provider) who tries to detect malicious coresidency by an attacker, who in turn attempts to co-reside its VM with a victim VM on the same physical machine by exploiting the VM allocation policy employed by the cloud service provider while at the same time, trying to evade detection. The problem is modeled as a two-player game. Specifically, the attacker chooses how long to keep its VM operational before terminating and relaunching it to increase its odds of success. On the other hand, the defender attempts to detect and penalize malicious VMs based on their activity in a given time window. The defender estimates a maliciousness measure for all active VMs which then modulates the likelihood of a specific VM being migrated to a different physical machine. We study the equilibrium strategies for both players for different ranges of environment parameters and show the non-existence of equilibrium with pure strategies. Subsequently, we characterize the equilibrium of the game with mixed strategies.
Hisham Alhulayyil, Karim Khalil, Srikanth V. Krishnamurthy, Derya Cansever, Thomas La Porta, Ananthram Swami
GLOBECOM3
2018 A Framework for MIMO-based Packet Header Obfuscation
abstract
Eavesdroppers can exploit exposed packet headers towards attacks that profile clients and their data flows. In this paper, we propose FOG, a framework for effective header blinding using MIMO, to thwart eavesdroppers. FOG effectively tracks header bits as they traverse physical (PHY) layer sub-systems that perform functions like scrambling and interleaving. It combines multiple blinding signals for more effective and less predictable obfuscation, as compared to using a fixed blinding signal. We implement FOG on the WARP platform and demonstrate via extensive experiments that it yields better obfuscation than prior schemes that deploy full packet blinding. It causes a bit error rate (BER) of > 40 % at an eavesdropper if two blinding streams are sent during header transmissions. Furthermore, FOG incurs a very small throughput hit of ≈5 % with one blinding stream (and 9 % with two streams). Full packet blinding incurs much higher throughput hits (25 % with one stream and 50 % with two streams).
Yue Cao 0003, Ahmed Atya, Shailendra Singh 0004, Zhiyun Qian, Srikanth V. Krishnamurthy, Thomas La Porta, Prashant Krishnamurthy, Lisa M. Marvel
INFOCOM5
2018 Off-Path TCP Exploits of the Challenge ACK Global Rate Limit
Yue Cao 0003, Zhiyun Qian, Zhongjie Wang 0002, Tuan Dao, Srikanth V. Krishnamurthy, Lisa M. Marvel
IEEE/ACM Trans. Netw.5
2017 Jaal: Towards Network Intrusion Detection at ISP Scale
abstract
We have recently seen an increasing number of attacks that are distributed, and span an entire wide area network (WAN). Today, typically, intrusion detection systems (IDSs) are deployed at enterprise scale and cannot handle attacks that cover a WAN. Moreover, such IDSs are implemented at a single entity that expects to look at all packets to determine an intrusion. Transferring copies of raw packets to centralized engines for analysis in a WAN can significantly impact both network performance and detection accuracy. In this paper, we propose Jaal, a framework for achieving accurate network intrusion detection at scale. The key idea in Jaal is to monitor traffic and construct in-network packet summaries. The summaries are then processed centrally to detect attacks with high accuracy. The main challenges that we address are (a) creating summaries that are concise, but sufficient to draw highly accurate inferences and (b) transforming traditional IDS rules to handle summaries instead of raw packets. We implement Jaal on a large scale SDN testbed. We show that on average Jaal yields a detection accuracy of about 98%, which is the highest reported for ISP scale network intrusion detection. At the same time, the overhead associated with transferring summaries to the central inference engine is only about 35% of what is consumed if raw packets are transferred.
Azeem Aqil, Karim Khalil, Ahmed Atya, Evangelos E. Papalexakis, Srikanth V. Krishnamurthy, Trent Jaeger, K. K. Ramakrishnan, Paul L. Yu, Ananthram Swami
CoNEXT5
2017 Energy Efficient Object Detection in Camera Sensor Networks
abstract
A wireless camera network can provide situation awareness information (e.g., humans in distress) in scenarios such as disaster recovery. If such camera sensors are battery operated, sending raw video feeds back to a central controller can be expensive in terms of energy consumption. Further, if all cameras were to use the optimal processing algorithm for object decision, they may also expend unnecessary energy. Stated otherwise, cameras that capture the same objects may not all have to use the optimal algorithm to achieve a desired accuracy, and this can save processing energy costs. In this paper, our objective is to design and implement a framework that can support coordination among cameras to deliver highly accurate detection of objects in an energy efficient way. The framework, which we call EECS (for energy efficient camera sensors), estimates the detection accuracy and energy costs incurred (both the processing and communication costs are taken into account) with each detection algorithm for each camera, and comes up with a choice of cameras for sending information pertaining to the object of interest. This set of cameras and the video processing algorithms that they must use, are chosen so as to minimize the energy expenditures, given a desired detection accuracy. We implement EECS on a camera network built with smartphones, and demonstrate that it reduces the energy consumption by up to 40% while ensuring a object detection accuracy of over 86%.
Tuan Dao, Karim Khalil, Amit K. Roy-Chowdhury, Srikanth V. Krishnamurthy, Lance M. Kaplan
ICDCS4
2017 Your state is not mine: a closer look at evading stateful internet censorship
abstract
Understanding the behaviors of, and evading state-level Internet-scale censorship systems such as the Great Firewall (GFW) of China, has emerged as a research problem of great interest. One line of evasion is the development of techniques that leverage the possibility that the TCP state maintained on the GFW may not represent the state at end-hosts. In this paper we undertake, arguably, the most extensive measurement study on TCP-level GFW evasion techniques, with several vantage points within and outside China, and with clients subscribed to multiple ISPs. We find that the state-of-the art evasion techniques are no longer very effective on the GFW. Our study further reveals that the primary reason that causes these failures is the evolution of GFW over time. In addition, other factors such as the presence of middleboxes on the route from the client to the server also contribute to previously unexpected behaviors.
Zhongjie Wang 0002, Yue Cao 0003, Zhiyun Qian, Chengyu Song, Srikanth V. Krishnamurthy
Internet Measurement Conference5
2017 Stealth migration: Hiding virtual machines on the network
abstract
Live virtual machine (VM) migration is commonly used for enabling dynamic resource or fault management, or for load balancing in datacenters or cloud platforms. A service hosted by a VM may also be migrated to prevent its visibility to an external adversary who may seek to disrupt its operation by launching a DDoS attack against it. We first show that current systems cannot adequately hide a VM migration from an external adversary. The key reason for this is that a migration typically manifests a traffic pattern with distinguishable statistical properties. We introduce two new attacks that can allow an adversary to effectively track a migration in progress, by leveraging observations of these properties. As our primary contribution, we design and implement a stealth migration framework that causes migration traffic to be indistinguishable from regular Internet traffic, with a negligible latency overhead of approximately 0.37 seconds, on average.
Stefan Achleitner, Thomas La Porta, Patrick D. McDaniel, Srikanth V. Krishnamurthy, Alexander Poylisher, Constantin Serban
INFOCOM4
2017 Malicious co-residency on the cloud: Attacks and defense
abstract
Attacker VMs try to co-reside with victim VMs on the same physical infrastructure as a precursor to launching attacks that target information leakage. VM migration is an effective countermeasure against attempts at malicious co-residency. In this paper, we first undertake an experimental study on Amazon EC2 to obtain an in-depth understanding of the side-channels an attacker can use to ascertain co-residency with a victim. Here, we identify a new set of stealthy side-channel attacks which, we show to be more effective than currently available attacks towards verifying co-residency. Based on the study, we develop a set of guidelines to determine under what conditions victim VM migrations should be triggered given performance costs in terms of bandwidth and downtime, that a user is willing to bear. Via extensive experiments on our private in-house cloud, we show that migrations using our guidelines can limit the fraction of the time that an attacker VM co-resides with a victim VM to about 1 % of the time with bandwidth costs of a few MB and downtimes of a few seconds, per day per VM migrated.
Ahmed Atya, Zhiyun Qian, Srikanth V. Krishnamurthy, Thomas La Porta, Patrick D. McDaniel, Lisa M. Marvel
INFOCOM3
2017 Accurate and Timely Situation Awareness Retrieval from a Bandwidth Constrained Camera Network
abstract
Wireless cameras can be used to gather situation awareness information (e.g., humans in distress) in disaster recovery scenarios. However, blindly sending raw video streams from such cameras, to an operations center or controller can be prohibitive in terms of bandwidth. Further, these raw streams could contain either redundant or irrelevant information. Thus, we ask "how do we extract accurate situation awareness information from such camera nodes and send it in a timely manner, back to the operations center?" Towards this, we design ACTION, a framework that (a) detects objects of interest (e.g., humans) from the video streams, (b) combines these streams intelligently to eliminate redundancies and (c) transmits only parts of the feeds that are sufficient in achieving a desired detection accuracy to the controller. ACTION uses small amounts of metadata to determine if the objects from different camera feeds are the same. A resource-aware greedy algorithm is used to select a subset of video feeds that are associated with the same object, so as to provide a desired accuracy, for being sent to the operations center. Our evaluations show that ACTION helps reduce the network usage up to threefold, and yet achieves a high detection accuracy of ≈ 90%.
Tuan Dao, Amit K. Roy-Chowdhury, Nasser M. Nasrabadi, Srikanth V. Krishnamurthy, Prasant Mohapatra, Lance M. Kaplan
MASS4
2017 Enhancing WiFi Throughput with PLC Extenders: A Measurement Study
Kittipat Apicharttrisorn, Ahmed Atya, Jiasi Chen, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy
PAM5
2017 Detecting Android Root Exploits by Learning from Root Providers
Ioannis Gasparis, Zhiyun Qian, Chengyu Song, Srikanth V. Krishnamurthy
USENIX Security Symposium4
2017 ZapDroid: Managing Infrequently Used Applications on Smartphones
abstract
User surveys have shown that a typical user has over a 100 apps on his/her smartphone [1], but stops using many of them. We conduct a user study to identify such unused apps, which we call zombies, and show via experiments that zombie apps consume significant resources on a user's smartphone and access his/her private information. We then design and build ZapDroid, which enables users to detect and silo zombie apps in an effective way to prevent their undesired activities. If and when the user wishes to resume using such an app, ZapDroid restores the app quickly and effectively. Our evaluations show that: (i) ZapDroid saves twice the energy from unwanted zombie app behaviors as compared to apps from the Play Store that kill background unwanted processes, and (ii) it effectively prevents zombie apps from using undesired permissions. In addition, ZapDroid is energy-efficient, consuming <;4 percent of the battery per day.
Indrajeet Singh, Srikanth V. Krishnamurthy, Harsha V. Madhyastha, Iulian Neamtiu
IEEE Trans. Mob. Comput.2
2017 Deceiving Network Reconnaissance Using SDN-Based Virtual Topologies
abstract
Advanced targeted cyber attacks often rely on reconnaissance missions to gather information about potential targets, their characteristics and location to identify vulnerabilities in a networked environment. Advanced network scanning techniques are often used for this purpose and are automatically executed by malware infected hosts. In this paper, we formally define network deception to defend reconnaissance and develop a reconnaissance deception system, which is based on software defined networking, to achieve deception by simulating virtual topologies. Our system thwarts network reconnaissance by delaying the scanning techniques of adversaries and invalidating their collected information, while limiting the performance impact on benign network traffic. By simulating the topological as well as physical characteristics of networks, we introduce a system which deceives malicious network discovery and reconnaissance techniques with virtual information, while limiting the information an attacker is able to harvest from the true underlying system. This approach shows a novel defense technique against adversarial reconnaissance missions which are required for targeted cyber attacks such as advanced persistent threats in highly connected environments. The defense steps of our system aim to invalidate an attackers information, delay the process of finding vulnerable hosts and identify the source of adversarial reconnaissance within a network.
Stefan Achleitner, Thomas La Porta, Patrick D. McDaniel, Shridatt Sugrim, Srikanth V. Krishnamurthy, Ritu Chadha
IEEE Trans. Netw. Serv. Manag.5
2017 Managing Redundant Content in Bandwidth Constrained Wireless Networks
abstract
Images/videos are often uploaded in situations like disasters. This can tax the network in terms of increased load and thereby upload latency, and this can be critical for response activities. In such scenarios, prior work has shown that there is significant redundancy in the content (e.g., similar photos taken by users) transferred. By intelligently suppressing/deferring transfers of redundant content, the load can be significantly reduced, thereby facilitating the timely delivery of unique, possibly critical information. A key challenge here however, is detecting “what content is similar,” given that the content is generated by uncoordinated user devices. Toward addressing this challenge, we propose a framework, wherein a service to which the content is to be uploaded first solicits metadata (e.g., image features) from any device uploading content. By intelligently comparing this metadata with that associated with previously uploaded content, the service effectively identifies (and thus enables the suppression of) redundant content. Our evaluations on a testbed of 20 Android smartphones and via ns3 simulations show that we can identify similar content with a 70% true positive rate and a 1% false positive rate. The resulting reduction in redundant content transfers translates to a latency reduction of 44 % for unique content.
Tuan Dao, Amit K. Roy-Chowdhury, Harsha V. Madhyastha, Srikanth V. Krishnamurthy, Thomas La Porta
IEEE/ACM Trans. Netw.4
2017 TIDE: A User-Centric Tool for Identifying Energy Hungry Applications on Smartphones
abstract
Today, many smartphone users are unaware of what applications (apps) they should stop using to prevent their battery from running out quickly. The problem is identifying such apps is hard due to the fact that there exist hundreds of thousands of apps and their impact on the battery is not well understood. We show via extensive measurement studies that the impact of an app on battery consumption depends on both environmental (wireless) factors and usage patterns. Based on this, we argue that there exists a critical need for a tool that allows a user to: 1) identify apps that are energy hungry and 2) understand why an app is consuming energy, on her phone. Toward addressing this need, we present TIDE, a tool to detect high energy apps on any particular smartphone. TIDE's key characteristic is that it accounts for usage-centric information while identifying energy hungry apps from among a multitude of apps that run simultaneously on a user's phone. Our evaluation of TIDE on a test bed of Android-based smartphones, using week-long smartphone usage traces from 17 real users, shows that TIDE correctly identifies over 94% of energy-hungry apps and has a false positive rate of <; 6%.
Tuan Dao, Indrajeet Singh, Harsha V. Madhyastha, Srikanth V. Krishnamurthy, Guohong Cao, Prasant Mohapatra
IEEE/ACM Trans. Netw.4
2017 TRINITY: Tailoring Wireless Transmission Strategies to User Profiles in Enterprise Wireless Networks
abstract
The proliferation of smartphones and tablet devices is changing the landscape of user connectivity and data access from predominantly static users to a mix of static and mobile users. While significant advances have been made in wireless transmission strategies (e.g., beamforming and network MIMO) to meet the increased demand for capacity, such strategies primarily cater to static users. To cope with growing heterogeneity in data access, it is critical to identify and optimize strategies that can cater to users of various profiles to maximize system performance and more importantly, improve users' quality of experience. Toward this goal, we first show that users can be profiled into three distinct categories based on their data access (mobility) and channel coherence characteristics. Then, with real-world experiments, we show that the strategy that best serves users in these categories varies distinctly from one profile to another and belongs to the class of strategies that emphasize either multiplexing (e.g., network MIMO), diversity (e.g., distributed antenna systems) or reuse (e.g., conventional CSMA). Two key challenges remain in translating these inferences to a practical system, namely: 1) how to profile users and 2) how to combine strategies to communicate with users of different profiles simultaneously. In addressing these challenges, we present the design of TRINITY-a practical system that effectively caters to a heterogeneous set of users. We implement and evaluate a prototype of TRINITY on our WARP radio testbed. Our extensive experiments show that TRINITY's intelligent combining of transmission strategies improves the total network rate by 50%-150%, satisfies the QoS requirements of thrice as many users, and improves PSNR for video traffic by 10 dB compared with individual transmission strategies.
Shailendra Singh 0004, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy, Xinyu Zhang 0003, Mohammad Ali Amir Khojastepour, Sampath Rangarajan
IEEE/ACM Trans. Netw.3
2016 Optimal Monitor Placement for Detection of Persistent Threats
abstract
We study optimal monitor placement for intrusion detection in networks with persistent attackers. The problem is modeled as a stochastic game in which the attacker attempts to control targets by delivering malicious packets while the defender tries to detect such attempts. The state of the game is determined by the target end-systems in the network, each of which can be in either a healthy or a compromised state. Compromised targets are controlled by the attacker and may be used to inject malicious packets into the network to attack healthy targets. In addition, a random re-imaging process is deployed on all targets to regain control of compromised targets. We find the game value and the equilibrium strategies for both players under different assumptions on the knowledge of the state at the defender.
Karim Khalil, Zhiyun Qian, Paul L. Yu, Srikanth V. Krishnamurthy, Ananthram Swami
GLOBECOM4
2016 Network coding efficiency in the presence of an intermittent backhaul network
abstract
In infrastructure-lacking environments, like military areas of operation, the intermittent availability of backhaul networks leads to greater reliance on peer to peer data exchange. In such settings, mobile nodes use Delay Tolerant Network (DTN) protocols for exchanging location specific data. High transmission delay, packet loss and intermittent connectivity increases the need for efficient data transmission in such scenarios. In this paper, we evaluate network coding for efficient data exchange between mobile wireless nodes under the presence of an intermittent backhaul network, like a satellite or cellular link. We analyze the upper bound of savings achievable with network coding for single-hop packet transmission, and introduce a network coding algorithm focused on reducing the required number of packet transmissions in such a setting. Evaluation of our proposed data exchange protocol shows how network coding can be applied to reduce transmission delay and minimize the dependency on an intermittent backhaul network in a communication scenario typical of a military environment.
Stefan Achleitner, Thomas La Porta, Srikanth V. Krishnamurthy, Victor S. Quizhpi
ICC3
2016 Off-Path TCP Exploits: Global Rate Limit Considered Dangerous
Yue Cao 0003, Zhiyun Qian, Zhongjie Wang 0002, Tuan Dao, Srikanth V. Krishnamurthy, Lisa M. Marvel
USENIX Security Symposium5
2016 Jammer localization in wireless networks: An experimentation-driven approach
Konstantinos Pelechrinis, Iordanis Koutsopoulos, Ioannis Broustis, Srikanth V. Krishnamurthy
Comput. Commun.4
2016 iBUS: An Integrated Beamformer and Uplink Scheduler for OFDMA Small Cells
abstract
Beamforming is a signal processing technique with numerous benefits in wireless communication. Unlike traditional omnidirectional communication, it focuses the energy of the transmitted and/or the received signal in a particular direction. Although beamforming has been extensively studied on conventional systems such as WiFi, little is known about its practical impact on performance in orthogonal frequency-domain multiple access (OFDMA) small-cell deployments. Since OFDMA schedules multiple clients (users) in the same frame in contrast to WiFi, designing intelligent scheduling mechanisms and at the same time leveraging beamforming is a challenging task. Unlike downlink, we show that the integration of beamforming with uplink scheduling projects an interesting tradeoff between beamforming gain on the one hand, and the power-pooling gain resulting from joint multiuser scheduling on the other hand. This, in turn, makes the uplink scheduling problem even hard to approximate. To address this, we propose algorithms that are simple to implement, yet provably efficient with a worst-case guarantee of 1/2. We implement our algorithms on a real WiMAX small-cell platform integrated with an eight-element phased-array beamforming antenna. Evaluations from both prototype implementation and trace-driven simulations show that the algorithms deliver throughput gains of over 40% compared to an omnidirectional scheme.
Mustafa Y. Arslan, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy, Sampath Rangarajan
IEEE/ACM Trans. Netw.3
2016 A Policy-Aware Enforcement Logic for Appropriately Invoking Network Coding
abstract
Network coding has been shown to offer significant throughput benefits over certain wireless network topologies. However, the application of network coding may not always improve the network performance. In this paper, we first provide an analytical study, which helps in assessing when network coding is preferable to a traditional store-and-forward approach. Interestingly, our study reveals that in many topological scenarios, network coding can in fact hurt the throughput performance; in such scenarios, applying the store-and-forward approach leads to higher network throughput. We validate our analytical findings via extensive testbed experiments. Guided by our findings as our primary contribution, we design and implement PACE, a Policy-Aware Coding Enforcement logic that enables network coding only when it is expected to offer performance benefits. Specifically, PACE leverages a minimal set of periodic link quality measurements in order to make per-flow online decisions with regards to when network coding should be activated, and when store-and-forward is preferable. It can be easily embedded into network-coding-aware routers as a user-level or kernel-level software utility. We evaluate the efficacy of PACE via: 1) ns-3 simulations, and 2) experiments on a wireless testbed. We observe that our scheme wisely activates network coding only when appropriate, thereby improving the total network throughput by as much as 350% in some scenarios.
Ahmed Atya, Ioannis Broustis, Shailendra Singh 0004, Dimitris Syrivelis, Srikanth V. Krishnamurthy, Thomas La Porta
IEEE/ACM Trans. Netw.5
2016 Forensic Analysis of Packet Losses in Wireless Networks
abstract
Due to the lossy nature of wireless links, it is difficult to determine if packet losses are due to wireless-induced effects or from malicious discarding. Many prior efforts on detecting malicious packet drops rely on evidence collected via passive monitoring by neighbor nodes. However, they do not analyze the cause of packet losses. In this paper, we ask: 1) Given certain macroscopic parameters of the network (like traffic intensity and node density) what is the likelihood that evidence exists with respect to a transmission? 2) How can these parameters be used to perform a forensic analysis of the reason for the losses? Toward answering the above questions, we first build an analytical framework that computes the likelihood that evidence (we call this transmission evidence, or TE for short) exists with respect to transmissions, in terms of a set of network parameters. We validate our analytical framework via both simulations as well as real-world experiments on two different wireless testbeds. The analytical framework is then used as a basis for a protocol within a forensic analyzer to assess the cause of packet losses and determine the likelihood of forwarding misbehaviors. Through simulations, we find that our assessments are close to the ground truth in all examined cases, with an average deviation of 2.3% from the ground truth and a worst case deviation of 15.0%.
