VLDB 2026 Research / reviewers in the wild / expert
Filippo Rebecchi
dblp:134/7810
· DBLP profile ↗
13ranked-venue papers
6as first author
6since 2021 · last 2025
0000-0002-3946-9047ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 5 first-author · 4 since 2021Software engineering, systems software and programming languages · 2 · 1 first-authorSecurity and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | RRC Signaling Storm Detection in O-RANabstractThe Open Radio Access Network (O-RAN) marks a significant shift in the mobile network industry. By transforming a traditionally vertically integrated architecture into an open, data-driven one, O-RAN promises to enhance operational flexibility and drive innovation. In this paper, we harness O-RAN’s openness to address one critical threat to 5G availability: signaling storms caused by abuse of the Radio Resource Control (RRC) protocol. Such attacks occur when a flood of RRC messages from one or multiple User Equipments (UEs) deplete resources at a 5 G base station (gNB), leading to service degradation. We provide a reference implementation of an RRC signaling storm attack, using the OpenAirInterface (OAI) platform to evaluate its impact on a gNB. We supplement the experimental results with a theoretical model to extend the findings for different load conditions. To mitigate RRC signaling storms, we develop a threshold-based detection technique that relies on RRC layer features to distinguish between malicious activity and legitimate high network load conditions. Leveraging O-RAN capabilities, our detection method is deployed as an external Application (xApp). Performance evaluation shows attacks can be detected within 90 ms, providing a mitigation window of 60 ms before gNB unavailability, with an overhead of $1.2 \%$ and $0 \%$ CPU and memory consumption, respectively. Dang Kien Nguyen, Rim El Malki, Filippo Rebecchi |
ISCC | 3 |
| 2025 | Managing Differentiated Secure Connectivity using IntentsabstractMobile networks in the 5G and 6G era require to rethink how to manage security due to the introduction of new services, use cases, each with its own security requirements, while simultaneously expanding the threat landscape. Although automation has emerged as a key enabler to address complexity in networks, existing approaches lack the expressiveness to define and enforce complex, goal-driven, and measurable security requirements. In this paper, we propose the concept of differentiated security levels and leveraging intents as a management framework. We discuss the requirements and enablers to extend the currently defined intent-based management frameworks to pave the path for intent-based security management in mobile networks. Our approach formalizes both functional and nonfunctional security requirements and demonstrates how these can be expressed and modeled using an extended TM Forum (TMF) intent security ontology. We further discuss the required standardization steps to achieve intent-based security management. Our work aims at advance security automation, improve adaptability, and strengthen the resilience and security posture of the next-generation mobile networks Loay Abdelrazek, Filippo Rebecchi |
MSWiM | 2 |
| 2025 | Beyond Static Thresholds: Adaptive RRC Signaling Storm Detection with Extreme Value TheoryabstractIn 5G and beyond networks, the radio communication between a User Equipment (UE) and a base station (gNodeB or gNB), also known as the air interface, is a critical component of network access and connectivity. During the connection establishment procedure, the Radio Resource Control (RRC) layer can be vulnerable to signaling storms, which threaten the availability of the radio access control plane. These attacks may occur when one or more UEs send a large number of connection requests to the gNB, preventing new UEs from establishing connections. In this paper, we investigate the detection of such threats and propose an adaptive threshold-based detection system based on Extreme Value Theory (EVT). The proposed solution is evaluated numerically by applying simulated attack scenarios based on a realistic threat model on top of real-world RRC traffic data from an operator network. We show that, by leveraging features from the RRC layer only, the detection system can not only identify the attacks but also differentiate them from legitimate high-traffic situations. The adaptive threshold calculated using EVT ensures that the system works well under diverse threat scenarios. The results show high accuracy, precision, and recall values (above 93%), and a low detection latency even under complex conditions. Dang Kien Nguyen, Rim El Malki, Filippo Rebecchi, Raymond Knopp, Melek Önen |
MSWiM | 3 |
