Miguel C. Neves

dblp:129/2290 · also Miguel Cardoso Neves · DBLP profile ↗
← Back
18ranked-venue papers
3as first author
8since 2021 · last 2025
0000-0002-6586-2846ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 12 · 3 first-author · 4 since 2021Systems, architecture and hardware · 2 · 2 since 2021Security and privacy · 1
YearPublicationVenuePosition
2025 On the Deployment Feasibility of Message Oriented Middlewares in Mission-critical Applications
abstract
Mission-critical applications (MCA) like smart grid management, first-aid response, and tactical coordination in military search and rescue operations refer to applications that can pose a risk to human lives or cause extensive and catastrophic losses. The deployment and management of these applications need careful consideration to meet the stringent performance demand of resource-constrained environments. One way to achieve such performance and dependability demand is to adopt Message Oriented Middlewares (MOMs) (e.g., Apache Kafka, RabbitMQ) as they enable real-time data analytics and informed decision making. Despite their extensive usage in legacy business intelligent applications, little is known about their suitability for mission-critical applications. This paper fills that gap by first deploying and testing mission-critical applications on Apache Kafka and RabbitMQ. Then, we measure the performance, security, and reliability of the chosen MOMs to support MCA. The evaluation results confirm that Apache Kafka outperforms RabbitMQ, making it a potential candidate to deploy MCA. Specifically, Kafka requires 13x less bandwidth than RabbitMQ, which could be further reduced by 85% using effective parameter tuning. Our findings pave the way for MOMs to be adopted in MCAs to meet their stringent performance and dependability demands.
Md. Monzurul Amin Ifath, Miguel C. Neves, Tommaso Melodia, Israat Haque 0001
GLOBECOM2
2024 PoirIoT: Fingerprinting IoT Devices at Tbps Scale
abstract
The massive growth in popularity of household IoT devices has brought new capabilities to our lives while also bringing new challenges to network providers. In particular, large numbers of devices have been used to cause disruptions to critical Internet services. Understanding which devices are connected to a network empowers administrators to mitigate threats with target-specific interventions. This information is obtained by analyzing traffic through a process known as device fingerprinting. Current device fingerprinting solutions face major scalability issues in high-speed and high-volume networks, either relying on middleboxes to perform their tasks or targeting a single household. This paper introduces a novel in-network fingerprinting system, PoirIoT, capable of real-time, accurate, and scalable IoT device fingerprinting. Specifically, PoirIoT takes advantage of recent programmable switches and use standard packet metadata, length, and direction information to gain high-throughput and per-packet fingerprinting granularity. We show the effectiveness (100% device detection accuracy) of our solution using a publicly available dataset on a testbed consisting of Intel Tofino switches. Moreover, PoirIoT adds no additional latency to the regular traffic flow and utilizes minimal switch resources (e.g., memory).
Carson Kuzniar, Miguel C. Neves, Vladimir Gurevich, Israat Haque 0001
IEEE/ACM Trans. Netw.2
2023 Fast Prototyping of Distributed Stream Processing Applications with stream2gym
abstract
Stream processing applications have been widely adopted due to real-time data analytics demands, e.g., fraud detection, video analytics, IoT applications. Unfortunately, prototyping and testing these applications is still a cumbersome process for developers that usually requires an expensive testbed and deep multi-disciplinary expertise, including in areas such as networking, distributed systems, and data engineering. As a result, it takes a long time to deploy stream processing applications into production and yet users face several correctness and performance issues. In this paper, we present stream2gym, a tool for the fast prototyping of large-scale distributed stream processing applications. stream2gym builds on Mininet, a widely adopted network emulation platform, and provides a high-level interface to enable developers to easily test their applications under various operating conditions. We demonstrate the benefits of stream2gym by prototyping and testing several applications as well as reproducing key findings from prior research work in video analytics and network traffic monitoring. Moreover, we show stream2gym presents accurate results compared to a hardware testbed while consuming a small amount of resources (enough to be supported in a single commodity laptop even when emulating a dozen of processing nodes).
Md. Monzurul Amin Ifath, Miguel C. Neves, Israat Haque 0001
ICDCS2
2022 Predicting and Avoiding SLA Violations of Containerized Applications using Machine Learning and Elasticity
abstract
Container-based virtualization represents a low-overhead and easy-to-manage alternative to virtual machines.On the other hand, containers are more prone to performance interference and unpredictability.Consequently, there is growing interest in predicting and avoiding performance issues in containerized environments.Existing solutions tackle this challenge through proactive elasticity mechanisms based on workload variation predictions.Although this approach may yield satisfactory results in some scenarios, external factors such as resource contention can cause performance losses regardless of workload variations.This paper presents Flavor, a machine-learning-based system for predicting and avoiding performance issues in containerized applications.Rather than relying on workload variation prediction as existing approaches, Flavor predicts application-level metrics (e.g., query latency and throughput) through a deep neural network implemented using Tensorflow and scales applications accordingly.We evaluate Flavor by comparing it against a state-ofthe-art resource scaling approach that relies solely on workload prediction.Our results show that Flavor can predict performance deviations effectively while assisting operators to wisely scale their services by increasing/decreasing the number of application containers to avoid performance issues and resource underutilization.
