
This paper presents an autonomic system for the monitoring of security-relevant information in a Grid-based operating system. Our approach is multi-layered. The first layer is security-agnostic, monitoring the states of processes and jobs. The second layer is security-aware, mon- itoring pre-defined security events and co-relating then using rule-based policies. Policies are capable of controlling the system environment based on changes in levels of CPU/memory usage, accesses to system resources, detection of abnormal behaviour such as DDos attacks.
The greatest challenge beyond trust and security for the long-term adoption of cloud computing is the interoperability between clouds. In the context of world-wide tremendous activities against the vendor lock-in and lack of integration of cloud computing services, keeping track of the new concepts and approaches is also a challenge. We considered useful to provide in this paper a snapshot of these concepts and approaches followed by a proposal of their classification. A new approach in providing cloud portability is also revealed.
Service-based Applications (SBAs) will increasingly be deployed in highly distributed and dynamic settings. To a large extent this dynamicity is caused by the trend to increasingly compose SBAs using third-party services. Those services are provided by external organizations and are thus not under the control of the SBA provider. For critical application domains (such as emergency or financial) and important customers (such as key accounts), the SBA developer needs to ensure that each individual SBA instance will live up to its expected requirements even though its constituent, third-party services might fail. To prevent such requirements violations, SBAs should be equipped with monitoring, prediction and adaptation capabilities which are able to foresee and avert menacing violations. Several approaches exploiting preventive adaptations have been presented in the literature, but they rely on the existence of cost models or comprehensive training data that limit their applicability in practice. In this paper we present SPADE, an automated technique that addresses those limitations. Based on assumptions about the SBA's constituent services (derived from SLAs), SPADE formally verifies the SBA against its requirements during run-time. The experimental evaluation of SPADE, using data collected for six real services, demonstrates its practical applicability in predicting violations of performance requirements.
In this demonstration, we show how the IBBT w-iLab.t wireless testbed, combined with multiple spectrum sensing engines designed by imec, can be used for experimentally-supported design and evaluation of cognitive networking protocols. Functionalities include the advanced characterization of the behavior of a cognitive solution under test, and characterization of the wireless experimentation environment itself.
The demonstration will show the live access to the control framework of a pan-European OpenFlow testbed. The testbed spans five islands all over Europe, allowing experimenters access not only to virtual machines but to the switches interconnecting them. This extends the control of networking experiments beyond best-effort overlays to a real control of the network, its routing and forwarding functions itself. A first video explaining the registration process and the setup of a slice for a new network experiment can be found here: http://www.youtube.com/watch?v=p482T9O9HOg. A tutorial explaining (in short video sequences) the registration and use of the testbed is online on http://www.fp7-ofelia.eu.
Almost all innovative applications in usage areas like energy, transport & logistics, healthcare rely on specific Information & Communication Technologies (ICT). These often need to fulfill very stringent requirements which cannot easily be fulfilled by today’s technologies. Developing usage area specific ICT solutions is not the solution since this prohibits benefiting from an economy of scale. Initiated by the European Commission (EC) the Future Internet Public Private Partnership (FI-PPP) has been setup to systematically identify ICT requirements from different usage areas and address as many of them as possible by so-called generic Future Internet / ICT enablers. Obviously, Smart Energy is a very important usage area which is addressed by the FI-PPP project FINSENY. This article will provide a detailed description of the project setup and its methodology.
