IMDEA Networks Institute Digital Repository
Not a member yet
1915 research outputs found
Sort by
LOKO: Localization-aware Roll-out Planning for Future Mobile Networks
The roll-out phase of the next generation of mobile networks (5G) has started and operators are required to devise deployment solutions while pursuing localization accuracy maximization. Enabling location-based services is expected to be a unique selling point for service providers now able to deliver critical mobile services, e.g., autonomous driving, public safety, remote operations. In this paper, we propose a novel roll-out base station placement solution that, given a Throughput-Positioning Ratio (TPR) target, selects the location of new-generation base stations (among available candidate sites) such that the throughput and localization accuracy are jointly maximized. Moving away from the canonical position error bound (PEB) analysis, we develop a realistic framework in which each positioning measurement is affected by errors depending upon the actual wireless channel between the measuring base station and the target device. Our solution, referred to as LOKO, is a fast-converging algorithm that can be readily applied to current 5G (or future) roll-out processes. LOKO is validated by means of an exhaustive simulation campaign considering real existing deployments of a major European network operator as well as synthetic scenarios.TRUEpu
HALE-IoT: HArdening LEgacy Internet-of-Things devices by retrofitting defensive firmware modifications and implants
Internet-Of-Things (IoT) devices and their firmware
are notorious for their lifelong vulnerabilities. As device infection
increases, vendors also fail to release patches at a competitive
pace. Despite security in IoT being an active area of research,
prior work has mainly focused on vulnerability detection and
exploitation, threat modelling, and protocol security. However,
these methods are ineffective in preventing attacks against legacy
and End-Of-Life devices that are already vulnerable. Current
research mainly focuses on implementing and demonstrating the
potential of malicious modifications. Hardening emerges as an
effective solution to provide IoT devices with an additional layer
of defense.
In this paper, we bridge these gaps through the design
of HALE-IoT, a generically applicable systematic approach to
HArdening LEgacy IoT non-low-end devices by retrofitting
defensive firmware modifications without access to the original source code.
HALE-IoT approaches this non-trivial task
via binary firmware reversing and modification while being
underpinned by a semi-automated toolset that aims to keep
cybersecurity of such devices in a hale state. Our focus is on
both modern and, especially, legacy or obsolete IoT devices as
they become increasingly prevalent. To evaluate the effectiveness
and efficiency of HALE-IoT, we apply it to a wide range of
IoT devices by retrofitting 395 firmware images with defensive
implants containing an intrusion prevention system in the form
of a Web Application Firewall (for prevention of web-attack
vectors), and an HTTPS-proxy (for latest and full end-to-end
HTTPS support) using emulation. We also test our approach on
four physical devices, where we show that HALE-IoT successfully
runs on protected and quite constrained devices with as low as
32MB of RAM and 8MB of storage. Overall, in our evaluation,
we achieve good performance and reliability with a remarkably
accurate detection and prevention rate for attacks coming from
both real CVEs and synthetic exploits.TRUEinpres
Jointly Learning Optimal Task Offloading and Scheduling Policies for Mobile Edge Computing
This work contributes towards optimizing edge analytics in Mobile Edge Computing (MEC) systems. We consider requests for computing tasks that are generated from users and can be satisfied either locally at their devices, or they can be offloaded to an edge server in their proximity for remote execution. We study a multi-user MEC system with limited energy autonomy for the mobile devices and with limitations on the computing capability of both mobile devices and at an edge server, where users can offload part of their computation load. We define a utility over “resource residuals”, that capture the difference between the resources assigned through our decisions, and those needed in practice, and we aim at the minimization of regret, i.e., of the difference between the utility obtained by an optimal offline benchmark that knows the system evolution in hindsight, and our online decision policy. We design an algorithm that jointly learns policies for offloading computations and scheduling them for execution at the shared MEC server. We prove that our algorithm is asymptotically optimal, i.e., it has no regret over the optimal static offline benchmark, and that its performance is independent of the number of devices in the system. From our numerical evaluation we conclude that our algorithm adapts to unpredictable demand changes, it learns to identify resource-limited devices, and it learns to share the server’s resources.This paper was supported by the Hellenic Foundation for Research and Innovation (H.F.R.I.) under the “1st Call for H.F.R.I. Research Projects to support Faculty Members & Researchers and the Procurement of high-cost research equipment grant” (Project Number: HFRI-FM17-352, Project Title: Wireless Mobile Delay-Tolerant Network Analysis and Experimentation, Project acronym: LEMONADE).TRUEpu
Scheduling of Wireless Edge Networks for Feedback-Based Interactive Applications
Interactive applications with automated feedback
will largely influence the design of future networked infrastructures.
