The Experts below are selected from a list of 318 Experts worldwide ranked by ideXlab platform
Lili Qiu - One of the best experts on this subject based on the ideXlab platform.
-
Opportunistic Routing for Interactive Traffic in Wireless Networks
2010 IEEE 30th International Conference on Distributed Computing Systems, 2010Co-Authors: Tianji Li, Douglas Leith, Lili QiuAbstract:To take advantage of the broadcast nature of wireless communication, a number of opportunistic routing protocols have recently been proposed. In order to manage the extra signaling overhead associated with operation of the opportunistic routing, these schemes work in terms of `batches' that consist of multiple packets. While these opportunistic protocols can dramatically improve the total throughput, the use of batches means that they are best suited to bulk UDP transfer. However, in the Internet and wireless networks, the vast majority of the Traffic is Interactive (e.g., TCP/VoIP which requires close interactions and feedback between the two communicating end points). To effectively support Interactive Traffic, we develop a new opportunistic routing protocol, called RIPPLE. RIPPLE uses an expedited multi-hop transmission opportunity mechanism to achieve low signaling overhead and eliminate re-ordering, and uses a two-way packet aggregation technique to further reduce overhead. We implement the RIPPLE in NS-2 along with several existing routing protocols, including predetermined routing, shortest path routing, the early version of ExOR, MCExOR, and an IEEE 802.11n-like single-hop packet aggregation scheme called AFR. We compare their performance for long-and short-lived TCP transfers and VoIP Traffic over a wide range of network conditions, including varying wireless channel states, collision levels, and types of network topologies. Our results show that the RIPPLE scheme consistently achieves 100\% – 300\% performance gains over other approaches.
-
ICDCS - Opportunistic Routing for Interactive Traffic in Wireless Networks
2010 IEEE 30th International Conference on Distributed Computing Systems, 2010Co-Authors: Douglas J. Leith, Lili QiuAbstract:To take advantage of the broadcast nature of wireless communication, a number of opportunistic routing protocols have recently been proposed. In order to manage the extra signaling overhead associated with operation of the opportunistic routing, these schemes work in terms of `batches' that consist of multiple packets. While these opportunistic protocols can dramatically improve the total throughput, the use of batches means that they are best suited to bulk UDP transfer. However, in the Internet and wireless networks, the vast majority of the Traffic is Interactive (e.g., TCP/VoIP which requires close interactions and feedback between the two communicating end points). To effectively support Interactive Traffic, we develop a new opportunistic routing protocol, called RIPPLE. RIPPLE uses an expedited multi-hop transmission opportunity mechanism to achieve low signaling overhead and eliminate re-ordering, and uses a two-way packet aggregation technique to further reduce overhead. We implement the RIPPLE in NS-2 along with several existing routing protocols, including predetermined routing, shortest path routing, the early version of ExOR, MCExOR, and an IEEE 802.11n-like single-hop packet aggregation scheme called AFR. We compare their performance for long-and short-lived TCP transfers and VoIP Traffic over a wide range of network conditions, including varying wireless channel states, collision levels, and types of network topologies. Our results show that the RIPPLE scheme consistently achieves 100\% – 300\% performance gains over other approaches.
Negar Kiyavash - One of the best experts on this subject based on the ideXlab platform.
-
Multi-Flow Attacks Against Network Flow Watermarks: Analysis and Countermeasures
arXiv: Cryptography and Security, 2012Co-Authors: Negar Kiyavash, Amir Houmansadr, Nikita BorisovAbstract:In this paper, we analyze several recent schemes for watermarking network flows that are based on splitting the flow into timing intervals. We show that this approach creates time-dependent correlations that enable an attack that combines multiple watermarked flows. Such an attack can easily be mounted in nearly all applications of network flow watermarking, both in anonymous communication and stepping stone detection. The attack can be used to detect the presence of a watermark, recover the secret parameters, and remove the watermark from a flow. The attack can be effective even if different flows are marked with different values of a watermark. We analyze the efficacy of our attack using a probabilistic model and a Markov-Modulated Poisson Process (MMPP) model of Interactive Traffic. We also implement our attack and test it using both synthetic and real-world traces, showing that our attack is effective with as few as 10 watermarked flows. Finally, we propose possible countermeasures to defeat the multi-flow attack.
