Ying-Dar Lin

dblp:l/YingDarLin · also Ying-Dar Jason Lin · DBLP profile ↗
← Back
150ranked-venue papers
55as first author
38since 2021 · last 2026
0000-0002-5226-4396ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 104 · 38 first-author · 23 since 2021Systems, architecture and hardware · 15 · 2 first-author · 1 since 2021Security and privacy · 15 · 8 first-author · 9 since 2021Software engineering, systems software and programming languages · 6 · 3 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 LLM+m: Dual-model chatGPT-based product training and testing with adversarial attack and defense
Ren-Hung Hwang, Yu-Hung Hsiao, Ying-Dar Lin, Yuan-Cheng Lai
Future Gener. Comput. Syst.3
2026 AI for AIoT as a Service: AI to Configure Models, Capacities, and Tasks
Ying-Dar Lin, Tin-Han Lin, Didik Sudyana, Yuan-Cheng Lai
IEEE Internet Things J.1
2026 Attack lifecycle extraction and mapping from CTF writeups using an enhanced LLM approach
Wei-Chian Kew, Ying-Dar Lin, Fietyata Yudha, Ren-Hung Hwang, Yuan-Cheng Lai, Hock Guan Goh
J. Netw. Comput. Appl.2
2025 P4+NFV: Optimal offloading from P4 switches to NFV for diverse traffic streams
Sidharth Sharma, Yuan-Cheng Lai, Ashwin Gumaste, Ying-Dar Lin
Comput. Networks4
2025 Enhancing can security with ML-based IDS: Strategies and efficacies against adversarial attacks
Ying-Dar Lin, Wei-Hsiang Chan, Yuan-Cheng Lai, Chia-Mu Yu, Yu-Sung Wu, Wei-Bin Lee
Comput. Secur.1
2025 Optimizing ratio-based task offloading in two-tier edge computing: Multi-agent weighted action TD3 approach
Widhi Yahya, Yuan-Cheng Lai, Ying-Dar Lin, Mahdin Rohmatillah, Binayak Kar
J. Netw. Comput. Appl.3
2025 Performance modelling and optimal stage assignment for multistage P4 switches
Geng-Li Zhou, Steven S. W. Lee, Ren-Hung Hwang, Ying-Dar Lin, Yuan-Cheng Lai
J. Netw. Comput. Appl.4
2025 TRACE: Relationship Analysis and Causal Factor Extraction in Cyber Threat Intelligence Reports
abstract
Cyber Threat Intelligence (CTI) reports provide valuable insights into cybersecurity attack techniques, which are essential for understanding threat execution. Identifying the root causes of these techniques is crucial for developing effective defense mechanisms. However, the unstructured nature and inconsistent terminology of CTI reports pose significant challenges in extracting causal factors, such as Common Weakness Enumerations (CWEs) and vulnerable data components, limiting proactive responses and the understanding of attack interdependencies. To address these challenges, we propose TRACE, a novel framework that extracts causal factors linked to adversarial techniques and generates comprehensive causal graphs revealing interdependencies within CTI reports. TRACE combines pattern extraction and tagging methods to address the limitations of existing approaches. Utilizing Sentence-based Bidirectional Encoder Representations from Transformers (SBERT) embeddings enhanced with knowledge mappings and deep learning techniques, TRACE discovers and models causal relationships between attack techniques within the reports. By bridging the gap between attack techniques and their underlying vulnerabilities, TRACE provides actionable insights to enhance cybersecurity defenses. Evaluated on 710 CTI reports, TRACE achieved an F1 score of 0.87, demonstrating its accuracy in extracting causal factors and its potential to advance automated causal analysis in cybersecurity.
R. Vaitheeshwari, Eric Hsiao-Kuang Wu, Ying-Dar Lin, Ren-Hung Hwang, Po-Ching Lin, Yuan-Cheng Lai
IEEE Trans. Dependable Secur. Comput.3
2025 5GPT: 5G Vulnerability Detection by Combining Zero-Shot Capabilities of GPT-4 With Domain Aware Strategies Through Prompt Engineering
abstract
Identifying vulnerabilities in complex 5G network protocols is a challenging task. Manual analysis is time-consuming and often inadequate. Modern ML and NLP methods, though effective, are resource-intensive and struggle to find implicit vulnerabilities. In this research, we utilize GPT-4’s advanced language understanding to detect vulnerabilities directly from 5G specifications. To assess GPT-4’s fundamental capabilities in this domain, we first adopt a zero-shot approach that relies solely on the specification text without external guidance. For detecting more sophisticated vulnerabilities that require deep contextual understanding, we introduce a novel domain-aware strategy, where we explicitly teach GPT-4 about security properties and hazard indicators from related works using few-shot learning. We further employ chain-of-thought prompting to guide the model through structured reasoning steps to identify violations or exploitations that may lead to vulnerabilities. A two-tier filtering process ensures that only promising test-cases are retained. Our method has identified 47 potential vulnerabilities in 5G mobility management procedures, including 27 previously unreported issues, and generated corresponding test-cases. Simulating 14 of them, we have found 9 vulnerabilities, five of which are new. The zero-shot approach is effective in detecting procedural and validation flaws, while the domain-aware method excels in finding protocol violations and advanced attack scenarios. These findings validate our methodology and demonstrate its strength in discovering both known and novel vulnerabilities in 5G protocols.
Asif Shahriar, Syed Jarullah Hisham, K. M. Asifur Rahman, Ruhan Islam, Md. Shohrab Hossain, Ren-Hung Hwang, Ying-Dar Lin
IEEE Trans. Inf. Forensics Secur.7
2025 Optimal Resource Allocation for AIoT as a Service Under Various Service Scenarios and Architectures
abstract
The integration of artificial intelligence (AI) with the Internet of Things (IoT) marks a significant advancement in sixth-generation (6G) networks. The complexity of these AIoT services has promoted an as-a-service model, where service providers offer tailored architectures to meet varied application needs. Despite the critical importance of optimizing both training and inference in service architectures, this aspect remains under-explored. Our study introduces service scenarios such as ‘no shared (NS)’, where tenants manage their data and models independently, ‘data shared (DS)’, where tenants provide data for collective training, and ‘parameter sharing (PS)’, where only model parameters are shared. We utilize a tandem queue model to simulate the communication and computing demands across cloud-edge-fog architectures. Our proposed Cost and Delay Resource Allocation (CDRA) method significantly reduces costs, with edge and fog-based training and inference lowering costs by up to 44% compared to cloud setups. The evaluation shows that the NS scenario is resource-intensive but offers high privacy, DS is cost-effective and improves model accuracy, and PS balances privacy with longer wait times. These findings provide service providers with a comprehensive comparison of service scenarios and architectures, offering guidance for strategic and economically sound decisions in the ever-evolving landscape of AIoT.
Ren-Hung Hwang, Tsai-Ying Chou, Jia-You Lin, Didik Sudyana, Yuan-Cheng Lai, Ying-Dar Lin
IEEE Trans. Netw. Serv. Manag.6
2025 Reinforcement Learning for AI as a Service: CPU-GPU Task Scheduling for Preprocessing, Training, and Inference Tasks
abstract
The rise of AI solutions has driven the emergence of AI as a Service (AIaaS), offering cost-effective and scalable solutions by outsourcing AI functionalities to specialized providers. Within AIaaS, three key components are essential: segmenting AI services into preprocessing, training, and inference tasks; utilizing GPU-CPU heterogeneous systems where GPUs handle parallel processing and CPUs manage sequential tasks; and minimizing latency in a distributed architecture consisting of cloud, edge, and fog computing. Efficient task scheduling is crucial to optimize performance across these components. In order to enhance task scheduling in AIaaS, we propose a user-experience-and-performance-balanced reinforcement learning (UXP-RL) algorithm. The UXP-RL algorithm considers 11 factors, including queuing task information. It then estimates resource release times and observes previous action outcomes, to select the optimal AI task for execution on either a GPU or CPU. This method effectively reduces the average turnaround time, particularly for rapid inference tasks. Our experimental findings show that the proposed RL-based scheduling algorithm reduces average turnaround time by 27.66% to 57.81% compared to the heuristic approaches such as SJF and FCFS. In a distributed architecture, utilizing distributed RL schedulers reduces the average turnaround time by 89.07% compared to a centralized scheduler.
Ying-Dar Lin, Yin-Tao Ling, Yuan-Cheng Lai, Didik Sudyana
IEEE Trans. Netw. Serv. Manag.1
2025 ML-Based Intrusion Detection as a Service: Traffic Split Offloading and Cost Allocation in a Multi-Tier Architecture
abstract
An Intrusion Detection System (IDS) employing machine learning (ML) solutions is crucial for identifying network intrusions. To minimize operational expenses and enhance performance, enterprises have begun outsourcing IDS management to service providers, giving rise to the concept of Intrusion Detection as a Service (IDaS). Earlier research primarily aimed at enhancing the accuracy of ML-based IDS models or expediting their computational process. However, from the service provider's perspective, an optimal architecture ensuring minimal computation cost and processing delay is crucial to increasing revenue. This study evaluates the performance of IDaS in a multi-tier architecture, utilizing traffic split offloading to enhance performance by mapping three in-sequence ML-based IDS tasks (pre-processing, binary detection, multi-class classification) to the architectures as the offloading destinations. We employ a simulated annealing-based traffic offloading and cost allocation (SA-TOCA) algorithm to determine the offloading ratio for each traffic path and the cost requirements for each tier. The results indicate that the edge-cloud architecture is 15% and four times more cost-effective compared to the fog-edge and fog-cloud architectures, respectively, and it demonstrates superior performance in minimizing processing delays. Offloading the majority of traffic to the edge and the remainder to the cloud proves to be an efficient strategy, reducing both computation costs and average delays.
Didik Sudyana, Yuan-Cheng Lai, Ying-Dar Lin, Piotr Cholda
IEEE Trans. Serv. Comput.3
2024 Queue-Length-Based Offloading for Delay Sensitive Applications in Federated Cloud-Edge-Fog Systems
abstract
Delay-sensitive applications demand ultra-low latency, which can be achieved by leveraging edge and fog computing to provide computation services closer to users. However, the server capacity limitation of edge and fog computing necessitates offloading to balance the computation load across cloud, edge, and fog servers. While previous works typically focus on the average delay of users' requests and employ probabilistic offloading schemes based on certain probabilities, our study introduces a novel approach that considers the QoS violating probability and offloads users' requests based on the queue length of computing servers. We propose an approximate model with closed-form solutions to determine the near-optimal offloading thresholds of the queue lengths at fog and edge servers. Although the performance results of the approximate queueing model do not precisely match the simulation results, our numerical findings demonstrate that they share the same trend, and the approximate queueing model can provide the optimal queue length threshold in most cases. Moreover, our numerical results reveal that the QoS violating probability of the queue-length-based offloading is significantly lower than that of the probabilistic offloading scheme, with potential reductions of up to 60% in QoS violations in large-scale network scenarios.
Ren-Hung Hwang, Yuan-Cheng Lai, Ying-Dar Lin
CCNC3
2024 Unmasking Vulnerabilities: Adversarial Attacks against DRL-based Resource Allocation in O-RAN
abstract
The rapid advancement of wireless networks towards Artificial Intelligence (AI)-driven solutions attracts many vendors to build resilient and intelligent capabilities for Open Radio Access Networks (O-RAN). However, besides the benefits of achieving flexibility and intelligence, openness in native AI-driven O-RAN functions is also the target of severe AI-related security threats, e.g., adversarial attacks. This work addresses the security matter for the AI-powered solutions in the physical layer of O-RAN, specifically within the context of deep reinforcement learning (DRL)-based resource allocation. We introduce a new adversarial attack variant that manipulates the environment parameters and misleads the agent's observation during the inference phase. The attack can cause incorrect allocation decisions and significant degradation in the transmission data rate. Our evaluation results show that the attack degrades user data and packet delivery rates by up to 40% and 77.74%, respectively, particularly in ultra-low-latency services. We also found that the major weakness of DRL-driven radio resource allocation is the environment observation stage, where a group of compromised users or jammers can spoof noises and signal power to mislead environment interaction. In our context, the proposed policy infiltration attack is the most efficient approach to cause sustained network inefficiencies or reduced throughput for benign users.
Yared Abera Ergu, Van Linh Nguyen, Ren-Hung Hwang, Ying-Dar Lin, Chuan-Yu Cho, Hui-Kuo Yang
ICC4
2024 Neural Network-based Functional Degradation for Cyber-Physical Systems
abstract
From gimmicky IoT devices to self-driving cars, cyber-physical systems have become increasingly accessible to the masses. As these systems interact intimately with the physical world, failures in the systems can lead to severe, potentially life-threatening damage. Classical cyber-physical systems, such as aircraft flight control, employ dedicated redundancies for fault tolerance. However, a more flexible and cost-effective approach to redundancy is needed as cyber-physical systems become more versatile and expand to the consumer market. In this work, we explore the synthesis of redundancies for program functionalities with neural network models. The models are trained with the data from normal program executions and will be deployed to supplant the original program functionalities when failures occur. We have tested the prototype on representative cyber-physical systems, including ArduPilot and OpenPilot. The evaluation results indicate that the approach can synthesize redundancy models for both numerical and logical programs. We also demonstrate that the redundancy models can effectively avoid bugs and security vulnerabilities in the original programs.
