Alex C. Snoeren

dblp:s/AlexCSnoeren · also Mark Alexander Connell Snoeren · DBLP profile ↗
← Back
118ranked-venue papers
5as first author
22since 2021 · last 2025
0000-0001-5679-3888ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 71 · 3 first-author · 13 since 2021Systems, architecture and hardware · 20 · 3 since 2021Security and privacy · 15 · 5 since 2021Software engineering, systems software and programming languages · 10 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 3Artificial intelligence and machine learning · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 Local Frames: Exploiting Inherited Origins to Bypass Content Blockers
abstract
We present a study of how local frames (i.e., iframes loading content like ''about:blank'') are mishandled by a wide range of popular Web security and privacy tools. As a result, users of these tools remain vulnerable to the very attack techniques against which they seek to protect themselves, including browser fingerprinting, cookie-based tracking, and data exfiltration. The tools we study are vulnerable in different ways, but all share a root cause: legacy Web functionality interacts with browser privacy boundaries in unexpected ways, leading to systemic vulnerabilities in tools developed, maintained, and recommended by privacy experts and activists.
Alisha Ukani, Hamed Haddadi 0001, Alex C. Snoeren, Peter Snyder
CCS3
2025 Eden: Developer-Friendly Application-Integrated Far Memory
Anil Yelam, Stewart Grant, Saarth Deshpande, Nadav Amit, Radhika Niranjan Mysore, Amy Ousterhout, Marcos K. Aguilera, Alex C. Snoeren
NSDI8
2025 Cuckoo for Clients: Disaggregated Cuckoo Hashing
Stewart Grant, Alex C. Snoeren
USENIX ATC2
2025 PageFlex: Flexible and Efficient User-space Delegation of Linux Paging Policies with eBPF
Anil Yelam, Suli Yang, Rajath Shashidhara, Stanko Novakovic, Alex C. Snoeren, Kimberly Keeton
USENIX ATC8
2024 Sublet Your Subnet: Inferring IP Leasing in the Wild
abstract
IPv4 addresses have become a commodity with monetary value since the exhaustion of unallocated IPv4 space. This led to the rise of a secondary market for buying, selling, and leasing IPv4 addresses. While prior work has studied the IPv4 transfer behavior, the IPv4 leasing ecosystem remains largely unexplored. In this paper, we analyze the IPv4 leasing ecosystem by designing a methodology to infer leased address space for all RIRs and study its impact on routing and hosting security. We infer that 4.1% of all advertised IPv4 prefixes (0.9% of routed v4 address space) were leased in April 2024. Our method achieves 98% precision when evaluated against our validated dataset. Finally, we show that leased address space is five times more likely to be abused compared to non-leased space.
Ben Du, Romain Fontugne, Cecilia Testart, Alex C. Snoeren, K. C. Claffy
IMC4
2024 Realizing RotorNet: Toward Practical Microsecond Scale Optical Networking
abstract
We describe our experience building and deploying a demand-oblivious optically-switched network based on the RotorNet and Opera architectures. We detail the design, manufacture, deployment, and end-to-end operation of a 128-port optical rotor switch along with supporting NIC hardware and host software. Using this prototype, we assess yield, synchronization, and interoperability with commodity hardware and software at a scale of practical relevance. We provide the first real-world measurements of Linux TCP throughput and host-to-host latency in an operational RotorNet, achieving 98% of link rate with 99th-percentile ping times faster than commodity packet-switching hardware. In the process, we uncover unexpected challenges with link-level dropouts and devise a novel and flexible way to address them. Our deployment experience demonstrates the feasibility of our implementation approach and identifies opportunities for future exploration.
William M. Mellette, Alex Forencich, Rukshani Athapathu, Alex C. Snoeren, George Papen, George Porter
SIGCOMM4
2023 Rosebud: Making FPGA-Accelerated Middlebox Development More Pleasant
abstract
We introduce an approach to designing FPGA-accelerated middleboxes that simplifies development, debugging, and performance tuning by decoupling the tasks of hardware-accelerator implementation and software-application programming. Rosebud is a framework that links hardware accelerators to a high-performance packet processing pipeline through a standardized hardware/software interface. This separation of concerns allows hardware developers to focus on optimizing custom accelerators while freeing software programmers to reuse, configure, and debug accelerators in a fashion akin to software libraries. We show the benefits of the Rosebud framework by building a firewall based on a large blacklist and porting the Pigasus IDS pattern-matching accelerator in less than a month. Our experiments demonstrate that Rosebud delivers high performance, serving ∼200 ‍Gbps of traffic while adding only 0.7–7 microseconds of latency.
Moein Khazraee, Alex Forencich, George Papen, Alex C. Snoeren, Aaron Schulman
ASPLOS (3)4
2023 IRRegularities in the Internet Routing Registry
abstract
The Internet Routing Registry (IRR) is a set of distributed databases used by networks to register routing policy information and to validate messages received in the Border Gateway Protocol (BGP). First deployed in the 1990s, the IRR remains the most widely used database for routing security purposes, despite the existence of more recent and more secure alternatives. Yet, the IRR lacks a strict validation standard and the limited coordination across different database providers can lead to inaccuracies. Moreover, it has been reported that attackers have begun to register false records in the IRR to bypass operators' defenses when launching attacks on the Internet routing system, such as BGP hijacks. In this paper, we provide a longitudinal analysis of the IRR over the span of 1.5 years. We develop a workflow to identify irregular IRR records that contain conflicting information compared to different routing data sources. We identify 34,199 irregular route objects out of 1,542,724 route objects from November 2021 to May 2023 in the largest IRR database and find 6,373 to be potentially suspicious.
Ben Du, Katherine Izhikevich, Sumanth Rao, Gautam Akiwate, Cecilia Testart, Alex C. Snoeren, K. C. Claffy
IMC6
2023 Destination Unreachable: Characterizing Internet Outages and Shutdowns
abstract
In this paper, we provide the first comprehensive longitudinal analysis of government-ordered Internet shutdowns and spontaneous outages (i.e., disruptions not ordered by the government). We describe the available tools, data sources and methods to identify and analyze Internet shutdowns. We then merge manually curated datasets on known government-ordered shutdowns and large-scale Internet outages, further augmenting them with data on real-world events, macroeconomic and sociopolitical indicators, and network operator statistics. Our analysis confirms previous findings on the economic and political profiles of countries with government-ordered shutdowns. Extending this analysis, we find that countries with national-scale spontaneous outages often have profiles similar to countries with shutdowns, differing from countries that experience neither. However, we find that government-ordered shutdowns are many more times likely to occur on days of mobilization, coinciding with elections, protests, and coups. Our study also characterizes the temporal characteristics of Internet shutdowns and finds that they differ significantly in terms of duration, recurrence interval, and start times when compared to spontaneous outages.
Zachary S. Bischof, Kennedy Pitcher, Esteban Carisimo, Amanda Meng, Rafael Bezerra Nunes, Ramakrishna Padmanabhan, Margaret E. Roberts, Alex C. Snoeren, Alberto Dainotti
SIGCOMM8
2023 Memory Management in ActiveRMT: Towards Runtime-programmable Switches
abstract
A wide variety of in-network services have been developed for RMT-based switching hardware, almost exclusively through the P4 language and ecosystem. Many of these applications maintain state in switch memory, a scarce shared resource. As with any other network resource, varying traffic demands necessitate reallocations, yet the P4 ecosystem is not well suited for dynamic resource management: Modifying the set of services deployed on a switch using P4 requires the network operator to prepare a new binary image and re-provision the switch, disrupting all existing traffic. We present an alternate approach---using techniques from capsule-based active networking---to programming RMT devices that enables non-disruptive (re)allocation of switch memory at time scales that are much faster than P4 compilation without operator intervention. We use P4 to implement a single, shared runtime on commodity RMT hardware that interprets instructions received via the switch data plane to deliver a variety of exemplar services including caching, load balancing, and network telemetry. Our prototype implementation is able to dynamically provision dozens-to-hundreds of instances of simultaneous stateful services at the timescale of seconds.
Rajdeep Das, Alex C. Snoeren
SIGCOMM2
2023 Poster: Taking the Low Road: How RPKI Invalids Propagate
abstract
The Border Gateway Protocol (BGP) includes no mechanism to verify the correctness of routing information exchanged between networks. To defend against unauthorized use of address space, the IETF developed the Resource Public Key Infrastructure (RPKI), a cryptographically attested database system that facilitates validation of BGP messages. Networks can use RPKI to check whether the Autonomous System (AS) at the origin of the AS path in a BGP announcement is authorized to originate the IP prefixes being announced.
Ben Du, Cecilia Testart, Romain Fontugne, Alex C. Snoeren, K. C. Claffy
SIGCOMM4
2023 A Cloud-Scale Characterization of Remote Procedure Calls
abstract
The global scale and challenging requirements of modern cloud applications have led to the development of complex, widely distributed, service-oriented applications. One enabler of such applications is the remote procedure call (RPC), which provides location-independent communication and hides the myriad of cloud communication complexities and requirements within the RPC stack. Understanding RPCs is thus one key to understanding the behavior of cloud applications. While there have been numerous studies of RPCs in distributed systems, as well as attempts to optimize RPC overheads with both software and hardware, there is still a lack of knowledge about the characteristics of RPCs "in the wild" in the modern cloud environment.
Korakit Seemakhupt, Brent E. Stephens, Samira Manabi Khan, Sihang Liu 0001, Hassan M. G. Wassel, Soheil Hassas Yeganeh, Alex C. Snoeren, Arvind Krishnamurthy, David E. Culler, Henry M. Levy
SOSP7
2023 Access Denied: Assessing Physical Risks to Internet Access Networks
Alexander Marder, Zesen Zhang, Ricky K. P. Mok, Ramakrishna Padmanabhan, Bradley Huffaker, Matthew J. Luckie, Alberto Dainotti, K. C. Claffy, Alex C. Snoeren, Aaron Schulman
USENIX Security Symposium9
2022 Scaling beyond packet switch limits with multiple dataplanes
abstract
Scale-out datacenter network fabrics enable network operators to translate improved link and switch speeds directly into end-host throughput. Unfortunately, limits in the underlying CMOS packet switch chip manufacturing roadmap mean that NICs, links, and switches are not getting faster fast enough to meet demand. As a result, operators have introduced alternative, parallel fabric designs in the core of the network that deliver N-times the bandwidth by simply forwarding traffic over any of N parallel network fabrics.
Yibo Guo, William M. Mellette, Alex C. Snoeren, George Porter
CoNEXT3
2022 Mind your MANRS: measuring the MANRS ecosystem
abstract
Mutually Agreed Norms on Routing Security (MANRS) is an industry-led initiative to improve Internet routing security by encouraging participating networks to implement a series of mandatory or recommended actions. MANRS members must register their IP prefixes in a trusted routing database and use such information to prevent propagation of invalid routing information. MANRS membership has increased significantly in recent years, but the impact of the MANRS initiative on the overall Internet routing security remains unclear. In this paper, we provide the first independent look into the MANRS ecosystem by using publicly available data to analyze the routing behavior of participant networks. We quantify MANRS participants' level of conformance with the stated requirements, and compare the behavior of MANRS and non-MANRS networks. While not all MANRS members fully comply with all required actions, we find that they are more likely to implement routing security practices described in MANRS actions. We assess the relevance of the MANRS effort in securing the overall routing ecosystem. We found that as of May 2022, over 83% of MANRS networks were conformant to the route filtering requirement by dropping BGP messages with invalid information according to authoritative records, and over 95% were conformant to the routing information facilitation requirement, registering their resources in authoritative databases.
