EDBT 2026 Demo / reviewers in the wild / expert
Zahir Tari
dblp:t/ZahirTari · also Tari Zahir
· DBLP profile ↗
191ranked-venue papers
17as first author
42since 2021 · last 2026
0000-0002-1235-9673ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 49 · 4 first-author · 8 since 2021Computer networks · 37 · 3 since 2021Databases, data management, data science and information retrieval · 30 · 10 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 18 · 6 since 2021Software engineering, systems software and programming languages · 17 · 1 first-author · 8 since 2021Security and privacy · 16 · 2 first-author · 9 since 2021Artificial intelligence and machine learning · 11 · 3 first-author · 3 since 2021Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RDSAD: Robust Threat Detection in Evolving Data Streams via Adaptive Latent DynamicsabstractCyber-Physical Systems (CPSs) are the backbone of Industry 4.0, seamlessly integrating physical and software components for advanced automation in diverse sectors. Recent cyber incidents have shown that these systems are increasingly vulnerable to targeted attacks. Undetected attacks on CPSs can disrupt operations, compromise safety, and cause significant economic losses. Thus, anomaly-based Intrusion Detection Systems (IDSs) are essential to ensure their safety and security, especially in an unsupervised setting where manual labelling is cost-prohibitive. However, current methods encounter significant challenges with complex and evolving characteristics of data streams generated from CPSs, like high dimensionality, uncertainty, and changing patterns, often resulting in high false alarms and missed attacks. This paper introduces RDSAD, an unsupervised, robust and adaptive anomaly-based intrusion detection method tailored to effectively monitor evolving complex CPS data streams. RDSAD integrates two innovative components: Dynamic Deviation Recognition (DDR) for capturing the underlying system dynamics, and Shift-aware Model Adaptation (SMA) for adaptive model updates in response to changing patterns. Through extensive evaluations, the experimental results demonstrate the superior performance of RDSAD compared with static and streaming state-of-the-art methods. It achieved the best AUC of 0.90 and 0.88 on SWaT and WADI datasets, respectively, and it obtained efficient runtime with large data streams. Abdullah Alsaedi, Zahir Tari, Md. Redowan Mahmud |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | LGP: Layerwise Gradient Purify for Robust Federated Learning Against Poisoning AttacksabstractFederated learning (FL) has become a promising framework for collaborative model training on devices while preserving privacy. However, despite its significant potential, it faces notable cyber threats, such as poisoning attacks and codenamed Byzantine clients. These threats have the potential to significantly degrade the global model by jeopardizing the integrity of the collaborative model training process. Whilst previous research has addressed the detection and elimination of malicious gradients from Byzantine clients, it has also shown that model poisoning attacks can evade most statistical defence approaches relying on metrics such as median and distance. To address the challenge posed by poisoning attacks, we introduce a novel approach called Layerwise Gradient Purify (LGP), which aims to remove any harmful gradients before the global aggregation process. It is comprised of two closely-related stages. The first stage focuses on pruning gradients at the layer level using the Median Absolute Deviation (MAD) pruning criterion. In the second stage, statistical features are extracted from the pruned gradients layer-by-layer and then clustered into honest and malicious categories. The proposed methodology treats each layer of the model across all clients as a probability distribution, employing hierarchical clustering to differentiate between malicious and honest clusters. Moreover, we introduce a new innocent criterion for selecting honest clusters, relying on reputation scores and gradient deviations from the global model. Extensive experiments were conducted employing diverse deep learning models, including CNN, RNN, and MLP, across a spectrum of datasets, including Cifar-10, AG-News, MNIST and ToN-IoT. The experiments evaluated the resilience of state-of-the-art approaches against recently introduced attacks. The numerical results demonstrate that theLGPapproach is effective and superior. Wael Issa, Nour Moustafa, Benjamin P. Turnbull, Zahir Tari |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Split Learning With Local Epoch Regulation and Time-Aware DetectionabstractFederated learning (FL) has become a popular approach in Edge AI for extracting valuable knowledge within edge computing (EC) systems. To enhance AI application performance, large-scale models have gained increasing attention due to their strong generalization capabilities. However, training and transmitting such models impose substantial computational and communication overhead on resource-constrained clients at the edge, and exchanging complete models may also compromise model privacy. To alleviate these burdens and safeguard privacy, split learning (SL) has been introduced by combining data and model parallelism. Although SL alleviates resource constraints, it still encounters efficiency and security challenges in EC environments, where heterogeneous clients can slow down training without enhancing accuracy, and malicious clients may manipulate model behavior. To address these challenges, we propose a novel SL framework, CoDefend, which integrates local epoch regulation and time-aware detection. Specifically, local epoch regulation dynamically assigns heterogeneous clients with appropriate local epoch numbers to improve training efficiency, while time-aware detection provides an effective detection window to identify clients' malicious manipulation to improve model security. Moreover, CoDefend jointly optimizes these two strategies by leveraging their interdependence to further improve SL performance. Extensive experiments on both simulated and real-world platforms using NVIDIA Jetson edge nodes demonstrate that CoDefend achieves approximately 2× faster training speed than baseline methods, while maintaining comparable model accuracy and effectively identifying malicious manipulations even under collusion. Yao Zhao 0006, Zahir Tari, Nasrin Sohrabi, Qin Wang 0008, Xiaoyu Xia 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | DSPFL: A Deep-Layer Sign Sharing Personalized Federated Learning Scheme for Mitigating Poisoning AttacksabstractWith the rise of the smart industry, machine learning (ML) has become a popular method to improve the security of the Industrial Internet of Things (IIoT) by training anomaly detection models. Federated learning (FL) is a distributed ML scheme that facilitates anomaly detection on IIoT by preserving data privacy and breaking data silos. However, poisoning attacks pose significant threats to FL, where adversaries upload poisoned local models to the aggregation server, thereby degrading model accuracy. The prevalence of non-independent and identically distributed (non-IID) data across IIoT devices further exacerbates this threat, as it naturally leads to diverse local models, making malicious ones harder to distinguish. To address the above challenges, we propose a deep-layer sign-sharing personalized FL (DSPFL) scheme. DSPFL innovatively aggregates only the signs of stochastic gradients (SignSGD) from the deep layers of local models during training. This targeted aggregation enhances the robustness of the shared components against poisoning attacks, while shallow layers are retained locally to preserve personalization. This integrated approach improves the accuracy and resilience of personalized local models on IIoT devices under poisoning attacks. Extensive experimental results show that DSPFL consistently achieves up to 20% higher and more stable overall personalized model accuracy compared to state-of-the-art methods under specific poisoning attacks. Chenhao Xu 0003, Nasrin Sohrabi, Youyang Qu, Hai Dong 0001, Zahir Tari, Xun Yi |
IEEE Trans. Neural Networks Learn. Syst. | 5 |
| 2026 | FedGDD: Defending Federated Learning Against Targeted Model Poisoning Sybil Attacks Based on Gradient Drift DetectionabstractSybil attacks pose a significant threat to federated learning, as malicious nodes can collaborate to form a majority and overwhelm the system. Therefore, developing effective countermeasures is essential to ensure the security of federated learning systems. To address this challenge, we introduce a novel targeted model poisoning defence method for federated learning, named Gradient Drift Detection (FedGDD). Unlike existing approaches, such as clustering, statistical analysis, and re-training, which struggle in scenarios where malicious nodes constitute the majority, FedGDD reframes malicious detection as a gradient drift detection problem. This approach identifies potential attacks by detecting deviations in gradients, operating on the premise that the loss functions for benign and malicious nodes are inherently different. Extensive experimental evaluations demonstrate the efficacy of FedGDD compared to six well-established methods: Flame, FLTrust, FedCPA, Median, Krum, and FL-WBC. Using tasks from both image classification and natural language processing, the experiments confirm that FedGDD is robust and independent of specific application settings. Results show that FedGDD effectively safeguards federated learning systems across a wide range of malicious node ratios. Specifically, FedGDD maintains a low attack success rate for malicious nodes when their ratio ranges from 0.2 to 0.8. Additionally, it preserves high model accuracy when the malicious node ratio is between 0.2 and 0.5. These findings highlight FedGDD's potential to enhance the reliability and performance of Federated Learning systems. Hai Dong 0001, Nasrin Sohrabi, Zahir Tari |
IEEE Trans. Reliab. | 4 |
| 2025 | Efficient and Secure Sleepy Model for BFT Consensus
Pengkun Ren, Hai Dong 0001, Zahir Tari, Pengcheng Zhang 0001 |
ESORICS (4) | 3 |
| 2025 | Legal Compliance Evaluation of Smart Contracts Generated by Large Language Models
Chanuka Wijayakoon, Hai Dong 0001, H. M. N. Dilum Bandara, Zahir Tari, Anurag Soin |
ICBC | 4 |
| 2025 | Motivation-Aware Session Planning over Heterogeneous Social PlatformsabstractWith the explosive growth of online service platforms, an increasing number of people and enterprises are undertaking personal and professional tasks online. In real applications such as trip planning and online marketing, planning sessions for a sequence of activities or services will enable social users to receive the optimal services, improving their experience and reducing the cost of their activities. These online platforms are heterogeneous, including different types of services with different attributes. However, the problem of session planning over heterogeneous platforms has not been studied so far. In this paper, we propose a Motivation-Aware Session Planning (MASP) framework for session planning over heterogeneous social platforms. Specifically, we first propose a novel HeterBERT model to handle the heterogeneity of items at both type and attribute levels. Then, we propose to predict user preference using the motivations behind user activities. Finally, we propose an algorithm together with its optimisations for efficient session generation. The extensive tests prove the high effectiveness and efficiency of MASP. Chengkun He, Xiangmin Zhou, Yurong Cheng, Jie Shao 0001, Guoren Wang, Iqbal Gondal, Zahir Tari |
WWW | 7 |
| 2025 | Securing cross-domain data access with decentralized attribute-based access controlabstractIn attribute-based access control (ABAC), access to resources depends on the specific attributes of the entity requesting access. Existing ABAC models primarily depend on local attribute authorities to define and confirm attributes, which makes it challenging to support access decisions cross-domains without introducing centralization. Centralized solutions often conflict with individual domains’ security, privacy, and control requirements and, if compromised for any reason, can impact access to large datasets across participating domains. This paper introduces a novel access control model for cross-domain environments that significantly reduces central control. Our decentralized ABAC (D-ABAC) model uses group signature techniques to exchange attribute information securely and privately within cross-domains. Each domain maintains its own policies and attribute authorities, reducing the need for global trust or centralization to mutual trust between attribute authorities. We further design and implement a proof-of-concept system to demonstrate the practical feasibility of our proposed system for the collaborative and secure sharing of healthcare data in cross-domain environments. The proposed system model enhances security, scalability, and privacy in cross-domain settings, making it suitable for sensitive environments such as healthcare. Ahmad Salehi S., Carsten Rudolph, Hooman Alavizadeh, A. S. M. Kayes, Wenny Rahayu, Zahir Tari |
Ad Hoc Networks | 6 |
| 2025 | MuLPP: A multi-level privacy preserving for blockchain-based bilateral P2P energy tradingabstractChallenges pertaining to user anonymity and data privacy are among the major concerns in blockchain-based bilateral Peer-to-Peer Energy Trading (P2P-ET). However, existing solutions focus only on user anonymity and are severely exposed to fake energy offers that can lead to denial-of-service attacks. Moreover, the off-chain communication mechanism used for private energy negotiation is computationally inefficient. This paper proposes a Multi-Level Privacy-Preserving system (MuLPP) for blockchain-based bilateral P2P-ET that provides user anonymity, energy price and energy amount privacy while protecting against fake energy offers. To address the privacy concerns in a comprehensive way, MuLPP offers three levels of privacy: public-level, energy authority-level and participant-level. MuLPP is based on blockchain smart contracts , RSA accumulators, public key aggregation and BLS-based multi-signature to achieve user anonymity, data privacy, robustness against fake energy offers and security in off-chain negotiation. This paper also proposes a permissioned anonymous decentralized P2P off-chain communication protocol, known as PADPeC, to enhance the privacy and performance of off-chain energy negotiations. Experimental results conducted in a real environment indicate that MuLPP provides 75 to 100 times lower on-chain latency. On the other hand, PADPeC reduces the message-sending time and the number of message exchanges in the off-chain communication by a factor of 4123 and 7.88 respectively compared to the existing systems. Formal security verification conducted using AVISPA security verification tool also revealed that the system is secure against various attacks such as sybil, network flooding and fake energy offer attack. Juhar Ahmed Abdella, Zahir Tari, Md. Redowan Mahmud |
J. Netw. Comput. Appl. | 2 |
| 2025 | ERT: Data placement based on estimated response time for P2P storage systems
Fitrio Pakana, Nasrin Sohrabi, Hai Dong 0001, Zahir Tari, Nour Moustafa |
J. Parallel Distributed Comput. | 4 |
| 2025 | Intelligent Edge Data Integrity Verification With Dynamic Unreliable Data Replica SelectionabstractWith the advancement of Mobile Edge Computing (MEC), App vendors are increasingly motivated to cache multiple data replicas on geographically distributed edge servers to ensure rapid responses for latency-sensitive applications. However, the security of data replicas is a critical concern due to the dynamic nature and resource limitations of MEC environments. To this end, data replicas’ integrity must be regularly verified to maintain the accuracy of data-driven decision-making. Existing Edge Data Integrity (EDI) verification solutions suffer from low efficiency due to relying on indiscriminative verification, where all data replicas are checked at each round without considering their inherent reliability characteristics. This paper designs an Intelligent framework called I-EDI, which enables discriminative EDI verification by integrating a novel Long-term Unreliable data Replica Selection (L-URS) mechanism. This framework aims to reduce verification costs without compromising accuracy, while resisting spoofing, forgery, outsourcing, collusion, alteration-before-verification, delayed-response, and adaptive attacks. Specifically, each data replica is associated with a reliability representation by evaluating its long-term performance. Based on that, the L-URS problem is defined as stochastically minimizing the global reliability representation over time, subject to constraints on the number of data replicas to be verified. To make it easy-to-handle, the L-URS problem is decomposed into a series of online minimization problems. An Online Opportunistic-based Replica Selection approach called O2RS is developed. O2RS allows App vendors to significantly decrease verification costs by targetedly inspecting unreliable data replicas. Moreover, this work provides a thorough theoretical analysis of O2RS’s time complexity and approximation bound, as well as I-EDI’s security. Extensive experiments are conducted to validate the effectiveness and efficiency of O2RS and I-EDI. The results demonstrate that, compared to commonly used alternatives, O2RS achieves an approximate 50% improvement in selection efficiency, while I-EDI reduces verification costs by 1.23 times on average. Yao Zhao 0006, Youyang Qu, Nasrin Sohrabi, Md. Redowan Mahmud, Zahir Tari |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | RACEMAN: Cross-Platform Intrusion Detection in Online Social NetworksabstractOnline Social Networks (OSNs) face various security threats, including account compromisation, where attackers seize control over legitimate user accounts and create fake profiles for nefarious purposes. The dynamic and open nature of OSNs presents unique challenges for cybersecurity, particularly in detecting unauthorized access and malicious activities such as phishing attacks, spamming, and spreading misinformation associated with account compromisation. Traditional intrusion detection systems (IDS) in OSNs often miss attacks or generate false positives due to static thresholds, delayed responses, and poor real-time data handling. These limitations often result in missed detections or false positives during sudden shifts in user activity patterns or emerging attack vectors. We introduce$RACEMAN$, an adaptive IDS designed explicitly for the OSN environment to address this. To enhance adaptability,$RACEMAN$incorporates emergency strategies such as dynamic threshold adjustments based on real-time network traffic analysis and early stopping mechanisms triggered by anomalous behavior spikes, enabling rapid adaptation to changing threat landscapes.$RACEMAN$leverages real-time OSN interactions to continuously update its metamorphic relations, ensuring an up-to-date understanding of normal user behaviour versus potential intrusions. This system utilises advanced semantic analysis to accurately represent user interactions. It generates diverse test cases using genetic algorithms and reinforcement learning to simulate user scenarios and potential intrusion methods. These test cases undergo input transformations to realistically mimic intrusion attempts while maintaining semantic integrity. The system's responses to these test cases are evaluated against expected behaviours defined by the updated metamorphic relations.$RACEMAN$utilizes statistical analysis, Multi-view Convolutional Neural Networks (MVCNN), and rule-based systems for intrusion classification. Our collaborative and distributed IDS approach enhances detection capabilities by promoting knowledge sharing across multiple systems and ensuring scalability without central points of failure. We evaluated$RACEMAN$using six publicly available datasets from Facebook, Google+, Twitter, linkedIn, Youtube and Reddit where it demonstrated a high accuracy rate of 98.85%, outperforming other models such as Convolutional Neural Network (CNN-85.67%), Artificial Neural Network (ANN-86.63%), and Random Forest (RF-78.26%). Edward Kwadwo Boahen, Ahmad Salehi S., Carsten Rudolph, Zahir Tari, Joseph K. Liu |
IEEE Trans. Serv. Comput. | 4 |
| 2025 | FedCAD: Federated Cyberattack Attribution Detection for Internet of Things ForensicsabstractAttributing cyberattacks in Internet of Things (IoT) environments is challenging due to their distributed, heterogeneous natures and the limitations of traditional Digital Forensics (DF) tools for preserving privacy and scalability. This paper presents FedCAD, a novel Federated Learning (FL)-based forensic method for multi-attribute cyberattack attribution that operates directly on IoT devices. It leverages a lightweight 1D Convolutional Neural Network (CNN) architecture with a shared feature extractor and three parallel sub-networks, each of which targets a distinct attribute, i.e., attack types, tactics/tools, and motives. Its architecture consists of three layers: an IoT device one collecting traces and local training; an FL one for privacy-preserving model aggregation via FedAvg; and a DF analysis one for multi-attribute inference and reporting. Also, FedCAD integrates the MITRE ATT&CK framework to enrich training data with real-world adversarial knowledge. Evaluations on the three public datasets TON-IoT, Bot-IoT, and UNSW-NB15 show that FedCAD outperforms centralized models, with gains of 2.1% accuracy, 1.0% precision, 1.5% recall, and 1.3% f1-score on TON-IoT. Experimental results demonstrate FedCAD's effectiveness as a scalable, privacy-preserving solution for cyberattack attribution in dynamic IoT ecosystems. Hania Mohamed, Nour Moustafa, Nickolaos Koroniotis, Zahir Tari, Albert Y. Zomaya, Francesco Schiliro |
IEEE Trans. Sustain. Comput. | 4 |
| 2025 | Cybersecurity Solutions and Techniques for Internet of Things Integration in Combat SystemsabstractThe Internet of Things (IoT) has enabled pervasive networking and multi-modal sensing, offering various services such as remote operations and augmenting existing processes. The military setting has increasingly and notably adopted IoT technologies, such as sensor-rich drones or autonomous vehicles, which provide military personnel with enhanced situational awareness, faster decision-making capabilities, and improved operational precision. However, integrating IoT into military systems introduces new security challenges due to increased connectivity and susceptibility to vulnerabilities. Cyberattacks on military IoT systems can have severe consequences, including operational disruptions and compromises of sensitive information. This article proposes a new perspective on examining threat models in IoT-enhanced combat systems, emphasising approaches for identifying threats, conducting vulnerability assessments, and suggesting countermeasures. It delves into the characteristics and structures of IoT-enhanced combat systems, exploring technical implementations and technologies. Additionally, it outlines five significant areas of focus, including blockchain, machine learning, game theory, protocols, and algorithms, to enhance understanding of IoT-enhanced combat systems. The insights gained from this analysis can inform the development of secure and resilient military IoT systems, ultimately enhancing the safety and effectiveness of military operations. Amirmohammad Pasdar, Nickolaos Koroniotis, Marwa Keshk, Nour Moustafa, Zahir Tari |
IEEE Trans. Sustain. Comput. | 5 |
| 2024 | A Predictive Profiling and Performance Modeling Approach for Distributed Stream Processing in EdgeabstractThe advent of edge computing has allowed the continuously generated data to be processed closer to their sources instead of being sent to the cloud for processing. Given the heterogeneous and limited computational resources and dynamic nature of edge computing, stream processing systems need an accurate and easily accessible performance modeling/measurement to perform efficiently in edge environments. This paper proposes a predictive profiling model to enable measuring the performance of a system by predicting the operators' processing time on heterogeneous devices without having to carry out the testing on individual devices. This profiling model comprises a quadratic function to generate CPU clock speed/processing time curves for each operator. By using these curves, the model predicts the processing times of operators without requiring any extra profiling runs. Moreover, a performance model is proposed to deal with (performance) degradation of stream processing applications by modeling their topologies as systems comprising M/M/1 queues. The model uses the performance expectations of queueing models to define the data transfer rates inside topologies and uses Integer Linear Programming to specify the maximum input rate and an operator placement plan that can process that input rate. Experimental results showed that the profiling approach predicts the processing times of 17 operators with an average error rate of 5%. The performance model finds the maximum input rate accurately, while the operator placement plan achieves up to 84% higher throughput and 70% less latency in AWS EC2 instances and 257% higher throughput and 66% less latency in real hardware compared to the default resource-aware scheduler of Apache Storm. Hasan Geren, Nasrin Sohrabi, Zahir Tari, Nour Moustafa |