In general, the use of adaptive services and adaptation frameworks for services is justified by the need of providing a flexible environment for service execution in changing environments, due to changes of context or changes in requirements. Such flexibility allows providing services in ways that are most suited to the current situation of invocation of the service. A parameter that is commonly used to assess the fitness of services in changing situations is quality of service, that commonly includes parameters such as, for instance, response time, availability, trust. Adaptivity can also be the basis for building dynamic service compositions driven by other types of goals, and in this talk the focus is on building adaptive services with the goal of improving energy efficiency. Energy efficiency is defined as the ability of a system to make an efficient use of the available resources. In variable and changing contexts the use of resources might be overprovisioned, in order to be able to cope with situations of system overload, maintaining the quality of service guarantees associated with a given service. As a result, in general we see a tradeoff between requirements imposed by quality of service and energy efficiency requirements. Adaptivity can help smoothing this tradeoff, since the services can be configured dynamically to exploit the available resources in a better way. We analyze energy efficiency in service compositions from two different perspectives. The first case is the execution of services in large service centers, in which services are executed dynamically sharing computing resources and storage systems. Such a case is studied in the GAMES (Green Active Management of IT Services) European project, in which IT resources are managed dynamically according to the context of execution and the characteristics of the services, which are driving adaptation policies. A second perspective is the use of dynamic services as enablers of energy efficiency strategies in given application domains, such as services in smart environments, e.g. in homes or buildings. In this case adaptive services can help reducing CO 2 emissions since the energy consuming resources can be controlled by adaptive services, based on the context which is providing information about the environment and behavior of inhabitants. Research directions in both perspectives require the ability to manage monitoring information dynamically, to ensure an adequate level of granularity of the information, and to model and control the components of the environment in order to provide adaptivity to support energy efficiency on one hand, and on the other hand to guarantee the quality of service required by the applications.
Service selection has been widely investigated as an effective adaptation mechanism that allows a service broker, offering a composite service, to bind each task of the abstract composition to a corresponding implementation, selecting it from a set of candidates. The selection aims typically to fulfill the Quality of Service (QoS) requirements of the composite service, considering several QoS parameters in the decision. We compare the performance of two representative examples of the per-request and per-flow approaches that address the service selection issue at a different granularity level. We present experimental results obtained with a prototype implementation of a service broker. Our results show the ability of the per-flow approach in sustaining an increasing traffic of requests, while the per-request approach appears more suitable to offer a finer customizable service selection in a lightly loaded system.
The rule and policy technological landscape is becoming ever more complex, with an extended number of specifications and products. It is therefore becoming increasingly difficult to integrate rule and policy driven components and manage interoperability in distributed environments. The described work presents an infrastructure going towards the governance of heterogeneous rule and policy driven components in distributed systems. The authors’ approach leverages on a set of middleware, discovery protocol, knowledge interchange and consolidation to alleviate the environment’s complexity.
The Future Internet will emerge through the convergence of software services, things, content, and communication networks. Service-orientation is expected to play a key role as enabling technology that allows the provisioning of hard- and software entities and contents as services. The dynamic composition of such services will enable the creation of service-oriented systems in the Future Internet (FI Apps), which will be increasingly provided by third parties. Together with increased expectations from end-users for personalization and customization, FI Apps will thus face an unprecedented level of change and dynamism. Based on our understanding of adaptive service-oriented systems, this paper discusses the key adaptation characteristics for FI Apps (illustrated by a concrete application domain). The importance of each of those characteristics has been empirically assessed by means of a survey study. We provide the results of this study which can help in better understanding where future research and development effort should be invested.
The Internet of Things plays a central role in the foreseen shift of the Internet to the Future Internet, as it incarnates the drastic expansion of the Internet network with non-classical ICT devices. It will further be a major source of evolution of usage, due to the penetration in the user's life. As such, we envision that the Internet of Things will cooperate with the Internet of Services to provide users with services that are aware of their surrounding environment. The supporting service-oriented middleware shall then abstract the functionalities of Things as services as well as provide the needed interoperability and flexibility, through a loose coupling of components and composition of services. Still, core functionalities of the middleware, namely service discovery and composition, need to be revisited to meet the challenges posed by the Internet of Things. Challenges in particular relate to the ultra large scale, heterogeneity and dynamics of the Internet of Things that are far beyond the ones of today's Internet of Services. In addition, new challenges also arise, pertaining to the physical-world aspect that is central to the IoT. In this paper, we survey the major challenges posed to service-oriented middleware towards sustaining a service-based Internet of Things, together with related state of the art. We then concentrate on the specific solutions that we are investigating within the INRIA ARLES project team as part of the CHOReOS European project, discussing new approaches to overcome the challenges particular to the Internet of Things.