Paulo Silas Severo de Souza, Miguel C. Neves, Carlos Henrique Kayser, Felipe Rubin, Conrado Boeira, Bernardo Bordin, Tiago Ferreto
CLOSER2
2022 IoT Device Fingerprinting on Commodity Switches
abstract
IoT devices such as wearables, voice assistants and home appliances are becoming an integral part of our lives. However, these devices still represent a security and privacy risk with large-scale coordinated attacks often populating the news. The ability to tell which IoT devices are where in a network (i.e., to fingerprint them) can help administrators to mitigate such attacks at the earliest stages. While fingerprinting solutions exist, they often work offline, depend on sampled data or rely on payload information to work. In this paper, we propose PoirIoT, a high-speed in-network system for fingerprinting IoT devices. PoirIoT is based only on packet metadata (e.g., length and direction) and can detect a device as soon as it exchanges its first packets. We implement a prototype of PoirIoT on a Tofino-based programmable switch and show it can detect all possible IoT devices on a publicly available dataset. Moreover, PoirIoT runs at line rate and incurs minimal resource overhead on the programmable switch ASIC.
Carson Kuzniar, Miguel C. Neves, Vladimir Gurevich, Israat Haque 0001
NOMS2
2021 Raptor: rapid prototyping of distributed stream processing applications at scale
abstract
Stream processing applications are becoming increasingly important in areas such as IoT, video analytics and social media. As a result, developers and operators must meet stringent time-to-market and scale requirements before bringing them to production. Unfortunately, testing a networked stream processing system is currently a cumbersome process that usually requires an expensive testbed and deep expertise on both networking and distributed systems. In this poster, we present Raptor, a tool for the fast prototyping of large-scale networked stream processing applications. Raptor builds on Mininet and Apache Kafka, two widely adopted platforms, to enable stakeholders to easily test their solutions under various operational conditions. Through a reasonably large setup (20 nodes) running on a single server, we show how unbalanced Kafka's leader selection algorithm can be and its implications on the overall system's throughput. We envision this work can help paving the way for more reproducible research in the stream processing domain, currently a first-class network application.
Md. Monzurul Amin Ifath, Miguel C. Neves, Israat Haque 0001
CoNEXT2
2021 Towards Network-accelerated ML-based Distributed Computer Vision Systems
abstract
Computer vision is a crucial component in many modern applications (e.g., medical image analysis, environmental monitoring and self-driving cars). However, their stringent computational, latency and bandwidth requirements still pose a huge challenge to system architects, which must seek for alternatives to both the limited resources (e.g., low-end CPU) on client devices and the hurdles of moving data from clients to cloud/edge servers for analysis. In this work, we advocate for the usage of emerging programmable network devices to speed up ML-based computer vision tasks, particularly image classification, on resource constrained environments. To take the first step towards this new paradigm, we propose NetPixel, a framework that enables P4-programmable switches to classify images in realtime, accurately and at scale. We implemented a prototype of NetPixel in a software switch to show its feasibility and conducted a preliminary evaluation on widely adopted datasets. Our results show that NetPixel can classify images with an accuracy within 8% that of a server-based implementation even for shallow classifiers and low-resolution images.
Hisham Siddique, Miguel C. Neves, Carson Kuzniar, Israat Haque 0001
ICPADS2
2021 Dynamic Property Enforcement in Programmable Data Planes
abstract
Network programmers can currently deploy an arbitrary set of protocols in forwarding devices through data plane programming languages such as P4. However, as any other type of software, P4 programs are subject to bugs and misconfigurations. Network verification tools have been proposed as a means of ensuring that the network behaves as expected, but these tools frequently face severe scalability issues. In this paper, we argue for a novel approach to this problem. Rather than statically inspecting a network configuration looking for bugs, we propose to enforce networking properties at runtime. To this end, we developed P4box, a system for deploying runtime monitors in programmable data planes. P4box allows programmers to easily express a broad range of properties (both program-specific and network-wide). Moreover, we provide an automated framework based on assertions and symbolic execution for ensuring monitor correctness. Our experiments on a SmartNIC show that P4box monitors represent a small overhead to network devices in terms of latency, throughput and power consumption.