Jianxia Ning, Shailendra Singh 0004, Konstantinos Pelechrinis, Bin Liu 0004, Srikanth V. Krishnamurthy, Ramesh Govindan
IEEE/ACM Trans. Netw.5
2016 FluidNet: A Flexible Cloud-Based Radio Access Network for Small Cells
abstract
Cloud-based radio access networks (C-RAN) have been proposed as a cost-efficient way of deploying small cells. Unlike conventional RANs, a C-RAN decouples the baseband processing unit (BBU) from the remote radio head (RRH), allowing for centralized operation of BBUs and scalable deployment of light-weight RRHs as small cells. In this work, we argue that the intelligent configuration of the front-haul network between the BBUs and RRHs, is essential in delivering the performance and energy benefits to the RAN and the BBU pool, respectively. We propose FluidNet-a scalable, light-weight framework for realizing the full potential of C-RAN. FluidNet deploys a logically re-configurable front-haul to apply appropriate transmission strategies in different parts of the network and hence cater effectively to both heterogeneous user profiles and dynamic traffic load patterns. FluidNet's algorithms determine configurations that maximize the traffic demand satisfied on the RAN, while simultaneously optimizing the compute resource usage in the BBU pool. We prototype FluidNet on a 6 BBU, 6 RRH WiMAX C-RAN testbed. Prototype evaluations and large-scale simulations reveal that FluidNet's ability to re-configure its front-haul and tailor transmission strategies provides a 50% improvement in satisfying traffic demands, while reducing the compute resource usage in the BBU pool by 50% compared to baseline schemes.
Karthikeyan Sundaresan, Mustafa Y. Arslan, Shailendra Singh 0004, Sampath Rangarajan, Srikanth V. Krishnamurthy
IEEE/ACM Trans. Netw.5
2015 BOLT: realizing high throughput power line communication networks
abstract
Power line communications (PLC) offer an immediate means of providing high bandwidth connectivity in settings where there is no in-built network infrastructure. While there is recent work on understanding physical and MAC layer artifacts of PLC, its applicability and performance in multi-flow settings is not well understood. We first undertake an extensive measurement study that sheds light on the properties of PLC that significantly affect performance in multi-flow settings. Using the understanding gained, we design BOLT, a framework that adopts a learning-based approach to effectively manage and orchestrate flows in a PLC network. BOLT is flexible and is agnostic to standards; it can be used to implement scheduling algorithms that target different performance goals. We implement BOLT on three different testbeds using off-the-shelf PLC adapters and showcase its ability to effectively manage flows, delivering several folds throughput improvement over state-of-the-art solutions.
Ahmed Atya, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy, Mohammad Ali Amir Khojastepour, Sampath Rangarajan
CoNEXT3
2015 ZapDroid: managing infrequently used applications on smartphones
abstract
User surveys have shown that a typical user has over a hundred apps on her smartphone [1], but stops using many of them. We conduct a user study to identify such unused apps, which we call zombies, and show via experiments that zombie apps consume significant resources on a user's smartphone and access her private information. We then design and build ZapDroid, which enables users to detect and silo zombie apps in an effective way to prevent their undesired activities. If and when the user wishes to resume using such an app, ZapDroid restores the app quickly and effectively. Our evaluations show that: (i) ZapDroid saves twice the energy from unwanted zombie app behaviors as compared to apps from the Play Store that kill background unwanted processes, and (ii) it effectively prevents zombie apps from using undesired permissions. In addition, ZapDroid is energ-efficient, consuming < 4% of the battery per day.
Indrajeet Singh, Srikanth V. Krishnamurthy, Harsha V. Madhyastha, Iulian Neamtiu
UbiComp2
2015 TIDE: A User-centric Tool for Identifying Energy Hungry Applications on Smartphones
abstract
Today, many smartphone users are unaware of what applications (apps) they should stop using to prevent their battery from running out quickly. The problem is identifying such apps is hard due to the fact that there exist hundreds of thousands of apps and their impact on the battery is not well understood. We show via extensive measurement studies that the impact of an app on battery consumption depends on both environmental (wireless) factors and usage patterns. Based on this, we argue that there exists a critical need for a tool that allows a user to (a) identify apps that are energy hungry, and (b) understand why an app is consuming energy, on her phone. Towards addressing this need, we present TIDE, a tool to detect high energy apps on any particular smartphone. TIDE's key characteristic is that it accounts for usage-centric information while identifying energy hungry apps from among a multitude of apps that run simultaneously on a user's phone. Our evaluation of TIDE on a testbed of Android-based smartphones, using weeklong smartphone usage traces from 17 real users, shows that TIDE correctly identifies over 94% of energy-hungry apps and has a false positive rate of <; 6%.
Tuan Dao, Indrajeet Singh, Harsha V. Madhyastha, Srikanth V. Krishnamurthy, Guohong Cao, Prasant Mohapatra
ICDCS4
2015 Streaming Lower Quality Video over LTE: How Much Energy Can You Save?
abstract
Streaming video content over cellular connectivity impacts the battery consumption of a client (e.g., a smartphone). The problem is exacerbated when the channel quality is poor because of a large number of retransmissions, moreover, streaming high quality video in such cases can negatively impact user experience (e.g., due to stalling). In this paper, we develop an analytical framework which can provide the user with an estimate of "how much" energy she can save by choosing to view a lower quality stream of the video she wishes to view. The framework takes as input the network conditions (in terms of packet error rate or PER) and a coarse characterization of the video to be viewed (slow versus fast motion, resolution), and yields as output the energy savings with different resolutions of the video to be viewed. Thus empowered, the user can then make a quick, educated decision on the version of the video to view. We validate that our framework is extremely accurate in estimating the energy consumption via both simulations, and experiments on smartphones (within ~ 5% of real measurements). We find that switching to a lower resolution video can potentially lead to ~ 418 mW (23.2%) decrease in the consumed power for slow motion video, and ~ 480 mW (26%) for fast motion video in bad channel conditions. This translates to an energy savings of 376.2 J and 432 J respectively, for video clips that are 15 minutes long.
Azeem Aqil, Ahmed Atya, Srikanth V. Krishnamurthy, George Papageorgiou 0004
ICNP3
2015 FlexiWeb: Network-Aware Compaction for Accelerating Mobile Web Transfers
abstract
To reduce page load times and bandwidth usage for mobile web browsing, middleboxes that compress page content are commonly used today. Unfortunately, this can hurt performance in many cases; via an extensive measurement study, we show that using middleboxes to facilitate compression results in up to 28% degradation in page load times when the client enjoys excellent wireless link conditions. We find that benefits from compression are primarily realized under bad network conditions. Guided by our study, we design and implement FlexiWeb, a framework that determines both when to use a middlebox and how to use it, based on the client's network conditions. First, FlexiWeb selectively fetches objects on a web page either directly from the source or via a middlebox, rather than fetching all objects via the middlebox. Second, instead of simply performing lossless compression of all content, FlexiWeb performs network-aware compression of images by selecting from among a range of content transformations. We implement and evaluate a prototype of FlexiWeb using Google's open source Chromium mobile browser and our implementation of a modified version of Google's open source compression proxy. Our extensive experiments show that, across a range of scenarios, FlexiWeb reduces page load times for mobile clients by 35-42% compared to the status quo.
Shailendra Singh 0004, Harsha V. Madhyastha, Srikanth V. Krishnamurthy, Ramesh Govindan
MobiCom3
2015 TRINITY: A Practical Transmitter Cooperation Framework to Handle Heterogeneous User Profiles in Wireless Networks
abstract
To handle increased capacity demands, sophisticated MIMO-based transmission strategies, based on transmitter cooperation, have emerged. However, different types of users' channels (e.g., static vs mobile, stable vs dynamic channels) that make up today's enterprises, require different MIMO transmission strategies. With the wrong strategy, a user could even see a degradation in performance. Our overarching goal is to design and implement a framework, TRINITY, that can simultaneously cater to a heterogeneous mix of users, by intelligently combining a plurality of MIMO transmission strategies wherein the transmitters at different nodes can cooperate to deliver significant performance gains. Three key challenges that we address in building TRINITY are: (i) how to categorize users into channel profiles such that a single transmission strategy caters to the users of a profile, (ii) how to combine strategies to communicate with users of different profiles simultaneously, and (iii) what is the granularity of transmitter cooperation needed to balance efficiency with complexity. We implement and evaluate TRINITY on our WARP radio testbed. Our extensive experiments show that TRINITY's intelligent combining of transmission strategies improves the total network rate by 50%-150%, satisfies the QoS requirements of thrice as many users, and improves PSNR for video traffic by 10 dB compared to individual transmission strategies.
Shailendra Singh 0004, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy, Xinyu Zhang 0003, Mohammad Ali Amir Khojastepour, Sampath Rangarajan
MobiHoc3
2015 Resource Efficient Privacy Preservation of Online Social Media Conversations
Indrajeet Singh, Masoud Akhoondi, Mustafa Y. Arslan, Harsha V. Madhyastha, Srikanth V. Krishnamurthy
SecureComm5
2015 CWC: A Distributed Computing Infrastructure Using Smartphones
abstract
Every night, many smartphones are plugged into a power source for recharging the battery. Given the increasing computing capabilities of smartphones, these idle phones constitute a sizeable computing infrastructure. Therefore, for an enterprise which supplies its employees with smartphones, we argue that a computing infrastructure that leverages idle smartphones being charged overnight is an energy-efficient and cost-effective alternative to running certain tasks on traditional servers. While parallel execution models and schedulers exist for servers, smartphones face a unique set of technical challenges due to the heterogeneity in CPU clock speed, variability in network bandwidth, and lower availability than servers. In this paper, we address many of these challenges to develop CWC-a distributed computing infrastructure using smartphones. We implement and evaluate a prototype of CWC that employs a novel scheduling algorithm to minimize the makespan of a set of computing tasks. Our evaluations using a testbed of 18 Android phones show that CWC's scheduler yields a makespan that is 1.6× faster than other simpler approaches.
Mustafa Y. Arslan, Indrajeet Singh, Shailendra Singh 0004, Harsha V. Madhyastha, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy
IEEE Trans. Mob. Comput.6
2015 Exploiting Subcarrier Agility to Alleviate Active Jamming Attacks in Wireless Networks
abstract
Malicious interference injection or jamming is one of the simplest ways to disrupt wireless communications. Prior approaches can alleviate jamming interference to a limited extent; they are especially vulnerable to a reactive jammer i.e., a jammer that injects noise upon sensing a legitimate transmission or wideband jamming. In this paper, we leverage the inherent features of OFDM (Orthogonal Frequency Division Multiplexing) to cope with such attacks. Specifically, via extensive experiments, we observe that the jamming signal experiences differing levels of fading across the composite sub-carriers in its transmission bandwidth. Thus, if the legitimate transmitter were to somehow exploit the relatively unaffected sub-carriers to transmit data to the receiver, it could achieve reasonable throughputs, even in the presence of the active jammer. We design and implement JIMS, a Jamming Interference Mitigation Scheme that exploits the above characteristic by overcoming key practical challenges. Via extensive testbed experiments and simulations we show that JIMS achieves a throughput restoration of up to 75 percent in the presence of an active jammer.
Ahmed Atya, Azeem Aqil, Shailendra Singh 0004, Ioannis Broustis, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy
IEEE Trans. Mob. Comput.6
2015 Adaptive Sub-Carrier Level Power Allocation in OFDMA Networks
abstract
In today's OFDMA networks, the transmission power is typically fixed and the same for all the sub-carriers that compose a channel. The sub-carriers though, experience different degrees of fading and thus, the received power is different for different sub-carriers; while some frequencies experience deep fades, others are relatively unaffected. In this paper, we make a case for redistributing the power across the sub-carriers (subject to a fixed power budget constraint) to better cope with this frequency selectivity. Specifically, we design a joint power and rate adaptation scheme (called JPRA for short) wherein power redistribution is combined with sub-carrier level rate adaptation to yield significant throughput benefits. We further consider three variants of JPRA: (a) JPRA-Basic where, the power is redistributed across sub-carriers so as to support a maximum common rate across all the sub-carriers (b) JPRA-Intermediate where, the power is redistributed across sub-carriers so as to support a maximum common rate across a “subset” of sub-carriers such that the aggregate rate is maximized. (c) JPRA-Adaptive where, the goal is to redistribute power such that the transmission time of a packet is minimized. While the first two variants decrease transceiver complexity and are simpler, the third is geared towards achieving the maximum throughput possible. We implement all three variants of JPRA on our WARP radio testbed. Our extensive experiments demonstrate that JPRA can provide a 35 percent improvement in total network throughput in testbed experiments compared to FARA, a scheme where only sub-carrier level rate adaptation is used. We also perform simulations to demonstrate the efficacy of JPRA in larger scale networks.
Shailendra Singh 0004, Moloud Shahbazi, Konstantinos Pelechrinis, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy, Sateesh Addepalli
IEEE Trans. Mob. Comput.5
2015 Self-Organizing Resource Management Framework in OFDMA Femtocells
abstract
Next generation wireless networks (i.e., WiMAX, LTE) provide higher bandwidth and spectrum efficiency leveraging smaller (femto) cells with orthogonal frequency division multiple access (OFDMA). The uncoordinated, dense deployments of femtocells however, pose several unique challenges relating to interference and resource management in OFDMA femtocell networks. Towards addressing these challenges, we propose RADION, a distributed resource management framework that effectively manages interference across femtocells. RADION's core building blocks enable femtocells to opportunistically determine the available resources in a completely distributed and efficient manner. Further, RADION's modular nature paves the way for different resource management solutions to be incorporated in the framework. We implement RADION on a real WiMAX femtocell testbed deployed in a typical indoor setting. Two distributed solutions are enabled through RADION and their performance is studied to highlight their quick self-organization into efficient resource allocations.
Jongwon Yoon, Mustafa Y. Arslan, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy, Suman Banerjee 0001
IEEE Trans. Mob. Comput.4
2015 A Distortion-Resistant Routing Framework for Video Traffic in Wireless Multihop Networks
abstract
Traditional routing metrics designed for wireless networks are application-agnostic. In this paper, we consider a wireless network where the application flows consist of video traffic. From a user perspective, reducing the level of video distortion is critical. We ask the question “Should the routing policies change if the end-to-end video distortion is to be minimized?” Popular link-quality-based routing metrics (such as ETX) do not account for dependence (in terms of congestion) across the links of a path; as a result, they can cause video flows to converge onto a few paths and, thus, cause high video distortion. To account for the evolution of the video frame loss process, we construct an analytical framework to, first, understand and, second, assess the impact of the wireless network on video distortion. The framework allows us to formulate a routing policy for minimizing distortion, based on which we design a protocol for routing video traffic. We find via simulations and testbed experiments that our protocol is efficient in reducing video distortion and minimizing the user experience degradation.
George Papageorgiou 0004, Shailendra Singh 0004, Srikanth V. Krishnamurthy, Ramesh Govindan, Thomas La Porta
IEEE/ACM Trans. Netw.3
2014 Managing Redundant Content in Bandwidth Constrained Wireless Networks
abstract
Images/videos are often uploaded in situations like disasters. This can tax the network in terms of increased load and thereby upload latency, and this can be critical for response activities. In such scenarios, prior work has shown that there is significant redundancy in the content (e.g., similar photos taken by users) transferred. By intelligently suppressing/deferring transfers of redundant content, the load can be significantly reduced, thereby facilitating the timely delivery of unique, possibly critical information. A key challenge here however, is detecting 'what content is similar,' given that the content is generated by uncoordinated user devices. Towards addressing this challenge, we propose a framework, wherein a service to which the content is to be uploaded first solicits metadata (e.g, image features) from any device uploading content. By intelligently comparing this metadata with that associated with previously uploaded content, the service effectively identifies (and thus enables the suppression of) redundant content. Our evaluations on a testbed of 20 Android smartphones and via ns3 simulations show that we can identify similar content with a 70% true positive rate and a 1% false positive rate. The resulting reduction in redundant content transfers translates to a latency reduction of 44 % for unique content.
Tuan Dao, Amit K. Roy-Chowdhury, Harsha V. Madhyastha, Srikanth V. Krishnamurthy, Thomas La Porta
CoNEXT4
2014 Performance of visible light communications with dimming controls
abstract
Visible light communications (VLC) have gained popularity as an alternative to RF. Understanding the underlying communications is key to the design of MAC protocols for arbitrating access across lights in multiple rooms. We consider the interference across two rooms from VLC emitters. The emitters use Binary Pulse Position Modulation (BPPM); the pulse width is varied to provide different dimming levels. We use a modified ray-tracing algorithm to calculate the channel impulse response between the emitters and receivers that are located at different positions within a room. We analyze the performance observed at the receivers in the presence of (i) illumination and (ii) transmissions from an interfering VLC emitter. We find that in the former case, the VLC emissions from the interferer do not impact the reception at the target receiver. In the latter case, the performance is degraded and it depends on the position of the receiver.
Zi Feng, George Papageorgiou 0004, Qian Gao 0002, Ahmed Atya, Srikanth V. Krishnamurthy, Gang Chen 0007
WCNC5
2013 Resource thrifty secure mobile video transfers on open WiFi networks
abstract
Video transfers using smartphones are becoming increasingly popular. To prevent the interception of content from eavesdroppers, video flows must be encrypted. However, encryption results in a cost in terms of processing delays and energy consumed on the user's device. We argue that encrypting only certain parts of the flow can create sufficiently high distortion at an eavesdropper preserving content confidentiality as a result. By selective encryption, one can reduce delay and the battery consumption on the mobile device. We develop a mathematical framework that captures the impact of the encryption process on the delay experienced by a flow, and the distortion seen by an eavesdropper. This provides a quick and efficient way of determining the right parts of a video flow that must be encrypted to preserve confidentiality, while limiting performance penalties. In practice, it can aid a user in choosing the right level of encryption. We validate our model via extensive experiments with different encryption policies using Android smartphones. We observe that by selectively encrypting parts of a video flow one can preserve the confidentiality while reducing delay by as much as 75% and the energy consumption by as much as 92%.
George Papageorgiou 0004, John Gasparis, Srikanth V. Krishnamurthy, Ramesh Govindan, Thomas La Porta
CoNEXT3
2013 On the trade-offs between collecting packet level forensic evidence and data delivery performance in wireless networks
abstract
Transmission Evidence (TE for short) refers to a historic trail of the packet transmissions in the network. TE is collected and maintained in a distributed manner by the nodes in the network and can be queried on demand by a network forensics system to trace past events. The latter can facilitate crucial applications such as identifying malicious or malfunctioning nodes. Recently, we developed an analytical framework towards computing the likelihood of TE availability in wireless networks. Our prior efforts [1] brought to light the impact of the network's operational parameters (such as transmission rate and packet length) on the availability of TE. However, provisioning for TE could impact the network performance in terms of throughput and/or delay. Our objective in this work is to capture and quantify the trade-offs between provisioning transmission evidence and achieving high performance in wireless networks. In particular, we investigate the network performance hit, under the constraint of TE availability guarantees. Our results indicate that the performance remains unaffected up to a certain TE requirement. Beyond this, the throughput could degrade and the delay could increase by as much as 30%. To the best of our knowledge, this is the first study of its kind.
Jianxia Ning, Konstantinos Pelechrinis, Srikanth V. Krishnamurthy, Ramesh Govindan
ICC3
2013 Mobility-Assisted Energy-Aware User Contact Detection in Mobile Social Networks
abstract
Many practical problems in mobile social networks such as routing, community detection, and social behavior analysis, rely on accurate user contact detection. The frequently used method for detecting user contact is through Bluetooth on smartphones. However, Bluetooth scans consume lots of power. Although increasing the scan duty cycle can reduce the power consumption, it also reduces the accuracy of contact detection. In this paper, we address this problem based on the observation that user contact changes (i.e., starts and ends of user contacts) are mainly caused by user movement. Since most smartphones have accelerometers, we can use them to detect user movement with much less energy and then start Bluetooth scans to detect user contacts. By conducting experiments on smartphones, we discover three relationships between user movement and user contact changes. According to these relationships, we propose a Mobility-Assisted User Contact detection algorithm (MAUC), which triggers Bluetooth scans only when user movements have a high possibility to cause contact changes. Moreover, we propose energy-aware MAUC (E-MAUC) to further reduce energy consumption during Bluetooth discovery, while keeping the same detection accuracy as MAUC. Via trace driven simulations, we show that MAUC can reduce the number of Bluetooth scans by half while maintaining similar contact detection rates compared to existing algorithms, and E-MAUC can further reduce the energy consumption by 45% compared to MAUC.
Wenjie Hu 0002, Guohong Cao, Srikanth V. Krishnamurthy, Prasant Mohapatra
ICDCS3
2013 Mitigating malicious interference via subcarrier-level radio agility in wireless networks
abstract
Malicious interference injection or jamming is one of the simplest ways to disrupt wireless communications. Prior approaches can alleviate jamming interference to a limited extent; they are especially vulnerable to a reactive jammer i.e., a jammer that injects noise upon sensing a legitimate transmission or wideband jamming. In this paper, we leverage the inherent features of OFDM (Orthogonal Frequency Division Multiplexing) to cope with such attacks. Specifically, via extensive experiments, we observe that the jamming signal experiences differing levels of fading across the composite sub-carriers in its transmission bandwidth. Thus, if the legitimate transmitter were to somehow exploit the relatively unaffected sub-carriers to transmit data to the receiver, it could achieve reasonable throughputs, even in the presence of the active jammer. We design and implement JIMS, a Jamming Interference Mitigation Scheme that exploits the above characteristic by overcoming key practical challenges. Via extensive testbed experiments and simulations we show that JIMS achieves a throughput restoration of up to 75% in the presence of an active jammer.
Ahmed Atya, Azeem Aqil, Shailendra Singh 0004, Ioannis Broustis, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy
ICNP6
2013 Wireless network coding: Deciding when to flip the switch
abstract
Network coding has been shown to offer significant throughput benefits over store-and-forward routing in certain wireless network topologies. However, the application of network coding may not always improve the network performance. In this paper1, we provide a comprehensive analytical study, which helps in assessing when network coding is preferable to a traditional store-and-forward approach. Interestingly, our study reveals that in many topological scenarios, network coding can in fact hurt the throughput performance; in such scenarios, applying the store-and-forward approach leads to higher network throughput. We validate our analytical findings via extensive testbed experiments, and we extract guidelines on when network coding should be applied instead of store-and-forward.
Ahmed Atya, Ioannis Broustis, Shailendra Singh 0004, Dimitris Syrivelis, Srikanth V. Krishnamurthy, Thomas La Porta
INFOCOM5
2013 Trading off distortion for delay for video transmissions in wireless networks
abstract
The end-user experience in viewing a video depends on the distortion; however, also of importance is the delay experienced by the packets of the video flow since it impacts the timeliness of the information contained and the playback rate at the receiver. Unfortunately, these performance metrics are in conflict with each other in a wireless network. Packet losses can be minimized by perfectly avoiding interference by separating transmissions in time or frequency; however, this decreases the rate at which transmissions occur, and this increases delay. Relaxing the requirement for interference avoidance can lead to packet losses and thus increase distortion, but can decrease the delay for those packets that are delivered. In this paper, we investigate this trade-off between distortion and delay for video. To understand the trade-off between video quality and packet delay, we develop an analytical framework that accounts for characteristics of the network (e.g. interference, channel variations) and the video content (motion level), assuming as a basis, a simple channel access policy that provides flexibility in managing the interference in the network. We validate our model via extensive simulations. Surprisingly, we find that the trade-off depends on the specific features of the video flow: it is better to trade-off high delay for low distortion with fast motion video, but not with slow motion video. Specifically, for an increase in PSNR (a metric that quantifies distortion) from 20 to 25 dB, the penalty in terms of the increase in mean delay with fast motion video is 91 times that with slow motion video. Our simulation results further quantify the trade-offs in various scenarios.