-
covert timing channels codes for communication over Interactive Traffic
International Conference on Acoustics Speech and Signal Processing, 2009Co-Authors: Negar Kiyavash, Todd P ColemanAbstract:This paper presents the first practical perfectly-secure steganography codes for covert communication via packet timings across Interactive Traffic relayed over network queuing systems. It has recently been shown that sparse-graph linear codes followed by shaping techniques, combined with message-passing decoding, can enable practical timing channel codes with low symbol error rates near the information capacity of the famous “Bits Through Queues” channel. Inspired by this new class of codes, we use an alternative shaping technique that employs random dithers and construct provably secure steganographic codes for communication using packet timings in Interactive Traffic. To validate the perfect secrecy of our steganographic codes, we model Interactive Traffic as a two-state Markov Modulated Poisson Process (MMPP) and show its goodness-of-fit.
-
ICASSP - Covert timing channels codes for communication over Interactive Traffic
2009 IEEE International Conference on Acoustics Speech and Signal Processing, 2009Co-Authors: Negar Kiyavash, Todd P ColemanAbstract:This paper presents the first practical perfectly-secure steganography codes for covert communication via packet timings across Interactive Traffic relayed over network queuing systems. It has recently been shown that sparse-graph linear codes followed by shaping techniques, combined with message-passing decoding, can enable practical timing channel codes with low symbol error rates near the information capacity of the famous “Bits Through Queues” channel. Inspired by this new class of codes, we use an alternative shaping technique that employs random dithers and construct provably secure steganographic codes for communication using packet timings in Interactive Traffic. To validate the perfect secrecy of our steganographic codes, we model Interactive Traffic as a two-state Markov Modulated Poisson Process (MMPP) and show its goodness-of-fit.
-
USENIX Security Symposium - Multi-flow attacks against network flow watermarking schemes
2008Co-Authors: Negar Kiyavash, Amir Houmansadr, Nikita BorisovAbstract:We analyze several recent schemes for watermarking network flows based on splitting the flow into intervals. We show that this approach creates time dependent correlations that enable an attack that combines multiple watermarked flows. Such an attack can easily be mounted in nearly all applications of network flow watermarking, both in anonymous communication and stepping stone detection. The attack can be used to detect the presence of a watermark, recover the secret parameters, and remove the watermark from a flow. The attack can be effective even if different the watermarks in different flows carry different messages. We analyze the efficacy of our attack using a probabilistic model and a Markov-modulated Poisson process (MMPP) model of Interactive Traffic. We also implement our attack and test it using both synthetic and real-world traces, showing that our attack is effective with as few as 10 watermarked flows. Finally, we propose a countermeasure that defeats the attack by using multiple watermark positions.
Ramon Agusti - One of the best experts on this subject based on the ideXlab platform.
-
mixing conversational and Interactive Traffic in the umts radio access network
Mobile and Wireless Communication Networks, 2002Co-Authors: J. Sanchez, Oriol Sallent, J Perezromero, Ramon AgustiAbstract:The definition and assessment of suitable radio resource management (RRM) strategies able to provide QoS in the framework of the UTRA segment of UMTS is a key issue for achieving the expectations created on 3G technology. This paper proposes and evaluates specific algorithms for the different RRM functions involved in the uplink direction in a scenario with a mixture of Interactive and conversational services. In particular the effect of prioritization of conversational users in the admission control has been analyzed in terms of admission, dropping probabilities and packet delay. Furthermore, the paper also studies the importance of suitable congestion control mechanisms that cope with load fluctuations in order to guarantee the negotiated QoS to already connected users. These fluctuations are mainly due to the randomness in the Traffic generation of Interactive users, that can seriously degrade performance of both conversational and even Interactive users if no congestion control is carried out.
-
MWCN - Mixing conversational and Interactive Traffic in the UMTS radio access network
4th International Workshop on Mobile and Wireless Communications Network, 2002Co-Authors: J. Sanchez, Jordi Perez Romero, Oriol Sallent, Ramon AgustiAbstract:The definition and assessment of suitable radio resource management (RRM) strategies able to provide QoS in the framework of the UTRA segment of UMTS is a key issue for achieving the expectations created on 3G technology. This paper proposes and evaluates specific algorithms for the different RRM functions involved in the uplink direction in a scenario with a mixture of Interactive and conversational services. In particular the effect of prioritization of conversational users in the admission control has been analyzed in terms of admission, dropping probabilities and packet delay. Furthermore, the paper also studies the importance of suitable congestion control mechanisms that cope with load fluctuations in order to guarantee the negotiated QoS to already connected users. These fluctuations are mainly due to the randomness in the Traffic generation of Interactive users, that can seriously degrade performance of both conversational and even Interactive users if no congestion control is carried out.
