VLDB 2026 Research / reviewers in the wild / expert
Simon Pietro Romano
dblp:02/4507
· DBLP profile ↗
49ranked-venue papers
2as first author
21since 2021 · last 2027
0000-0002-5876-0382ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 28 · 9 since 2021Security and privacy · 9 · 7 since 2021Artificial intelligence and machine learning · 5 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 4Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | BabeLLM: A unified taxonomy for NLP-based LLM cybersecurity applicationsabstractAs cybersecurity becomes increasingly complex, Large Language Models (LLMs) are emerging as valuable tools for supporting security professionals in routine tasks. However, existing research remains fragmented: no unified, machine-readable reference exists to compare and consolidate LLM use cases across academia and industry, limiting knowledge sharing and encouraging duplicated efforts. This paper presents BabeLLM, a concept-based taxonomy and OWL ontology grounded in established literature and cybersecurity standards (NIST, ISO/IEC, FIRST, JRC, and IETF). BabeLLM integrates NLP tasks, cybersecurity processes, and their intersection as LLM-based cybersecurity applications. Our analysis of 46 taxonomic efforts shows that none covers all three dimensions, leaving 17 LLM application categories absent from existing taxonomies. BabeLLM also introduces an operational architecture organized around three capabilities: exploration of existing work, design of new use cases, and automated ontology maintenance through LLM-assisted metadata enrichment and classification. The ontology is constructed through an umbrella systematic literature review covering more than 1,400 publications, combined with a concept-based cross-dimensional analysis of NLP and cybersecurity, and refined through iterative expert review. BabeLLM is validated through complementary evaluations: coverage and agreement analyses across existing taxonomies, a real-world Security Operations Center (SOC) deployment demonstrating practical applicability, and an LLM-assisted classification pipeline benchmarked against human-annotated ground truth. The ontology is released as an open-source resource alongside this paper. Pellegrino Casoria, Simon Pietro Romano |
Expert Syst. Appl. | 2 |
| 2026 | Multimedia over Satellite with QUIC-Wave: An Experimental Evaluation of PerformanceabstractQUIC is emerging as the de facto transport protocol for modern applications and forms the basis of HTTP/3. Within the European Space Agency (ESA) project QUICoS, we developed QUIC-Wave, a satellite-tailored extension of QUIC designed to address the limitations of TCP-based transport in high-latency and lossy satellite environments (GEO, MEO, LEO). Unlike Performance Enhancing Proxy (PEP) approaches, QUIC-Wave preserves end-to-end semantics and encryption while enhancing congestion control. The protocol extensions are engineered to sustain throughput and responsiveness under satellite-specific conditions such as long RTTs, bandwidth variability, and mobility-induced handovers, while maintaining compliance with QUIC specifications and interoperability with terrestrial networks. To validate QUIC-Wave, we conducted extensive real experiments using standard browsers and servers. Results show that QUIC-Wave supports interactive web browsing and multimedia streaming with improved performance over satellite links, without compromising either end-to-end encryption or protocol integrity. Armir Bujari, Michele Luglio, Claudio E. Palazzi, Simon Pietro Romano, Cesare Roseti, Domenico Verde, Francesco Zampognaro |
CCNC | 4 |
| 2026 | RTC-Attack Lab: A reproducible security testbed for real-time attacks experimentation
Martina Borgstrom, Gaetano Perrone, Simon Pietro Romano |
Comput. Networks | 3 |
| 2026 | Towards the integration of Privacy-Preserving technologies in future mobile networking
Vittorio Prodomo, Roberto Gonzalez, Giancarlo Sperlì, Simon Pietro Romano |
Comput. Commun. | 4 |
| 2025 | Harnessing NLP for test case prioritization: unsupervised approachesabstractDesigning and testing modern network systems is a complex and costly process, particularly during the testing phase, where time constraints and unpredictability often lead to inflated development efforts. In this paper, we propose a novel methodology that leverages natural language comments from developer commits to optimize test execution. By extracting meaningful insights from comments, we construct a prioritized task list, focusing on those tasks that are most likely to fail. This approach streamlines the testing workflow, accelerates execution, and reduces overall development costs. Our pipeline combines transformer-based models for semantic understanding with unsupervised anomaly detection methods, including clustering algorithms, autoencoders (AE), and variational autoencoders (VAE), to identify failure-prone scenarios without requiring labeled data. Applied to a real-world industrial dataset, the AE model achieves an F1score of 0.838, and the VAE follows closely with 0.805, significantly outperforming traditional clustering approaches. These results highlight the effectiveness of leveraging commit metadata for intelligent test prioritization and demonstrate the potential for scalable improvements in continuous integration pipelines. Andrea Vignali, Giancarlo Sperlì, Simon Pietro Romano |
IJCNN | 3 |
