In this letter, we propose three schemes designed to detect attacks over the air interface in cellular networks. These decision rules rely on the generalized likelihood ratio test, and are fed by data that can be acquired using common off-the-shelf receivers. In addition to more classical (barrage/smart) noise jamming attacks, we further assess the capability of the proposed schemes to detect the stealthy activation of a rogue base station. The evaluation is carried out through an experimentation of a LTE system concretely reproduced using Software-Defined Radios. Illustrative examples confirm that the proposed schemes can effectively detect air interface threats with high probability.
"Geographic Load Balancing" is a strategy for reducing the energy cost of data centers spreading across different terrestrial locations. In this paper, we focus on load balancing among micro-datacenters powered by renewable energy sources. We model via a Markov Chain the problem of scheduling jobs by prioritizing datacenters where renewable energy is currently available. Not finding a convenient closed form solution for the resulting chain, we use mean field techniques to derive an asymptotic approximate model which instead is shown to have an extremely simple and intuitive steady state solution. After proving, using both theoretical and discrete event simulation results, that the system performance converges to the asymptotic model for an increasing number of datacenters, we exploit the simple closed form model's solution to investigate relationships and trade-offs among the various system parameters.
S. Sciancalepore∗, A. Capossele†, G. Piro∗, G. Boggia∗ and G. Bianchi‡ ∗Dep. of Electrical and Information Engineering (DEI), Politecnico di Bari, Italy; e-mail: {name.surname}@poliba.it. † Department of Computer Science “Sapienza”, University of Rome, Italy; e-mail: capossele@di.uniroma1.it ‡ Department of Electronic Engineering, University of Rome 2 “Tor Vergata”, Italy; e-mail: giuseppe.bianchi@uniroma2.it
OpenState targets programmability of stateful forwarding at data plane. OpenState challenges the following question: can we devise a pragmatic, OpenFlow-like, approach for programming forwarding behaviors inside the switch? In other words, can we deploy dynamic forwarding rules inside the fast data path, capable of autonomously and “instantaneously” change in the switch at the occurrence of packetlevel events, opposed to today’s OpenFlow forwarding states which are changed only through the (slow path) controller’s involvement? We implemented OpenState as an OpenFlow extension. We present here two applications showing the benefits of a stateful data plane.
The recent evolution of the Internet towards "Information-centric" transfer modes has renewed the interest in characterizing multi-cache systems, in which requests not satisfied by a cache are forwarded to other caches. In this work, we characterize the traffic statistics of the output (miss) stream, via a simple but accurate approximate analysis for LRU caches feeded by general "renewal" traffic patterns. In turn, we exploit such output stream traffic pattern to analyze the performance of the subsequent cache stage, and so on. The computational efficiency of our model, joint with its ability to handle traffic patterns beyond the traditional independent reference model, permits simple and tractable assessment of cache hierarchies.
Mobile networks for Internet Access are a fundamental segment of Internet access networks, where resource optimization are really critical because of the limited bandwidth availability. While traditionally resource optimizations have been focused on high efficient modulation and coding schemes, to be dynamically tuned according to the wireless channel and interference conditions, it has also been shown how medium access schemes can have a significant impact on the network performance according to the application and networking scenarios. This thesis work proposes an architectural solution for supporting Medium Access Control (MAC) reconfigurations in terms of dynamic programming and code mobility. Since the MAC protocol is usually implemented in firmware/hardware (being constrained to very strict reaction times and to the rules of a specific standard), our solution is based on a different wireless card architecture, called Wireless MAC Processor (WMP), where standard protocols are replaced by standard programming interfaces. The control architecture developed in this thesis exploits this novel behavioral model of wireless cards for extending the network intelligence and enabling each node to be remotely reprogrammed by means a so called “MAC Program”, i.e. a software element that defines the description of a MAC protocol. This programmable protocol can be remotely injected and executed on running network devices allowing on-the-fly MAC reconfigurations. This work aim to obtain a formal description of the a software defined wireless network requirements and define a mechanism for a reliable MAC program code mobility throw the network elements, transparently to the upper-level and supervised by a global control logic that optimizes the radio resource usage; it extends a single protocol paradigm implementation to a programmable protocol abstraction and redefines the overall wireless network view with support for cognitive adaptation mechanisms. The envisioned solutions have been supported by real experiments running on different WMP prototypes , showing the benefits given by a medium control infrastructure which is dynamic, message-oriented and reconfigurable.