Ben Du, Cecilia Testart, Romain Fontugne, Gautam Akiwate, Alex C. Snoeren, K. C. Claffy
IMC5
2022 Measuring UID smuggling in the wild
abstract
This work presents a systematic study of UID smuggling, an emerging tracking technique that is designed to evade browsers' privacy protections. Browsers are increasingly attempting to prevent cross-site tracking by partitioning the storage where trackers store user identifiers (UIDs). UID smuggling allows trackers to synchronize UIDs across sites by inserting UIDs into users' navigation requests. Trackers can thus regain the ability to aggregate users' activities and behaviors across sites, in defiance of browser protections.
Audrey Randall, Peter Snyder, Alisha Ukani, Alex C. Snoeren, Geoffrey M. Voelker, Stefan Savage, Aaron Schulman
IMC4
2022 IRR Hygiene in the RPKI Era
Ben Du, Gautam Akiwate, Thomas Krenc, Cecilia Testart, Alexander Marder, Bradley Huffaker, Alex C. Snoeren, K. C. Claffy
PAM7
2022 Quantifying Nations' Exposure to Traffic Observation and Selective Tampering
Alexander Gamero-Garrido, Esteban Carisimo, Shuai Hao 0001, Bradley Huffaker, Alex C. Snoeren, Alberto Dainotti
PAM5
2022 Time-division TCP for reconfigurable data center networks
abstract
Recent proposals for reconfigurable data center networks have shown that providing multiple time-varying paths can improve network capacity and lower physical latency. However, existing TCP variants are ill-suited to utilize available capacity because their congestion control cannot react quickly enough to drastic variations in bandwidth and latency.
Shawn Shuoshuo Chen, Weiyang Wang, Christopher Canel, Srinivasan Seshan, Alex C. Snoeren, Peter Steenkiste
SIGCOMM5
2021 Identifying ASes of state-owned internet operators
abstract
In this paper we present and apply a methodology to accurately identify state-owned Internet operators worldwide and their Autonomous System Numbers (ASNs). Obtaining an accurate dataset of ASNs of state-owned Internet operators enables studies where state ownership is an important dimension, including research related to Internet censorship and surveillance, cyber-warfare and international relations, ICT development and digital divide, critical infrastructure protection, and public policy. Our approach is based on a multi-stage, in-depth manual analysis of datasets that are highly diverse in nature. We find that each of these datasets contributes in different ways to the classification process and we identify limitations and shortcomings of these data sources. We obtain the first data set of this type, make it available to the research community together with the several lessons we learned in the process, and perform a preliminary analysis based on our data. We find that 53% (i.e., 123) of the world's countries are majority owners of Internet operators, highlighting that this is a widespread phenomenon. We also find and document the existence of subsidiaries of state-owned governments operating in foreign countries, an aspect that touches every continent and particularly affects Africa. We hope that this work and the associated data set will inspire and enable a broad set of Internet measurement studies and interdisciplinary research.
Esteban Carisimo, Alexander Gamero-Garrido, Alex C. Snoeren, Alberto Dainotti
Internet Measurement Conference3
2021 Locked-in during lock-down: undergraduate life on the internet in a pandemic
abstract
Governments around the world enacted stay-at-home orders in response to the COVID-19 pandemic, which changed many aspects of life, including how people interacted with the Internet. These draconian restrictions on in-person social interactions were perhaps most acutely felt by people living alone. We study the changes in network traffic of one such population, students remaining in the (single-occupancy) on-campus dormitories at a large residential educational institution during the onset and initial few months of the lock-down. Specifically, we analyze how students shifted their online work and leisure behaviors at an application level. Further, we segment the population into domestic and international students, and find that even within these two broad sub-populations, there are significant differences in Internet-based behavior. Our work provides a focused lens on pandemic Internet usage, examining both 1) a concentrated user population and 2) the differing impacts of a global pandemic on disparate sub-populations.
Alisha Ukani, Ariana Mirian, Alex C. Snoeren
Internet Measurement Conference3
2021 Inferring Cloud Interconnections: Validation, Geolocation, and Routing Behavior
Alexander Marder, K. C. Claffy, Alex C. Snoeren
PAM3
2020 Corundum: An Open-Source 100-Gbps Nic
abstract
Corundum is an open-source, FPGA-based prototyping platform for network interface development at up to 100 Gbps and beyond. The Corundum platform includes several core features to enable real-time, high-line-rate operations including: a high-performance datapath, 10G/25G/100G Ethernet MACs, PCI Express gen 3, a custom PCIe DMA engine, and native high-precision IEEE 1588 PTP timestamping. A key feature is extensible queue management that can support over 10,000 queues coupled with extensible transmit schedulers, enabling fine-grained hardware control of packet transmission. In conjunction with multiple network interfaces, multiple ports per interface, and per-port event-driven transmit scheduling, these features enable the development of advanced network interfaces, architectures, and protocols. The software interface to these hardware features is a high-performance driver for the Linux networking stack. The platform also supports scatter/gather DMA, checksum offloading, receive flow hashing, and receive-side scaling. Development and debugging is facilitated by a comprehensive open-source, Python-based simulation framework that includes the entire system from a simulation model of the driver and PCI express interface to the Ethernet interfaces. The power and flexibility of Corundum is demonstrated by the implementation of a microsecond-precision time-division multiple access (TDMA) hardware scheduler to enforce a TDMA schedule at 100 Gbps line rate with no CPU overhead.
Alex Forencich, Alex C. Snoeren, George Porter, George Papen
FCCM2
2020 Enabling Active Networking on RMT Hardware
abstract
The ecosystem of application functionality built around programmable switch hardware is growing at a rapid pace in recent times, fueled by the advent of reconfigurable match-action table (RMT) technology. This new class of devices is capable of simultaneously delivering basic computation and line-rate forwarding at a reasonable cost. Given this transformation in commodity switching functionality, we suggest it may be time to reconsider the concept of active networking, where end hosts can off-load application functionality to the network in real time without requiring the assistance of the network operator. We present a preliminary approach to encoding (nearly) arbitrary computation into a series of network packets that can be decoded and executed on programmable switch hardware. Our programs can leverage both the forwarding and storage capabilities of RMT devices. We also conduct an initial exploration into the importance of dynamically allocating switch resources across active programs to improve aggregate performance.
Rajdeep Das, Alex C. Snoeren
HotNets2
2020 Expanding across time to deliver bandwidth efficiency and low latency
William M. Mellette, Rajdeep Das, Yibo Guo, Rob McGuinness, Alex C. Snoeren, George Porter
NSDI5
2020 Adapting TCP for Reconfigurable Datacenter Networks
Matthew K. Mukerjee, Christopher Canel, Weiyang Wang, Daehyeok Kim, Srinivasan Seshan, Alex C. Snoeren
NSDI6
2020 SmartNIC Performance Isolation with FairNIC
abstract
Multiple vendors have recently released SmartNICs that provide both special-purpose accelerators and programmable processing cores that allow increasingly sophisticated packet processing tasks to be offloaded from general-purpose CPUs. Indeed, leading data-center operators have designed and deployed SmartNICs at scale to support both network virtualization and application-specific tasks. Unfortunately, cloud providers have not yet opened up the full power of these devices to tenants, as current runtimes do not provide adequate isolation between individual applications running on the SmartNICs themselves.
Stewart Grant, Anil Yelam, Maxwell Bland, Alex C. Snoeren
SIGCOMM4
2019 SparSDR: Sparsity-proportional Backhaul and Compute for SDRs
abstract
We present SparSDR, a resource-efficient architecture for softwaredefined radios whose backhaul bandwidth and compute power requirements scale in inverse proportion to the sparsity (in time and frequency) of the signals received. SparSDR requires dramatically fewer resources than existing approaches to process many popular protocols while retaining both flexibility and fidelity. We demonstrate that our approach has negligible impact on signal quality, receiver sensitivity, and processing latency. The SparSDR architecture makes it possible to capture signals across bandwidths far wider than the capacity of a radio's backhaul through the addition of lightweight frontend processing and corresponding backend reconstruction to restore the signals to their original sample rate. We employ SparSDR to develop two wideband applications running on a USRP N210 and a Raspberry Pi 3+: an IoT sniffer that scans 100 MHz of bandwidth and decodes received BLE packets, and a wideband Cloud SDR receiver that requires only residential-class Internet uplink capacity. We show that our SparSDR implementation fits in the constrained resources of popular low-cost SDR platforms, such as the AD Pluto.
Moein Khazraee, Yeswanth Guddeti, Sam Crow, Alex C. Snoeren, Kirill Levchenko, Dinesh Bharadia, Aaron Schulman
MobiSys4
2019 Understanding the Limits of Passive Realtime Datacenter Fault Detection and Localization
abstract
Datacenters are characterized by large scale, stringent reliability requirements, and significant application diversity. However, the realities of employing hardware with non-zero failure rates mean that datacenters are subject to significant numbers of failures that can impact performance. Moreover, failures are not always obvious; network components can fail partially, dropping or delaying only subsets of packets. Thus, traditional fault detection techniques involving end-host or router-based statistics can fall short in their ability to identify these errors. We describe how to expedite the process of detecting and localizing partial datacenter faults using an end-host method generalizable to most datacenter applications. In particular, we correlate end-host transport-layer flow metrics with per-flow network paths and apply statistical analysis techniques to identify outliers and localize faulty links and/or switches. We evaluate our approach in a production Facebook front-end datacenter, focusing on its effectiveness across a range of traffic patterns.
Rajdeep Das, Hongyi Zeng, Jasmeet Bagga, Alex C. Snoeren
IEEE/ACM Trans. Netw.5
2018 Toward Optical Switching in the Data Center (Invited Paper)
abstract
Optical switching may be instrumental in meeting the cost, power, and bandwidth requirements of future data center networks. However, optical switching faces many challenges to practical adoption. We discuss some of the physical- and control-layer challenges that have been uncovered in the research community, and potential ways to address them.