Zheng-Hong Huang, Yu-Sung Wu, Ying-Dar Lin, Chia-Mu Yu, Wei-Bin Lee
QRS3
2024 3GPP Edge-Fog federation: Transparent 3rd-party authentication and application mobility
Minhajul Islam, Tushin Mallick, Mohammad Sakibul Islam, Sadman Sakib, Md. Shohrab Hossain, Ying-Dar Lin
Comput. Commun.7
2024 Improving quality of indicators of compromise using STIX graphs
Shengshan Chen, Ren-Hung Hwang, Ying-Dar Lin, Yu-Chih Wei, Tun-Wen Pai
Comput. Secur.4
2024 Two-stage multi-datasource machine learning for attack technique and lifecycle detection
Ying-Dar Lin, Shin-Yi Yang, Didik Sudyana, Fietyata Yudha, Yuan-Cheng Lai, Ren-Hung Hwang
Comput. Secur.1
2024 The universal federator: A third-party authentication solution to federated cloud, edge, and fog
Ying-Dar Lin, Jian Liu 0031, Chin-Tser Huang
J. Netw. Comput. Appl.2
2024 AI for AI-based intrusion detection as a service: Reinforcement learning to configure models, tasks, and capacities
Ying-Dar Lin, Hao-Xuan Huang, Didik Sudyana, Yuan-Cheng Lai
J. Netw. Comput. Appl.1
2024 Imperceptible adversarial attack via spectral sensitivity of human visual system
Chen-Kuo Chiang, Ying-Dar Lin, Ren-Hung Hwang, Po-Ching Lin, Shih-Ya Chang, Hao-Ting Li
Multim. Tools Appl.2
2024 Transparent Third-Party Authentication With Application Mobility for 5G Mobile-Edge Computing
abstract
Mobile Edge Computing (MEC) is a key technology for supporting low latency applications close to the end user. Users can access application servers in MEC instead of routing to the Internet by passing through a core cellular network. Few security challenges arise as the traffic does not traverse through the core network, and these can be solved by providing authentication services in the MEC. However, authentication and application mobility issues arise in the case of multiple MECs where a user is mobile and needs continuous service from application servers, without needing to establish a new session and providing authentication information repeatedly to every new MEC the user connects with. In this work, we propose two solutions, a TC3A (Token-based Cookie transfer & 3rd-party Authentication) and a TS3A (Token-based State transfer & 3rd-party Authentication) for resolution of authentication and application mobility issues while achieving low latency. We conducted experiments on a testbed that had MECs deployed in a real-time cellular network (emulated via OpenAirInterface) and performed user handover between two MECs. The experimental results show that TC3A and TS3A successfully re-authenticate the users, without provision of login credentials with target MEC, while reducing the latency by approximately 49.76–59.72% as compared to simple login method. The TC3A and TS3A also eliminate the need of keeping multiple accounts for applications at different MECs and most importantly provide application service continuity, through state transfer during cross-system handover, which is not provided by a simple login method. TC3A provides the application service continuity without any loss of session state, which is suitable for applications that cannot afford state loss, and TS3A provides the same while reducing the latency by 47.05–51.25% as compared to TC3A, which is suitable for applications that require low latency.
Ying-Dar Lin, Chi-Yu Li 0001, Yuan-Cheng Lai
IEEE Trans. Netw. Serv. Manag.2
2024 MITREtrieval: Retrieving MITRE Techniques From Unstructured Threat Reports by Fusion of Deep Learning and Ontology
abstract
Cyber Threat Intelligence (CTI) plays a crucial role in understanding and preemptively defending against emerging threats. Typically disseminated through unstructured reports, CTI encompasses detailed insights into threat actors, their actions, and attack patterns. The MITRE ATT&CK framework offers a comprehensive catalog of adversary tactics, techniques, and procedures (TTPs), serving as a valuable resource for deciphering attacker behavior and enhancing defensive measures. Addressing the challenge of time-consuming manual analysis of MITRE TTPs in unstructured CTI reports, this paper presents MITREtrieval, a novel system that leverages deep learning and ontology to efficiently extract MITRE techniques. This approach mitigates issues related to the implicit nature of TTPs, textual semantic dependencies, and the scarcity of adequately labeled datasets, enabling more effective analysis even with limited sample sizes. Our approach combines a sophisticated sentence-level BERT deep learning model with ontology knowledge to address sparse data challenges, using a voting algorithm to merge outcomes. This results in a more accurate classification of MITRE techniques, capturing contextual nuances effectively. Our evaluation confirms MITREtrieval’s effectiveness in identifying techniques, regardless of their representation in training samples. MITREtrieval has surpassed benchmarks, achieving F2 scores of 58%, 62%, and 69% in multi-label technique identification across 113, 46, and 23 CTI reports, respectively, thereby streamlining CTI analysis and improving threat intelligence.
Yi-Ting Huang, R. Vaitheeshwari, Meng Chang Chen, Ying-Dar Lin, Ren-Hung Hwang, Po-Ching Lin, Yuan-Cheng Lai, Eric Hsiao-Kuang Wu, Chung-Hsuan Chen, Zi-Jie Liao, Chung-Kuan Chen
IEEE Trans. Netw. Serv. Manag.4
2023 Enhancing Cyber Threat Intelligence with Named Entity Recognition Using BERT-CRF
abstract
Cyber Threat Intelligence (CTI) helps organizations understand the tactics, techniques, and procedures used by potential cyber criminals to defend against cyber threats. To protect the core systems and services of organizations, security analysts must analyze information about threats and vulnerabilities. However, analyzing large amounts of data requires significant time and effort. To streamline this process, we propose an enhanced architecture, BERT-CRF, by removing the BiLSTM layer from the conventional BERT-BiLSTM-CRF model. This model leverages the strengths of deep learning-based language models to extract critical threat intelligence and novel information from threats effectively. In our BERT-CRF model, the token embeddings generated by BERT are directly fed into the Conditional Random Field (CRF) layer for efficient Named Entity Recognition (NER), thus preventing the need for an intermediate BiLSTM layer. We train and evaluate the model with three publicly available threat entity databases. We also collect open-source threat intelligence data from recent years for evaluating the applicability of the constructed model in a real-world environment. Furthermore, we compare our model with the most popular GPT-3.5 and the most downloaded open-source BERT question-and-answer models. Through this study, our proposed model demonstrated robust usability and outperformed other models, signifying its potential for application in CTI. In a real-world scenario, our model achieved an accuracy of 82.64%, while with malware-specific threat intelligence data, it achieved an impressive accuracy of 93.95%. The code for this research is publicly available at https://github.com/stwater20/ner_bert_crf_open_version.
Shengshan Chen, Ren-Hung Hwang, Chin-Yu Sun, Ying-Dar Lin, Tun-Wen Pai
GLOBECOM4
2023 Correlation of cyber threat intelligence with sightings for intelligence assessment and augmentation
Po-Ching Lin, Wen-Hao Hsu, Ying-Dar Lin, Ren-Hung Hwang, Eric Hsiao-Kuang Wu, Yuan-Cheng Lai, Chung-Kuan Chen
Comput. Networks3
2023 Two-phase Defense Against Poisoning Attacks on Federated Learning-based Intrusion Detection
Yuan-Cheng Lai, Jheng-Yan Lin, Ying-Dar Lin, Ren-Hung Hwang, Po-Ching Lin, Eric Hsiao-Kuang Wu, Chung-Kuan Chen
Comput. Secur.3
2023 Host-based intrusion detection with multi-datasource and deep learning
Ren-Hung Hwang, Chieh-Lun Lee, Ying-Dar Lin, Po-Ching Lin, Eric Hsiao-Kuang Wu, Yuan-Cheng Lai, Chung-Kuan Chen
J. Inf. Secur. Appl.3
2023 Cost optimization of omnidirectional offloading in two-tier cloud-edge federated systems
Binayak Kar, Ying-Dar Lin, Yuan-Cheng Lai
J. Netw. Comput. Appl.2
2023 Task Assignment and Capacity Allocation for ML-Based Intrusion Detection as a Service in a Multi-Tier Architecture
abstract
Intrusion Detection Systems (IDS) play an important role in detecting network intrusions. Because intrusions have many variants and zero-day attacks, traditional signature- and anomaly-based IDS often fail to detect them. On the other hand, solutions based on Machine Learning (ML), have better capabilities for detecting variants. In this work, we adopt an ML-based IDS which uses three in-sequence tasks, pre-processing, binary detection, and multi-class detection, with a multi-tier architecture with one-, two-, and three-tier architectural configurations. We then mapped three in-sequence tasks into these architectures, resulting in ten task assignments. We evaluated these with queueing theory to determine which tasks assignments were more appropriate for particular service providers. With simulated annealing, we obtained the computation capacity by allocating the total cost appropriate to each tier, based on the fixed parameter set with the objective of minimizing overall delay. These investigations showed that using only the edge and allocating all tasks to it gave the best performance. Furthermore, a two-tier architecture with edge and cloud components was also sufficient for IDS as a Service with the delay that was three times better than for other task assignments. Our results also indicate that more than 85% of the total capacity was allocated and spread across nodes in the lowest tier for pre-processing to reduce delays.
Yuan-Cheng Lai, Didik Sudyana, Ying-Dar Lin, Miel Verkerken, Laurens D'hooge, Tim Wauters, Bruno Volckaert, Filip De Turck
IEEE Trans. Netw. Serv. Manag.3
2023 A Novel Multi-Stage Approach for Hierarchical Intrusion Detection
abstract
An intrusion detection system (IDS), traditionally an example of an effective security monitoring system, is facing significant challenges due to the ongoing digitization of our modern society. The growing number and variety of connected devices are not only causing a continuous emergence of new threats that are not recognized by existing systems, but the amount of data to be monitored is also exceeding the capabilities of a single system. This raises the need for a scalable IDS capable of detecting unknown, zero-day, attacks. In this paper, a novel multi-stage approach for hierarchical intrusion detection is proposed. The proposed approach is validated on the public benchmark datasets, CIC-IDS-2017 and CSE-CIC-IDS-2018. Results demonstrate that our proposed approach besides effective and robust zero-day detection, outperforms both the baseline and existing approaches, achieving high classification performance, up to 96% balanced accuracy. Additionally, the proposed approach is easily adaptable without any retraining and takes advantage of n-tier deployments to reduce bandwidth and computational requirements while preserving privacy constraints. The best-performing models with a balanced set of thresholds correctly classified 87% or 41 out of 47 zero-day attacks, while reducing the bandwidth requirements up to 69%.
Miel Verkerken, Laurens D'hooge, Didik Sudyana, Ying-Dar Lin, Tim Wauters, Bruno Volckaert, Filip De Turck
IEEE Trans. Netw. Serv. Manag.4
2022 Prioritized Traffic Shaping for Low-latency MEC Flows in MEC-enabled Cellular Networks
abstract
Multi-access edge computing (MEC) has been introduced as an enabler of low-latency performance in 4G/5G cellular networks. For the MEC-enabled cellular networks, several deployment options have been proposed by ETSI. One promising deployment option called Bump-in-the-wire does not require changes on the base station or the core network, so it has the advantage of easy deployment and low cost. However, the unchanged base station connecting to an MEC platform cannot differentiate MEC traffic from Internet traffic or prioritize it; its traffic congestion may thus cause the MEC traffic to suffer from high latency. In this work, we thus design a solution, designated PTS-MEC (Prioritized Traffic Shaping for MEC), to control the forwarding of downlink MEC/Internet traffic at the MEC and prioritize the MEC traffic based on a hierarchical MEC-prioritized fair service model. PTS-MEC alleviates the base station’s traffic congestion with a latency-aware service rate adaptor at run time by applying the service curve concept to delaying or/and skipping the Internet traffic. We prototype PTS-MEC on an open source MEC platform and evaluate it with congested cases. The evaluation result confirms the effectiveness of PTS-MEC; it can satisfy latency goals, e.g., 50 ms at the 90th percentile, within 3.70% error for MEC flows while fairly allocating remaining resource to non-MEC UEs.
Po-Hao Huang, Fu-Cheng Hsieh, Wen-Jen Hsieh, Chi-Yu Li 0001, Ying-Dar Lin
CCNC5
2022 Provisioning Fog Services to 3GPP Subscribers: Authentication and Application Mobility
abstract
Multi-Access Edge computing (MEC) and Fog computing provide services to subscribers at low latency. There is a need to form a federation among 3GPP MEC and fog to provide better coverage to 3GPP subscribers. This federation gives rise to two issues—third-party authentication and application mobility—for continuous service during handover from 3GPP MEC to fog without re-authentication. In this paper, we propose: 1) a proxy-based state transfer and third-party authentication (PS3A) that uses a transparent proxy to transfer the authentication and application state information, and 2) a token-based state transfer and proxy-based third-party authentication (TSP3A) that uses the proxy to transfer the authentication information and tokens to transfer the application state from 3GPP MEC to the fog. The proxy is kept transparent with virtual counterparts, to avoid any changes to the existing 3GPP MEC and fog architectures. We implemented these solutions on a testbed and results show that PS3A and TSP3A provide authentication within 0.345–2.858s for a 0–100 Mbps proxy load. The results further show that TSP3A provides application mobility while taking 40–52% less time than PS3A using state tokens. TSP3A and PS3A also reduce the service interruption latency by 82.4% and 84.6%, compared to the cloudbased service via tokens and prefetching.
Tushin Mallick, Sadman Sakib, Md. Shohrab Hossain, Ying-Dar Lin
ICC5
2022 ELAT: Ensemble Learning with Adversarial Training in defending against evaded intrusions
Ying-Dar Lin, Jehoshua-Hanky Pratama, Didik Sudyana, Yuan-Cheng Lai, Ren-Hung Hwang, Po-Ching Lin, Hsuan-Yu Lin, Wei-Bin Lee, Chen-Kuo Chiang
J. Inf. Secur. Appl.1
2022 Multi-datasource machine learning in intrusion detection: Packet flows, system logs and host statistics
Ying-Dar Lin, Ze-Yu Wang, Po-Ching Lin, Van Linh Nguyen, Ren-Hung Hwang, Yuan-Cheng Lai
J. Inf. Secur. Appl.1
2022 Low-Latency Service Chaining With Predefined NSH-Based Multipath Across Multiple Datacenters
abstract
Service Function Chaining (SFC) provides a method of forwarding traffic flows through one or more service functions (SFs). For service providers, chaining SFs across multiple datacenters to deliver end-to-end services not only provides better utilization of computing resources of datacenters, but also achieves scalability and fault tolerance. However, most telecommunication applications are sensitive to latency, which tends to degrade due to both virtualization and the long distances among datacenters. In this paper, we extend the network service header (NSH) protocol and propose a multipath chaining with the partially-ordered NSH (MCPON) mechanism to achieve low-latency, partially-ordered service function chaining. MCPON adopts a proactive multipath installation for commonly-used service function paths (SFP, a sequence of requisite SFs) to eliminate reactive path decision delays and to reduce end-to-end service latency. To increase multipath diversity for better load balancing, we modify the original NSH encapsulation design so that the multiple paths selected for an SFP are not limited to having the same execution orders of some non-order-constrained SFs. MCPON also utilizes an entry-saving forwarding table design which enables forwarding entries to be shared among different SFC requests. Our evaluations show that proactive k-path computation for an SFC of length l at a scale of n SFFs saves time complexity of${\mathrm{ O}}(kl^{3}n^{3})$, and multipath service chaining reduces latency by 33–68% compared to single-path service chaining in our simulation scenarios.
Yao-Chun Wang, Ren-Hung Hwang, Ying-Dar Lin
IEEE Trans. Netw. Serv. Manag.3
2021 Offloading Optimization with Delay Constraint in the 3-tier Federated Cloud, Edge, and Fog Systems
abstract
Mobile edge computing and fog computing are promising techniques providing computation service closer to users to achieve lower latency. In this work, we study the optimal offloading strategy in the three-tier federated computation offloading system. We first present queueing models and closed-form solutions for computing the service delay distribution and the probability of the delay of a task exceeding a given threshold. We then propose an optimal offloading probability algorithm based on the sub-gradient method. Our numerical results show that our simulation results match very well with that of our closed-form solutions, and our sub-gradient-based search algorithm can find the optimal offloading probabilities. Specifically, for the given system parameters, our algorithm yields the optimal QoS violating probability of 0.188 with offloading probabilities of 0.675 and 0.37 from Fog to edge and from edge to cloud, respectively.