| 2022 | Learning State Machines to Monitor and Detect Anomalies on a Kubernetes ClusterabstractThese days more companies are shifting towards using cloud environments to provide their services to their client. While it is easy to set up a cloud environment, it is equally important to monitor the system’s runtime behaviour and identify anomalous behaviours that occur during its operation. In recent years, the utilisation of Recurrent Neural Networks (RNNs) and Deep Neural Networks (DNNs) to detect anomalies that might occur during runtime has been a trending approach. However, it is unclear how to explain the decisions made by these networks and how these networks should be interpreted to understand the runtime behaviour that they model. On the contrary, state machine models provide an easier manner to interpret and understand the behaviour that they model. In this work, we propose an approach that learns state machine models to model the runtime behaviour of a cloud environment that runs multiple microservice applications. To the best of our knowledge, this is the first work that tries to apply state machine models to microservice architectures. The state machine model is used to detect the different types of attacks that we launch on the cloud environment. From our experiment results, our approach can detect the attacks very well, achieving a balanced accuracy of 99.2% and a F1 score of 0.982. Clinton Cao, Agathe Blaise, Sicco Verwer, Filippo Rebecchi |
ARES | 4 |
| 2022 | Stay at the Helm: secure Kubernetes deployments via graph generation and attack reconstructionabstractIn recent years, there has been an explosion of attacks directed at microservice-based platforms – a trend that follows closely the massive shift of the digital industries towards these environments. Management and operation of container-based microservices is automation-heavy, leveraging on container orchestration engines such as Kubernetes (K8s). Helm is the package manager of choice for K8s and provides Charts, i.e., configuration files that define a programmatic model for application deployments. In this paper, we propose a novel methodology for extracting and evaluating the security model of Helm Charts. Our proposal extracts a topological graph of the Chart, whose nodes and edges are then characterised by security features. We carry out risk assessments that refer to the attack tactics of the MITRE ATT&CK framework. Furthermore, starting from these scores, we extract the riskiest attack paths. We adopt an experimental validation approach by analysing a dataset created from multiple publicly accessible Helm Chart repositories. Our methodology reveals that, in most cases, they have vulnerabilities that can be exploited through complex attack paths. Agathe Blaise, Filippo Rebecchi |
CLOUD | 2 |
| 2022 | A Digital Twin for the 5G Era: the SPIDER Cyber RangeabstractService providers, 5G network operators and, more generally, vertical industries face today a dangerous shortage of highly skilled cybersecurity experts. Along with the escalation and growing sophistication of cyber-attacks, 5G networks require the training of skilled and highly competent cyber forces. To meet these requirements, the SPIDER cyber range focuses specifically on 5G, and is based on three pillars, (i) cyber security assessment, (ii) training cyber security teams to defend against complex cyber-attack scenarios, and (iii) evaluation of cyber risk. The SPIDER cyber range replicates a customized 5G network, enabling the execution of cyber-exercises that take advantage of hands-on interaction in real time, the sharing of information between participants, and the gathering of feedback from network equipment, as well as the development and adaptation of advanced operational procedures. This aims to help 5G security professionals improve their ability to collaboratively manage and predict security incidents, complex attacks, and propagated vulnerabilities. The SPIDER cyber range is validated in two relevant use case scenarios aimed at demonstrating, in a realistic, measurable, and replicable way the transformations SPIDER will bring to the cybersecurity industry. Filippo Rebecchi, Antonio Pastor 0001, Alberto Mozo, Chiara Lombardo, Roberto Bruschi, Ilias Aliferis, Roberto Doriguzzi Corin, Panagiotis Gouvas, Antonio Álvarez Romero, Anna Angelogianni, Ilias Politis, Christos Xenakis |
WoWMoM | 1 |
| 2017 | Statesec: Stateful monitoring for DDoS protection in software defined networksabstractSoftware-Defined Networking (SDN) allows for fast reactions to security threats by dynamically enforcing simple forwarding rules as counter-measures. However, in classic SDN all the intelligence resides at the controller, with the switches only capable of performing stateless forwarding as ruled by the controller. It follows that the controller, in addition to network management and control duties, must collect and process any piece of information required to take advanced (stateful) forwarding decisions. This threatens both to overload the controller and to congest the control channel. On the other hand, stateful SDN represents a new concept, developed both to improve reactivity and to offload the controller and the control channel by delegating local treatments to the switches. In this paper, we adopt this stateful paradigm to protect end-hosts from Distributed Denial of Service (DDoS). We propose StateSec, a novel approach based on in-switch processing capabilities to detect and mitigate DDoS attacks. StateSec monitors packets matching configurable traffic features (e.g., IP src/dst, port src/dst) without resorting to the controller. By feeding an entropy-based algorithm with such monitoring features, StateSec detects and mitigates several threats such as (D)DoS and port scans with high accuracy. We implemented StateSec and compared it with a state-of-the-art approach to monitor traffic in SDN. We show that StateSec is more efficient: it achieves very accurate detection levels, limiting at the same time the control plane overhead. Julien Boite, Pierre-Alexis Nardin, Filippo Rebecchi, Mathieu Bouet, Vania Conan |
NetSoft | 3 |