Zi Feng, George Papageorgiou 0004, Srikanth V. Krishnamurthy, Ramesh Govindan, Thomas La Porta
INFOCOM3
2013 FluidNet: a flexible cloud-based radio access network for small cells
abstract
Cloud-based radio access networks (C-RAN) have been proposed as a cost-efficient way of deploying small cells. Unlike conventional RANs, a C-RAN decouples the baseband processing unit (BBU) from the remote radio head (RRH), allowing for centralized operation of BBUs and scalable deployment of light-weight RRHs as small cells. In this work, we argue that the intelligent configuration of the front-haul network between the BBUs and RRHs, is essential in delivering the performance and energy benefits to the RAN and the BBU pool, respectively. We then propose FluidNet - a scalable, light-weight framework for realizing the full potential of C-RAN. FluidNet deploys a logically re-configurable front-haul to apply appropriate transmission strategies in different parts of the network and hence cater effectively to both heterogeneous user profiles and dynamic traffic load patterns. FluidNet's algorithms determine configurations that maximize the traffic demand satisfied on the RAN, while simultaneously optimizing the compute resource usage in the BBU pool. We prototype FluidNet on a 6 BBU, 6 RRH WiMAX C-RAN testbed. Prototype evaluations and large-scale simulations reveal that FluidNet's ability to re-configure its front-haul and tailor transmission strategies provides a 50% improvement in satisfying traffic demands, while reducing the compute resource usage in the BBU pool by 50% compared to baseline transmission schemes.
Karthikeyan Sundaresan, Mustafa Y. Arslan, Shailendra Singh 0004, Sampath Rangarajan, Srikanth V. Krishnamurthy
MobiCom5
2013 Secret Key Extraction from Wireless Signal Strength in Real Environments
abstract
We evaluate the effectiveness of secret key extraction, for private communication between two wireless devices, from the received signal strength (RSS) variations on the wireless channel between the two devices. We use real world measurements of RSS in a variety of environments and settings. The results from our experiments with 802.11-based laptops show that in certain environments, due to lack of variations in the wireless channel, the extracted bits have very low entropy making these bits unsuitable for a secret key, an adversary can cause predictable key generation in these static environments, and in dynamic scenarios where the two devices are mobile, and/or where there is a significant movement in the environment, high entropy bits are obtained fairly quickly. Building on the strengths of existing secret key extraction approaches, we develop an environment adaptive secret key generation scheme that uses an adaptive lossy quantizer in conjunction with Cascade-based information reconciliation and privacy amplification. Our measurements show that our scheme, in comparison to the existing ones that we evaluate, performs the best in terms of generating high entropy bits at a high bit rate. The secret key bit streams generated by our scheme also pass the randomness tests of the NIST test suite that we conduct. We also build and evaluate the performance of secret key extraction using small, low-power, hand-held devices-Google Nexus One phones-that are equipped 802.11 wireless network cards. Last, we evaluate secret key extraction in a multiple input multiple output (MIMO)-like sensor network testbed that we create using multiple TelosB sensor nodes. We find that our MIMO-like sensor environment produces prohibitively high bit mismatch, which we address using an iterative distillation stage that we add to the key extraction process. Ultimately, we show that the secret key generation rate is increased when multiple sensors are involved in the key extraction process.
Sriram Nandha Premnath, Suman Jana, Jessica Croft, Prarthana Lakshmane Gowda, Mike Clark, Sneha Kumar Kasera, Neal Patwari, Srikanth V. Krishnamurthy
IEEE Trans. Mob. Comput.8
2013 ACORN: An Auto-Configuration Framework for 802.11n WLANs
abstract
The wide channels feature combines two adjacent channels to form a new, wider channel to facilitate high-data-rate transmissions in multiple-input-multiple-output (MIMO)-based IEEE 802.11n networks. Using a wider channel can exacerbate interference effects. Furthermore, contrary to what has been reported by prior studies, we find that wide channels do not always provide benefits in isolation (i.e., one link without interference) and can even degrade performance. We conduct an in-depth, experimental study to understand the implications of wide channels on throughput performance. Based on our measurements, we design an auto-configuration framework called ACORN for enterprise 802.11n WLANs. ACORN integrates the functions of user association and channel allocation since our study reveals that they are tightly coupled when wide channels are used. We show that the channel allocation problem with the constraints of wide channels is NP-complete. Thus, ACORN uses an algorithm that provides a worst-case approximation ratio of O(1/Δ + 1), with Δ being the maximum node degree in the network. We implement ACORN on our 802.11n testbed. Our evaluations show that ACORN: 1) outperforms previous approaches that are agnostic to wide channels constraints; it provides per-AP throughput gains ranging from 1.5 × 6×; and 2) in practice, its channel allocation module achieves an approximation ratio much better than the theoretically predicted O(1/Δ + 1).
Mustafa Y. Arslan, Konstantinos Pelechrinis, Ioannis Broustis, Shailendra Singh 0004, Srikanth V. Krishnamurthy, Sateesh Addepalli, Konstantina Papagiannaki
IEEE/ACM Trans. Netw.5
2013 A Resource Management System for Interference Mitigation in Enterprise OFDMA Femtocells
abstract
To meet the capacity demands from ever-increasing mobile data usage, mobile network operators are moving toward smaller cell structures. These small cells, called femtocells, use sophisticated air interface technologies such as orthogonal frequency division multiple access (OFDMA). While femtocells are expected to provide numerous benefits such as energy efficiency and better throughput, the interference resulting from their dense deployments prevents such benefits from being harnessed in practice. Thus, there is an evident need for a resource management solution to mitigate the interference that occurs between collocated femtocells. In this paper, we design and implement one of the first resource management systems, FERMI, for OFDMA-based femtocell networks. As part of its design, FERMI: 1) provides resource isolation in the frequency domain (as opposed to time) to leverage power pooling across cells to improve capacity; 2) uses measurement-driven triggers to intelligently distinguish clients that require just link adaptation from those that require resource isolation; 3) incorporates mechanisms that enable the joint scheduling of both types of clients in the same frame; and 4) employs efficient, scalable algorithms to determine a fair resource allocation across the entire network with high utilization and low overhead. We implement FERMI on a prototype four-cell WiMAX femtocell testbed and show that it yields significant gains over conventional approaches.
Mustafa Y. Arslan, Jongwon Yoon, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy, Suman Banerjee 0001
IEEE/ACM Trans. Netw.4
2013 Topology Control for Effective Interference Cancellation in Multiuser MIMO Networks
abstract
In multiuser multiple-input-multiple-output (MIMO) networks, receivers decode multiple concurrent signals using successive interference cancellation (SIC). With SIC, a weak target signal can be deciphered in the presence of stronger interfering signals. However, this is only feasible if each strong interfering signal satisfies a signal-to-noise-plus-interference ratio (SINR) requirement. This necessitates the appropriate selection of a subset of links that can be concurrently active in each receiver's neighborhood; in other words, a subtopology consisting of links that can be simultaneously active in the network is to be formed. If the selected subtopologies are of small size, the delay between the transmission opportunities on a link increases. Thus, care should be taken to form a limited number of subtopologies. We find that the problem of constructing the minimum number of subtopologies such that SIC decoding is successful with a desired probability threshold is NP-hard. Given this, we propose MUSIC, a framework that greedily forms and activates subtopologies in a way that favors successful SIC decoding with a high probability. MUSIC also ensures that the number of selected subtopologies is kept small. We provide both a centralized and a distributed version of our framework. We prove that our centralized version approximates the optimal solution for the considered problem. We also perform extensive simulations to demonstrate that: 1) MUSIC forms a small number of subtopologies that enable efficient SIC operations; the number of subtopologies formed is at most 17% larger than the optimum number of topologies, discovered through exhaustive search (in small networks); 2) MUSIC outperforms approaches that simply consider the number of antennas as a measure for determining the links that can be simultaneously active. Specifically, MUSIC provides throughput improvements of up to four times, as compared to such an approach, in various topological settings. The improvements can be directly attributable to a significantly higher probability of correct SIC based decoding with MUSIC.
Ece Gelal, Jianxia Ning, Konstantinos Pelechrinis, Tae-Suk Kim, Ioannis Broustis, Srikanth V. Krishnamurthy, Bhaskar D. Rao
IEEE/ACM Trans. Netw.6
2013 Realizing the Benefits of Wireless Network Coding in Multirate Settings
abstract
Network coding has been proposed as a technique that can potentially increase the transport capacity of a wireless network via mixing data packets at intermediate routers. However, most previous studies either assume a fixed transmission rate or do not consider the impact of using diverse rates on the network coding gain. Since in many cases, network coding implicitly relies on overhearing, the choice of the transmission rate has a big impact on the achievable gains. The use of higher rates works in favor of increasing the native throughput. However, it may in many cases work against effective overhearing. In other words, there is a tension between the achievable network coding gain and the inherent rate gain possible on a link. In this paper, our goal is to drive the network toward achieving the best tradeoff between these two contradictory effects. We design a distributed framework that: facilitates the choice of the best rate on each link while considering the need for overhearing; and dictates the choice of which decoding recipient will acknowledge the reception of an encoded packet. We demonstrate that both of these features contribute significantly toward gains in throughput. We extensively simulate our framework in a variety of topological settings. We also fully implement it on real hardware and demonstrate its applicability and performance gains via proof-of-concept experiments on our wireless testbed. We show that our framework yields throughput gains of up to 390% as compared to what is achieved in a rate-unaware network coding framework.
Tae-Suk Kim, Ioannis Broustis, Serdar Vural, Dimitris Syrivelis, Shailendra Singh 0004, Srikanth V. Krishnamurthy, Thomas La Porta
IEEE/ACM Trans. Netw.6
2013 Resource Allocation for QoS Support in Wireless Mesh Networks
abstract
Many next generation applications (such as video flows) are likely to have associated minimum data rate requirements in order to ensure satisfactory quality as perceived by end-users. In this paper, we develop a framework to address the problem of maximizing the aggregate utility of traffic flows in a multi-hop wireless network, with constraints imposed both due to self-interference and minimum rate requirements. The parameters that are tuned in order to maximize the utility are (i) transmission powers of individual nodes and (ii) the channels assigned to the different communication links. Our framework is based on using a cross-decomposition technique that takes both inter-flow interference and self-interference into account. The output of our framework is a schedule that dictates what links are to be activated in each slot and the parameters associated with each of those links. If the minimum rate constraint cannot be satisfied for all of the flows, the framework intelligently rejects a sub-set of the flows and recomputes a schedule for the remaining flows. We also design an admission control module that determines if new flows can be admitted without violating the rate requirements of the existing flows in the network. We provide numerical results to demonstrate the efficacy of our framework.
Tae-Suk Kim, Yong Yang 0009, Jennifer C. Hou, Srikanth V. Krishnamurthy
IEEE Trans. Wirel. Commun.4
2013 An integrated routing and rate adaptation framework for multi-rate multi-hop wireless networks
Tae-Suk Kim, Gentian Jakllari, Srikanth V. Krishnamurthy, Michalis Faloutsos
Wirel. Networks3
2013 UVOC-MAC: a MAC protocol for outdoor ultraviolet networks
Yiyang Li 0003, Jianxia Ning, Zhengyuan Xu, Srikanth V. Krishnamurthy, Gang Chen 0007
Wirel. Networks4
2012 Enabling private conversations on Twitter
abstract
User privacy has been an increasingly growing concern in online social networks (OSNs). While most OSNs today provide some form of privacy controls so that their users can protect their shared content from other users, these controls are typically not sufficiently expressive and/or do not provide fine-grained protection of information. In this paper, we consider the introduction of a new privacy control---group messaging on Twitter, with users having fine-grained control over who can see their messages. Specifically, we demonstrate that such a privacy control can be offered to users of Twitter today without having to wait for Twitter to make changes to its system. We do so by designing and implementing Twitsper, a wrapper around Twitter that enables private group communication among existing Twitter users while preserving Twitter's commercial interests. Our design preserves the privacy of group information (i.e., who communicates with whom) both from the Twitsper server as well as from undesired Twitsper users. Furthermore, our evaluation shows that our implementation of Twitsper imposes minimal server-side bandwidth requirements and incurs low client-side energy consumption. Our Twitsper client for Android-based devices has been downloaded by over 1000 users and its utility has been noted by several media articles.
Indrajeet Singh, Michael Butkiewicz, Harsha V. Madhyastha, Srikanth V. Krishnamurthy, Sateesh Addepalli
ACSAC4
2012 Computing while charging: building a distributed computing infrastructure using smartphones
abstract
Every night, a large number of idle smartphones are plugged into a power source for recharging the battery. Given the increasing computing capabilities of smartphones, these idle phones constitute a sizeable computing infrastructure. Therefore, for an enterprise which supplies its employees with smartphones, we argue that a computing infrastructure that leverages idle smartphones being charged overnight is an energy-efficient and cost-effective alternative to running tasks on traditional server infrastructure. While parallel execution and scheduling models exist for servers (e.g., MapReduce), smartphones present a unique set of technical challenges due to the heterogeneity in CPU clock speed, variability in network bandwidth, and lower availability compared to servers.
Mustafa Y. Arslan, Indrajeet Singh, Shailendra Singh 0004, Harsha V. Madhyastha, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy
CoNEXT6
2012 One strategy does not serve all: tailoring wireless transmission strategies to user profiles
abstract
The proliferation of smartphones and tablet devices is changing the landscape of user connectivity and data access from predominantly static users to a mix of static and mobile users. While significant advances have been made in wireless transmission strategies (e.g., network MIMO) to meet the increased demand for capacity, such strategies primarily cater to static users. To cope with growing heterogeneity in data access, it is critical to identify and optimize strategies that can cater to users of various profiles to maximize system performance and more importantly, improve users' quality of experience.
Shailendra Singh 0004, Karthikeyan Sundaresan, Mohammad Ali Amir Khojastepour, Sampath Rangarajan, Srikanth V. Krishnamurthy
HotNets5
2012 Network Coding Aware Queue Management in Multi-Rate Wireless Networks
abstract
While network coding can potentially provide significant throughput benefits by combining packets prior to forwarding them, the achievable gains are directly related to the coding opportunities at a relay that performs encoding. If the relay does not have packets destined for distinct destinations, that can be encoded together, the network coding gains could be marginal. Towards increasing the opportunities for network coding, in this paper we propose a queue management scheme, that arbitrates the rate at which distinct transmitters send packets to a common relay which applies network coding. Our queue management approach prioritizes the channel access of nodes that do not have enough enqueued packets at the common relay, thereby essentially attempting to balance the number of packets from the distinct senders at the relay. We perform extensive simulations of our approach (built as a wrapper on top of the popular network coding approach COPE) in multi-rate scenarios. We find that our approach yields throughput gains of up to 57% compared to COPE due to enhanced opportunities towards encoding packets.
Nicola De Coppi, Jianxia Ning, George Papageorgiou 0004, Michele Zorzi, Srikanth V. Krishnamurthy, Thomas La Porta
ICCCN5
2012 Forensic analysis of packet losses in wireless networks
abstract
Due to the lossy nature of wireless links, it is difficult to determine if packet losses are due to wireless-induced effects or from malicious discarding. Many prior efforts on detecting malicious packet drops rely on evidence collected via passive monitoring by neighbor nodes; however, they do not analyze the cause of packet losses. In this paper, we ask: (a) Given certain macroscopic parameters of the network (like traffic intensity and node density) what is the likelihood that evidence exists with respect to a transmission? and, (b) How can these parameters be used to perform a forensic analysis of the reason for the losses? Towards answering the above questions, we first build an analytical framework that computes the likelihood that evidence (we call this transmission evidence or TE for short) exists with respect to transmissions, in terms of a set of network parameters. We validate our analytical framework via both simulations as well as real-world experiments on two different wireless testbeds. The analytical framework is then used as a basis for a protocol within a forensic analyzer to assess the cause of packet losses and determine the likelihood of forwarding misbehaviors. Through simulations, we find that our assessments are close to the ground truth in all examined cases, with an average deviation of 2.3% from the ground truth and a worst case deviation of 15.0%.
Jianxia Ning, Shailendra Singh 0004, Konstantinos Pelechrinis, Bin Liu 0004, Srikanth V. Krishnamurthy, Ramesh Govindan
ICNP5
2012 Distortion-Resilient Routing for Video Flows in Wireless Multi-hop Networks
abstract
Traditional routing metrics designed for wireless networks are application agnostic. In this paper, we consider a wireless network where the application flows consist of video traffic. From a user-perspective, reducing the level of video distortion is critical. We ask the question “Should the routing policies change if the end-to-end video distortion is to be minimized?” Popular link-quality based routing metrics (such as ETX) do not account for dependence (in terms of congestion) across the links of a path; as a result, they can cause video flows to converge onto a few paths and thus, cause high video distortion. To account for the evolution of the video frame loss process we construct an analytical framework to first, understand and second, assess the impact of the wireless network on video distortion. The framework allows us to formulate a routing policy for minimizing distortion, based on which we design a protocol for routing video traffic. We find via simulations and testbed experiments that our protocol is efficient in reducing video distortion and minimizing the user experience degradation. Specifically, our protocol reduces the distortion by 20% over traditional methods, which significantly improves the video quality perceived by a user.
George Papageorgiou 0004, Shailendra Singh 0004, Srikanth V. Krishnamurthy, Ramesh Govindan, Thomas La Porta
ICNP3
2012 Experimental characterization of interference in OFDMA femtocell networks
abstract
The increase in mobile data usage is pushing broadband operators towards deploying smaller cells (femtocells) and sophisticated access technologies such as OFDMA. The expected high density of deployment and uncoordinated operations of femtocells however, make interference management both critical and extremely challenging. Femtocells have to use the same access technology as traditional macrocells. Given this, understanding the impact of the system design choices (originally tailored to well-planned macrocells) on interference management, forms an essential first step towards designing efficient solutions for next-generation femtocells. This in turn is the focus of our work. With extensive measurements from our WiMAX OFDMA femtocell testbed, we characterize the impact of various system design choices on interference. Based on the insights from our measurements, we discuss several implications on how to efficiently operate a femtocell network.
Mustafa Y. Arslan, Jongwon Yoon, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy, Suman Banerjee 0001
INFOCOM4
2012 Collaborative assessment of functional reliability in wireless networks
abstract
Nodes that are part of a multihop wireless network, typically deployed in mission critical settings, are expected to perform specific functions. Establishing a notion of reliability of the nodes with respect to each function (referred to as functional reliability or FR) is essential for efficient operations and management of the network. This is typically assessed based on evidence collected by nodes with regards to other nodes in the network. However, such evidence is often affected by factors such as channel induced effects and interference. In multihop contexts, unreliable intermediary relays may also influence evidence. We design a framework for collaborative assessment of the FR of nodes, with respect to different types of functions; our framework accounts for the above factors that influence evidence collection. Each node (say Chloe) in the network derives the FR of other nodes (say Jack) based on two types of evidence: (i) direct evidence, based on her direct transactions with each such node and (ii) indirect evidence, based on feedback received regarding Jack from others. Our framework is generic and is applicable in a variety of contexts. We also design a module that drastically reduces the overhead incurred in the propagation of indirect evidence at the expense of slightly increased uncertainty in the assessed FR values. We implement our framework on an indoor/outdoor wireless testbed. We show that with our framework, each node is able to determine the FR for every other node in the network with high accuracy. Our indirect evidence propagation module decreases the overhead by 37% compared to a simple flooding based evidence propagation, while the accuracy of the FR computations is decreased only by 8%. Finally, we examine the effect of different routing protocols on the accuracy of the assessed values.
Zi Feng, Konstantinos Pelechrinis, Srikanth V. Krishnamurthy, Ananthram Swami, Shyhtsun Felix Wu, Munindar P. Singh
MASS3
2012 VICO: A framework for configuring indoor visible light communication networks
abstract
Visible light communications (VLC) are gaining popularity and may provide an alternative means of communications in indoor settings. However, to date, there is very little research on the deployment or higher layer protocol design for VLC. In this paper, we first perform channel measurements using a physical layer testbed in the visible light band to understand its physical layer characteristics. Our measurements suggest that in order to increase data rates with VLC (1) the beam width of a communicating link can be shrunk, and (2) the transmission beam can be tuned to point towards the target recipient. We then perform Matlab simulations to verify that the human eye is able to accommodate the changes brought by shrinking a beam or by tuning the beam direction appropriately. As our main contribution, we then design a configuration framework for a VLC indoor local area network, which we call VICO; we leverage the above features towards achieving the highest throughput while maintaining fairness. VICO first tunes the beamwidths and pointing angles of the transmitters to configurations that provide the highest throughput for each client. It then tries to schedule transmissions while accounting for conflicts and the VLC PHY characteristics. Finally, it opportunistically tunes the idle LEDs to reinforce existing transmissions to increase throughput to the extent possible. We perform extensive simulations to demonstrate the effectiveness of VICO. We find that VICO provides as much as 5-fold increase in throughput compared to a simple scheduler that does not exploit the possible variations in beamwidth or beam-angle.
Yiyang Li 0003, Leijie Wang, Jianxia Ning, Konstantinos Pelechrinis, Srikanth V. Krishnamurthy, Zhengyuan Xu
MASS5
2012 Design and implementation of an integrated beamformer and uplink scheduler for OFDMA femtocells
abstract
Beamforming is a signal processing technique with numerous benefits. Unlike with omni-directional communications, it focuses the energy of the transmitted and/or the received signal in a particular direction. Although beamforming has been extensively studied on conventional systems such as WiFi, little is known about its practical impact on OFDMA femtocell deployments. Since OFDMA schedules multiple clients (users) in the same frame (in contrast to WiFi), designing intelligent scheduling mechanisms and at the same time leveraging beamforming, is a challenging task.