ICDE | 3 |
| 2024 | Influence-Aware Group Recommendation for Social Media PropagationabstractGroup recommendation over social media streams has attracted attention due to its wide applications such as e-commerce, entertainment and online news broadcasting. However, existing stream group recommendation techniques ignore the influence of user groups, which are not effective for item propagation over social networks. To address this problem, we propose a framework for Influence-aware Group Recommendation (IGR) over high-speed social streams. Specifically, we first propose a novel GroupGCN model to capture the dynamics of user attributes and interactions which maps groups and items to their embeddings. A Temporal GroupGCN-RNN-Autoencoder (TGGCN-RA) model is designed to extend GroupGCN for sequence-based tasks, enabling the prediction of group interests over time. Then, we adopt an Independent Cascade (IC) model to predict the influence propagation of social items over user groups. Extensive experiments prove the high effectiveness and efficiency of IGR. Chengkun He, Xiangmin Zhou, Chen Wang 0008, Longbing Cao, Jie Shao 0001, Zahir Tari |
ICDM | 6 |
| 2024 | A Query Language to Enhance Security and Privacy of Blockchain as a Service (BaaS)
Nasrin Sohrabi, Norrathep Rattanavipanon, Zahir Tari |
ICSOC (2) | 3 |
| 2024 | A Smart Contract-Based Access Control Framework For Smart Healthcare SystemsabstractAbstract Security faces huge challenges in Internet of Things (IoT) environments. In particular, conventional access control standards and models tend to be less tailored for IoT due to the constrained nature of smart objects. Usually, a powerful third party is used to handle the access control logic. However, this third party is lacking in transparency and could harm user privacy. Therefore, providing a distributed access control solution, while considering transparency and privacy-preserving awareness in IoT smart systems, is of paramount importance. The described issue can be addressed using the emergent Blockchain technology that provides a promising choice to build a new generation of decentralized and transparent access control solutions. This paper proposes a smart contract-based access control framework for IoT smart healthcare systems, which is based on smart contracts to provide a distributed and trustworthy access control, combined with the GTRBAC model to express fine-grained access control policies while considering temporal authorization constraints. To prove the feasibility and validity of the proposed framework, this paper also provides a detailed technical description and an initial implementation and execution. An experimental evaluation shows that security properties’ analyses on smart contracts achieved the best possible evaluation with no vulnerabilities found, and the cost of access control operations increases linearly as the number of policy constraints increases. Besides, a comparative analysis reveals that the proposed approach can achieve good results with low gas costs and latency. Amal Abid 0002, Saoussen Cheikhrouhou, Slim Kallel, Zahir Tari, Mohamed Jmaiel |
Comput. J. | 4 |
| 2024 | Proactive defense mechanism: Enhancing IoT security through diversity-based moving target defense and cyber deceptionabstractThe Internet of Things (IoT) has become increasingly prevalent in various aspects of our lives, enabling billions of devices to connect and communicate seamlessly. However, the intricate nature of IoT connections and device vulnerabilities exposes the devices to security threats. To address the security challenges, we propose a proactive defense framework that leverages a model-based approach for security analysis and facilitates the defense strategies. Our proposed approach incorporates proactive defense mechanisms that combine Moving Target Defense techniques with cyber deception. The proposed approach involves the use of a decoy nodes as a deception technique and operating system based diversity as a moving target defense strategy to change the attack surface area of IoT networks. Additionally, we introduce a technique known as Important Measure-based Operating System Diversity to reduce defense cost. The effectiveness of the defense mechanisms was evaluated by using a graphical security model in a Software Defined Networking-based IoT network. Simulation results demonstrate the effectiveness of our approach in mitigating the impact of attacks while maintaining high performance levels in IoT networks. Zubaida Rehman, Iqbal Gondal, Hai Dong 0001, Mark A. Gregory, Zahir Tari |
Comput. Secur. | 6 |
| 2024 | Hygiea+: Toward Energy-Efficient and Highly Accurate Toothbrushing Monitoring via Wrist-Worn Gesture SensingabstractProper and effective toothbrushing technique is crucial for maintaining oral health. However, there are often limited opportunities for individuals to receive specific training in toothbrushing posture in their daily lives. In this article, we propose Hygiea+, a convenient, energy-efficient, and highly accurate toothbrushing monitoring system based on wrist-worn wearables. By leveraging inertial measurement units (IMUs) in wrist-worn devices for gesture sensing, Hygiea+ enables users to accurately and efficiently monitor their toothbrushing activities without any modifications to the toothbrush. We propose a number of novel techniques to achieve the goal of high sensing accuracy and energy efficiency. To reduce the energy consumption of continuous IMU sampling, we model the sensing problem as a Markov process and design a partially observable Markov decision process (POMDP)-based adaptive sampling strategy to dynamically adjust the sampling frequency. To achieve high sensing accuracy, we first propose a novel signal preprocessing method to mitigate variations resulting from different toothbrush types and user habits. Then, we propose a deep reinforcement learning-based data distillation mechanism to extract key segments from continuous toothbrushing actions, thus reducing the impact of redundant data and noise. In the classification stage, we design an attention-based long short-term memory (AT-LSTM) network for fine-grained toothbrushing posture recognition. In addition, to address the accuracy degradation of new users, we adopt the common but effective fine-tuning method to alleviate the data collection burden on new users. Finally, we connect advanced large language models (LLMs) to provide users with necessary feedback on toothbrushing behavior and health recommendations. Extensive experiments using both manual and electric toothbrushes demonstrate Hygiea+ achieves up to 98.8% accuracy in toothbrushing posture recognition while maintaining superior energy efficiency. Xingyu Feng 0001, Chengwen Luo 0001, Junliang Chen 0002, Jianqiang Li 0001, Zahir Tari, Weitao Xu |
IEEE Internet Things J. | 6 |
| 2024 | CeKT: Knowledge Tracing for Predicting Collective Performance on Exercise SequenceabstractThe integration of artificial intelligence has become a hot topic in the field of education. However, current studies primarily focus on personalization for learners, with the aim of accurately modeling learners’ knowledge level based on their learning history and providing better personalized services, while overlooking the needs of educators. In contrast to the focus on personalization of learners, educators place greater emphasis on accurately assessing collective performance and relative differences within a group, which serves as a qualitative measure of the teaching quality. In this study, we investigate collective knowledge tracing (CeKT), a method designed to estimate the average knowledge level of all students in a course based on a sequence of exercises. To achieve this objective, we propose a graph-based solution capable of estimating the average knowledge level solely from the exercise sequence as well as capturing the intrinsic structure of the exercise sequence (i.e., the sequential order of exercises and the repetition of exercises). Through experimental validation, we affirm that our approach enables a precise estimation of the average knowledge mastery of all students given an exercise sequence and also holds distinct value in three applications within the education domain. Zetao Zheng, Zhengyang Wu 0001, Zahir Tari, Jia Zhu 0003 |
IEEE Trans. Comput. Soc. Syst. | 3 |
| 2024 | Request Dispatching Over Distributed SDN Control Plane: A Multiagent ApproachabstractSoftware-defined networking (SDN) allows flexible and centralized control in cloud data centers. An elastic set of distributed SDN controllers is often required to provide sufficient yet cost-effective processing capacity. However, this introduces a new challenge: Request Dispatching among the controllers by SDN switches. It is essential to design a dispatching policy for each switch to guide the request distribution. Existing policies are designed under certain assumptions, including a single centralized agent, global network knowledge, and a fixed number of controllers, which often cannot be satisfied in practice. This article proposes MADRina, Multiagent Deep Reinforcement Learning for request dispatching, to design policies with high dispatching adaptability and performance. First, we design a multiagent system to address the limitation of using a centralized agent with global network knowledge. Second, we propose a Deep Neural Network-based adaptive policy to enable request dispatching over an elastic set of controllers. Third, we develop a new algorithm to train the adaptive policies in a multiagent context. We prototype MADRina and build a simulation tool to evaluate its performance using real-world network data and topology. The results show that MADRina can significantly reduce response time by up to 30% compared to existing approaches. Victoria Huang 0001, Gang Chen 0002, Xingquan Zuo, Albert Y. Zomaya, Nasrin Sohrabi, Zahir Tari, Qiang Fu 0011 |
IEEE Trans. Cybern. | 6 |
| 2024 | Dependency-Aware Task Offloading Based on Application Hit RatioabstractMobile devices commonly offload latency-sensitive applications to edge servers to meet low-latency requirements. However, existing studies overlook dependency and application hit ratio considerations, hindering effective offloading for multi-applications and multi-tasks. To this end, this article proposes a Dependent task offloading and Service placement Optimization (DSO) method to maximize the application hit ratio, thereby providing high-quality service. The proposed DSO includes Improved Multi-Agent Q-Learning (IMAQL) and greedy algorithms. IMAQL optimizes service placement via Q-learning, while the greedy algorithm schedules task offloading. Extensive experiments on public datasets demonstrate that the DSO method enhances the application hit ratio by 4.7% to 11.7% and reduces the completion time by about 3.4% to 4.9% compared to alternative approaches. Junna Zhang, Peiyan Yuan, Hai Dong 0001, Pengcheng Zhang 0001, Zahir Tari |
IEEE Trans. Serv. Comput. | 6 |
| 2023 | RADAR: Reactive Concept Drift Management with Robust Variational Inference for Evolving IoT Data StreamsabstractThe accuracy and performance of Machine Learning (ML) models can gradually or even suddenly degrade when the underlying statistical distribution of data streams changes over time; this is known as concept drift. This phenomenon could adversely affect the IoT data management and analysis landscape that relies intensely on data-driven cognitive technologies. Therefore, concept drift should be detected immediately, which is challenging due to the increasing number of dimensional features and lack of ground truth. Its adaptive countermeasures also become difficult to design when data streams are being generated frequently and require latency-sensitive responses. The uncertainty and time dependencies characteristics of IoT data streams further intensify the complexity of concept drift management. This work proposes a reactive drift management framework named RADAR for streaming IoT applications that can simultaneously detect and react to concept drift using two novel methods: temporal discrepancy measure, and intensity-aware analyser. Collectively, these methods help to determine the adaptation decision to ensure reliable performance, thereby limiting the scope of the frequent ML model update. Experiments conducted using synthetic and real-world setups comprising end-to-end systems demonstrate that RADAR outperforms other benchmarks in achieving better improvement of the performance with the best F-score of 0.86, and obtaining efficient runtime with large data streams. Abdullah Alsaedi, Nasrin Sohrabi, Md. Redowan Mahmud, Zahir Tari |
ICDE | 4 |
| 2023 | Energy efficient resource controller for Apache StormabstractSummary Apache Storm is a distributed processing engine that can reliably process unbounded streams of data for real‐time applications. While recent research activities mostly focused on devising a resource allocation and task scheduling algorithm to satisfy high performance or low latency requirements of Storm applications across a distributed and multi‐core system, finding a solution that can optimize the energy consumption of running applications remains an important research question to be further explored. In this article, we present a controlling strategy for CPU throttling that continuously optimize the level of consumed energy of a Storm platform by adjusting the voltage and frequency of the CPU cores while running the assigned tasks under latency constraints defined by the end‐users. The experimental results running over a Storm cluster with 4 physical nodes (total 24 cores) validates the effectiveness of proposed solution when running multiple compute‐intensive operations. In particular, the proposed controller can keep the latency of analytic tasks, in terms of 99th latency percentile, within the quality of service requirement specified by the end‐user while reducing the total energy consumption by 18% on average across the entire Storm platform. M. Reza HoseinyFarahabady, Javid Taheri, Albert Y. Zomaya, Zahir Tari |
Concurr. Comput. Pract. Exp. | 4 |
| 2023 | USMD: UnSupervised Misbehaviour Detection for Multi-Sensor DataabstractCyber-Physical Systems (CPSs) enable Information Technology to be integrated with Operation Technology to efficiently monitor and manage the physical processes of various critical infrastructures. Recent incidents in cyber ecosystems have shown that CPSs are becoming increasingly vulnerable to complex attacks. These incidents often lead to sensing and actuation misbehaviour by illegal manipulations of data, which can severely impact the underlying physical processes of critical infrastructures. Current research acknowledges that IT-based security measures cannot entirely protect CPSs from such threats. Moreover, they are not designed to monitor the measurement level activities of physical processes, and they fail to mitigate blended cyberattacks, especially multi-stage and zero-day ones. This article addresses these limitations by proposing a framework, named UnSupervised Misbehaviour Detection (USMD), comprising a deep neural network that learns about a system's expected behaviour from data-driven representations. USMD can identify in real-time the attacks on CPSs by using the long-short term memory and Attention method for multi-sensor data. The USMD's performance is evaluated on various known data sets (i.e., ToN_IoT, SWaT, WADI and Gas pipeline datasets). The experimental results indicate that the superior performance of USMD compared with six state-of-the-art methods, which we implemented and extensively tested. USMD achieves F-scores of 0.9699 and 0.9702 on SWaT and WADI datasets, respectively. Abdullah Alsaedi, Zahir Tari, Md. Redowan Mahmud, Nour Moustafa, Abdun Naser Mahmood, Adnan Anwar |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Transition Waste Optimization for Coded Elastic ComputingabstractDistributed computing, in which a resource-intensive task is divided into subtasks and distributed among different machines, plays a key role in solving large-scale problems.Coded computingis a recently emerging paradigm where redundancy for distributed computing is introduced to alleviate the impact of slow machines (stragglers) on the completion time. We investigate coded computing solutions over elastic resources, where the set of available machines may change in the middle of the computation. This is motivated by recently available services in the cloud computing industry (e.g., EC2 Spot, Azure Batch) where low-priority virtual machines are offered at a fraction of the price of the on- demand instances but can be preempted on short notice. Our contributions are three-fold. We first introduce a new concept calledtransition wastethat quantifies the number of tasks existing machines must abandon or take over when a machine joins/leaves. We then develop an efficient method to minimize the transition waste for the cyclic task allocation scheme recently proposed in the literature (Yang et al. ISIT’19). Finally, we establish a novel solution based on finite geometry achievingzerotransition wastes given that the number of active machines varies within a fixed range. Son Hoang Dau, Ryan Gabrys, Yu-Chih Huang, Chen Feng 0001, Quang-Hung Luu, Eidah J. Alzahrani, Zahir Tari |
IEEE Trans. Inf. Theory | 7 |
| 2023 | An Explainable Deep Learning Framework for Resilient Intrusion Detection in IoT-Enabled Transportation NetworksabstractThe security of safety-critical IoT systems, such as the Internet of Vehicles (IoV), has a great interest, focusing on using Intrusion Detection Systems (IDS) to recognise cyber-attacks in IoT networks. Deep learning methods are commonly used for the anomaly detection engines of many IDSs because of their ability to learn from heterogeneous data. However, while this type of machine learning model produces high false-positive rates and the reasons behind its predictions are not easily understood, even by experts. The ability to understand or comprehend the reasoning behind the decision of an IDS to block a particular packet helps cybersecurity experts validate the system’s effectiveness and develop more cyber-resilient systems. This paper proposes an explainable deep learning-based intrusion detection framework that helps improve the transparency and resiliency of DL-based IDS in IoT networks. The framework employs a SHapley Additive exPlanations (SHAP) mechanism to interpret decisions made by deep learning-based IDS to experts who rely on the decisions to ensure IoT networks’ security and design more cyber-resilient systems. The proposed framework was validated using the ToN_IoT dataset and compared with other compelling techniques. The experimental results have revealed the high performance of the proposed framework with a 99.15% accuracy and a 98.83% F1 score, illustrating its capability to protect IoV networks against sophisticated cyber-attacks. Ayodeji Oseni, Nour Moustafa, Gideon Creech, Nasrin Sohrabi, Andrew Strelzoff, Zahir Tari, Igor Linkov |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2023 | AI-Enabled Secure Microservices in Edge Computing: Opportunities and ChallengesabstractThe paradigm of edge computing has formed an innovative scope within the domain of the Internet of Things (IoT) through expanding the services of the cloud to the network edge to design distributed architectures and securely enhance decision-making applications. Due to the heterogeneous, distributed and resource-constrained essence of edge Computing, edge applications are required to be developed as a set of lightweight and interdependent modules. As this concept aligns with the objectives of microservice architecture, effective implementation of microservices-based edge applications within IoT networks has the prospective of fully leveraging edge nodes capabilities. Deploying microservices at IoT edge faces plenty of challenges associated with security and privacy. Advances in Artificial Intelligence (AI) (especially Machine Learning), and the easy access to resources with powerful computing providing opportunities for deriving precise models and developing different intelligent applications at the edge of network. In this study, an extensive survey is presented for securing edge computing-based AI Microservices to elucidate the challenges of IoT management and enable secure decision-making systems at the edge. We present recent research studies on edge AI and microservices orchestration and highlight key requirements as well as challenges of securing Microservices at IoT edge. We also propose a Microservices-based edge computing framework that provides secure edge AI algorithms as Microservices utilizing the containerization technology to offer automated and secure AI-based applications at the network edge. Firas Al-Doghman, Nour Moustafa, Ibrahim Khalil 0001, Nasrin Sohrabi, Zahir Tari, Albert Y. Zomaya |
IEEE Trans. Serv. Comput. | 5 |
| 2023 | SAZyzz: Scaling AZyzzyva to Meet Blockchain RequirementsabstractWe present SAZyzz, a leader-based Byzantine Fault Tolerant consensus protocol for partially synchronous networks. SAZyzz exhibits a better performance/scalability compared to the state-of-the-art leader-based BFT consensus protocols. It is built on top of AZyzzyva and has adopted a tree-based communication model which enables it to enhance the scalability of AZyzzyva. Additionally, SAZyzz reduces the communication complexity toO(logN) in two paths of the protocol. However, the tree-based topology has been argued that has a shortcoming when used in designing BFT consensus protocols. This refers to the strong assumption that all the internal nodes of the tree are honest, which leads to a trade-off between tolerating Byzantine faults and better performance and scalability. This paper shows that, with the current technological infrastructures available for industrial systems, such as Trusted Execution Environment (TEE) and Public Key Infrastructure (PKI), this assumption is realistic. SAZyzz comprises of fast-path and backup-path, each of which has two modes:simple modeandscalable mode. To demonstrate the efficiency and feasibility of SAZyzz's adoption for blockchain systems, we designed and implemented the ZyConChain blockchain system based on SAZyzz. The evaluation results show that SAZyzz can significantly improve the performance/scalability of blockchain systems. Nasrin Sohrabi, Zahir Tari, Gauthier Voron, Vincent Gramoli, Qiang Fu 0011 |
IEEE Trans. Serv. Comput. | 2 |
| 2023 | Editorial Sustainable Defence and Security SystemsabstractIn an increasingly interconnected world, the sophistication of cyber-attacks is on the rise. Cybersecurity research stands as a pivotal factor in shaping the prosperity of nations. To counter threats to network infrastructure and sensitive data, a multitude of security solutions with varying degrees of efficacy have been proposed. However, these solutions have thus far insufficiently accounted for a critical dimension: sustainability. In this context, sustainability entails the continuous support of processes over time by enhancing the computational requisites, scalability, energy efficiency, and resource utilization of defence and security systems. This special issue endeavors to explore recent strides in model development, innovative methodologies, and insightful observations aimed at enhancing cybersecurity, with a particular emphasis on the sustainability of defence and security systems. Paul D. Yoo, Zahir Tari |
IEEE Trans. Sustain. Comput. | 2 |
| 2022 | GreenFog: A Framework for Sustainable Fog Computing
Adel Nadjaran Toosi, Chayan Agarwal, Lena Mashayekhy, Sara Kardani-Moghaddam, Md. Redowan Mahmud, Zahir Tari |
ICSOC | 6 |
| 2022 | Enhancing disk input output performance in consolidated virtualized cloud platforms using a randomized approximation schemeabstractAbstract In a virtualized computer system with shared resources, consolidated virtual services (VSs) fiercely compete with each other to obtain the required capacity of resources, and this causes significant system's performance degradation. The performance of input output (I/O)‐bound applications running inside their own VS is mainly determined by the total time required to schedule every read/write request, plus the actual time needed by the device driver to complete the request. To achieve a right performance isolation of shared resources (e.g., the last level cache, memory bandwidth, and the disk buffer), it is essential to limit the performance degradation level among collocated applications, as simultaneously several I/O operations are requested by VSs, perhaps with different priorities. This article proposes a resource allocation controller that uses a fully polynomial‐time randomized approximation scheme to enable performance isolation of concurrent I/O requests in a shared system with multiple consolidated VSs. This controller uses a Monte Carlo sampling approach to measure and estimate the unknown attributes of operational requests originating from each VS. This is formalized as an optimization problem with the aim to minimize the degree of total quality of service (QoS) violation incidents in the entire platform. We associated a reward function to every working machine that represents the fulfillment degree of quality of service metric among all running VSs. The conducted comprehensive set of experiments showed that the proposed algorithm can reduce the QoS violation incidents by 32%, compared with the result which is obtained by employing the default resource allocation policy embedded in the existing Linux container layer. M. Reza HoseinyFarahabady, Javid Taheri, Albert Y. Zomaya, Zahir Tari, Wei Bao 0001 |