William M. Mellette, Alex C. Snoeren, George Porter
HPSR2
2018 An Empirical Analysis of the Commercial VPN Ecosystem
Mohammad Taha Khan, Joe DeBlasio, Geoffrey M. Voelker, Alex C. Snoeren, Chris Kanich, Narseo Vallina-Rodriguez
Internet Measurement Conference4
2018 Cloud Datacenter SDN Monitoring: Experiences and Challenges
Deepak Bansal, David Brumley, Harish Kumar Chandrappa, Parag Sharma, Rishabh Tewari, Behnaz Arzani, Alex C. Snoeren
Internet Measurement Conference8
2018 Inferring persistent interdomain congestion
abstract
There is significant interest in the technical and policy communities regarding the extent, scope, and consumer harm of persistent interdomain congestion. We provide empirical grounding for discussions of interdomain congestion by developing a system and method to measure congestion on thousands of interdomain links without direct access to them. We implement a system based on the Time Series Latency Probes (TSLP) technique that identifies links with evidence of recurring congestion suggestive of an under-provisioned link. We deploy our system at 86 vantage points worldwide and show that congestion inferred using our lightweight TSLP method correlates with other metrics of interconnection performance impairment. We use our method to study interdomain links of eight large U.S. broadband access providers from March 2016 to December 2017, and validate our inferences against ground-truth traffic statistics from two of the providers. For the period of time over which we gathered measurements, we did not find evidence of widespread endemic congestion on interdomain links between access ISPs and directly connected transit and content providers, although some such links exhibited recurring congestion patterns. We describe limitations, open challenges, and a path toward the use of this method for large-scale third-party monitoring of the Internet interconnection ecosystem.
Amogh Dhamdhere, David D. Clark, Alexander Gamero-Garrido, Matthew J. Luckie, Ricky K. P. Mok, Gautam Akiwate, Kabir Gogia, Vaibhav Bajpai, Alex C. Snoeren, K. C. Claffy
SIGCOMM9
2018 Tracking Ransomware End-to-end
abstract
Ransomware is a type of malware that encrypts the files of infected hosts and demands payment, often in a crypto-currency like Bitcoin. In this paper, we create a measurement framework that we use to perform a large-scale, two-year, end-to-end measurement of ransomware payments, victims, and operators. By combining an array of data sources, including ransomware binaries, seed ransom payments, victim telemetry from infections, and a large database of bitcoin addresses annotated with their owners, we sketch the outlines of this burgeoning ecosystem and associated third-party infrastructure. In particular, we are able to trace the financial transactions, from the acquisition of bitcoins by victims, through the payment of ransoms, to the cash out of bitcoins by the ransomware operators. We find that many ransomware operators cashed out using BTC-e, a now-defunct Bitcoin exchange. In total we are able to track over $16 million USD in likely ransom payments made by 19,750 potential victims during a two-year period. While our study focuses on ransomware, our methods are potentially applicable to other cybercriminal operations that have similarly adopted Bitcoin as their payment channel.
Danny Yuxing Huang, Max Aliapoulios, Vector Guo Li, Luca Invernizzi, Elie Bursztein, Kylie McRoberts, Kirill Levchenko, Alex C. Snoeren, Damon McCoy
IEEE Symposium on Security and Privacy9
2017 Using Indirect Routing to Recover from Network Traffic Scheduling Estimation Error
abstract
Increasingly, proposals for new datacenter networking fabrics employ some form of traffic scheduling-often to avoid congestion, mitigate queuing delays, or avoid timeouts. Fundamentally, practical implementations require estimating upcoming traffic demand. Unfortunately, as our results show, it is difficult to accurately predict demand in typical datacenter applications more than a few milliseconds ahead of time. We explore the impact of errors in demand estimation on traffic scheduling in circuit-switched networks. We show that even relatively small estimation errors such as shifting the arrival time of at most 30% of traffic by a few milliseconds can lead to suboptimal schedules that dramatically reduce network efficiency. Existing systems cope by provisioning extra capacity-either on each circuit, or through the addition of a separate packet-switched fabric. We show through simulation that indirect traffic routing is a powerful technique for recovering from the inefficiencies of suboptimal scheduling under common datacenter workloads, performing as well as networks with 16% extra circuit bandwidth or a packet switch with 6% of the circuit bandwidth.
Conglong Li, Matthew K. Mukerjee, David G. Andersen, Srinivasan Seshan, Michael Kaminsky, George Porter, Alex C. Snoeren
ANCS7
2017 Quantifying the Pressure of Legal Risks on Third-party Vulnerability Research
abstract
Product vendors and vulnerability researchers work with the same underlying artifacts, but can be motivated by goals that are distinct and, at times, disjoint. This potential for conflict, coupled with the legal instruments available to product vendors (e.g., EULAs, DMCA, CFAA, etc.) drive a broad concern that there are "chilling effects" that dissuade vulnerability researchers from vigorously evaluating product security. Indeed, there are well-known examples of legal action taken against individual researchers. However, these are inherently anecdotal in nature and skeptics of the chilling-effects hypothesis argue that there is no systematic evidence to justify such concerns. This paper is motivated by precisely this tussle. We present some of the first work to address this issue on a quantitative and empirical footing, illuminating the sentiments of both product vendors and vulnerability researchers. First, we canvas a range of product companies for explicit permission to conduct security assessments and thus characterize the degree to which the broad software vendor community is supportive of vulnerability research activities and how this varies based on the nature of the researcher. Second, we conduct an online sentiment survey of vulnerability researchers to understand the extent to which they have abstract concerns or concrete experience with legal threats and the extent to which this mindset shapes their choices.
Alexander Gamero-Garrido, Stefan Savage, Kirill Levchenko, Alex C. Snoeren
CCS4
2017 Exploring the dynamics of search advertiser fraud
abstract
Most search engines generate significant revenue through search advertising, wherein advertisements are served alongside traditional search results. These advertisements are attractive to advertisers because ads can be targeted and prominently presented to users at the exact moment that the user is searching for relevant topics.
Joe DeBlasio, Saikat Guha 0002, Geoffrey M. Voelker, Alex C. Snoeren
Internet Measurement Conference4
2017 Tripwire: inferring internet site compromise
abstract
Password reuse has been long understood as a problem: credentials stolen from one site may be leveraged to gain access to another site for which they share a password. Indeed, it is broadly understood that attackers exploit this fact and routinely leverage credentials extracted from a site they have breached to access high-value accounts at other sites (e.g., email accounts). However, as a consequence of such acts, this same phenomena of password reuse attacks can be harnessed to indirectly infer site compromises---even those that would otherwise be unknown. In this paper we describe such a measurement technique, in which unique honey accounts are registered with individual third-party websites, and thus access to an email account provides indirect evidence of credentials theft at the corresponding website. We describe a prototype system, called Tripwire, that implements this technique using an automated Web account registration system combined with email account access data from a major email provider. In a pilot study monitoring more than 2,300 sites over a year, we have detected 19 site compromises, including what appears to be a plaintext password compromise at an Alexa top-500 site with more than 45 million active users.
Joe DeBlasio, Stefan Savage, Geoffrey M. Voelker, Alex C. Snoeren
Internet Measurement Conference4
2017 Passive Realtime Datacenter Fault Detection and Localization
Hongyi Zeng, Jasmeet Bagga, Alex C. Snoeren
NSDI4
2017 RotorNet: A Scalable, Low-complexity, Optical Datacenter Network
abstract
The ever-increasing bandwidth requirements of modern datacenters have led researchers to propose networks based upon optical circuit switches, but these proposals face significant deployment challenges. In particular, previous proposals dynamically configure circuit switches in response to changes in workload, requiring network-wide demand estimation, centralized circuit assignment, and tight time synchronization between various network elements--- resulting in a complex and unwieldy control plane. Moreover, limitations in the technologies underlying the individual circuit switches restrict both the rate at which they can be reconfigured and the scale of the network that can be constructed.
William M. Mellette, Rob McGuinness, Alex Forencich, George Papen, Alex C. Snoeren, George Porter
SIGCOMM6
2017 Pinning Down Abuse on Google Maps
abstract
In this paper, we investigate a new form of blackhat search engine optimization that targets local listing services like Google Maps. Miscreants register abusive business listings in an attempt to siphon search traffic away from legitimate businesses and funnel it to deceptive service industries---such as unaccredited locksmiths---or to traffic-referral scams, often for the restaurant and hotel industry. In order to understand the prevalence and scope of this threat, we obtain access to over a hundred-thousand business listings on Google Maps that were suspended for abuse. We categorize the types of abuse affecting Google Maps; analyze how miscreants circumvented the protections against fraudulent business registration such as postcard mail verification; identify the volume of search queries affected; and ultimately explore how miscreants generated a profit from traffic that necessitates physical proximity to the victim. This physical requirement leads to unique abusive behaviors that are distinct from other online fraud such as pharmaceutical and luxury product scams.
Danny Yuxing Huang, Doug Grundman, Kurt Thomas, Elie Bursztein, Kirill Levchenko, Alex C. Snoeren
WWW7
2016 P-FatTree: A multi-channel datacenter network topology
abstract
The bandwidth and latency requirements of next-generation datacenter networks stress the limits of CMOS manufacturing. A key trend in their design will be a move from single-channel links and switches to multi-channel links and switches. Today's network topologies erase this distinction, providing the illusion of a unified network fabric. In this work we propose P-FatTree, which is a FatTree topology designed specifically for the future multi-channel reality. P-FatTree requires fewer switch chips and as a result has lower cost, power consumption, and latency than existing approaches. Furthermore, by embracing the parallel nature of the network itself, it enables compelling new ways to better manage and deliver application traffic.
William M. Mellette, Alex C. Snoeren, George Porter
HotNets2
2016 Lost in Space: Improving Inference of IPv4 Address Space Utilization
abstract
One challenge in understanding the evolution of the Internet infrastructure is the lack of systematic mechanisms for monitoring the extent to which allocated IP addresses are actually used. In this paper, we advance the science of inferring IPv4 address space utilization by proposing a novel taxonomy and analyzing and correlating results obtained through different types of measurements. We have previously studied an approach based on passive measurements that can reveal used portions of the address space unseen by active approaches. In this paper, we study such passive approaches in detail, extending our methodology to new types of vantage points and identifying traffic components that most significantly contribute to discovering used IPv4 network blocks. We then combine the results we obtained through passive measurements together with data from active measurement studies, as well as measurements from Border Gateway Protocol and additional data sets available to researchers. Through the analysis of this large collection of heterogeneous data sets, we substantially improve the state of the art in terms of: 1) understanding the challenges and opportunities in using passive and active techniques to study address utilization and 2) knowledge of the utilization of the IPv4 space.
Alberto Dainotti, Karyn Benson, Alistair King, Bradley Huffaker, Eduard Glatz, Xenofontas A. Dimitropoulos, Philipp Richter, Alessandro Finamore, Alex C. Snoeren
IEEE J. Sel. Areas Commun.9
2015 Security by Any Other Name: On the Effectiveness of Provider Based Email Security
abstract
Email as we use it today makes no guarantees about message integrity, authenticity, or confidentiality. Users must explicitly encrypt and sign message contents using tools like PGP if they wish to protect themselves against message tampering, forgery, or eavesdropping. However, few do, leaving the vast majority of users open to such attacks. Fortunately, transport-layer security mechanisms (available as extensions to SMTP, IMAP, POP3) provide some degree of protection against network-based eavesdropping attacks. At the same time, DKIM and SPF protect against network-based message forgery and tampering. In this work we evaluate the security provided by these protocols, both in theory and in practice. Using a combination of measurement techniques, we determine whether major providers supports TLS at each point in their email message path, and whether they support SPF and DKIM on incoming and outgoing mail. We found that while more than half of the top 20,000 receiving MTAs supported TLS, and support for TLS is increasing, servers do not check certificates, opening the Internet email system up to man-in-the-middle eavesdropping attacks. At the same time, while use of SPF is common, enforcement is limited. Moreover, few of the senders we examined used DKIM, and fewer still rejected invalid DKIM signatures. Our findings show that the global email system provides some protection against passive eavesdropping, limited protection against unprivileged peer message forgery, and no protection against active network-based attacks. We observe that protection even against the latter is possible using existing protocols with proper enforcement.