Mustafa Y. Arslan, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy, Sampath Rangarajan
MobiHoc3
2012 A case for adaptive sub-carrier level power allocation in OFDMA networks
abstract
In today's OFDMA networks, the transmission power is typically fixed and the same for all the sub-carriers that compose a channel. The sub-carriers though, experience different degrees of fading and thus, the received power is different for different sub-carriers; while some frequencies experience deep fades, others are relatively unaffected. In this paper, we make a case of redistributing the power across the sub-carriers (subject to a fixed power budget constraint) to better cope with this frequency selectivity. Specifically, we design a joint power and rate adaptation scheme (called JPRA for short) wherein power redistribution is combined with sub-carrier level rate adaptation to yield significant throughput benefits. We further consider two variants of JPRA: (a) JPRA-CR where, the power is redistributed across sub-carriers so as to support a maximum common rate (CR) across sub-carriers and (b) JPRA-MT where, the goal is to redistribute power such that the transmission time of a packet is minimized. While the first variant decreases transceiver complexity and is simpler, the second is geared towards achieving the maximum throughput possible. We implement both variants of JPRA on our WARP radio testbed. Our extensive experiments demonstrate that our scheme provides a 35% improvement in total network throughput in testbed experiments compared to FARA, a scheme where only sub-carrier level rate adaptation is used. We also perform simulations to demonstrate the efficacy of JPRA in larger scale networks.
Shailendra Singh 0004, Moloud Shahbazi, Konstantinos Pelechrinis, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy, Sateesh Addepalli
MobiHoc5
2012 A distributed resource management framework for interference mitigation in OFDMA femtocell networks
abstract
Next generation wireless networks (i.e., WiMAX, LTE) provide higher bandwidth and spectrum efficiency leveraging smaller (femto) cells with orthogonal frequency division multiple access (OFDMA). The uncoordinated, dense deployments of femtocells however, pose several unique challenges relating to interference and resource management in these networks. Towards addressing these challenges, we propose RADION, a distributed resource management framework that effectively manages interference across femtocells. RADION's core building blocks enable femtocells to opportunistically find the available resources in a completely distributed and efficient manner. Further, RADION's modular nature paves the way for different resource management solutions to be incorporated in the framework. We implement RADION on a real WiMAX femtocell testbed deployed in a typical indoor setting. We extensively evaluate two solutions integrated with RADION, both via prototype implementation and simulations and quantify their performance in terms of quick and efficient self-organization.
Jongwon Yoon, Mustafa Y. Arslan, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy, Suman Banerjee 0001
MobiHoc4
2012 Link Positions Matter: A Noncommutative Routing Metric for Wireless Mesh Networks
abstract
We revisit the problem of computing the path with the minimum cost in terms of the expected number of link layer transmissions (including retransmissions) in wireless mesh networks. Unlike previous efforts, such as the popular ETX, we account for the fact that MAC protocols (including the IEEE 802.11 MAC) incorporate a finite number of transmission attempts per packet. This in turn leads to our key observation: the performance of a path depends not only on the number of the links on the path and the quality of its links, but also, on the relative positions of the links on the path. Based on this observation, we propose ETOP, a path metric that accurately captures the expected number of link layer transmissions required for reliable end-to-end packet delivery. We analytically compute ETOP, which is not trivial, since ETOP is a noncommutative function of the link success probabilities. Although ETOP is a more involved metric, we show that the problem of computing paths with the minimum ETOP cost can be solved by a greedy algorithm. We implement and evaluate a routing approach based on ETOP on a 25-node indoor mesh network. Our experiments show that the path selection with ETOP consistently results in superior TCP goodput (by over 50 percent in many cases) compared to path selection based on ETX. We also perform an in-depth analysis of the measurements to better understand why the paths selected by ETOP improve the TCP performance.
Gentian Jakllari, Stephan J. Eidenbenz, Nicolas W. Hengartner, Srikanth V. Krishnamurthy, Michalis Faloutsos
IEEE Trans. Mob. Comput.4
2012 Detection of Selfish Manipulation of Carrier Sensing in 802.11 Networks
abstract
Recently, tuning the clear channel assessment (CCA) threshold in conjunction with power control has been considered for improving the performance of WLANs. However, we show that, CCA tuning can be exploited by selfish nodes to obtain an unfair share of the available bandwidth. Specifically, a selfish entity can manipulate the CCA threshold to ignore ongoing transmissions; this increases the probability of accessing the medium and provides the entity a higher, unfair share of the bandwidth. We experiment on our 802.11 testbed to characterize the effects of CCA tuning on both isolated links and in 802.11 WLAN configurations. We focus on AP-client(s) configurations, proposing a novel approach to detect this misbehavior. A misbehaving client is unlikely to recognize low power receptions as legitimate packets; by intelligently sending low power probe messages, an AP can efficiently detect a misbehaving node. Our key contributions are: 1) We are the first to quantify the impact of selfish CCA tuning via extensive experimentation on various 802.11 configurations. 2) We propose a lightweight scheme for detecting selfish nodes that inappropriately increase their CCAs. 3) We extensively evaluate our system on our testbed; its accuracy is 95 percent while the false positive rate is less than 5 percent.
Konstantinos Pelechrinis, Guanhua Yan, Stephan J. Eidenbenz, Srikanth V. Krishnamurthy
IEEE Trans. Mob. Comput.4
2012 Obtaining Provably Legitimate Internet Topologies
abstract
What topologies should be used to evaluate protocols for interdomain routing? Using the most current Internet topology is not practical since its size is prohibitive for detailed, packet-level interdomain simulations. Besides being of moderate size, the topology should be policy-aware, that is, it needs to represent business relationships between adjacent nodes (that represent autonomous systems). In this paper, we address this issue by providing a framework to generate small, realistic, and policy-aware topologies. We propose HBR, a novel sampling method, which exploits the inherent hierarchy of the policy-aware Internet topology. We formally prove that our approach generates connected and legitimate topologies, which are compatible with the policy-based routing conventions and rules. Using simulations, we show that HBR generates topologies that: 1) maintain the graph properties of the real topology; 2) provide reasonably realistic interdomain simulation results while reducing the computational complexity by several orders of magnitude as compared to the initial topology. Our approach provides a permanent solution to the problem of interdomain routing evaluations: Given a more accurate and complete topology, HBR can generate better small topologies in the future.
Yihua He, Michalis Faloutsos, Srikanth V. Krishnamurthy, Marek Chrobak
IEEE/ACM Trans. Netw.3
2011 Detecting Route Attraction Attacks in Wireless Networks
abstract
Selecting high performance routes in wireless networks requires the exchange of link quality information among nodes. Adversaries can manipulate this functionality by advertising fake qualities for links; by doing so, they can attract routes and subsequently launch pernicious attacks. Our measurements suggest that malicious route attraction can fatally impact throughput. We design a framework that is effective against both independent and colluding attackers. In the latter case, we consider both local and remote colluders. With local collusion, malicious nodes exchange and advertise fake routing information to increase the probability of being selected as relays. Remote collusion refers to nodes residing in distant parts of the network that (i) create sybil identities in a local neighborhood and / or (ii) utilize link quality reports to advertise fake links. Our framework combines packet signing and frequency hopping to accurately detect the adversaries. We implement the framework on our testbed and conduct experiments to assess its efficacy. We observe that our framework provides significant throughput benefits by detecting attackers with 90% accuracy.
Mustafa Y. Arslan, Konstantinos Pelechrinis, Ioannis Broustis, Srikanth V. Krishnamurthy, Prashant Krishnamurthy, Prasant Mohapatra
MASS4
2011 A Unified Metric for Routing and Rate Adaptation in Multi-Rate Wireless Mesh Networks
abstract
In this paper, we propose a new metric that is applicable both to routing and rate adaptation in multi-rate wireless mesh networks. Unlike many previous efforts, our metric is comprehensive; it considers several factors that affect end-to-end performance such as the effect of the relative positions of the links on a path when choosing the rates of operation and the importance of avoiding congested areas. We call our metric ETM (for Expected Transmission cost in Multi-rate wireless networks). We analytically derive the ETM metric. We show that the ETM metric can be used (a) to determine the best end-to-end path with a greedy routing approach and (b) it can be used to dynamically select the best transmission rate for each link on the path via a dynamic programming approach. Based on ETM, we design and implement the ETM-framework on an indoor wireless mesh network and compare its performance with that of the popular ETT and the recently proposed ETOP metrics. Our experiments show that the ETM-framework yields throughput improvements of up to 253% and 368% as compared with the ETT and ETOP frameworks.
Tae-Seok Kim, Gentian Jakllari, Srikanth V. Krishnamurthy, Michalis Faloutsos
MASS3
2011 FERMI: a femtocell resource management system forinterference mitigation in OFDMA networks
abstract
The demand for increased spectral efficiencies is driving the next generation broadband access networks towards deploying smaller cells (femtocells) with sophisticated air interface technologies (Orthogonal Frequency Division Multiple Access or OFDMA). The projected dense deployment of femtocells however, makes interference and hence resource management both critical and extremely challenging. In this paper, we design and implement one of the first resource management systems, FERMI, for OFDMA-based femtocell networks. As part of its design, FERMI (i) provides resource isolation in the frequency domain (as opposed to time) to leverage power pooling across cells to improve capacity; (ii) uses measurement-driven triggers to intelligently distinguish clients that require just link adaptation from those that require resource isolation; (iii) incorporates mechanisms that enable the joint scheduling of both types of clients in the same frame; and (iv) employs efficient, scalable algorithms to determine a fair resource allocation across the entire network with high utilization and low overhead. We implement FERMI on a prototype four-cell WiMAX femtocell testbed and show that it yields significant gains over conventional approaches.
Mustafa Y. Arslan, Jongwon Yoon, Karthikeyan Sundaresan, Srikanth V. Krishnamurthy, Suman Banerjee 0001
MobiCom4
2011 A novel neighbor discovery protocol for ultraviolet wireless networks
abstract
Ultraviolet (UV) communication is an attractive option for tactical networks or environmental monitoring. The underlying UV PHY layer has unique characteristics that render previously proposed higher layer protocols for RF communications inappropriate or inefficient. Neighbor discovery is an important functional component of a UV ad hoc wireless network. While there has been some work in UV PHY layers, there is very limited work in network study. In this paper, we propose a new neighbor discovery protocol for this setting; unlike prior protocols, our approach alleviates the negative effects of random access based collisions by choosing a leader that arbitrates the discovery process. Without prior knowledge of the number of nodes in the network, the approach facilitates neighbor discovery in a fast, fair and efficient manner. We perform extensive simulations with a realistic UV PHY layer and demonstrate that the approach reduces the required neighbor discovery time by as much as 90%. We also examine the impact of various system parameters that can be especially useful to UV network and system designers.
Leijie Wang, Yiyang Li 0003, Zhengyuan Xu, Srikanth V. Krishnamurthy
MSWiM4
2011 Coping with packet replay attacks in wireless networks
abstract
In this paper, we consider a variant of packet replay attacks wherein, an attacker simply replays overheard frames as they are, or with minor manipulations in the packet header; we refer to this as the copycat attack. When routers forward such replayed packets, the levels of congestion and interference increase in large portions of the network. Our experiments indicate that even a single attacker can degrade the route throughput by up to 61%. While simple to use techniques such as digitally signing every packet can stem the dissemination of such packets, they are resource intense. Thus, we design a lightweight detection and prevention system, COPS (for Copycat Online Prevention System), that intelligently uses a combination of digital signatures and Bloom filters to cope with the attack. With our system, the task of identifying and discarding replayed packets is distributed across a plurality of nodes on a route. We implement COPS on real hardware and perform experiments on our 42 node wireless testbed. Our measurements indicate that COPS achieves its objective; it can efficiently contain the effects of replayed packets to a local neighborhood without incurring high resource consumption penalties. Specifically, we show that COPS reduces the route throughput degradation by up to 66%.
Zi Feng, Jianxia Ning, Ioannis Broustis, Konstantinos Pelechrinis, Srikanth V. Krishnamurthy, Michalis Faloutsos
SECON5
2011 Neighbor Discovery for Ultraviolet Ad Hoc Networks
abstract
The solar blind ultraviolet (UV) scattering channel makes non-line-of-sight UV communications very attractive for military applications, particularly for communication on-the-move with low probability of detection and low probability of interception. Despite significant research effort on the UV physical layer, work on protocol design at the upper layers is quite limited. We consider a mobile ad hoc UV network, with each node equipped with a transceiver capable of transmitting in multiple directions and performing omni-directional receptions. Full-duplexing is enabled. We develop efficient neighbor discovery protocols by accounting for the unique UV physical (PHY) layer characteristics, namely varying channel qualities along different scattering directions. In addition to a list of neighbor nodes' identities, our protocols also construct and maintain a table which contains a ranked list of node pointing directions between each pair of nodes in terms of channel qualities. Our approach does not need support from the global positioning system (GPS) or temporal synchronization across nodes like many radio frequency (RF) protocols. Specifically, two algorithms are proposed with and without the need for direction synchronization. We further improve the latter by more efficiently utilizing neighbor feedback. We perform extensive simulations to evaluate our algorithms.
Yiyang Li 0003, Leijie Wang, Zhengyuan Xu, Srikanth V. Krishnamurthy
IEEE J. Sel. Areas Commun.4
2011 Directional neighbor discovery in 60 GHz indoor wireless networks
Jianxia Ning, Tae-Suk Kim, Srikanth V. Krishnamurthy, Carlos Cordeiro 0001
Perform. Evaluation3
2011 Special Section on A World of Wireless, Mobile and Multimedia Networks
Christos Gkantsidis, Srikanth V. Krishnamurthy
Pervasive Mob. Comput.2
2011 MAC Layer Throughput Estimation in Impulse-Radio UWB Networks
abstract
The inherent channel characteristics of impulse-based UWB networks affect the MAC layer performance significantly. Most previous studies on evaluating MAC protocols are based on prolonged simulations and do not account for the multiple access interference due to multipath delay spread. In this work, we develop CTU, an analytical framework for Capturing the Throughput dependencies in UWB networks, while taking into account the PHY layer effects. The key attributes of CTU are: 1) It is modular; it can be easily modified to provide a basis for evaluating a wide range of MAC protocols for impulse-based UWB networks. The only requirements are that the MAC protocol under study be based on time-hopping and the modulation scheme be pulse position modulation; these are common design decisions in UWB networks. 2) It considers the channel characteristics in addition to MAC layer effects; CTU correlates probabilistically the multipath delay profile of the channel with the packet error rate. We employ CTU to evaluate the performance of different generic medium access procedure. We compare the results with those from extensive simulations and show the high accuracy of CTU. We use CTU to assess the impact of various system parameters on the MAC layer performance; we make several interesting observations that are discussed in depth.
Ioannis Broustis, Angelos Vlavianos, Prashant Krishnamurthy, Srikanth V. Krishnamurthy
IEEE Trans. Mob. Comput.4
2011 A measurement-driven anti-jamming system for 802.11 networks
abstract
Dense, unmanaged IEEE 802.11 deployments tempt saboteurs into launching jamming attacks by injecting malicious interference. Nowadays, jammers can be portable devices that transmit intermittently at low power in order to conserve energy. In this paper, we first conduct extensive experiments on an indoor 802.11 network to assess the ability of two physical-layer functions, rate adaptation and power control, in mitigating jamming. In the presence of a jammer, we find that: 1) the use of popular rate adaptation algorithms can significantly degrade network performance; and 2) appropriate tuning of the carrier sensing threshold allows a transmitter to send packets even when being jammed and enables a receiver to capture the desired signal. Based on our findings, we build ARES, an Anti-jamming REinforcement System, which tunes the parameters of rate adaptation and power control to improve the performance in the presence of jammers. ARES ensures that operations under benign conditions are unaffected. To demonstrate the effectiveness and generality of ARES, we evaluate it in three wireless test-beds: 1) an 802.11n WLAN with MIMO nodes; 2) an 802.11a/g mesh network with mobile jammers; and 3) an 802.11a WLAN with TCP traffic. We observe that ARES improves the network throughput across all test-beds by up to 150%.
Konstantinos Pelechrinis, Ioannis Broustis, Srikanth V. Krishnamurthy, Christos Gkantsidis
IEEE/ACM Trans. Netw.3
2011 A software framework for alleviating the effects of MAC-aware jamming attacks in wireless access networks
Ioannis Broustis, Konstantinos Pelechrinis, Dimitris Syrivelis, Srikanth V. Krishnamurthy, Leandros Tassiulas
Wirel. Networks4
2010 Auto-configuration of 802.11n WLANs
abstract
Channel Bonding (CB) combines two adjacent frequency bands to form a new, wider band to facilitate high data rate transmissions in MIMO-based 802.11n networks. However, the use of a wider band with CB can exacerbate interference effects. Furthermore, CB does not always provide benefits in interference-free settings, and can even degrade performance in some cases. We conduct an in-depth, experimental study to understand the implications of CB. Based on this study we design an auto-configuration framework, ACORN, for enterprise 802.11n WLANs. ACORN integrates the functions of user association and channel allocation, since our study reveals that they are tightly coupled when CB is used. We show that the channel allocation problem with the constraints of CB is NP-complete. Thus, ACORN uses an algorithm that provides a worst case approximation ratio of [EQUATION] with Δ being the maximum node degree in the network. We implement ACORN on our 802.11n testbed. Our experiments show that ACORN (i) outperforms previous approaches that are agnostic to CB constraints; it provides per-AP throughput gains from 1.5x to 6x and (ii) in practice, its channel allocation module achieves an approximation ratio much better than [EQUATION].
Mustafa Y. Arslan, Konstantinos Pelechrinis, Ioannis Broustis, Srikanth V. Krishnamurthy, Sateesh Addepalli, Konstantina Papagiannaki
CoNEXT4
2010 On the Impact of MIMO Diversity on Higher Layer Performance
abstract
In this paper, we shed light on the cross-layer interactions between the PHY, link and routing layers in networks with MIMO links operating in the diversity mode. Many previous studies assume an overly simplistic PHY layer model that does not sufficiently capture these interactions. We show that the use of simplistic models can in fact lead to misleading conclusions with regards to the higher layer performance with MIMO diversity. Towards understanding the impact of various PHY layer features on MIMO diversity, we begin with a simple but widely-used model and progressively incorporate these features to create new models. We examine the goodness of these models by comparing the simulated performance results with each, with measurements on an indoor 802.11 n testbed. Our work reveals several interesting cross-layer dependencies that affect the gains due to MIMO diversity. In particular, we observe that relative to SISO links: (a) PHY layer gains due to MIMO diversity do not always carry over to the higher layers, (b) the use of other PHY layer features such as FEC codes significantly influence the gains due to MIMO diversity, and (c) the choice of the routing metric can impact the gains possible with MIMO.
Ece Gelal, Konstantinos Pelechrinis, Ioannis Broustis, Srikanth V. Krishnamurthy, Saif K. Mohammed, Ananthanarayanan Chockalingam, Sneha Kumar Kasera
ICDCS4
2010 Network Coding aware Rate Selection in multi-rate IEEE 802.11
abstract
Network coding has been proposed as an alternative to the conventional store-and-forward routing paradigm for data delivery in networks. When deployed in a multi-rate wireless network, network coding has to interact with rate adaptation. When multicasting packets (a requirement of network coding) in a multi-rate IEEE 802.11 wireless network, one must use care when selecting the transmission rate to use. We refer to this problem as rate selection. We analyze the performance of network coding for a small set of scenarios representative of common topologies in a network that lead to coding opportunities. Based on this analysis, we present our Network Coding aware Rate Selection (NCRS) algorithm which takes into account transmission rates used for unicast links to all multicast targets. Simulation results show that in a multi-hop wireless network, network coding with NCRS achieves up to 24% more gain over routing than network coding with other rate selection algorithms.
Raju Kumar, Srikar Tati, Felipe de Mello, Srikanth V. Krishnamurthy, Thomas La Porta
ICNP4
2010 UVOC-MAC: A MAC protocol for outdoor ultraviolet networks
abstract
As an alternative to radio-frequency (RF) communications, optical wireless communications (OWC) can support high data rates and low power operations while providing good jamming resistance. Our focus in this paper is on deep ultraviolet (UV) outdoor communications (UVOC) where solar blind and non-line-of-sight operations are attractive. Light beams from UV LED arrays serve as information carriers. In an abstract sense, this is similar to directional transmissions in RF; however, the PHY layer characteristics significantly differ due to atmospheric scattering. First, we perform extensive experiments on a UV testbed towards understanding signal propagation and the impact of the PHY on medium access. We find that UV propagation supports (a) fully duplex communications and (b) multiple data rate transmissions. Next, we propose a novel contention-based media access control (UVOC-MAC) protocol that inherently accounts for the UV PHY layer and fully exploits multi-fold spatial reuse opportunities. Evaluations via both simulations and analysis show that UVOC-MAC effectively mitigates collisions and achieves high throughput. In particular, up to a 4-fold increase in throughput and 50% reduction in collision are possible compared to a MAC protocol agnostic to the UV PHY properties.
Yiyang Li 0003, Jianxia Ning, Zhengyuan Xu, Srikanth V. Krishnamurthy, Gang Chen 0007
ICNP4
2010 Topology Control for Effective Interference Cancellation in Multi-User MIMO Networks
abstract
In Multi-User MIMO networks, receivers decode multiple concurrent signals using Successive Interference Cancellation (SIC). With SIC a weak target signal can be deciphered in the presence of stronger interfering signals. However, this is only feasible if each strong interfering signal satisfies a signal-to-noise-plus-interference ratio (SINR) requirement. This necessitates the appropriate selection of a subset of links that can be concurrently active in each receiver's neighborhood; in other words, a sub-topology consisting of links that can be simultaneously active in the network is to be formed. If the selected sub-topologies are of small size, the delay between the transmission opportunities on a link increases. Thus, care should be taken to form a limited number of sub-topologies. We find that the problem of constructing the minimum number of sub-topologies such that SIC decoding is successful with a desired probability threshold, is NP-hard. Given this, we propose MUSIC, a framework that greedily forms and activates sub-topologies, in a way that favors successful SIC decoding with a high probability. MUSIC also ensures that the number of selected sub-topologies is kept small. We provide both a centralized and a distributed version of our framework. We prove that our centralized version approximates the optimal solution for the considered problem. We also perform extensive simulations to demonstrate that (i) MUSIC forms a small number of sub-topologies that enable efficient SIC operations; the number of sub-topologies formed is at most 17% larger than the optimum number of topologies, discovered through exhaustive search (in small networks). (ii) MUSIC outperforms approaches that simply consider the number of antennas as a measure for determining the links that can be simultaneously active. Specifically, MUSIC provides throughput improvements of up to 4 times, as compared to such an approach, in various topological settings. The improvements can be directly attributable to a significantly higher probability of correct SIC based decoding with MUSIC.