International freight transport is the foundation of global trade, representing a large and growing industry where various stakeholders collaborate to transport goods around the world. The ICT infrastructures currently employed throughout logistics business networks are limited and the use of manual systems is common. This drastically hampers the operational efficiency of logistic service providers, carriers, and the various other stakeholders involved in transport processes. This paper presents an initial conceptual architecture for an ICT platform to overcome these deficiencies. The architecture is built on top of Future Internet technologies that provide generic capabilities for the efficient and effective development of cloud-based applications based on the Internet of Services, Internet of Things, and Internet of Contents with integrated security and privacy mechanisms.
This paper presents SeCMER, a tool for requirements evolution management developed in the context of the SecureChange project. The tool supports automatic detection of requirement changes and violation of security properties using change-driven transformations. The tool also supports argumentation analysis to check security properties are preserved by evolution and to identify new security properties that should be taken into account.
Currently, cloud databases serve as mainstream data storage mechanism for unstructured data, primarily because of their high scalability and ease of availability. However, as yet, they lag behind RDBMs in terms of their support to developers for querying the data. The problem of developing frameworks to support flexible data queries is a very active area of research. In this work we consider HBase, a popular cloud database, inspired by Google’s BigTable. Relying on the recent Coprocessor feature of HBase, we have developed a framework that developers can use to implement aggregate functions like row count, max, min, etc. We further extended the existing Coprocessor framework to support a Cursor functionality, so that a client can incrementally consume the Coprocessor generated result. We demonstrate the effectiveness of our extension by comparatively evaluating it against the existing Scanner API with four queries on three different data sets.
In this paper a concept and an architecture of the Federated Networks Protection System (FNPS) is proposed. The system components are described and, particularly, the Decision Module (FNPS-DM) is discussed. The major contributions of the paper are: concept of federated networks security, the proposition of the network events correlation approach and semantic notations aimed at detecting complex cyber attacks and 0-day exploits. Moreover P2P based communication between federated networks is proposed.
The support of stakeholders is critical to the success of any project, and is equally important in SOA-related projects. Traditional software development methodologies no longer meet the requirements for developing service-based applications, or SBAs, due to the shift away from monolithic application development to service provision and composition. This shift introduces more types of stakeholders, each of which can take multiple roles within the lifecycle of the SBA, and who have an interest in or are influenced by the service-oriented software process. To understand these stakeholder types and roles, this paper presents an initial set of stakeholder types and roles solicited from within the EC’s Network of Excellence in Software Services and Systems (S-Cube). By describing these stakeholder types in the context of the S-Cube service engineering lifecycle, we demonstrate the lifecycle phases each stakeholder and role is involved in during the development and operation of SBAs. The stakeholder roles and types found and the methodology we describe for their discovery aids the identification of the requirements for these stakeholders and contributes to research in service engineering methodologies.
UMA proposes a novel testing facility based on normal mobile devices as testing nodes, exposing their functionalities through a new technology agnostic control node (UMA controller). This solution will provide a scheme to deploy experiments not only on top of current mobile technologies (e.g. UMTS, HSPA...) but also over the upcoming LTE or LTE-Advanced standards as they are introduced in the market.
The utilisation of Grid and Cloud-based computing environments for solving scientific problems has become an increasingly used practice in the last decade. To ease the use of these global distributed resources, sophisticated middleware systems have been developed, enabling the transparent execution of applications by hiding low-level technology details from the user. The ASKALON environment is such a system, which supports the development and execution of distributed applications such as scientific workflows or parameter studies in Grid and Cloud computing environments. On the other hand, simulation is a widely accepted approach to analyse and further optimise the behaviour of software systems. Beside the advantage of enabling repeatable deterministic evaluations, simulations are able to circumvent the difficulties in setting up and operating multi-institutional Grid systems, thus providing a lightweight simulated distributed environment on a single machine. In this paper, we present the integration of the GroudSim Grid and Cloud event-based simulator into the ASKALON environment. This enables system, application developers, and users to perform simulations using their accustomed environment, thereby benefiting from the combination of an established real-world platform and the advantages of a simulation.