Ian D. Foster, Jon Larson, Max Masich, Alex C. Snoeren, Stefan Savage, Kirill Levchenko
CCS4
2015 Scheduling techniques for hybrid circuit/packet networks
abstract
A range of new datacenter switch designs combine wireless or optical circuit technologies with electrical packet switching to deliver higher performance at lower cost than traditional packet-switched networks. These "hybrid" networks schedule large traffic demands via a high-rate circuits and remaining traffic with a lower-rate, traditional packet-switches. Achieving high utilization requires an efficient scheduling algorithm that can compute proper circuit configurations and balance traffic across the switches. Recent proposals, however, provide no such algorithm and rely on an omniscient oracle to compute optimal switch configurations.
Matthew K. Mukerjee, Conglong Li, Nicolas Feltman, George Papen, Stefan Savage, Srinivasan Seshan, Geoffrey M. Voelker, David G. Andersen, Michael Kaminsky, George Porter, Alex C. Snoeren
CoNEXT12
2015 Leveraging Internet Background Radiation for Opportunistic Network Analysis
abstract
For more than a decade, unsolicited traffic sent to unused regions of the address space has provided valuable insight into malicious Internet activities. In this paper, we explore the utility of this traffic, known as Internet Background Radiation (IBR), for a different purpose: as a data source of Internet-wide measurements. We collect and analyze IBR from two large darknets, carefully deconstructing its various components and characterizing them along dimensions applicable to Internet-wide measurements. Intuitively, IBR can provide insight into network properties when traffic from that network contains relevant information and is of sufficient volume. We turn this intuition into a scientific investigation, examining which networks send IBR, identifying components of IBR that enable opportunistic network inferences, and characterizing the frequency and granularity of traffic sources. We also consider the influences of time of collection and position in the address space on our results. We leverage IBR properties in three case studies to show that IBR can supplement existing techniques by improving coverage and/or diversity of analyzable networks while reducing measurement overhead. Our main contribution is a new framework for understanding the circumstances and properties for which unsolicited traffic is an appropriate data source for inference of macroscopic Internet properties, which can help other researchers assess its utility for a given study.
Karyn Benson, Alberto Dainotti, K. C. Claffy, Alex C. Snoeren, Michael G. Kallitsis
Internet Measurement Conference4
2015 Empirical Analysis of Search Advertising Strategies
abstract
Top search ad placement is the coin of today's Internet services realm. An entire industry of search engine marketing companies have emerged to help advertisers optimize their ad campaigns to deliver high returns on investment, peddling a plethora of advertising strategies. Yet, very little is publicly known about the effectiveness of online search advertising, especially when trying to compare the various campaign strategies used by advertisers.
Bhanu Chandra Vattikonda, Vacha Dave, Saikat Guha 0002, Alex C. Snoeren
Internet Measurement Conference4
2015 Interpreting Advertiser Intent in Sponsored Search
abstract
Search engines derive revenue by displaying sponsored results along with organic results in response to user queries. In general, search engines run a per-query, on-line auction amongst interested advertisers to select sponsored results to display. In doing so, they must carefully balance the revenue derived from sponsored results against potential degradation in user experience due to less-relevant results. Hence, major search engines attempt to analyze the relevance of potential sponsored results to the user's query using supervised learning algorithms. Past work has employed a bag-of-words approach using features extracted from both the query and potential sponsored result to train the ranker.
Bhanu Chandra Vattikonda, Santhosh Kodipaka, Vacha Dave, Saikat Guha 0002, Alex C. Snoeren
KDD6
2015 Inside the Social Network's (Datacenter) Network
abstract
Large cloud service providers have invested in increasingly larger datacenters to house the computing infrastructure required to support their services. Accordingly, researchers and industry practitioners alike have focused a great deal of effort designing network fabrics to efficiently interconnect and manage the traffic within these datacenters in performant yet efficient fashions. Unfortunately, datacenter operators are generally reticent to share the actual requirements of their applications, making it challenging to evaluate the practicality of any particular design.
Hongyi Zeng, Jasmeet Bagga, George Porter, Alex C. Snoeren
SIGCOMM5
2015 Achieving Congestion Diversity in Multi-Hop Wireless Mesh Networks
abstract
This paper reports on a comprehensive study comparing congestion-aware routing algorithms for wireless mesh networks with a state-of-the-art shortest-path routing protocol: Link-Quality Source Routing (LQSR). In particular, a set of congestion-aware protocols in the literature, Backpressure (BP), Enhanced-Backpressure (E-BP) and Congestion Diversity Protocol (CDP) are suitably adapted for implementation on 802.11-compatible radios. A testbed consisting of 802.11g nodes is deployed to empirically compare the performance of these congestion-aware routing protocols against LQSR. The results show that, under moderate to heavy UDP traffic, CDP delivers significant improvement compared to LQSR in 80-90 percent of the instances studied, while backpressure-based routing algorithms (BP and E-BP) frequently show significant degradation with respect to LQSR for both UDP and TCP traffic.
Abhijeet Bhorkar, Tara Javidi, Alex C. Snoeren
IEEE Trans. Mob. Comput.3
2015 Managing Contention with Medley
abstract
As WLANs achieve gigabit per second speeds, they will need to support users with a wide range of workloads, ranging from VoIP and Web clients to data backup, file transfers, and streaming high-definition video. Unfortunately, channel efficiency degrades severely in these scenarios under existing MAC protocols due to contention and back-off overheads. Moreover, small yet latency-sensitive flows suffer disproportionally as load increases. We present Medley, a system that leverages frequency-based contention to allocate subchannels in an OFDMA-based link layer in a delay-fair manner. In contrast to traditional CSMA schemes in which each node competes uniformly for the channel, Medley ensures that nodes with smaller service rates are served before those with heavier demand; the more bandwidth a node consumes, the larger its packet average delay will become. An initial implementation of Medley on a software defined radio platform demonstrates its feasibility in a small network, while more comprehensive simulation results show its benefits under a wider range of conditions. Medley delivers delay fairness while remaining over 94 percent efficient in the face of massive over-subscription.
Geoffrey M. Voelker, Alex C. Snoeren
IEEE Trans. Mob. Comput.3
2014 Blender: upgrading tenant-based data center networking
abstract
This paper presents Blender, a framework that enables network operators to improve tenant performance by tailoring the network's behavior to tenant needs. Tenants may upgrade their provisioned portion of the network with specific features, such as multi-path routing, isolation, and failure recovery, without modifying hosted application code. Network operators may differentiate themselves based on upgrades they offer, creating new upgrades via a light-weight programming interface. Blender safely executes multiple tenants' selections simultaneously across a shared network infrastructure. We show that the Blender model can express and extend recently proposed network functionality on existing SDN networks. We use an OpenFlow-based prototype to quantify Blender's performance and potential for deployment at scale.
Kevin C. Webb 0001, Ken Yocum, Alex C. Snoeren
ANCS4
2014 On The Security of Mobile Cockpit Information Systems
abstract
Recent trends in aviation have led many general aviation pilots to adopt the use of iPads (or other tablets) in the cockpit. While initially used to display static charts and documents, uses have expanded to include live data such as weather and traffic information that is used to make flight decisions. Because the tablet and any connected devices are not a part of the onboard systems, they are not currently subject to the software reliability standards applied to avionics. In this paper, we create a risk model for electronic threats against mobile cockpit information systems and evaluate three such systems popular with general aviation pilots today: The Appareo Stratus 2 receiver with the ForeFlight app, the Garmin GDL~39 receiver with the Garmin Pilot app, and the SageTech Clarity CL01 with the WingX Pro7 app. We found all three to be vulnerable, allowing an attacker to manipulate information presented to the pilot, which in some scenarios would lead to catastrophic outcomes. Finally, we provide recommendations for securing such systems.
Devin Lundberg, Brown Farinholt, Edward Sullivan, Ryan Mast, Stephen Checkoway, Stefan Savage, Alex C. Snoeren, Kirill Levchenko
CCS7
2014 Deniable Liaisons
abstract
People sometimes need to communicate directly with one another while concealing the communication itself. Existing systems can allow users to achieve this level of privacy in the wide-area Internet, but parties who are in close proximity (e.g., a public square or coffee shop) may want a lightweight communications channel with similar properties. Today, covert exchanges in local settings typically require the exchange of physical media or involve other forms of direct communication (e.g., conversations, blind drops); most, if not all, of these exchanges are observable: in other words, even if the message exchanges are confidential, they are not covert or deniable. We construct a local communications channel that is unobservable to everyone except the parties exchanging messages. To do so, we take advantage of the ubiquitous phenomenon of packet corruption in wireless networks, which provide deniable cover for message exchange between parties within radio range. The communicating parties use a shared secret to differentiate truly corrupted frames from those that hide messages; to other parties, messages appear as corrupted wireless frames. We tackle the challenge of designing the observable corruption patterns to ensure that an observer can neither link sender and receiver of a hidden message(unlinkability), nor determine so much as the existence of any hidden message (deniability). We present the design and implementation of a prototype system that achieves these properties using off-the-shelf 802.11 hardware, evaluate its performance, and assess its resilience to various attacks.
Abhinav Narain, Nick Feamster, Alex C. Snoeren
CCS3
2014 Enfold: downclocking OFDM in WiFi
abstract
Dynamic voltage and frequency scaling (DVFS) has long been used as a technique to save power in a variety of computing domains but typically not in communications devices. A fundamental limit that prevents decreasing the clock frequency is the Nyquist(-Shannon) sampling theorem, which states that the sampling rate must be twice the signal bandwidth. Recently, researchers have leveraged compressive sensing to demonstrate the possibility of decoding a sparse signal below Nyquist rate. In this work, we dramatically extend the state of the art by showing how to decode non-sparse signals, in particular, OFDM systems at sub-Nyquist rates. We exploit the aliasing that results from under-sampling and observe that there exists well-defined structure in terms of how OFDM signals are "folded up" under aliasing. Based on our observations, we present Enfold, which allows existing WiFi chipsets to decode standards-compliant WiFi frames while operating at 50% and 25% of their rated clock rate. Our design is able to attain greater than 96% and 83% raw packet reception rates for moderate SNR while reducing the clock rate by 2x and 4x, respectively. Moreover, our approach can be easily applied to other communication systems based on OFDM modulation. When evaluated on popular smartphone app traces, Enfold reduces energy consumption by up to 34%.