Concurr. Comput. Pract. Exp. | 4 |
| 2021 | Data-Intensive Workload Consolidation in Serverless (Lambda/FaaS) PlatformsabstractA significant amount of research studies in the past years has been devoted on developing efficient mechanisms to control the level of degradation among consolidate workloads in a shared platform. Workload consolidation is a promising feature that is employed by most service providers to reduce the total operating costs in traditional computing systems [1]–[3]. Serverless paradigm - also known as Function as a Service, FaaS, and Lambda - recently emerged as a new virtualization run-time model that disentangles the traditional state of applications' users from the burden of provisioning physical computing resources, leaving the difficulty of providing the adequate resource capacity on the service provider's side. This paper focuses on a number of challenges associated with workload consolidation when a serverless platform is expected to execute several data-intensive functional units. Each functional unit is considered to be the atomic component that reacts to a stream of input data. A serverless application in the proposed model is composed of a series of functional units. Through a systematic approach, we highlight the main challenges for devising an efficient workload consolidation process in a data-intensive serverless platform. To this end, we first study the performance interference among multiple workloads to obtain the capacity of last level cache (LLC). We show how such contention among workloads can lead to a significant throughput degradation on a single physical server. We expand our investigation into a general case with the aim to prevent the total throughput never falling below a predefined utilization level. Based on the empirical results, we develop a consolidation model and then design a computationally efficient controller to optimize the throughput degradation among a platform consists fs multiple machines. The performance evaluation is conducted using modern workloads inspired by data management services, and data analytic benchmark tools in our in-house four node platform showing the efficiency of the proposed solution to mitigate the QoS violation rate for high priority applications by 90% while can enhance the normalized throughput usage of disk devices by 39 %. M. Reza HoseinyFarahabady, Javid Taheri, Albert Y. Zomaya, Zahir Tari |
NCA | 4 |
| 2021 | QSpark: Distributed Execution of Batch & Streaming Analytics in Spark PlatformabstractA significant portion of research work in the past decade has been devoted on developing resource allocation and task scheduling solutions for large-scale data processing platforms. Such algorithms are designed to facilitate deployment of data analytic applications across either conventional cluster computing systems or modern virtualized data-centers. The main reason for such a huge research effort stems from the fact that even a slight improvement in the performance of such platforms can bring a considerable monetary savings for vendors, especially for modern data processing engines that are designed solely to perform high throughput or/and low-latency computations over massive-scale batch or streaming data. A challenging question to be yet answered in such a context is to design an effective resource allocation solution that can prevent low resource utilization while meeting the enforced performance level (such as 99-th latency percentile) in circumstances where contention among applications to obtain the capacity of shared resources is a non negligible performance-limiting parameter. This paper proposes a resource controller system, called QSpark, to cope with the problem of (i) low performance (i.e., resource utilization in the batch mode and p-99 response time in the streaming mode), and (ii) the shared resource interference among collocated applications in a multi-tenancy modern Spark platform. The proposed solution leverages a set of controlling mechanisms for dynamic partitioning of the allocation of computing resources, in a way that it can fulfill the QoS re-quirements of latency-critical data processing applications, while enhancing the throughput for all working nodes without reaching their saturation points. Through extensive experiments in our in-house Spark cluster, we compared the achieved performance of proposed solution against the default Spark resource allocation policy for a variety of Machine Learning (ML), Artificial Intelligence (AI), and Deep Learning (DL) applications. Experimental results show the effectiveness of the proposed solution by reducing the p-99 latency of high priority applications by 32 % during the burst traffic periods (for both batch and stream modes), while it can enhance the QoS satisfaction level by 65 % for applications with the highest priority (compared with the results of default Spark resource allocation strategy). M. Reza HoseinyFarahabady, Javid Taheri, Albert Y. Zomaya, Zahir Tari |
NCA | 4 |
| 2021 | Low Latency Execution Guarantee Under Uncertainty in Serverless Platforms
M. Reza HoseinyFarahabady, Javid Taheri, Albert Y. Zomaya, Zahir Tari |
PDCAT | 4 |
| 2021 | Future generation of service-oriented computing systems
Sami Yangui, Andrzej M. Goscinski, Khalil Drira, Zahir Tari, Djamal Benslimane |
Future Gener. Comput. Syst. | 4 |
| 2021 | Towards an ultra lightweight block ciphers for Internet of Things
Layth Sliman, Tasnime Omrani, Zahir Tari, Abed Ellatif Samhat, Rhouma Rhouma |
J. Inf. Secur. Appl. | 3 |
| 2021 | Semantic eSystems: Engineering methods, techniques, and toolsabstractWe are delighted to present this novel special issue, which emphasizes semantic eSystems and their engineering methods, techniques, and tools. “eSystems” are those interdisciplinary cost-effective and interconnected solutions that leverage advanced information and communication technologies' techniques and tools to gain competitive advantage. Recent years have witnessed increasing interest in the design and development of various eSystem-based applications, ranging from real-world to machine and robotic applications. An essential feature in eSystems is their intelligent ability to “speak” and interact with one another to support function “extensibility” so that complex interactions could be established with other eSystems. Therefore, connecting disparate eSystems “on the fly” necessitates engineering a dialog channel such that it enables data fusion, exchange, and link in a unified and understandable way. While data emitted from eSystems are of different formats, sizes, and types, adopting semantic data technologies is a natural way to address these differences. Simply put, semantics is about agreeing on a common understanding of data that need to be exchanged between systems and between humans and systems. This special issue received 22 submissions, which were aligned with the theme of semantic eSystems' methods, techniques, and tools. Those submissions came from diverse researchers from academia, industry, and individuals from all over the globe. First, all submissions were screened closely by the editors to check their suitability with the special issue's list of topics. Second, after multiple rounds of peer review, only 11 high-quality submissions were accepted for publication in this special issue. Those accepted papers address the semantic eSystems theme from different perspectives including, for instance, efficient semantic–visual indexing model for large-scale image retrieval in cloud environment, trilateration-based indoor localization engineering technique for visible light communication system, graph-based system to enable efficient transformation of enterprise infrastructures, recognizing physical activities having complex interclass variations using semantic data of smartphone, spatiotemporal-based sentiment analysis on tweets for risk assessment of an event using the deep-learning approach, sentiment-based eSystem using hybridized fuzzy and deep neural network for measuring customer satisfaction, data fusion analysis for emotion recognition with thermal image and Internet of Thing devices, unified framework to manage cybersecurity and safety in manufacturing industry, graph-based convolutional neural network stock price prediction with leading indicators, author classification using transfer learning and predicting stars in coauthor networks, and DNA signal analysis tool: intelligent noise suppression window filter. The authors express their sincere thanks to the Editor-in-Chief for allowing them to organize this special issue. The editorial office staff members are excellent and are thanked for their support. The authors are also thankful to all the contributors who made this special issue possible and to the reviewers for their thoughtful contributions. Thar Baker, Dhiya Al-Jumeily, Zakaria Maamar, Zahir Tari |
Softw. Pract. Exp. | 4 |
| 2021 | Assessing the Severity of Smart Attacks in Industrial Cyber-Physical SystemsabstractIndustrial cyber-physical systems (ICPS) are heterogeneous inter-operating parts that can be physical, technical, networking, and even social like agent operators. Incrementally, they perform a central role in critical and industrial infrastructures, governmental, and personal daily life. Especially with the Industry 4.0 revolution, they became more dependent on the connectivity by supporting novel communication and distance control functionalities, which expand their attack surfaces that result in a high risk for cyber-attacks. Furthermore, regarding physical and social constraints, they may push up new classes of security breaches that might result in serious economic damages. Thus, designing a secure ICPS is a complex task, since this needs to guarantee security and harmonize the functionalities between the various parts that interact with different technologies. This article highlights the significance of cyber-security infrastructure and shows how to evaluate, prevent, and mitigate ICPS-based cyber-attacks. We carried out this objective by establishing an adequate semantics for ICPS’s entities and their composition, which includes social actors that act differently than mobile robots and automated processes. This article also provides the feasible attacks generated by a reinforcement learning mechanism based on multiple criteria that selects both appropriate actions for each ICPS component and the possible countermeasures for mitigation. To efficiently analyze ICPS’s security, we proposed a model-checking-based framework that relies on a set of predefined attacks from where the security requirements are used to assess how well the model is secure. Finally, to show the effectiveness of the proposed solution, we model, analyze, and evaluate the ICPS security on two real use cases. Abdelaziz Khaled, Samir Ouchani, Zahir Tari, Khalil Drira |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2021 | Editorial: Sustainable Information Security and Forensic Computing
Paul D. Yoo, Zahir Tari |
IEEE Trans. Sustain. Comput. | 2 |
| 2020 | Spark-Tuner: An Elastic Auto-Tuner for Apache Spark StreamingabstractSpark has emerged as one of the most widely and successfully used data analytical engine for large-scale enterprise, mainly due to its unique characteristics that facilitate computations to be scaled out in a distributed environment. This paper deals with the performance degradation due to resource contention among collocated analytical applications with different priority and dissimilar intrinsic characteristics in a shared Spark platform. We propose an auto-tuning strategy of computing resources in a distributed Spark platform for handling scenarios in which submitted analytical applications have different quality of service (QoS) requirements (e.g., latency constraints), while the interference among computing resources is considered as a key performance-limiting parameter. We compared Spark-Tuner to two widely used resource allocation heuristics in a large scale Spark cluster through extensive experimental settings across several traffic patterns with uncertain rate and application types. Experimental results show that with Spark-Tuner, the Spark engine can decrease the p-99 latency of high priority applications by 43% during the high-rate traffic periods, while maintaining the same level of CPU throughput across a cluster. M. Reza HoseinyFarahabady, Javid Taheri, Albert Y. Zomaya, Zahir Tari |
CLOUD | 4 |
| 2020 | Q-Flink: A QoS-Aware Controller for Apache FlinkabstractModern stream-data processing platforms are required to execute processing pipelines over high-volume, yet high-velocity, datasets under tight latency constraints. Apache Flink has emerged as an important new technology of large-scale platform that can distribute processing over a large number of computing nodes in a cluster (i.e., scale-out processing). Flink allows application developers to design and execute queries over continuous raw-inputs to analyze a large amount of streaming data in a parallel and distributed fashion. To increase the throughput of computing resources in stream processing platforms, a service provider might be tempted to use a consolidation strategy to pack as many processing applications as possible on the working nodes, with the hope of increasing the total revenue by improving the overall resource utilization. However, there is a hidden trap for achieving such a higher throughput solely by relying on an interference-oblivious consolidation strategy. In practice, collocated applications in a shared platform can fiercely compete with each others for obtaining the capacity of shared resources (e.g., cache and memory bandwidth) which in turn can lead to a severe performance degradation for all consolidated workloads.This paper addresses the shared resource contention problem associated with the auto-resource controlling mechanism of Apache Flink engine running across a distributed cluster. A controlling strategy is proposed to handle scenarios in which stream processing applications may have different quality of service (QoS) requirements while the resource interference is considered as the key performance-limiting parameter. The performance evaluation is carried out by comparing the proposed controller with the default Flink resource allocation strategy in a testbed cluster with total 32 Intel Xeon cores under different workload traffic with up to 4000 streaming applications chosen from various benchmarking tools. Experimental results demonstrate that the proposed controller can successfully decrease the average latency of high priority applications by 223% during the burst traffic while maintaining the requested QoS enforcement levels. M. Reza HoseinyFarahabady, Ali Jannesari, Javid Taheri, Wei Bao 0001, Albert Y. Zomaya, Zahir Tari |
CCGRID | 6 |
| 2020 | DyBatch: Efficient Batching and Fair Scheduling for Deep Learning Inference on Time-sharing DevicesabstractRecently, Deep Learning (DL) is widely applied to intelligent systems equipped with resource-constraint hardware accelerators. With multiple DL applications sharing the resource, the execution model can be divided into two stages: (i) batching independent inference tasks initiated by each application, and (ii) scheduling batches to run in a time-sharing manner. The state-of-the-art DL serving systems employ the execution model by organizing sequential tasks into batches and then scheduling batches concerning their targeting deep neural network (DNN) models in a round-robin manner. However, we demonstrated that these practices fail to alleviate the slowdown of tasks, and there is a need to re-visit batching and scheduling in terms of efficiency and fairness. To this end, we formulated batching as a resource allocation problem and investigated scheduling in terms of each application's utilization on the device. Then, we proposed the fine-grained batching scheme and fairness-driven scheduling scheme for DL serving and implemented a prototype system called DyBatch. To be exact, DyBatch accomplishes efficient batching by taking into account Pareto efficiency of and envy between batches. Besides, DyBatch's fair scheduler monitors the resource utilization of all applications and assigns a batch from the application with the lowest utilization for execution first. Evaluation under various benchmarks with comparison to the baseline system Tensorflow Serving (TFS) shows the superiority of DyBatch, which achieves up to 55% reduction of slowdown, and up to 12% improvement of throughput. Shaojun Zhang, Wei Li 0058, Chen Wang 0008, Zahir Tari, Albert Y. Zomaya |
CCGRID | 4 |
| 2020 | Auto-tuning of large-scale iterative operations on modern streaming platformsabstractAs more analytical applications today require real-time processing over high volume data streams, finding an optimal implementation of traditional algorithms which possess iterative computations are gaining popularity and become crucial in most commercial contexts, particularly in edge processing and cloud applications. In this work, we propose an auto-tuning mechanism for enhancing the run-time performance of real-world iterative and cyclic stream processing applications (Multi-Join Operation as the study case) to correctly adjust the right performance bounds for workloads with different characteristics and data-sizes running on modern streaming data processing platform. M. Reza HoseinyFarahabady, Javid Taheri, Albert Y. Zomaya, Zahir Tari |
CoNEXT | 4 |
| 2020 | On The Scalability of Blockchain SystemsabstractBlockchain, as a promising solution to develop secure distributed ledgers, has drawn a huge attention over the last decade. By introducing a pseudonymous payment model with no central authority, blockchain marked the new generation of online payment systems, known as Cryptocurrencies. For most of the existing cryptocurrencies, scalability has become a challenging problem. When dealing with an ever increasing number of users, miners, and transactions, the technology is unable to scale and provide the same performance as centralised systems (e.g. centralised payment systems).Without addressing this fundamental scalability problem, such a promising technology may not be able to be adopted in mainstream. This paper provides an attempt to analyse the scalability of existing blockchain protocols and look at the major factors affecting scalability, namely throughput and latency. We also describe the HTNZ protocol, a new approach to improve the scalability of Satoshi Nakamoto's model [1], validated by experimental results. HTNZ introduces two new components, namely, sideBlock and helper. SideBlock has a slightly different structure of block and increases the number of transactions that can be processed per each interval. Nasrin Sohrabi, Zahir Tari |
IC2E | 2 |
| 2020 | Optimizing the Transition Waste in Coded Elastic ComputingabstractMotivated by recently available services in the cloud computing industry, e.g., EC2 Spot or Azure Batch, where spare/low-priority virtual machines are offered at a fraction of the price of the on-demand instances but can be preempted on short notice, we investigate coded computing solutions over elastic resources, where the set of available machines may change in the middle of the computation. Our contributions are two-fold: We first propose an efficient method to minimize the transition waste, a newly introduced concept quantifying the total number of tasks that existing machines have to abandon or take on anew when a machine joins or leaves, for the cyclic elastic task allocation scheme recently proposed in the literature (Yang et al. ISIT'19). We then proceed to generalize such a scheme and introduce new task allocation schemes based on finite geometry that achieve zero transition wastes as long as the number of active machines varies within a fixed range. The proposed solutions can be applied on top of existing coded computing schemes tolerating stragglers. Son Hoang Dau, Ryan Gabrys, Yu-Chih Huang, Chen Feng 0001, Quang-Hung Luu, Eidah J. Alzahrani, Zahir Tari |
ISIT | 7 |
| 2020 | A Dynamic Resource Controller for Resolving Quality of Service Issues in Modern Streaming Processing EnginesabstractDevising an elastic resource allocation controller of data analytical applications in virtualized data-center has received a great attention recently, mainly due to the fact that even a slight performance improvement can translate to huge monetary savings in practical large-scale execution. Apache Flink is among modern streamed data processing run-times that can provide both low latency and high throughput computation in to execute processing pipelines over high-volume and high-velocity data-items under tight latency constraints. However, a yet to be answered challenge in a large-scale platform with tens of worker nodes is how to resolve the run-time violation in the quality of service (QoS) level in a multi-tenant data streaming platforms, particularly when the amount of workload generated by different users fluctuates. Studies showed that a static resource allocation algorithm (round-robin), which is used by default in Apache Flink, suffer from lack of responsiveness to sudden traffic surges happening unpredictably during the run-time. In this paper, we address the problem of resource management in a Flink platform for ensuring different QoS enforcement levels in a platform with shared computing resources. The proposed solution applies theoretical principals borrowed from close-loop control theory to design a CPU and memory adjustment mechanism with the primary goal to fulfill the different QoS levels requested by submitted applications while the resource interference is considered as the critical performance-limiting factor. The performance evaluation is carried out by comparing the proposed resource allocation mechanism with two static heuristics (round robin and class-based weighted fair queuing) in a 80-core cluster under multiple traffic patterns resembling sudden changes in the incoming workloads of low-priory streaming applications. The experimental results confirm the stability of the proposed controller to regulate the underlying platform resources to smoothly follow the target values (QoS violation rates). Particularly, the proposed solution can achieve higher efficiency compared to the other heuristics by reducing the response-time of high priority applications by 53% while maintaining the enforced QoS levels during the burst traffic periods. M. Reza HoseinyFarahabady, Javid Taheri, Albert Y. Zomaya, Zahir Tari |
NCA | 4 |
| 2020 | Graceful Performance Degradation in Apache Storm
M. Reza HoseinyFarahabady, Javid Taheri, Albert Y. Zomaya, Zahir Tari |
PDCAT | 4 |
| 2020 | Sub-curve HMM: A malware detection approach based on partial analysis of API call sequences
Jakapan Suaboot, Zahir Tari, Abdun Naser Mahmood, Albert Y. Zomaya, Wei Li 0058 |
Comput. Secur. | 2 |
| 2020 | A Spatiotemporal Data Summarization Approach for Real-Time Operation of Smart GridabstractIn a smart grid distribution management system, operation, planning, forecasting and decision making relies on demand-side management functions, which require real-time smart grid data. This data has significant dollar value because it is extremely useful for efficient control and intelligent prediction of the energy consumption, and expert management of residential and commercial load. However, the huge amount of (smart grid) data generated at a very high velocity poses a number of challenges. Utility companies have a huge demand for efficient summarization techniques to mine interesting patterns and extracting useful and actionable intelligence. Research from various domains has shown that data summarization can significantly improve the scalability and efficiency of various data analytic tasks (e.g., transactional database mining, data streams mining, network monitoring). This paper proposes a summarization approach (i.e., a set of algorithms, data structures, and query mechanisms) that enables the utility company to accurately infer various energy consumption patterns in real-time by automatic monitoring of smart grid data using significantly less computational resources. The proposed summarization approach is suitable for processing spatiotemporal streams, and it can also provide answers in real-time to various smart grid applications (e.g., demand-side management, direct load control, smart pricing and Volt-VAr control). Both theoretical bound and experimental evaluation are presented in this paper, which shows that the memory required for the proposed data structure grows linearly for the first 52 weeks; but interestingly, after the first year, the memory growth is negligible. The experimental results show that the proposed approach can process around 4 million smart meter readings every second or 120 million readings every minute. The proposed approach outperforms widely commercially used Database Management Systems (DBMSs) in terms of update and query costs: it is about 200 times faster than DBMSs in terms of update time, and about 340 times faster than DBMSs in terms of query time. Zubair Shah, Adnan Anwar, Abdun Naser Mahmood, Zahir Tari, Albert Y. Zomaya |