Ece Gelal, Konstantinos Pelechrinis, Tae-Suk Kim, Ioannis Broustis, Srikanth V. Krishnamurthy, Bhaskar D. Rao
INFOCOM5
2010 A Framework for Joint Network Coding and Transmission Rate Control in Wireless Networks
abstract
Network coding has been proposed as a technique that can potentially increase the transport capacity of a wireless network via processing and mixing of data packets at intermediate routers. However, most previous studies either assume a fixed transmission rate or do not consider the impact of using diverse rates on the network coding gain. Since in many cases, network coding implicitly relies on overhearing, the choice of the transmission rate has a big impact on the achievable gains. The use of higher rates works in favor of increasing the native throughput; however, it may in many cases work against effective overhearing. In other words, there is a tension between the achievable network coding gain and the inherent rate gain possible on a link. In this paper our goal is to drive the network towards achieving the best trade-off between these two contradictory effects. Towards this, we design a distributed framework that (a) facilitates the choice of the best rate on each link while considering the need for overhearing and (b) dictates the choice of which decoding recipient will acknowledge the reception of an encoded packet. We demonstrate that both of these features contribute significantly towards gains in throughput. We extensively simulate our framework in a variety of topological settings. We also fully implement it on real hardware and demonstrate its applicability and performance gains via proof-of-concept experiments on our wireless testbed. We show that our framework yields throughput gains of up to 390% as compared to what is achieved in a rate-unaware network coding framework.
Tae-Suk Kim, Serdar Vural, Ioannis Broustis, Dimitris Syrivelis, Srikanth V. Krishnamurthy, Thomas La Porta
INFOCOM5
2010 A simple conceptual generator for the Internet graph
abstract
The evolution of the Internet during the last years, has lead to a dramatic increase in the size of its representation as a graph at the Autonomous System (AS) level. Reproducing a smaller size snapshot of the AS graph is important for studying protocols in realistic settings. The objective of our work, is to create a generator that accurately emulates and reproduces the distinctive properties of the Internet graph. Our approach is based on (a) the incorporation of the jellyfish-like structure of the Internet and (b) the consideration of the peer-to-peer and customer-provider relations between ASs. We are the first to capture the distinctive structure of the Internet graph together with utilizing the information provided by the AS relationships in order to create a tool for generating a realistic representation. Compared with existing generators, our tool does not try to satisfy specific metrics; instead, it tries to remain faithful to the conceptual model of the Internet structure. In addition, our approach can lead to (i) the identification of important attributes and patterns in the Internet AS topology, and (ii) the extraction of valuable information on various relationships between ASs and the corresponding impact on the Internet structure.We implement our graph generator and evaluate it using one of the largest and most recent datasets for the AS topology. Our evaluations clearly show the ability of our tool to capture the structural properties of the Internet topology at the AS level with high accuracy. Finally, we discuss how our generator can not only reproduce, but also shrink the input graph while maintaining its unique structure and properties.
Theodoros Lappas, Konstantinos Pelechrinis, Michalis Faloutsos, Srikanth V. Krishnamurthy
LANMAN4
2010 On the Uplink Capacity of Hybrid Cellular Ad Hoc Networks
abstract
Towards increasing spatial reuse, cellular networks may be augmented with ad hoc connectivity. In the resulting hybrid network, the coverage area of the base station (BS) is reduced and the users within this area relay packets from/to the users outside. With this approach, shorter range, higher-rate links are used; this favors an increase in spatial reuse and thus, the achievable capacity. However, multi-hop relaying overhead can hurt capacity. In this paper, we analytically compute the uplink capacity, defined as an upper bound on the achievable throughput under max-min fairness. To gage the tightness of the bound, we seek to find the optimal transmission schedule for delivering the packets from the nodes in a cell to the BS. In general, constructing the optimal uplink schedule is NP-hard. We develop a heuristic approach and show via simulations that the resulting performance is close to the derived capacity bound. Our results suggest that (a) the hybrid network can achieve up to a 200 % increase in the uplink capacity compared to a pure cellular network, and (b) the simulated throughput is close to the analytically computed capacity showing that our bound is tight.
Serdar Vural, Lap Kong Law, Srikanth V. Krishnamurthy, Michalis Faloutsos
SECON3
2010 Quantifying the Overhead Due to Routing Probes in Multi-Rate WMNs
abstract
The selection of high-throughput routes is a key element towards improving the performance of wireless multihop networks. While several routing metrics have been proposed in the literature, it has been shown that link-quality aware metrics can provide significantly higher end-to-end throughput. To date, the online computation of such metrics requires the periodic transmission of probe packets at all available transmission rates. However, our link level measurement study on two different 802.11 testbeds demonstrates that: (a) multi-rate probe transmissions increase the number of collisions and enforce nodes to reside in the back-off state for prolonged time periods, and (b) the extent of performance degradation depends on the network density; a network-wide throughput reduction of the order of 400% is possible. In addition, our measurements show that the impact of probing in terms of end-to-end performance can be devastating. In particular, the probing functionality can pose a significant degradation in the end-to-end throughput of a single flow, by at least 35% and as high as 90%, depending on the probing frequency and network density. Finally, we discuss different alternatives to multi-rate probing for the online computation of such metrics.
Ioannis Broustis, Konstantinos Pelechrinis, Dimitris Syrivelis, Srikanth V. Krishnamurthy, Leandros Tassiulas
WCNC4
2010 Measurement-Driven Guidelines for 802.11 WLAN Design
abstract
Dense deployments of WLANs suffer from increased interference and, as a result, reduced capacity. There are three main functions used to improve the overall network capacity: 1) intelligent frequency allocation across access points (APs); 2) load-balancing of user affiliations across APs; and 3) adaptive power control for each AP. Several algorithms have been proposed in each category, but so far, their evaluation has been limited to: a) each approach in isolation; and b) simulations or small-scale testbeds. In this paper, we ask the question: What is the best way to combine these different functions? Our focus is to fully explore the interdependencies between the three functions in order to understand when and how to deploy them on a network. We follow a measurement-driven study to quantify the effects of three previously proposed optimization schemes (one for each category) on a relatively large testbed and in many different scenarios. Surprisingly, we find that blindly applying all the three optimization schemes is not always preferable; it can sometimes degrade the performance by as much as 24% compared to using only two of the schemes. We discover that there are explicit conditions that are conducive for applying specific combinations of the optimization schemes. We capture these conditions within a comprehensive framework, which we call measurement-driven guidelines (MDG). While we derive such guidelines based on measurements on one experimental testbed, we test their applicability and efficacy on a second testbed in a different location. We show that our framework improves network capacity consistently across both testbeds, with improvements ranging from 22% to 142% with 802.11a, and 103% to 274% with 802.11g.
Ioannis Broustis, Konstantina Papagiannaki, Srikanth V. Krishnamurthy, Michalis Faloutsos, Vivek P. Mhatre
IEEE/ACM Trans. Netw.3
2010 Downlink capacity of hybrid cellular ad hoc networks
Lap Kong Law, Konstantinos Pelechrinis, Srikanth V. Krishnamurthy, Michalis Faloutsos
IEEE/ACM Trans. Netw.3
2010 On the Efficacy of Frequency Hopping in Coping with Jamming Attacks in 802.11 Networks
abstract
Frequency hopping (FH) has been the most popularly considered approach for alleviating the effects of jamming attacks. We re-examine, the efficacy of FH based on both experimentation and analysis. Briefly, the limitations of FH are: (a) the energy spill over between adjacent channels that are considered to be orthogonal, and (b) the small number of available orthogonal bands. In a nutshell, the main contributions of our work are: (a) Construction of a measurement-driven game theoretic framework which models the interactions between a jammer and a communication link employing FH. Our model accounts for the above limiting factors and provides bounds on the performance of proactive FH in coping with jamming. (b) Extensive experimentation to quantify the impact of a jammer on 802.11a/g/n networks. Interestingly, we find that 802.11n devices can be more vulnerable to jamming as compared with legacy devices. We carefully analyze the reasons behind this observation. (c) Application of our framework to quantify the efficacy of proactive FH and validation of our analytical bounds across various 802.11 network configurations. (d) Formal derivation of the optimal strategies for both the link and the jammer in 802.11 networks. Our results demonstrate that FH seems to be inadequate in coping with jamming attacks in current 802.11 networks.
Konstantinos Pelechrinis, Christos Koufogiannakis, Srikanth V. Krishnamurthy
IEEE Trans. Wirel. Commun.3
2009 ARES: an anti-jamming reinforcement system for 802.11 networks
abstract
Dense, unmanaged 802.11 deployments tempt saboteurs into launching jamming attacks by injecting malicious interference. Nowadays, jammers can be portable devices that transmit intermittently at low power in order to conserve energy. In this paper, we first conduct extensive experiments on an indoor 802.11 network to assess the ability of two physical layer functions, rate adaptation and power control, in mitigating jamming. In the presence of a jammer we find that: (a) the use of popular rate adaptation algorithms can significantly degrade network performance and, (b) appropriate tuning of the carrier sensing threshold allows a transmitter to send packets even when being jammed and enables a receiver capture the desired signal. Based on our findings, we build ARES, an Anti-jamming REinforcement System, which tunes the parameters of rate adaptation and power control to improve the performance in the presence of jammers. ARES ensures that operations under benign conditions are unaffected. To demonstrate the effectiveness and generality of ARES, we evaluate it in three wireless testbeds: (a) an 802.11n WLAN with MIMO nodes, (b) an 802.11a/g mesh network with mobile jammers and (c) an 802.11a WLAN with TCP traffic. We observe that ARES improves the network throughput across all testbeds by up to 150%.
Konstantinos Pelechrinis, Ioannis Broustis, Srikanth V. Krishnamurthy, Christos Gkantsidis
CoNEXT3
2009 Lightweight Jammer Localization in Wireless Networks: System Design and Implementation
abstract
Jamming attacks have become prevalent during the last few years, due to the shared nature and the open access to the wireless medium. Finding the location of a jamming device is of great importance for restoring normal network operations. After detecting the malicious node we want to find its position, in order for further security actions to be taken. Our goal in this paper is the design and implementation of a simple, lightweight and generic localization algorithm. Our scheme is based on the principles of the gradient descent minimization algorithm. The key observation is that the packet delivery ratio (PDR) has lower values as we move closer to the jammer. Hence, the use of a gradient-based scheme, operating on the discrete plane of the network topology, can help locate the jamming device. The contributions of our work are the following: (a) we demonstrate, through analysis and experimentation, the way that the jamming effects propagate through the network in terms of the observed PDR. (b) we design a distributed, lightweight jammer localization system which does not require any modifications to the driver/firmware of commercial NICs. (c) We implement and evaluate our localization system on our 802.11 indoor testbed. An attractive and important feature of our system is that it does not rely on special hardware.
Konstantinos Pelechrinis, Iordanis Koutsopoulos, Ioannis Broustis, Srikanth V. Krishnamurthy
GLOBECOM4
2009 Detecting Selfish Exploitation of Carrier Sensing in 802.11 Networks
abstract
Recently, tuning the clear channel assessment (CCA) threshold in conjunction with power control has been considered for improving the performance of Wireless LANs. However, CCA tuning can be exploited by selfish nodes in order to obtain an unfair share of the available bandwidth. In particular, by increasing the CCA threshold, a selfish client can manipulate the carrier sensing mechanism to ignore the presence of other transmissions on the medium; consequently, it increases the probability of accessing the medium and therefore obtains a higher, unfair share of the available bandwidth. In this paper, we propose a novel approach to detect this misbehavior in WLANs. A key insight that leads to our approach is that a misbehaving node that has increased its CCA is unlikely to recognize low power receptions as legitimate packets; by intelligently sending low power probe messages, an AP can detect a misbehaving node with high probability. In a nutshell, our contributions are as follows: (a) We are the first to quantify the impact of selfish CCA tuning via extensive experimentation (b) We propose a novel lightweight scheme for detecting selfish nodes that inappropriately increase their CCA thresholds; we call our scheme CMD (for carrier sensing misbehavior detection) (c) We perform extensive evaluations on an indoor 802.11 WLAN testbed to demonstrate that CMD detects misbehaving users with very high accuracy (approximately 95 % of the time). Furthermore, it only incurs a false positive rate of less than 5 %.
Konstantinos Pelechrinis, Guanhua Yan, Stephan J. Eidenbenz, Srikanth V. Krishnamurthy
INFOCOM4
2009 On the effectiveness of secret key extraction from wireless signal strength in real environments
abstract
We evaluate the effectiveness of secret key extraction, for private communication between two wireless devices, from the received signal strength (RSS) variations on the wireless channel between the two devices. We use real world measurements of RSS in a variety of environments and settings. Our experimental results show that (i) in certain environments, due to lack of variations in the wireless channel, the extracted bits have very low entropy making these bits unsuitable for a secret key, (ii) an adversary can cause predictable key generation in these static environments, and (iii) in dynamic scenarios where the two devices are mobile, and/or where there is a significant movement in the environment, high entropy bits are obtained fairly quickly. Building on the strengths of existing secret key extraction approaches, we develop an environment adaptive secret key generation scheme that uses an adaptive lossy quantizer in conjunction with Cascade-based information reconciliation [7] and privacy amplification [14]. Our measurements show that our scheme, in comparison to the existing ones that we evaluate, performs the best in terms of generating high entropy bits at a high bit rate. The secret key bit streams generated by our scheme also pass the randomness tests of the NIST test suite [21] that we conduct.
Suman Jana, Sriram Nandha Premnath, Mike Clark, Sneha Kumar Kasera, Neal Patwari, Srikanth V. Krishnamurthy
MobiCom6
2009 Directional neighbor discovery in 60 GHz indoor wireless networks
abstract
The unlicensed 60 GHz band brings the promise of multi-gigabit data rates to support new applications such as high definition video over wireless links. Signal propagation in the 60 GHz band significantly differs from that in the traditionally used 2.4 and 5 GHz bands. The propagation and penetration losses in the 60 GHz band are much higher. Furthermore, the signals are often reflected in indoor settings. Previous physical layer studies show that the use of directional antennas can significantly help in coping with these effects. In this paper, we address the problem of neighbor discovery in the 60 GHz band. We account for not only discovery via direct line-of-sight paths, but also via reflected beams. To the best of our knowledge, none of the previous efforts on higher layer protocols for use with directional antennas account for reflections. We consider two approaches for neighbor discovery (a) direct discovery where each node explicitly discovers its neighbors and, (b) gossip-based discovery where nodes exchange information with regards to their already discovered neighbors. We develop analytical models to capture the performance of the two approaches and validate the models via simulations in indoor settings with obstacles that reflect the transmitted signals. As one might expect, the gossip based discovery incurs a lower neighbor-discovery latency than direct discovery. We examine the impact of system parameters such as varying beamwidth and node density. Our study provides insights on the right choice of system parameters for efficient neighbor discovery in the 60 GHz regime.
Jianxia Ning, Tae-Suk Kim, Srikanth V. Krishnamurthy, Carlos Cordeiro 0001
MSWiM3
2009 Cross-layer Enhanced Source Location Privacy in Sensor Networks
abstract
Source location privacy is an important issue in sensor network monitoring applications. It is difficult to be addressed by traditional security mechanisms, because an external attacker may perform simple traffic analysis to trace back to the event source. Solutions such as flooding or using dummy messages have the drawback of introducing a large amount of message overhead. In this paper, we avoid using network-wide dummy messages by utilizing beacons at the MAC layer. Beacons are sent out regularly, which essentially forms a constant-rate of dummy messages. Using beacons to replace the dummy messages may increase the delivery delay of event information because beacons are only sent out at the predefined beacon interval, but this latency can be controlled. To do this, we propose a cross- layer solution in which the event information is first propagated several hops through a MAC-layer beacon. Then, it is propagated at the routing layer to the destination to avoid further beacon delays. Simulation results show that our cross-layer solutions can maintain low message overhead and high privacy, while controlling delay.
Wenhui Hu, Sencun Zhu, Guohong Cao, Srikanth V. Krishnamurthy, Thomas La Porta
SECON5
2009 FIJI: Fighting Implicit Jamming in 802.11 WLANs
Ioannis Broustis, Konstantinos Pelechrinis, Dimitris Syrivelis, Srikanth V. Krishnamurthy, Leandros Tassiulas
SecureComm4
2009 Joint resource allocation and admission control in wireless mesh networks
abstract
Many next generation applications (such as video flows) are likely to have associated minimum data rate requirements to ensure satisfactory quality as perceived by end-users. While there have been prior approaches on supporting quality-of-service (QoS) in mesh networks, they have largely ignored the issues that arise due to self-interference, the interference between different link layer transmissions of a single flow along a multi-hop path. In this paper, we develop a framework to address the problem of maximizing the aggregate utility of traffic flows in wireless mesh networks, with constraints imposed both due to self-interference and minimum rate requirements. The output of our framework is a schedule that dictates which links are to be activated simultaneously, and provides specifications of the resources associated with each of those links. Utilizing the proposed framework as a basis, we build an admission control module that intelligently manages the resources among the flows in the network and admits as many new flows as possible without violating the QoS of the existing flows. We provide numerical results to demonstrate the efficacy of our framework.
Tae-Suk Kim, Yong Yang 0009, Jennifer C. Hou, Srikanth V. Krishnamurthy
WiOpt4
2009 Gaming the jammer: Is frequency hopping effective?
abstract
Frequency hopping has been the most popularly considered approach for alleviating the effects of jamming attacks. In this paper, we provide a novel, measurement-driven, game theoretic framework that captures the interactions between a communication link and an adversarial jammer, possibly with multiple jamming devices, in a wireless network employing frequency hopping (FH). The framework can be used to quantify the efficacy of FH as a jamming countermeasure. Our model accounts for two important factors that affect the aforementioned interactions: (a) the number of orthogonal channels available for use and (b) the frequency separation between these orthogonal bands. If the latter is small, then the energy spill over between two adjacent channels (considered orthogonal) is high; as a result a jammer on an orthogonal band that is adjacent to that used by a legitimate communication, can be extremely effective. We account for both these factors and using our framework we provide bounds on the performance of proactive frequency hopping in alleviating the impact of a jammer. The main contributions of our work are: (a) Construction of a measurement driven game theoretic framework which models the interactions between a jammer and a communication link that employ FH. (b) Extensive experimentation on our indoor testbed in order to quantify the impact of a jammer in a 802.11a/g network. (c) Application of our framework to quantify the efficacy of proactive FH across a variety of 802.11 network configurations. (d) Formal derivation of the optimal strategies for both the link and the jammer in 802.11 networks. Our results demonstrate that frequency hopping is largely inadequate in coping with jamming attacks in current 802.11 networks. In particular, we show that if current systems were to support hundreds of additional channels, FH would form a robust jamming countermeasure.
Konstantinos Pelechrinis, Christos Koufogiannakis, Srikanth V. Krishnamurthy
WiOpt3
2009 Topology Management in Directional Antenna-Equipped Ad Hoc Networks
abstract
With fully directional communications, nodes must track the positions of their neighbors so that communication with these neighbors is feasible when needed. Tracking process introduces an overhead, which increases with the number of discovered neighbors. The overhead can be reduced if nodes maintain only a subset of their neighbors; however, this may increase the length of paths between node pairs in the network. In this work, we study the tradeoffs between node degree and path stretch. We first design a topology control algorithm to optimize this tradeoff. Assuming that nodes communicate with their directional neighbors using circular directional transmissions, we model the original graph as a unit disk graph (UDG). Given a UDG G, our algorithm finds a sparse subgraph G' with a maximum degree of 6, and connecting each node pair u,v by a path of length hopsG(u, v) = O(hopsG(u, v) + log Delta), where Delta is the maximum degree in G, hopsG'(u, v) denotes length of the shortest path between u, v in G. We show that this result is near-optimal. Based on the insights gained from this design, we next construct a simpler, more practical scheme that integrates fully-directional neighbor discovery and maintenance with topology control strategy. We simulate both algorithms and compare their performances.
Ece Gelal, Gentian Jakllari, Srikanth V. Krishnamurthy, Neal E. Young
IEEE Trans. Mob. Comput.3
2009 Lord of the links: a framework for discovering missing links in the internet topology
Yihua He, Georgos Siganos, Michalis Faloutsos, Srikanth V. Krishnamurthy
IEEE/ACM Trans. Netw.4
2008 CTU: Capturing Throughput Dependencies in UWB Networks
abstract
The inherent channel characteristics of impulse-based UWB networks affect the MAC layer performance significantly. Previous studies on evaluating MAC protocols are based on prolonged simulations, and do not account for the multiple-access interference that arises due to multipath delay spread. In this work, we develop CTU, an analytical framework that captures the performance of MAC protocols, while taking into account the underlying PHY layer effects. The key attributes that make CTU novel are: (a) It is modular and therefore flexible; it can be easily modified to provide a basis for characterizing and evaluating a wide range of MAC protocols designed for impulse-based UWB networks. The only requirements are that the MAC protocol under study be based on time-hopping, and the modulation scheme be pulse position modulation; these are common design decisions in most impulse based UWB networks, (b) It considers the channel characteristics in addition to MAC layer effects; in particular, CTU correlates probabilistically the multipath delay profile of the channel with the packet error rate. We employ CTU to evaluate the performance of a generic medium access procedure. We compare the results with those from extensive simulations and show the high accuracy of CTU. We use CTU to assess the impact of various system parameters on the MAC layer performance; we make several interesting observations that are discussed in depth.
Ioannis Broustis, Angelos Vlavianos, Prashant Krishnamurthy, Srikanth V. Krishnamurthy
INFOCOM4
2008 Policy-Aware Topologies for Efficient Inter-Domain Routing Evaluations
abstract
The Internet community has not reached a consensus on an appropriate topological model for evaluating the performance of inter-domain routing protocols. Using the current Internet topology is not realistic, since its size is prohibitively large for, say, a packet-level BGP simulation. Furthermore, routing policies, which play a critical role in inter-domain routing, are often ignored in many simulation studies. In this paper, we address this issue by designing an algorithm to generate small-scale, realistic, and policy-aware topologies. We propose HBR, a network sampling method, which produces topologies that preserve the fundamental properties of the Internet graph, including, in particular, its hierarchical structure. Our approach provides a long-term solution to the difficult problem of AS-level routing evaluations: it can be used to generate small realistic topologies in the future, starting from any newer or more complete Internet instance.