Patrick Ling, Geoffrey M. Voelker, Alex C. Snoeren
MobiCom4
2014 Botcoin: Monetizing Stolen Cycles
Danny Yuxing Huang, Hitesh Dharmdasani, Sarah Meiklejohn, Vacha Dave, Chris Grier, Damon McCoy, Stefan Savage, Nicholas Weaver, Alex C. Snoeren, Kirill Levchenko
NDSS9
2014 Circuit Switching Under the Radar with REACToR
Alex Forencich, Rishi Kapoor, Malveeka Tewari, Geoffrey M. Voelker, George Papen, Alex C. Snoeren, George Porter
NSDI8
2014 Exposing Inconsistent Web Search Results with Bobble
Xinyu Xing 0001, Wei Meng 0001, Dan Doozan, Nick Feamster, Wenke Lee, Alex C. Snoeren
PAM6
2013 Bullet trains: a study of NIC burst behavior at microsecond timescales
abstract
While numerous studies have examined the macro-level behavior of traffic in data center networks---overall flow sizes, destination variability, and TCP burstiness---little information is available on the behavior of data center traffic at packet-level timescales. Whereas one might assume that flows from different applications fairly share available link bandwidth, and that packets within a single flow are uniformly paced, the reality is more complex. To meet increasingly high link rates of 10 Gbps and beyond, batching is typically introduced across the network stack---at the application, middleware, OS, transport, and NIC layers. This batching results in short-term packet bursts, which have implications for the design and performance requirements of packet processing devices along the path, including middleboxes, SDN-enabled switches, and virtual machine hypervisors.
Rishi Kapoor, Alex C. Snoeren, Geoffrey M. Voelker, George Porter
CoNEXT2
2013 A comparison of syslog and IS-IS for network failure analysis
abstract
Accurate reporting and analysis of network failures has historically required instrumentation (e.g., dedicated tracing of routing protocol state) that is rarely available in practice. In previous work, our group has proposed that a combination of common data sources could be substituted instead. In particular, by opportunistically stitching together data from router configuration logs and syslog messages, we demonstrated that a granular picture of network failures could be resolved and verified with human trouble tickets. In this paper, we more fully evaluate the fidelity of this approach, by comparing with high-quality "ground truth" data derived from an analysis of contemporaneous IS-IS routing protocol messages. We identify areas of agreement and disparity between these data sources, as well as potential ways to correct disparities when possible.
Daniel Turner, Kirill Levchenko, Stefan Savage, Alex C. Snoeren
Internet Measurement Conference4
2013 SloMo: Downclocking WiFi Communication
Geoffrey M. Voelker, Alex C. Snoeren
NSDI3
2013 Quantifying the benefits of joint content and network routing
abstract
Online service providers aim to provide good performance for an increasingly diverse set of applications and services. One of the most effective ways to improve service performance is to replicate the service closer to the end users. Replication alone, however, has its limits: while operators can replicate static content, wide-scale replication of dynamic content is not always feasible or cost effective. To improve the latency of such services many operators turn to Internet traffic engineering. In this paper, we study the benefits of performing replica-to-end-user mappings in conjunction with active Internet traffic engineering. We present the design of PECAN, a system that controls both the selection of replicas ("content routing") and the routes between the clients and their associated replicas ("network routing"). We emulate a replicated service that can perform both content and network routing by deploying PECAN on a distributed testbed. In our testbed, we see that jointly performing content and network routing can reduce round-trip latency by 4.3% on average over performing content routing alone (potentially reducing service response times by tens of milliseconds or more) and that most of these gains can be realized with no more than five alternate routes at each replica.
Vytautas Valancius, Bharath Ravi, Nick Feamster, Alex C. Snoeren
SIGMETRICS4
2013 Take This Personally: Pollution Attacks on Personalized Services
Xinyu Xing 0001, Wei Meng 0001, Dan Doozan, Alex C. Snoeren, Nick Feamster, Wenke Lee
USENIX Security Symposium4
2012 Practical TDMA for datacenter ethernet
abstract
Cloud computing is placing increasingly stringent demands on datacenter networks. Applications like MapReduce and Hadoop demand high bisection bandwidth to support their all-to-all shuffle communication phases. Conversely, Web services often rely on deep chains of relatively lightweight RPCs. While HPC vendors market niche hardware solutions, current approaches to providing high-bandwidth and low-latency communication in the datacenter exhibit significant inefficiencies on commodity Ethernet hardware.
Bhanu Chandra Vattikonda, George Porter, Amin Vahdat, Alex C. Snoeren
EuroSys4
2012 scc: cluster storage provisioning informed by application characteristics and SLAs
Harsha V. Madhyastha, John McCullough, George Porter, Rishi Kapoor, Stefan Savage, Alex C. Snoeren, Amin Vahdat
FAST6
2012 Weighted fair queuing with differential dropping
abstract
Weighted fair queuing (WFQ) allows Internet operators to define traffic classes and then assign different bandwidth proportions to these classes. Unfortunately, the complexity of efficiently allocating the buffer space to each traffic class turns out to be overwhelming, leading most operators to vastly overprovision buffering-resulting in a large resource footprint. A single buffer for all traffic classes would be preferred due to its simplicity and ease of management. Our work is inspired by the approximate differential dropping scheme but differs substantially in the flow identification and packet dropping strategies. Augmented with our novel differential dropping scheme, a shared buffer WFQ performs as well or better than the original WFQ implementation under varied traffic loads with a vastly reduced resource footprint.
Geoffrey M. Voelker, Alex C. Snoeren
INFOCOM3
2012 Router Support for Fine-Grained Latency Measurements
abstract
An increasing number of datacenter network applications, including automated trading and high-performance computing, have stringent end-to-end latency requirements where even microsecond variations may be intolerable. The resulting fine-grained measurement demands cannot be met effectively by existing technologies, such as SNMP, NetFlow, or active probing. We propose instrumenting routers with a hash-based primitive that we call a Lossy Difference Aggregator (LDA) to measure latencies down to tens of microseconds even in the presence of packet loss. Because LDA does not modify or encapsulate the packet, it can be deployed incrementally without changes along the forwarding path. When compared to Poisson-spaced active probing with similar overheads, our LDA mechanism delivers orders of magnitude smaller relative error; active probing requires 50-60 times as much bandwidth to deliver similar levels of accuracy. Although ubiquitous deployment is ultimately desired, it may be hard to achieve in the shorter term; we discuss a partial deployment architecture called mPlane using LDAs for intrarouter measurements and localized segment measurements for interrouter measurements.
Ramana Rao Kompella, Kirill Levchenko, Alex C. Snoeren, George Varghese
IEEE/ACM Trans. Netw.3
2011 TransCloud - Design Considerations for a High-performance Cloud Architecture Across Multiple Administrative Domains
Andy C. Bavier, Marco Yuen, Jessica Blaine, Rick McGeer, Alvin AuYoung, Yvonne Coady, Chris Matthews, Christopher Pearson, Alex C. Snoeren, Joe Mambretti
CLOSER9
2011 Achieving congestion diversity in wireless ad-hoc networks
abstract
This work presents the Congestion Diversity Protocol (CDP), a routing protocol for multi-hop wireless networks that combines important aspects of shortest-path and backpressure routing to achieve improved end-end delay performance. In particular, CDP delivers lower end-to-end delay and fewer packet drops than existing routing protocols while maintaining equivalent throughput. This paper reports on a practical (hardware and software) implementation of CDP in an indoor WiFi network consisting of 12 802.11g nodes. This small test-bed enables an imperical comparison of CDP's performance against a set of state of the art protocols which include both congestion unaware and congestion aware routing protocols. In most topologies and scenarios we consider, CDP provides improvements for UDP traffic with respect to both end-end delay and throughput over the existing protocols.
Abhijeet Bhorkar, Tara Javidi, Alex C. Snoeren
INFOCOM3
2011 On the empirical performance of self-calibrating WiFi location systems
abstract
The pervasive deployment of 802.11 in modern enterprise buildings has long made it an attractive technology for constructing indoor location services. To this end, a broad range of algorithms have been proposed to accurately estimate location from 802.11 signal strength measurements, some without requiring manual calibration for each physical location. Prior work suggests that many of these protocols can be highly effective- reporting median errors of under 2 meters in some instances. However, there are few studies validating these claims at scale, nor comparing the algorithms in a uniform, realistic environment. Our work provides precisely this kind of empirical evaluation in a realistic office building environment. Surprisingly, we find that median errors in our environment are consistently greater than 5 meters and, counter-intuitively, that simpler algorithms frequently outperform their more sophisticated counterparts. In analyzing our results, we argue that unrealistic assumptions about access point densities and underlying variability in the indoor environment may preclude highly accurate location estimates based on 802.11 signal strength.
Daniel Turner, Stefan Savage, Alex C. Snoeren
LCN3
2011 DieCast: Testing Distributed Systems with an Accurate Scale Model
abstract
Large-scale network services can consist of tens of thousands of machines running thousands of unique software configurations spread across hundreds of physical networks. Testing such services for complex performance problems and configuration errors remains a difficult problem. Existing testing techniques, such as simulation or running smaller instances of a service, have limitations in predicting overall service behavior at such scales. Testing large services should ideally be done at the same scale and configuration as the target deployment, which can be technically and economically infeasible. We present DieCast , an approach to scaling network services in which we multiplex all of the nodes in a given service configuration as virtual machines across a much smaller number of physical machines in a test harness. We show how to accurately scale CPU, network, and disk to provide the illusion that each VM matches a machine in the original service in terms of both available computing resources and communication behavior. We present the architecture and evaluation of a system we built to support such experimentation and discuss its limitations. We show that for a variety of services---including a commercial high-performance cluster-based file system---and resource utilization levels, DieCast matches the behavior of the original service while using a fraction of the physical resources.
Diwaker Gupta, Kashi Venkatesh Vishwanath, Marvin McNett, Amin Vahdat, Ken Yocum, Alex C. Snoeren, Geoffrey M. Voelker
ACM Trans. Comput. Syst.6
2011 Distributed application configuration, management, and visualization with plush
abstract
Support for distributed application management in large-scale networked environments remains in its early stages. Although a number of solutions exist for subtasks of application deployment, monitoring, and maintenance in distributed environments, few tools provide a unified framework for application management. Many of the existing tools address the management needs of a single type of application or service that runs in a specific environment, and these tools are not adaptable enough to be used for other applications or platforms. To this end, we present the design and implementation of Plush, a fully configurable application management infrastructure designed to meet the general requirements of several different classes of distributed applications. Plush allows developers to specifically define the flow of control needed by their computations using application building blocks. Through an extensible resource management interface, Plush supports execution in a variety of environments, including both live deployment platforms and emulated clusters. Plush also uses relaxed synchronization primitives for improving fault tolerance and liveness in failure-prone environments. To gain an understanding of how Plush manages different classes of distributed applications, we take a closer look at specific applications and evaluate how Plush provides support for each.
Jeannie R. Albrecht, Christopher Tuttle, Ryan Braud, Darren Dao, Nikolay Topilski, Alex C. Snoeren, Amin Vahdat
ACM Trans. Internet Techn.6
2010 California fault lines: understanding the causes and impact of network failures
abstract
Of the major factors affecting end-to-end service availability, network component failure is perhaps the least well understood. How often do failures occur, how long do they last, what are their causes, and how do they impact customers? Traditionally, answering questions such as these has required dedicated (and often expensive) instrumentation broadly deployed across a network.