| 2025 | A chit-chat between Llama 2 and ChatGPT for the automated creation of exploitsabstractSoftware exploitation is the process of taking advantage of vulnerabilities in software systems in order to perform unintended activities. Its understanding leads to improved defensive measures and informed decision making about which security mechanisms to prioritize. However, creating a software exploit is typically a time-consuming and manual task that demands a deep understanding of programming, network protocols, operating system internals, and computer architectures. Additionally, it requires the ability to integrate this knowledge through complex reasoning and problem-solving techniques. This paper proposes an approach to tackle the aforementioned problems by encouraging a conversation between Large Language Models (LLMs) with the purpose of generating software exploits. First, the chosen LLMs are provided with the necessary context knowledge, through modern techniques of fine-tuning and prompt engineering. Then, the exploitation methodology is divided into several steps: vulnerable program analysis, identification of the exploit, planning of the exploitation process, discovery of architecture internals, and production of the exploit software. A first Large Language Model (LLM) is designed to ask questions to a second LLM regarding the execution of the above mentioned steps. The final output from the second LLM provides fully automated, functional exploit code. This method demonstrates how two LLMs – one possessing capabilities in exploitation and coding, and the other with expertise in computer architecture – can collaborate to successfully exploit Buffer Overflow vulnerabilities. Francesco Caturano, Jordan Ciotola, Simon Pietro Romano, Mario Varlese |
Comput. Networks | 3 |
| 2025 | SMASH: An SDN-MTD framework for efficient honeypot deployment and insider threat mitigationabstractConventional cybersecurity tools, such as firewalls and Intrusion Prevention Systems, have been widely employed to protect against digital threats. However, these approaches reveal their inherent limitations as the complexity and sophistication of cyberattacks increase. Consequently, there is a growing demand for more proactive and adaptive cyber-defense strategies. Deception-based techniques, such as Moving Target Defense (MTD) and honeypots, have emerged as powerful approaches to enhance security by confusing and misleading attackers. Despite their potential, deploying these solutions in large-scale network infrastructures poses significant challenges. Manual configuration of honeypots is time-consuming, resource-intensive, and difficult to scale. Moreover, it is mandatory to ensure that honeypots do not become a pivot for attackers to penetrate the enterprise network infrastructure further. To address these issues, we propose “Sdn-Mtd Automated System with Honeypot integration” (SMASH), a framework that leverages Software Defined Networking (SDN) principles in conjunction with MTD and decoy techniques. Following a Design Science approach, we designed, implemented, and evaluated SMASH to overcome these deployment and management challenges. SMASH not only makes it more difficult for attackers to target the production network infrastructure, but also provides valuable real-time threat intelligence by observing attacker behavior. When an intrusion attempt is detected, MTD techniques redirect the attacker to an isolated subnet dedicated to threat monitoring, preventing access to sensitive systems and data. Furthermore, SMASH introduces a flexible and scalable management system that allows automatic deployment, setup, and real-time monitoring of honeypots. This dynamic adaptability allows organizations to scale their defenses in response to evolving threats, significantly enhancing the security posture of real-world enterprise environments. Nicola d'Ambrosio, Claudio Lista, Gaetano Perrone, Simon Pietro Romano |
Comput. Networks | 4 |
| 2025 | An anomaly-based approach for cyber-physical threat detection using network and sensor dataabstractIntegrating physical and cyber realms, Cyber–Physical Systems (CPSs) expand the potential attack surface for intruders. Given their deployment in critical infrastructures like Industrial Control Systems (ICSs), ensuring robust security is imperative. Current research has developed various Intrusion Detection techniques to identify and counter malicious activities. However, traditional methods often encounter challenges in detecting several attack types due to reliance on a single data source such as time series data from sensors and actuators. In this study, we meticulously design advanced Deep Learning (DL) anomaly-based techniques trained on either sensor/actuator data or network traffic statistics in an unsupervised setting. We evaluate these techniques on network and physical data collected concurrently from a real-world CPS. Through meticulous hyperparameter tuning, we identify the optimal parameters for each model and compare their efficiency and effectiveness in detecting different types of attacks. In addition to demonstrating superior performance compared to various baselines, we showcase the best model for each data source. Eventually, we show how utilizing diverse data sources can enhance cyber-threat detection, recognizing different kinds of attacks. • We design DL anomaly-based techniques trained on either sensor or network data. • We evaluate techniques on different data sources collected from a real-world CPS. • After hyperparameter tuning, we compare the models’ attack detection ability. • We demonstrate superior performance compared to state-of-the-art base-lines. • We show how utilizing diverse data sources can enhance cyber-threat detection. Roberto Canonico, Giovanni Esposito, Annalisa Navarro, Simon Pietro Romano, Giancarlo Sperlì, Andrea Vignali |