Ren-Hung Hwang, Yuan-Cheng Lai, Ying-Dar Lin
GLOBECOM3
2021 CREME: A toolchain of automatic dataset collection for machine learning in intrusion detection
Huu-Khoi Bui, Ying-Dar Lin, Ren-Hung Hwang, Po-Ching Lin, Van Linh Nguyen, Yuan-Cheng Lai
J. Netw. Comput. Appl.2
2021 Scaling and Offloading Optimization in Pre-CORD and Post-CORD Multi-Access Edge Computing
abstract
In 5G networks, multi-access edge computing (MEC) can be embedded into an access network (AN-MEC) and a core network (CN-MEC), which composes a two-tier MEC architecture for better scalability. In pre-Central Office Re-architected as a Data center (pre-CORD), AN-MECs are connected to a single but distant CN-MEC through Central Offices (COs). Disaggregation and virtualization of 5G network functions push CN-MEC into COs, which is known as post-CORD. Post-CORD has more CN-MECs closer to User Equipments than pre-CORD. In this work, we propose a scalable two-tier, multi-site, multi-server MEC architecture for pre-CORD and post-CORD. To adjust capacity and traffic allocation in such a distributed two-tier architecture, we integrate scaling and offloading with the objective of minimizing total capacity cost subject to the latency satisfaction percentage constraints, and solve the problem by Latency Aware Two-Phase Iterative Optimization (LA-TPIO). The results show that post-CORD with ten CN-MEC sites requires 30% less capacity than pre-CORD in satisfying 95% of URLLC traffic. Post-CORD utilizes about 48-77% less AN-MEC capacity than pre-CORD because post-CORD’s aggregated but close-enough CN-MEC sites are ideal for serving URLLC traffic. Under heavy hotspot traffic, post-CORD’s vertical and horizontal offloading percentages are 72% and 28%, respectively, while pre-CORD’s are 99% and 1%, which means post-CORD introduces more horizontal offloading because it has links between not only AN-MEC sites but also CN-MEC sites to accommodate hotspot traffic.
Widhi Yahya, Eiji Oki, Ying-Dar Lin, Yuan-Cheng Lai
IEEE Trans. Netw. Serv. Manag.3
2020 Communication and Computation Offloading for 5G V2X: Modeling and Optimization
abstract
Vehicle-to-everything (V2X) is one of the generic services provided by emerging 5G wireless technology. Data traffic in V2X demands both communication and computation which is a challenge to ensure better user experience where communication and computation offloading are an effective scheme. Earlier works have only focused on communication offloading policies and algorithms. However, there have been a few analytical studies, especially on computation offloading and the role of Road-Side Units (RSUs). In this work, we propose an analytical model for communication and computation offloading to RSUs and gNB to minimize average packet delay by finding an optimal offloading probability through a sub-gradient based algorithm. Extensive simulations have been carried out to validate our model. Our results show that deploying RSUs with gNB increases efficiency by as much as 19% than deploying only gNB. Sensitivity analysis also shows that RSU service rate has 10 times more impact on reducing average packet delay than gNB service rate caused by relatively lower communication bandwidth of gNB.
Ren-Hung Hwang, Md. Muktadirul Islam, Md. Asif Tanvir, Md. Shohrab Hossain, Ying-Dar Lin
GLOBECOM5
2020 Modeling and Minimizing Latency in Three-tier V2X Networks
abstract
Leveraging mobile cloud computing (MCC) and mobile edge computing (MEC) for offloading computational tasks is a promising approach to enabling delay-sensitive applications executing vehicles. Despite MCC and MEC's ability and complementary characteristics, most of the existing works on offloading focus on only either MCC or MEC. In this paper, we study their cooperation in a three-tier offloading model of a V2X network where a vehicle can offload computational tasks to cloud computing and MEC. Specifically, we investigate the optimal offloading probabilities of three offloading paths, including Vehicle-to- Infrastructure, Vehicle-to-Cloud, and Infrastructure-to-Cloud. Our contribution is twofold. First, we derive a mathematical model of task execution latency and a formulation to find an optimal solution for the minimum latency problem. Second, we propose an approximation algorithm based on the genetic algorithm toward the optimum. The experiment results show that by exploiting both MCC and MEC's complementary advantages, our proposed algorithm in the three-tier model can shorten the delay significantly compared to existing two-tier models. Depending on the traffic load and the number of Road Side Units, our proposal can reduce the delay by 93.75% on the average, and 99.9% in the best case.
Phi-Le Nguyen, Ren-Hung Hwang, Pham Minh Khiem, Kien Nguyen 0002, Ying-Dar Lin
GLOBECOM5
2020 OMNI: Omni-directional Dual Cost Optimization of Two-Tier Federated Cloud-Edge Systems
abstract
The federation between cloud and edge has been proposed to exploit the advantages of both technologies. However, the existing studies have only considered cloud-edge computing systems which merely support vertical offloading from edges to clouds in one direction. However, there are certain cases, where the offloading needs to be done from clouds to edges and between edges. Such a cloud to edge offloading is called reverse offloading. To this end, this paper proposes a generic Omni-directional architecture of cloud-edge computing systems intending to provide vertical and horizontal offloading. To investigate the effectiveness of the proposed architecture in different operational scenarios, we formulate the dual cost optimization problem with different latency (loose, low, ultra-low) constraints. We develop an offloading algorithm using simulated annealing (SA). The experimental results show by our proposed OMNI architecture we can reduce the total cost by 15-25% and 10-20% in non-uniform and uniform inputs, respectively, compared to other existing architectures. The average latency in OMNI architecture is relatively very less compared to other architectures. It also increases utilization in the edge nodes by 5-30% in comparison to other existing architectures.
Binayak Kar, Ying-Dar Lin, Yuan-Cheng Lai
ICC2
2020 Resource Management in LADNs Supporting 5G V2X Communications
abstract
Local access data network (LADN) is a promising paradigm to reduce latency, enable lowering energy consumption, and improve quality of service (QoS) for the Fifth Generation (5G) radio access network (RAN) supporting vehicle to everything (V2X) communications. To achieve optimum resource allocation and save energy by minimizing the activation of LADN servers in Cloud-RAN, some remote radio heads (RRHs) can be turned on or off depending on the traffic demand. In this paper, we investigate the problem of how to realize effective resource management in 5G RAN supporting V2X communications. More precisely, we first propose a formulation of the resource management problem as an optimization problem with the objective of minimizing the number of RRHs to be turned on subject to the uplink bandwidth constraints. We then use a fully-fledged professional software to solve our optimization problem and propose a solution with heuristic algorithms to deal with the complexity of the problem for large scenarios. Moreover, we analyze the impact of the density of vehicles on the computation time and the influence of the uplink data rate and vehicle densities on the number of active RRHs. Our numerical results show that our proposed model can efficiently utilize the resources and provide optimum vehicles-to-RRHs associations which lead to energy-savings. For instance, to serve 100 vehicles with aggregated uplink data rate equal to 100 [Mbps], the optimal associations save about 70% of the energy comparing to the strongest-signal associations. Furthermore, we obtain optimal results for the small size problem in reasonable computation times, which are around 50 [ms].
Ren-Hung Hwang, Faysal Marzuk, Marek Sikora, Piotr Cholda, Ying-Dar Lin
VTC Fall5
2020 Maximizing accuracy in multi-scanner malware detection systems
Muhammad N. Sakib, Chin-Tser Huang, Ying-Dar Lin
Comput. Networks3
2020 Full encapsulation or internal buffering in OpenFlow based hardware switches?
Bryan C. K. Ng, Yuan-Cheng Lai, Ying-Dar Lin, Winston Khoon Guan Seah
Comput. Networks4
2020 ReFSM: Reverse engineering from protocol packet traces to test generation by extended finite state machines
Ying-Dar Lin, Yu-Kuen Lai, Quan Tien Bui, Yuan-Cheng Lai
J. Netw. Comput. Appl.1
2020 Workload and Capacity Optimization for Cloud-Edge Computing Systems with Vertical and Horizontal Offloading
abstract
A collaborative integration between cloud and edge computing is proposed to be able to exploit the advantages of both technologies. However, most of the existing studies have only considered two-tier cloud-edge computing systems which merely support vertical offloading between local edge nodes and remote cloud servers. This paper thus proposes a generic architecture of cloud-edge computing with the aim of providing both vertical and horizontal offloading between service nodes. To investigate the effectiveness of the design for different operational scenarios, we formulate it as a workload and capacity optimization problem with the objective of minimizing the system computation and communication costs. Because such a mixed-integer nonlinear programming (MINLP) problem is NP-hard, we further develop an approximation algorithm which applies a branch-and-bound method to obtain optimal solutions iteratively. Experimental results show that such a cloud-edge computing architecture can significantly reduce total system costs by about 34%, compared to traditional designs which only support vertical offloading. Our results also indicate that, to accommodate the same number of input workloads, a heterogeneous service allocation scenario requires about a 23% higher system costs than a homogeneous scenario.
Minh-Tuan Thai, Ying-Dar Lin, Yuan-Cheng Lai, Hsu-Tung Chien
IEEE Trans. Netw. Serv. Manag.2
2020 Smoothed Graphic User Interaction on Smartphones With Motion Prediction
abstract
The smoothness of human-smartphone interaction directly influences users experience and affects their purchase decisions. A commonly used method to improve user interaction of smartphones is to optimize the CPU scheduler. However, optimizing the CPU scheduler requires a modification of operating system. In addition, the improvement of the smoothness of human-smartphone interaction may be limited because the display subsystem is not optimized. Therefore, in this paper, we design a motion prediction queuing system, named MPQS, to improve the smoothness of human-smartphone interaction. For this, we use the information of vector, speed, movement, provided by the queuing mechanism of Android, to predict the movement of user-smartphone interaction. Based on the prediction, we then utilize available execution time between frames to perform image processing. We conducted a set of experiments on beagleboard-xM to evaluate the performance of MPQS. Our experiment results show that the proposed method can reduce the number of jank by up to 21.75%.
Ying-Dar Lin, Edward T.-H. Chu, Evan Chang, Yuan-Cheng Lai
IEEE Trans. Syst. Man Cybern. Syst.1
2019 Cost Minimization with Offloading to Vehicles in two-Tier Federated Edge and Vehicular-Fog Systems
abstract
Vehicular-fog system consists of vehicles with computing resources that are mostly under-utilized. Therefore, an edge system may offload some workloads for remote execution at nearby vehicular- fogs. Whether this is cost-effective depends on not only the costs and computation capacities of vehicles but also the amount of workloads and associated latency constraint. In this paper, we consider a two-tier federated Edge and Vehicular- Fog (EVF) architecture and aim to minimize overall cost while meeting latency constraint by setting up an appropriate offloading configuration. We model this to a singleobjective mixed integer programming problem. To solve this mixed integer problem in real time we propose an iterative greedy algorithm using the queuing model. The results show, our proposed architecture reduces the cost of vehicular-fogs by 40â€"45% and the total cost by 35â€"40% compared to the existing architecture and help the edge to provide services beyond its capacity with specified latency constraint.
Ying-Dar Lin, Jui-Chung Hu, Binayak Kar, Li-Hsing Yen
VTC Fall1
2019 A scalable and accurate distributed traffic generator with Fourier transformed distribution over multiple commodity platforms
Chin-Chen Chang 0001, Ying-Dar Lin, Yu-Kuen Lai, Yuan-Cheng Lai
J. Netw. Comput. Appl.2
2019 Performance modeling and analysis of TCP and UDP flows over software defined networks
Yuan-Cheng Lai, Md. Shohrab Hossain, Ying-Dar Lin
J. Netw. Comput. Appl.4
2019 Analytical Modelling of Software and Hardware Switches with Internal Buffer in Software-Defined Networks
Bryan C. K. Ng, Yuan-Cheng Lai, Ying-Dar Lin, Winston Khoon Guan Seah
J. Netw. Comput. Appl.4
2018 Modelling Switches with Internal Buffering in Software-Defined Networks
abstract
OpenFlow supports internal buffering of data packets in an SDN switch whereby a fraction of data packet header is sent to the controller instead of an entire data packet. This internal buffering increases the robustness and the utilization of the link between SDN switches and controller by absorbing temporary burst of packets which may overwhelm the controller. Existing queuing models for SDN have focused on the switches that immediately send packets to the controller for decisioning, with no existing models investigating the impact of the internal buffer in an SDN switch and the associated trade-offs of having an internal buffer. In this paper, we propose an analytical model for SDN switch with the internal buffer to investigate the potential benefits, drawbacks and trade-off of internal buffering in SDN switches. It was observed that a switch with internal buffer achieves up to 30% lower average packet transfer delay and 7% lower packet loss rate at the cost of requiring up to 50% more queue capacity than one without the internal buffer. The proposed model is validated with discrete event simulation where the difference between simulation and analytical results was between 0.6% and 2.8% for average packet transfer delay and less than 6% for average packet loss rate. With this investigation, we provide some guidelines to SDN switch designers on the merits, demerits and trade-off of internal buffering in an SDN switch.
Bryan C. K. Ng, Yuan-Cheng Lai, Ying-Dar Lin, Winston Khoon Guan Seah
ICCCN4
2018 Performance modeling and comparison of NFV integrated with SDN: Under or aside?
Ahmed Fahmin, Yuan-Cheng Lai, Md. Shohrab Hossain, Ying-Dar Lin
J. Netw. Comput. Appl.4
2018 Modelling Software-Defined Networking: Software and hardware switches
Bryan C. K. Ng, Yuan-Cheng Lai, Ying-Dar Lin, Winston Khoon Guan Seah
J. Netw. Comput. Appl.4
2018 Towards load-balanced service chaining by Hash-based Traffic Steering on Softswitches
Minh-Tuan Thai, Ying-Dar Lin, Po-Ching Lin, Yuan-Cheng Lai
J. Netw. Comput. Appl.2
2018 Energy Cost Optimization in Dynamic Placement of Virtualized Network Function Chains
abstract
Network function virtualization (NFV), with its virtualization technologies, brings cloud computing to networking. Virtualized network functions (VNFs) are chained together to provide the required functionality at runtime on demand. It has a direct impact on power consumption depending on where and how these VNFs are placed and chained to accomplish certain demands as the power consumption of a physical machine (PM) depends on its traffic load. One of the advantages of VNF placement over traditional virtual machine placement is that virtualization is not limited solely to servers. The PMs, including the servers and varying loads to these machines and their utilization, are critical issues related to the network's energy consumption. In this paper, we designed a dynamic energy-saving model with NFV technology using an M/M/c queuing network with the minimum capacity policy where a certain amount of load is required to start the machine, which increases the utilization of the machine and avoids frequent changes of the machines' states. We formulate an energy-cost optimization problem with capacity and delay as constraints. We propose a dynamic placement of VNF chains (DPVC) heuristic solution to the NP-hard problem. The results show that the DPVC solution performs better and saves more energy. It uses 45%-55% less active nodes to satisfy the requested demands and increases the utilization of the active nodes by 40%-50% compared to other algorithms.
