
Home network complexity is dramatically growing in terms of topology (devices and connectivity technologies) and services leading to increasingly challenging management issues. In this context, enabling a better visibility of home network traffic usage and performance is a crucial step to provide efficient self-care and customer care. In this paper, we study home network traffic monitoring architectural approaches. In particular, we study the feasibility of a Home Gateway based flow monitoring approach, which will allow enhancing home network diagnostic and performance tracking. Our experimental evaluation aims at providing a better understanding of deployment possibilities and limits. The obtained experimental results, based on an open source tool, are promising in terms of resource consumption (an average load of 6,6% and 18MB for CPU and memory respectively) as well as bandwidth utilization (average 156 Kbps) for typical DSL access speed scenario.
Nowadays, thanks to the increasing technologies, soldiers and vehicles are equiped with wireless technology to communicate on the battlefield. They form adhoc network and particularly Mobile Ad hoc Network (MANET). Since the battlefield is organized as a coalition, we are in front of a situation where several groups (nations mainly) want to connect to others and establish inter-MANET communication. Inter-MANET (or interdomain-MANET) communication should allow exchange, but maintain a supervision on the exchanged information. Several protocols have been designed in order to handle inter-domain routing for tactical MANETs. In this article, we describe these protocols and focus on the general issues they solve. Then, we compare the results of a simulator (NS3), an emulator (CORE) and a real platform (laptops) on simple network characteristics on Network and Data Link layers. We highlight behavioral differences between the three candidates and particularly softwares (NS3 and CORE). They create problems that do not exist in reality. Consequently, most existing protocols proposed in the litterature are more complex than they should be. Based on this comparison, we propose some guidelines to design Inter-domain routing protocols for MANET.
Wireless body area network (WBAN) has shown great potential in improving healthcare quality not only for patients but also for medical staff. However, security and privacy are still an important issue in WBANs especially in multi-hop architectures. In this paper, we propose and present the design and the evaluation of a secure lightweight and energy efficient authentication scheme BANZKP based on an efficient cryptographic protocol, Zero Knowledge Proof (ZKP) and a commitment scheme. ZKP is used to confirm the identify of the sensor nodes, with small computational requirement, which is favorable for body sensors given their limited resources, while the commitment scheme is used to deal with replay attacks and hence the injection attacks by committing a message and revealing the key later. BANZKP reduces the memory requirement by 56,13% compared to TinyZKP [16], the comparable alternative so far for Body Area Networks. Also, the simulation results demonstrate that our proposed scheme is 17 and 5 times more efficient in term of execution time, and uses 94.11% and 80% less energy compared to TinyZKP and W-ECDSA [25], respectively.
The explosive trend of smartphone usage as the most effective and convenient communication tools of human life in recent years make developers build ever more complex smartphone applications. Gaming, navigation, video editing, augmented reality, and speech recognition applications require considerable computational power and energy. Although smart-phones have a wide range of capabilities - GPS, WiFi, cameras - their inherent limitations - frequent disconnections, mobility and significant constraints - size, lower weights, longer battery life - make difficult to exploiting their full potential to run complex applications. Several research works have proposed solutions in application offloading domain, but few ones concerning the highly changing properties of the environment. To address these issues, we realize an automated application offloading middleware, ACOMMA, with dynamic and re-adaptable decision-making engine. The decision engine of ACOMMA is based on an ant-inspired algorithm.
This paper is a first attempt to define a set of security vulnerabilities for the Internet of Things (IoT), in a corporate environment, in order to classify various connected objects based on a taxonomy that was previously proposed. The IoT is a complex infrastructure that we divide in four parts (objects, transport, storage, interfaces). It needs protection and supervision. The object and its ecosystem are surrounded with other devices that can become entry points or targets of attacks, even if they are protected from the outer world but not from their local environment. We study the impact of attacks (such as OS reprogramming that has been recently published) on connected thermostats and their possible consequences on their environment, as a first approach to a threat analysis for the IoT.
6LowPAN was introduced by the IETF as a standard protocol to interconnect tiny and constrained devices across IPv6 clouds. 6LowPAN supports a QoS feature based on two priority bits. So far, little interest has been granted and this QoS feature and there are no implementations of such feature in real networks. In this paper, we evaluate the effectiveness of these priority bits in various scenarios. We show that under very heavy or very low network load, these bits have a limited effect on the delay
We present Acadoop, a lightweight MapReduce framework, which offers the main features of the Hadoop framework, and follows its architecture. The purpose of this lightening is mainly educational : it aims at enabling students to understand more easily the design of such frameworks, and to experiment with the behaviour of the applications that run on these frameworks. A further benefit of this lightening is that Acadoop provides a simple tool for prototyping and assessing scheduling policies for the MapReduce framework. We give a few simple examples of comparisons between scheduling policies, in order to illustrate Acadoop's possibilities with regard to both education and prototyping. In conclusion, we present the context in which Acadoop was developped, and present some lines for further improvement.