Yihua He, Michalis Faloutsos, Srikanth V. Krishnamurthy, Marek Chrobak
INFOCOM3
2008 Link Positions Matter: A Noncommutative Routing Metric for Wireless Mesh Network
abstract
We revisit the problem of computing the path with the minimum cost in terms of the expected number of link layer transmissions (including retransmissions) in wireless mesh networks. Unlike previous efforts, such as the popular ETX, we account for the fact that MAC protocols (including the IEEE 802.11 MAC) incorporate a finite number of transmission attempts per packet. This in turn leads to our key observation: the performance of a path depends not only on the number of the links on the path and the quality of its links, but also, on the relative positions of the links on the path. Based on this observation, we propose ETOP, a path metric that accurately captures the expected number of link layer transmissions required for reliable end-to-end packet delivery. We analytically compute ETOP, which is not trivial, since ETOP is a noncommutative function of the link success probabilities. Although ETOP is a more involved metric, we show that the problem of computing paths with the minimum ETOP cost can be solved by a greedy algorithm. We implement and evaluate a routing approach based on ETOP on a 25-node indoor mesh network. Our experiments show that the path selection with ETOP consistently results in superior TCP goodput (by over 50% in many cases) compared to path selection based on ETX. We also perform an in-depth analysis of the measurements to better understand why the paths selected by ETOP improve the TCP performance.
Gentian Jakllari, Stephan J. Eidenbenz, Nicolas W. Hengartner, Srikanth V. Krishnamurthy, Michalis Faloutsos
INFOCOM4
2008 Capacity of Hybrid Cellular-Ad Hoc Data Networks
abstract
In this paper, towards improving spatial reuse in a cellular network, we consider augmenting it with wireless ad hoc connectivity. The coverage area of each base-station is reduced and the users that are within the area relay traffic to nodes outside the area; these users further relay data to more distant users within the cell. The resulting network is referred to as a hybrid network. While this approach can result in shorter range higher-rate links and improved spatial reuse which, together favor a capacity increase, it relies on multi-hop forwarding which is detrimental to the overall capacity. Our objective in this work is to evaluate the impact of these conflicting factors on the capacity of the hybrid network and determine if this capacity is higher than that of the original cellular network. We formally define the capacity of the network as the maximum possible downlink throughput under the conditions of max-min fairness. We analytically compute the capacity of a two-dimensional hybrid network withregularplacements of base-stations (BSs) and users. We validate our analytical results via simulations. Our studies demonstrate that capacity improvements are possible in certain parametric regimes in which the penalty due to multi-hop relaying does not outweigh the gains due to spatial reuse and shorter higher-rate links. Our simulations also demonstrate that if the users are placed randomly, the behavioral results are similar to that with regular placements of users.
Lap Kong Law, Srikanth V. Krishnamurthy, Michalis Faloutsos
INFOCOM2
2008 Assessing link quality in IEEE 802.11 Wireless Networks: Which is the right metric?
abstract
The accurate determination of the link quality is critical for ensuring that functionalities such as intelligent routing, load-balancing, power control and frequency selection operate efficiently. There are 4 primary metrics for capturing the quality of a wireless link: RSSI (Received Signal Strength Indication), SINR (Signal-to-Interference-plus-Noise Ratio), PDR (Packet-Delivery Ratio), and BER (Bit-Error Rate). In this paper, we perform a measurement-based study in order to answer the question: which is the appropriate metric to use, and under what conditions? We evaluate the relative accuracy of each metric by conducting experiments with multiple transmission rates and varying levels of interference on a large set of links. We observe that each metric has advantages and projects one or more limitations. Our study suggests that a careful consideration of these limitations is essential, and provides guidelines on the applicability of each metric.
Angelos Vlavianos, Lap Kong Law, Ioannis Broustis, Srikanth V. Krishnamurthy, Michalis Faloutsos
PIMRC4
2008 Cluster-based congestion control for sensor networks
abstract
In wireless sensor networks, multiple flows from data collecting sensors to an aggregating sink could traverse paths that are largely interference coupled. These interference effects manifest themselves as congestion, and cause the flows to experience high packet loss and arbitrary packet delays. This is particularly problematic in event-based sensor networks (such as those in disaster recovery missions) where some flows are of greater importance than others and require a higher fidelity in terms of packet delivery and timeliness. In this paper we present COMUT (COngestion control for MUlti-class Traffic), a distributed cluster-based mechanism for supporting multiple classes of traffic in sensor networks. COMUT is based on the self-organization of the network into clusters , each of which autonomously and proactively monitors congestion within its localized scope. The clusters then exchange appropriate information to facilitate system wide rate control where, each data source, depending on the relative importance of its data flow and the experienced congestion en route the sink, is coerced into controlling its rate. Our simulation results demonstrate that (i) our techniques are highly effective in dealing with multiple, interfering flows and in achieving high delivery ratios and low delays compared to traditional approaches, (ii) operate successfully over multiple underlying routing protocols, (iii) provide higher throughput to higher importance flows, (iv) are responsive to failures and, finally, (v) achieve substantial energy savings due to the considerable reduction in packet drops via the effective regulation of the network load.
Kyriakos Karenos, Vana Kalogeraki, Srikanth V. Krishnamurthy
ACM Trans. Sens. Networks3
2007 Routing amid Colluding Attackers
abstract
We propose the first practical solution to the longstanding problem of secure wireless routing in the presence of colluding attackers. Our secure routing protocol, Sprout, continuously tries new routes to the destination. Routes are probabilistically generated, with complete disregard for performance metrics. This makes Sprout uniquely resilient to attack: it cannot be tempted by shortcuts. In order to avoid compromised routes, and to ensure good overall performance, the quality of each active route is monitored by means of signed end-to-end acknowledgments. The amount of traffic sent on each route is adjusted accordingly. Sprout effectively mitigates the vast majority of known routing layer attacks, even when under assault from a large number of colluding attackers. Experiments on our 31-node testbed demonstrates the real-world performance of Sprout in terms of packet delivery ratio, round-trip times and TCP throughput. Our security analysis and simulation results show that Sprout is able to quickly find working paths in networks of hundreds of nodes and dozens or more attackers. For example, in a network of 200 nodes and an astounding 64 attackers, Sprout, on average, found a successful route within less than 10 attempts. Yet, in benign settings, Sprout provides TCP throughput within 15% of the shortest path throughput Overall, Sprout consistently delivers high, reliable performance in benign as well as hostile environments.
Jakob Eriksson, Michalis Faloutsos, Srikanth V. Krishnamurthy
ICNP3
2007 MDG: measurement-driven guidelines for 802.11 wlan design
abstract
Dense deployments of WLANs suffer from increased interference and as a result, reduced capacity. There are three main functions used to improve the overall network capacity: a) intelligent frequency allocation across APs, b) load-balancing of user affiliations across APs, and c) adaptive power-control for each AP. Several algorithms have been proposed in each category, but so far, their evaluation has been limited to: (a) each approach in isolation and, (b)simulations or small-scale testbeds. In this paper, we ask the question: what is the best way to combine these different functions? Our focus is to fully explore the interdependencies between the three functions in order to understand when and how to deploy them on a network. We follow a measurement-driven study to quantify the effects of three previously proposed optimization schemes (one for each category) on a relatively large testbed and in many different scenarios. Surprisingly, we find that blindly applying all the three optimization schemes is not always preferable; it can sometimes degrade the performance by as much as 24% compared to using only two of the schemes. We discover that there are explicit conditions that are conducive for applying specific combinations of the optimization schemes. We capture those conditions within a comprehensive framework, which we call MDG (Measurement-Driven Guidelines). While we derive suchguidelines based on measurements on one experimental testbed, we test their applicability and efficacy on a second testbed in a different location. We show that our framework improves network capacity consistently acrossboth testbeds, with improvements ranging from 22% to 142% with 802.11a, and 103% to 274% with 802.11g.
Ioannis Broustis, Konstantina Papagiannaki, Srikanth V. Krishnamurthy, Michalis Faloutsos, Vivek P. Mhatre
MobiCom3
2007 Revisiting minimum cost reliable routing in wireless mesh networks
abstract
We revisit the problem of computing the path with the minimum cost in terms of the expected number of link layer retransmissions in wireless mesh networks. Unlike previous efforts (such as the popular ETX) we account for the fact that link layer protocols (such as the IEEE 802.11 MAC) incorporate a non-zero but finite number of retransmission attempts per packet. A key observation that motivates this work is that the performance of a path depends not only on the number of links on the path and their qualities, but also on the relative positions of the links on the path. In particular, the closer a lossy link to the destination, the higher is its impact on the performance of that path. We design a new path metricthat captures all of the above factors and we call this metric ETOP. In this paper, we provide a synopsis of the analytical computation of ETOP. We also implement a routing strategy based on ETOP on a 25-node experimental testbed and provide sample results to showcase the performance with ETOP.
Gentian Jakllari, Stephan J. Eidenbenz, Nicolas W. Hengartner, Srikanth V. Krishnamurthy, Michalis Faloutsos
MobiCom4
2007 A Systematic Framework for Unearthing the Missing Links: Measurements and Impact
Yihua He, Georgos Siganos, Michalis Faloutsos, Srikanth V. Krishnamurthy
NSDI4
2007 Implications of Power Control in Wireless Networks: A Quantitative Study
Ioannis Broustis, Jakob Eriksson, Srikanth V. Krishnamurthy, Michalis Faloutsos
PAM3
2007 A novel adaptive protocol for lightweight efficient multicasting in ad hoc networks
Lap Kong Law, Srikanth V. Krishnamurthy, Michalis Faloutsos
Comput. Networks2
2007 Handling asymmetry in power heterogeneous ad hoc networks
Vasudev Shah, Ece Gelal, Srikanth V. Krishnamurthy
Comput. Networks3
2007 Predictive channel reservation for handoff prioritization in wireless cellular networks
Zhenqiang Ye, Lap Kong Law, Srikanth V. Krishnamurthy, Zhong Xu, Suvidhean Dhirakaosal, Satish K. Tripathi, Mart L. Molle
Comput. Networks3
2007 On broadcasting with cooperative diversity in multi-hop wireless networks
abstract
Cooperative diversity facilitates spatio-temporal communications without requiring the deployment of physical antenna arrays. While physical layer studies on cooperative diversity have been extensive, higher layer protocols which translate the achievable reduction in the SNR per bit for a given target BER, into system wide performance enhancements are yet to mature. The challenge is that appropriate higher layer functions are needed in order to enable cooperative diversity at the physical layer. We focus on network-wide broadcasting with the use of cooperative diversity in ad hoc networks. We design a novel distributed network-wide broadcasting protocol that takes into account the physical layer dependencies that arise with cooperative diversity. We perform extensive simulations that show that our protocol can outperform the best of the noncooperative broadcasting protocols by: (a) achieving up to a threefold increase in network coverage and, (b) by decreasing the latency incurred during the broadcast by about 50%. We also construct an analytical model that captures the behavior of our protocol. Furthermore, we show that computing the optimal solution to the cooperative broadcast problem is NP-complete and construct centralized approximation algorithms. Specifically, we construct an O(Nepsi)-approximation algorithm with a computational complexity of O(N4/epsi); we also construct a simpler greedy algorithm.. The costs incurred with these algorithms serve as benchmarks with which one can compare that achieved by any distributed protocol
Gentian Jakllari, Srikanth V. Krishnamurthy, Michalis Faloutsos, Prashant Krishnamurthy
IEEE J. Sel. Areas Commun.2
2007 Multiband Media Access Control in Impulse-Based UWB Ad Hoc Networks
abstract
We propose a MAC protocol for use in multihop wireless networks that deploy an underlying UWB (ultra wide band)-based physical layer. We consider a multiband approach to better utilize the available spectrum, where each transmitter sends longer pulses in one of many narrower frequency bands. The motivation comes from the observation that, in the absence of a sophisticated equalizer, the size of a slot for transmitting a UWB pulse is typically dictated by the delay spread of the channel. Therefore, using a wider frequency band to shorten the transmission time for each pulse does not increase the data rate in proportion to the available bandwidth. Our approach allows data transmissions to be contiguous and practically interference free, and, thus, highly efficient. For practicality, we ensure the conformance of our approach to FCC-imposed emission limits. We evaluate our approach via extensive simulations, and our results demonstrate the significant advantages of our approach over single-band solutions: the throughput increases significantly and the number of collisions decreases considerably. Finally, we analyze the behavior of our MAC protocol in a single-hop setting in terms of its efficiency in utilizing the multiple bands
Ioannis Broustis, Srikanth V. Krishnamurthy, Michalis Faloutsos, Mart L. Molle, Jeffrey R. Foerster
IEEE Trans. Mob. Comput.2
2007 A Cross-Layer Framework for Exploiting Virtual MISO Links in Mobile Ad Hoc Networks
abstract
Space-time communications can help combat fading and, hence, can significantly increase the capacity of ad hoc networks. Cooperative diversity or virtual antenna arrays facilitate spatio-temporal communications without actually requiring the deployment of physical antenna arrays. Virtual MISO entails the simultaneous transmission of appropriately encoded information by multiple nodes to effectively emulate a transmission on an antenna array. We present a novel multilayer approach for exploiting virtual MISO links in ad hoc networks. The approach spans the physical, medium access control and routing layers, and provides 1) a significant improvement in the end-to-end performance in terms of throughput and delay and 2) robustness to mobility and interference-induced link failures. The key physical layer property that we exploit is an increased transmission range due to achieved diversity gain. Except for space-time signal processing capabilities, our design does not require any additional hardware. We perform extensive simulations to quantify the benefits of our approach using virtual MISO links. As compared to using only SISO links, we achieve an increase of up to 150 percent in terms of the end-to-end throughput and a decrease of up to 75 percent in the incurred end-to-end delay. Our results also demonstrate a reduction in the route discovery attempts due to link failures by up to 60 percent, a direct consequence of the robustness that our approach provides to link failures
Gentian Jakllari, Srikanth V. Krishnamurthy, Michalis Faloutsos, Prashant Krishnamurthy, Özgür Erçetin
IEEE Trans. Mob. Comput.2
2007 Understanding and Exploiting the Trade-Offs between Broadcasting and Multicasting in Mobile Ad Hoc Networks
abstract
We find that current group communications protocols are far from "one size fits all", they are typically geared toward and optimized for particular scenarios. Multicasting, in general, works well if the density of group members is sparse and in low mobility; broadcasting, in contrast, works well with a high density of group members and in high mobility. Due to the dynamics of the network, one strategy may be preferable to the other at different times and in different localized regions. In this paper, we first quantify the trade-offs between broadcasting and multicasting and evaluate the suitability of a strategy in various scenarios of deployment. Based on the lessons learned, we design a protocol that adapts in response to the dynamics of the network. We named our protocol Fireworks. Fireworks is a hybrid two-tier multicast/broadcast protocol that provides efficient and lightweight multicast dissemination and self-adapts in response to variations in the density and distribution of group members to provide efficient performance. Fireworks creates pockets of broadcast distribution in areas with many members, while it creates and maintains a multicast backbone to interconnect these dense pockets. Fireworks offers packet delivery statistics comparable to that of a pure multicast scheme but with significantly lower overheads. We also show that Fireworks has a lower level of degrading influence on the performance of coexisting unicast sessions than either traditional multicast or broadcast methods
Lap Kong Law, Srikanth V. Krishnamurthy, Michalis Faloutsos
IEEE Trans. Mob. Comput.2
2007 DART: dynamic address routing for scalable ad hoc and mesh networks
Jakob Eriksson, Michalis Faloutsos, Srikanth V. Krishnamurthy
IEEE/ACM Trans. Netw.3
2007 An Integrated Neighbor Discovery and MAC Protocol for Ad Hoc Networks Using Directional Antennas
abstract
Many MAC sub-layer protocols for supporting the usage of directional antennas in ad hoc networks have been proposed in literature. However, there remain two open issues that are yet to be resolved completely. First, in order to fully exploit the spatial diversity gains possible due to the use of directional antennas, it is essential to shift to the exclusive usage of directional antennas for the transmission and reception of all the MAC layer frames. This would facilitate maximal spatial reuse and will efface the phenomena of asymmetry in gain. Second, in the presence of mobility the MAC protocol should incorporate mechanisms by which a node can efficiently discover and track its neighbors. In this paper we propose PMAC, a new MAC protocol that addresses both the issues in an integrated way. PMAC incorporates an efficient mechanism for neighbor discovery, and a scheduling based medium sharing that allows for exclusive directional transmissions and receptions. We perform analysis and simulations to understand the performance of our scheme. We find that each node, on average, can achieve a per node utilization of about 80% in static and about 45% in mobile scenarios. In terms of throughput, our protocol is seen to outperform both the traditional IEEE 802.11 and previously proposed MAC protocols for use with directional antennas in ad hoc networks
Gentian Jakllari, Srikanth V. Krishnamurthy
IEEE Trans. Wirel. Commun.3
2006 On the MAC Layer Performance of Time-Hopped UWB Ad Hoc Networks
abstract
Ultra Wide Band (UWB) is a promising technology for short-range wireless networks. In this paper we present our efforts on investigating the impact of the multipath delay spread on the MAC layer performance of time-hopped impulse-based UWB ad hoc networks. We discuss a simplified channel model for the multipath delay spread and we simulate a single-band MAC protocol which employs binary pulse position modulation. Our simulation results demonstrate that the performance is determined by the properties of the time hopping sequences of the nodes. We observe that the right parameter values depend on the number of nodes deployed, and the delay spread experienced. If the topology changes dynamically, adaptive strategies for varying system parameters are required for achieving the best performance.
Ioannis Broustis, Angelos Vlavianos, Srikanth V. Krishnamurthy
ICCCN3
2006 Detecting MAC Layer Back-off Timer Violations in Mobile Ad Hoc Networks
abstract
In IEEE 802.11 based ad hoc networks, by simply manipulating the back-off timers and/or wait times prior to transmission, malicious nodes can cause a drastically reduced allocation of bandwidth to well-behaved nodes. This can result in causing bandwidth starvation and hence, a denial of service to legitimate nodes. We propose a combination of deterministic and statistical methods that facilitate detection of such misbehavior. With our approach, each of the nodes is made aware of the pseudo-random sequences that dictate the back-off times of all its one-hop neighbors. A blatant violation of the timer is thus, immediately detected. In certain cases, a node may be unable to monitor the activities of its neighbor and therefore deterministically ascertain if the neighbor is misbehaving. To cope with such cases, we propose a statistical inference method, wherein based on an auto-regressive moving average (ARMA) of observations of the system state, a node is able to estimate if its neighbor is indulging in misbehavior. Simulation results show that with our methods, it is possible to detect a malicious node with a probability close to one. Furthermore, the probability of false alarms is lower than 1%.
Venkata Nishanth Lolla, Lap Kong Law, Srikanth V. Krishnamurthy, Chinya V. Ravishankar, Dharmaiah Manjunath
ICDCS3
2006 TrueLink: A Practical Countermeasure to the Wormhole Attack in Wireless Networks
abstract
In a wormhole attack, wireless transmissions are recorded at one location and replayed at another, creating a virtual link under attacker control. Proposed counter-measures to this attack use tight clock synchronization, specialized hardware, or overhearing, making them difficult to realize in practice. TrueLink is a timing based countermeasure to the wormhole attack. Using TrueLink, a node i can verify the existence of a direct link to an apparent neighbor, j. Verification of a link i harr j operates in two phases. In the rendezvous phase, the nodes exchange nonces alphajand betai. This is done with tight timing constraints, within which it is impossible for attackers to forward the exchange between distant nodes. In the authentication phase, i and j transmit a signed message (alphaj,betai), mutually authenticating themselves as the originator of their respective nonce. TrueLink does not rely on precise clock synchronization, GPS coordinates, overhearing, geometric inconsistencies, or statistical methods. It can be implemented using only standard IEEE 802.11 hardware with a minor backwards compatible firmware update. TrueLink is meant to be used together with a secure routing protocol. Such protocols require an authentication mechanism, which will also be used by TrueLink. TrueLink is virtually independent of the routing protocol used. Our performance evaluation shows that TrueLink provides effective protection against potentially devastating wormhole attacks.
Jakob Eriksson, Srikanth V. Krishnamurthy, Michalis Faloutsos
ICNP2
2006 A Framework for Distributed Spatio-Temporal Communications in Mobile Ad Hoc Networks
abstract
Space-time communications can help combat fading and hence can significantly increase the capacity of ad hoc networks. Cooperative diversity or virtual antenna arrays facilitate spatio-temporal communications without actually requiring the deployment of physical antenna arrays. Virtual MISO entails the simultaneous transmission of appropriately encoded information by multiple nodes to effectively emulate a transmission on an antenna array. We present a novel multi-layer approach for exploiting virtual MISO links in ad hoc networks. The approach spans the physical, medium access control and routing layers and provides: (a) a significant improvement in the end-to-end performance in terms of throughput and delay and, (b) robustness to mobility and interference induced link failures. The key physical layer property that we exploit is an increased transmission range due to achieved the diversity gain. Except for space-time signal processing capabilities, our design does not require any additional hardware. We perform extensive simulations to quantify the benefits of our approach using virtual MISO links. As compared to using only SISO links, we achieve an increase of up to 150% in terms of the end-to-end throughput and a decrease of up to 75% in the incurred end-to-end delay. Our results also demonstrate a reduction in the route discovery attempts due to link failures by up to 60%, a direct consequence of the robustness that our approach provides to link failures.