IEEE Trans. Big Data | 4 |
| 2020 | Correlated Differential Privacy: Feature Selection in Machine LearningabstractPrivacy preserving in machine learning is a crucial issue in industry informatics since data used for training in industries usually contain sensitive information. Existing differentially private machine learning algorithms have not considered the impact of data correlation, which may lead to more privacy leakage than expected in industrial applications. For example, data collected for traffic monitoring may contain some correlated records due to temporal correlation or user correlation. To fill this gap, in this article, we propose a correlation reduction scheme with differentially private feature selection considering the issue of privacy loss when data have correlation in machine learning tasks. The proposed scheme involves five steps with the goal of managing the extent of data correlation, preserving the privacy, and supporting accuracy in the prediction results. In this way, the impact of data correlation is relieved with the proposed feature selection scheme, and moreover the privacy issue of data correlation in learning is guaranteed. The proposed method can be widely used in machine learning algorithms, which provide services in industrial areas. Experiments show that the proposed scheme can produce better prediction results with machine learning tasks and fewer mean square errors for data queries compared to existing schemes. Tao Zhang 0055, Tianqing Zhu, Ping Xiong 0001, Huan Huo, Zahir Tari, Wanlei Zhou 0001 |
IEEE Trans. Ind. Informatics | 5 |
| 2020 | Fully Homomorphic based Privacy-Preserving Distributed Expectation Maximization on CloudabstractExpectation maximization (EM) is a clustering-based machine learning algorithm that is widely used in many areas of science (e.g., bioinformatics and computer vision) to find maximum likelihood and maximum a posteriori estimates for models with latent variables. To deploy such an algorithm in cloud environments, security and privacy issues need be considered to avoid data breaches or abuses by external malicious parties or even by cloud service providers. However, the processing performance of the EM algorithm poses a challenge in terms of building a secure environment. This article describes an innovative and practical privacy-preserving EM algorithm for cloud systems that addresses this challenge, and estimates the EM parameters in an accurate and secure manner. Fully homomorphic encryption (FHE) is used to ensure the privacy of both the EM algorithm computations and the users' sensitive data in the cloud. A distributed-based approach is also proposed to overcome the overheads of FHE computations and ensure a fast convergence of the EM algorithm. The conducted experiments demonstrate a significant improvement in the convergence time of the distributed EM algorithm, while achieving a high level of accuracy and reducing the associated computational FHE overheads. Abdulatif Alabdulatif, Ibrahim Khalil 0001, Albert Y. Zomaya, Zahir Tari, Xun Yi |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2019 | Online VM Consolidation in Cloud EnvironmentsabstractDynamic virtual machine (VM) consolidation is considered an effective approach for improving power consumption and computing resource utilization in cloud-based data centers. However, the ever-changing workload in a data center makes it difficult for VM consolidation to prevent service level agreement (SLA) violations and optimize power consumption. The detection of overutilized and underutilized physical machines (PMs) plays a significant role in effective VM consolidation, immediately improving resource utilization, SLA violations, and power consumption. This paper proposes the dynamic threshold-based fuzzy approach (DTFA) for detecting overloaded and underutilized PMs, and the Lowest Interdependence Factor Exponent Multiple Resources Predictive (LIFE-MP) approach for VM placement, by considering multiple computing resources being used simultaneously in a cloud environment. The DTFA is a fuzzy threshold-based approach used to adjust the threshold values of PMs in a cloud environment. The LIFE-MP approach selects a PM at which to place the migrating VM, based on the PM with the lowest correlation coefficient value among the already-running VMs and the migrating VM to reduce performance degradation because of the VM migration. The comparison between LIFE-MP scheme and a power-aware best-fit decreasing (PABFD) scheme shows that the proposed scheme reduces power consumption by 22.52, SLA violations by 45.63, and the number of VM migrations by 56.68. Deafallah Alsadie, Zahir Tari, Eidah J. Alzahrani |
CLOUD | 2 |
| 2019 | A Network-aware and Partition-based Resource Management Scheme for Data Stream ProcessingabstractWith the increasing demand for data-driven decision making, there is an urgent need for processing geographically distributed data streams in real-time. The existing scheduling and resource management schemes efficiently optimize stream processing performance with the awareness of resource, quality-of-service, and network traffic. However, the correlation between network delay and inter-operator communication pattern is not well-understood. In this study, we propose a network-aware and partition-based resource management scheme to deal with the ever-changing network condition and data communication in stream processing. The proposed approach applies operator fusion by considering the computational demand of individual operators and the inter-operator communication patterns. It maps the fused operators to the clustered hosts with the weighted shortest processing time heuristic. Meanwhile, we established a 3-dimensional coordinate system for prompt reflection of the network condition, real-time traffic, and resource availability. We evaluated the proposed approach against two benchmarks, and the results demonstrate the efficiency in throughput and resource utilization. We also conducted a case study and implemented a prototype system supported by the proposed approach that aims to utilize the stream processing paradigm for pedestrian behavior analysis. The prototype application estimates walking time for a given path according to the real crowd traffic. The promising evaluation results of processing performance further illustrate the efficiency of the proposed approach. Zahir Tari, Xiaoran Huang, Albert Y. Zomaya |
ICPP | 2 |
| 2019 | Brush like a Dentist: Accurate Monitoring of Toothbrushing via Wrist-Worn Gesture SensingabstractOral health has significant impact on people’s over-all well-being. While many activity recognition systems exist in the literature, accurately sensing toothbrushing activities remains an unsolved challenging problem due to the diversity of tooth-brushing habits among different users and subtle distinctions between different brushing actions. In this work, we propose Hygiea, an energy-efficient and highly-accurate toothbrushing monitoring system which exploits IMU-based wrist-worn gesture sensing using unmodified toothbrushes. To address toothbrushing variety, Hygiea incorporates a number of novel signal preprocessing techniques to automatically transform the sensory input during arbitrary toothbrushing activities to the consistent user coordinate system. To distinguish different brushing actions, Hygiea leverages an emerging deep learning model (e.g., AT-LSTM) to achieve fine-grained activity recognitions. Moreover, a POMDP model is incorporated for sampling control to balance activity detection and energy efficiency. Extensive real-world experiments show that the Hygiea system achieves a 11.7% accuracy gain compared to the state-of-the-art while maintaining energy-efficiency and zero modification on the toothbrushes. Chengwen Luo 0001, Xingyu Feng 0001, Junliang Chen 0002, Jianqiang Li 0001, Weitao Xu, Wei Li 0058, Zahir Tari, Albert Y. Zomaya |
INFOCOM | 8 |
| 2019 | Dynamic Control of CPU Cap Allocations in Stream Processing and Data-Flow PlatformsabstractThis paper focuses on Timely dataflow programming model for processing streams of data. We propose a technique to define CPU resource allocation (i.e., CPU capping) with the goal to improve response time latency in such type of applications with different quality of service (QoS) level, as they are concurrently running in a shared multi-core computing system with unknown and volatile demand. The proposed solution predicts the expected performance of the underlying platform using an online approach based on queuing theory and adjusts the corrections required in CPU allocation to achieve the most optimized performance. The experimental results confirms that measured performance of the proposed model is highly accurate while it takes into account the percentiles on the QoS metrics. The theoretical model used for elastic allocation of CPU share in the target platform takes advantage of design principals in model predictive control theory and dynamic programming to solve an optimization problem. While the prediction module in the proposed algorithm tries to predict the temporal changes in the arrival rate of each data flow, the optimization module uses a system model to estimate the interference among collocated applications by continuously monitoring the available CPU utilization in individual nodes along with the number of outstanding messages in every intermediate buffer of all TDF applications. The optimization module eventually performs a cost-benefit analysis to mitigate the total amount of QoS violation incidents by assigning the limited CPU shares among collocated applications. The proposed algorithm is robust (i.e., its worst-case output is guaranteed for arbitrarily volatile incoming demand coming from different data streams), and if the demand volatility is not large, the output is optimal, too. Its implementation is done using the TDF framework in Rust for distributed and shared memory architectures. The experimental results show that the proposed algorithm reduces the average and p99 latency of delay-sensitive applications by 21% and 31.8%, respectively, while can reduce the amount of QoS violation incidents by 98% on average. M. Reza HoseinyFarahabady, Ali Jannesari, Zahir Tari, Javid Taheri, Albert Y. Zomaya |
NCA | 3 |
| 2019 | Real-Time Stream Data Processing at ScaleabstractA typical scenario in a stream data-flow processing engine is that users submit continues queries in order to receive the computational result once a new stream of data arrives. The focus of the paper is to design a dynamic CPU cap controller for stream data-flow applications with real-time constraints, in which the result of computations must be available within a short time period, specified by the user, once a recent update in the input data occurs. It is common that the stream data-flow processing engine is deployed over a cluster of dedicated or virtualized server nodes, e.g., Cloud or Edge platform, to achieve a faster data processing. However, the attributes of incoming stream data-flow might fluctuate in an irregular way. To effectively cope with such unpredictable conditions, the underlying resource manager needs to be equipped with a dynamic resource provisioning mechanism to ensure the real-time requirements of different applications. The proposed solution uses control theory principals to achieve a good utilization of computing resources and a reduced average response time. The proposed algorithm dynamically adjusts the required quality of service (QoS) in an environment when multiple stream & data-flow processing applications concurrently run with unknown and volatile workloads. Our study confirms that such a unpredictable demand can negatively degrade the system performance, mainly due to adverse interference in the utilization of shared resources. Unlike prior research studies which assumes a static or zero correlation among the performance variability among consolidated applications, we presume the prevalence of shared-resource interference among collocated applications as a key performance-limiting parameter and confront it in scenarios where several applications have different QoS requirements with unpredictable workload demands. We design a low-overhead controller to achieve two natural optimization objectives of minimizing QoS violation amount and maximizing the average CPU utilization. The algorithm takes advantage of design principals in model predictive control theory for elastic allocation of CPU share. The experimental results confirm that there is a strong correlation in performance degradation among consolidation strategies and the system utilization for obtaining the capacity of shared resources in a non-cooperative manner. The results confirm that the proposed solution can reduce the average latency of delay-sensitive applications by 17% comparing to the results of a well established heuristic called Class-Based Weighted Fair Queuing (CFWFQ). At the same time, the proposed solution can prevent the QoS violation incidents by 62%. M. Reza HoseinyFarahabady, Ali Jannesari, Wei Bao 0001, Zahir Tari, Albert Y. Zomaya |
PDCAT | 4 |
| 2019 | Disk Throughput Controller for Cloud Data-CentersabstractWith the increasing popularity of virtual machine monitoring (VMM) technologies, performance variability among collocated virtual machines (VMs) can easily become a severe scalability issue. Particularly, it becomes a necessary for administrative team to control the performance degradation level in a shared environment when multiple I/O-intensive applications simultaneously request their I/O operations [1]. Nevertheless, adding several logical layers between the running applications and the physical storage system, as seen in contemporary virtualized storage devices, makes it considerably difficult to build a low overhead controlling mechanism for such systems (while each VM may running a separate operating system instance) [2]. In this paper, we propose a strategy based on control theory for managing the performance of several I/O requests, such as mean response times and read/write throughput in a consolidated environment where multiple virtual services can share access to a storage system. This scheme uses an approach for measuring the characterization of read/write performance attributes of each virtual services and also takes into account the run-time quality of service enforcement levels requested by them. This is formulated as an optimization problem where a reward function is defined to reduce the overall QoS violation incidents among all consolidated virtual services. Performance evaluation is carried out by comparing the proposed solution with the default embedded Linux controller across a range of emulated application workloads in scenarios with multiple consolidated virtual containers. The results confirm that the proposed solution can reduce the overall QoS violation incident rates in scenarios in which the platform operates at a significant traffic load comparing to the default policy in LXC engine. M. Reza HoseinyFarahabady, Zahir Tari, Albert Y. Zomaya |
PDCAT | 2 |
| 2019 | Efficient threshold password-authenticated secret sharing protocols for cloud computing
Xun Yi, Zahir Tari, Feng Hao 0001, Liqun Chen 0002, Joseph K. Liu, Xuechao Yang, Kwok-Yan Lam, Ibrahim Khalil 0001, Albert Y. Zomaya |
J. Parallel Distributed Comput. | 2 |
| 2019 | SemTra: A semi-supervised approach to traffic flow labeling with minimal human effort
Adil Fahad, Abdulmohsen Almalawi, Zahir Tari, Kurayman Alharthi, Fawaz S. Al-Qahtani, Mohamed Cheriet |
Pattern Recognit. | 3 |
| 2018 | DTFA: A Dynamic Threshold-Based Fuzzy Approach for Power-Efficient VM ConsolidationabstractDynamic virtual machine (VM) consolidation is considered an effective approach for improving power consumption and computing resource utilization in cloud-based data centers. However, the ever-changing workload in a data center makes it difficult for VM consolidation to prevent service level agreement (SLA) violations and optimize power consumption. Detection of overutilized and underutilized physical machines (PMs) plays a significant role in effective VM consolidation, immediately improving resource utilization, SLA violations, and power consumption. This paper presents a new proposal for the dynamic adjustment of threshold values that aims to minimize the number of migrations in varying workload environments. The proposed approach, named the `dynamic threshold-based fuzzy approach' (DTFA), is a fuzzy threshold-based approach used for adjusting the threshold values of PMs in a cloud environment. The proposed approach allows the number of migrations caused by overloading to be reduced and SLAs to be met. Three sets of experiments with different workloads were conducted to validate the proposed approach. The results demonstrate that DTFA outperforms existing solutions by an average of 22.52%, 45.63% and 56.68% in power consumption, VM migration count, and SLA violations, respectively. Deafallah Alsadie, Eidah J. Alzahrani, Nasrin Sohrabi, Zahir Tari, Albert Y. Zomaya |
NCA | 4 |
| 2018 | UFSSF - An Efficient Unsupervised Feature Selection for Streaming Features
Naif Almusallam, Zahir Tari, Jeffrey Chan, Adil AlHarthi |
PAKDD (2) | 2 |
| 2018 | MicroGRID: An Accurate and Efficient Real-Time Stream Data Clustering with Noise
Zahir Tari, A. Thompson, N. Almusalam, Peter Bertók, A. Mahmood |
PAKDD (2) | 1 |
| 2018 | LIFE-MP: Online Virtual Machine Consolidation with Multiple Resource Usages in Cloud Environments
Deafallah Alsadie, Zahir Tari, Eidah J. Alzahrani, Ahmed Alshammari |
WISE (2) | 2 |
| 2018 | Context-Aware Multifaceted Trust Framework For Evaluating Trustworthiness of Cloud Providers
Mohannad Alhanahnah, Peter Bertók, Zahir Tari, Sahel Alouneh |
Future Gener. Comput. Syst. | 3 |
| 2018 | A Model Predictive Controller for Managing QoS Enforcements and Microarchitecture-Level Interferences in a Lambda PlatformabstractLambda paradigm, also known as Function as a Service (FaaS), is a novel event-driven concept that allows companies to build scalable and reliable enterprise applications in an off-premise computing data-center as a serverless solution. In practice, however, an important goal for the service provider of a Lambda platform is to devise an efficient way to consolidate multiple Lambda functions in a single host. While the majority of existing resource management solutions use only operating-system level metrics (e.g., average utilization of computing and I/O resources) to allocate the available resources among the submitted workloads in a balanced way, a resource allocation schema that is oblivious to the issue of shared-resource contention can result in a significant performance variability and degradation within the entire platform. This paper proposes a predictive controller scheme that dynamically allocates resources in a Lambda platform. This scheme uses a prediction tool to estimate the future rate of every event stream and takes into account the quality of service enforcements requested by the owner of each Lambda function. This is formulated as an optimization problem where a set of cost functions are introduced (i) to reduce the total QoS violation incidents; (ii) to keep the CPU utilization level within an accepted range; and (iii) to avoid the fierce contention among collocated applications for obtaining shared resources. Performance evaluation is carried out by comparing the proposed solution with an enhanced interference-aware version of three well-known heuristics, namely spread, binpack (the two native clustering solutions employed by Docker Swarm) and best-effort resource allocation schema. Experimental results show that the proposed controller improves the overall performance (in terms of reducing the end-to-end response time) by 14.9 percent on average compared to the best result of the other heuristics. The proposed solution also increases the overall CPU utilization by 18 percent on average (for lightweight workloads), while achieves an average 87 percent (maximum 146 percent) improvement in preventing QoS violation incidents. M. Reza HoseinyFarahabady, Albert Y. Zomaya, Zahir Tari |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2018 | Computing Hierarchical Summary from Two-Dimensional Big Data StreamsabstractThere are many application domains, where hierarchical data is inherent, but surprisingly, there are few techniques for mining patterns from such important data. Hierarchical Heavy Hitters (HHH) and multilevel and Cross-Level Association Rules (CLAR) mining are well-known hierarchical pattern mining techniques. The problem in these techniques; however, is that they focus on capturing only global patterns from data but cannot identify local contextual patterns. Another problem in these techniques is that they treat all data items in the transaction equally and do not consider the sequential nature of the relationship among items within a transaction; hence, they cannot capture the correlation semantic within the transactions of the data items. There are many applications such as clickstream mining, healthcare data mining, network monitoring, and recommender systems, which require to identify local contextual patterns and correlation semantics. In this work, we introduce a new concept, which can capture the sequential nature of the relationship between pairs of hierarchical items at multiple concept levels and can capture local contextual patterns within the context of the global patterns. We call this notion Hierarchically Correlated Heavy Hitters (HCHH). Specifically, the proposed approach finds the correlation between items corresponding to hierarchically discounted frequency counts. We have provided formal definitions of the proposed concept and developed algorithmic approaches for computing HCHH in data streams efficiently. The proposed HCHH algorithm have deterministic error guarantees, and space bounds. It requires O(η/ϵpϵs) memory, where h is a small constant, and ϵp∈ [0,1], ϵs∈ [0,1] are user defined parameters on upper bounds of estimation error. We have compared the proposed HCHH concept with existing hierarchical pattern mining approaches both theoretically as well as experimentally. Zubair Shah, Abdun Naser Mahmood, Michael Barlow 0001, Zahir Tari, Xun Yi, Albert Y. Zomaya |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2017 | QoS- and Contention- Aware Resource Provisioning in a Stream Processing EngineabstractThis paper addresses the shared resource contention problem associated with the auto-parallelization of running queries in distributed stream processing engines. In such platforms, analyzing a large amount of data often requires to execute user-defined queries over continues raw-inputs in a parallel fashion at each single host. However, previous studies showed that the collocated applications can fiercely compete for shared resources, resulting in a severe performance degradation among applications. This paper presents an advanced resource allocation strategy for handling scenarios in which the target applications have different quality of service (QoS) requirements while shared-resource interference is considered as a key performance-limiting parameter. To properly allocate the best possible resource to each query, the proposed controller predicts the performance degradation of the running pane-level as well as the window-level queries when co-running with other queries. This is addressed as an optimization problem where a set of cost functions is defined to achieve the following goals: a) reduce the sum of QoS violation incidents over all machines; b) keep the CPU utilization level within an accepted range; and c) avoid fierce shared resource interference among collocated applications. Particle swarm optimization is used to find an acceptable solution at each round of the controlling period. The performance of the proposed solution is benchmarked with Round-Robin and best-effort strategies, and the experimental results clearly demonstrate that the proposed controller has the following advantages over its opponents: it increases the overall resource utilization by 15% on average while can reduce the average tuple latencies by 14%. It also achieves an average 123% improvement in preventing QoS violation incidents. M. Reza HoseinyFarahabady, Albert Y. Zomaya, Zahir Tari |
CLUSTER | 3 |