Daniel Turner, Kirill Levchenko, Alex C. Snoeren, Stefan Savage
SIGCOMM3
2010 Stout: An Adaptive Interface to Scalable Cloud Storage
John McCullough, John Dunagan, Alec Wolman, Alex C. Snoeren
USENIX ATC4
2010 Neon: system support for derived data management
abstract
Modern organizations face increasingly complex information management requirements. A combination of commercial needs, legal liability and regulatory imperatives has created a patchwork of mandated policies. Among these, personally identifying customer records must be carefully access-controlled, sensitive files must be encrypted on mobile computers to guard against physical theft, and intellectual property must be protected from both exposure and "poisoning." However, enforcing such policies can be quite difficult in practice since users routinely share data over networks and derive new files from these inputs--incidentally laundering any policy restrictions. In this paper, we describe a virtual machine monitor system called Neon that transparently labels derived data using byte-level "tints" and tracks these labels end to end across commodity applications, operating systems and networks. Our goal with Neon is to explore the viability and utility of transparent information flow tracking within conventional networked systems when used in the manner in which they were intended. We demonstrate that this mechanism allows the enforcement of a variety of data management policies, including data-dependent confinement, mandatory I/O encryption, and intellectual property management.
Qing Zhang 0012, John McCullough, Justin Ma, Nabil Schear, Michael Vrable, Amin Vahdat, Alex C. Snoeren, Geoffrey M. Voelker, Stefan Savage
VEE7
2010 Fault Localization via Risk Modeling
abstract
Internet backbone networks are under constant flux in order to keep up with demand and offer new features. The pace of change in technology often outstrips the pace of introduction of associated fault monitoring capabilities that are built into today's IP protocols and routers. Moreover, some of these new technologies cross networking layers, raising the potential for unanticipated interactions and service disruptions, which the individual layers' built-in monitoring capabilities may not detect. In these instances, operators typically employ higher layer monitoring techniques such as end-to-end liveness probing to detect lower or cross-layer failures, but lack tools to precisely determine where a detected failure may have occurred. In this paper, we evaluate the effectiveness of using risk modeling to translate high-level failure notifications into lower layer root causes in two specific scenarios in a tier-1 ISP. We show that a simple greedy heuristic works with accuracy exceeding 80 percent for many failure scenarios in simulation, while delivering extremely high precision (greater than 80 percent). We report our operational experience using risk modeling to isolate optical component and MPLS control plane failures in an ISP backbone.
Ramana Rao Kompella, Jennifer Yates, Albert G. Greenberg, Alex C. Snoeren
IEEE Trans. Dependable Secur. Comput.4
2010 Usage Patterns in an Urban WiFi Network
abstract
While WiFi was initially designed as a local-area access network, mesh networking technologies have led to increasingly expansive deployments of WiFi networks. In urban environments, the WiFi mesh frequently supplements a number of existing access technologies, including wired broadband networks, 3G cellular, and commercial WiFi hotspots. It is an open question what role citywide WiFi deployments play in the increasingly diverse access network spectrum. We study the usage of the Google WiFi network deployed in Mountain View, CA, and find that usage naturally falls into three classes based almost entirely on client device type, which we divide into traditional laptop users, fixed-location access devices, and PDA-like smartphone devices. Moreover, each of these classes of use has significant geographic locality, following the distribution of residential, commercial, and transportation areas of the city. When comparing the network usage of each device class, we find a diverse set of mobility patterns that map well to the archetypal use cases for traditional access technologies. To help place our results in context, we also provide key performance measurements of the mesh backbone and, where possible, compare them to those of previously studied urban mesh networks.
Mikhail Afanasyev, Tsuwei Chen, Geoffrey M. Voelker, Alex C. Snoeren
IEEE/ACM Trans. Netw.4
2010 Covenant: An architecture for cooperative scheduling in 802.11 wireless networks
abstract
Wireless networks based on 802.11a/b/g protocols have gained wide-spread acceptance in both enterprise as well as home networks. However, these devices lack native support for many advanced features such as service differentiation, etc., that are required in specific application domains. In this paper, we propose Covenant, a software based cooperative scheduling framework to provide a rich set of features for applications that require nodes to cooperate with each other to satisfy system-wide objectives. We propose a novel 2 1/2-stage pipeline architecture as an efficient mechanism to implement cooperative scheduling among multiple nodes. We demonstrate how Covenant can be easily implemented in software, thus requiring absolutely no hardware or firmware changes to the already widely installed base of 802.11a/b/g based wireless devices. We also evaluate, using a real Linux based test-bed with Covenant drivers, the efficacy of the approach on two different scheduling disciplines: proportional priority and strict priority. We demonstrate that these scheduling disciplines are effective in providing service guarantees to multimedia applications even in the presence of other competing traffic.
Ishwar Ramani, Ramana Rao Kompella, Sriram Ramabhadran, Alex C. Snoeren
IEEE Trans. Wirel. Commun.4
2009 The importance of being overheard: throughput gains in wireless mesh networks
abstract
A flurry of recent work has focused on the performance gains that may be achieved by leveraging the broadcast nature of the wireless channel. In particular, researchers have observed that nodes other than the intended recipient of a packet may overhear the transmission in certain settings. Systems have been proposed to leverage this so-called overhearing phenomena by opportunistically adjusting forwarding paths, suppressing similar transmissions, and superimposing packet transmissions using network coding. The effectiveness of such approaches in practice depends greatly on the empirical overhearing rate, which is a function not only of the particular network and its environment, but also upon individual nodes' transmission rates.
Mikhail Afanasyev, Alex C. Snoeren
Internet Measurement Conference2
2009 Softspeak: Making VoIP Play Well in Existing 802.11 Deployments
Patrick Verkaik, Yuvraj Agarwal, Rajesh K. Gupta 0001, Alex C. Snoeren
NSDI4
2009 Application Management and Visualization with Plush
abstract
Deploying, running, and maintaining applications running on a distributed set of resources is a challenging task. Software developers often spend a significant amount of time dealing with the complexities associated with software configuration and management in these environments. Distributed application management systems are designed to automate the process, and to ultimately help developers cope with the common problems that arise during the design, implementation, and evaluation of distributed systems. In this talk, we highlight the key features of Plush, an application management system for PlanetLab and ModelNet, and describe how Plush simplifies peer-to-peer system visualization and evaluation.
Jeannie R. Albrecht, Ryan Braud, Alex C. Snoeren, Amin Vahdat
Peer-to-Peer Computing3
2009 Enlisting ISPs to Improve Online Privacy: IP Address Mixing by Default
Barath Raghavan, Tadayoshi Kohno, Alex C. Snoeren, David Wetherall
Privacy Enhancing Technologies3
2009 Evaluating the impact of inaccurate information in utility-based scheduling
abstract
Proponents of utility-based scheduling policies have shown the potential for a 100--1400% increase in value-delivered to users when used in lieu of traditional approaches such as FCFS, backfill or priority queues. However, perhaps due to concerns about their potential fragility, these policies are rarely used in practice. We present an evaluation of a utility-based scheduling policy based upon real workload data from both an auction-based resource infrastructure, and a supercomputing cluster. We model potential sources of imperfect operating conditions for a utility-based policy: user uncertainty and wealth inequity. Through simulation, we find that while the value delivered by a utility-based policy can degrade to half that of traditional approaches in the worst case, the policy we study provides 20--100% improvement under realistic operating conditions. We conclude that future efforts in designing utility-based allocation mechanisms and policies must explicitly consider the fidelity of elicited job value information from users.
Alvin AuYoung, Amin Vahdat, Alex C. Snoeren
SC3
2009 Every microsecond counts: tracking fine-grain latencies with a lossy difference aggregator
abstract
Many network applications have stringent end-to-end latency requirements, including VoIP and interactive video conferencing, automated trading, and high-performance computing---where even microsecond variations may be intolerable. The resulting fine-grain measurement demands cannot be met effectively by existing technologies, such as SNMP, NetFlow, or active probing. We propose instrumenting routers with a hash-based primitive that we call a Lossy Difference Aggregator (LDA) to measure latencies down to tens of microseconds and losses as infrequent as one in a million.Such measurement can be viewed abstractly as what we refer to as a coordinated streaming problem, which is fundamentally harder than standard streaming problems due to the need to coordinate values between nodes. We describe a compact data structure that efficiently computes the average and standard deviation of latency and loss rate in a coordinated streaming environment. Our theoretical results translate to an efficient hardware implementation at 40 Gbps using less than 1% of a typical 65-nm 400-MHz networking ASIC. When compared to Poisson-spaced active probing with similar overheads, our LDA mechanism delivers orders of magnitude smaller relative error; active probing requires 50--60 times as much bandwidth to deliver similar levels of accuracy.
Ramana Rao Kompella, Kirill Levchenko, Alex C. Snoeren, George Varghese
SIGCOMM3
2009 Secure and policy-compliant source routing
Barath Raghavan, Patrick Verkaik, Alex C. Snoeren
IEEE/ACM Trans. Netw.3
2008 Analysis of a mixed-use urban wifi network: when metropolitan becomes neapolitan
abstract
While WiFi was initially designed as a local-area access network, mesh networking technologies have led to increasingly expansive deployments of WiFi networks. In urban environments, the WiFi mesh frequently supplements a number of existing access technologies, including wired broadband networks, 3G cellular, and commercial WiFi hotspots. It is an open question what role city-wide WiFi deployments play in the increasingly diverse access network spectrum. We study the usage of the Google WiFi network deployed in Mountain View, California, and find that usage naturally falls into three classes, based almost entirely on client device type. Moreover, each of these classes of use has significant geographic locality, following the distribution of residential, commercial, and transportation areas of the city. Finally, we find a diverse set of mobility patterns that map well to the archetypal use cases for traditional access technologies.
Mikhail Afanasyev, Tsuwei Chen, Geoffrey M. Voelker, Alex C. Snoeren
Internet Measurement Conference4
2008 Efficiency Through Eavesdropping: Link-layer Packet Caching
Mikhail Afanasyev, David G. Andersen, Alex C. Snoeren
NSDI3
2008 Difference Engine: Harnessing Memory Redundancy in Virtual Machines
Diwaker Gupta, Michael Vrable, Stefan Savage, Alex C. Snoeren, George Varghese, Geoffrey M. Voelker, Amin Vahdat
OSDI5
2008 High-bandwidth data dissemination for large-scale distributed systems
abstract
This article focuses on the multireceiver data dissemination problem. Initially, IP multicast formed the basis for efficiently supporting such distribution. More recently, overlay networks have emerged to support point-to-multipoint communication. Both techniques focus on constructing trees rooted at the source to distribute content among all interested receivers. We argue, however, that trees have two fundamental limitations for data dissemination. First, since all data comes from a single parent, participants must often continuously probe in search of a parent with an acceptable level of bandwidth. Second, due to packet losses and failures, available bandwidth is monotonically decreasing down the tree. To address these limitations, we present Bullet, a data dissemination mesh that takes advantage of the computational and storage capabilities of end hosts to create a distribution structure where a node receives data in parallel from multiple peers. For the mesh to deliver improved bandwidth and reliability, we need to solve several key problems: (i) disseminating disjoint data over the mesh, (ii) locating missing content, (iii) finding who to peer with (peering strategy), (iv) retrieving data at the right rate from all peers (flow control), and (v) recovering from failures and adapting to dynamically changing network conditions. Additionally, the system should be self-adjusting and should have few user-adjustable parameter settings. We describe our approach to addressing all of these problems in a working, deployed system across the Internet. Bullet outperforms state-of-the-art systems, including BitTorrent, by 25-70% and exhibits strong performance and reliability in a range of deployment settings. In addition, we find that, relative to tree-based solutions, Bullet reduces the need to perform expensive bandwidth probing.