Comput. Commun. | 4 |
| 2025 | Empowered Cyber-Physical Systems security using both network and physical dataabstractThe protection of Cyber–Physical Systems (CPSs) from cybersecurity threats is essential to ensure the resilience and safety of critical infrastructures. Anomaly detection approaches for CPSs proposed in the literature use either network data or data from sensors/actuators as inputs, often failing to detect attacks that affect only specific components. In this paper, we propose a novel two-stage framework for threat detection in CPSs. This framework integrates anomaly detection models that operate on both network and physical data, by leveraging a decision fusion technique to combine the outputs into a coherent decision. To assess the effectiveness of the framework, we employ an unlabeled release of a real-world dataset, integrating network traffic with sensors/actuators data. Additionally, we offer explicit labeling rules to ensure reproducibility. The results demonstrate that our approach substantially improves CPSs security, efficiently identifying subtle attacks that can evade traditional methods relying on a single data source. In particular, we show that integrating both physical and network data improves the F1 score by approximately 10% compared to using just network data, and by nearly 30% compared to using just physical data. • We propose a framework for CPS threat detection using both network and physical data. • We integrate diverse deep learning models to analyze each data source independently. • We design a decision fusion technique to integrate network and sensor readings. • We achieve a 10% F1 improvement over network data and a 30% over sensor data. • Our method detects threats in 2–3 s, enabling quick response to CPS attacks. Roberto Canonico, Giovanni Esposito, Annalisa Navarro, Simon Pietro Romano, Giancarlo Sperlì, Andrea Vignali |
Comput. Secur. | 4 |
| 2025 | SCASS: Breaking into SCADA Systems SecurityabstractIndustrial Controls Systems (ICS) represent a relevant target for attackers. In order to prevent such critical security threats, ICS security assessment activities should be conducted. Conventional vulnerability assessment and penetration testing within ICSs are not practicable due to safety risks and cost constraints. To overcome these challenges, security researchers have developed cybersecurity testbeds. However, these testbeds commonly rely on closed components, cannot be extended, and are very expensive. This research investigates how a modular, open-source framework can enhance the development of robust cybersecurity testbeds and facilitate the implementation of digital twins for securing Industrial Control Systems. We present SCASS, a fully customizable testbed designed to replicate complex SCADA and ICS environments with high fidelity. SCASS addresses the need for accessible, scalable platforms by supporting both physical and virtual components while enabling the evaluation of heterogeneous attack scenarios and security methodologies. By combining advanced attack scenarios with an objective comparative analysis against existing testbeds, SCASS demonstrates its ability to fill critical gaps in the ICS security landscape, fostering collaboration and advancing security assessment methodologies. Nicola d'Ambrosio, Giulio Capodagli, Gaetano Perrone, Simon Pietro Romano |
Comput. Secur. | 4 |
| 2025 | A cyber-resilient open architecture for drone controlabstractUnmanned Aerial Vehicles (UAVs) are becoming important tools in both military and civilian sectors. However, the prevalent use of monolithic architectures in contemporary platforms limits the swift integration of new features and significantly hampers the adaptability of UAVs to an ever-changing operational environment. Furthermore, this constantly evolving landscape highlights the inherent complexity of assessing drone safety and security since this process requires managing multiple and rapidly changing variables. Therefore, it is imperative to adopt an open system approach that relies on microservices and virtualization in order to overcome the limits of traditional drone architectures. This study presents a new method that involves breaking down the UAV monolithic system into a network of separate and virtualized components, each holding a single responsibility and designed according to the Open System Architecture (OSA) principle. Moreover, this work proposes a novel cyber-resilience model to determine cyber threats and assess their impact on the system. This approach leverages NIST 800-53, MITRE ATT&CK, STPA-Sec, and Attack Graph in order to identify the sequence of malicious actions that can lead to a specific hazardous scenario. Lastly, we demonstrate the effectiveness of this novel architectural paradigm by developing a software-in-the-loop simulation testbed for fast prototyping new features and validating the results of the cyber-resilience model. Nicola d'Ambrosio, Gaetano Perrone, Simon Pietro Romano, Alberto Urraro |
Comput. Secur. | 3 |