Many effective approaches are proposed for adapting the wireless devices' operation to specific contexts and services, but only a few of them can be really implemented in the actual wireless interfaces. The road to accommodate necessary and advocated improvement of wireless technologies goes through the rethinking of the current protocol stacks, pushing the programmability of the system towards the physical interface. New architectures proposed for wireless interfaces provide great flexibility obtained through the rationalization and modularization of existing solutions. However the effective exploitation of this flexibility is closely related with the implementation of a suitable infrastructure able to support the dynamic composition of elementary functions. In this paper we present an information management framework that greatly simplifies the data sharing among the components of a wireless stack designed according to a modular and flexible architecture. The designed information management framework enforces a data model that accounts for synchronous and asynchronous interactions, protection of values and includes a consistent memory management approach. A prototype implementation has been integrated in the wireless stack of the Linux kernel, as an extension of the mac80211 framework.
Performance evaluation of caching systems is an old and widely investigated research topic. The research community is once again actively working on this topic because the Internet is evolving towards new transfer modes, which envisage to cache both contents and instructions within the network. In particular, there is interest in characterizing multi-cache systems, in which requests not satisfied by a cache are forwarded to other caches. In this field, this paper contributes as follows. First, we devise a simple but accurate approximate analysis for caches fed by general "renewal" traffic patterns. Second, we characterize and model the traffic statistics for the output (miss) stream. Third, we show in the simple example case of tandem caches how the resulting output stream model can be conveniently exploited to analyze the performance of subsequent cache stages. The main novelty of our work stems in the ability to handle traffic patterns beyond the traditional independent reference model, thus permitting simple assessment of cascade of caches as well as improved understanding of the phenomena involved in cache hierarchies.
Programmable wireless platforms aim at responding to the quest for wireless access flexibility and adaptability. This paper introduces the notion of wireless MAC processors. Instead of implementing a specific MAC protocol stack, Wireless MAC processors do support a set of Medium Access Control “commands” which can be run-time composed (programmed) through software-defined state machines, thus providing the desired MAC protocol operation. We clearly distinguish from related work in this area as, unlike other works which rely on dedicated DSPs or programmable hardware platforms, we experimentally prove the feasibility of the wireless MAC processor concept over ultra-cheap commodity WLAN hardware cards. Specifically, we reflash the firmware of the commercial Broadcom AirForce54G off-the-shelf chipset, replacing its 802.11 WLAN MAC protocol implementation with our proposed extended state machine execution engine. We prove the flexibility of the proposed approach through three use-case implementation examples.
Application layer centralized business players, such as search engines, have revolutionized the Internet, by smartly mediating between the users' generic interests and the specific resources returned. Meanwhile, networks consistently neglect the human nature of demand, and persist in handling a-priori offered load expressed in terms of requests for precisely identified network resources. A twofold paradox emerges: users remain unaware of cost/performance convenient, ”network-nearby”, resource alternatives well fitting their needs; networks, oblivious to such fitting, persist in serving ”network-far-away” resources. A foundational rethinking of human generated workload as something which may adapt to, and be shepherded by the network operation, could bring about significant network performance and service quality benefits, as well as new business opportunities. Our thesis is that the network operation should proactively assist the human user in her resource addressing decisions, by providing meant-for-human feedbacks on network-convenient resource alternatives. We could be at the dawn of a new intriguing interdisciplinary area, where the intrinsic ability of individuals to adapt their decision making and online behavior merges with the network operation itself, and becomes crucial in resource-constrained mobile networks.
In future HEP experiments the increased luminosity and the need of higher detector performance will push toward severe requirements on radiation hardness and power dissipation of hardware components. The use of “standard” and flexible protocols, modular architectures and IP-cores available to ASIC and FPGA designers will contribute to meet these requirements, while keeping development and production costs under control. The goal of the FF-LYNX project is the definition of a flexible protocol that allows the use of the same physical serial links and interfaces for the transmission of Timing, Trigger and Control (TTC) signals and Data Acquisition (DAQ). The protocol has been implemented in TX and RX interfaces based on serial electrical links designed as IP Cores. A test chip has been fabricated in the IBM 130nm CMOS technology. The architecture of the test interface and of the test chip will be presented together with preliminary results on area, speed and power consumption. Also the performance in terms of total ionization dose rad-tolerance will be reported.