In such applications, status information about an
environment of interest is captured and forwarded to a compute
node, which analyzes the information and generates a feedback
message. Timely processing and forwarding must ensure the
feedback information to be still applicable; thus, the quality-ofservice
parameter for such applications is the end-to-end latency
over the entire loop. By modelling the communication of a
feedback loop as a two-hop network, we address the problem
of allocating network resources in order to minimize the delay
violation probability (DVP), i.e. the probability of the end-to-end
latency exceeding a target value. We investigate the influence
of the network queue states along the network path on the
performance of semi-static and dynamic scheduling policies. The
former determine the schedule prior to the transmission of the
packet, while the latter benefit from feedback on the queue
states as time evolves and reallocate time slots depending on
the queue’s evolution. The performance of the proposed policies
is evaluated for variations in several system parameters and
comparison baselines. Results show that the proposed semi-static
policy achieves close-to-optimal DVP and the dynamic policy
outperforms the state-of-the-art algorithms.TRUEpu
Challenges in inferring privacy properties of smart devices: Towards scalable multi-vantage point testing methods
The growth of the number of Internet of Things (IoT) devices in the home has introduced unprecedented challenges for preserving con- sumers’ privacy. To enhance the transparency and trustworthiness of IoT products, industry actors, regulators and standardization bodies have proposed several certifications processes. While previ- ous research developed methodologies to expose a wide range of harmful behaviors in smart home devices, the research community has not yet produced scalable methods to exhaustively detect infor- mation leakage in heterogeneous environments so that they can be effectively used for independent certification processes. Research questions such as to what extent is it possible to automatically and independently validate high-level privacy properties and can we evaluate the correctness of privacy controls in a smart home by analyzing the home traffic? remain open. This paper explores and discusses open research challenges in this complex domain and sketches a roadmap to build scalable methods for smart home privacy testing.TRUEpu
Characterizing Location Management Function Performance in 5G Core Networks
Despite the large attention achieved by 5G localization in standardization bodies, the integration of 5G network function modules designed for localization lacks experimental work. Assessing the performance of these modules is essential to offering location services. In this work, we present our design, implementation and evaluation of the 5G Location Management Function (LMF), the key network function in the 5G core for localization services. Our implementation complies with the 3GPP standard and OpenAirInterface, the currently most advanced framework that implements a full 5G-New Radio stack. We show that we can extend the functionality of OpenAirInterface, enabling location services. Finally, we demonstrate that the performance of our implementation satisfies the 5G Key Performance Indicators required by 3GPP for localization.TRUEpu
Edge Gaming: a Greening Perspective
We tackle the problem of how to support gaming at the edge of the cellular network. The reduced latency and higher bandwidth that the edge enjoys with respect to cloud-based solutions implies that transferring cloud-based games to the edge could be a premium service for end-users. The goal of this work is to design a scheme compatible with MEC and network slicing principles of 5G and beyond, and which maximizes the utility of a service/infrastructure provider with time-varying edge node capacities due to the access to intermittent renewable energy. We formulate a multi-dimensional integer linear programming problem, proving that it is NP-hard in the strong sense. We prove that our problem is sub-modular and propose an efficient heuristic, GREENING, which considers the allocation of gaming sessions and their migration. For the mentioned scenario, we analyze a wide variety of realistic configurations at the edge, studying how the performance depends on i) whether the games have a static or dynamic workload, ii) the distribution of renewable energy through nodes and time, or iii) the topology of the edge network. Through simulations, we show that our heuristic achieves performance close to that achieved by solving the NP-hard optimization problem, except with extremely lower complexity, and performs up to 25% better than state-of-the-art algorithms.TRUEpu
Henna: hierarchical machine learning inference in programmable switches
The recent proliferation of programmable network equipment has opened up new possibilities for embedding intelligence into the data plane. Deploying models directly in the data plane promises to achieve high throughput and low latency inference capabilities that cannot be attained with traditional closed loops involving control-plane operations. Recent efforts have paved the way for the integration of trained machine learning models in resource-constrained programmable switches, yet current solutions have significant limitations that translate into performance barriers when coping with complex inference tasks. In this paper, we present Henna, a first in-switch implementation of a hierarchical classification system. The concept underpinning our solution is that of splitting a difficult classification task into easier cascaded decisions, which can then be addressed with separated and resource-efficient tree-based classifiers. We propose a design of Henna that aligns with the internal organization of the Protocol Independent Switch Architecture (PISA), and integrates state-of-the-art strategies for mapping decision trees to switch hardware. We then implement Henna into a real testbed with off-the-shelf Intel Tofino programmable switches using the P4 language. Experiments with a complex 21-category classification task based on measurement data demonstrate how Henna improves the F1 score of an advanced single-stage model by 21%, while keeping usage of switch resources at 8% on average.European Union Horizon 2020 research and innovation program under Marie Skłodowska-Curie grant agreement no. 860239 “BANYAN”CHIST-ERA grant no. CHIST-ERA-20-SICT- 001 “ECOMOME”, via grant PCI2022-133013 of Agencia Estatal de InvestigaciónEuropean Union Horizon 2020 research and innovation program under grant agreement no. 101017109 “DAEMON”TRUEpu
Machine learning algorithms for provisioning cloud/edge applications
Reinforcement Learning (RL), in which an agent is trained to make the most favourable decisions in the long run, is an established technique in artificial intelligence. Its popularity has increased in the recent past, largelydue to the development of deep neural networks spawning deep reinforcement learning algorithms such as Deep QLearning. The latter have been used to solve previously insurmountable problems, such as playing the famed game of “Go” that previous algorithms could not. Many such problems suffer the curse of dimensionality, in which the sheer number of possible states is so overwhelming that it is impractical to explore every possible option.