-
PIMRC - On managing uplink videophone and Web browsing Traffic in UTRA W-CDMA
14th IEEE Proceedings on Personal Indoor and Mobile Radio Communications 2003. PIMRC 2003., 1Co-Authors: Jordi Perez Romero, Oriol Sallent, N. Garcia, Ramon AgustiAbstract:This paper focuses on the interactions between uplink admission and congestion control strategies in UTRA-W-CDMA. The proposed strategies are analysed in the framework of a representative multiservice scenario where conversational and Interactive Traffic are present and the presented solutions are compliant with 3GPP UTRA FDD specifications. Furthermore, the results consider a complete approach where all the radio resource management strategies are taken into account, including admission, congestion, short term RRM, handover and power control feasible solutions. Therefore, obtained results allow to devise a range of guidelines for the joint design of RRM algorithms.
Jason But - One of the best experts on this subject based on the ideXlab platform.
-
ANGEL client manager software architecture design document
2007Co-Authors: Jason ButAbstract:The Automated Network Games Enhancement Layer (ANGEL) project aims to leverage Machine Learning (ML) techniques to automate the classification and isolation of Interactive (e.g. games, voice over IP) and non-Interactive (e.g. web) Traffic. This information is then used to dynamically reconfigure the network to improve the Quality of Service provided to the current Interactive Traffic flows and subsequently deliver improved performance to the end users. Within this scope, the project will develop protocols that allow the adjustment of Consumer Premise Equipment (CPE eg. cable/ADSL) configuration to provide better quality of service to Interactive flows detected in real-time. This document describes the basic design motivation of the Client Manager Software Component of ANGEL. The Client Manager is responsible for managing registration and de-registration of individual ANGEL-enabled CPE devices and then delivering flow classification information from the Flow Classifier to all registered users that are routing those flows.
-
ANGEL flow meter software architecture design document
2007Co-Authors: Jason ButAbstract:The Automated Network Games Enhancement Layer (ANGEL) project aims to leverage Machine Learning (ML) techniques to automate the classification and isolation of Interactive (e.g. games, voice over IP) and non-Interactive (e.g. web) Traffic. This information is then used to dynamically reconfigure the network to improve the Quality of Service provided to the current Interactive Traffic flows and subsequently deliver improved performance to the end users. Within this scope, the project will develop protocols that allow the adjustment of Consumer Premise Equipment (CPE eg. cable/ADSL) configuration to provide better quality of service to Interactive flows detected in real-time. This document describes the basic design motivation of the Flow Meter Software Component of ANGEL. The Flow Meter is responsible for capturing packets off a network connection, collating the statistical properties and forwarding this information to the Flow Classifier Component.
-
ANGEL flow classifier software architecture design document
2007Co-Authors: Jason ButAbstract:The Automated Network Games Enhancement Layer (ANGEL) project aims to leverage Machine Learning (ML) techniques to automate the classification and isolation of Interactive (e.g. games, voice over IP) and non-Interactive (e.g. web) Traffic. This information is then used to dynamically reconfigure the network to improve the Quality of Service provided to the current Interactive Traffic flows and subsequently deliver improved performance to the end users. Within this scope, the project will develop protocols that allow the adjustment of Consumer Premise Equipment (CPE eg. cable/ADSL) configuration to provide better quality of service to Interactive flows detected in real-time. This document describes the basic design motivation of the Flow Classifier Software Component of ANGEL. The Flow Classifier is responsible for analysing packet/flow statistics compiled by the system Flow Meter(s) to classify the flows in realtime, and then to forward any changes to Classification in any current flows to the Client Manager Component.
Rei Safavi-naini - One of the best experts on this subject based on the ideXlab platform.
-
ACSAC - Detecting Policy Violations through Traffic Analysis
2006 22nd Annual Computer Security Applications Conference (ACSAC'06), 2006Co-Authors: Jeffrey Horton, Rei Safavi-nainiAbstract:Restrictions are commonly placed on the permitted uses of network protocols in the interests of security. These restrictions can sometimes be difficult to enforce. As an example, a permitted protocol can be used as a carrier for another protocol not otherwise permitted. However, if the observable behaviour of the protocol exhibits differences between permitted and non-permitted uses, it is possible to detect inappropriate use. We consider SSH, the Secure Shell protocol. This is an encrypted protocol with several uses. We attempt firstly to classify SSH sessions according to some different types of Traffic for which the sessions have been used, and secondly, given a policy that permits SSH use for Interactive Traffic, to identify when a session appears to have been used for some other purpose.