Binayak Kar, Eric Hsiao-Kuang Wu, Ying-Dar Lin
IEEE Trans. Netw. Serv. Manag.3
2018 Soft Partitioning Flow Tables for Virtual Networking in Multi-Tenant Software Defined Networks
abstract
In a multi-tenancy software defined network (SDN) environment, physical devices such as switches are shared among tenants. In addition to a centralized controller, each tenant has his own controller that manages resources allocated to the tenant. Hence, the centralized controller performs SDN resource virtualization among tenants and acts as proxy between physical resources and tenant controllers. In order to manage the flow tables of the SDN switches, two partitioning strategies are considered. Hard partitioning of flow tables allocates a fixed amount of flow entries to each tenant, but flow tables are wasted if the tenant does not actually use them. On the other hand, soft partitioning strategy shares available flow entries among tenants, resulting in higher utilization but a resource monopoly problem, i.e., flow entries dominated by some greedy tenants. To achieve high flow table utilization and avoid the resource monopoly problem, we propose a soft-partitioning resource manager (SPRM) to manage the flow table resources in a multi-tenancy SDN environment. In SPRM, the allowed number of flow entries for each tenant ranges from a lower bound which equals to the tenant's quota to an upper bound which is dynamically adjusted according to the tenant's past usage. If an incoming flow request of a tenant is beyond his lower bound but under his upper bound, it could be temporarily accepted when there are free entries available. These borrowed flow entries will later be replaced if needed. If a request of a tenant is beyond his upper bound, SPRM will select a least-recently used flow entry of the tenant and replace it with the new request. In addition, SPRM monitors flow table resources and submits modify flow entry messages directly to SDN switches without checks by the management plane as possible in order to reduce flow modification latency. As a result, SPRM could reach higher flow table utilization and lower both flow entry miss rate and Packet_in events. Experimental results show that 100% flow rejections, and 95% Packet_in events are reduced while flow modification latency is decreased by 30%, as compared to hard partitioning.
Ying-Dar Lin, Te-Lung Liu, Yuan-Cheng Lai
IEEE Trans. Netw. Serv. Manag.1
2018 Three-Tier Capacity and Traffic Allocation for Core, Edges, and Devices for Mobile Edge Computing
abstract
In order to satisfy the 5G requirements of ultra-low latency, mobile edge computing (MEC)-based architecture, composed of three-tier nodes, core, edges, and devices, is proposed. In MEC-based architecture, previous studies focused on the controlplane issue, i.e., how to allocate traffic to be processed at different nodes to meet this ultra-low latency requirement. Also important is how to allocate the capacity to different nodes in the management plane so as to establish a minimal-capacity network. The objectives of this paper is to solve two problems: 1) to allocate the capacity of all nodes in MEC-based architecture so as to provide a minimal-capacity network and 2) to allocate the traffic to satisfy the latency percentage constraint, i.e., at least a percentage of traffic satisfying the latency constraint. In order to achieve these objectives, a two-phase iterative optimization (TPIO) method is proposed to try to optimize capacity and traffic allocation in MEC-based architecture. TPIO iteratively uses two phases to adjust capacity and traffic allocation respectively because they are tightly coupled. In the first phase, using queuing theory calculates the optimal traffic allocation under fixed allocated capacity, while in the second phase, allocated capacity is further reduced under fixed traffic allocation to satisfy the latency percentage constraint. Simulation results show that MEC-based architecture can save about 20.7% of capacity of two-tier architecture. Further, an extra 12.2% capacity must be forfeited when the percentage of satisfying latency is 90%, compared to 50%.
Ying-Dar Lin, Yuan-Cheng Lai, Jian-Xun Huang, Hsu-Tung Chien
IEEE Trans. Netw. Serv. Manag.1
2018 Toward Optimal Resource Allocation of Virtualized Network Functions for Hierarchical Datacenters
abstract
Telecommunications service providers (TSPs) previously provided network functions to end users with dedicated hardware, but they are resorting to virtualized infrastructure for reducing costs and increasing flexibility in resource allocation. A representative case is the Central Office Re-architected as Datacenter (CORD) project from AT&T, which aims to deploy virtualized network functions (VNFs) to over 4000 central offices (COs) across the U.S. However, there is a wide spectrum of options for deploying VNFs over the COs, varying from highly distributed to highly centralized manners. The former benefits end users with short response time but has its inherent limitation on utilizing geographically dispersed resources, while the latter allows resources to be better utilized at a cost of longer response time. In this work, we model the TSP's virtualized infrastructure as hierarchical datacenters, namely hierarchical CORD, and provide a resource allocation solution to strike the optimal balance between the two extreme options. Our evaluations reveal that in general, the 3-tier architecture incurs the least cost in case of deploying VNFs under moderate or loose delay constraints. Furthermore, the margin of improvement on the resource allocation cost increases inversely with the overall system utilization rate. Our results also suggest that as heavy request load overwhelms the network infrastructure, the relevant VNFs shall be migrated to lower-tier edge datacenters or to some nearby datacenters with superior network capacity. The evaluations also demonstrate that the proposed model allows highly adaptive VNF deployment in the hierarchical architecture under various conditions.
Chih-Chiang Wang 0001, Ying-Dar Lin, Jang-Jiin Wu, Po-Ching Lin, Ren-Hung Hwang
IEEE Trans. Netw. Serv. Manag.2
2018 Clustering and Symbolic Regression for Power Consumption Estimation on Smartphone Hardware Subsystems
abstract
The subsystem in a smartphone means its hardware components, such as the CPU, GPU, and screen. Accurately estimating subsystem power consumption of commercial smartphones is necessary for applicable to wide research areas. Current subsystem power estimation techniques are mostly based on power models, resulting in considerable errors for various types of power consumption behaviors. These include (1) asynchrony between the measured power consumption and the corresponding workload statistics, and (2) nonlinearity concerning CPU idle states, pixels colors of AMOLED screen, and GPU workload statistics. In this study, we propose a novel utilization-based, subsystem power estimation method for a smartphone, namely Clustering and Symbolic Regression (CSR) that takes these power consumption behaviors into account so as to increase power estimation accuracy. To address asynchrony, we cluster the subsystem workload statistics into synchronous and asynchronous groups by employing affinity propagation clustering. To address nonlinearity, we employ symbolic regression for fitting measured power consumptions with respect to subsystem workload statistics. We compare our approach with various power estimation methods, Linear Regression Model (LM), Genetic Programming (GP), and Support Vector Regression (SVR). The results show Mean Absolute Percentage Error (MAPE) reduction between 23.61 and 42.55 percent on the estimated power consumption of a simple (Nexus S) and complex (Galaxy S4) smartphone subsystems.
Ekarat Rattagan, Ying-Dar Lin, Yuan-Cheng Lai, Edward T.-H. Chu, Kate Ching-Ju Lin
IEEE Trans. Sustain. Comput.2
2018 Wi-Fi offloading between LTE and WLAN with combined UE and BS information
Ying-Dar Lin, Chia-Yu Ku, Yuan-Cheng Lai, Yun-Hao Liang
Wirel. Networks1
2018 Two-tier dynamic load balancing in SDN-enabled Wi-Fi networks
Ying-Dar Lin, Chih-Chiang Wang 0001, Yi-Jen Lu, Yuan-Cheng Lai, Hsi-Chang Yang
Wirel. Networks1
2017 Performance Modeling and Analysis of TCP Connections over Software Defined Networks
abstract
Software Defined Networking (SDN) decouples the control plane from the data plane, thereby enhancing flexibility in network management. Earlier works on SDN modeling only focused on packet-level arrivals without considering flow-level arrivals. However, a model without considering flow-level arrivals cannot correctly reflect the probability of sending packets to the controller. In this paper, we propose an analytical model of SDN considering flow-level (TCP connection) arrivals and packet-level arrivals simultaneously. We use an analytical method termed as 4D state model, which uses four-dimensional states. We have derived the state transition rates of the model and also the packet delay and packet loss probability. We have conducted numerical analysis and extensive simulations. Our results show good matches, which verify the suitability and correctness of our analysis. Error ratios of the analytical results for 4D state model and M/M/1 model against simulation results are also given. Results show that for data packet delays, 4D state can achieve error ratios of 1.16-3.30%, which is much better than 8.57-35.7% attained by M/M/1 model, which only considers packet-level arrivals.
Yuan-Cheng Lai, Md. Mahadi Hassan, Md. Shohrab Hossain, Ying-Dar Lin
GLOBECOM5
2017 Hash-based load balanced traffic steering on softswitches for chaining virtualized network functions
abstract
Prior load balancing solutions for chaining virtualized network functions cause significant control and data plane overheads and demand special requirements on network hardware. In this study, we present the design, implementation, and evaluation of Hash-based Traffic Steering on Softswitches (HATS), a load balancing mechanism that aims at mitigating such drawbacks. The method exploits flow hashing technique implemented on softswitches to perform server and network load balancing without triggering the control plane. We have implemented this design using OpenDayLight controller and Open vSwitch platform. The implementation demonstrates that HATS can be readily implemented with commodity network hardware. Furthermore, the experiment results confirm that HATS can reduce the number of flow entries and service chaining time up to 85% and 93%, respectively, when compared with Least Load First (LLF), a controller-based service chaining algorithm.
Minh-Tuan Thai, Ying-Dar Lin, Po-Ching Lin, Yuan-Cheng Lai
ICC2
2017 SDN-based dynamic multipath forwarding for inter-data center networking
abstract
Since traffic engineering (TE) in Software Defined Networking (SDN) can be much more efficiently and intelligently implemented, Multipath in SDN becomes a new option. However, Ternary Content Addressable Memory (TCAM) size become the bottleneck of SDN. In this paper, we propose an SDN-based Dynamic Flowentry-Saving Multipath (DFSM) mechanism for inter-DC WAN traffic forwarding. DFSM adopts source-destination-based multipath forwarding and latency-aware flow-based traffic splitting to save flow entries and achieve better load balancing. Our evaluations indicate that DFSM saves 15% to 30% system flow entries in different topologies compared to label-based tunneling, and also reduces average latency by 10% to 48% by consuming 8% to 20% more flow entries than Equal-Cost Multipath (ECMP) in less-interconnected topologies. In addition, compared to even traffic splitting, DFSM reduces the standard deviation of path latencies from 14% to 7%.
Yao-Chun Wang, Ying-Dar Lin, Guey-Yun Chang
LANMAN2
2017 Modelling Software-Defined Networking: Switch Design with Finite Buffer and Priority Queueing
abstract
Software Defined Networking (SDN) is a new network architecture that separates control plane and data plane. SDN switch models in the literature primarily use queueing theory in two distinct categories: (i) single shared buffer for control plane traffic and data plane traffic, and (ii) buffer with two priorities to isolate control plane and data plane traffic. Several research works have independently studied these two buffer sharing mechanism but do not address the tradeoffs between these two buffer sharing mechanisms. The evaluation shows that shared buffer requires approximately up to 85% higher delays to install the flow table entries in the switch and up to 82% extra buffer capacity compared with the priority queueing buffer.
Bryan C. K. Ng, Yuan-Cheng Lai, Ying-Dar Lin, Winston Khoon Guan Seah
LCN4
2017 Scalable multicasting with multiple shared trees in software defined networking
Ying-Dar Lin, Yuan-Cheng Lai, Hung-Yi Teng, Chun-Chieh Liao, Yi-Chih Kao
J. Netw. Comput. Appl.1
2016 Fast failover and switchover for link failures and congestion in software defined networks
abstract
In this paper, we present a fast failover mechanism and a fast switchover mechanism to deal with link failure and congestion problems. In the fast failover mechanism, the controller pre-establishes multiple paths for each source-destination pair in the related OpenFlow-enabled (OF) switches. When a link becomes faulty, OF switches are able to failover the affected flows to another path. Based on the pre-established paths, in the fast switchover mechanism, the controller periodically monitors the status of each port of each OF switch. When the average transmission rate of a port consistently exceeds the rate threshold, the controller would decrease the transmission rate of the port by iteratively switching the flow with the minimum rate to another path. The emulation on Ryu controller and Mininet emulator shows the average recovery time of the fast failover mechanism is less than 40 ms, compared to hundreds of ms in the fast restoration mechanism. And, the fast switchover mechanism can reduce 47.5%-72.5% sustained time of link congestion depending on the parameter setting.
Ying-Dar Lin, Hung-Yi Teng, Chia-Rong Hsu, Chun-Chieh Liao, Yuan-Cheng Lai
ICC1
2016 A joint network and server load balancing algorithm for chaining virtualized network functions
abstract
Chaining virtualized network functions (VNF) is an effective practice to deploy network services in network operator's data centers. Two common concerns arise in such a deployment are network load balancing and server load balancing. In this study, motivated by the argument that such two concerns should be jointly addressed for efficiently chaining VNFs in a data center environment, we propose a 2-phase algorithm, Nearest First and Local-Global Transformation (NF-LGT), which concurrently supports network and service load balancing. The algorithm firstly constructs service chains by a greedy strategy which both considers network latency and server latency. Then a searching technique is applied to improve the solutions. We have implemented the algorithm using Software-defined networking (SDN)/OpenFlow concept. The experimental results indicate that, compared with a sequential approach, NF-LGT improves the system bandwidth utilization up to 45%.
Minh-Tuan Thai, Ying-Dar Lin, Yuan-Cheng Lai
ICC2
2016 High performance traffic classification based on message size sequence and distribution
Chun-Nan Lu, Chun-Ying Huang, Ying-Dar Lin, Yuan-Cheng Lai
J. Netw. Comput. Appl.3
2016 The Budgeted Maximum Coverage Problem in Partially Deployed Software Defined Networks
abstract
Due to the large installed base of distributed legacy networks, software defined networking (SDN) nodes may be required to coexist with legacy nodes to form hybrid networks. It has been shown that such a hybrid network has better performance than a pure legacy network due to smarter transmission scheduling. Despite such advantages, limited budgets continue to hinder the rapid adaptation of SDNs. Only a part of the network can be upgraded at a time especially for large-scale networks. In this paper, we define the minimum percentage of SDN nodes in a path, and paths with at least one SDN node, as the hop coverage and path coverage, respectively. We intend to evaluate the relationship between cost and coverage in the partially deployed SDNs. We formulate SDN node selection as four optimization problems with hop/path coverage and cost as objectives and constraints, respectively, and vice-versa. We propose two heuristic solutions: 1) maximum number of uncovered path first (MUcPF) and 2) maximum number of minimum hop covered path first (MMHcPF), to these NP-hard problems. Through a MATLAB experiment, we show that MUcPF is significantly better in terms of economy and efficiency to establish a hybrid path between every pair of hosts in the network. In particular, it required 5%-15% less investment to achieve 100% path coverage compared to other algorithms. The results show the coverage consistency of MMHcPF on each individual path along with gains in terms of cost and efficiency. It takes 5%-20% less investment to achieve certain hop coverage target compared to other existing algorithms.