| 2024 | Securing Industrial Systems: A Testbed for Cyber-Defense Evaluation and Data CollectionabstractOver recent years, many Industrial Control System (ICS) components have been exposed to both the Internet and corporate networks to enhance the management of industrial processes. However, this increased exposure has often taken place without adequate consideration for cybersecurity, making industrial networks more vulnerable to cyberattacks. In this context, digital twins have emerged as innovative solutions to evaluate novel cyber-defense strategies that can mitigate threats affecting industrial networks. Unfortunately, to the best of the authors’ knowledge, there is no digital twin that is flexible enough to integrate both physical and virtualized components according to user preferences while simultaneously supporting novel approaches based on the Software-Defined Networking (SDN) paradigm. To address these issues, we developed a flexible hybrid/virtual digital twin that mimics a physical Microgrid testbed known as EPIC. Specifically, our solution leverages vir-tualization and containerization to create a lightweight platform that can include the widest possible range of vulnerabilities. Furthermore, we employ Open vSwitch to implement SDN-based methodologies and integrate physical components into our platform. Lastly, we provide a comprehensive tool that collects all possible logs from the testbed. Raffaele Cuorvo, Nicola d'Ambrosio, Domenico Iorio, Gaetano Perrone, Simon Pietro Romano |
CNSM | 5 |
| 2024 | An NLP-based approach to assessing a company's maturity level in the digital eraabstractConducting a maturity assessment allows companies to measure their readiness in implementing novel technologies. However, this task is challenging due to the multidimensional, complex, unpredictable, and non-linear nature of innovation. In this paper, we introduce an innovative approach to maturity assessment that enables both intra- and inter-company analysis. Our approach evaluates a company’s absolute maturity score concerning a specific technology or area. By leveraging a Natural Language Processing pipeline applied to a semi-structured questionnaire we extract popular concepts from the answers and present them to a human expert for analysis. The expert can refine the analysis by adding or removing concepts as needed. Subsequently, we compute a similarity metric for each answer to determine a company’s maturity in specific concepts. The output of our analysis is presented through human-readable plots, offering clear insights into the internal maturity level of the company and allowing for a comparison with competitors across the chosen concepts. To demonstrate the capabilities of our method, we provide a running example showcasing both quantitative and qualitative results of the analysis. Our approach demonstrates efficiency, with preprocessing completed in 1.967±0.758 s, and information extraction in 0.074±0.017 s on average, excluding human intervention time, and requiring low hardware resources. Simon Pietro Romano, Giancarlo Sperlì, Andrea Vignali |
Expert Syst. Appl. | 1 |
| 2024 | Playing With a Multi Armed Bandit to Optimize Resource Allocation in Satellite-Enabled 5G NetworksabstractIn this paper, we address issues associated with the effective management of handover events in satellite-enabled 5G network infrastructures. Namely, we devise a strategy for dynamically allocating 5G gNB available resources in the presence of a constellation of LEO satellites, based on several parameters collected and dispatched by an ad hoc orchestration platform. We propose to leverage a Combinatorial Multi-Armed Bandit approach to design a resource allocation game that helps make decisions over time under uncertainty conditions related to the incidence of several factors that can determine the quality of experience perceived on the user equipment side. The introduced approach does represent a pioneering one, since it allows us to model a joint optimization task as a competitive game in which agents typically share resources with other agents instead of occupying them exclusively. The designed task allows to dynamically enable and disable channels, taking care of the relationships with the lower layer, transparently managing the required handover operations, and considering possible interference with other channels. We discuss an implementation of the proposed solution in a simulated environment. We also analyze the performance it attains, by measuring both its efficiency and efficacy in a trial setup reproducing a scenario with near real-time temporal requirements. Results show that the proposed approach has a linear trend in terms of running time with respect to the number of user equipments and gNbs involved, while achieving a sub-optimal solution of the handover task in around 20–30 rounds. Antonio Galli, Vincenzo Moscato, Simon Pietro Romano, Giancarlo Sperlì |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | Including insider threats into risk management through Bayesian threat graph networks
Nicola d'Ambrosio, Gaetano Perrone, Simon Pietro Romano |
Comput. Secur. | 3 |
| 2022 | Satellite multi-beam multicast support for an efficient community-based CDN
Michele Luglio, Simon Pietro Romano, Cesare Roseti, Francesco Zampognaro |
Comput. Networks | 2 |
| 2022 | An automated approach to Web Offensive Security
Nicola Auricchio, Andrea Cappuccio, Francesco Caturano, Gaetano Perrone, Simon Pietro Romano |
Comput. Commun. | 5 |