Miguel C. Neves, Bradley Huffaker, Kirill Levchenko, Marinho P. Barcellos
IEEE/ACM Trans. Netw.1
2020 SafeGuard: Congestion and Memory-aware Failure Recovery in SD-WAN
abstract
In software-defined WANs (SD-WAN), link failure can lead to congestion and packet loss, hence degrading application performance. State-of-the-art traffic engineering approaches can speed up failure recovery by proactively installing backup tunnels and redirecting affected traffic immediately in the data plane, which reduces the burden on the network controller. However, these approaches either lead to bandwidth waste because of reserved link capacity or impose restrictions on network topologies, e.g., the existence of link-disjoint routes or large switch memory resources. In this paper, we propose SafeGuard, a software-defined proactive recovery system that improves bandwidth allocation and switch-memory usage while working on any connected network. We formulate the failure recovery problem as a multi-objective MILP optimization problem for all possible single link failures, the most common case in current WANs as temporally-coinciding failures are rare. We then develop a heuristic to efficiently compute backup routes as the problem is NP-Hard. We implemented a prototype of SafeGuard using the Ryu SDN controller and extensively evaluate it in Mininet over two real topologies, Google B4 and ATT. Our results show that SafeGuard can reduce the number of congested links by up to 50% compared to the state-of-the-art failure recovery scheme.
Meysam Shojaee, Miguel C. Neves, Israat Haque 0001
CNSM2
2020 POSTER: Accelerating Encrypted Data Stores Using Programmable Switches
abstract
This poster presents P4-EncKV, an in-network proxy for accelerating encrypted data stores using recent programmable switches. P4-EncKV can perform operations over encrypted data while reducing query latency and required bandwidth. As proof-of-concept, we implement a prototype of P4-EncKV using BMv2 software switch, and show it can speedup encrypted queries by 20-25% using basic caching operations. Our optimized cache design also reduces memory consumption by 18% compared to the state-of-the-art in-network caching approach, thanks to a novel hash-based indexing scheme.
Carson Kuzniar, Miguel C. Neves, Israat Haque 0001
ICNP2
2019 Dynamic Property Enforcement in Programmable Data Planes
abstract
Network programmers can currently deploy an arbitrary set of protocols in forwarding devices through data plane programming languages such as P4. However, as any other type of software, P4 programs are subject to bugs and misconfigurations. Network verification tools have been proposed as a means of ensuring that the network behaves as expected, but these tools typically require programmers to manually model P4 programs, are limited in terms of the properties they can guarantee and frequently face severe scalability issues. In this paper, we argue for a novel approach to this problem. Rather than statically inspecting a network configuration looking for bugs, we propose to enforce networking properties at runtime. To this end, we developed P4box, a system for deploying runtime monitors in programmable data planes. Our results show that P4box allows programmers to easily express a broad range of properties. Moreover, we demonstrate that runtime monitors represent a small overhead to network devices in terms of latency and resource consumption.
Miguel C. Neves, Bradley Huffaker, Kirill Levchenko, Marinho P. Barcellos
Networking1
2018 Verification of P4 programs in feasible time using assertions
abstract
Recent trends in software-defined networking have extended network programmability to the data plane. Unfortunately, the chance of introducing bugs increases significantly. Verification can help prevent bugs by assuring that the program does not violate its requirements. Although research on the verification of P4 programs is very active, we still need tools to make easier for programmers to express properties and to rapidly verify complex invariants. In this paper, we leverage assertions and symbolic execution to propose a more general P4 verification approach. Developers annotate P4 programs with assertions expressing general network correctness properties; the result is transformed into C models and all possible paths symbolically executed. We implement a prototype, and use it to show the feasibility of the verification approach. Because symbolic execution does not scale well, we investigate a set of techniques to speed up the process for the specific case of P4 programs. We use the prototype implemented to show the gains provided by three speed up techniques (use of constraints, program slicing, parallelization), and experiment with different compiler optimization choices. We show our tool can uncover a broad range of bugs, and can do it in less than a minute considering various P4 applications.
Miguel C. Neves, Lucas Freire, Alberto E. Schaeffer Filho, Marinho P. Barcellos
CoNEXT1
2017 POSTER: Finding Vulnerabilities in P4 Programs with Assertion-based Verification
abstract
Current trends in SDN extend network programmability to the data plane through the use of programming languages such as P4. In this context, the chance of introducing errors and consequently software vulnerabilities in the network increases significantly. Existing data plane verification mechanisms are unable to model P4 programs or present severe restrictions in the set of modeled properties. To overcome these limitations and make programmable data planes more secure, we present a P4 program verification technique based on assertion checking and symbolic execution. First, P4 programs are annotated with assertions expressing general correctness and security properties. Then, the annotated programs are transformed into C code and all their possible paths are symbolically executed. Results show that it is possible to prove properties in just a few seconds using the proposed technique. Moreover, we were able to uncover two potential vulnerabilities in a large scale P4 production application.