Dejan Kostic, Alex C. Snoeren, Amin Vahdat, Ryan Braud, Chip Killian, James W. Anderson, Jeannie R. Albrecht, Adolfo Rodriguez, Erik Vandekieft
ACM Trans. Comput. Syst.2
2007 Detection and Localization of Network Black Holes
abstract
Internet backbone networks are under constant flux, struggling to keep up with increasing demand. The pace of technology change often outstrips the deployment of associated fault monitoring capabilities that are built into today's IP protocols and routers. Moreover, some of these new technologies cross networking layers, raising the potential for unanticipated interactions and service disruptions that the built-in monitoring systems cannot detect. In such instances, failures may cause data packets to be silently dropped inside the network without triggering any alarms or responses (e.g., the failure is not routed around). So-called "silent failures" or "black holes" represent a critical threat to today's rapidly evolving networks. In this paper, we present a simple and effective method to detect and diagnose such silent failures. Our method uses active measurement between edge routers to raise alarms whenever end-to-end connectivity is disrupted, regardless of the cause. These alarms feed localization agents that employ spatial correlation techniques to isolate the root-cause of failure. Using data from two real systems deployed on sections of a tier-I ISP network, we successfully detect and localize three known black holes. Further, we present simulation results demonstrating that our system accurately and precisely (both greater than 80% according to our metrics) localizes a variety of failures classes.
Ramana Rao Kompella, Jennifer Yates, Albert G. Greenberg, Alex C. Snoeren
INFOCOM4
2007 A Performance Analysis of Indirect Routing
abstract
Indirect routing involves sending messages between Internet end nodes through a specified intermediate node to effect a different end-to-end route than the default "direct" route. Indirect routing offers the potential for significant improvements in throughput performance by exploiting the Internet's richness in throughput diversity. We present a performance analysis of indirect routing, showing that it can result in a 33-49% increase in average throughput performance while incurring low overhead.
Joshua M. Opos, Sriram Ramabhadran, Andrew Terry, Joseph Pasquale, Alex C. Snoeren, Amin Vahdat
IPDPS5
2007 Remote Control: Distributed Application Configuration, Management, and Visualization with Plush
Jeannie R. Albrecht, Ryan Braud, Darren Dao, Nikolay Topilski, Christopher Tuttle, Alex C. Snoeren, Amin Vahdat
LISA6
2007 Automating cross-layer diagnosis of enterprise wireless networks
abstract
Modern enterprise networks are of sufficient complexity that even simple faults can be difficult to diagnose - let alone transient outages or service degradations. Nowhere is this problem more apparent than in the 802.11-based wireless access networks now ubiquitous in the enterprise. In addition to the myriad complexities of the wired network, wireless networks face the additional challenges of shared spectrum, user mobility and authentication management. Not surprisingly, few organizations have the expertise, data or tools to decompose the underlying problems and interactions responsible for transient outages or performance degradations. In this paper, we present a set of modeling techniques for automatically characterizing the source of such problems. In particular, we focus on data transfer delays unique to 802.11 networks - media access dynamics and mobility management latency. Through a combination of measurement, inference and modeling we reconstruct sources of delay - from the physical layer to the transport - layer as well as the interactions among them. We demonstrate our approach using comprehensive traces of wireless activity in the UCSD Computer Science building.
Yuchung Cheng, Mikhail Afanasyev, Patrick Verkaik, Péter Benkö, Jennifer Chiang, Alex C. Snoeren, Stefan Savage, Geoffrey M. Voelker
SIGCOMM6
2007 Cloud control with distributed rate limiting
abstract
Today's cloud-based services integrate globally distributed resources into seamless computing platforms. Provisioning and accounting for the resource usage of these Internet-scale applications presents a challenging technical problem. This paper presents the design and implementation of distributed rate limiters, which work together to enforce a global rate limit across traffic aggregates at multiple sites, enabling the coordinated policing of a cloud-based service's network traffic. Our abstraction not only enforces a global limit, but also ensures that congestion-responsive transport-layer flows behave as if they traversed a single, shared limiter. We present two designs - one general purpose, and one optimized for TCP - that allow service operators to explicitly trade off between communication costs and system accuracy, efficiency, and scalability. Both designs are capable of rate limiting thousands of flows with negligible overhead (less than 3% in the tested configuration). We demonstrate that our TCP-centric design is scalable to hundreds of nodes while robust to both loss and communication delay, making it practical for deployment in nationwide service providers.
Barath Raghavan, Kashi Venkatesh Vishwanath, Sriram Ramabhadran, Ken Yocum, Alex C. Snoeren
SIGCOMM5
2007 Wresting Control from BGP: Scalable Fine-Grained Route Control
Patrick Verkaik, Dan Pei, Tom Scholl, Aman Shaikh, Alex C. Snoeren, Jacobus E. van der Merwe
USENIX ATC5
2006 Decongestion Control
Barath Raghavan, Alex C. Snoeren
HotNets2
2006 To Infinity and Beyond: Time-Warped Network Emulation
Diwaker Gupta, Ken Yocum, Marvin McNett, Alex C. Snoeren, Amin Vahdat, Geoffrey M. Voelker
NSDI4
2006 Jigsaw: solving the puzzle of enterprise 802.11 analysis
abstract
The combination of unlicensed spectrum, cheap wireless interfaces and the inherent convenience of untethered computing have made 802.11 based networks ubiquitous in the enterprise. Modern universities, corporate campuses and government offices routinely de-ploy scores of access points to blanket their sites with wireless Internet access. However, while the fine-grained behavior of the 802.11 protocol itself has been well studied, our understanding of how large 802.11 networks behave in their full empirical complex-ity is surprisingly limited. In this paper, we present a system called Jigsaw that uses multiple monitors to provide a single unified view of all physical, link, network and transport-layer activity on an 802.11 network. To drive this analysis, we have deployed an infrastructure of over 150 radio monitors that simultaneously capture all 802.11b and 802.11g activity in a large university building (1M+ cubic feet). We describe the challenges posed by both the scale and ambiguity inherent in such an architecture, and explain the algorithms and inference techniques we developed to address them. Finally, using a 24-hour distributed trace containing more than 1.5 billion events, we use Jigsaw's global cross-layer viewpoint to isolate performance artifacts, both explicit, such as management inefficiencies, and implicit, such as co-channel interference. We believe this is the first analysis combining this scale and level of detail for a production 802.11 network.
Yuchung Cheng, John Bellardo, Péter Benkö, Alex C. Snoeren, Geoffrey M. Voelker, Stefan Savage
SIGCOMM4
2006 Loose Synchronization for Large-Scale Networked Systems
Jeannie R. Albrecht, Christopher Tuttle, Alex C. Snoeren, Amin Vahdat
USENIX ATC, General Track3
2006 Service Placement in a Shared Wide-Area Platform
David Oppenheimer, Brent N. Chun, David A. Patterson 0001, Alex C. Snoeren, Amin Vahdat
USENIX ATC, General Track4
2005 Why Markets Could (But Don't Currently) Solve Resource Allocation Problems in Systems
Jeffrey Shneidman, Chaki Ng, David C. Parkes, Alvin AuYoung, Alex C. Snoeren, Amin Vahdat, Brent N. Chun
HotOS5
2005 Distributed application management using Plush
abstract
Recent computing trends have shown an increase in the demand for large-scale, distributed, federated computing environments. Two of the more popular environments that have emerged are the grid and PlanetLab. At a high level, these systems are similar in many ways; both are comprised of a set of heterogeneous interconnected machines that allows secure resource sharing for a variety of different users and applications. However, at a lower level, the systems are very distinct in the sense that they were designed to solve different types of problems, and therefore have fundamental differences that make it difficult to develop and deploy applications on both platforms. As a result, application designers and researchers create software that runs on either the grid or PlanetLab, but not both. We propose to solve this problem by describing a common abstraction for both PlanetLab and grid applications. Further, we present Plush - a tool that implements the distributed application abstraction by providing a pluggable and extensible infrastructure allowing users to customize their environment for running experiments on both PlanetLab and the grid.
Jeannie R. Albrecht, Christopher Tuttle, Alex C. Snoeren, Amin Vahdat
HPDC3
2005 IP Fault Localization Via Risk Modeling
Ramana Rao Kompella, Jennifer Yates, Albert G. Greenberg, Alex C. Snoeren
NSDI4
2005 Brief announcement: the overlay network content distribution problem
abstract
Many overlay multicast protocols have been designed and deployed across the Internet to support content distribution. To our knowledge, however, none have provided a rigorous analysis of the problem or the effectiveness of their proposed solutions. We define the Overlay Network Content Distribution (OCD) problem to allow such analyses.
Chip Killian, Michael Vrable, Alex C. Snoeren, Amin Vahdat, Joseph Pasquale
PODC3
2005 To infinity and beyond: time warped network emulation
abstract
This work explores the viability and benefits of time dilation - providing the illusion to an operating system and its applications that time is passing at a rate different from real time. For example, we may wish to convince a system that for every 10 seconds of wall clock time, only one second of time passes in the host's dilated time frame. This enables external stimuli to appear to take place at higher rates than would be physically possible. For example, a host dilated by a factor of 10 receiving data from a network interface at a real rate of 1-Gbps believes it is receiving data at 10-Gbps.
Diwaker Gupta, Ken Yocum, Marvin McNett, Alex C. Snoeren, Amin Vahdat, Geoffrey M. Voelker
SOSP4
2005 Service placement in shared wide-area platforms
abstract
Federated geographically-distributed computing platforms such as PlanetLab [1] and the Grid [2, 3] have recently become popular for evaluating and deploying network services and scientific computations. As the size, reach, and user population of such infrastructures grow, resource discovery and resource selection become increasingly important. Although a number of resource discovery and allocation services have been built, there is little data on the utilization of the distributed computing platforms they target. Yet the design and efficacy of such services depends on the characteristics of the target platform.