| 2017 | A Dynamic Resource Controller for a Lambda ArchitectureabstractLambda architecture is a novel event-driven serverless paradigm that allows companies to build scalable and reliable enterprise applications. As an attractive alternative to traditional service oriented architecture (SOA), Lambda architecture can be used in many use cases including BI tools, in-memory graph databases, OLAP, and streaming data processing. In practice, an important aim of Lambda's service providers is devising an efficient way to co-locate multiple Lambda functions with different attributes into a set of available computing resources. However, previous studies showed that consolidated workloads can compete fiercely for shared resources, resulting in severe performance variability/degradation. This paper proposes a resource allocation mechanism for a Lambda platform based on the model predictive control framework. Performance evaluation is carried out by comparing the proposed solution with multiple resource allocation heuristics, namely enhanced versions of spread and binpack, and best-effort approaches. Results confirm that the proposed controller increases the overall resource utilization by 37% on average and achieves a significant improvement in preventing QoS violation incidents compared to others. M. Reza HoseinyFarahabady, Javid Taheri, Zahir Tari, Albert Y. Zomaya |
ICPP | 3 |
| 2017 | A QoS-Aware Resource Allocation Controller for Function as a Service (FaaS) Platform
M. Reza HoseinyFarahabady, Young Choon Lee, Albert Y. Zomaya, Zahir Tari |
ICSOC | 4 |
| 2017 | State estimation for a TCP/IP network using terminal sliding-mode methodologyabstractRecently, the state estimation issue of a TCP/IP network has attracted much attention from different communities. In this paper, a terminal sliding-mode observer (TSMO) is proposed based on a fluid-flow model of a TCP/IP network to estimate traffic flow states. A novel control strategy is proposed to fasten the convergence of the estimation error for average congestion window (ACwnd). Furthermore, a continuous control strategy is directly used to estimates the flooding rate of additional traffic flow (ATF). The efficacy of the proposed TSMO is verified by a numerical simulation implementations via the networking simulator NS-2. Long Xu 0003, Xinghuo Yu 0001, Yong Feng 0001, Fengling Han, Jiankun Hu, Zahir Tari |
IECON | 6 |
| 2017 | LIFE: A predictive approach for VM placement in cloud environmentsabstractThe key to maintaining high standards of quality and power conservation of physical machines in data centers lies in efficient consolidation of virtual machines (VMs). Several schemes have been proposed for this purpose; and these include online migration and VM placement - which can offer the best in terms of resource utilization. The consolidation process can be made effective by finding “opportunities” to migrate VMs as well approximating the resource utilization for the VM placement. An inefficient placement scheme, however, will lead to a substantial overloading of physical machines. This proposed VM placement scheme uses correlation coefficient and predicted future requirements of computing resources to accurately compute the value/s of variable, and has been termed LIFE - Lowest Interdependence Factor Exponent. This variable shows the extent to which a VM can be associated with a target physical machine. Higher value of LIFE will correspondingly result in a larger impact factor influencing the performance of existing VMs whenever a VM is selected for migration to a target machine. To minimize performance degradation, migration of a VM to a target machine will only take place if it is found to correspond with a value of LIFE that is found to be the lowest. Intensive experiments show that the proposed scheme offers better performance attributes over Minimum Correlation Coefficient (MCC) and Power Aware Best Fit Decreasing (PABFD) schemes measured in terms of the following metrics: power consumption by 44.08% and 27.52%, SLA violation by 50.90% and 19.53% and number of VM migration by 52.91% and 9.66% respectively. Deafallah Alsadie, Zahir Tari, Eidah J. Alzahrani, Albert Y. Zomaya |
NCA | 2 |
| 2017 | Energy-efficient tailoring of VM size and tasks in cloud data centersabstractNowadays, cloud computing has emerged as the most popular computing platform due to its ability to reduce the operating costs. A sizable chunk of the operating costs is composed of power consumption of the cloud data center alone. It has been observed that improperly sized virtual machines result in comparatively higher power consumption. Although efforts have been made to address the issue of high power consumption, still efficient resource allocation in a cloud environment continues to pose a significant challenge. The proposed design is based on the concept of clustering tasks based on computing resource requirements, and then distributing the tasks among appropriately sized virtual machines on the basis of computing resources. The current paper evaluates the proposed model against representational techniques in the field. A benchmark dataset from Google cloud trace is used for the evaluation. Empirical results analysis has shown that the proposed model offers significant advantages over the existing schemes in so far as load balancing of active physical servers is concerned in terms of defined performance metrics. Deafallah Alsadie, Zahir Tari, Eidah J. Alzahrani, Albert Y. Zomaya |
NCA | 2 |
| 2017 | adCFS: Adaptive completely fair scheduling policy for containerised workflows systemsabstractScientific workflows are increasingly containerised, which requires rethinking central processing unit (CPU) sharing policies to accommodate different workload types. However, container engines running scientific workflows struggle to share the CPU fairly, as workload characteristics are not taken into account. This paper proposes a sharing policy called the Adaptive Completely Fair Scheduling policy (adCFS), which considers the future state of CPU usage and proactively shares CPU cycles between various containers based on their corresponding workload metrics (e.g., CPU usage, task runtime, #tasks). adCFS estimates the weight of workload characteristics and redistributes the CPU based on the corresponding weights. The Markov chain model is used to predict CPU state use, and the adCFS policy is triggered to dynamically allocate containers to the proper CPU portions. Experimental results show enhanced container CPU response time for those containers that run heavy and large jobs: these display 12% faster response time compared with the default CFS (Completely Fair Scheduler). adCFS therefore enhances CFS by considering workload metrics, which leads to the CPU being shared fairly when it is fully used. Eidah J. Alzahrani, Zahir Tari, Young Choon Lee, Deafallah Alsadie, Albert Y. Zomaya |
NCA | 2 |
| 2017 | QoS-aware resource allocation for stream processing engines using priority channelsabstractThis paper addresses the challenging problem of guaranteeing quality-of-service (QoS) requirements associated with parallel running queries in distributed stream processing engines. In such platforms, the real-time processing of streaming data often requires executing a set of user-defined queries over continues data flows. However, previous studies showed that guaranteeing QoS enforcement (such as end-to-end response time) for a collection of applications is a complex problem. This paper presents an advanced resource allocation strategy to tackle such a problem by considering the traffic pattern of individual data streams. To properly allocate resource for streaming queries execution, we define a certain number of priority channels to categorize the streaming data across the system. The resource allocation is addressed as an optimization problem where a set of cost functions is defined to achieve the following goals: a) reduce the sum of QoS violation incidents across all applications; b) increase the CPU utilization level, and (c) avoid the additional costs caused by frequent reconfigurations. The proposed solution does not depend on any assumption about the incoming data rate or the query processing time. The performance of the proposed solution is benchmarked, and the experimental results reveal that the proposed scheme increases the overall resource utilization by 23% on average and reduces the QoS violations by 29% against round-robin strategy. It could also prevent QoS violation incidents at different levels by tuning the cost function. Zahir Tari, M. Reza HoseinyFarahabady, Albert Y. Zomaya |
NCA | 2 |
| 2017 | Achieving energy efficiency in data centers with a performance-guaranteed power aware routing
Emna Baccour, Sebti Foufou, Ridha Hamila, Zahir Tari |
Comput. Commun. | 4 |
| 2017 | LaCoDa: Layered connected topology for massive data centers
Zina Chkirbene, Sebti Foufou, Ridha Hamila, Zahir Tari, Albert Y. Zomaya |
J. Netw. Comput. Appl. | 4 |
| 2017 | PTNet: An efficient and green data center network
Emna Baccour, Sebti Foufou, Ridha Hamila, Zahir Tari, Albert Y. Zomaya |
J. Parallel Distributed Comput. | 4 |
| 2017 | KRNN: k Rare-class Nearest Neighbour classification
Xiuzhen Zhang 0001, Yuxuan Li 0001, Kotagiri Ramamohanarao, Lifang Wu, Zahir Tari, Mohamed Cheriet |
Pattern Recognit. | 5 |
| 2017 | BDCaM: Big Data for Context-Aware Monitoring - A Personalized Knowledge Discovery Framework for Assisted HealthcareabstractContext-aware monitoring is an emerging technology that provides real-time personalised health-care services and a rich area of big data application. In this paper, we propose a knowledge discovery-based approach that allows the context-aware system to adapt its behaviour in runtime by analysing large amounts of data generated in ambient assisted living (AAL) systems and stored in cloud repositories. The proposed BDCaM model facilitates analysis of big data inside a cloud environment. It first mines the trends and patterns in the data of an individual patient with associated probabilities and utilizes that knowledge to learn proper abnormal conditions. The outcomes of this learning method are then applied in context-aware decision-making processes for the patient. A use case is implemented to illustrate the applicability of the framework that discovers the knowledge of classification to identify the true abnormal conditions of patients having variations in blood pressure (BP) and heart rate (HR). The evaluation shows a much better estimate of detecting proper anomalous situations for different types of patients. The accuracy and efficiency obtained for the implemented case study demonstrate the effectiveness of the proposed model. Abdur Forkan, Ibrahim Khalil 0001, Ayman Ibaida, Zahir Tari |
IEEE Trans. Cloud Comput. | 4 |
| 2017 | Cloud-Based Utility Service Framework for Trust Negotiations Using Federated Identity ManagementabstractUtility based cloud services can efficiently provide various supportive services to different service providers. Trust negotiations with federated identity management are vital for preserving privacy in open systems such as distributed collaborative systems. However, due to the large amounts of server based communications involved in trust negotiations scalability issues prove to be less cumbersome when offloaded on to the cloud as a utility service. In this view, we propose trust based federated identity management as a cloud based utility service. The main component of this model is the trust establishment between the cloud service provider and the identity providers. We propose novel trust metrics based on the potential vulnerability to be attacked, the available security enforcements and a novel cost metric based on policy dependencies to rank the cooperativeness of identity providers. Practical use of these trust metrics is demonstrated by analyses using simulated data sets, attack history data: published by MIT Lincoln laboratory, real-life attacks and vulnerabilities extracted from Common Vulnerabilities and Exposures (CVE) repository and fuzzy rule based evaluations. The results of the evaluations imply the significance of the proposed trust model to support cloud based utility services to ensure reliable trust negotiations using federated identity management. Uthpala Subodhani Premarathne, Ibrahim Khalil 0001, Zahir Tari, Albert Y. Zomaya |
IEEE Trans. Cloud Comput. | 3 |
| 2017 | Ensuring Data Integrity of OPF Module and Energy Database by Detecting Changes in Power Flow Patterns in Smart GridsabstractRecent studies show that smart grid is vulnerable to cyber anomalies. In this paper, an anomaly detection method is proposed to identify the abnormal patterns in the network power flows, which results from the accidental or deliberate changes of the database. The proposed method utilizes a multivariate time series statistical forecasting technique based on vector autoregressive model. To understand the power flow behavior of the system, a multiphase optimal power flow analysis is conducted. The proposed method is validated using IEEE Power Distribution System Analysis Subcommittee recommended 34-node and 123-node test systems. Three different experiments are performed to test the effectiveness of the proposed approach. Vulnerability and computational complexity issues of this paper are also addressed elaborately. Results obtained from this analysis show that the proposed method successfully captures the network anomalies at a high detection rate allowing only a few number of false alarms. Adnan Anwar, Abdun Naser Mahmood, Zahir Tari |
IEEE Trans. Ind. Informatics | 3 |
| 2017 | A Technique for Efficient Query Estimation over Distributed Data StreamsabstractDistributed data stream mining in a sliding window has emerged recently, due to its applications in many domains including large Telecoms and Internet Service Providers, financial tickers, ATM and credit card operations in banks and transactions in retail chains. Many of these large-scale applications prohibit monitoring data centrally at a single location due to their massive volume of the data; therefore, data acquisition, processing, and mining tasks are often distributed to a number of processing nodes, which monitor their local streams and exchange only the summary of data either periodically or on demand. While this offer many advantages, distributed stream applications possess significant challenges including problems related to an online analysis of the recent data, communication efficiency and various estimation of various complex queries. There are few existing techniques which solve problems related to distributed sliding window data stream; however, those techniques are focused on solving only simple problems and require high space, query, and communication cost, which can be a bottleneck for many of these large scale applications. In this paper, we propose an efficient query estimation technique by constructing a small sketch of the data stream. The constructed sketch uses a deterministic sliding window model and can estimate various complex queries, for both centralized and distributed applications; including point queries (i.e., range queries and heavy hitter queries), quantiles, inner product, and self-join size queries, with deterministic guarantees on the precision. The proposed approach improves upon recent existing work for these problems, in terms of the memory and query cost in a centralized setting and in terms of communication cost and merge complexity in a distributed setting. It requires O(1/ε21 log (εN)) memory (where 0 <; ε <; 1 is a user defined parameter), can provide estimates in O(1) time, and processes each incoming record in O(1) amortized time. Detailed experimental analysis, both in centralized and distributed settings demonstrates that in practice the proposed approach uses about six times less memory, and has about eight times less query time when compared to ECM sketches. In a distributed application, the proposed technique also significantly improves (around seven times) on the communication cost between distributed sites. Zubair Shah, Abdun Naser Mahmood, Zahir Tari, Albert Y. Zomaya |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2016 | kNNVWC: An efficient k-nearest neighbours approach based on Various-Widths ClusteringabstractIn this paper, a novel k-NN approach based on Various-Widths Clustering, named kNNVWC, is proposed to efficiently find k-NNs for a query object from a given data set. kNNVWC does clustering using various widths, where a data set is clustered with a global width first and each produced cluster that meets the predefined criteria is recursively clustered with its own local width that suits its distribution. Experimental results demonstrate that kNNVWC performs well compared to state-ofart of k-NN search algorithms. Abdulmohsen Almalawi, Adil Fahad, Zahir Tari, Muhammad Aamir Cheema, Ibrahim Khalil 0001 |
ICDE | 3 |
| 2016 | A Model Predictive Controller for Contention-Aware Resource Allocation in Virtualized Data CentersabstractData center efficiency is primarily sought by sharing physical resources, such as processors, memory, and disks in the form of virtual machines or containers among multiple users, i.e., workload consolidation. However, the reality is co-located applications in these virtual platforms compete for resources and interfere with each others' performance, resulting in performance variability/degradation. In this paper, we present the contentionaware resource allocation (CARA) solution, which optimizes data center efficiency. It is essentially devised based on a model predictive control that enables to make judicious consolidation decisions with future system states. CARA consolidates workloads explicitly taking into account the correlation between shared and isolated resource usage patterns. Based on our experimental results, CARA improves the overall resource utilization by 32%, without a significant impact on the quality-of-service (QoS) enforcement level. Such improvement results in a fewer number of active servers and in turn contributes to an overall energy saving by 33%. M. Reza HoseinyFarahabady, Young Choon Lee, Albert Y. Zomaya, Zahir Tari, Andy Song |
MASCOTS | 4 |
| 2016 | Securing Body Sensor Network with ECG
Xuechao Yang, Xun Yi, Ibrahim Khalil 0001, Fengling Han, Zahir Tari |
MoMM | 5 |
| 2016 | A QoS-aware controller for Apache StormabstractApache Storm has recently emerged as an attractive fault-tolerant open-source distributed data processing platform that has been chosen by many industry leaders to develop real-time applications for processing a huge amount of data in a scalable manner. A key aspect to achieve the best performance in this system lies on the design of an efficient scheduler for component execution, called topology, on the available computing resources. In response to workload fluctuations, we propose an advanced scheduler for Apache Storm that provides improved performance with highly dynamic behavior. While enforcing the required Quality-of-Service (QoS) of individual data streams, the controller allocates computing resources based on decisions that consider the future states of non-controllable disturbance parameters, e.g. arriving rate of tuples or resource utilization in each worker node. The performance evaluation is carried out by comparing the proposed solution with two well-known alternatives, namely the Storm's default scheduler and the best-effort approach (i.e. the heuristic that is based on the first-fit decreasing approximation algorithm). Experimental results clearly show that the proposed controller increases the overall resource utilization by 31% on average compared to the two others solutions, without significant negative impact on the QoS enforcement level. M. Reza HoseinyFarahabady, Hamid R. Dehghani Samani, Albert Y. Zomaya, Zahir Tari |
NCA | 5 |
| 2016 | ID2S Password-Authenticated Key Exchange ProtocolsabstractIn a two-server password-authenticated key exchange (PAKE) protocol, a client splits its password and stores two shares of its password in the two servers, respectively, and the two servers then cooperate to authenticate the client without knowing the password of the client. In case one server is compromised by an adversary, the password of the client is required to remain secure. In this paper, we present two compilers that transform any two-party PAKE protocol to a two-server PAKE protocol on the basis of the identity-based cryptography, called ID2S PAKE protocol. By the compilers, we can construct ID2S PAKE protocols which achieve implicit authentication. As long as the underlying two-party PAKE protocol and identity-based encryption or signature scheme have provable security without random oracles, the ID2S PAKE protocols constructed by the compilers can be proven to be secure without random oracles. Compared with the Katz et al.'s two-server PAKE protocol with provable security without random oracles, our ID2S PAKE protocol can save from 22 to 66 percent of computation in each server. Xun Yi, Fang-Yu Rao, Zahir Tari, Feng Hao 0001, Elisa Bertino, Ibrahim Khalil 0001, Albert Y. Zomaya |
IEEE Trans. Computers | 3 |
| 2016 | An Efficient Data-Driven Clustering Technique to Detect Attacks in SCADA SystemsabstractSupervisory control and data acquisition (SCADA) systems have become a salient part in controlling critical infrastructures, such as power plants, energy grids, and water distribution systems. In the past decades, these systems were isolated and use proprietary software, operating systems, and protocols. In recent years, SCADA systems have been interfaced with enterprise systems, which therefore exposed them to the vulnerabilities of the Internet and the security threats. Traditional security solutions (e.g., firewalls, antivirus software, and intrusion detection systems) cannot fully protect SCADA systems, because they have different requirements. This paper presents an innovative intrusion detection approach to detect SCADA tailored attacks. This is based on a data-driven clustering technique of process parameters, which automatically identifies the normal and critical states of a given system. Later, it extracts proximity-based detection rules from the identified states for monitoring purposes. The effectiveness of the proposed approach is tested by conducting experiments on eight data sets that consist of process parameters' values. The empirical results demonstrated an average accuracy of 98% in automatically identifying the critical states, while facilitating the monitoring of the SCADA system. Abdulmohsen Almalawi, Adil Fahad, Zahir Tari, Abdullah Alamri, Rayed Abdullah A. AlGhamdi, Albert Y. Zomaya |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2016 | kNNVWC: An Efficient k-Nearest Neighbors Approach Based on Various-Widths ClusteringabstractThe k-nearest neighbor approach (k-NN) has been extensively used as a powerful non-parametric technique in many scientific and engineering applications. However, this approach incurs a large computational cost. Hence, this issue has become an active research field. In this work, a novel k-NN approach based on various-widths clustering, named kNNVWC, to efficiently find k-NNs for a query object from a given data set, is presented. kNNVWC does clustering using various widths, where a data set is clustered with a global width first and each produced cluster that meets the predefined criteria is recursively clustered with its own local width that suits its distribution. This reduces the clustering time, in addition to balancing the number of produced clusters and their respective sizes. Maximum efficiency is achieved by using triangle inequality to prune unlikely clusters. Experimental results demonstrate that kNNVWC performs well in finding k-NNs for query objects compared to a number of k-NN search algorithms, especially for a data set with high dimensions, various distributions and large size. Abdulmohsen Almalawi, Adil Fahad, Zahir Tari, Muhammad Aamir Cheema, Ibrahim Khalil 0001 |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2016 | An Efficient Privacy-Preserving Ranked Keyword Search MethodabstractCloud data owners prefer to outsource documents in an encrypted form for the purpose of privacy preserving. Therefore it is essential to develop efficient and reliable ciphertext search techniques. One challenge is that the relationship between documents will be normally concealed in the process of encryption, which will lead to significant search accuracy performance degradation. Also the volume of data in data centers has experienced a dramatic growth. This will make it even more challenging to design ciphertext search schemes that can provide efficient and reliable online information retrieval on large volume of encrypted data. In this paper, a hierarchical clustering method is proposed to support more search semantics and also to meet the demand for fast ciphertext search within a big data environment. The proposed hierarchical approach clusters the documents based on the minimum relevance threshold, and then partitions the resulting clusters into sub-clusters until the constraint on the maximum size of cluster is reached. In the search phase, this approach can reach a linear computational complexity against an exponential size increase of document collection. In order to verify the authenticity of search results, a structure called minimum hash sub-tree is designed in this paper. Experiments have been conducted using the collection set built from the IEEE Xplore. The results show that with a sharp increase of documents in the dataset the search time of the proposed method increases linearly whereas the search time of the traditional method increases exponentially. Furthermore, the proposed method has an advantage over the traditional method in the rank privacy and relevance of retrieved documents. Chi Chen 0001, Xiaojie Zhu, Peisong Shen, Jiankun Hu, Song Guo 0001, Zahir Tari, Albert Y. Zomaya |