While these recent techniques have been successful, they may not be strictly necessary or practical for some applications such as cloud provisioning. In these situations, the action space is not as vast and workload data required to train such systems is not as widely shared, as it is considered commercially sensitive by the Application Service Provider (ASP). Given that provisioning decisions evolve over time in sympathy to incident workloads, they fit into the sequential decision process problem that legacy RL was designed to solve. However, because of the high correlation of time series data, states are not independent of each other, and the legacy Markov Decision Processes (MDPs) must be cleverly adapted to create robust provisioning algorithms.
As the first contribution of this thesis, we exploit the knowledge of both the application and configuration to create an adaptive provisioning system leveraging stationary Markov distributions. We then develop algorithms that, with neither application nor configuration knowledge, solve the underlying Markov Decision Process (MDP) to create provisioning systems. Our Q-Learning algorithms factor in the correlation between states and the consequent transitions between them to create provisioning systems that do not only adapt to workloads, but can also exploit similarities between them, thereby reducing the retraining overhead. Our algorithms also exhibit convergence in fewer learning steps given that we restructure the state and action spaces to avoid the curse of dimensionality without the need for the function approximation approach taken by deep Q-Learning systems.
A crucial use-case of future networks will be the support of low-latency applications involving highly mobile users. With these in mind, the European Telecommunications Standards Institute (ETSI) has proposed the Multi-access Edge Computing (MEC) architecture, in which computing capabilities can be located close to the network edge, where the data is generated. Provisioning for such applications therefore entails migrating them to the most suitable location on the network edge as the users move. In this thesis, we also tackle this type of provisioning by considering vehicle platooning or Cooperative Adaptive Cruise Control (CACC) on the edge. We show that our QLearning algorithm can be adapted to minimize the number of migrations required to effectively run such an application on MEC hosts, which may also be subject to traffic from other competing applications.Telematics EngineeringUniversidad Carlos III de Madrid, Spai
A new methodology to measure faultlines at scale leveraging digital traces
The definition of society is tight with human group-level behavior. Group faultlines defined as hypothetical lines splitting groups into homogeneous subgroups based on members’ attributes have been proposed as a theoretical method to identify conflicts within groups. For instance, crusades and women’s rights protests are the consequences of strong faultlines in societies with diverse cultures.
Measuring the presence and strength of faultlines represents an important challenge. Existing literature resorts in questionnaires as traditional tool to find group-level behavioral attributes and thus identify faultlines. However, questionnaire data usually come with limitations and biases, especially for large-scale human group-level research. On top of that, questionnaires limit faultline research due to the possibility of dishonest answers, unconscientious responses, and differences in understanding and interpretation.
In this paper, we propose a new methodology for measuring faultlines in large-scale groups, which leverages data readily available from online social networks’ marketing platforms. Our methodology overcomes the limitations of traditional methods to measure group-level attributes and group faultlines at scale.
To prove the applicability of our methodology, we analyzed the faultlines between people living in Spain, grouped by geographical regions. We collected data on 67,270 interest topics from Facebook users living in Spain, France, Germany, Greece, Italy, Portugal, and the United Kingdom. We computed existing metrics to measure faultlines’ distance and strenght using our data to identify potential faultlines existing among Spanish regions. The results reveal that the strongest faultlines in Spain belong to Spanish Islands (the Canary Islands and the Balearic Islands), Catalonia, and Basque regions. These findings are aligned with the historical secessionist movements and cultural diversity reports supporting the validity of our methodology.TRUEpu