| 2021 | Discovering reflected cross-site scripting vulnerabilities using a multiobjective reinforcement learning environment
Francesco Caturano, Gaetano Perrone, Simon Pietro Romano |
Comput. Secur. | 3 |
| 2021 | Exploiting the MIL-STD-1553 avionic data bus with an active cyber device
Damiano De Santo, Claudio Santo Malavenda, Simon Pietro Romano, Cristian Vecchio |
Comput. Secur. | 3 |
| 2021 | A distributed security tomography framework to assess the exposure of ICT infrastructures to network threats
Mauro Alberto Brignoli, Alessio P. Caforio, Francesco Caturano, Maurizio D'Arienzo, Marco Latini, Walter Matta, Simon Pietro Romano, B. Ruggiero |
J. Inf. Secur. Appl. | 7 |
| 2021 | Cooperative Intersection Crossing Over 5GabstractAutonomous driving is a safety critical application of sensing and decision-making technologies. Communication technologies extend the awareness capabilities of vehicles, beyond what is achievable with the on-board systems only. Nonetheless, issues typically related to wireless networking must be taken into account when designing safe and reliable autonomous systems. The aim of this work is to present a control algorithm and a communication paradigm over 5G networks for negotiating traffic junctions in urban areas. The proposed control framework has been shown to converge in a finite time and the supporting communication software has been designed with the objective of minimizing communication delays. At the same time, the underlying network guarantees reliability of the communication. The proposed framework has been successfully deployed and tested, in partnership with Ericsson AB, at the AstaZero proving ground in Goteborg, Sweden. In our experiments, three heterogeneous autonomous vehicles successfully drove through a 4-way intersection of 235 square meters in an urban scenario. Luca Maria Castiglione, Paolo Falcone, Alberto Petrillo, Simon Pietro Romano, Stefania Santini |
IEEE/ACM Trans. Netw. | 4 |
| 2020 | Enabling an efficient satellite-terrestrial hybrid transport service through a QUIC-based proxy functionabstractThe QUIC (Quick UDP Internet Connection) protocol suite is going to approach its final stages of standardization to become part of the official Internet standards (RFCs) and of the new HTTP/3 specification. Some of its disruptive characteristics, such as the 0-RTT establishment of secure communications and a connection-oriented management over a UDP-based connection-less transport, can be reused and tailored in the framework of a Performance Enhancing Proxy (PEP) architecture for the effective management of multiple links. In this paper, we describe the design and implementation of a QUIC-based splitting solution to enhance the communication across multiple backhaul links, each associated with a different network technology (e.g., satellite and terrestrial). After discussing the working principles of the designed QUIC-based proxy, we present a software implementation, as well as preliminary results obtained, through a set of meaningful test-cases deployed over a Linux based testbed. Michele Luglio, Mattia Quadrini, Simon Pietro Romano, Cesare Roseti, Francesco Zampognaro |
ISNCC | 3 |
| 2020 | IntentKeeper: Intent-oriented Data Usage Control for Federated Data AnalyticsabstractData usage control is of utmost importance for federated data analytics across multiple business domains. However, the existing data usage control approaches are limited due to their complexity and inefficiency. This paper proposes an intent-oriented data usage control system for federated data analytics, called IntentKeeper. The system allows users to specify intents for data usage policies and services easily. Thus, it reduces the data sharing complexity for data providers and consumers. Moreover, IntentKeeper enforces preventive and proactive data usage control for better security and efficiency through joint decisions based on policy enforcement and service orchestration. The use case validations for the automotive industry scenario show that IntentKeeper significantly reduces the complexity of policy specification (up to 75% for moderately complex scenarios) compared to the state-of-the-art flow-based approach. Lastly, the experimental results show that the IntentKeeper system provides sufficiently short response times (less than 40ms) with minimal overhead (less than 10ms). Flavio Cirillo, Bin Cheng 0003, Raffaele Porcellana, Marco Russo, Gürkan Solmaz, Hisashi Sakamoto, Simon Pietro Romano |
LCN | 7 |
| 2020 | Hacking Goals: A Goal-Centric Attack Classification Framework
Francesco Caturano, Gaetano Perrone, Simon Pietro Romano |
ICTSS | 3 |
| 2019 | LIoTS: League of IoT Sovereignties. A Scalable approach for a Transparent Privacy-safe Federation of Secured IoT PlatformsabstractInternet-of-Things has entered all the fields where data are produced and processed, resulting in a plethora of IoT platforms, typically cloud-based, centralizing data and services management. This has brought to many disjoint IoT silos. Significant efforts have been devoted to integration, recurrently resulting into bigger centralized infrastructures. Such an approach often stumbles upon the reluctance of IoT system owners to loose the dominion over data. We introduce a secured and privacy-safe infrastructure where a federation overlay is distributed among parties and the data control is kept locally. This establishes a league of peers each sovereign of their IoT system and data: League of IoT Sovereignties (LIoTS). LIoTS is scalable by design, allowing iterative formation of domains levels due to the transparency of its federation. Tests show that the overhead is minimal when exchanged data is hefty, and that LIoTS performs better in large IoT deployments than centralized approaches. Flavio Cirillo, Nicola Capuano, Simon Pietro Romano, Ernö Kovacs |