IEEE Trans. Parallel Distributed Syst. | 6 |
| 2015 | A Memetic Algorithm for Dynamic Shortest Path Routing on Mobile Ad-hoc NetworksabstractThe shortest path routing (SPR) problem is a well-known challenge in the field of mobile network routing. The aim is to find the least cost path that connect a specific source node with a specific destination node. Although there are numerous algorithms to solve SPR, most of them consider only static environments in which the network topology and link-cost never change. A network with dynamic topologies and cost are indeed more challenging but more practical in real world applications. This paper presents a memetic algorithm for dynamic SPR (DSPR) problems in a mobile network. The proposed approach consists of three stages: genetic algorithm, local search and elitism-based immigrants procedure. Genetic algorithm (GA) is applied in the first stage to explore the search space and generate a new set of solutions. The generated solutions are further improved in the second stage by a local search algorithm. In third stage, an elitism-based immigrants procedure is activated to handle the dynamic changes by maintaining the diversity of the search process. The performance of the proposed algorithm has been evaluated on dynamic shortest path routing problem instances under both cyclic and acyclic environments. The study shows that, on both circumstances, the proposed algorithm is very stable with regards to dynamic network changes. This method is highly competitive compared to state-of-the-art algorithms in the literature as it outperformed these algorithms on all instances of dynamic routing during evaluation. Nasser R. Sabar, Andy Song, Zahir Tari, Xun Yi, Albert Y. Zomaya |
ICPADS | 3 |
| 2015 | Identification of vulnerable node clusters against false data injection attack in an AMI based Smart Grid
Adnan Anwar, Abdun Naser Mahmood, Zahir Tari |
Inf. Syst. | 3 |
| 2015 | A context-aware approach for long-term behavioural change detection and abnormality prediction in ambient assisted living
Abdur Forkan, Ibrahim Khalil 0001, Zahir Tari, Sebti Foufou, Abdelaziz Bouras |
Pattern Recognit. | 3 |
| 2015 | Granular Evaluation of Anomalies in Wireless Sensor Networks Using Dynamic Data Partitioning with an Entropy CriteriaabstractThis paper presents an anomaly detection model that is granular and distributed to accurately and efficiently identify sensed data anomalies within wireless sensor networks. A more decentralised mechanism is introduced with wider use of in-network processing on a hierarchical sensor node topology resulting in a robust framework for dynamic data domains. This efficiently addresses the big data issue that is encountered in large scale industrial sensor network applications. Data vectors on each node's observation domain is first partitioned using an unsupervised approach that is adaptive regarding dynamic data streams using cumulative point-wise entropy and average relative density. Second order statistical analysis applied on average relative densities and mean entropy values is then used to differentiate anomalies through robust and adaptive thresholds that are responsive to a dynamic environment. Anomaly detection is then performed in a non-parametric and non-probabilistic manner over the different network tiers in the hierarchical topology in offering increased granularity for evaluation. Experiments were performed extensively using both real and artificial data distributions representative of different dynamic and multi-density observation domains. Results demonstrate higher accuracies in detection as more than 94 percent accompanied by a desirable reduction of more than 85 percent in communication costs when compared to existing centralized methods. Heshan Kumarage, Ibrahim Khalil 0001, Zahir Tari |
IEEE Trans. Computers | 3 |
| 2015 | By-Passing Infected Areas in Wireless Sensor Networks Using BPRabstractAbnormalities in sensed data streams indicate the spread of malicious attacks, hardware failure and software corruption among the different nodes in a wireless sensor network. These factors of node infection can affect generated and incoming data streams resulting in high chances of inaccurate data, misleading packet translation, wrong decision making and severe communication disruption. This problem is detrimental to real-time applications having stringent quality-of-service (QoS) requirements. The sensed data from other uninfected regions might also get stuck in an infected region should no prior alternative arrangements are made. Although several existing methods (BOUNDHOLE and GAR) can be used to mitigate these issues, their performance is bounded by some limitations, mainly the high risk of falling into routing loops and involvement in unnecessary transmissions. This paper provides a solution to by-pass the infected nodes dynamically using a twin rolling balls technique and also divert the packets that are trapped inside the identified area. The identification of infected nodes is done by adapting a Fuzzy data clustering approach which classifies the nodes based on the fraction of anomalous data that is detected in individual data streams. This information is then used in the proposed by-passed routing (BPR) which rotates two balls in two directions simultaneously: clockwise and counter-clockwise. The first node that hits any ball in any direction and is uninfected, is selected as the next hop. We are also concerned with the incoming packets or the packets-on-the-fly that may be affected when this problem occurs. Besides solving both of the problems in the existing methods, the proposed BPR technique has greatly improved the studied QoS parameters as shown by almost 40 percent increase in the overall performance. Naimah Yaakob, Ibrahim Khalil 0001, Heshan Kumarage, Mohammed Atiquzzaman, Zahir Tari |
IEEE Trans. Computers | 5 |
| 2015 | Cooperative Web Caching Using Dynamic Interest-Tagged Filtered Bloom FiltersabstractAlthough cooperative Web caching has been widely researched, comparatively little has been done to reduce inter-proxy network overhead whilst allowing for a high percentage of requested documents to be retrieved from the cache. Alleviating these issues can substantially reduce Web traffic, increase scalability and enhance a user's browsing experience. This paper introduces a novel cache sharing system employing data structures called Dynamic Interest-Tagged Filtered Bloom Filters (DITFBFs). DITFBFs are capable of representing the cache content of a proxy in a compact form, which is then shared with other proxies in the cooperative Web caching system. What distinguishes the proposed system from others is that DITFBFs only represent the portion of a proxy's cache content that will be of interest to another proxy. This then results in a reduction of inter-proxy overhead. Experimental simulations indicate that, when compared with existing protocols, the proposed system is capable of multiple improvements. Namely, lowering the number of remote cache search messages by at least 60 percent, decreasing user-perceived latency by at least 65 percent and appreciably reducing the overall inter-proxy network overhead. The proposed system accomplishes this whilst maintaining a cache hit ratio as high as the other protocols. Holly Alexander, Ibrahim Khalil 0001, Conor Cameron, Zahir Tari, Albert Y. Zomaya |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2015 | Enhancing Availability in Content Delivery Networks for Mobile PlatformsabstractEnsuring high data availability is a vital prerogative for Content Delivery Networks (CDN), and as we look to deploy CDN mechanisms onto mobile platforms, this imperative becomes ever more challenging. In traditional CDNs, replication ensures high availability of data, with server-loads and content-popularity often used as parameters to tightly control the process. However, the highly transient properties of such wireless and mobile devices constitute a major hurdle for any replication algorithm, rendering most simplified methods inadequate. Our contribution begins with a unique message-pulsing mechanism operating within a wireless cluster, that detects devices and ascertains their reliability. Results show the viability of our pulsing algorithm in determining a base replication level. Next, a Markovian queueing model is introduced, allowing us to induce replication based on the required speed of service. This affords finer control over the replication process, creating a more effective replication strategy suited for mobile-based CDNs. Extensive analysis of the model were performed, with parameters derived from real-world conditions. Results indicate that the model is able to compute logical values for the expected waiting times in service and thus, control the speed of replication within the CDN. Mahathir Almashor, Ibrahim Khalil 0001, Zahir Tari, Albert Y. Zomaya, Sartaj Sahni |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2014 | SaaS clouds supporting non computing specialistsabstractBy processing big data using clouds, scientific researchers can achieve remarkable outcomes. However, these non-computing specialists do not have the computing knowledge and skills to deal with big data, build HPC applications, and execute them on clouds. Non-computing specialists also face a major problem with accessing HPC and cloud resources through a command driven interfaces, preferring to use menu-driven interfaces. In response we propose that that the future of big data processing lies in SaaS clouds and exposing applications as services. In this way, researchers are relieved from computing activities and concentrate on their research goals. This paper presents a SaaS cloud framework to support eScience, starting with software tools and other SaaS clouds, a description of an implementation of the proposed framework, and study of its features. Philip C. Church, Andrzej M. Goscinski, Zahir Tari |
AICCSA | 3 |
| 2014 | CluClas: Hybrid clustering-classification approach for accurate and efficient network classificationabstractThe traffic classification is the foundation for many network activities, such as Quality of Service (QoS), security monitoring, Lawful Interception and Intrusion Detection Systems (IDS). A recent statistics-based approach to address the unsatisfactory results of traditional port-based and payload-based approaches has attracted attention. However, the presence of non-informative attributes and noise instances degrade the performance of this approach. Thus, to address this problem, in this paper, we propose a hybrid clustering-classification approach (called CluClas) to improve the accuracy and efficiency of network traffic classification by selecting informative attributes and representative instances. An extensive empirical study on four traffic data sets shows the effectiveness of our proposed approach. Adil Fahad, Kurayman Alharthi, Zahir Tari, Abdulmohsen Almalawi, Ibrahim Khalil 0001 |
LCN | 3 |
| 2014 | An unsupervised anomaly-based detection approach for integrity attacks on SCADA systems
Abdulmohsen Almalawi, Xinghuo Yu 0001, Zahir Tari, Adil Fahad, Ibrahim Khalil 0001 |
Comput. Secur. | 3 |
| 2014 | PPFSCADA: Privacy preserving framework for SCADA data publishing
Adil Fahad, Zahir Tari, Abdulmohsen Almalawi, Andrzej M. Goscinski, Ibrahim Khalil 0001, Abdun Naser Mahmood |
Future Gener. Comput. Syst. | 2 |
| 2014 | An optimal and stable feature selection approach for traffic classification based on multi-criterion fusion
Adil Fahad, Zahir Tari, Ibrahim Khalil 0001, Abdulmohsen Almalawi, Albert Y. Zomaya |
Future Gener. Comput. Syst. | 2 |
| 2014 | CoCaMAAL: A cloud-oriented context-aware middleware in ambient assisted living
Abdur Forkan, Ibrahim Khalil 0001, Zahir Tari |
Future Gener. Comput. Syst. | 3 |
| 2014 | Pareto frontier for job execution and data transfer time in hybrid clouds
Javid Taheri, Albert Y. Zomaya, Howard Jay Siegel, Zahir Tari |
Future Gener. Comput. Syst. | 4 |
| 2014 | A distributed aggregation and fast fractal clustering approach for SOAP traffic
Dhiah Al-Shammary, Ibrahim Khalil 0001, Zahir Tari |
J. Netw. Comput. Appl. | 3 |
| 2014 | An ID-based approach to the caching and distribution of peer-to-peer, proxy-based video content
Conor Cameron, Ibrahim Khalil 0001, Zahir Tari |
J. Netw. Comput. Appl. | 3 |
| 2014 | PileCast: Multiple bit rate live video streaming over BitTorrent
Aukrit Chadagorn, Ibrahim Khalil 0001, Conor Cameron, Zahir Tari |
J. Netw. Comput. Appl. | 4 |
| 2014 | Data summarization for network traffic monitoring
Demetris Hoplaros, Zahir Tari, Ibrahim Khalil 0001 |
J. Netw. Comput. Appl. | 2 |
| 2014 | Performance Analysis of EDF Scheduling in a Multi-Priority Preemptive M/G/1 QueueabstractThis paper presents a queueing theoretic performance model for a multipriority preemptive M/G/1/./EDF system. Existing models on EDF scheduling consider them to be M/M/1 queues or nonpreemptive M/G/1 queues. The proposed model approximates the mean waiting time for a given class based on the higher and lower priority tasks receiving service prior to the target and the mean residual service time experienced. Additional time caused by preemptions is estimated as part of mean request completion time for a given class and as part of the mean delay experienced due to jobs in execution, on an arrival. The model is evaluated analytically and by simulation. Results confirm its accuracy, with the difference being a factor of two on average in high loads. Comparisons with other algorithms (such as First-Come-First-Served, Round-Robin and Nonpreemptive Priority Ordered) reveal that EDF achieves a better balance among priority classes where high priority requests are favored while preventing lower priority requests from overstarvation. EDF achieves best waiting times for higher priorities in lower to moderate loads (0.2-0.6) and while only being 6.5 times more than static priority algorithms in high loads (0.9). However, for the lowest priority classes, it achieves comparable waiting times to Round-Robin and First-Come-First-Served in low to moderate loads and achieves waiting times only twice the amount of Round-Robin in high system loads. Vidura Gamini Abhaya, Zahir Tari, Panlop Zeephongsekul, Albert Y. Zomaya |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2014 | ADAPT-POLICY: Task Assignment in Server Farms when the Service Time Distributionof Tasks is Not Known A PrioriabstractService time distribution of certain computing workloads such as static web content is well known. However, for many other computing workloads (e.g., dynamic web content, scientific workloads) the service time distribution is not well understood and it is not correct to assume that these tasks follow a particular distribution. In this paper, we consider task assignment in server farms when both the service time distribution of tasks and (actual) sizes of tasks are not known a priori. We propose an adaptive task assignment policy, called ADAPT-POLICY, which is based on the concept of multiple static-based task assignment policies. ADAPT-POLICY defines a set of policies for a given system taking into account the specific properties of the system. These policies are selected in such a way that they have different performance characteristics under different workload conditions (i.e., service time distributions, etc.). The objective is to use the task assignment policy with the best performance (i.e., the one with the least expected waiting time) to assign tasks. Which task assignment policy performs the best depends on the traffic conditions that vary over time. ADAPT-POLICY determines the best task assignment using the service time distribution of tasks (and various other traffic properties), which is estimated on-line and then it adaptively changes the task assignment policy to suit the most recent traffic conditions. The experimental results show that ADAPT-POLICY can result in significant performance improvements over both static and dynamic task assignment policies. Malith Jayasinghe, Zahir Tari, Panlop Zeephongsekul, Albert Y. Zomaya |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2013 | SCADAVT-A framework for SCADA security testbed based on virtualization technologyabstractSupervisory Control and Data Acquisition (SCADA) systems monitor and control infrastructures and industrial processes such as smart grid power and water distribution systems. Recently, such systems have been attacked, and traditional security solutions have failed to provide an appropriate level of protection. Therefore, it is important to develop security solutions tailored to SCADA systems. However, it is impractical to evaluate such solutions on actual live systems. This paper proposes a SCADA security testbed based on virtualization technology, and introduces a server which is used as a surrogate for water distribution systems. In addition, this paper presents a case study of two malicious attacks to demonstrate how the testbed can easily monitor and control any automatised processes, and also to show how malicious attacks can disrupt supervised processes. Abdulmohsen Almalawi, Zahir Tari, Ibrahim Khalil 0001, Adil Fahad |
LCN | 2 |
| 2013 | Toward an efficient and scalable feature selection approach for internet traffic classification
Adil Fahad, Zahir Tari, Ibrahim Khalil 0001, Ibrahim Habib, Hussein M. Alnuweiri |
Comput. Networks | 2 |
| 2013 | Fractal self-similarity measurements based clustering technique for SOAP Web messages
Dhiah Al-Shammary, Ibrahim Khalil 0001, Zahir Tari, Albert Y. Zomaya |
J. Parallel Distributed Comput. | 3 |
| 2013 | Distributed anomaly detection for industrial wireless sensor networks based on fuzzy data modelling
Heshan Kumarage, Ibrahim Khalil 0001, Zahir Tari, Albert Y. Zomaya |
J. Parallel Distributed Comput. | 3 |
| 2013 | Automatic and Autonomous Load Management in Peer-to-Peer Virtual EnvironmentsabstractThe very notion of a fully Peer-to-Peer (P2P) Virtual Environment (VE) places exacting demands on its underlying network. Subset applications such as online games are notorious for their sensitivity to latency and high bandwidth demands. By omitting the centralised mechanisms that underpin current commercial implementations, the task of managing a disparate and dynamic peer population is made ever more daunting. For any VE, arbitrating the interactions between players is an inescapable need. Online games are equal parts collaboration and competition, requiring robust conflict resolution mechanisms to govern game-play. With centralised systems, arbitration duties are simply assigned to a provisioned server infrastructure. In a P2P system however, the issue looms large. As such, managing arbitration loads across the peer population is the focus here. Being a game-play arbitrator entails added bandwidth and processing demands. Thus, great care is needed to avoid overloading peers whilst providing a responsive and uninterrupted experience. The work here exploits 3D Voronoi Diagrams (3D-VD) as a scalable, flexible and fault-tolerant P2P overlay that is able to automatically balance arbitration loads amongst peers. Simulation results indicate how 3D-VD, with the right arbitrator-selection policy, can appropriately distribute loads and reduce load fluctuations by up to 90%. This is then augmented with algorithms based on classical Newtonian gravity laws. Doing so provides an autonomous method to detect and respond to high-demand areas within the VE. Further experimentation demonstrates an ability to reduce the instances of failed arbitration attempts by 50%. Mahathir Almashor, Ibrahim Khalil 0001, Zahir Tari, Albert Y. Zomaya |
IEEE J. Sel. Areas Commun. | 3 |
| 2013 | A Probabilistic Model to Predict the Survivability of SCADA SystemsabstractRecent spate of cyber attacks against critical infrastructure systems, which are vital to society, have shown that in addition to be infeasible to stop every possible attack it is imperative to keep such systems running. Survivability models and tools are good to evaluate system's capacity to handling undesired events. Current survivability measurement techniques are limited, since they only use performance to model system behaviour, and do not take into account service interdependencies. This paper introduces a probabilistic model that offers a new direction in measuring survivability. The proposed model solves the issues with current models by combining the formalism of Bayesian networks with information diversity. Service interdependencies are properly taken into account and the information diversity metric is used to represent service behaviour. In addition, the model is evaluated through a simulation of a SCADA system, where the entire process to construct and to use the model is detailed. Carlos Queiroz, Abdun Naser Mahmood, Zahir Tari |
IEEE Trans. Ind. Informatics | 3 |
| 2012 | High-Order Terminal Sliding-Mode Observers for Anomaly Detection
Yong Feng 0001, Fengling Han, Xinghuo Yu 0001, Zahir Tari, Lilin Li, Jiankun Hu |
ICIC (1) | 4 |
| 2012 | Building Web services middleware with predictable execution times
Vidura Gamini Abhaya, Zahir Tari, Peter Bertók |
World Wide Web | 2 |
| 2011 | Task assignment in multiple server farms using preemptive migration and flow control
Malith Jayasinghe, Zahir Tari, Panlop Zeephongsekul, Albert Y. Zomaya |
J. Parallel Distributed Comput. | 2 |
| 2010 | Performance Analysis of Multi-level Time Sharing Task Assignment Policies on Cluster-Based SystemsabstractThere is extensive evidence indicating that modern computer workloads exhibit highly variability in their processing requirements. Under such workloads, traditional task assignment policies do not perform well. Size-based policies perform significantly better than traditional policies under highly variable workloads. The main limitation of existing size-based policies though is that these have been targeted for batch computing systems. In this paper, we provide performance analysis of 3 novel task assignment policies that are based on multi-level time sharing policy, namely MLMS (Multi-level Multi-server Task Assignment Policy), MLMS-M (Multi-level Multi-server Task Assignment Policy with Task Migration) and MLMS-M* (Multi-tier Multi-level Multi-server Task Assignment policy with Task Migration). These policies attempt to improve the performance first by giving preferential treatment to small tasks and second by reducing the task size variability in host queues. MLMS only reduces the variability of tasks locally, while MLMS-M and MLMS-M* utilise both local and global variance reduction mechanisms. MLMS outperforms existing size-based policies such as TAGS under specific workload conditions. MLMS-M outperforms TAGS under all the scenarios considered. MLMS-M*outperforms TAGS and MLMS-M under specific workload conditions and vice versa. Malith Jayasinghe, Zahir Tari, Panlop Zeephongsekul |
CLUSTER | 2 |
| 2010 | Survivable SCADA Systems: An Analytical Framework Using Performance ModellingabstractSupervisory Control and Data Acquisition (SCADA) systems control and monitor industrial and critical infrastructure functions, such as the electricity, gas, water, waste, railway and traffic. Recently, SCADA systems have been targeted by an increasing number of attacks from the Internet due to its grow- ing connectivity to Enterprise networks. Traditional techniques and models of identifying attacks, and quantifying its impact cannot be directly applied to SCADA systems because of their limited resources and real-time operating characteristics. The paper introduces a novel framework for evaluating survivability of SCADA systems from a service-oriented perspective. The framework uses an analytical model to evaluate the status of services performance and the survivability of the overall system using queuing theory and Bayesian networks. We further discuss how to learn from historical or simulated data automatically for building the conditional probability tables and the Bayesian networks. Carlos Queiroz, Abdun Naser Mahmood, Zahir Tari |
GLOBECOM | 3 |
| 2010 | Using Real-Time Scheduling Principles in Web Service Clusters to Achieve Predictability of Service Execution
Vidura Gamini Abhaya, Zahir Tari, Peter Bertók |
ICSOC | 2 |
| 2010 | Security, Privacy and Interoperability in Heterogeneous Systems
Peter Bertók, Zahir Tari |
PRO-VE | 3 |
