Mario Di Mauro

dblp:141/0295 · DBLP profile ↗
← Back
39ranked-venue papers
19as first author
25since 2021 · last 2026
0000-0001-6574-2601ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 7 first-author · 6 since 2021Security and privacy · 8 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 6 · 4 first-author · 4 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Transient-Aware Performability of Softwarized 5G Service Chains under Non-Exponential Failure Models
Mario Di Mauro, Maurizio Longo, Fabio Postiglione, Ermanno Troisi
NetSoft1
2026 A framework for binary classification evaluation metrics
abstract
This paper presents a novel framework for analyzing and designing evaluation metrics in binary classification tasks. Traditional metrics—such as Accuracy, Precision, Recall, F1-score, and Cohen’s —often embed implicit assumptions about the relative costs and benefits of correct and incorrect predictions. However, these assumptions are not always transparent and may not align with domain-specific cost–benefit structures. By systematically evaluating classifiers through an underlying reward matrix, the proposed framework reveals that each metric reduces to a single break-even ratio between the resources invested and the value gained. This connects classical confusion matrix based metrics to an explicit cost–benefit interpretation. We derive this ratio explicitly for several widely used confusion matrix based metrics, thereby making their implicit trade-offs directly comparable under a unified interpretation. The paper demonstrates how metric values can be interpreted and applied to comprehensively assess classifier performance. Additionally, the framework allows researchers to define new metrics tailored to specific problem requirements. Experiments with commonly used metrics illustrate the framework’s broad applicability and highlight the value of explicitly modeling both costs and benefits for more context-sensitive performance evaluation.
Mohammad Shirdel, Mario Di Mauro, Antonio Liotta
Inf. Sci.2
2026 Performance Assessment of Multi-Class 5G Chains: A Non-Product-Form Queueing Networks Approach
abstract
This work presents a performance assessment of 5G Service Function Chains (SFCs) by examining and comparing two architectural models. The first is the Mono chain model, which relies on a single path for data processing through a series of 5G nodes, ensuring straightforward and streamlined service delivery. The second is the Poly (or sliced) chain model, which leverages multiple paths for data flow, enhancing load balancing and resource distribution across nodes to improve network resilience. To evaluate the performance of these models, we introduce a performance indicator that captures two critical stages: the time required for user registration to the 5G infrastructure and the time needed for Protocol Data Unit (PDU) session establishment. From a performance standpoint, these stages are deemed crucial by the European Telecommunications Standards Institute (ETSI), as they can adversely affect both objective and subjective network parameters. Using a non-product-form queueing network approach, we develop an algorithm named ChainPerfEval, which accurately estimates the proposed performance indicator. This approach outperforms standard queueing network models, where the exponential assumption of inter-arrival and/or service times may lead to an inaccurate estimation of the performance indicator. An extensive experimental campaign is conducted using an Open5GS testbed to simulate real-world traffic scenarios, categorizing 5G flows into three priority classes: gold (high priority), silver (moderate priority), and bronze (low priority). The results provide significant insights into the trade-offs between the Mono and Poly chain models, particularly in terms of resource allocation strategies and their impact on SFC performance. Ultimately, this comprehensive analysis offers valuable and actionable recommendations for network operators seeking to optimize service delivery in multi-class 5G environments, ensuring enhanced user experience and efficient resource utilization.
Mario Di Mauro
IEEE Trans. Netw. Serv. Manag.1
2025 Queueing-Based Performance Analysis of 5G Service Function Chains
abstract
In this work we propose a queueing-based framework for evaluating the performance of 5 G Service Function Chains (SFCs), focusing on the impact of delays at virtualized network nodes on end-to-end service delivery. Our approach employs an $M / G / k$ queueing model to characterize the delays in control and data plane nodes. Additionally, we introduce a greedy optimization algorithm, OptInst, to determine the minimum number of instances (e.g., containers or processes) to be deployed on 5 G nodes to meet performance constraints. Using a realistic testbed based on Open5GS and UERANSIM platforms, we estimate the service times of the nodes and identify the optimal SFC deployment that minimizes resource consumption while fulfilling delay constraints. Our findings demonstrate the effectiveness of the proposed model in optimizing 5 G network performance and offer insights into balancing delay requirements with resource efficiency.