LCN | 3 |
| 2018 | SHINE: Secure Hybrid In Network caching EnvironmentabstractIn this paper we look after the secure delivery of multimedia content across an innovative Content Delivery Network comprising both satellite and terrestrial trunks. The CDN in question leverages state-of-the-art technologies both at the edges and in the core of the integrated distribution architecture and highly relies upon in-network caching strategies in order to improve its performance. We propose an architecture envisaging a combination of multicast, simulcast and unicast communication scenarios where satellite links are exploited to support local in-network caching. We analyse integrated network deployment scenarios where the satellite acts as the interconnection link between distributed in-network caches and a terrestrial CDN and/or feeds edge-network caches at micro-centre locations. Simon Pietro Romano, Cesare Roseti, Antonia M. Tulino |
ISNCC | 1 |
| 2017 | Kerberos: A real-time fraud detection system for IMS-enabled VoIP networks
L. Manunza, S. Marseglia, Simon Pietro Romano |
J. Netw. Comput. Appl. | 3 |
| 2016 | GOSPF: An energy efficient implementation of the OSPF routing protocol
Maurizio D'Arienzo, Simon Pietro Romano |
J. Netw. Comput. Appl. | 2 |
| 2013 | An anomaly-based approach to the analysis of the social behavior of VoIP users
S. Chiappetta, Claudio Mazzariello, Roberta Presta, Simon Pietro Romano |
Comput. Networks | 4 |
| 2013 | A Distributed Control Law for Load Balancing in Content Delivery NetworksabstractIn this paper, we face the challenging issue of defining and implementing an effective law for load balancing in Content Delivery Networks (CDNs). We base our proposal on a formal study of a CDN system, carried out through the exploitation of a fluid flow model characterization of the network of servers. Starting from such characterization, we derive and prove a lemma about the network queues equilibrium. This result is then leveraged in order to devise a novel distributed and time-continuous algorithm for load balancing, which is also reformulated in a time-discrete version. The discrete formulation of the proposed balancing law is eventually discussed in terms of its actual implementation in a real-world scenario. Finally, the overall approach is validated by means of simulations. Sabato Manfredi, Francesco Oliviero, Simon Pietro Romano |
IEEE/ACM Trans. Netw. | 3 |
| 2012 | Can cooperation improve energy efficiency in ad hoc wireless networks?
Maurizio D'Arienzo, Francesco Oliviero, Simon Pietro Romano |
Comput. Commun. | 3 |
| 2012 | Optimised balancing algorithm for content delivery networksabstractIn this study the authors present the ‘fictitiously starred optimised balancing’ (FSOB), a novel algorithm for load balancing in a content delivery network (CDN) scenario. FSOB exploits the multiple redirection mechanism of the HTTP protocol to optimally redistribute clients requests among the servers which build up the CDN. Load redistribution is aimed at equalising the level of occupancy of the server queues and is achieved through the periodical exchange of information computed locally at each node. The algorithm initially makes a fictitious assumption about the local topology of the network, as it is seen by each single server node, which looks at itself as the centre (i.e. the master) of a star made up of all of its neighbours (i.e. the slaves). Load redistribution is performed by the master which, if needed, appropriately redirects incoming requests to its slaves. The authors show how FSOB outperforms most of its competitors under a number of fundamental aspects, at the price of an increased overhead owing to the adoption of the multiple redirections mechanism for the redistribution phase. Finally, they study the scalability properties of FSOB and perform a comparative evaluation of its performance with respect to the most interesting existing solutions. Sabato Manfredi, Francesco Oliviero, Simon Pietro Romano |
IET Commun. | 3 |
| 2012 | Energy- and Delay-Efficient Routing in Mobile Ad Hoc Networks
Nicola Costagliola, Pedro García López, Francesco Oliviero, Simon Pietro Romano |
Mob. Networks Appl. | 4 |
| 2012 | Standard multimedia conferencing in the wild: the Meetecho architecture
Alessandro Amirante, Tobia Castaldi, Lorenzo Miniero, Roberta Presta, Simon Pietro Romano |
Multim. Tools Appl. | 5 |
| 2011 | Protecting Critical Infrastructures from Stealth Attacks: A Closed-Loop Approach Involving Detection and Remediation - (Short Paper)
Stefano Avallone, Claudio Mazzariello, Francesco Oliviero, Simon Pietro Romano |
CRITIS | 4 |
