Network


Latest external collaboration on country level. Dive into details by clicking on the dots.

Hotspot


Dive into the research topics where David Hadas is active.

Publication


Featured researches published by David Hadas.


IEEE Computer | 2011

Reservoir - When One Cloud Is Not Enough

Benny Rochwerger; David Breitgand; Amir Epstein; David Hadas; Irit Loy; Kenneth Nagin; Johan Tordsson; Carmelo Ragusa; Massimo Villari; Stuart Clayman; Eliezer Levy; Alessandro Maraschini; Philippe Massonet; Henar Muñoz; Giovanni Tofetti

As cloud computing becomes more predominant, the problem of scalability has become critical for cloud computing providers. The cloud paradigm is attractive because it offers a dramatic reduction in capital and operation expenses for consumers.


ieee conference on mass storage systems and technologies | 2013

Secure Logical Isolation for Multi-tenancy in cloud storage

Michael Factor; David Hadas; Aner Hamama; Nadav Har'El; Elliot K. Kolodner; Anil Kurmus; Alexandra Shulman-Peleg; Alessandro Sorniotti

Storage cloud systems achieve economies of scale by serving multiple tenants from a shared pool of servers and disks. This leads to the commingling of data from different tenants on the same devices. Typically, a request is processed by an application running with sufficient privileges to access any tenants data; this application authenticates the user and authorizes the request prior to carrying it out. Since the only protection is at the application level, a single vulnerability threatens the data of all tenants, and could lead to cross-tenant data leakage, making the cloud much less secure than dedicated physical resources. To provide security close to physical isolation while allowing complete resource pooling, we propose Secure Logical Isolation for Multi-tenancy (SLIM). SLIM incorporates the first complete security model and set of principles for the safe logical isolation between tenant resources in a cloud storage system, as well as a set of mechanisms for implementing the model. We show how to implement SLIM for OpenStack Swift and present initial performance results.


haifa experimental systems conference | 2010

Plugging the hypervisor abstraction leaks caused by virtual networking

Alex Landau; David Hadas; Muli Ben-Yehuda

Virtual machines are of very little use if they cannot access the underlying physical network. Virtualizing the network has traditionally been considered a challenge best met by such network-centric measures as VLANs, implemented by switches. We begin by arguing that network virtualization is best done by hypervisors, not switches. We then show that modern hypervisors do a poor job in virtualizing the network, leaking details of the physical network into virtual machines. For example, IP addresses used across the hosts physical network, are exposed to guest virtual machines. We then propose a method for plugging the network-related leaks by ensuring that the virtual network traffic is encapsulated inside a host envelope prior to transmission across the underlying physical network. In order to overcome the performance hit related to traffic encapsulation, we analyze the unique case of virtual machine traffic encapsulation, exploring the problems arising from dual networking stacks --- the guests and the hosts. Using a number of simple optimizations, we show how an unmodified guest under the KVM hypervisor can reach throughput of 5.5Gbps for TCP and 6.6Gbps for UDP for encapsulated traffic, compared to 280Mbps and 510Mbps respectively when using the default guest and host networking stacks.


european conference on service-oriented and cloud computing | 2013

Availability Assessment of a Vision Cloud Storage Cluster

Dario Bruneo; Francesco Longo; David Hadas; Hillel Kolodner

VISION Cloud is a European Commission funded project, whose aim is to design and propose a new architecture for a scalable and flexible cloud environment. The VISION Cloud reference architecture considers a single cloud as composed by multiple distributed data centers each of which can be composed by a great number of storage clusters. On top of the storage rich nodes forming each cluster, a distributed file system is built. In this paper, we provide an stochastic reward net model for a storage cluster in the context of the storage cloud environment proposed by the VISION Cloud project. The proposed model represents a first step in the direction of obtaining a quantification of the availability level reached through the use of the VISION Cloud proposed architecture from a user perspective.


Archive | 2011

Hypervisor routing between networks in a virtual networking environment

Robert Cowart; David Hadas; Daniel Joseph Martin; Bruce H. Ratcliff; Renato J. Recio


DC-CaVES '11 Proceedings of the 3rd Workshop on Data Center - Converged and Virtual Ethernet Switching | 2011

A case for overlays in DCN virtualization

Katherine Barabash; Rami Cohen; David Hadas; Vinit Jain; Renato J. Recio; Benny Rochwerger


Archive | 2009

MANAGING COMMUNICATION BETWEEN NODES IN A VIRTUAL NETWORK

David Hadas; Irit Loy; Benny Rochwerger; Julian Satran


Archive | 2011

Migration of virtual resources over remotely connected networks

David Hadas; Irit Loy; Kenneth Nagin; Benny Rochwerger; Alexander Glikson; Liran Schour


Archive | 2013

Secure isolation of tenant resources in a multi-tenant storage system using a security gateway

Michael Factor; David Hadas; Elliot K. Kolodner; Anil Kurmus; Alexandra Shulman-Peleg; Alessandro Sorniotti


Archive | 2012

Hypervisor application of service tags in a virtual networking environment

David Hadas; Vivek Kashyap; Jayakrishna Kidambi; Renato J. Recio; Benny Rochwerger

Researchain Logo
Decentralizing Knowledge