| 2010 | A scalable Multi-Tier Task Assignment Policy with Minimum Excess LoadabstractExisting task assignment policies designed to schedule highly variable computer workloads are not scalable and they generate large amount of wasted processing. This paper proposes a scalable Multi-Tier Task Assignment Policy with Minimum Excess Load (MTTMEL) that can efficiently schedule tasks with highly variable processing requirements. Unlike existing policies, the proposed policy does not assign all incoming tasks to the first host in the system, rather it assigns incoming tasks to a subset of hosts in the system. The proposed policy has multiple tiers that consist of one or more hosts. The proposed policy scales well and it significantly reduces the amount wasted processing (excess load). For example, the TAGS policy produces 460% more wasted processing compared to MTTMEL under certain workloads. MTTMEL outperforms existing policies under a wide range of workload conditions. It outperforms RANDOM by a factor of 23 and TAGS by a factor of 2.6 under certain scenarios. Malith Jayasinghe, Zahir Tari, Panlop Zeephongsekul |
ISCC | 2 |
| 2010 | Multi-level Multi-server Task Assignment with Work-Conserving MigrationabstractSize-based task assignment policies have shown significant performance improvements over traditional task assignment policies under highly variable workload conditions. However, these policies are not suitable to assign tasks in time sharing systems. Moreover, these policies are not scalable and they also generate significant amount of wasted processing. This paper proposes a Multi-Level-Multi-Server Task Assignment Policy with Work-Conserving Migration (MLMS-WC-M) that addresses these issues. MLMS-WC-M has three important features. First, it gives preferential treatment to tasks with short processing requirements. Second, it utilises a 2-level variance reduction mechanism. Third, it supports work-conserving migration. We evaluate the performance of MLMS-WC-M against the performance of several well known task assignment policies. The proposed policy outperforms existing policies significantly under a wide range of workload conditions. Malith Jayasinghe, Zahir Tari, Panlop Zeephongsekul |
NCA | 2 |
| 2010 | Building Web Services Middleware with Predictable Service Execution
Vidura Gamini Abhaya, Zahir Tari, Peter Bertók |
WISE | 2 |
| 2010 | Critical infrastructure protection: Resource efficient sampling to improve detection of less frequent patterns in network traffic
Abdun Naser Mahmood, Jiankun Hu, Zahir Tari, Christopher Leckie |
J. Netw. Comput. Appl. | 3 |
| 2010 | The Impact of Service Cohesion on the Analyzability of Service-Oriented SoftwareabstractService-Oriented Computing (SOC) is intended to improve software maintainability as businesses become more agile and underlying processes and rules change more frequently. However, to date, the impact of service cohesion on the analyzability subcharacteristic of maintainability has not been rigorously studied. Consequently, this paper extends existing notions of cohesion in the Procedural and OO paradigms in order to account for the unique characteristics of SOC, thereby supporting the derivation of design-level software metrics for objectively quantifying the degree of service cohesion. The metrics are theoretically validated, and an initial empirical evaluation using a small-scale controlled study suggests that the proposed metrics could help predict analyzability early in the Software Development Life Cycle. If future industrial studies confirm these findings, the practical applicability of such metrics is to support the development of service-oriented systems that can be analyzed, and thus maintained, more easily. In addition, such metrics could help identify design problems in existing systems. Mikhail Perepletchikov, Caspar Ryan, Zahir Tari |
IEEE Trans. Serv. Comput. | 3 |
| 2009 | On the performance of multi-level time sharing policy under heavy-tailed workloadsabstractMany existing works on multi-level time sharing policies have assumed infinitely small quanta, infinite levels or exponential service time distributions. In this paper, we investigate the performance of a multi-level time sharing policy under heavy-tailed workloads under finite levels when quanta are not infinitely small. Such a policy is consistent with those implemented on modern computer systems and these findings will enable system designers to better understand how various factors (e.g. system load, task size variability and number of levels) affect the overall performance of a given system. First, we obtain the performance metrics for a multi-level time sharing policy with finite number of levels. Second, for the case of 2 and 3 levels (queues), we show that optimal quantum multi-level time sharing policy (MLOQTP) can result in significant performance improvements over other policies under certain traffic and workload conditions. Finally, we investigate the impact of number of levels on the overall performance and propose a simple statistical regression model that can accurately estimate overall performance of a multi-level time sharing system. Malith Jayasinghe, Zahir Tari, Panlop Zeephongsekul, James Broberg |
ISCC | 2 |
| 2009 | Building a SCADA Security TestbedabstractSCADA (supervisory control and data acquisition) systems control and monitor industrial and critical infrastructure functions, such as the electricity, gas, water, waste, railway and traffic. Recent attacks on SCADA systems highlight the need of a SCADA security testbed, which can be used to model real SCADA systems and study the effects of attacks on them. We propose the architecture of a modular SCADA testbed and describe our tool which mimics a SCADA network, monitors and controls real sensors and actuators using Modbus/TCP protocol. Using distributed denial of service (DDoS) scenarios we show how attackers can disrupt the operation of a SCADA system. Carlos Queiroz, Abdun Naser Mahmood, Jiankun Hu, Zahir Tari, Xinghuo Yu 0001 |
NSS | 4 |
| 2009 | MetaCDN: Harnessing 'Storage Clouds' for high performance content delivery
James Broberg, Rajkumar Buyya, Zahir Tari |
J. Netw. Comput. Appl. | 3 |
| 2008 | MetaCDN: Harnessing Storage Clouds for High Performance Content Delivery
James Broberg, Zahir Tari |
ICSOC | 2 |
| 2008 | VGC: Generating Valid Global Communication Models of Composite Services Using Temporal Reasoning
Nalaka Gooneratne, Zahir Tari, James Harland |
ICSOC | 2 |
| 2008 | QoS-aware Application Layer MulticastabstractThe crux of large scale Application Layer Multicast or Peer-to-Peer streaming systems is how to cope with the inherent dynamics, the reason is that the participating users may join and leave at will. It is even worse for single-tree-based multicast systems, which are preferred due to their efficiency. In these single multicast tree based schemes, userpsilas departure may cause serious service disruption for all the downstream users. The solution stems from the characteristics of the problem itself, and it exploits the property that the participating userspsila lifetime follow a Pareto distribution, which has the used better than new (UBTN) feature. The participating nodes are dynamically organized into a hierarchy in such a way that it reflects the relative stabilities among the nodes. The proposed algorithm is distributed in the sense that no a prior knowledge about userspsila lifetime is needed. A maximum of 50% improvement can be achieved in terms of peerspsila perceived QoS. Detailed mathematical analysis and simulation results are presented to validate the proposed algorithm. Simulation results show that the algorithm is valid for other lifetime distributions as well. Bin Rong, Ibrahim Khalil 0001, Zahir Tari |
ISCC | 3 |
| 2008 | Matching independent global constraints for composite web servicesabstractService discovery employs matching techniques to select services by comparing their descriptions against user constraints. Semantic-based matching approaches achieve higher recall than syntactic-based ones (as they employ ontological reasoning mechanisms to match syntactically heterogeneous descriptions). However, semantic-based approaches still have problems (e.g. lack of scalability as an exhaustive search is often performed to located services conforming to constraints). This paper proposes two approaches that deal with the problem of scalability/performance for composite service location. First, services are indexed based on the values they assign to their restricted attributes (the attributes restricted by a given constraint). Then, services that assign "conforming values" to those attributes are combined to form composite services. The first proposed approach extends a local optimisation technique to perform the latter, since identifying such values is NP-hard. However, this approach returns false negatives since the local optimisation technique does not consider all the values. Hence, a second approach that derives conforming values using domain rules is defined. The used rules are returned with each composite service so that a user can understand the context in which it is retrieved. Results obtained from the experiments that varied the number of available services demonstrate that the performance of the local optimisation-based approach is 76% better than existing semantic-based approaches and recall is 98% higher than syntactic-based approaches. Nalaka Gooneratne, Zahir Tari |
WWW | 2 |
| 2008 | Similarity-Based SOAP Multicast Protocol to Reduce Bandwith and Latency in Web ServicesabstractWeb Services technology provided several advantages over other technologies, however it still has serious limitations, including high latency and high protocol overhead. To improve performance, SOAP network traffic needs to be substantially reduced. This paper presents a novel approach, called similarity-based SOAP multicast protocol (SMP), to address the issue of latency. SMP reduces network traffic by aggregating syntactically similar SOAP messages to form a "compact SMP message";. The addresses of clients are encoded as strings in the SMP message header. The similarity of SOAP messages is measured in pairs and is based both on the message template and on the values of each XML tag in the messages. Each XML node in a SOAP message is indexed with an identifier and its position in the SOAP message. Only the indexed form of a SOAP message is sent to clients. Intermediary routers along the paths from server to clients parse the content of each SMP message passing through them and perform necessary operations to forward it to neighbouring routers. Experiments show that SMP can achieve up to 70% reduction in network traffic compared to traditional SOAP unicast. Khoi Anh Phan, Zahir Tari, Peter Bertók |
IEEE Trans. Serv. Comput. | 2 |
| 2008 | Correctness-aware high-level functional matching approaches for semantic Web servicesabstractService matching approaches trade precision for recall, creating the need for users to choose the correct services, which obviously is a major obstacle for automating the service discovery and aggregation processes. Our approach to overcome this problem, is to eliminate the appearance of false positives by returning only the correct services. As different users have different semantics for what is correct, we argue that the correctness of the matching results must be determined according to the achievement of users' goals: that only services achieving users' goals are considered correct. To determine such correctness, we argue that the matching process should be based primarily on the high-level functional specifications (namely goals, achievement contexts, and external behaviors). In this article, we propose models, data structures, algorithms, and theorems required to correctly match such specifications. We propose a model calledG+, to capture such specifications, for both services and users, in a machine-understandable format. We propose a data structure, called a Concepts Substitutability Graph (CSG), to capture the substitution semantics of application domain concepts in a context-based manner, in order to determine the semantic-preserving mapping transformations required to match differentG+models. We also propose a behavior matching approach that is able to match states in an m-to-n manner, such that behavior models with different numbers of state transitions can be matched. Finally, we show how services are matched and aggregated according to theirG+models. Results of supporting experiments demonstrate the advantages of the proposed service matching approaches. Islam Elgedawy, Zahir Tari, James A. Thom |
ACM Trans. Web | 2 |
| 2007 | Approximating Bounded General Service DistributionsabstractExponential distributions have traditionally been used to model the traffic (e.g. inter-arrival and service distributions) experienced in computer networks. They are attractive as they are amenable to analysis typically utilised in queueing models. However, modern traffic analysis has shown that many computing workloads are in fact 'heavy-tailed' and highly variable, and are better represented by general distributions such as Log-normal and Pareto. The use of General distributions can make an analytical analysis of some queueing metrics (e.g. waiting time, busy period, slowdown) difficult due to the fact that the Markovian properties of certain stochastic processes in queues are no longer in force. For such distributions Prony 's method can be utilised to fit a series of exponentials to the original General distribution, resulting in a Hyper-exponential distribution that represents the characteristics of the original workload, but is more amenable to analysis. Bounded representations of general distributions (such as Bounded Pareto) are frequently used, but by default, Prony's method is not ideally suited to fitting such distributions. We present two ways of addressing this issue: by normalising the Hyper-exponential resulting from Prony's method between the bounds of the workload distribution being approximated, and by re-evaluating Prony's method to fit directly to a Bounded Hyper-exponential. James Broberg, Panlop Zeephongsekul, Zahir Tari |
ISCC | 3 |
| 2007 | eSMP: A Multicast Protocol to Minimize SOAP Network Traffic in Low Bandwidth EnvironmentsabstractWeb services, which are built on SOAP as the transport protocol, have emerged in recent years as a promising technology to enable interoperability between distributed applications. As such, SOAP may be used to handle a large number of transactions; and consequently it is desirable to have SOAP perform efficiently in high traffic environments. This paper presents eSMP, an extension of our previous work on a similarity-based SOAP multicast protocol (SMP). eSMP offers improvements over SMP in terms of traffic size by using its own routing protocol instead of the conventional shortest path algorithm to route messages to paths that will minimize the number of bytes transmitted in the network. From extensive experiments, it is shown that eSMP achieves a minimum of 25 percent reduction in total network traffic than SMP with a trade-off of 10 percent increase in average response time. Compared to unicast, bandwidth consumptions can by reduced by up to 80 percent when using eSMP and 70 percent when using SMP. Therefore, eSMP is suitable for applications where bandwidth requirement is critical but not time. Khoi Anh Phan, Zahir Tari, Peter Bertók |
LCN | 2 |
| 2006 | Probabilistic QoS Routing inWiFi P2P NetworksabstractQoS routing in WiFi P2P networks is the process of selecting a path to be used by peers based on their QoS requirements, such as bandwidth or delay. Existing QoS routing solutions provide an effective way of dealing with path selection; however, even though there exist paths with more available capacity or better reliability, these paths are not taken into consideration. In this paper we propose algorithms to compute paths with maximal path-capacity-to-hop count ratio from a super-peer to all other super-peers in a WiFi P2P network. The complexities of these algorithms are O(MH), where M is the number of edges and H is the diameter of the P2P network. Simulations conducted on different topologies demonstrate that our proposed algorithms perform up to 15% better (in terms of information loss) when compared to existing techniques Sathish Rajasekhar, Ibrahim Khalil 0001, Zahir Tari |
AINA (1) | 3 |
| 2006 | Load Sharing in Peer-to-Peer Networks using Dynamic ReplicationabstractThe peer-to-peer (P2P) architecture provides support for the next generation of information sharing applications. A difficult challenge faced by these systems in the presence of non-uniform data distribution and dynamic network conditions is load sharing. This paper addresses the problem of load sharing in P2P networks across heterogeneous super-peers. We propose two load sharing techniques that use data replication to improve access performance. In the first technique, called periodic push-based replication (PPR), super-peers periodically send replicas of the most frequently accessed files to remote super-peers. This effectively reduces the hop count to fetch these files. The second technique, called on-demand replication (ODR), performs replication based on access frequency. By performing replication on-demand, ODR provides adaptability to changes in access behavior. Extensive testing have been conducted to study the performance of the proposed techniques. The results obtained demonstrate significant performance improvements through replication Sathish Rajasekhar, Bin Rong, Kwong Yuen Lai, Ibrahim Khalil 0001, Zahir Tari |
AINA (1) | 5 |
| 2006 | Reliability Enhanced Large-Scale Application Layer MulticastabstractReliability has become the major concern in application layer multicast because the participating users may join and leave at will. The overlay network, built on-the-fly, is highly dynamic. It is getting worse in reality because single-tree based multicast structures are preferred, due to their efficient usage of network resources. In these single multicast tree based schemes, users' departure may cause serious service disruption for all the downstream users. A new tree construction algorithm is proposed to enhance reliability for application layer multicast. It exploits the property that the participating users' lifetime follow a Pareto distribution, which has the used better than new (UBTN) feature, and dynamically adjusts the multicast tree. The participating nodes are mapped into a hierarchy which is organized in such a way that it reflects the relative stability among the participating nodes. The proposed approach is light-weight and no a prior knowledge about users' lifetime is needed. A minimum of 50% reduction can be achieved in terms of service disruption frequency. Detailed mathematical analysis and simulation results are presented to validate the proposed algorithm. Bin Rong, Ibrahim Khalil 0001, Zahir Tari |
GLOBECOM | 3 |
| 2006 | Multipath Aware TCP (MATCP)abstractOn the Internet many different paths exist between each source and destination. When single path routing is used these paths can be under utilized, not used fairly or not used at all. One way to overcome this is to allow multipath routing. But when multiple paths are used TCP congestion control can be negatively affected and cause poor goodput performance due to the reordering of packets. We proposeMATCP (Multipath Aware TCP) which makes modifications to TCP that allows it to monitor and select which path it takes through the network for each flow. MATCP is compared to single path routing and is validated using extensive simulation. MATCP is found to greatly improve fairness between flows while providing equal or better utilization of links than single best path networks. Peter Dimopoulos, Panlop Zeephongsekul, Zahir Tari |
ISCC | 3 |
| 2006 | Making Application Layer Multicast Reliableis FeasibleabstractApplication layer multicast (ALM henceforth) was proposed as a substitute for network layer multicast (IP multicast). However, the end users, who take the responsibility to replicate and forward data in ALM, are not as stable as routers in IP multicast. Therefore, reliability has become the major concern in ALM. This paper presents a new tree construction algorithm and demonstrates that making ALM reliable is achievable, even when a single-tree based multicast structure is used. It exploits the property that participating users' lifetime follow a Pareto distribution which has the used better than new (UBTN) feature, and dynamically adjusts the multicast tree. Participating nodes are organized into a hierarchy and the hierarchy is organized in such a way that it reflects the relative stability among participating nodes. The proposed approach achieves reliability enhancement for ALM by using a very low overhead and no a priori knowledge about users' lifetime is required. A minimum reduction of 50% can be achieved in terms of service disruption frequency. Detailed mathematical analysis and simulation results reveal that making ALM reliable is feasible Bin Rong, Ibrahim Khalil 0001, Zahir Tari |
LCN | 3 |
| 2006 | Task assignment with work-conserving migration
James Broberg, Zahir Tari, Panlop Zeephongsekul |
Parallel Comput. | 2 |
| 2005 | Reducing the user perceived delay of interactive TCP connections using a dynamic priority approachabstractMany interactive applications require continuous user interaction, for example ssh and many Web applications. The TCP connections created by these applications are therefore in a class called interactive. When interactive applications suffer from packet loss, the packet retransmission time severely increases the user perceived delay. This work introduces a dynamic priority RED queue (DPRQ) algorithm that dynamically changes the priority of queues instead of dropping packets when the queue is overloaded. The algorithm reduces the user perceived delay by reducing packet loss in interactive TCP connections. The DPRQ is compared to an existing class-based queue which incorporates RED (RCBQ) as would typically be used for assured forwarding. An analytical model of the DPRQ and RCBQ is presented with both experimental and analytical results. The DPRQ is found by simulation to decrease packet loss by up to eight times and therefore provide a lower user perceived delay even though queuing delay is increased by up to five times. Peter Dimopoulos, Panlop Zeephongsekul, Zahir Tari |
ICCCN | 3 |
| 2005 | Supporting disconnection operations through cooperative hoardingabstractMobile clients often need to operate while disconnected from the network due to limited battery life and network coverage. Hoarding supports this by fetching frequently accessed data into clients' local caches prior to disconnection. Existing work on hoarding have focused on improving data accessibility for individual mobile clients. However, due to storage limitations, mobile clients may not be able to hoard every data object they need. This leads to cache misses and disruption to clients' operations. In this paper, a new concept called cooperative hoarding is introduced to reduce the risks of cache misses for mobile clients. Cooperative hoarding takes advantage of group mobility behaviour, combined with peer cooperation in ad-hoc mode, to improve hoard performance. Two cooperative hoarding approaches are proposed that take into account access frequency, connection probability, and cache size of mobile clients so that hoarding can be performed cooperatively. Simulation results show that the proposed methods significantly improve cache hit ratio and provides better support for disconnected operations compared to existing schemes. Kwong Yuen Lai, Zahir Tari, Peter Bertók |
ICCCN | 2 |
| 2005 | Improving Data Accessibility For Mobile Clients Through Cooperative HoardingabstractIn this paper, we introduce the concept of cooperative hoarding to reduce the risks of cache misses for mobile clients. Cooperative hoarding takes advantage of group mobility behaviour, combined with peer cooperation in ad-hoc mode, to improve hoard performance. Two cooperative hoarding approaches that take into account clients' access frequencies, connection probabilities and cache size when performing hoarding are proposed. Test results show that the proposed methods significantly improve cache hit ratio and reduce query costs compared to existing approaches. Kwong Yuen Lai, Zahir Tari, Peter Bertók |
ICDE | 2 |
| 2005 | A High-Level Functional Matching for Semantic Web Services
Islam Elgedawy, Zahir Tari, James A. Thom |
ICSOC | 2 |
| 2005 | A Task-Based Adaptive TTL Approach for Web Server Load BalancingabstractWeb sites attracting a high client-traffic cannot simply rely on either mirrored servers or a single server to balance the client-request generated load. DNS load balancing techniques have shown their advantages in dealing with heavy Web traffic. These techniques use the time-to-live (TTL) value associated with a name-to-address translation. Unfortunately name-to-address translations are cached in intermediate name servers for a period defined by the TTL This results in all requests reaching the same Web server for this TTL period. The proposed adaptive-TTL approach (called DLB-TS - dynamic load balancing based on task size) takes into account the time taken to fetch a document while choosing the least loaded server. To alleviate the problems of client-side caching and non-cooperative intermediate name servers, a server-side redirection is proposed and implemented. Though the algorithm caused degraded performance because of server-side load balancing under a light load, it reduced the client perceived latency by at least 16% when compared to existing size-based algorithms. Devarshi Chatterjee, Zahir Tari, Albert Y. Zomaya |