| 2010 | Performance assessment of a distributed intrusion detection system in a real network scenarioabstractThe heterogeneity and complexity of modern networks and services urge the requirement for flexible and scalable security systems, which can be dynamically configured to suit the everchanging nature of security threats and user behavior patterns. In this paper we present a distributed architecture for an Intrusion Detection System, allowing for traffic analysis at different granularity levels, performed by using the best available techniques. Such architecture leverages the principle of separation of concerns, and hence proposes to build up a system comprising entities specialized in performing different tasks, appropriately orchestrated by a broker entity playing the crucial role of the mediator. This paper stresses the point that a distributed system, besides being inherently more scalable than a centralized one, allows for better detection capabilities thanks to the effective exploitation of the inner heterogeneity of the involved detection engines. In order to support our findings, we will describe the design, implementation and deployment of the proposed solution in the framework of the INTERSECTION FP7 European Project. Salvatore D'Antonio, Valerio Formicola, Claudio Mazzariello, Francesco Oliviero, Simon Pietro Romano |
CRiSIS | 5 |
| 2008 | A Reputation-Based Metric for Secure Routing in Wireless Mesh NetworksabstractThe continuous growth of wireless networks calls for more and more sophisticated solutions for their security. In particular, mechanisms for limiting effects of routing protocol attacks are becoming a mandatory requirement: black-hole and gray-hole attacks can in fact seriously compromise the performance of a critical infrastructure like a Wireless Mesh Network. In this paper we present a new routing metric aimed at mitigating the effects of such attacks, based on an estimation of the trustworthiness level of network nodes. By applying the metric to existing wireless routing protocols we show that it is possible to increase both the security level and the performance of the overall network, even in the presence of routing attacks. Francesco Oliviero, Simon Pietro Romano |
GLOBECOM | 2 |
| 2008 | REFACING: An autonomic approach to network security based on multidimensional trustworthiness
Francesco Oliviero, L. Peluso, Simon Pietro Romano |
Comput. Networks | 3 |
| 2006 | Pinball Caching: Improving Performance of a Framework for Dynamic Web-Content Adaptation and DeliverabstractIn this work we deal with a multi-layer caching architecture capable to optimize delivery of dynamically produced web content. With reference to such architecture, we propose a technique named Pinball Caching, representing a useful means to estimate attainable performance improvement with respect to the trend of the main parameters characterizing the system. The application of such instrument allows clearly identifying where to concentrate efforts in order to optimize the joint utilization of the content adaptation architecture on one side and the hierarchical caching pool on the other. Salvatore D'Antonio, Marcello Esposito, Simon Pietro Romano |
ISCC | 3 |
| 2006 | A link weight assignment algorithm for traffic-engineered networks
E. Atteo, Stefano Avallone, Simon Pietro Romano |
Comput. Networks | 3 |
| 2005 | Time-aware admission control on top of time-unaware network infrastructures
Salvatore D'Antonio, Marcello Esposito, Simon Pietro Romano, Giorgio Ventre |
Comput. Commun. | 3 |
| 2004 | Managing service level agreements in Premium IP networks: a business-oriented approach
Salvatore D'Antonio, Maurizio D'Arienzo, Marcello Esposito, Simon Pietro Romano, Giorgio Ventre |
Comput. Networks | 4 |
| 2003 | Introducing QoS awareness in distributed programming: QTclabstractAbstract A number of distributed applications require communication services with quality of service (QoS) guarantees. Building global‐scale distributed systems with predictable properties is one of the great challenges for computer systems engineering in the new century. Work undertaken within the Internet Engineering Task Force has led to the definition of novel architectural models for the Internet with QoS support. According to these models, the network has to be appropriately configured in order to provide applications with the required performance guarantees. In next‐generation networks, enabling applications to interact with the underlying QoS services is of primary importance. Hence, several special‐purpose application programming interfaces (APIs) have been defined to let applications negotiate QoS parameters across QoS‐capable networks. However, so far, none of these APIs are available in different operating environments. We believe that such features should be embedded in programming environments for distributed applications. In this work we present how we included QoS control features in Tcl, a programming language that has been widely adopted for the development of distributed multimedia applications. Our work has led to the implementation of QTcl, an extended Tcl interpreter that provides programmers with a new set of primitives, in full compliance with the standard SCRAPI programming interface for the RSVP protocol. QTcl in highly portable, in that it enables standard QoS negotiation to be performed in a seamless fashion on the most common operating systems. Copyright © 2003 John Wiley & Sons, Ltd. Roberto Canonico, Maurizio D'Arienzo, Simon Pietro Romano, Giorgio Ventre |
Softw. Pract. Exp. | 3 |