Binayak Kar, Eric Hsiao-Kuang Wu, Ying-Dar Lin
IEEE Trans. Netw. Serv. Manag.3
2016 SEMI: Semi-Online Power Estimates for Smartphone Hardware Components
abstract
Using the data obtained from a battery monitoring unit (BMU) are a low-cost, easy-to-use way to estimate the power consumption of smartphones. Current online power estimation methods produce significant errors compared to using external power monitors because online methods do not address the three most important factors which affect the efficacy of online power consumption estimates. These are: (1) battery capacity degradation with aging, (2) asynchronous power consumption, and (3) the effect of state-of-charge (SoC) difference, the remaining power level of the battery. This paper presents a semi-online power estimate method which uses charging data to determine actual battery capacity, applies the discrepancy between battery voltage at different workloads for asynchronous power detection, and analyzes the range of SoC (0-100 percent) which causes minimal power estimate errors. The proposed method is validated by conducting a series of experiments on a smartphone and comparing the results with the existing online power estimation methods. Experimental results on the power consumption estimates of real applications indicate that the semi-online method reduced the error rate of power estimates obtained from existing online methods by 27-94 percent. Moreover, this work also shows that battery capacity degradation is the major factor affecting the efficacy of online power estimations.
Ekarat Rattagan, Edward T.-H. Chu, Ying-Dar Lin, Yuan-Cheng Lai
IEEE Trans. Sustain. Comput.3
2015 Security and privacy in unified communications: Challenges and solutions
Georgios Karopoulos, Georgios Portokalidis, Josep Domingo-Ferrer, Ying-Dar Lin, Dimitris Geneiatakis, Georgios Kambourakis
Comput. Commun.4
2015 Two-tier project and job scheduling for SaaS cloud service providers
Ying-Dar Lin, Minh-Tuan Thai, Chih-Chiang Wang 0001, Yuan-Cheng Lai
J. Netw. Comput. Appl.1
2015 Stateful traffic replay for web application proxies
abstract
Abstract It is a common practice to test a network device by replaying network traffic onto it and observe its reactions. Many replay tools support Transmission Control Protocol/Internet Protocol stateful traffic replay and hence can be used to test switches, routers, and gateway devices. However, they often fail if the device under test (DUT) is an application level proxy. In this paper, we design and implement ProxyReplay to replay application‐layer traffic for network proxies. As many application proxies have built‐in security functions, the main purpose of this tool is to evaluate the security functionalities of DUTs using payloads constructed from real network traces. ProxyReplay modifies requests and responses and maintains queues for request‐response pairs to resolve the issues of protocol dependency, functional dependency, concurrent replay, and error resistance. The solution provides two replay modes, that is, the preprocess mode and the concurrent mode. Depending on the benchmark scenario, we show that the preprocess mode is better for benchmarking the performance capability of a DUT. In contrast, the concurrent mode is used when the replayed trace file is extremely large. Our experiments show 99% accuracy. In addition, the replay performance exceeds 320 Mbps by running the benchmark with an off‐the‐shelf personal computer in the preprocess mode. Copyright © 2014 John Wiley & Sons, Ltd.
Chun-Ying Huang, Ying-Dar Lin, Peng-Yu Liao, Yuan-Cheng Lai
Secur. Commun. Networks2
2015 Three-phase behavior-based detection and classification of known and unknown malware
abstract
Abstract To improve both accuracy and efficiency in detecting known and even unknown malware, we propose a three‐phase behavior‐based malware detection and classification approach, with a faster detector in the first phase to filter most samples, a slower detector in the second phase to observe remaining ambiguous samples, and then a classifier in the third phase to recognize their malware type. The faster detector executes programs in a sandbox to extract representative behaviors fed into a trained artificial neural network to evaluate their maliciousness, whereas the slower detector extracts and matches the LCSs of system call sequences fed into a trained Bayesian model to calculate their maliciousness. In the third phase, we define malware behavior vectors and calculate the cosine similarity to classify the malware. The experimental results show that the hybrid two‐phase detection scheme outperforms the one‐phase schemes and achieves 3.6% in false negative and 6.8% in false positive. The third‐phase classifier also distinguishes the known‐type malware with an accuracy of 85.8%. Copyright © 2015 John Wiley & Sons, Ltd.
Ying-Dar Lin, Yuan-Cheng Lai, Chun-Nan Lu, Peng-Kai Hsu, Chia-Yin Lee
Secur. Commun. Networks1
2014 Reducing power consumption in LTE data scheduling with the constraints of channel condition and QoS
Li-Ping Tung, Ying-Dar Lin, Yu-Hsien Kuo, Yuan-Cheng Lai, Krishna M. Sivalingam
Comput. Networks2
2014 Calibrating parameters and formulas for process-level energy consumption profiling in smartphones
Ying-Dar Lin, Ekarat Rattagan, Yuan-Cheng Lai, Li-Pin Chang, Yun-Chien Yo, Cheng-Yuan Ho, Shun-Lee Chang
J. Netw. Comput. Appl.1
2014 Guest Editorial Deep Packet Inspection: Algorithms, Hardware, and Applications
abstract
The thirteen articles in this special section explore the technology of deep packet inspection (DPI). DPI examines the content in packet payloads to search for signatures of network applications, signs of malicious activities, and leaks of sensitive information, rather than just examine packet headers for information such as IP addresses and port numbers. The inspection provides network devices with rich information of application protocol messages in packet payloads, and enables them to make intelligent decisions in packet processing based on the information. The papers are organized into the following four sections: (1) Scalable Algorithms and Architectures for DPI, (2) Network Traffic Analysis with DPI, (3) Network Protocol Identification with DPI, and (4) Network Security Analysis with DPI.
Ying-Dar Lin, Po-Ching Lin, Viktor Prasanna 0001, H. Jonathan Chao, John W. Lockwood
IEEE J. Sel. Areas Commun.1
2014 Secure and transparent network traffic replay, redirect, and relay in a dynamic malware analysis environment
abstract
ABSTRACT Dynamic analysis is typically performed in a closed network environment to prevent the malware under analysis from attacking machines on the Internet. However, many of today's malwares require Internet connectivity to operate and to be thoroughly analyzed in a closed network environment. We propose a secure and transparent network environment that allows the malware in a dynamic analysis environment to have seemingly unrestricted Internet access in a secure manner. Our environment transparently dispatches malicious network traffic to compatible decoys while allowing harmless control traffic to have Internet access. We use 12 real‐world malware samples, which involve Internet connections, to evaluate the effectiveness of the proposed environment. The evaluation shows that the proposed environment can allow malware to exhibit more network activities than a closed network environment and can even outperform the baseline open network environment in some cases. In the meantime, Internet security is maintained by the dispatching of attack and propagation traffic to decoys inside the analysis environment. Copyright © 2013 John Wiley & Sons, Ltd.
Ying-Dar Lin, Tzung-Bi Shih, Yu-Sung Wu, Yuan-Cheng Lai
Secur. Commun. Networks1
2014 Behavior-based botnet detection in parallel
abstract
ABSTRACT Botnet has become one major Internet security issue in recent years. Although signature‐based solutions are accurate, it is not possible to detect bot variants in real‐time. In this paper, we propose behavior‐based botnet detection in parallel (BBDP). BBDP adopts a fuzzy pattern recognition approach to detect bots. It detects a bot based on anomaly behavior in domain name service (DNS) queries and transmission control protocol (TCP) requests. With the design objectives of being efficient and accurate, a bot is detected using the proposed five‐stage process, including: (i) traffic reduction, which shrinks an input trace by deleting unnecessary packets; (ii) feature extraction, which extracts features from a shrunk trace; (iii) data partitioning, which divides features into smaller pieces; (iv) DNS detection phase, which detects bots based on DNS features; and (v) TCP detection phase, which detects bots based on TCP features. The detection phases, which consume approximately 90% of the total detection time, can be dispatched to multiple servers in parallel and make detection in real‐time. The large scale experiments with the Windows Azure cloud service show that BBDP achieves a high true positive rate (95%+) and a low false positive rate ( ∼ 3%). Meanwhile, experiments also show that the performance of BBDP can scale up linearly with the number of servers used to detect bots. Copyright © 2013 John Wiley & Sons, Ltd.
Kuochen Wang, Chun-Ying Huang, Li-Yang Tsai, Ying-Dar Lin
Secur. Commun. Networks4
2014 On-the-Fly Capture and Replay Mechanisms for Multi-Port Network Devices in Operational Networks
abstract
Testing network devices in a live environment is desirable due to its reality. However, the defects are not reproducible, and the network connectivity will be broken if the device is down. For effective defect reproduction from real traffic, we design a new mechanism, which allows the device under test (DUT) to be automatically online/offline, and supports multi-port replay for multi-port network devices with an OpenFlow switch. The defect traces are captured when the DUT is online. When a DUT failure is detected, the DUT will be offline, and the defect-triggering traces will be replayed to identify the defect. For efficient replay, we keep only partial payloads in a reduced number of packets in the defect traces that are sufficient to trigger the defects. For defect identification, reduction based on a binary search algorithm is presented to deal with the defects caused by payload anomalies and by overloading. The downsizing ratios in the cases of payload anomalies and overloading are up to 98.8% and 96%, respectively. The minimum outage time of the failover during the DUT failure is obtained when the check interval is 1 second and the number of tolerable consecutive failures is 2.
Ying-Dar Lin, Po-Ching Lin, Yuan-Cheng Lai
IEEE Trans. Netw. Serv. Manag.1
2014 On the Accuracy, Efficiency, and Reusability of Automated Test Oracles for Android Devices
abstract
Automated GUI testing consists of simulating user events and validating the changes in the GUI in order to determine if an Android application meets specifications. Traditional record-replay testing tools mainly focus on facilitating the test case writing process but not the replay and verification process. The accuracy of testing tools degrades significantly when the device under test (DUT) is under heavy load. In order to improve the accuracy, our previous work, SPAG, uses event batching and smart wait function to eliminate the uncertainty of the replay process and adopts GUI layout information to verify the testing results. SPAG maintains an accuracy of up to 99.5 percent and outperforms existing methods. In this work, we propose smart phone automated GUI testing tool with camera (SPAG-C), an extension of SPAG, to test an Android hardware device. Our goal is to further reduce the time required to record test cases and increase reusability of the test oracle without compromising test accuracy. In the record stage, SPAG captures screenshots from device's frame buffer and writes verification commands into the test case. Unlike SPAG, SPAG-C captures the screenshots from an external camera instead of frame buffer. In the replay stage, SPAG-C automatically performs image comparison while SPAG simply performs a string comparison to verify the test results. In order to make SPAG-C reusable for different devices and to allow bettersynchronization at the time of capturing images, we develop a new architecture that uses an external camera and Web services to decouple the test oracle. Our experiments show that recording a test case using SPAG-C's automatic verification is as fast as SPAG's but more accurate. Moreover, SPAG-C is 50 to 75 percent faster than SPAG in achieving the same test accuracy. With reusability, SPAG-C reduces the testing time from days to hours for heterogeneous devices.
Ying-Dar Lin, José F. Rojas, Edward T.-H. Chu, Yuan-Cheng Lai
IEEE Trans. Software Eng.1
2013 Identifying android malicious repackaged applications by thread-grained system call sequences
Ying-Dar Lin, Yuan-Cheng Lai, Hao-Chuan Tsai
Comput. Secur.1
2013 Creditability-based weighted voting for reducing false positives and negatives in intrusion detection
Ying-Dar Lin, Yuan-Cheng Lai, Cheng-Yuan Ho, Wei-Hsuan Tai
Comput. Secur.1
2013 Booting, browsing and streaming time profiling, and bottleneck analysis on android-based systems
Ying-Dar Lin, Cheng-Yuan Ho, Yuan-Cheng Lai, Tzu-Hsiung Du, Shun-Lee Chang
J. Netw. Comput. Appl.1
2012 Real traffic replay over WLAN with environment emulation
abstract
Real traffic replay is one of the solutions used to test network devices over complicated scenarios. Packet traces captured in a real environment hold more details than any mathematical models. However, the lack of packet-replay control and environment emulation might highly affect traffic behaviors, especially in wireless networks. Real traffic replay in wireless networks requires packet-replay control to manage the interactions with the device under test (DUT), and coordinately reproduces environment effects, such as fading, noise, and interference. In this work, we propose a method, called Event-driven Automata-synchronized Replay (EAR), to address real traffic replay over WLAN. EAR transforms the captured packet trace into a sequence of events that follow the IEEE 802.11 protocol. The three-level automata are applied to achieve packet-replay control and synchronize the environment effects in traffic replay with the packets and signals captured in a real environment. We propose a quantitative metric, called the event reproduction ratio (ERR), to evaluate the effectiveness of traffic replay. Our software implementation on the Linux-based system demonstrates that EAR achieves the ERR of 95.9% and 92.45% over the DUT-dependent traffic and fading environments, respectively. Under the same condition, the straight-forward replay can only produce the ERR of 20.6% and 0%, respectively.
Chia-Yu Ku, Ying-Dar Lin, Yuan-Cheng Lai, Pei-Hsuan Li, Kate Ching-Ju Lin
WCNC2
2012 Session level flow classification by packet size distribution and session grouping
Chun-Nan Lu, Chun-Ying Huang, Ying-Dar Lin, Yuan-Cheng Lai
Comput. Networks3
2012 Test coverage optimization for large code problems
Ying-Dar Lin, Chi-Heng Chou, Yuan-Cheng Lai, Tse-Yau Huang, Simon Chung, Jui-Tsun Hung, Frank C. Lin
J. Syst. Softw.1
2011 Indoor deployment of IEEE 802.11s mesh networks: Lessons and guidelines
Ying-Dar Lin, Shun-Lee Chang, Jui-Hung Yeh, Shau-Yu Cheng
Ad Hoc Networks1
2011 A fuzzy pattern-based filtering algorithm for botnet detection
Kuochen Wang, Chun-Ying Huang, Shang-Jyh Lin, Ying-Dar Lin
Comput. Networks4
2011 Research challenges towards the Future Internet
Marco Conti, Song Chong, Serge Fdida, Weijia Jia 0001, Holger Karl, Ying-Dar Lin, Petri Mähönen, Martin Maier 0001, Refik Molva, Steve Uhlig, Moshe Zukerman
Comput. Commun.6
2011 Realizing and benchmarking broadcast algorithms in wireless mesh networks
Ying-Dar Lin, Shun-Lee Chang, Shi-Hung Tao, Jui-Hung Yeh
Comput. Commun.1
2011 A Hybrid Algorithm of Backward Hashing and Automaton Tracking for Virus Scanning
abstract
Virus scanning involves computationally intensive string matching against a large number of signatures of different characteristics. Matching a variety of signatures challenges the selection of matching algorithms, as each approach has better performance than others for different signature characteristics. We propose a hybrid approach that partitions the signatures into long and short ones in the open-source ClamAV for virus scanning. An algorithm enhanced from the Wu-Manber algorithm, namely the Backward Hashing algorithm, is responsible for only long patterns to lengthen the average skip distance, while the Aho-Corasick algorithm scans for only short patterns to reduce the automaton sizes. The former utilizes the bad-block heuristic to exploit long shift distance and reduce the verification frequency, so it is much faster than the original WM implementation in ClamAV. The latter increases the AC performance by around 50 percent due to better cache locality. We also rank the factors to indicate their importance for the string matching performance.