David Oppenheimer, Brent N. Chun, David A. Patterson 0001, Alex C. Snoeren, Amin Vahdat
SOSP4
2005 Scalability, fidelity, and containment in the potemkin virtual honeyfarm
abstract
The rapid evolution of large-scale worms, viruses and bot-nets have made Internet malware a pressing concern. Such infections are at the root of modern scourges including DDoS extortion, on-line identity theft, SPAM, phishing, and piracy. However, the most widely used tools for gathering intelligence on new malware -- network honeypots -- have forced investigators to choose between monitoring activity at a large scale or capturing behavior with high fidelity. In this paper, we describe an approach to minimize this tension and improve honeypot scalability by up to six orders of magnitude while still closely emulating the execution behavior of individual Internet hosts. We have built a prototype honeyfarm system, called Potemkin, that exploits virtual machines, aggressive memory sharing, and late binding of resources to achieve this goal. While still an immature implementation, Potemkin has emulated over 64,000 Internet honeypots in live test runs, using only a handful of physical servers.
Michael Vrable, Justin Ma, Jay Chen, David Moore 0001, Erik Vandekieft, Alex C. Snoeren, Geoffrey M. Voelker, Stefan Savage
SOSP6
2005 Maintaining High-Bandwidth Under Dynamic Network Conditions
Dejan Kostic, Ryan Braud, Chip Killian, Erik Vandekieft, James W. Anderson, Alex C. Snoeren, Amin Vahdat
USENIX ATC, General Track6
2004 A system for authenticated policy-compliant routing
abstract
Internet end users and ISPs alike have little control over how packets are routed outside of their own AS, restricting their ability to achieve levels of performance, reliability, and utility that might otherwise be attained. While researchers have proposed a number of source-routing techniques to combat this limitation, there has thus far been no way for independent ASes to ensure that such traffic does not circumvent local traffic policies, nor to accurately determine the correct party to charge for forwarding the traffic.We present Platypus, an authenticated source routing system built around the concept of network capabilities. Network capabilities allow for accountable, fine-grained path selection by cryptographically attesting to policy compliance at each hop along a source route. Capabilities can be composed to construct routes through multiple ASes and can be delegated to third parties. Platypus caters to the needs of both end users and ISPs: users gain the ability to pool their resources and select routes other than the default, while ISPs maintain control over where, when, and whose packets traverse their networks. We describe how Platypus can be used to address several well-known issues in wide-area routing at both the edge and the core, and evaluate its performance, security, and interactions with existing protocols. Our results show that incremental deployment of Platypus can achieve immediate gains.
Barath Raghavan, Alex C. Snoeren
SIGCOMM2
2003 Best-path vs. multi-path overlay routing
abstract
Time-varying congestion on Internet paths and failures due to software, hardware, and configuration errors often disrupt packet delivery on the Internet.Many aproaches to avoiding these problems use multiple paths between two network locations. These approaches rely on a path-independence assumption in order to work well; i.e., they work best when the problems on different paths between two locations are uncorrelated in time.This paper examines the extent to which this assumption holds on the Internet by analyzing 14 days of data collected from 30 nodes in the RON testbed. We examine two problems that manifest themselves---congestion-triggered loss and path failures---and find that the chances of losing two packets between the same hosts is nearly as high when those packets are sent through an intermediate node (60%) as when they are sent back-to-back on the same path (70%). In so doing, we also compare two different ways of taking advantage of path redundancy proposed in the literature: mesh routing based on packet replication, and reactive routing based on adaptive path selection.
David G. Andersen, Alex C. Snoeren, Hari Balakrishnan
Internet Measurement Conference2
2003 Practical lazy scheduling in sensor networks
abstract
Experience has shown that the power consumption of sensors and other wireless computational devices is often dominated by their communication patterns. We present a practical realization of lazy packet scheduling that attempts to minimize the total transmission energy in a broadcast network by dynamically adjusting each node's transmission power and rate on a per-packet basis. Lazy packet scheduling leverages the fact that many channel coding schemes are more efficient at lower transmission rates; that is, the energy required to send a fixed amount of data can be reduced by transmitting the data at a lower bit rate and transmission powe.The optimal per-packet transmission rate in a multi-node network is governed in practice by the available bit rates of the given transceiver(s), the nodes' delay tolerance, and the offered load at every node contending for the shared broadcast channel. We propose an extension to the traditional CSMACA MAC scheme called L-CSMACA that allows individual nodes to continually estimate the current demand for a broadcast channel and adjust their transmission schedules accordingly. Our simulation results show that L-CSMACA can provide improved energy efficiency in a single-hop, broadcast network (20--25% with more than 10 nodes, and up to 99% for four nodes with a standard power function) for both Poisson and bursty arrivals with only minor degradation the capacity of the channe.
Ramana Rao Kompella, Alex C. Snoeren
SenSys2
2002 Single-packet IP traceback
abstract
The design of the IP protocol makes it difficult to reliably identify the originator of an IP packet. Even in the absence of any deliberate attempt to disguise a packet's origin, widespread packet forwarding techniques such as NAT and encapsulation may obscure the packet's true source. Techniques have been developed to determine the source of large packet flows, but, to date, no system has been presented to track individual packets in an efficient, scalable fashion. We present a hash-based technique for IP traceback that generates audit trails for traffic within the network, and can trace the origin of a single IP packet delivered by the network in the recent past. We demonstrate that the system is effective, space efficient (requiring approximately 0.5% of the link capacity per unit time in storage), and implementable in current or next-generation routing hardware. We present both analytic and simulation results showing the system's effectiveness.
Alex C. Snoeren, Craig Partridge, Christine E. Jones, Fabrice Tchakountio, Beverly Schwartz, Stephen T. Kent, W. Timothy Strayer
IEEE/ACM Trans. Netw.1
2001 Reconsidering Internet Mobility
abstract
Despite the popularity of mobile computing platforms, appropriate system support for mobile operation is lacking in the Internet. The paper argues that this is not for lack of deployment incentives, but because a comprehensive system architecture that efficiently addresses the needs of mobile applications does not exist. We identify five fundamental issues raised by mobility: location, preservation of communication, disconnection handling, hibernation, and reconnection, and suggest design guidelines for a system that attempts to support Internet mobility. In particular, we argue that a good system architecture should: (i) eliminate the dependence of higher protocol layers upon lower-layer identifiers; (ii) work with any application-selected naming scheme; (iii) handle (unexpected) network disconnections in a graceful way, exposing its occurrence to applications; and (iv) provide mobility services at the mobile nodes themselves, rather than via proxies. Motivated by these principles, we propose a session-oriented, end-to-end architecture called Migrate, and briefly examine the set of services it should provide.
Alex C. Snoeren, Hari Balakrishnan, M. Frans Kaashoek
HotOS1
2001 Hash-based IP traceback
abstract
The design of the IP protocol makes it difficult to reliably identify the originator of an IP packet. Even in the absence of any deliberate attempt to disguise a packet's origin, wide-spread packet forwarding techniques such as NAT and encapsulation may obscure the packet's true source. Techniques have been developed to determine the source of large packet flows, but, to date, no system has been presented to track individual packets in an efficient, scalable fashion.We present a hash-based technique for IP traceback that generates audit trails for traffic within the network, and can trace the origin of a single IP packet delivered by the network in the recent past. We demonstrate that the system is effective, space-efficient (requiring approximately 0.5% of the link capacity per unit time in storage), and implementable in current or next-generation routing hardware. We present both analytic and simulation results showing the system's effectiveness.
Alex C. Snoeren
SIGCOMM1
2001 Mesh Based Content Routing using XML
abstract
We have developed a new approach for reliably multicasting time-critical data to heterogeneous clients over mesh-based overlay networks. To facilitate intelligent content pruning, data streams are comprised of a sequence of XML packets and forwarded by application-level XML routers. XML routers perform content-based routing of individual XML packets to other routers or clients based upon queries that describe the information needs of downstream nodes. Our PC-based XML router prototype can route an 18 Mbit per second XML stream.Our routers use a novel Diversity Control Protocol (DCP) for router-to-router and router-to-client communication. DCP reassembles a received stream of packets from one or more senders using the first copy of a packet to arrive from any sender. When each node is connected to n parents, the resulting network is resilient to (n − 1) router or independent link failures without repair. Associated mesh algorithms permit the system to recover to (n − 1) resilience after node and/or link failure. We have deployed a distributed network of XML routers that streams real-time air traffic control data. Experimental results show multiple senders improve reliability and latency when compared to tree-based networks.
Alex C. Snoeren, Kenneth Conley, David K. Gifford
SOSP1
2001 FIRE: flexible intra-AS routing environment
abstract
Current routing protocols are monolithic, specifying the algorithm used to construct forwarding tables, the metric used by the algorithm (generally some form of hop count), and the protocol used to distribute these metrics as an integrated package. The flexible intra-AS routing environment (FIRE) is a link-state, intradomain routing protocol that decouples these components. FIRE supports run-time-programmable algorithms and metrics over a secure link-state distribution protocol. By allowing the network operator to dynamically reprogram both the properties being advertised and the routing algorithms used to construct forwarding tables, FIRE enables the development and deployment of novel routing algorithms without the need for a new protocol to distribute state. FIRE supports multiple concurrent routing algorithms and metrics, each constructing separate forwarding tables. By using operator-specified packet filters, separate classes of traffic may be routed using completely different routing algorithms, all supported by a single routing protocol. This paper presents an overview of FIRE, focusing particularly on FIRE's novel aspects with respect to traditional routing protocols. We consider deploying several current unicast and multicast routing algorithms in FIRE, and describe our Java-based implementation.
Craig Partridge, Alex C. Snoeren, W. Timothy Strayer, Beverly Schwartz, Matthew Condell, Isidro Castiñeyra
IEEE J. Sel. Areas Commun.2
2000 An end-to-end approach to host mobility
abstract
We present the design and implementation of an end-to-end architecture for Internet host mobility using dynamic updates to the Domain Name System (DNS) to track host location. Existing TCP connections are retained using secure and efficient connection migration, enabling established connections to seamlessly negotiate a change in endpoint IP addresses without the need for a third party. Our architecture is secure—name updates are effected via the secure DNS update protocol, while TCP connection migration uses a novel set of Migrate options—and provides a pure end-system alternative to routing-based approaches such as Mobile IP.
Alex C. Snoeren, Hari Balakrishnan
MobiCom1
2000 FIRE: Flexible intra-AS routing environment
abstract
Current routing protocols are monolithic, specifying the algorithm used to construct forwarding tables, the metric used by the algorithm (generally some form of hop-count), and the protocol used to distribute these metrics as an integrated package. The Flexible Intra-AS Routing Environment (FIRE) is a link-state, intra-domain routing protocol that decouples these components. FIRE supports run-time-pro- grammable algorithms and metrics over a secure link-state distribution protocol. By allowing the network operator to dynamically reprogram both the information being advertised and the routing algorithm used to construct forwarding tables in Java, FIRE enables the development and deployment of novel routing algorithms without the need for a new protocol to distribute state. FIRE supports multiple concurrent routing algorithms and metrics, each constructing separate forwarding tables. By using operator-specified packet filters, separate classes of traffic are routed using completely different routing algorithms, all supported by a single routing protocol.
Craig Partridge, Alex C. Snoeren, W. Timothy Strayer, Beverly Schwartz, Matthew Condell, Isidro Castiñeyra
SIGCOMM2