In this paper, we propose an optimization approach for designing WLAN networks in an Indoor environment. This approach integrates all relevant parameters to find the optimal placement of access points, there optimum settings (transmission power, azimuth, radiation patterns, etc.) and the optimal allocation of channels while maximizing the coverage, minimizing the interference and minimizing the number of access points to install. Our approach was evaluated when planning a WLAN 802.11an with a 5GHz band and 20MHz bandwidth on a 5-story building. The results show the effectiveness of our approach to quickly plan a high quality WLANs.
The average Web Page size is constantly increasing: it doubled between January 2012 and January 2015 [1]. In such a context the transport of the Internet traffic becomes very challenging. To moderate the impact of the increase of traffic on end-users' Quality of Experience (QoE), the IETF specified the protocol HTTP2, which optimizes the transfer of the HTTP1 protocol. In this paper we provide a comparison of HTTP1 and HTTP2, both in terms of functionalities and in terms of Page Download Time (PDT). As end-to-end encryption is not always required, this comparison is provided in-the-clear. To avoid any bias in the comparison, our measurements are made with the same hardware, the same software and the same transport conditions (multiplexing over a single TCP connection per domain). Based on our measurement, we show that HTTP2 always highlights better performances that HTTP1. More precisely, we observe the HTTP2 PDT remains 15% lower than HTTP1 PDT as the network delay increases. Furthermore, we observe that the ratio of HTTP2 PDT to HTTP1 PDT decreases as the packet loss increases, showing that HTTP2 is more resilient to packet loss than HTTP1.
Today authentication has become a major challenge in mobile cloud computing. Using a static password for authentication in cloud provider presents several security drawbacks: passwords can be forgotten, guessed, written down and stolen, eavesdropped or deliberately being told to other people. In this article, we propose a solution in order to improve authentication in mobile cloud computing and mainly resolves men in the middle attack. This solution is inspired by the authentication algorithms studied in 3G (the 3rd Generation) and TLS (Transport Layer Security) to secure the data exchanged in the network. These algorithms ensure a strong authentication before stating the communication. However, a sensitive data in the network can also be exchanged during the communication. To ensure a strong authentication during a communication, the multi-scale Situation Identification from Context (muSIC) system is used to detect the suspect behavior of the users.
The topic of this paper is to propose a new network design algorithm which defines an efficient multi-path routing scheme in an MLPS network. Our goal is to offer QoS guarantees for delay and jitter which are considered as important performance metrics for interactive and real time services. To this end, we have formulated several nonlinear objective functions for determining network link utilization as well as traffic flow routing through the network. Several issues are described and simulations are performed in order to evaluate our model. Furthermore, we have proposed three load balancing modules: one which minimizes the network link utilization and offers performance guarantee in terms of delay. The second model aims to select feasible paths by taking into account the characteristics and behavior of the jitter by defining the splitting scheme. The third one is a general model based on the two previous algorithms which defines the routing scheme for traffic sensitive to delay and jitter. Finally, our model is compared to other multi-path routing algorithms, and the results showed a significant improvement of QoS parameters and network link utilization than these models.
Besides the increasing complexity, real time behavior and dynamic evolution are other critical challenges imposed by the RT-DS (Real Time Distributed Systems) design. Component Based Software Engineering, as well as Model Driven Engineering may offer well-suited software development methodologies to tackle these challenges. This paper proposes and explains, through a realistic application, a hybrid approach, based on the main artifacts of MDA techniques and formal methods, for specifying and thereafter analyzing RT-DS. First, we provide DySAM*, as an extension with time dependent features of DySAM (Dynamic Software Architecture Meta-model) proposed in a previous work. Then, we integrate DySAM* in K-Maude tool in order to define the operational semantics of DS that deal with temporal features. This has the advantage to make possible both, system execution and temporal properties verification, in transparent manner.
Not all header fields in IP packets are used simultaneously during transmissions. Some fields may provide traceback services, especially for the defense against DDoS attacks. In this paper, we analyze which IP header fields may be used without impacting the other services provided by the IP protocol. We also analyze how unused fields can be filled for the purpose of traceback, and with what probability can a router mark packets. Finally we compare the different existing methods for packet marking based on the fields used and marking information.