Cross-domain Internet-scale collaborative security is affected by a native dichotomy. On one side, sharing of monitoring data across domains may significantly help in detecting large scale threats and attacks; on the other side, data sharing conflicts with the need to protect network customers' privacy and confidentiality of business and operational information. The approach first proposed in this paper enables what we call “conditional data sharing”, i.e., permit cross-domain sharing of fine-grained organized subsets of network security data (called monitoring data feeds), only when a threshold number of domains are ready to reveal their data for the same feed. The proposed approach revolves on a careful combination of distributed threshold based cryptography with identity-based encryption. It appears scalable and easy to deploy, not requiring neither a-priori monitoring data feeds identification, nor explicit coordination among domains. Protection is accomplished by “simply” using different cryptographic keys per feed, and automatically permitting per-feed key reconstruction upon the occurrence of independent and asynchronous per-domain/per-feed alerts.
The FF-LYNX project aims at the definition of a flexible protocol that can handle both the distribution of Timing, Trigger and Control (TTC) signals and the data acquisition in future High Energy Physics (HEP) experiments. The implementation of this protocol in digital interfaces designed and produced in standard CMOS technologies (130 and/or 90nm) and available as “IP cores” is also foreseen.
Thanks to its in-network drop-based adaptation capabilities, H.264 Scalable Video Coding is perceived as an effective approach for delivering video over networks characterized by sudden large bandwidth fluctuations, such as Wireless LANs. Performance may be boosted by the adoption of application-aware/cross-layer schedulers devised to intelligently drop video data units (NALUs), so that i) decoding dependencies are preserved, and ii) the quality perceived by the end users is maximized. In this paper, we provide a theoretical formulation of a QoE utility-optimal cross-layer scheduling problem for H.264 SVC downlink delivery over WLANs. We show that, because of the unique characteristics of the WLAN MAC operation, this problem significantly differs from related approaches proposed for scheduled wireless technologies, especially when the WLAN carries background traffic in the uplink direction. From these theoretical insights, we derive, design, implement and experimentally assess a simple practical scheduling algorithm, whose performance is very close to the optimal solution.
An important requirement in high speed network monitoring is the fast and scalable identification of heavy-hitters, traffic flows whose generation rate exceeds some pre-established peak or mean rate conditions. This problem has been addressed in the past through the design of approximate counters, derived from counting Bloom filters, capable of performing this task without the need to keep per-flow state. This paper presents an enhancement to the primitive operation used in this approach. We demonstrate an approximate excess rate detector, which exhibits faster operation and significant memory savings. Our construction can detect both flows which exceed a given average long term transmission rate as well as burst patterns exceeding a predetermined configuration threshold. We show that there exists a tight relationship between the configuration parameter of an approximate excess rate detector and that of a token bucket. We further provide dimensioning guidelines highlighting the detector's relationship with the aggregate traffic rate and the number of hitters.
The FF-LYNX protocol provides an innovative solution for the integrated distribution of Timing, Trigger and Control signals and the data readout in future High Energy Physics experiments. Transmitter and receiver interfaces implementing the FF-LYNX protocol have been simulated with a high-level simulator and in an FPGA based emulator. The design of the interfaces in a commercial CMOS technology as radiation tolerant and low power modules is ongoing and the submission of a test circuit is foreseen in fall 2010. The key features of the protocol are described in this paper as well as its possible application for the transmission from Silicon Trackers to trigger processors with short and constant latency of data to be used for the L1 trigger generation.
The indiscriminate collection and processing of all traffic carried via high speed networks poses a serious threat to the privacy of network users. In early results of the PRISM project, we have proposed an approach for cryptographically protecting, directly on the network monitoring probe, captured traffic on a per-flow basis, and permitting decryption only for the specific flows for which an anomalous behavior is suspected. This new work shows the viability of such an approach, by documenting a gigabit-speed hardware implementation of the underlying cryptographic techniques. In addition to ordinary symmetric encryption, these include i) dynamic and stateless generation of per-flow encryption keys, and ii) delivery of decryption keys in the form of Shamir's secret shares computed over on-the-fly generated Shamir's per-flow polynomials. To the best of our knowledge, this is the first work which applies a Shamir secret sharing scheme at such high throughput rates.
The FF-LYNX project, aimed at the design of an innovative data transmission protocol for high energy physics experiments and its implementation in rad-hard, low-power interfaces, is described in this document. An outline of the present project status and results is presented, as well as the foreseen future activity.
The FF-LYNX project aims at the definition of a flexible protocol for the distribution of Timing, Trigger and Control (TTC) signals and for the readout in future High Energy Physics (HEP) experiments and its implementation in radiation tolerant and low power interfaces designed and developed in standard CMOS technologies (130 nm-90 nm) and available as IP cores to designers of integrated circuits. The results of the first year of activity and future plans are here presented.
Flaminio Borgonovo合作论文数Dipartimento di Elettronica e Informazione, Politecnico di Milano6