Po-Ching Lin, Ying-Dar Lin, Yuan-Cheng Lai
IEEE Trans. Computers2
2010 Embedded TaintTracker: Lightweight Tracking of Taint Data against Buffer Overflow Attacks
abstract
Taint tracking is a novel technique to prevent buffer overflow. Previous studies on taint tracking ran a victim's program on an emulator to dynamically instrument the code for tracking the propagation of taint data in memory and checking whether malicious code is executed. However, the critical problem of this approach is its heavy performance overhead. This paper proposes a new taint-style system called Embedded TaintTracker to eliminate the overhead in the emulator and dynamic instrumentation by compressing a checking mechanism into the operating system (OS) kernel and moving the instrumentation from runtime to compilation time. Results show that the proposed system outperforms the previous work, TaintCheck, by at least 8 times on throughput degradation, and is about 17.5 times faster than TaintCheck when browsing 1KB web pages.
Ying-Dar Lin, Fan-Cheng Wu, Tze-Yau William Huang, Yuan-Cheng Lai, Frank C. Lin
ICC1
2010 Thread allocation in CMP-based multithreaded network processors
Yi-Neng Lin, Ying-Dar Lin, Yuan-Cheng Lai
Parallel Comput.2
2009 Extracting Attack Sessions from Real Traffic with Intrusion Prevention Systems
abstract
False Positive (FP) and False Negative (FN) happen to every Intrusion Prevention System (IPS). No one could do better judgment than others all the time. This work proposes a system of Attack Session Extraction (ASE) to create a pool of suspicious traffic traces which cause potential FNs (abbreviated as P-FNs) and potential FPs (abbreviated as P-FPs) to IPSes. Developers of IPSes can use these suspicious traffic traces to improve the accuracy of their products. Traffic traces are called suspicious since what they cause are P-FNs and P-FPs which need to be confirmed by the developers of IPSes whether P-FNs are FNs and P-FPs are FPs. First, the ASE captures real traffic and replays captured traffic traces to multiple IPSes. By comparing the logs of IPSes, we can find that some attack logs are logged or not logged only at certain IPS. The former is P-FPs, while the latter is P-FNs to that IPS. The ASE then starts to extract this suspicious traffic from replayed traffic traces. The extracted traffic traces can then be used for further analysis by IPS developers. Some of the traces may prove to be guilty, i.e. confirmed to be FNs and FPs. To completely extract a suspicious session, the ASE uses an association mechanism based on anchor packets, five-tuple and time, and similarity for the first packet, first connection, and whole session, respectively. It calculates the degree of similarity among packets to extract a suspicious session containing multiple connections. We define variation and completeness/purity as the performance indexes to evaluate ASE. The experiments demonstrate that 95% of extracted sessions have low variation, and the average completeness/purity is around 80%.
I-Wei Chen, Po-Ching Lin, Chi-Chung Luo, Tsung-Huan Cheng, Ying-Dar Lin, Yuan-Cheng Lai, Frank C. Lin
ICC5
2009 Highest Urgency First (HUF): A latency and modulation aware bandwidth allocation algorithm for WiMAX base stations
Yi-Neng Lin, Ying-Dar Lin, Yuan-Cheng Lai, Che-Wen Wu
Comput. Commun.2
2009 Application classification using packet size distribution and port association
Ying-Dar Lin, Chun-Nan Lu, Yuan-Cheng Lai, Wei-Hao Peng, Po-Ching Lin
J. Netw. Comput. Appl.1
2009 Modeling and analysis of core-centric network processors
abstract
Network processors can be categorized into two types, the coprocessors-centric model in which the data-plane is handled by coprocessors, and the core-centric model in which the core processes most of the data-plane packets yet offloading some tasks to coprocessors. While the former has been properly explored over various applications, researches regarding the latter remain limited. Based on the previous experience of prototyping the virtual private network (VPN) over the IXP425 network processor, this work aims to derive design implications for the core-centric model performing computational intensive applications. From system and IC vendors' perspectives, the continuous-time Markov chain and Petri net simulations are adopted to explore this architecture. Analytical results prove to be quite inline with those of the simulation and implementation. With subsequent investigation we find that appropriate process run lengths can improve the effective core utilization by 2.26 times, and by offloading the throughput boosts 7.5 times. The results also suggest single process programming since context switch overhead impacts considerably on the performance.
Yi-Neng Lin, Ying-Dar Lin, Kuo-Kun Tseng, Yuan-Cheng Lai
ACM Trans. Embed. Comput. Syst.2
2009 A fast scalable automaton-matching accelerator for embedded content processors
abstract
Home and office network gateways often employ a cost-effective embedded network processor to handle their network services. Such network gateways have received strong demand for applications dealing with intrusion detection, keyword blocking, antivirus and antispam. Accordingly, we were motivated to propose an appropriate fast scalable automaton-matching (FSAM) hardware to accelerate the embedded network processors. Although automaton matching algorithms are robust with deterministic matching time, there is still plenty of room for improving their average-case performance. FSAM employs novel prehash and root-index techniques to accelerate the matching for the nonroot states and the root state, respectively, in automation based hardware. The prehash approach uses some hashing functions to pretest the input substring for the nonroot states while the root-index approach handles multiple bytes in one single matching for the root state. Also, FSAM is applied in a prevalent automaton algorithm, Aho-Corasick (AC), which is often used in many content-filtering applications. When implemented in FPGA, FSAM can perform at the rate of 11.1Gbps with the pattern set of 32,634 bytes, demonstrating that our proposed approach can use a small logic circuit to achieve a competitive performance, although a larger memory is used. Furthermore, the amount of patterns in FSAM is not limited by the amount of internal circuits and memories. If the high-speed external memories are employed, FSAM can support up to 21,302 patterns while maintaining similar high performance.
Kuo-Kun Tseng, Yuan-Cheng Lai, Ying-Dar Lin, Tsern-Huei Lee
ACM Trans. Embed. Comput. Syst.3
2009 Realizing a Sub-Linear Time String-Matching Algorithm With a Hardware Accelerator Using Bloom Filters
abstract
Many network security applications rely on string matching to detect intrusions, viruses, spam, and so on. Since software implementation may not keep pace with the high-speed demand, turning to hardware-based solutions becomes promising. This work presents an innovative architecture to realize string matching in sub-linear time based on algorithmic heuristics, which come from parallel queries to a set of space-efficient Bloom filters. The algorithm allows skipping characters not in a match in the text, and in turn simultaneously inspect multiple characters in effect. The techniques to reduce the impact of certain bad situations on performance are also proposed: thebad-blockheuristic, a linear worst-case time method and a non-blocking interface to hand over the verification job to a verification module. This architecture is simulated with both behavior simulation in C and timing simulation in HDL for antivirus applications. The simulation shows that the throughput of scanning Windows executable files for more than 10000 virus signatures can achieve 5.64 Gb/s, while the worst-case performance is 1.2 Gb/s if the signatures are properly specified.
Po-Ching Lin, Ying-Dar Lin, Yuan-Cheng Lai, Yi-Jun Zheng, Tsern-Huei Lee
IEEE Trans. Very Large Scale Integr. Syst.2
2008 Thread Allocation in Chip Multiprocessor Based Multithreaded Network Processors
abstract
This work tries to derive ideas for thread allocation in chip multiprocessor (CMP)-based network processors performing general applications by continuous-time Markov chain modeling and Petri net simulations. The concept of P-M ratio, where P and M indicate the computational and memory access overhead when processing a packet, is introduced and the relation to thread allocation is explored. Results indicate that the demand of threads in a processor diminishes rapidly as P-M ratio increases to 0.066, and decreases slowly afterwards. Observations from a certain P-M ratio can be applied to various software-hardware combinations having the same ratio.
Yi-Neng Lin, Ying-Dar Lin, Yuan-Cheng Lai
AINA2
2008 Multiple-Resource Request Scheduling for Differentiated QoS at Website Gateway
abstract
Differentiated quality of service is a way for a website operator to provide different service levels to its clients. Traditional HTTP request scheduling schemes can achieve this, but they schedule requests to manage only one server resource, such as CPU or disk I/O. Actually, processing a request on the server will consume multiple resources. This paper presents a multiple-resource request scheduling algorithm, called mQoS, for differentiating the utilization of the server resource. The mQoS scheduler consists of several sub-schedulers and a main scheduler. Each sub-scheduler manages a server resource to differentiate its utilization among the classes. The main scheduler checks the availability of every server resource and triggers an appropriate sub-scheduler to balance the utilization of server resources. The implementation of the mQoS gateway is based on Squid and Linux. The evaluation compares the mQoS scheduling with no scheduling (nQoS) and single-re source request scheduling (sQoS). The mQoS scheduling reveals the accurate differentiation on every server resource. In addition, the total server throughput in the mQoS scheduling is improved by 21%, compared with the sQoS scheduling. The average user-perceived latency of the mQoS scheduling is also shorter than other scheduling.
Ying-Dar Lin, Ching-Ming Tien, Shih-Chiang Tsao, Ruo-Hua Feng, Yuan-Cheng Lai
AINA1
2008 A Latency and Modulation Aware Bandwidth Allocation Algorithm for WiMAX Base Stations
abstract
The mobile WiMAX systems based on IEEE 802.16e-2005 provide high data rate for the mobile wireless network. However, the link quality is frequently unstable owing to the long-distance and air interference and therefore impacts real-time applications. Thus, a bandwidth allocation algorithm is required to be modulation-aware, while further satisfying the latency guarantee, service differentiation and fairness. This work proposes the Highest Urgency First (HUF) algorithm to conquer the above challenges by taking into consideration the adaptive modulation and coding scheme (MCS) and the urgency of requests. Downlink and uplink sub-frames are determined by reserving the bandwidth for the most urgent requests and proportionating the remaining bandwidth for others. Then, independently in the downlink and uplink, the HUF allocates bandwidth to every mobile station according to a pre-calculated U-factor which considers urgency, priority and fairness. Simulation results prove the HUF is modulation-aware and achieves the above three objectives, notably the zero violation rate within system capacity as well as the throughput paralleling to the best of the existing approaches.
Yi-Neng Lin, Che-Wen Wu, Ying-Dar Lin, Yuan-Cheng Lai
WCNC3
2008 On applying fair queuing discipline to schedule requests at access gateway for downlink differential QoS
Shih-Chiang Tsao, Yuan-Cheng Lai, Le-Chi Tsao, Ying-Dar Lin
Comput. Networks4
2008 Multiple-resource request scheduling for differentiated QoS at website gateway
Ying-Dar Lin, Ching-Ming Tien, Shih-Chiang Tsao, Ruo-Hua Feng, Yuan-Cheng Lai
Comput. Commun.1
2008 Erratum to "Multiple-resource request scheduling for differentiated QoS at website gateway"
Ying-Dar Lin, Ching-Ming Tien, Shih-Chiang Tsao, Ruo-Hua Feng, Yuan-Cheng Lai
Comput. Commun.1
2008 Designing and evaluating interleaving decompressing and virus scanning in a stream-based mail proxy
Ying-Dar Lin, Szu-Hao Chen, Po-Ching Lin, Yuan-Cheng Lai
J. Syst. Softw.1
2008 Modeling and analysis of core-centric network processors
abstract
Network processors can be categorized into two types, the coprocessors-centric model in which data-plane is handled by coprocessors, and the core-centric model in which the core processes most of the data-plane packets yet offloading some tasks to coprocessors. While the former has been properly explored over various applications, research regarding the latter remain limited. Based on the previous experience of prototyping the virtual private network (VPN) over the IXP425 network processor, this work aims to derive design implications for the core-centric model performing computational intensive applications. From system and IC vendors' perspectives, the continuous-time Markov chain and Petri net simulations are adopted to explore this architecture. Analytical results prove to be quite inline with those of the simulation and implementation. With subsequent investigation, we find that appropriate process run lengths can improve the effective core utilization by 2.26 times, and by offloading the throughput boosts 7.5 times. The results also suggest single-process programming, since context-switch overhead impacts considerably on the performance.
Yi-Neng Lin, Ying-Dar Lin, Yuan-Cheng Lai, Kuo-Kun Tseng
ACM Trans. Embed. Comput. Syst.2
2007 kP2PADM: An In-kernel Gateway Architecture for Managing P2P Traffic
abstract
This work presents an in-kernel gateway architecture on Linux, namely kP2PADM, for managing P2P traffic on dynamic ports. This design can effectively eliminate redundant data passing between the kernel space and the user space. The management functions include: (1) classifying and filtering P2P traffic, (2) scanning viruses on shared files, (3) auditing chatting messages and transferred files, and (4) bandwidth control. Practical implementation issues and techniques in the system design are discussed herein. This design proposes a dual-queue architecture to handle packet reassembly and resolve head-of-line blocking. A connection cache accelerates handling the reconnection requests from the peers. The throughput can achieve up to 185.73 Mbps even with content filtering, and remains around 79.09 Mbps when virus scanning is enabled. The impacts of each management function and out-of-order packets on performance are also analyzed through the internal benchmarks.