ISCC | 2 |
| 2005 | Efficient SOAP Binding for Mobile Web ServicesabstractExisting Web services rely on HTTP and TCP as the underlying transport protocols for SOAP messaging. While these protocols provide a number of benefits, including being able to pass through firewalls and are universally supported across different platforms, they were designed for wired networks with high bandwidth, low latency and low error rate transmissions. Due to the variability of wireless channels however, these assumptions do not hold in wireless environments. In this paper, we investigate the performance of HTTP and TCP as transport protocols for SOAP in wireless environments. Through extensive testing, we show that SOAP-over-HTTP and SOAP-over-TCP are inefficient and lead to high latency and transmission overhead for wireless applications. To overcome these limitations, we study the use of UDP as a binding protocol for SOAP. The results obtained are promising and show that SOAP-over-UDP provides throughput that is ten times higher compared to SOAP-over-HTTP in a wireless setting. Furthermore, using UDP to transport SOAP messages reduces transmission overhead by more than 50% compared to SOAP-over-HTTP. Finally, to illustrate where UDP binding can be useful, example applications are also described in this paper Kwong Yuen Lai, Thi Khoi Anh Phan, Zahir Tari |
LCN | 3 |
| 2005 | A Gossip-based Membership Management Algorithm for Large-Scale Peer-to-Peer Media StreamingabstractA new adaptive gossip-based membership management algorithm is proposed. Its adaptive nature enables it to confine the control overhead to local ranges, and adapt to the ever-changing network traffic conditions and group membership. The random nature of the algorithm ensures that it can cope with random failures and offer proactive measures to maintain service at a certain level. Mathematical analysis and simulation results indicate that more than 90% of the nodes can work properly even under very high network dynamics (with a short half-life time of 50 seconds), and all these are achieved by using a relatively low overhead. Bin Rong, Ibrahim Khalil 0001, Zahir Tari |
LCN | 3 |
| 2005 | A least flow-time first load sharing approach for distributed server farm
Zahir Tari, James Broberg, Albert Y. Zomaya, Roberto Baldoni |
J. Parallel Distributed Comput. | 1 |
| 2004 | Location-aware cache replacement for mobile environmentsabstractTraditional cache replacement policies rely on the temporal locality of users' access pattern to improve cache performance. These policies, however, are not ideal in supporting mobile clients. As mobile clients can move freely from one location to another, their access pattern not only exhibits temporal locality, but also exhibits spatial locality. In order to ensure efficient cache utilisation, it is important to take into consideration the location and movement direction of mobile clients when performing cache replacement. In this paper. we propose a mobility-aware cache replacement policy, called MARS, suitable for wireless environments. MARS takes into account important factors (e.g. client access rate, access probability, update probability and client location) in order to improve the effectiveness of onboard caching for mobile clients. Test results show that MARS consistently outperforms existing cache replacement policies and significantly improves mobile clients' cache hit ratio. Kwong Yuen Lai, Zahir Tari, Peter Bertók |
GLOBECOM | 2 |
| 2004 | Improving Cache Performance in Mobile Computing Networks through Dynamic Object Relocation
Kwong Yuen Lai, Zahir Tari, Peter Bertók |
ICPADS | 2 |
| 2004 | Exact functional context matching for web servicesabstractService discovery approaches, which mainly use keyword matching of service descriptions, have a low matching precision. This paper proposes an approach to increasing the matching precision by using services' functional contexts during the matching process. To enable a precise functional context matching, both the services' goals and the domain semantics are considered. For that purpose, we introduce the concept of functional substitutability and the proposed context matching technique uses this concept to match the underlying constraints of the functional contexts. Compared to the keyword-based context matching approach, simulation experiments showed that the (context retrieval) precision using the devised matching approach is much better and more stable against query semantic mutations. Islam Elgedawy, Zahir Tari, Michael Winikoff |
ICSOC | 2 |
| 2004 | An analytical study of object relocation strategies for wireless environmentsabstractCaching is a commonly used technique for reducing access latency and improving scalability. However, the static nature of existing network caching techniques makes them unsuitable for wireless environments. As mobile clients move from one location to another, the performance of these caches deteriorates. To combat this problem, object relocation strategies can be used, where objects are dynamically relocated to locations near the moving clients. Existing work on object relocation have focused on achieving relocation transparency. Little attention has been given to the network overhead introduced by the relocation. In this paper, we propose a low overhead object relocation strategy suitable for wireless environments. Object lists are passed between nodes prior to relocation to ensure only the nearest copy of each object is relocated. We have developed detailed analytical models of the proposed strategy and a number of other strategies to facilitate comparison. Analytical and simulation results show the proposed strategy effectively reduce the effect of mobility on the performance of network caches. The relocation overhead of the proposed method is also significantly lower compared to existing schemes. Mario Gerla, Zahir Tari, Peter Bertók |
ISCC | 2 |
| 2004 | A workflow-based dynamic scheduling approach for Web services platformsabstractSeveral techniques have been proposed to deal with task assignment in workflow systems. An "appropriate" service provider is selected using specific details about tasks (such as task type and price). The matching of the specific requirements of a task is performed and the task is then assigned to an appropriate provider. These solutions work well, however they do not produce good performance in terms of the mean flow time and the mean slow down. Existing solutions also do not deal with the issues of reliability (i.e. failure of the service provider), server load (i.e. the amount of tasks in the queue) and processing capacity of the service provider. This paper addresses these limitations by assigning tasks to the solution provider with lower load, higher processing capacity and better reliability. We introduce the concept of "delay factor", which is computed for each server to characterise the reliability of a service provider. For a given server with a specific load and processing capacity, we measure the mean flow time of tasks. The dispatcher then assigns tasks to the service provider that has the lower mean flow time and the smallest delay factor. With extensive performance testing, we demonstrate that proposed approach out-performs existing load distribution strategies. Muhammed S. Peerbocus, Zahir Tari |
ISCC | 2 |
| 2004 | Mobility-Aware Cache Replacement for Users of Location-Dependent ServicesabstractRecent advances in wireless communication and global positioning technologies have led to increasing interest in location dependent information services. As mobile users move between locations utilising such services, their access patterns not only exhibit temporal locality, but also spatial locality. Traditional cache replacement policies were designed to deal with temporal locality, as a result, they are inefficient location dependent services. In this paper a mobility-aware algorithm called MARS+ is proposed to detect regular client movement patterns and provides information to improve cache performance. Test results show that MARS+ improves clients' cache hit ratio by more than 16% compared to existing policies. Kwong Yuen Lai, Zahir Tari, Peter Bertók |
LCN | 2 |
| 2004 | Task Assignment Based on Prioritising Traffic Flows
James Broberg, Zahir Tari, Panlop Zeephongsekul |
OPODIS | 2 |
| 2004 | An Hoarding Approach for Supporting Disconnected Write Operations in Mobile EnvironmentsabstractCaching is one technique that reduces costs and improves performance in mobile environments. It also increases availability during temporary, involuntary disconnections. However, our focus is on voluntary, client initiated disconnections, where hoarding can be used to predict data requirements. Existing hoarding approaches ignore conflicts arising out of write sharing and are thus unable to deal with them. However, since conflicts are detrimental to bandwidth utilisation, for scenarios with high write sharing, hoarding techniques need to provide support for sharing in a manner that reduces or avoids conflicts. We propose a hoarding approach for disconnected write operations that focuses on reducing the likelihood of conflicts, arising from write sharing, in a highly concurrent environment. Data that clients might need when disconnected is predicted based on the notion of semantic similarity. To avoid/reduce conflicts, data are first clustered based on their update probabilities. The hoard tree is then created based on the clusters and semantic similarity between data. Simulations show an increase in the cache hit-rate along with an reduction in the total number of conflicts. Abhinav Vora, Zahir Tari, Peter Bertók |
SRDS | 2 |
| 2004 | Scenario Matching Using Functional Substitutability in Web Services
Islam Elgedawy, Zahir Tari, Michael Winikoff |
WISE | 2 |
| 2003 | A Variable Cache Consistency Protocol for Mobile Systems Using Time Locks
Abhinav Vora, Zahir Tari, Peter Bertók |
DAIS | 2 |
| 2003 | Task Assignment Strategy for Overloaded SystemsabstractSize-based load distribution approaches are proposed to deal with high variation of task size. One of the most critical problem of these approaches is that they do not consider task deadlines (which if not met may cause task starvation). This paper proposes an extension of our early work on dynamic load balancing [E.L. Hahne et al., June 2002, M. Mirhakkak et al., Aug. 2001, A.S. Tanenbaum, 1996] (called LFF) which takes the relative processing time of task of a task into account and dynamically assigns it to the fittest server with a lighter load and high processing capacity. LFF-PRIORITY dynamically computes the task size priority and task deadline priority and puts them in a priority based multi-section queue. The testing results clearly show that LFF-PRIORITY out performs existing load distribution strategies. More importantly, more than 80% of tasks meet their task deadlines under LFF-PRIORITY strategy. James Broberg, Zahir Tari |
ISCC | 3 |
| 2002 | A Mobile Cache Consistency Protocol Using Shareable Read/Write Time LocksabstractObject caching is often used to improve the performance of mobile applications, but the gain is often lessened by the additional load of maintaining consistency between an original object and its cached copy. This paper aims at reducing the consistency maintenance work and proposes a protocol that distinguishes between two classes of consistency (i.e. weak and strong) and treats them differently. Strong consistency is used for data that needs to be consistent all the time, whereas weak consistency is for cases when stale data can be tolerated or only specific updates are relevant to the application. Consistency is maintained by using strict and permissive read/write time locks that enable data sharing for a fixed time period and support concurrency control. A notification protocol for propagating updates to clients is also proposed. Performance tests have shown that switching from strong to weak consistency reduces the number of aborts due to conflicting operations by almost half even with high read/write sharing. Abhinav Vora, Zahir Tari, Peter Bertók, Kwong Yuen Lai |
ICPADS | 2 |
| 2002 | Dynamic task assignment in server farms: better performance by task groupingabstractThis paper describes a dynamic load balancing approach to distributed server farm systems. This approach overcomes the interference caused by non-negligible very large tasks in the heavy-tailed distribution. First, a subset of tasks is allocated proportionally to the processing capability of participating servers by taking into account their remaining processing time. Later, tasks in the servers are processed in order of priority to optimise the system response time. The proposed load balancing algorithm also takes into account the information on server loads to avoid load imbalance caused by very large tasks. The experiments show that the mean waiting time and the mean slowdown time are reduced at the server farm system. Zahir Tari |
ISCC | 2 |
| 2001 | Special Issue: Distributed Objects and Applications '99abstractDistributed Objects and Applications ' Zahir Tari, Robert Meersman |
Concurr. Comput. Pract. Exp. | 1 |
| 2001 | Guest Editors' Introduction: Special Section on Semantic Issues of Multimedia Systems
Zahir Tari, Robert Meersman |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2001 | Controlling Aggregation in Distributed Object Systems: A Graph-Based ApproachabstractThe Distributed Object Kernel is a federated database system providing a set of services which allow cooperative processing across different databases. The focus of this paper is the design of a DOK security service that provides for enforcing both local security policies, related to the security of local autonomous databases, and federated security policies, governing access to data aggregates composed of data from multiple distributed databases. We propose Global Access Control, an extended access control mechanism enabling a uniform expression of heterogeneous security information. Mappings from existing Mandatory and Discretionary Access Controls are described. To permit the control of data aggregation, the derivation of unauthorized information from authorized data, our security framework provides a logic-based language, the Federated Logic Language (FELL), which can describe constraints on both single and multiple states of the federation. To enforce constraints, FELL statements are mapped to state transition graphs which model the different subcomputations required to check the aggregation constraints. Graph aggregation operations are proposed for building compound state transition graphs for complex constraints. To monitor aggregation constraints, two marking techniques, called Linear Marking Technique and Zigzag Marking Technique, are proposed. Finally, we describe a three-layer DOK logical secure architecture enabling the implementation of the different security agents. This includes a Coordination layer, a Task layer, and a Database layer. Each contains specialized agents that enforce a different part of the federated security policy. Coordination is performed by the DOK Manager, enforcing security is performed by a specialized Constraint Manager agent, and the database functions are implemented by user and data agents. Zahir Tari, Andrew G. Fry |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2000 | A Query Propagation Approach to Improve CORBA Trading Service ScalabilityabstractExisting CORBA traders, at least most of them, support the core functions of the OMG specification of the Trading Service. We believe that this is useful and can help potential users to use such a service in heterogeneous environments. However we also believe that this is not sufficient because such environments deal with dynamic information and often require scalability (e.g. stock market applications). The CORBA Trading Service uses static information recorded in different components of a trading graph, which reduces its ability to deal with dynamic environments. This paper proposes solutions to the issue of type management and query routing in the context of CORBA Trading Service to improve the scalability and the quality of the results returned by the core trader functions. We propose a query routing mechanism that uses dynamic information recorded within different traders. Some of this information, such as hit factor, is calculated based on the number of offers a remote trader can address and their relative hops away. Finally, we demonstrate that the proposed approach has led to better performance for the core CORBA trader functions. Zahir Tari, Gregory Craske |
ICDCS | 1 |
| 1999 | A COBRA Object-Based Caching with Consistency
Zahir Tari, Slimane Hammoudi, Stephen Wagner |
DEXA | 1 |
| 1999 | A Property-based Clustering Approach for the CORBA Trading ServiceabstractThe CORBA Trading Service is an object service advertiser for heterogeneous distributed computing environments. Current approaches for the design and implementation of such a CORBA service do not deal with some of the major problems of searching for service offers in large-scale distributed systems, namely performance and scalability problems. This paper proposes an appropriate approach for clustering service offers based on the service properties, in order to enhance the efficiency of the trading service. The proposed approach clusters service offers within a hierarchy of contexts by specialisation of property sets. Performance results of the proposed clustering approach are discussed, and the benefits of including clustering of properties with the CORBA Trading Service are shown. Gregory Craske, Zahir Tari |
ICDCS | 2 |
| 1999 | QAL: A Query Algebra of Complex Objects
Iztok Savnik, Zahir Tari, Tomaz Mohoric |
Data Knowl. Eng. | 2 |
| 1999 | Type Safety in the Context of Method Updates
Zahir Tari |
J. Intell. Inf. Syst. | 1 |
| 1998 | Querying Objects with Complex Static Structure
Iztok Savnik, Zahir Tari |
FQAS | 2 |
| 1998 | Dealing with Version Pertinence to Design an Efficient Schema Evolution FrameworkabstractThe paper addresses the design of a schema evolution framework enabling an efficient management of object versions. This framework is based on the adaptation and extension of two main schema evolution approaches, that is the approaches based on schema modification and those based on schema versioning. The framework provides an integrated environment to support different levels of adaptation (such as, modification and versioning at the schema level, conversion, object versioning, and emulation at the instance level). In addition, the authors introduce the concept of class/schema version pertinence enabling the database administrator to judge the pertinence of versions with regard the application programs. Finally, they provide operations for immediate refreshing of a database to enable an efficient manipulation of versions by a large number of application programs. Boualem Benatallah, Zahir Tari |
IDEAS | 2 |
| 1997 | Designing Security Agents for the DOK Federated System
Zahir Tari |
DBSec | 1 |
| 1997 | Designing the Reengineering Services for the DOK Federated Database SystemabstractAddresses the design of the reengineering service for the DOK (Distributed Object Kernel) federated database. This service allows the hiding of the heterogeneity of databases involved in a federation by generating object-oriented representations from their corresponding schemata. We propose a complete methodology that supports the identification and the translation of both the explicit and implicit information. The identification of object-oriented constructs is performed by classifying a relational schema into different categories of relations, namely base, dependent and composite relations. The main difficulty in designing the reengineering service relies on the distinction between the different types of relationships amongst classes. Our approach deals with this problem by analysing relations according two types of correlation: (i) the degree of correlation between the external and primary keys, and (ii) the degree of correlation between sets of tuples in the relations. Examining these correlations uncovers implicit relationships contained as well-hidden classes in a relational schema. Zahir Tari, John Stokes |
ICDE | 1 |
| 1997 | Object Normal Forms and Dependency Constraints for Object-Oriented SchemataabstractWe address the development of a normalization theory for object-oriented data models that have common features to support objects. We first provide an extension of functional dependencies to cope with the richer semantics of relationships between objects, called path dependency, local dependency, and global dependency constraints. Using these dependency constraints, we provide normal forms for object-oriented data models based on the notions of user interpretation (user-specified dependency constraints) and object model . In constrast to conventional data models in which a normalized object has a unique interpretation, in object-oriented data models, an object may have many multiple interpretations that form the model for that object. An object will then be in a normal form if and only if the user's interpretation is derivable from the model of the object. Our normalization process is by nature iiterative, in which objects are restructured until their models reflect the user's interpretation. Zahir Tari, John Stokes, Stefano Spaccapietra |
ACM Trans. Database Syst. | 1 |
| 1996 | Security Enforcement in the DOK Federated Database System
Zahir Tari, George Fernandez |
DBSec | 1 |
| 1996 | A Framework for Method Evolution and Behavior Consistency in Object-Oriented DatabasesabstractThis paper addresses the problem of method evolution in object-oriented databases. We propose a set of evolutionary operations that affect all parts of methods, the signature and the implementation. When a restructuring operation is applied to a schema, behavioral consistency is checked by constructing a proof of program correctness. Two levels of granularity for behavioral consistency are described. The first level relates to the evolution of methods in the context of class inheritance hierarchy and is concerned with the semantics of the polymorphism of methods. The second level relates to behavioral evolution in which the chain of calling relationships between methods is considered. Behavioral consistency is checked with a graph-based approach that deals with problems such as run-time type errors, side-effects, redundant methods, and unexpected behaviors. Zahir Tari |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 1995 | An Overview of Reflection and Its Use in CooperationabstractThis paper describes a number of approaches to the development of more intelligent and more adaptable software. The paper introduces the notion of reflection and surveys two major styles: task and programming reflection. The paper then introduces a new form, viz operational reflection, based on the integration of these styles. This form of reflection is applied to cooperative environments and enables local database systems to be surrounded by a layer of meta-level software. This is used to capture domain and operational knowledge, and to describe, at least in part, remote systems and to monitor task-oriented activities. Thus we can turn a set of discrete database systems into a cooperative environment. David Edmond, Mike P. Papazoglou, Zahir Tari |
Int. J. Cooperative Inf. Syst. | 3 |
| 1994 | Consistency Checking of Evolving Methods
Zahir Tari |
DEXA | 2 |
| 1994 | Method Restructuring and Consistency Checking for Object-Oriented Schemas
Zahir Tari |
ER | 1 |
| 1993 | ERC++: A Conceptual Data Model Based on Object and Logic ParadigmsabstractArticle ERC++: a model based on object and logic paradigms Share on Author: Zahir Tari School of Information Systems, Queensland University of Technology, GPO Box 2434, Australia School of Information Systems, Queensland University of Technology, GPO Box 2434, AustraliaView Profile Authors Info & Claims CIKM '93: Proceedings of the second international conference on Information and knowledge managementDecember 1993 Pages 625–634https://doi.org/10.1145/170088.170443Online:01 December 1993Publication History 0citation201DownloadsMetricsTotal Citations0Total Downloads201Last 12 Months1Last 6 weeks0 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access Zahir Tari |
CIKM | 1 |
| 1992 | Designing Object-Oriented Databases with a Semantic Data Model and a Rule Model
Zahir Tari |
DEXA | 1 |
| 1992 | SUPER - Visual Interaction with an Object-Based ER Model
Annamaria Auddino, Yves Dennebouy, Yann Dupont, Edi Fontana, Stefano Spaccapietra, Zahir Tari |
ER | 6 |
| 1992 | A Design Methodology for Object Oriented Databases
Zahir Tari |
ER | 1 |