| 2017 | Traffic monitoring and DDoS detection using stateful SDNabstractWe propose to showcase the benefits of stateful SDN in the context of DDoS detection and mitigation. By delegating some local tasks to the switch rather than relying always on the controller, it is possible to monitor data-plane traffic efficiently and to detect malicious network behaviours with high accuracy. Stateful SDN concepts are employed both to improve reactivity and to offload the controller and the control channel by delegating local treatments down to the switches. The demo illustrates how to protect end-hosts from Distributed Denial of Service (DDoS) attacks. Our approach, named StateSec, is built on advanced in-switch processing capabilities to detect and mitigate threats swiftly. StateSec relies on a detection loop to: 1) match and count a configurable set of traffic features (e.g., IP source and destination, port source and destination) without resorting to the controller; 2) use an entropy-based detection algorithm with such monitored features, 3) detect several threats such as (D)DoS and port scans with high accuracy, and 4) take countermeasures by installing OpenFlow rules at the switch. Filippo Rebecchi, Julien Boite, Pierre-Alexis Nardin, Mathieu Bouet, Vania Conan |
NetSoft | 1 |
| 2016 | Should I seed or should I not: On the remuneration of seeders in D2D offloadingabstractTraffic offloading using opportunistic device-to-device (D2D) communications is a new and exciting opportunity for cellular operators to cope with the unprecedented mobile data growth. A limitation of existing proposals is that they assume that all terminals are, by default, involved in the D2D forwarding process. In particular, they do not capture the need to reward seed users. For this reason, we include a rewarding cost in the design of the opportunistic offloading strategy. In our solution, we make the difference between nodes that receive content through the cellular channel only (leechers) and nodes that take part in the forwarding process (seeders). The key point for an operator is to design a global strategy to select which nodes act as seeders and which ones as leechers, in order to reduce the total dissemination cost. We formulate this question as a stochastic control problem that we solve using an application of Pontryagin's Maximum Principle. We provide a mathematical framework to devise the optimal strategy for opportunistic offloading under a generic cost model. First, we show that an optimal solution exists; then, from this policy, we extract some insights to develop heuristics. Finally, we discuss the advantages of the proposed model compared to the classic seeder-only model. We demonstrate that separating seeders/leechers leads to better incentive strategies in the most demanding cases of content with a large span of delivery delays. Filippo Rebecchi, Marcelo Dias de Amorim, Vania Conan |
WoWMoM | 1 |
| 2016 | Circumventing plateaux in cellular data offloading using adaptive content reinjection
Filippo Rebecchi, Marcelo Dias de Amorim, Vania Conan |
Comput. Networks | 1 |
| 2015 | Demo: D2D Rescue of Overloaded Cellular ChannelsabstractMobile data traffic is set to triple in three years from now according to Cisco. This trend is a real challenge for operators since wireless capacity is bounded. Farid Benbadis, Filippo Rebecchi, Florian Cosnier, Matteo Sammarco, Marcelo Dias de Amorim, Vania Conan |
MobiSys | 2 |
| 2015 | A joint multicast/D2D learning-based approach to LTE traffic offloading
Filippo Rebecchi, Lorenzo Valerio, Raffaele Bruno 0001, Vania Conan, Marcelo Dias de Amorim, Andrea Passarella |
Comput. Commun. | 1 |
| 2014 | DROid: Adapting to individual mobility pays off in mobile data offloadingabstractCellular operators count on the potentials of offloading techniques to relieve their overloaded data channels. Beyond standard access point-based offloading strategies, a promising alternative is to exploit opportunistic direct communication links between mobile devices. Nevertheless, achieving efficient device-to-device offloading is challenging, as communication opportunities are, by nature, dependent on individual mobility patterns. We propose, design, and evaluate DROiD (Derivative Re-injection to Offload Data), an original method to finely control the distribution of popular contents throughout a mobile network. The idea is to use the infrastructure resources as seldom as possible. To this end, DROiD injects copies through the infrastructure only when needed: (i) at the beginning, in order to trigger the dissemination, (ii) if the evolution of the opportunistic dissemination is below some expected pace, and (iii) when the delivery delay is about to expire, in order to guarantee 100% diffusion. Our strategy is particularly effective in highly dynamic scenarios, where sudden creation and dissolution of clusters of mobile nodes prevent contents to diffuse properly. We assess the performance of DROiD by simulating a traffic information service on a realistic large-scale vehicular dataset composed of more than 10,000 nodes. DROiD substantially outperforms other offloading strategies, saving more than 50% of the infrastructure traffic even in the case of tight delivery delay constraints. DROiD allows terminal-to-terminal offloading of data with very short maximum reception delay, in the order of minutes, which is a realistic bound for cellular user acceptance. Filippo Rebecchi, Marcelo Dias de Amorim, Vania Conan |
Networking | 1 |