Mario Di Mauro, Raffaele Peluso
CNSM1
2025 Performability Management of 5G Service Chains with Rejuvenation: The Open5GS Use Case
abstract
This paper presents a stochastic framework for managing the performability (performance and availability) of 5G-based service function chains (SFCs). By integrating an$M / G / m$queueing model for latency estimation and Stochastic Reward Networks (SRNs) for availability assessment, we evaluate the impact of software rejuvenation on 5 G network performability. The final goal is to derive the optimal 5G setting that meets both performance (e.g., delay threshold) and availability (e.g., the “five nines”). Our testbed, based on Open5GS, validates the model and provides insights into optimal 5G settings that balance performance, availability, and resource utilization.
Luigi De Simone, Mario Di Mauro, Maurizio Longo, Roberto Natella, Fabio Postiglione
NetSoft2
2024 Exploring Evaluation Metrics for Binary Classification in Data Analysis: the Worthiness Benchmark Concept
Mohammad Shirdel, Mario Di Mauro, Antonio Liotta
DaWaK2
2024 Unsupervised Underwater Image Enhancement Combining Imaging Restoration and Prompt Learning
Wei Song 0007, Chengbing Liu, Mario Di Mauro, Antonio Liotta
PRCV (2)3
2024 Hybrid learning strategies for multivariate time series forecasting of network quality metrics
abstract
This work addresses the challenge of forecasting temporal metrics that characterize cellular traffic behavior. The ultimate goal is to provide network operators with a valuable tool for modeling mobile network traffic and optimizing connected resources. The idea is to estimate beforehand the temporal evolution of some Quality-of-Experience (QoE) and Quality-of-Service (QoS) metrics, which is helpful for accurately tuning the allocation of network resources. Remarkably, these metrics (expressed as time series) are typically correlated, and changes in one time series can affect others in a variety of ways and to different extents. For example, high network delay (a QoS-related metric) is associated with degradation in voice quality over time (a QoE-related metric). Accordingly, we address the problem of cellular traffic forecasting with correlated time series, proposing three innovative hybrid learning strategies designed by combining the advantages of two approaches: (i) a statistical approach, implemented through the Vector Autoregressive (VAR) model, which encodes each metric as a combination of past values of the same metric along with a combination of values of other related metrics, resulting in a multivariate structure; and (ii) an approach based on deep learning techniques (specifically, CNN, LSTM, and GRU) which operate on such a multivariate structure to perform the forecasting. The resulting performance demonstrates the benefits of the proposed hybrid schemes (VAR-CNN, VAR-LSTM, VAR-GRU) over their pure counterparts, with a significant reduction in forecasting errors. The network metrics were gathered in a real urban cellular environment, where the presence of exogenous factors (e.g., interferences, weather conditions, etc.) makes the forecasting assessment particularly challenging.
Mario Di Mauro, Giovanni Galatro, Fabio Postiglione, Wei Song 0007, Antonio Liotta
Comput. Networks1
2024 Worthiness Benchmark: A novel concept for analyzing binary classification evaluation metrics
abstract
Binary classification deals with identifying whether elements belong to one of two possible categories. Various metrics exist to evaluate the performance of such classification systems. It is important to study and contrast these metrics to find the best one for assessing a particular system. Despite extensive research in this field, a particular systematic comparison of these evaluation metrics remains an unaddressed area. The performance of a classifier is usually evaluated through the confusion matrix, a table including the count of accurate and inaccurate predictions for each category. To judge if one classifier is better than another, examining variations in the confusion matrix is necessary. However, no agreed-upon method exists for this analysis. This is crucial because different metrics may interpret and rate two confusion matrices differently. We introduce the Worthiness Benchmark (γ), a new concept useful to characterize the principles by which performance metrics rank classifiers. In particular, the Worthiness Benchmark is useful to assess how a metric evaluates the superiority among two classifiers by analyzing differences in their confusion matrices. Through this new concept, we are able to deal with the main challenge of selecting the best metric to evaluate a classifier. We then perform a γ-analysis on several binary classification metrics to outline the specific benchmarks these metrics follow when comparing different classifiers.
Mohammad Shirdel, Mario Di Mauro, Antonio Liotta
Inf. Sci.2
2024 Multivariate Time Series Characterization and Forecasting of VoIP Traffic in Real Mobile Networks
abstract
Predicting the behavior of real-time traffic (e.g., VoIP) in mobility scenarios could help the operators to better plan their network infrastructures and to optimize the allocation of resources. Accordingly, in this work the authors propose a forecasting analysis of crucial QoS/QoE descriptors (some of which neglected in the technical literature) of VoIP traffic in a real mobile environment. The problem is formulated in terms of a multivariate time series analysis. Such a formalization allows to discover and model the temporal relationships among various descriptors and to forecast their behaviors for future periods. Techniques such as Vector Autoregressive models and machine learning (deep-based and tree-based) approaches are employed and compared in terms of performance and time complexity, by reframing the multivariate time series problem into a supervised learning one. Moreover, a series of auxiliary analyses (stationarity, orthogonal impulse responses, etc.) are performed to discover the analytical structure of the time series and to provide deep insights about their relationships. The whole theoretical analysis has an experimental counterpart since a set of trials across a real-world LTE-Advanced environment has been performed to collect, post-process and analyze about 600,000 voice packets, organized per flow and differentiated per codec.