Lucas Freire, Miguel C. Neves, Alberto E. Schaeffer Filho, Marinho P. Barcellos
CCS2
2016 PredCloud: Providing predictable network performance in large-scale OpenFlow-enabled cloud platforms through trust-based allocation of resources
Daniel S. Marcon, Miguel C. Neves, Rodrigo Ruas Oliveira, Luciano Paschoal Gaspary, Marinho P. Barcellos
Comput. Commun.2
2015 IoNCloud: Exploring application affinity to improve utilization and predictability in datacenters
abstract
The intra-cloud network is typically shared in a best-effort manner, which causes tenant applications to have no actual bandwidth guarantees. Recent proposals address this issue either by statically reserving a slice of the physical infrastructure for each application or by providing proportional sharing among flows. The former approach results in overprovisioned network resources, while the latter requires substantial management overhead. In this paper, we introduce a resource allocation strategy that aims at providing an efficient way to predictably share bandwidth among applications and at minimizing resource underutilization while maintaining low management overhead. To demonstrate the benefits of the strategy, we develop IoNCloud, a system that implements the proposed allocation scheme. IoNCloud employs the abstraction of attraction/repulsion among applications according to their temporal bandwidth demands in order to group them in virtual networks. In doing so, we explore the trade-off between high resource utilization (which is desired by providers to achieve economies of scale) and strict network guarantees (necessary for tenants to run jobs predictably). Evaluation results show that IoNCloud can (a) provide predictable network sharing; and (b) reduce allocated bandwidth, resource underutilization and management overhead when compared against state-of-the-art proposals.
Daniel S. Marcon, Miguel C. Neves, Rodrigo Ruas Oliveira, Leonardo Richter Bays, Raouf Boutaba, Luciano Paschoal Gaspary, Marinho P. Barcellos
ICC2
2015 Opportunistic resilience embedding (ORE): Toward cost-efficient resilient virtual networks
abstract
Network Virtualization promotes the development of new architectures and protocols by enabling the creation of multiple virtual networks on top of the same physical substrate. One of its main advantages is the use of isolation to limit the scope of attacks – that is, avoiding traffic from one virtual network to interfere with the others. However, virtual networks are still vulnerable to disruptions on the underlying network. Particularly, high capacity physical links constitute good targets since they may be important for a large number of virtual networks. Previous work protects virtual networks by setting aside backup resources. Although effective, this kind of solution tends to be expensive, as backup resources increase the cost to infrastructure providers and usually remain idle. This paper presents ORE (opportunistic resilience embedding), a novel embedding approach for protecting virtual links against substrate network disruptions. ORE’s design is two-fold: while a proactive strategy embeds each virtual link into multiple substrate paths in order to mitigate the initial impact of a disruption, a reactive one attempts to recover any capacity affected by an underlying disruption. Both strategies are modeled as optimization problems . Additionally, since the embedding problem is NP -Hard, ORE uses a simulated annealing-based meta-heuristic to solve it efficiently. Numerical results show that ORE can provide resilience to disruptions at a lower cost.
Rodrigo Ruas Oliveira, Daniel S. Marcon, Leonardo Richter Bays, Miguel C. Neves, Luciano Paschoal Gaspary, Deep Medhi, Marinho P. Barcellos
Comput. Networks4
2013 No more backups: Toward efficient embedding of survivable virtual networks
abstract
Although network virtualization can improve security by isolating traffic from different networks, routers and links are still vulnerable to attacks on the underlying network. High capacity physical links, in particular, constitute good targets since they may be important for a large number of virtual networks. Previous work protects virtual networks by setting aside backup resources. Although effective, this solution increases the cost to infrastructure providers. In this paper, we present a virtual network embedding approach which enables resilience to attacks and efficiency in resource utilization. Our approach is two-folded: while a preventive strategy embeds virtual links into multiple substrate paths, a reactive strategy attempts to reallocate any capacity affected by an underlying DoS attack. Since the embedding problem is NP-Hard, we devise a Simulated Annealing meta-heuristic to solve it efficiently. Results show our solution can provide resilience to attacks at a lower cost.
Rodrigo Ruas Oliveira, Daniel S. Marcon, Leonardo Richter Bays, Miguel C. Neves, Luciana S. Buriol, Luciano Paschoal Gaspary, Marinho P. Barcellos
ICC4
2013 Trust-based grouping for cloud datacenters: Improving security in shared infrastructures
Daniel S. Marcon, Rodrigo Ruas Oliveira, Miguel C. Neves, Luciana S. Buriol, Luciano Paschoal Gaspary, Marinho P. Barcellos
Networking3