| 2002 | An active security protocol against DoS attacksabstractDenial of service (DoS) attacks represent, in today's Internet, one of the most complex issues to address. A session is under a DoS attack if it cannot achieve its intended throughput due to the misbehavior of other sessions. Many research studies dealt with DoS, proposing models and/or architectures mostly based on an attack prevention approach. Prevention techniques lead to different models, each suitable for a single type of misbehavior, but do not guarantee the protection of a system from a more general DoS attack. We analyze the fundamental requirements to be satisfied in order to protect hosts and routers from any form of distributed DoS (DDoS). Then we propose a network signaling protocol, named active security protocol(ASP), which satisfies most of the defined requirements. ASP provides an active protection from a DDoS attack, being able to adapt its defense strategies to the current type of violation. Protocol specification and design are performed using an object oriented methodology: we used Unified Modeling Language (UML) as a software description language. Domenico Cotroneo, L. Peluso, Simon Pietro Romano, Giorgio Ventre |
ISCC | 3 |
| 2002 | An active network approach to virtual private networksabstractVirtual private networks (VPN) represent, in today's Internet, one of the most interesting applications. This is due both to their usefulness in corporate network scenarios and to the high revenues they guarantee to network providers. We propose an innovative approach to VPN implementation, exploiting the capabilities of active networks. We present a model aiming at building and dynamically configuring VPNs in a modular way and with a high degree of flexibility. We claim that the proposed approach has substantial advantages over traditional techniques and clearly shows how active technologies may help network engineers realize a number of critical applications for next generation networks. R. Maresca, Maurizio D'Arienzo, Marcello Esposito, Simon Pietro Romano, Giorgio Ventre |
ISCC | 4 |
| 2002 | A Framework for Policy-Based Management of QoS Aware IP Networks
Piergiorgio Cremonese, Marcello Esposito, Silvia Giordano, M. Mondini, Simon Pietro Romano, Giorgio Ventre |
NETWORKING | 5 |
| 2002 | On the introduction of quality of service awareness in legacy ditributed applicationsabstractA number of distributed applications require communication services with Quality of Service (QoS) guarantees. Work undertaken within the Internet Engineering Task Force (IETF) has led to the definition of novel architectural models for the Internet with QoS support. According to these models, the network has to be appropriately configured in order to provide applications with the needed performance guarantees. In a first proposal, called Integrated Services, applications need to explicitly interact with network routers by means of a signaling protocol (such as RSVP), in order to enforce QoS on a per-flow basis. The Differentiated Services architecture, on the other hand, looks after scalability, thus providing performance guarantees to aggregates of flows. In the case of real-time applications, a hybrid model capable of putting together micro-flow guarantees in the access network and aggregate management in the backbone seems to represent the ideal tradeoff between strict performance and scalability. In this scenario, giving applications a means to interact with the underlying QoS services is of primary importance. Hence, several special-purpose APIs have been defined to let applications negotiate QoS parameters across QoS-capable networks. However, so far, none of these APIs is available for the use of programmers in different operating environments. We believe that such features should be embedded in programming environments for distributed applications. In this work we present how we included QoS control features in a programming language that since years has been adopted for the development of network-based applications: Tcl. We present QTcl, an extension of Tcl, which provides program- mers with a new set of primitives fully compliant with the standard SCRAPI programming interface for the RSVP protocol. We gave QTcl a high portability, in that it enables standard QoS negotiation to be performed in a seamless fashion on the most common operating systems. Roberto Canonico, Maurizio D'Arienzo, B. Fadini, Simon Pietro Romano, Giorgio Ventre |
SEKE | 4 |
| 2002 | Designing service negotiation entities for the electronic market-placeabstractThe emergence of service providers and brokers who are independent of network providers has opened the way to a spot market in free network resources: it is under everybody's eyes that market enabled service provision based on Service Level Agreements (SLAs) will be essential for the delivery of many services such as bandwidth on demand. In order for those services to be created, configured and delivered dynamically via automated SLAs, a market enabling mechanism is required that is sufficiently flexible to convey the varying information requirements of the various stakeholders involved in the service delivery chain, together with their internal processes. In this paper an innovative framework for the negotiation of services with quality assurances is presented. The study is conducted keeping an eye on the latest standard proposals coming from the electronic business research community, with respect to both the modeling methodology and the actual design for implementation. Salvatore D'Antonio, B. Fadini, Simon Pietro Romano, Giorgio Ventre |
SEKE | 3 |
| 2000 | A Scheme for Time-Dependent Resource Reservation in QoS-Enabled IP Networks
Roberto Canonico, Simon Pietro Romano, Mauro Sellitto, Giorgio Ventre |
NETWORKING | 2 |