Gentian Jakllari, Srikanth V. Krishnamurthy, Michalis Faloutsos, Prashant Krishnamurthy, Özgür Erçetin
INFOCOM2
2006 Overcoming the challenge of security in a mobile environment
abstract
The secure operation of ad hoc networks faces the novel challenge of location verification on top of the security challenges that wireline networks face. The novelty lies in the fact that a node can correctly validate who it is, but lie about its location and exploit this to create problems to the network. There are three main factors that make ad hoc networks more vulnerable: (a) nodes can overhear other nodes announcements, (b) nodes can lie about their location, and (c) nodes can avoid detection and isolation by moving. As a result, malicious nodes can fake their position and this way obstruct the routing. In this work, we explain how location and topology related malice can affect the security of wireless ad hoc networks. First, we present the most important attacks that can stem from misuse of location information. Second, we provide an overview of security routing approaches. Although several of the current techniques are promising, we conclude that there does not exist a bulletproof approach as of yet
Ioannis Broustis, Michalis Faloutsos, Srikanth V. Krishnamurthy
IPCCC3
2006 An Integrated Scheme for Fully-Directional Neighbor Discovery and Topology Management in Mobile Ad hoc Networks
abstract
With directional antennas, it is extremely important that a node maintains information with regards to the positions of its neighbors. This would allow the node to "track" the neighbors as they move; otherwise, a node will have to resort to either omnidirectional or circular directional transmissions (or receptions) fairly often. This can be overhead intense and can reduce spatial reuse. Maintaining directional information with regards to a large number of neighbors can itself be expensive; therefore it is important to limit a node's degree. We propose a topology control scheme (Di-ATC) that works with fully directional communications and offers a low degree bound while preserving network connectivity. The key idea is to execute Di-ATC on the discovered neighbors to select and maintain connectivity with only a subset of these neighbors. The members of this subset are those with high angular separations. We perform extensive simulations and demonstrate that our scheme effectively limits node degree while at the same time, preserves network connectivity and achieves low path stretch
Ece Gelal, Gentian Jakllari, Srikanth V. Krishnamurthy, Neal E. Young
MASS3
2006 Topology Control to Simultaneously Achieve Near-Optimal Node Degree and Low Path Stretch in Ad hoc Networks
abstract
Our objective in this paper is to design topology control algorithms such that (i) nodes have low degree and (ii) paths in the network have few hops. Low node degree is desirable in networks equipped with smart antennas and to reduce access contention. Short paths are desirable for minimizing communication delays and for better robustness to channel impairments and to mobility. Given any arbitrary unit-disc graph G representing all feasible links, our algorithms find a sparse subgraph G' having a maximum node degree of six and, for each pair of vertices u, v, having hopsG'(u, v) = O(hopsG(u,v) + logDelta), where Delta is the maximum node degree in G and hopsG(u, v) denotes the shortest path length from u to v in G. This result is near-optimal: (i) there is a connected UDG G in which no connected subgraph has degree less than five, and (ii) for any graph G, any bounded-degree subgraph G' must have hopsG'(u, v) = Omega(hopsG(u, v) + logDelta) for some u, v. Our distributed algorithm scales, preserves link symmetry, does not need node synchronization, and requires only O(n) messages. We perform extensive simulations that quantify the performance of our algorithm in realistic scenarios
Ece Gelal, Gentian Jakllari, Srikanth V. Krishnamurthy, Neal E. Young
SECON3
2006 Application versus network layer multicasting in ad hoc networks: the ALMA routing protocol
Min Ge, Srikanth V. Krishnamurthy, Michalis Faloutsos
Ad Hoc Networks2
2006 A new binary conflict resolution-based MAC protocol for impulse-based UWB ad hoc networks
abstract
Abstract Ultra wide band (UWB) technology offers a promising high capacity solution for short‐range wireless ad hoc networks, as in home networks or in wearable ad hoc networks. In this paper, we propose a novel multi‐band MAC protocol for use in small ad hoc networks that deploy an underlying UWB based physical layer. In our approach, we divide the available UWB bandwidth into multiple simultaneously usable bands. In the absence of a sophisticated equalizer, the size of a slot for transmitting a UWB pulse is typically dictated by thedelay spreadof the channel. Therefore, using a wider frequency band to shorten the transmission time for each pulse does not increase the data rate in proportion to the available bandwidth. A multi‐band approach that uses a plurality of bands that adhere to FCC specifications, with slightly elongated pulse durations, provides a solution that can effectively utilize the UWB spectrum. Our approach is based on the idea of conflict resolution using binary ‘something’/‘nothing’ feedback, which has not been widely studied in wireless and specifically in UWB networks. Our protocol unites binary conflict resolution and multi‐band utilization to effectively utilize the available bandwidth. To ensure that our proposed approach is tightly knit with the underlying physical layer, we discuss physical–layer dependencies and the conformance to FCC‐imposed emission limits. We evaluate our approach via extensive simulations. Our simulation results demonstrate the significant advantages of our approach over single‐band solutions: the throughput increases significantly, and the number of collisions decreases considerably. Copyright © 2006 John Wiley & Sons, Ltd.
Ioannis Broustis, Mart L. Molle, Srikanth V. Krishnamurthy, Michalis Faloutsos, Jeffrey R. Foerster
Wirel. Commun. Mob. Comput.3
2005 A Lightweight framework for source-to-sink data transfer in wireless sensor networks
abstract
Lightweight protocols that are both bandwidth and power thrifty are desirable for sensor networks. In addition, for many sensor network applications, timeliness of data delivery at a sink that collects and interprets raw sensor data is of great importance. In this work, we propose a lightweight framework for source-to-sink data transfer in a wireless sensor network that is geared towards achieving the above two objectives. Our integrated framework consists of three elements: 1) simple labels that eliminate complex addressing requirements, 2) implicit routing that provides an inherent robustness during sleep/wake schedules, and 3) MAC layer anycast to support routing. Our framework, in addition, facilitates the self-organization of sensor nodes into a network that efficiently relays information from the sources to the sink. The key idea of our framework is to associate each sensor node with a hierarchical level with respect to a sink and using MAC layer anycast to simply further packets to higher levels towards the sink. There are no explicit route tables created or maintained; this eliminates the overhead due to route queries or updates, the need for complex processing and the memory requirements for caching routing information. Furthermore, with our framework, the energy costs of data transmission are evenly distributed across the nodes, thereby improving the longevity of the network. Our MAC layer anycast mechanism not only facilitates routing, but also reduces the number of MAC layer back-offs incurred and, consequently, the waiting times for data transmission. This in turn, improves the timeliness of data delivery at the sink. To summarize, our framework is a) energy efficient, b) inherently robust, and c) conceptually simple. We qualitatively assess our scheme to show its efficiency in terms of power consumption, robustness to failure, ease of setup. The results from our simulations and assessments demonstrate the aforementioned benefits and the viability and potential of using our framework.
James Jobin, Zhenqiang Ye, Honomount Rawat, Srikanth V. Krishnamurthy
BROADNETS4
2005 On routing asymmetry in the Internet
abstract
Routing asymmetry in the Internet can significantly affect the manner in which we model and simulate its behavior. In this paper, we study routing asymmetry in the Internet and present quantitative evaluations on the extent of such asymmetry today. Our quantitative evaluations provide a measure of the difference between the forward and reverse paths between two end points. Routing asymmetry has not been studied extensively before; this is primarily due to the lack of a systematic approach for quantifying asymmetry except for simply computing the difference between the forward and reverse path lengths. By applying our framework for representing asymmetry, we quantify routing asymmetry for both US higher education academic networks and general commercial networks at two different levels: the autonomous system (AS) level and the router (or link) level. We take into consideration, not only the difference in the forward and reverse path lengths, but also the AS and link identities and the sequence in which these entities appear on the paths. We measure the AS level routing asymmetry, and provide upper lower bounds on link level routing asymmetry. Our studies show that academic networks appear to be more symmetric than general commercially deployed networks. Furthermore, our studies demonstrate that routing asymmetry exhibits a skewed distribution i.e., a few end-points seem to display a higher extent of participation on asymmetric routes.
Yihua He, Michalis Faloutsos, Srikanth V. Krishnamurthy, Bradley Huffaker
GLOBECOM3
2005 Handling Asymmetry in Power Heterogeneous Ad Hoc Networks: A Cross Layer Approach
abstract
Power heterogeneous ad hoc networks are characterized by link layer asymmetry: the ability of lower power nodes to receive transmissions from higher power nodes but not vice versa. This not only poses challenges at the routing layer, but also results in an increased number of collisions at the MAC layer due to high power nodes initiating transmissions while low power communications are in progress. Previously proposed routing protocols for handling unidirectional links largely ignore MAC layer dependencies. In this paper, we propose a cross layer framework that effectively improves the performance of the MAC layer in power heterogeneous ad hoc networks. In addition, our approach seamlessly supports the identification and usage of unidirectional links at the routing layer. The framework is based on intelligently propagating low power MAC layer control messages to higher power nodes so as to preclude them from initiating transmissions while the low power communications are in progress within their sensing range. The integrated approach also constructs reverse tunnels to bridge unidirectional links thereby facilitating their effective usage at the routing layer. Extensive simulations are performed to study the proposed framework in various settings. The use of our framework improves the overall throughput of the power heterogeneous network by as much as 25 % over traditional layered approaches. In summary, our framework offers a simple, yet effective and viable approach for media access control and to support routing in power heterogeneous ad hoc networks.
Vasudev Shah, Srikanth V. Krishnamurthy
ICDCS2
2005 Justice: Flexible and Enforceable Per-Source Bandwidth Allocation
Jakob Eriksson, Michalis Faloutsos, Srikanth V. Krishnamurthy
NETWORKING3
2005 Fireworks: An Adaptive Group Communications Protocol for Mobile Ad Hoc Networks
Lap Kong Law, Srikanth V. Krishnamurthy, Michalis Faloutsos
NETWORKING2
2005 Handling asymmetry in gain in directional antenna equipped ad hoc networks
abstract
The deployment of traditional higher layer protocols (especially the IEEE 802.11 MAC protocol at the MAC layer) with directional antennae could lead to problems from an increased number of collisions; this effect is primarily seen due to three specific effects: (i) an increase in the number of hidden terminals; (ii) the problem of deafness and, (iii) a difficulty in determining the locations of neighbors. In this work we propose a new MAC protocol that incorporates circular RTS and CTS transmissions. We show that the circular transmission of the control messages helps avoid collisions of both DATA and ACK packets from hidden terminals. Our protocol intelligently determines the directions in which the control messages ought to be transmitted so as to eliminate redundant transmissions in any given direction. We perform extensive simulations and analyze the obtained results in order to compare our scheme with previously proposed protocols that have been proposed for use in directional antenna equipped ad hoc networks. Our simulation results clearly demonstrate the benefits of incorporating both circular RTS and CTS messages in terms of the achieved aggregate throughput.
Gentian Jakllari, Ioannis Broustis, Thanasis Korakis, Srikanth V. Krishnamurthy, Leandros Tassiulas
PIMRC4
2005 A Rate Control Framework for Supporting Multiple Classes of Traffic in Sensor Networks
abstract
Wireless sensor network applications typically integrate, within the same network, a variety of sensing devices including those for imaging, sound and temperature. In these settings, multiple flows of packets with different requirements in terms of transmission rates, bandwidth and jitter demands may be initiated towards the sink. Uncontrolled introduction of traffic from sources can cause network overload in areas of the network where the paths of the different flows interfere with each other. Such interference effects may result in congestion which leads to high packet loss and excessive delays. In this paper, we present CoBRA, a framework which incorporates distributed, cluster-based mechanisms to address the problem of congestion by enforcing rate control, for supporting multiple classes of traffic in sensor networks. Towards this goal, CoBRA periodically estimates the collective traffic load and, based on the current conditions, allocates and adjusts rates to sources on per-cluster bases. While doing so, CoBRA takes into consideration interference effects and rate requirements of concurrent flows. We have applied two different rate allocation policies using our framework and, through extensive simulation results we demonstrate its feasibility, effectiveness and performance advantages over traditional approaches
Kyriakos Karenos, Vana Kalogeraki, Srikanth V. Krishnamurthy
RTSS3
2005 A multiband mac protocol for impulse-based UWB ad hoc networks
abstract
Abstract — Ultra Wide Band (UWB) technology offers a promising high capacity solution for wireless networks with short-range links. However, MAC and higher-layer ad hoc network protocols that exploit the UWB technology are yet to mature. In this paper, we propose a MAC protocol for use in multi-hop wireless networks that deploy an underlying UWB based physical layer. We adopt a multi-band approach wherein we divide the available UWB bandwidth into multiple simultaneously usable bands. The motivation comes from the following observation: in the absence of a sophisticated equalizer, the size of a slot for transmitting a UWB pulse is typically dictated by the delay spread of the channel. Therefore, using a wider frequency band to shorten the transmission time for each pulse may not increase the data rate in proportion to the available bandwidth. Thus, we consider a multi-band approach to better utilize the available spectrum, where each transmitter sends longer pulses in one of many narrower frequency bands. Unlike previous single hopped schemes that rely on timehopping, our approach allows data transmissions to be contiguous, and thus, highly efficient. The approach also ensures that data communications are practically interference free and are only subject to thermal noise effects. To ensure that our proposed approach is tightly knit with the underlying physical layer, we discuss physical-layer dependencies and the conformance of our approach to FCC-imposed emission limits. We evaluate our approach via extensive simulations. Our simulation results demonstrate the significant advantages of our approach over single-band solutions: the throughput increases significantly, and the number of collisions decreases considerably.
Ioannis Broustis, Srikanth V. Krishnamurthy, Michalis Faloutsos, Mart L. Molle, Jeffrey R. Foerster
SECON2
2005 Local versus global power adaptive broadcasting in ad hoc networks
abstract
Broadcasting is an ad hoc network critical function component, and, in many deployments, making it power efficient is extremely important. Current power adaptive approaches proposed for broadcasting can be grouped into (a) centralized or omniscient schemes, and (b) decentralized or localized schemes. Due to the absence of global information, localized algorithms may not produce optimal or near-optimal solutions. On the other hand, global knowledge is not typically available to nodes and may be extremely expensive to disseminate. We examine the importance of the lack of global information on the performance of localized approaches. We have performed extensive simulations and compare the performance of localized power adaptive broadcasting with the performance of the well-known broadcast incremental power (BIP), an omniscient algorithm. We analyze the behaviors of the two protocols and identify the reasons for the differences in behavior. We observe that while the global state does provide better performance in terms of energy efficiency, the localized scheme performs better in terms of the latency incurred in the broadcast. Based on the observed behavioral traits of the two protocols, we suggest changes by which the energy consumption with the localized scheme is reduced by as much as 20%, while incurring almost no penalty in terms of latency.
Kyriakos Karenos, Asheq Khan, Srikanth V. Krishnamurthy, Michalis Faloutsos
WCNC3
2005 An Integrated Neighbor Discovery and MAC Protocol for Ad Hoc Networks Using Directional Antennas
abstract
Many MAC sub-layer protocols for supporting the use of directional antennas in ad hoc networks have been proposed. However, there remain two open issues that are yet to be resolved completely. First, in order to exploit fully the spatial diversity gains due to the use of directional antennas, it is essential to shift to the exclusive use of directional antennas for the transmission and reception of all the upper layers frames. This facilitates maximal spatial re-use and effaces the phenomenon of asymmetry in gain. Second, in the presence of mobility, the MAC protocol should incorporate mechanisms by which a node can efficiently locate and track its neighbors. We propose a new polling based MAC protocol that addresses both the issues in an integrated way. We perform analysis and extensive simulations to understand the performance of our scheme in terms of its ability to maintain connectivity, the achieved utilization efficiency, and throughput. We find that each node, on average, can achieve a per node utilization of about 80% in static and about 45% in mobile scenarios. Our protocol is seen to outperform both the traditional IEEE 802.11 MAC protocol and previously proposed protocols for use with directional antennas that provide partial solutions to solve the aforementioned problems. Finally, we also study the sensitivity of our protocol to various system parameters.
Gentian Jakllari, Srikanth V. Krishnamurthy
WOWMOM3
2005 Improving TCP performance in ad hoc networks using signal strength based link management
Fabius Klemm, Zhenqiang Ye, Srikanth V. Krishnamurthy, Satish K. Tripathi
Ad Hoc Networks3
2004 Quantifying routing asymmetry in the Internet at the AS level
abstract
Our objective is to quantify the extent of routing asymmetry in the Internet: the measure of the difference between the forward and backward paths between two end points. Routing asymmetry has not been studied extensively. Most previous studies only consider asymmetry in terms of length and there is a lack of a systematic approach for quantifying asymmetry. One of the challenges in quantifying asymmetry is the formulation of an appropriate set of metrics that can effectively capture various notions of asymmetry. We point out that asymmetry could be of various types. We propose a framework to quantify the routing asymmetry between end hosts and propose two new metrics: absolute asymmetry and length-based normalized asymmetry. Our metrics capture the differences in router/AS identities, their appearing sequences and path lengths in a seamless way. We apply our framework to real Internet measurement data and examine routing asymmetry at the autonomous system (AS) level. We deduce the routing asymmetry distribution based on our framework, and we find that about 14% of pairs of routes considered display AS level routing asymmetry. Furthermore, our studies demonstrate that the routing asymmetry exhibits a skewed distribution, since a few end-points are consistently members of asymmetric pairs.
Yihua He, Michalis Faloutsos, Srikanth V. Krishnamurthy
GLOBECOM3
2004 Effects of multipath routing on TCP performance in ad hoc networks
abstract
In mobile ad hoc networks, one might expect multipath routing to provide some robustness to link failures and facilitate the transmission of packets along paths that avoid regions of congestion. Consequently, one would expect an improvement in network performance in terms of the achieved throughput. We consider TCP goodput as the metric of performance. We find that, contrary to expectations, not all TCP connections enjoy the benefits of multipath routing. Specifically, we find that while long (in terms of hop-count) TCP connections seem to benefit, short connections in fact suffer a slight degradation in goodput as compared to TCP using the single shortest path. Furthermore, we find that alternate path routing, wherein packets are routed on a secondary alternate path only upon the failure of the primary path, helps achieve almost the same goodput as when the multiple paths are used simultaneously. The main benefits of currently proposed multipath routing schemes seem to be limited to improving the efficiency of route discoveries that are initiated either due to real route failures (due to mobility) or due to false failures (due to interference effects) for long TCP connections.
Zhenqiang Ye, Srikanth V. Krishnamurthy, Satish K. Tripathi
GLOBECOM2
2004 Improving the MAC layer performance in ad hoc networks of nodes with heterogeneous transmit power capabilities
abstract
The performance of the IEEE 802.11 MAC protocol has been shown to degrade considerably in an ad hoc network with nodes that transmit at heterogeneous power levels. The main cause of this degradation is the potential inability of the high power nodes to hear the RTS/CTS exchanges between nodes when at least one node involved in the communication is a low power node. The propagation of the CTS message beyond the one-hop neighborhood of two communicating low power nodes was considered in our prior work in an attempt to alleviate this effect. However, this resulted in an excessive overhead and further degraded the performance at the MAC layer. In this paper we consider two techniques to reduce the overhead incurred due to the aforementioned propagation of the CTS message: (a) the use of an intelligent broadcast scheme and (b) the reservation of bandwidth for the sequential transmission of multiple data packets with a single RTS/CTS exchange (and propagation as needed). These techniques require changes only at the MAC layer. We find, by means of extensive simulations, that these techniques provide a significant improvement over the legacy IEEE 802.11 MAC protocol in the considered power heterogeneous ad hoc network. The overall throughput improves by as much as 12 % and the throughput of the low power nodes improves by up to 14 % as compared to the IEEE 802.11 MAC protocol. Furthermore, the schemes find applicability even in homogeneous networks as they reduce the number of false link failures that arise when the IEEE 802.11 MAC protocol is used, by about 20 %. We conclude that the proposed schemes together offer a simple yet effective and viable means of performing medium access control in power heterogeneous ad hoc networks.
Vasudev Shah, Srikanth V. Krishnamurthy, Neeraj Poojary
ICC2
2004 Scalable Ad Hoc Routing: The Case for Dynamic Addressing
abstract
We show that the use of dynamic addressing can enable scalable routing in ad hoc networks. It is well known that the current ad hoc protocol suites do not scale to work efficiently in networks of more than a few hundred nodes. Most current ad hoc routing architectures use flat static addressing and thus, need to keep track of each node individually, creating a massive overhead problem as the network grows. Could dynamic addressing alleviate this problem? To begin to answer this question, we provide an initial design of a routing layer based on dynamic addressing, and evaluate its performance. Each node has a unique permanent identifier and a transient routing address, which indicates its location in the network at any given time. The main challenge is dynamic address allocation in the face of node mobility. We propose mechanisms to implement dynamic addressing efficiently. Our initial evaluation suggests that dynamic addressing is a promising approach for achieving scalable routing in meganode ad hoc networks.
Jakob Eriksson, Michalis Faloutsos, Srikanth V. Krishnamurthy
INFOCOM3
2004 Understanding the Effects of Hotspots in Wireless Cellular Networks
abstract
In this work, we study and quantify the effects of hotspots in wireless cellular networks. Hotspots are caused when the bandwidth resources available at some location in the network are not enough to sustain the needs of the users, which are then blocked or dropped. A deeper understanding of hotspots can help in conducting more realistic simulations and enable improved network design. We identify some causes for the formation of hotspots and based on them, categorize hotspots into three different types: a) capacity based, b) delay based, and c) preferential mobility based. We show how these types have different effects on network performance. We also consider the effects of hotspots from various perspectives such as the number of hotspots, the placement of hotspots, etc. We also develop a fluid flow model and an analytical model to study hotspots. The fluid flow model is surprisingly simple yet effective in helping us understand hotspots and their properties. We also describe an analytical model in which we consider a cell as an M/M/B/B queue. We use these models to substantiate some of the observations from the simulations.
James Jobin, Michalis Faloutsos, Satish K. Tripathi, Srikanth V. Krishnamurthy
INFOCOM4
2004 Improving the reliability of event reports in wireless sensor networks
abstract
In wireless sensor networks, data from sensors has to be transported to a central server or sink. Since the sensors are power-constrained devices, the data is typically fused en route, and an aggregated report of fused information is finally available at the sink. It is important that information from as many sensors as possible be fused in order to increase the credibility of the aggregated report. However, in sensor networks there may be faulty sensors or even malicious intruders that generate and report misleading information. Thus, it is important to collect and fuse enough correct reports that agree with each other; this would enable nodes that perform fusion to detect and ignore the effects of the faulty reports. In this work, we propose a protocol called corroborative aggregation protocol (CAP), in which, each sensor that detects a report from its neighbor that contradicts its own findings generates its own report to dispute the faulty report. The idea is to increase the number of correct reports so as to effectively reduce the adverse effects of faulty reports. We show by simulations that CAP is effective in maintaining the credibility of the final fused content even if approximately 30% of sensors within a detecting zone are wrong about an event.
Srikanth V. Krishnamurthy, Satish K. Tripathi
ISCC2
2004 TCP-friendly medium access control for ad-hoc wireless networks: alleviating self-contention
abstract
We focus on self-contention: contention between packets of the same transport layer connection along the path from source to destination. We observe that self-contention plays an important role in degrading TCP performance in multi-hop wireless networks and that the use of the popular IEEE 802.11 MAC protocol exacerbates self-contention. We propose and study two MAC-layer approaches to alleviate self-contention. The first approach, called quick-exchange (QE), is designed with the intent of reducing the effects of inter-flow self-contention (e.g. between packets of the same connection traveling in opposite directions). The design of our second mechanism, called fast-forward (FF), is geared towards decreasing intra-flow self-contention (e.g. between packets of the same connection traveling in the same direction). We simulate and study our proposed schemes and observe that quick-exchange consistently improves net-work aggregate goodput (by as much as 20% in string topologies, 15% in random static scenarios, and 10% in random mobile scenarios). In contrast to our expectations, fast-forward causes sporadic and often negative effects on goodput for TCP connections. Upon investigation we find that while the MAC is, in some respect, operating more efficiently, as demonstrated by improved UDP throughput; interactions with TCPs congestion control mechanism cause the goodput to degrade. We analyze various effects that cause the respective behaviors with QE and FF in detail.