Ying-Dar Lin, Po-Ching Lin, Meng-Fu Tsai, Tsao-Jiang Chang, Yuan-Cheng Lai
IPDPS1
2007 On-the-fly TCP path selection algorithm in access link load balancing
Ying-Dar Lin, Shih-Chiang Tsao, Un-Pio Leong
Comput. Commun.1
2007 A platform-based SoC design and implementation of scalable automaton matching for deep packet inspection
Ying-Dar Lin, Kuo-Kun Tseng, Tsern-Huei Lee, Yi-Neng Lin, Chen-Chou Hung, Yuan-Cheng Lai
J. Syst. Archit.1
2007 Resource allocation in network processors for network intrusion prevention systems
Yi-Neng Lin, Yao-Chung Chang, Ying-Dar Lin, Yuan-Cheng Lai
J. Syst. Softw.3
2005 A Parallel Automaton String Matching with Pre-Hashing and Root-Indexing Techniques for Content Filtering Coprocessor
abstract
We propose a new parallel automaton string matching approach and its hardware architecture for content filtering coprocessor. This new approach can improve the average matching time of the parallel automaton with pre-hashing and root-indexing techniques. The pre-hashing technique uses a hashing function to verify quickly the text against the partial patterns in the automaton, and the root-indexing technique matches multiple bytes for the root state in one single matching. A popular automaton algorithm, Aho-Corasick (AC) is chosen to be implemented by adding the two techniques; we employ these two techniques in a memory efficient version of AC namely bitmap AC. For the average-case time, our approach improves bitmap AC by 494% and 224% speedup for URL and virus patterns, respectively. Since pre-hashing and root-indexing techniques can be concurrently executed with bitmap AC in the hardware, our proposed approach has the same worst-case time as bitmap AC.
Kuo-Kun Tseng, Ying-Dar Lin, Tsern-Huei Lee, Yuan-Cheng Lai
ASAP2
2005 VPN Gateways over Network Processors: Implementation and Evaluation
abstract
Networking applications, such as VPN and content filtering, demand extra computing power in order to meet the throughput requirement nowadays. In addition to pure ASIC solutions, network processor architecture is emerging as an alternative to scale up data-plane processing while retaining design flexibility. This article, rather than proposing new algorithms, illustrates the experience in developing IPSec-based VPN gateways over network processors, and investigates the performance issues. The external benchmarks reveal that the system can reach 45 Mbps for IPSec using 3DES algorithm, which improves by 350% compared to single XScale core processor and parallels the throughput of a PIII 1 GHz processor. Through the internal benchmarks, we analyze the turnaround times of the main functional blocks, and identify the core processor as the performance bottleneck for both packet forwarding and IPSec processing.
Yi-Neng Lin, Chiuan-Hung Lin, Ying-Dar Lin, Yuan-Cheng Lai
IEEE Real-Time and Embedded Technology and Applications Symposium3
2004 Tunnel minimization and relay for managing virtual private networks
abstract
A virtual private network (VPN) is a private data network, that carries traffic between remote sites. One of the most popular VPN applications is the "intranet/extranet VPN", which establishes network layer connections between remote intranet sites, using various tunneling protocols, to create an IP overlay network. IPSec, which is very prevalent in the industry, is one of these tunneling protocols that not only provide encapsulation/decapsulation but encryption/decryption and hashing, However, an IPSec tunnel often fails to be established due to the management complexity. The paper proposes a new concept of authority to alleviate the management overhead by reducing the number of tunnels. The problem of tunnel minimization is first formalized under three conditions - no constraint, a tunnel path length constraint and a tunnel relay degree constraint - and is then solved using graphical models and the zero-one integer programming algorithm. The effect of tunnel minimization is also investigated, and at most 90% of the tunnels are found to be reducible in a general enterprise VPN.
I-Wei Chen, Ying-Dar Lin, Yi-Neng Lin
GLOBECOM2
2004 On-the-fly TCP path selection algorithm in access link load balancing
abstract
Many enterprises install multiple access links for fault tolerance or bandwidth enlargement. Dispatching connections through good links is the ultimate goal in utilizing multiple access links. The traditional dispatching method is only based on the condition of the access links to ISPs. It may achieve fair utilization of the access links but poor performance on connection throughput. In this work, we propose a new approach to maximize the per-connection end-to-end throughput by the on-the-fly round trip time (RTT) probing mechanism. The RTTs through all possible links are probed by duplicating the SYN packet during the three way handshaking stage of a TCP connection. Combined with the statistical packet loss ratio and the passively collected link metrics, our algorithm can real-time select a link which provides the maximum throughput for the TCP connection. The experiment results show that the accuracy of choosing the best outgoing access link is over 71%. If the second best link is chosen, it is usually very close to the best, thus achieving over 89% of the maximum possible throughput. The average per-connection throughput for our algorithm and the traditional round-robin algorithm is 94% vs. 69%.
Ying-Dar Lin, Shih-Chiang Tsao, Un-Pio Leong
GLOBECOM1
2004 On shaping TCP traffic at edge gateways
abstract
Many security and QoS functions have been deployed at edge gateways to provide policy-based network management. For QoS functions, the bandwidth management system can manage the narrow WAN access links. When managing the TCP traffic, pass-through TCP flows can introduce large buffer requirement, latency, buffer overflows, and unfairness among flows competing for the same queue. This study evaluates possible TCP-aware approaches through self-developed implementations in Linux, testbed emulation, and live WAN measurement. The widely deployed TCP rate control (TCR) approach is found to be more vulnerable to WAN packet losses and less compatible to several TCP sending operating systems. The proposed PostACK approach can preserve TCR's advantages while avoiding TCR's drawbacks. PostACK emulates per-flow queuing but relocates the queuing of data to the queuing of ACKs in the reverse direction, hence minimizes buffer requirement up to 96%. PostACK also has 10% goodput improvement against TCR under lossy WAN. Experimental results can be reproduced through our open sources: (1) tcp-masq: a modified Linux kernel; (2) wan-emu: a testbed for conducting switched LAN-to-WAN or WAN-to-LAN experiments with RTT/loss/jitter emulations.
Huan-Yun Wei, Shih-Chiang Tsao, Ying-Dar Lin
GLOBECOM3
2004 Assessing and Improving TCP Rate Shaping over Edge Gateways
abstract
Computers installed with commercial/open-source software have been widely employed as organizational edge gateways to provide policy-based network management. Such gateways include firewalls for access control, and bandwidth managers for managing the narrow Internet access links. When managing the TCP traffic, pass-through TCP flows can introduce large buffer requirements, large latency, frequent buffer overflows, and unfairness among flows competing for the same queue. So, how to allocate the bandwidth for a TCP flow without the above drawbacks becomes an important issue. This study assesses and improves TCP rate shaping algorithms to solve the above problems through self-developed implementations in Linux, testbed emulations, live Internet measurements, computer simulations, modeling, and analysis. The widely deployed TCP rate control (TCR) approach is found to be more vulnerable to Internet packet losses and less compatible to some TCP sending operating systems. The proposed PostACK approach can preserve TCR's advantages while avoiding TCR's drawbacks. PostACK emulates per-flow queuing, but relocates the queuing of data to the queuing of ACKs in the reverse direction, hence minimizing the buffer requirement up to 96 percent. PostACK also has 10 percent goodput improvement against TCR under lossy WAN environments. A further scalable design of PostACK can scale up to 750Mbps while seamlessly cooperating with the link-sharing architecture. Experimental results can be reproduced through our open sources: 1) tcp-masq: a modified Linux kernel, 2) wan-emu: a testbed for conducting switched LAN-to-WAN or WAN-to-LAN experiments with RTT/loss/jitter emulations.
Huan-Yun Wei, Shih-Chiang Tsao, Ying-Dar Lin
IEEE Trans. Computers3
2003 Direct Web switch routing with state migration, TCP masquerade, and cookie name rewriting
abstract
Existing layer 4 load balancers are content-blind and often have difficulty in redirecting HTTP requests to the appropriate server in the session manner. Layer 7 load balancers, also referred to as Web switches, are content-aware and support session persistence. However, most Web switches employ a bidirectional architecture, which means that request and response traffic must both pass through the load balancer. This means a Web switch can easily become a bottleneck. We present a direct routing architecture to prevent response traffic from passing through the Web switch. Our solution is highly scalable in the number of back-end servers. In addition, two simple but effective mechanisms, one-packet TCP state migration and cookie name rewriting to packet filter, are presented to support persistent connection and session persistence. Through the external benchmark, we prove that our system outperforms existing solutions. The internal benchmark investigates the bottlenecks of our system and suggests areas for future improvement.
Ying-Dar Lin, Ping-Tsai Tsai, Po-Ching Lin, Ching-Ming Tien
GLOBECOM1
2003 Co-DRR: An Integrated Uplink and Downlink Scheduler for Bandwidth Management over Wireless LANs
abstract
Bandwidth management over wired bottleneck links has been an effective way to utilize network resources. For the rapidly emerging IEEE 802.11 wireless LAN (WLAN), the limited WLAN bandwidth becomes a new bottleneck and requires bandwidth management. Most possible existing solutions only exclusively focus on optimizing multimedia traffic, pure downlink or pure uplink fairness, or are incompatible with IEEE 802.11. This study proposes a cooperative deficit round robin (co-DRR), an IEEE 802.11-compatible host based fair scheduling algorithm based on the deficit round robin (DRR) and distributed-DRR (DDRR) schemes, to cooperate the uplink and downlink quantum calculations to simultaneously control uplink and downlink bandwidth. Co-DRR uses the standard PCF mode to utilize the contention-free period to compensate for the unfairness in the contention period. Numerical results demonstrate that: co-DRR can scale up to 100 mobile hosts even under high bit error rate (0.0001) while simultaneous achieving uplink/downlink long-term fairness (CoV<0.01) among competing mobile hosts.
Huan-Yun Wei, Ching-Chuang Chiang, Ying-Dar Lin
ISCC3
2002 Base-centric routing protocol for multihop cellular networks
abstract
This paper presents base-centric routing (BCR) protocol, which is designed for multihop cellular networks (MCNs) for wireless data communications. MCN, in which packets are multi-hopped to their destination, is hybrid of traditional single-hop cellular networks (SCNs) and ad-hoc networks architecture. Because the existing routing protocols designed for ad-hoc networks are not suitable for MCN, herein, a hybrid of table-driven and demand-driven protocols with base-centric computing is designed. The base tracks network topology by the table-driven method and can thus compute paths for MSs, constituting base-centric computing. When paths are needed by MSs, when is demand-driven, the path query messages are unicast to the base. If MSs do not obtain paths from the base, then path query messages will be flooded as in AODV. Simulation yields the following conclusions. The throughput of MCN increases as radio distance decreases and is higher than that of SCN. When the radio distance in MCN is the same as that in SCN, the throughput in MCN is about twice that in SCN. Moreover, the improvement can be by up to a factor of three when the radio distance in MCN is 1/4 of that in SCN. The hybrid protocol outperforms AODV because with base-centric computing, path query messages can be unicast to the base and the overhead is greatly reduced. Without mobility, UDP outperforms TCP. However, with mobility, TCP outperforms UDP.
Yu-Ching Hsu, Ying-Dar Lin
GLOBECOM2
2002 RPIM-SM: extending PIM-SM for RP relocation
Ying-Dar Lin, Nai-Bin Hsu, Ren-Hung Hwang
Comput. Commun.1
2001 Multipath QoS routing with bandwidth guarantee
abstract
Recently, QoS routing has been studied intensively. In QoS routing, an essential issue is routing granularity. Most of the research adopts per-flow granularity in the forwarding table. Some research advocates per-source-destination pair granularity in the forwarding table with route pinning. The flow based approach has finer granularity, thus is more efficient in traffic engineering and resource utilization. However, the computation overhead and storage overhead are also higher. On the other hand, source-destination based granularity is more efficient on packet processing and forwarding, but has higher blocking probability. We propose the concept of forwarding with routing marks. With a limited number of routing marks, the proposed routing algorithm reduces the forwarding complexity and storage overhead significantly while yielding very competitive performance in terms of fractional reward loss.
Yun-Wen Chen, Ren-Hung Hwang, Ying-Dar Lin
GLOBECOM3
2001 Bandwidth brokers of instantaneous and book-ahead requests for differentiated services networks
abstract
The quality of service (QoS) reservations in differentiated service (DiffServ) networks can be classified into two sets: book-ahead (BA) requests and instantaneous requests (IRs). When an admitted BA request becomes active, some ongoing IRs are dropped when the bandwidth is insufficient for supporting both IRs and BA requests. The admission control should predict the lifetime, i.e. look-ahead time, of the IRs to prevent the admitted IRs from being dropped. The control should then check whether the available bandwidth during the look-ahead time is sufficient for the incoming IRs. We propose an application-aware look-ahead admission control for IRs, which determines the look-ahead time for specific types of IR applications. An admitted BA request might block subsequent ones that could bring more effective revenue. Thus, we propose the deferrable model of the admission control for BA requests. Simulation results indicate that the application-aware look-ahead admission control successfully reduces the dropping probability and wasted revenue of IRs by up to 10 times and 30%, respectively. Besides, the deferrable model indeed results in more BA effective revenue.
Ying-Dar Lin, Cheng-Hsien Chang, Yu-Ching Hsu
GLOBECOM1
2001 Two-phase minislot scheduling algorithm for HFC QoS services provisioning
abstract
Data-over-cable service interface specifications v1.1 (DOCSIS v1.1) defines five upstream services for supporting per-flow quality of service (QoS). The cable modem termination system (CMTS) must periodically grant upstream transmission opportunities to the QoS flows based on their QoS parameters. This study proposes a two-phase minislot scheduling algorithm to reduce the QoS violation rate. In the scheduling sequence determination phase, the flow whose packets are most unlikely to violate QoS is scheduled first. In the minislot assignment phase, the scheduler allocates to a flow the available interval where the likelihood of packet violation is minimum. Simulation results demonstrate that our scheduling algorithm can reduce the QoS violation rate by 80% - 35% over that of the first-come-first-serve-random-selection algorithm and increase the utilization by 25% as well.
Wei-Ming Yin, Chia-Jen Wu, Ying-Dar Lin
GLOBECOM3
2001 Two-stage dynamic uplink channel and slot assignment for GPRS
abstract
General Packet Radio Service (GPRS) uses a two-stage mechanism to allocate uplink radio resource to mobile stations (MSs). In stage-1, the base station (BS) assigns several packet data channels (PDCHs) to an MS. Furthermore, a PDCH may be assigned to multiple MSs. In stage-2, therefore, the BS selects one of the multiplexed MSs in a PDCH to use the radio resource. In this work, maintaining a load balance between PDCHs in stage-1 is examined and several selection schemes to lower the mis-selection rate in stage-2 are proposed. From our simulation results, the cost deduced from the poor load balancing and selection schemes render a lower system throughput and a non-negligible increase in packet queuing delay. Among the various stage-2 selection policies, round robin with linearly-accumulated adjustment (RRLAA) has the lowest mis-selection rate and outperforms the one without any heuristic up to 50%.