Cloud computing allows to move computing and storage components from individual systems into the cloud, which provides software and hardware services over the Internet. A collaborative application is among software services that can be provided by the cloud computing to enable collaboration among users from the same or different tenants. In this context, security of the shared resources in a collaborative session becomes an important issue that must be addressed. This paper proposes an approach that ensures access control to the shared resources in a collaborative session in single tenant environments. The suggested approach introduces new entities and relationships to support collaborative sessions in single-tenant environments. Finally, we validate this approach by an implementation in the SwiftStack environment.
Despite the agreement on the Wireless Mesh Networks impact as a flexible way to provide Internet connections with low cost, they still suffer from some limits that degrade their performance, resulting from their Wireless/multihop nature. Using multiple paths principale and an appropriate Channels Assignment process may confront one of the most encountered problems in wireless communication field, known as interference. In this article, we'll focus on this limit using formal methods. To do so, we opt for Bigraphical Reactive Systems with nodes sharing (BRS with sharing) as a basic formalism to specify the WMN topology on one hand, and the rational channels assignment process (AC) in the multi-interfaces/multi-channels environment, on the other hand.
In this paper we introduce a Domaine Specific Language called Compose. This language allows composing heterogeneous remote services. The domain of this language is Scientific Research Reproducibility. The main advantage of this language is its simplicity. In fact, this language is designed to be used by Business Domain Experts, in opposite to other business process composition languages, which are designed to be used by software experts. Furthermore, the design of this language covers the whole software application lifecycle. This includes specification phase, development phase and deployment phase, while transparently integrating the fault tolerance mechanisms necessary for each phase. It can also be used in association with other programming languages.
Network virtualization allows to establishing multiple independent logical networks through resource sharing of the underlying substrate network. To ensure optimal deployment of virtual networks, one has to find an effective mapping between logical resources claimed by the virtual networks and the physical resources belonging to the substrate network. This mapping problem, called VNE (Virtual Network Embedding), is NP complete, and is extensively treated in the literature. To ensure service continuity even after a failure, the virtual networks must implement protection. One of the major issues and challenges is to optimize the resources allocated in the substrate network for the purpose of the protection of virtual networks. In this paper, we first present the main VNE approaches and the traditional network protection schemes. We then provide a synthetic and critical analysis of methods to protect virtual networks.
The Trickle algorithm is the principal solution for information dissemination in Wireless Sensor Networks. Trickle controls the timing and suppression of application messages. For example, Routing Protocol for Low-Power and Lossy Networks (RPL) uses it to govern dissemination of control overhead. Key parameter of Trickle is the redundancy constant that defines if a message transmission should be suppressed, based on the number of receptions. Existing work in the literature and real-world deployments utilize a single redundancy constant for the network. We analytically study Trickle and derive a model to estimate the transmission load for each node with its own redundancy constant. We show that single redundancy constant leads to higher transmission load for nodes with less neighbors and propose a heuristic algorithm that calculates the redundancy constant locally at each node as a function of its number of neighbors. The strategy of locally calculating the redundancy constant at each node allows us to improve fairness in the network and thus prolong the network lifetime. We validate our analytic results using instruction-level emulations in Contiki and Cooja.
Peripheral devices working in the context of the Internet of Things, specifically sensors, produce large amounts of data that can be used to infer knowledge. In this area, machine learning technologies are increasingly used to establish versatile models. In this article, we present a new architecture capable of running machine learning algorithms in a sensor network. This approach has advantages in terms of confidentiality and energy efficiency-related data transfer. First, we argue that some types of machine learning algorithms are consistent with this approach, particularly those based on the use of generative algorithms. Subsequently we detail our proposed architecture based on Internet of Things and Web of Things paradigms facilitating the integration in sensor networks. The convergence of generative models and Web Objects leads to the concept of virtual sensors exposing high-level knowledge using data from various sensors. Finally, we demonstrate the feasibility and performance of our proposal using a real scenario.
Given the ever changing needs of the job markets, education and training centers are increasingly held accountable for student success. Therefore, education and training centers have to focus on ways to streamline their offers and educational processes in order to achieve the highest level of quality in curriculum contents and managerial decisions. Educational process mining is an emerging field in the educational data mining (EPM) discipline, concerned with developing methods to discover, analyze and provide a visual representation of complete educational processes. In this paper, we present our distributed computation platform, under construction, which allows different education centers and institutions to load their data and access to advanced data mining and process mining services. To achieve this, we present also a comparative study of the different clustering techniques developed in the context of process mining to partition efficiently educational traces. Our goal is to find the best strategy for distributing heavy analysis computations on many processing nodes of our platform.