Dan Berger, Zhenqiang Ye, Prasun Sinha, Srikanth V. Krishnamurthy, Michalis Faloutsos, Satish K. Tripathi
MASS4
2004 Use of congestion-aware routing to spatially separate TCP connections in wireless ad hoc networks
abstract
Spatially separating TCP sessions such that they inflict much lower interference effects on each other may provide gains in performance. We first investigate the possibilities of achieving such gains by considering a centralized, ideal, and unrealistic congestion aware routing approach. We then consider the implementation of a distributed routing protocol to achieve the aforementioned spatial separation benefits. We find that due to practicalities such as the need for the exchange of congestion state, the existence of stale congestion information and the creation of sub-optimal paths, the benefits due to spatial separation are considerably undermined. We perform both macroscopic simulations and microscopic studies of specific constructed examples to understand the reasons and quantify the various effects with both the centralized and the distributed approaches. Our studies suggest that achieving noteworthy performance gains by spatially separating TCP sessions may be extremely difficult if not impossible in ad hoc networks.
Zhenqiang Ye, Srikanth V. Krishnamurthy, Satish K. Tripathi
MASS2
2004 Improving the Performance of TCP in the Presence of Interacting UDP Flows in Ad Hoc Networks
Vikram Gupta, Srikanth V. Krishnamurthy, Michalis Faloutsos
NETWORKING2
2004 A routing framework for providing robustness to node failures in mobile ad hoc networks
Zhenqiang Ye, Srikanth V. Krishnamurthy, Satish K. Tripathi
Ad Hoc Networks2
2003 Synchronization of multiple levels of data fusion in wireless sensor networks
abstract
In wireless sensor networks, in-network data fusion is needed for energy-efficient information flow from a plurality of sensors to a central server or sink. As data (either raw or fused) is propagated towards the sink, multiple levels of data fusion are likely. The data fusion at various levels should be synchronized in order to fuse data effectively. It is important that information from as many sensors as possible to be fused in order to increase the credibility of the aggregated report. However, there are trade-offs between fusing a large number of sensor reports and the latency incurred in the aggregation process. The paths taken by the data towards the sink determine where data can be fused, and thus, have an effect on the efficiency of the aggregation process. In this work, we propose a methodology by which the various levels of fusion are synchronized to ensure that the aggregated report has a desired trade-off between credibility and latency, regardless of the topology of the structure created by the integration of the paths on which data traverses towards the sink.
Srikanth V. Krishnamurthy, Satish K. Tripathi
GLOBECOM2
2003 Power Adaptive Broadcasting with Local Information in Ad Hoc Networks
abstract
Network wide broadcasting is an energy intensive function. In this paper we propose a new method that performs transmission power adaptations based on information available locally, to reduce the overall energy consumed per broadcast. In most of the prior work on energy efficient broadcasting it is assumed that the originator of the broadcast has global network information (both topology information as well as the geographical distance between nodes). This can be prohibitive in terms of the consumed overhead. In our protocol, each node attempts to tune its transmit power based on local information (of up to two hops from the transmitting node). We perform extensive simulations to evaluate our protocol. Our simulations take into account the possible loss of packets due to collision effects and the additional re-broadcasts that are necessary due to lower power transmissions. We show that our protocol achieves almost the same coverage as other non power-adaptive broadcast schemes hut with a reduction of approximately 40% in terms of the consumed power as compared to a scheme that does not adapt its power.
Michalis Faloutsos, Srikanth V. Krishnamurthy
ICNP3
2003 A Framework for Reliable Routing in Mobile Ad Hoc Networks
abstract
Mobile ad hoc networks consist of nodes that are often vulnerable to failure. As such, it is important to provide redundancy in terms of providing multiple node-disjoint paths from a source to a destination. We first propose a modified version of the popular AODV protocol that allows us to discover multiple node-disjoint paths from a source to a destination. We find that very few of such paths can be found. Furthermore, as distances between sources and destinations increase, bottlenecks inevitably occur and thus, the possibility of finding multiple paths is considerably reduced. We conclude that it is necessary to place what we call reliable nodes (in terms of both being robust to failure and being secure) in the network for efficient operations. We propose a deployment strategy that determines the positions and the trajectories of these reliable nodes such that we can achieve a framework for reliably routing information. We define a notion of a reliable path which is made up of multiple segments, each of which either entirely consists of reliable nodes, or contains a preset number of multiple paths between the end points of the segment. We show that the probability of establishing a reliable path between a random source and destination pair increases considerably even with a low percentage of reliable nodes when we control their positions and trajectories in accordance with our algorithm.
Zhenqiang Ye, Srikanth V. Krishnamurthy, Satish K. Tripathi
INFOCOM2
2002 Split TCP for mobile ad hoc networks
abstract
The fairness and throughput of TCP suffer when it is used in mobile ad hoc networks. This is because TCP wrongly attributes packet losses due to link failures (a consequence of mobility) to congestion. The resulting overall degradation of throughput especially affects connections with a large number of hops, where link failures are more likely; thus, short connections enjoy an unfair advantage. Furthermore, if the IEEE 802.11 MAC protocol is used, the problems are exacerbated due to the protocol-induced capture effect, leading to greater unfairness and a further throughput degradation. We develop a scheme, called split TCP, which separates the TCP functions of congestion control and reliable packet delivery. For any TCP connection, certain nodes along the route take up the role of being proxies for that connection. The proxies buffer packets upon receipt and administer rate control. The buffering enables dropped packets to be recovered from the most recent proxy. The rate control helps in controlling congestion on inter-proxy segments. Thus, we emulate shorter TCP connections and can thereby achieve better parallelism in the network. Simulations show that the use of proxies improves the total throughput by as much as 30% in typical scenarios and reduces unfairness significantly. In terms of an unfairness metric that we introduce, the unfairness decreases from 0.8 to 0.2 (1.0 being the maximum unfairness). We conclude that incorporating TCP proxies is beneficial in terms of improving TCP performance in ad hoc networks.
Swastik Kopparty, Srikanth V. Krishnamurthy, Michalis Faloutsos, Satish K. Tripathi
GLOBECOM2
2002 A New Adaptive Channel Reservation Scheme for Handoff Calls in Wireless Cellular Networks
Zhong Xu, Zhenqiang Ye, Srikanth V. Krishnamurthy, Satish K. Tripathi, Mart L. Molle
NETWORKING3
2002 Distributed power control in ad-hoc wireless networks
abstract
Mobile ad-hoc networking involves peer-to-peer communication in a network with a dynamically changing topology. Achieving energy efficient communication in such a network is more challenging than in cellular networks since there is no centralized arbiter such as a base station that can administer power management. We propose and evaluate a power control loop, similar to those commonly found in cellular CDMA networks, for ad-hoc wireless networks. We use a comprehensive simulation infrastructure consisting of group mobility, group communication and terrain blockage models. A major focus of research in ad-hoc wireless networking is to reduce energy consumption because the wireless devices are envisioned to have small batteries and be incapable of energy scavenging. We show that this power control loop reduces energy consumption per transmitted byte by 10-20%. Furthermore, we show that it increases overall throughput by 15%.
Sharad Agarwal, Randy H. Katz, Srikanth V. Krishnamurthy, Son K. Dao
PIMRC3
2002 An architecture for providing range extension by deploying mobile gateways in ad hoc networks
abstract
The dynamic nature of a mobile ad hoc network (MANET) may result in a cluster of nodes being isolated from the rest of the network, especially when deployed in a terrain with blockages. To provide connectivity between the partitions of an ad hoc network that might occur due to mobility, a 'range extension' network can be employed. Such a network might consist of airborne communication platforms, or geostationary/low-Earth-orbit satellites maintaining communication links with specific 'gateway' nodes that are dispersed among the mobile ground nodes. Thus, to communicate with a node that is geographically distant or belongs to a different network partition, an ad hoc node can relay its data packets through an appropriate mobile gateway and via the range extension network. In such an architecture, MANET is divided into different domains with a mobile gateway deployed for each domain. The objective, then, is to determine the position and trajectory of the gateways to optimize network performance metrics such as throughput and latency. In this paper, computation of the optimal position for a gateway is shown to be equivalent to a linear optimization problem by means of some simplifying but realistic assumptions. An algorithm is proposed for the control of the gateway trajectory. The practical constraints imposed by the velocity and maneuverability of the gateways are taken into account. Simulation results show a 10-15% improvement in the throughput and latency, per gateway domain, if a gateway has a dynamic trajectory whose locus follows the computed optimal position, as compared to a gateway that is statically placed at a fixed position, or to a gateway that has a random trajectory.
Srikanth V. Krishnamurthy, Randy H. Katz, Son K. Dao
PIMRC2
2002 Capacity of a multihop mesh arrangement of radio cells connected by free-space optical links
abstract
Provision of multimedia services to both stationary and non-stationary terminals is one of the key challenges in modern day telecommunications. A multi-tiered cellular radio system may provide adequate capacity needed to ensure reliable delivery of high quality broadband services to home, office, and mobile users. At the lowest tier, one may envisage picocellular base stations interconnected via short, highly focused free-space optical links, in a multihop mesh arrangement, thereby eliminating the need for new broadband access cabling to backhand traffic from the base stations. Ultimately, the traffic generated in these picocells must be relayed to an entry/exit port (end-office) of the core network. An intelligent routing/load-balancing strategy will help avoid hot spots on the mesh and increase network capacity. The performance metric would be the probability that a newly generated virtual connection must be blocked to maintain QoS guarantees, within this mesh network. A new dynamic routing/load-balancing algorithm is proposed to achieve high performance in terms of blocking probability in the presence of both uniform and nonuniform traffic distributions. Simulation results show that the algorithm dramatically helps in reducing congestion at hot spots in the network. For a toroidal grid configuration it is seen that the new dynamic routing to different end-offices achieves a 20% reduction in blocking probability when compared with a routing scheme wherein picocells have static affiliations with end-offices.
Srikanth V. Krishnamurthy, Anthony S. Acampora
PIMRC1
2002 Trajectory control of mobile gateways for range extension in ad hoc networks
Srikanth V. Krishnamurthy, Randy H. Katz, Son K. Dao
Comput. Networks2
2002 Provision of guaranteed services in broadband LEO satellite networks
Özgür Erçetin, Srikanth V. Krishnamurthy, Son K. Dao, Leandros Tassiulas
Comput. Networks2
2001 Medium access control in a network of ad hoc mobile nodes with heterogeneous power capabilities
abstract
MAC layer protocols for wireless ad hoc networks typically assume that the network is homogeneous with respect to the transmit power capability of individual nodes in the network. The IEEE 802.11 MAC protocol has been popular for use in ad hoc networks. We investigate the performance of this protocol when it is used in a network with nodes that transmit at various power levels. We show that overall throughput is lower than the throughput of a network in which all nodes transmit at identical power levels. In addition, low power nodes have a disadvantage in accessing the medium due to higher levels of interference from the high power nodes. We consider propagating the control messages generated by a node wishing to initiate communication to distant nodes so that they may forbear transmissions for some time, thereby allowing clear access to the initiating node. We find that the overhead incurred due to the additional message transmissions outweighs the potential gain achieved by propagating these messages. This indicates that the signalling mechanism used in the IEEE 802.11 standard or the variants thereof are not sufficient to alleviate the loss in throughput and the lack of fairness engendered by networks that are heterogeneous with regard to the transmit power capabilities of individual nodes.
Neeraj Poojary, Srikanth V. Krishnamurthy, Son K. Dao
ICC2
2001 Polling-based media access protocols for use with smart adaptive array antennas
abstract
Use of an adaptive antenna array or a space-time processor at each base station of a wireless network can substantially abate the effects of multipath fading and co-channel interference. Among the expected benefits are higher data rates, greater frequency reuse factors, and overall higher capacity systems as needed to enable wireless multimedia services. Media access control (MAC) protocols which facilitate the deployment of such a processor have been previously proposed and studied. These MAC protocols invoke the delivery of a pilot tone from each packet access unit in the network as needed, so that the array antenna at the associated base station may rapidly adjust its weighting coefficients, or its per branch equalization coefficients, thereby ensuring subsequent reliable communication between the access unit and the base station. This paper considers two modifications to these earlier protocols, both based upon the notion of piggybacking information requests on to the actual information messages and both intended to improve utilization efficiency and mean delay performance. Results show that a maximum link utilization efficiency of 97% is readily achieved with either modification, and that this maximum utilization efficiency is independent of the number of remote users in the network. Note that the utilization efficiency refers to the throughput at maximum loading, i.e., when the remotes always have queued requests. The modifications also help in achieving a considerable reduction in the average delay in low-load regimes: for typical system parameters, the average delay at low load is only about 10% of that produced by the original schemes.
Srikanth V. Krishnamurthy, Anthony S. Acampora, Michele Zorzi
IEEE/ACM Trans. Netw.1
2000 Power Management for Throughput Enhancement in Wireless Ad-Hoc Networks
abstract
We introduce the notion of power management within the context of wireless ad-hoc networks. More specifically, we investigate the effects of using different transmit powers on the average power consumption and end-to-end network throughput in a wireless ad-hoc environment. This power management approach would help in reducing the system power consumption and hence prolonging the battery life of mobile nodes. Furthermore, it improves the end-to-end network throughput as compared to other ad-hoc networks in which all mobile nodes use the same transmit power. The improvement is due to the achievement of a tradeoff between minimizing interference ranges, reduction in the average number of hops to reach a destination, reducing the probability of having isolated clusters, and reducing the average number of transmissions (including retransmissions due to collisions). The protocols would first dynamically determine an optimal connectivity range wherein they adapt their transmit powers so as to only reach a subset of the nodes in the network. The connectivity range would then be dynamically changed in a distributed manner so as to achieve the near optimal throughput. Minimal power routing is used to further enhance performance. Simulation studies are carried out in order to investigate these design approaches. It is seen a network with such a power managed scheme would achieve a better end-to-end throughput performance (about 10% improvement with a slotted aloha MAC protocol) and lower transmit power (about an 80% Improvement) than a network without such a scheme.
Tamer A. ElBatt, Srikanth V. Krishnamurthy, Dennis Connors, Son K. Dao
ICC (3)2
2000 Multicasting Sustained CBR and VBR Traffic in Wireless Ad-Hoc Networks
abstract
Wireless ad-hoc networks consist of mobile nodes forming a dynamically changing topology without any infrastructure. Multicasting in a wireless ad-hoc network is difficult and challenging. We propose a novel protocol, the Wireless Ad-hoc Real-Time Multicast (WARM) protocol, for multicasting real-time (CBR and VBR) data among nodes in a wireless ad-hoc network. The protocol is distributed, highly adaptive and flexible. Multicast affiliation is receiver initiated. The messaging is localized to the neighborhood of the receiving multicast member and thus the overhead consumed is low. The protocol enables spatial bandwidth reuse along a multicast mesh (a connected structure of multicast group members). The real time connection is guaranteed quality of service (QoS) in terms of bandwidth. For VBR traffic, a combination of reserved and random access mechanisms are used. The protocol is self-healing in the sense that the mesh structure has the ability to repair itself when members either move or relays fail. We present simulation results to demonstrate features of the protocol and show that the throughput is above 90% for pedestrian environments.
George D. Kondylis, Srikanth V. Krishnamurthy, Son K. Dao, Gregory J. Pottie
ICC (1)2
2000 A predictive QoS routing scheme for broadband low Earth orbit satellite networks
abstract
Low Earth orbit satellite networks can augment terrestrial wireless networks to provide global broadband services to users regardless of the users' locations. Delivering QoS guarantees to the users of LEO satellite networks is complicated since the footprints of the LEO satellites move as the satellites traverse their orbits, and thus, causing frequent user handovers between the satellites. Traffic on inter-satellite links of a particular satellite change as the user traffic served by the satellite changes with the satellite's mobility. The change in user traffic on the inter-satellite links may cause violation of QoS requirements of on-going calls. We propose a novel routing algorithm called the predictive routing protocol (PRP), that exploits the predictive nature of the LEO satellite topology to maximize the total number of users served by the system, while maintaining each user's QoS requirements. The PRP predicts the user traffic load on the inter-satellite links up to a short time in the future by using the deterministic knowledge of the LEO satellite topology, and user location information. The PRP determines multiple paths for a particular connection that effectively help avoid possible future bottlenecks as predicted by estimated future traffic on the inter-satellite links. The algorithm is compared with other non-predictive routing protocols such as IP routing by extensive simulations and it is shown that PRP can deliver deterministic QoS guarantees (such as delay jitter), without over-reserving channel bandwidth. An admission control curve has also been obtained which may be used to ensure that the desired QoS metrics may be guaranteed.
Özgür Erçetin, Srikanth V. Krishnamurthy, Son K. Dao, Leandros Tassiulas
PIMRC2
2000 On tolerating single link, double link, and nodal failures in symmetric grid networks
abstract
We consider a symmetric grid network consisting of N distinct nodes. The number or allowable calls (either the number of circuit switched calls or the maximum number of virtual connections such that QoS objectives are maintained) between any two nodes of the network is assumed to be a constant. We first determine this constant assuming that the network is fully loaded. Then, we find the maximum additional capacity needed on each link such that single link, and double link failures can be tolerated by rerouting calls around faded links. Results show that the maximum additional capacity needed to recover from any single link, double link, or single node failure, with no loss of connections (except for those connections terminating at a failed node) scales as 1//spl radic/(N). Thus, we conclude that rerouting, combined with an admission policy which blocks new call attempts such that a fraction of capacity proportional to 1//spl radic/(N) is reserved for failure recovery, provides totally failsafe operation in the presence of such failure events.
Anthony S. Acampora, Ralph A. Gholmieh, Srikanth V. Krishnamurthy
WCNC3
2000 Scalable unidirectional routing with zone routing protocol (ZRP) extensions for mobile ad-hoc networks
abstract
Ad-hoc networks consist of peer-to-peer communicating nodes that are highly mobile. As such, an ad-hoc network lacks infrastructure and the topology of the network changes dynamically. The task of routing data from a source to a destination in such a network is challenging. Several routing protocols have been proposed for wireless ad-hoc networks. Most of these protocols, however, pre-suppose the presence of bi-directional links between the nodes in the network. In reality the ad-hoc network may consist of heterogeneous nodes with different power capabilities and hence, different transmission ranges. When this is the case, a given node might be able to receive the transmission of another given node but might not be able to successfully transmit to the latter. Thus, unidirectional links are formed. Most of the current routing protocols are unsuitable for deployment when such unidirectional links are present. We consider a routing protocol called the zone routing protocol (ZRP) that has been proposed for wireless ad-hoc networks with bi-directional links. The zone routing protocol employs a hybrid proactive (table driven) and reactive (on-demand) methodology to provide scalable routing in the ad-hoc network. However, in the presence of unidirectional links some routes remain undiscovered if ZRP is used. We propose extensions to ZRP to support its deployment when unidirectional links are present. In particular, we propose a query enhancement mechanism that recursively builds partial routes to a destination. Simulation results show that even at a high mobility of 20 m/s, the queries resulting due to the enhancement mechanism result in the computation of valid routes more than 80% of the time. These results are valid even when a large number (40% of nodes have half the transmission range as that of the remaining nodes) of unidirectional links are present in the network.
Prasun Sinha, Srikanth V. Krishnamurthy, Son K. Dao
WCNC2
2000 A new adaptive MAC layer protocol for broadband packet wireless networks in harsh fading and interference environments
abstract
A new medium-access protocol is proposed for sharing a high-speed radio channel among a number of small wireless packet-access units, some of which may be stationary and some of which may be within moving vehicles. Such a system could provide fixed-point pedestrian and remote users with wireless access to CPU and database resources of an underlying asynchronous transfer mode (ATM) wireline network, essentially extending the ATM bandwidth-upon-demand interface directly to the wireless units and enabling delivery of multimedia services (albeit at the lower peak rate afforded by the radio channel). A primary goal of the proposed medium-access protocol is the pre-delivery of a signal from each packet-access unit as needed to rapidly compute the weights needed by a base station's adaptive array processor or a space-time processor, thereby protecting the packet flow in each direction from the effects of both multipath propagation and adjacent channel interference arising in neighboring radio cells. An impairment-robust direct sequence spread-spectrum-based polling signal is invoked to stimulate a pilot tone from a given remote immediately prior to packet transfer in either direction, thereby permitting the base station to determine a good set of antenna element combining or power splitting weights to be used for that packet. Reasonable approximations are invoked to study the performance of the proposed protocol and the link utilization efficiency and average message delay are found. By proper choice of protocol parameters, a radio resource utilization efficiency of about 95% is readily achieved. The accuracy of the approximations is confirmed by extensive computer simulations.
Anthony S. Acampora, Srikanth V. Krishnamurthy
IEEE/ACM Trans. Netw.2
1998 On the capacity of TDMA and CDMA for broadband wireless packet access
abstract
Studies of the capacity of cellular systems, stated in terms of the admissible number of remote users, have generally been limited to voice telephony. We address the problem of comparing the interference-limited performance of CDMA and TDMA systems in a packet switched environment. The objective is to determine whether the capacity advantages claimed for circuit-switched CDMA still apply in a packet-switched environment, where the natural time diversity of bursty transmission may be a significant factor. Under a set of specific assumptions about the wireless environment (including path loss, shadow fading, multipath delay spread, co-channel interference, power control, coding), we evaluate the number of users which can be admitted to the system while maintaining some desired quality-of-service level. Four different classes of users with different characteristics and requirements are considered. The system capacity is found to significantly depend on the QoS objectives, which might be stated in terms of availability of some specified signal to interference level, packet loss rate, or mean tolerable delay. The main finding is that strict requirements imposed on the radio access level tend to favor CDMA, whereas if some form of packet recovery at the higher layers is allowed (implying a relaxed set of requirements on the radio interface), then a somewhat higher capacity may be achieved by TDMA.
Srikanth V. Krishnamurthy, Anthony S. Acampora, Michele Zorzi
PIMRC1
1998 UniNet: a hybrid approach for universal broadband access using small radio cells interconnected by free-space optical links
abstract
A new type of broadband access system is proposed for providing high-quality, bandwidth-upon-demand telecommunication services to the home and office. Communication terminals attach to the network via short radio links, and users can roam freely within a house or building unencumbered by the availability of wired "telecommunications outlets". Basic service is extended through small, high-capacity radio cells; the base stations are interconnected via short, highly focused free-space optical links in a multihop mesh arrangement; and the need for new broadband access cabling is totally surmounted. A tiered arrangement of radio cells further extends service to both out-of-building pedestrian and vehicular users, and service is universally available. Benefits of the approach are described, and issues involving reliability, availability, capacity, and hand off are identified and addressed. Opportunities to refine the basic approach are suggested for further study.
Anthony S. Acampora, Scott H. Bloom, Srikanth V. Krishnamurthy
IEEE J. Sel. Areas Commun.3