Ying-Dar Lin, Yu-Ching Hsu, Mei-Yan Chiang
ICC1
2001 Extension of RP relocation to PIM-SM multicast routing
abstract
The protocol independent multicast-sparse mode (PIM-SM) protocol establishes a core-base tree to forward multicast datagrams in a network. In PIM-SM, the core or rendezvous point (RP) of a group is determined at each multicast router by hashing a group address, i.e., a class-D IP address, to one of the candidate RPs. The hash function is characterized by its ability to evenly and uniquely choose the core for a group and remains insensitive to the geographic distribution of the group members and the sources. However, it may result in a multicast tree with high cost. This study presents a relocation mechanism which is extended to PIM-SM, in which RP could be relocated periodically. When a new RP is found, the original RP informs all members to re-join to the new RP. Simulation results indicate that the extended version, RPIM-SM, reduces about 20% tree cost than PIM-SM when the group size is medium. Moreover, comparing RPIM-SM with the optimal core-based tree reveals that they have less than 5% difference in tree cost. Furthermore, an increase of the number of candidate RPs brings RPIM-SM even closer to the optimal core-based tree. Results in this study demonstrate that relocation improves the performance of PIM-SM.
Ying-Dar Lin, Nai-Bin Hsu, Chen-Ju Pan
ICC1
2001 Granularity of QoS Routing in MPLS Networks
Ying-Dar Lin, Nai-Bin Hsu, Ren-Hung Hwang
IWQoS1
2001 Pre-order Deficit Round Robin: a new scheduling algorithm for packet-switched networks
Shih-Chiang Tsao, Ying-Dar Lin
Comput. Networks2
2001 Ordered lookup with bypass matching for scalable per-flow classification in layer 4 routers
Ying-Dar Lin, Huan-Yun Wei, Kuo-Jui Wu
Comput. Commun.1
2001 Dynamic resizing of utilization target in measurement-based admission control
Yeali S. Sun, Chih-Chiang Chuang, Ying-Dar Lin
Comput. Commun.3
2000 Multihop Cellular: A New Architecture for Wireless Communications
abstract
This work presents a new architecture, multihop cellular network (MCN), for wireless communications. MCN preserves the benefit of conventional single-hop cellular networks (SCN) where the service infrastructure is constructed by fixed bases, and it also incorporates the flexibility of ad-hoc networks where wireless transmission through mobile stations in multiple hops is allowed. MCN can reduce the required number of bases or improve the throughput performance, while limiting path vulnerability encountered in ad-hoc networks. In addition, MCN and SCN are analyzed, in terms of mean hop count, hop-by-hop throughput, end-to-end throughput, and mean number of channels (i.e. simultaneous transmissions) under different traffic localities and transmission ranges. Numerical results demonstrate that the throughput of MCN exceeds that of SCN, the former also increases as the transmission range decreases. The above results can be accounted for by the different orders, linear and square, at which the mean hop count and mean number of channels increase, respectively.
Ying-Dar Lin, Yu-Ching Hsu
INFOCOM1
2000 Statistically optimized minislot allocation for initial and collision resolution in hybrid fiber coaxial networks
abstract
In a two-way hybrid fiber coaxial (HFC) network, the headend broadcasts in downstream channels, whereas all stations share the upstream channels. Hence, collision occurs when multiple stations send their bandwidth requests in a minislot. The headend determines how many minislots to allocate to manage collisions. This paper proposes a minislot allocation (SOMA) algorithm to optimize minislot throughput based on statistical estimation. A time proportional scheme is adopted to estimate the number of new requests in the initial resolution process. In addition, the number of retry requests in the collision resolution process is estimated by looking up a predetermined table of the most likely number of requests (MLR). In addition, SOMA is modified to reduce the request access delay by relaxing its allocation policy in a specific situation. We use a self-similar traffic model for simulation and analysis to compare SOMA with the optimal bound and the 3-ary tree algorithm.
Wei-Ming Yin, Ying-Dar Lin
IEEE J. Sel. Areas Commun.2
1999 Multihop wireless IEEE 802.11 LANs: a prototype implementation
abstract
We present a prototype for a new architecture, MCN (multihop cellular network), implemented over a wireless LAN platform. MCN preserves the virtue of traditional single-hop cellular networks where the service infrastructure is constructed by many bases, but it also adds the flexibility of ad-hoc networks where wireless transfer through mobile stations in multiple hops is allowed. The MCN can reduce the number of required bases or improve the throughput performance. On IEEE 802.11 compliant wireless LAN products, a bridging protocol, our BMBP (base-driven multihop bridging protocol), runs between mobile stations and access points to build bridging tables. The demonstration shows that MCN is a feasible architecture for wireless LANs.
Ying-Dar Lin, Yu-Ching Hsu, Kuan-Wen Oyang, Tzu-Chieh Tsai, Dong-Su Yang
ICC1
1998 QoS routing in multihop packet radio environment
abstract
We present a method to compute the path bandwidth for the DSDV (destination-sequenced distance-vector) based routing algorithm. The addressed network does not necessarily have a cellular structure and could have no fixed infrastructure. This network can be either stand-alone, or connected to the wired network. Each mobile station has to relay packets for others, thus achieving multihop routing. To calculate the available bandwidth of a path in this environment, it is incorrect to simply compute the minimum bandwidth of the links along the path. There are two crucial steps in the path bandwidth computation process of this multihop environment: (1) intersecting the sets of common free slots of two adjacent links, and (2) dividing the intersection for the adjacent links to share. We present two bandwidth computation rules including the half rule and the floating rule. Numerical results are given to evaluate the performance of applying these rules to the DSDV-based QoS routing algorithm.
Yu-Ching Hsu, Tzu-Chieh Tsai, Ying-Dar Lin
ISCC3
1998 Interoperability of EFCI and ER switches for ABR services in ATM networks
abstract
With the advances in switching technologies, explicit rate (ER) switches are becoming popular since they perform better than explicit forward congestion indication (EFCI) switches. In the transitional period, the EFCI and ER switches may coexist in the same ATM network. Hence the efficiency of various ER schemes should be considered in the mixed EFCI-ER environment, not only in the homogeneous ER environment. In this paper we describe five ER control mechanisms and compare their performance in the mixed EFCI-ER environment. Simulation results show that these algorithms can interoperate with the EFCI switches. However, the behavior of these ER schemes in the mixed EFCI-ER environment is sometimes different from that in the homogeneous ER environment. These ER schemes are re-evaluated based on their interoperability with EFCI schemes.
Yuan-Cheng Lai, Ying-Dar Lin, Nai-Bin Hsu
ISCC2
1998 Performance analysis of rate-based flow control under a variable number of sources
Yuan-Cheng Lai, Ying-Dar Lin
Comput. Networks ISDN Syst.2
1998 An efficient and orderly implementation of bypass queue under bursty traffic
Joe Shang-Chieh Wu, Ying-Dar Lin
Parallel Comput.2
1997 Performance Analysis of Rate-based Congestion Control Scheme and Choice of High and Low Thresholds
abstract
The paper presents a performance analysis of a rate-based congestion control mechanism. The switching capacity of the buffer is finite to reflect real conditions. Using a differential equation approach, we get the closed-form equations of cell loss probability, and utilization. Numerical results are given to show that our analysis is correct. In rate-based control, the important issue is how to determine congestion occurrence and congestion relief. The most common method is to set two thresholds of queue length, a high threshold and a low threshold. The values of these two thresholds seriously influence the system performance. Hence, we present the concept of best area to determine how to set the high and low thresholds to guarantee good performance, i.e., cell loss probability is zero and utilization is one, if it is possible. When good performance is not achieved due to too many connections or too large propagation delay, some rules are also given to prevent unnecessary cell-loss and under-utilization.
Yuan-Cheng Lai, Ying-Dar Lin
ICCCN2
1997 GMNF-DVMRP : A Modified Version of Distance Vector Multicast Routing Protocol
abstract
In this paper, we make a survey of distance vector multicast routing protocol (DVMRP) and find that it is not optimal in the aspect of network cost (NC). Therefore, we propose a modified version of DVMRP, called "group membership near first-DVMRP" (GMNF-DVMRP), to decrease the NC of the multicast tree formed by DVMRP. A simulation is implemented to compare our modified version and the original DVMRP. We find that our method save about 5-7 percent of NC of the multicast tree formed by DVMRP.
Yuan-Cheng Lai, Ying-Dar Lin, Wei-Che Yu, Yuh-Tay Lin
ICCCN2
1997 PCUP: Pipelined Cyclic Upstream Protocol over Hybrid Fiber Coax
abstract
In order to span the NII (National Information Infrastructure) into the homes, the community cable TV networks have to be re-engineered to support two-way interactive services. We propose the PCUP (pipelined cyclic upstream protocol) as the upstream MAC (medium access control) protocol for HFC (hybrid fiber coax) community access network. The PCUP is designed with the intention of pipelining the upstream channel. This is achieved by proper station positioning, which measures the station propagation offset from the headend, and transmission scheduling, which assigns each station the transmission starting time and duration in a cycle. By taking into account the propagation offsets and the transmission times, the transmitted cells can appear back-to-back, ie. pipelined, at the headend. Since only the active stations are scheduled to transmit in a cycle, a membership control mechanism, which runs a contention-based tree walk algorithm, is executed periodically to allow the stations to join or leave. We also compare the PCUP with various schemes proposed to IEEE 802.14 committee.
Ying-Dar Lin, Chia-Jen Wu, Wei-Ming Yin
INFOCOM1
1996 Characterization and Control of Highly Correlated Traffic in High-Speed Networks
abstract
By assuming network traffic to be independent from each other, the analysis of network performance can be simplified. However, the real traffic sources may have some correlation which makes their behavior tend to converge or diverge. This phenomenon has a tremendous influence on congestion control. In this paper, we explain the possible reasons for correlated behavior, namely, top-down and client-server correlation, and analyze their impacts. We also use the rapid matrix-geometric solution to investigate the cost to pay when applying the leaky bucket input control scheme to the independent traffic sources (e.g. Poisson) and the correlated traffic sources (such as on-off and HAP (hierarchical arrival process)).
Ying-Dar Lin, Tian-Ren Huang, Yuan-Cheng Lai
LCN1
1996 A Hierarchical Network Storage Architecture for Video-on-Demand Services
abstract
Recent advances in cable TV networks and multimedia technologies open the possibilities for network/service/content providers to offer residential customers with video-on-demand services. However, the mass storage system in supporting such services demands proper organization and management. We present a three-level hierarchical network storage architecture for the video-on-demand storage system. At the first-level (local service center, LSC) a limited number of programs with high viewing probabilities are stored while at the second-level (local central service center, LCSC) a few programs with second high viewing probabilities are stored. The third-level (central service center, CSC) contains all programs provided in the system. Based on this architecture and the program viewing probability distribution function, we use a minimum-cost function to find out the number of programs stored in the two service centers (LSC and LCSC) and the number of links among these three service centers. We also describe two program reallocation algorithms which swap programs between service centers according to the change in user request patterns.
Ying-Dar Lin, Horng-Zhu Lai, Yuan-Cheng Lai
LCN1
1996 Alarm correlation for congestion diagnosis in ATM networks
abstract
We examine the tradeoff between fine-grade and coarse-grade OAM measurements. The fine-grade OAM measurement, with the overhead of voluminous measurement information, leads to pin-pointed identification when problems occur; while with coarse-grade OAM measurement, without detailed information, one needs to correlate many alarms which may be triggered by a single problem. Alarm correlation, however, requires some heuristics for problem diagnosis and has some degree of uncertainty. Taking VP (virtual path) congestion diagnosis as our target example, we present the path intersection heuristics as the alarm correlation method used to analyze the congestion alarms and locate the congestion areas. Our simulation results show that the intersection heuristics with output link consideration locates the congestion nodes precisely. We also analyze the congestion pattern and find that the congestion area has the tendency of expanding from one node to its neighbors. After identifying the congested nodes, we apply three methods to choose the congested VPCs for rerouting. The results show that the method of less summed capacity performs the best in terms of the average rerouted capacity.
Ying-Dar Lin, Ren-Kuei Yang, Chi-Chun Lo
NOMS1
1993 HAP: A New Model for Packet Arrivals
abstract
Applications to be supported on broadband networks exhibit a wide range of traffic statistics and many of them are sensitive to delay and loss violations. To accurately estimate admissible workload and bandwidth requirement, a detailed traffic model, HAP (Hierarchical Arrival Process) is proposed in this paper. Packets generated from HAP are modulated by processes at user, application, and message levels. This model is a generalization of on-off traffic models and is shown to be equivalent to a special class of MMPP (Markov Modulated Poisson Process). Three algorithmic methods along with simulations are applied to evaluate the queueing performance under HAP traffic. Delay under HAP traffic can be well over tens of times higher than Poisson traffic, depending on parameters and load. Congestion may persist for minutes. HAP's dramatic short-term behavior explains the occasional congestion in the real networks. Conventional traffic models, however, do not exhibit this behavior. With these results, we give implications for broadband network control.
Ying-Dar Lin, Tzu-Chieh Tsai, San-Chiao Huang, Mario Gerla
SIGCOMM1
1993 Induction and Deduction for Autonomous Networks
abstract
The key issues in network management are the representation and sharing of management information and the automatic management mechanisms based on the underlying information infrastructure. The authors propose a framework, which operates on the standard management information base (MIB) and common management information protocol (CMIP), for a network management system with learning and inference as its management engines. In addition to the general domain knowledge, patterns related to the managed network are learned to enhance the understanding of the network and refine the knowledge base. Facts in object-oriented databases or queries from management applications trigger the inference process on logical rules which are either prespecified knowledge or learned network patterns. Forward inference drives prediction and control, while backward inference directs diagnosis and supports view abstraction. A case study on ATM network topology tuning is presented.>
Ying-Dar Lin, Mario Gerla
IEEE J. Sel. Areas Commun.1
1991 Network management using database discovery tools
abstract
As the volume of network traffic increases due to the proliferation of distributed systems and the growth of real-time applications, a good understanding of traffic distribution and patterns becomes critical in network control and performance management. The authors upgrade the facilities of network management from traditional file systems to database and knowledge base systems and apply machine learning techniques to discover traffic patterns which are difficult to discern by human operators among a large volume of measurements. An experiment on interconnected LANs is conducted where some interesting patterns are found. The results show a strong traffic locality and some cyclic traffic patterns. The discovered rule base can describe the traffic distribution and patterns which need to be captured for any sophisticated performance management. The experiment has shown the high applicability of induction techniques to network management.>
Mario Gerla, Ying-Dar Lin
LCN2
1991 Brouter: the transparent bridge with shortest path in interconnected LANs
abstract
Transparency is a popular feature in a distributed system where users can access any local or remote resources just as if they were local. The paper proposes a protocol which combines the features of transparency and shortest path. The result is a bridge which supports self learning and distributed routing computation. Since this bridge has all routing facilities as a router, it is called brouter (i.e. bridge+router). Brouters are compared with current bridge schemes. Also, performance aspects of the protocol are examined.>
Ying-Dar Lin, Mario Gerla
LCN1