Mario Di Mauro, Giovanni Galatro, Fabio Postiglione, Wei Song 0007, Antonio Liotta
IEEE Trans. Netw. Serv. Manag.1
2024 Performance and Availability Challenges in Designing Resilient 5G Architectures
abstract
This work proposes a stochastic characterization of resilient 5G architectures, where attributes such as performance and availability play a crucial role. As regards performance, we focus on the delay associated with the Packet Data Unit session establishment, a 5G procedure recognized as critical for its impact on the Quality of Service and Experience of end-users. To formally characterize this aspect, we employ the non-product-form queueing networks framework where: i) main nodes of a 5G architecture have been realistically modeled as G/G/m queues which do not admit analytical solutions; ii) the decomposition method useful to catch subtle quantities involved in the chain of 5G interconnected nodes has been conveniently customized. The results of performance characterization constitute the input of the availability modeling, where we design a hierarchical scheme to characterize the probabilistic failure/repair behavior of 5G nodes combining two formalisms: i) the Reliability Block Diagrams, useful to capture the high-level interconnections between nodes; ii) the Stochastic Reward Networks to model the internal structure of each node. The final result is an optimal resilient 5G setting that fulfills both a performance constraint (e.g., a temporal threshold) and an availability constraint (e.g., the so-called five nines) at the minimum cost, namely, with the smallest number of redundant elements. The theoretical part is complemented by an empirical assessment carried out through Open5GS, a 5G testbed that we have deployed to realistically estimate main performance and availability metrics.
Luigi De Simone, Mario Di Mauro, Roberto Natella, Fabio Postiglione
IEEE Trans. Netw. Serv. Manag.2
2023 Relative Information Superiority (RIS): a Novel Evaluation Measure for Binary Rule-Based Classification Models
Mohammad Shirdel, Mario Di Mauro, Antonio Liotta
EWSN2
2023 Multi-Provider IMS Infrastructure With Controlled Redundancy: A Performability Evaluation
abstract
In modern telecommunication networks, services are provided through Service Function Chains (SFC), where network resources are implemented by leveraging virtualization and containerization technologies. In particular, the possibility of easily adding or removing network resources has prompted service providers to redefine some concepts including performance and availability. In line with this new trend, we propose a performability study of a multi-provider containerized IP Multimedia Subsystem (cIMS), an SFC-like infrastructure used in the core part of 4G/5G networks to handle multimedia sessions. On the one hand, performance issues are tackled by modeling each cIMS node in terms of a G/G/m queueing system to derive the Call Setup Delay (CSD), a performance metric related to the user-end experience in multimedia communications. On the other hand, availability issues are addressed through the Multi-State System (MSS) formalism, to take into account different performance rates of the system. Then, we devise an algorithm called PE-MUGF (Performability Evaluation through Multidimensional Universal Generating Function) to identify the minimum-redundancy cIMS configuration which meets given performance and availability targets at the same time. Finally, an extensive experimental analysis based on Clearwater, a containerized IMS testbed, allows us to estimate most of system parameters whose robustness is evaluated through a sensitivity analysis.
Luigi De Simone, Mario Di Mauro, Maurizio Longo, Roberto Natella, Fabio Postiglione
IEEE Trans. Netw. Serv. Manag.2
2023 A Latency-Driven Availability Assessment for Multi-Tenant Service Chains
abstract
Nowadays, most telecommunication services adhere to the Service Function Chain (SFC) paradigm, where network functions are implemented via software. In particular, container virtualization is becoming a popular approach to deploy network functions and to enable resource slicing among several tenants. The resulting infrastructure is a complex system composed by a huge amount of containers implementing different SFC functionalities, along with different tenants sharing the same chain. The complexity of such a scenario lead us to evaluate two critical metrics: the steady-state availability (the probability that a system is functioning in long runs) and the latency (the time between a service request and the pertinent response). Consequently, we propose a latency-driven availability assessment for multi-tenant service chains implemented via Containerized Network Functions (CNFs). We adopt a multi-state system to model single CNFs and the queueing formalism to characterize the service latency. To efficiently compute the availability, we develop a modified version of the Multidimensional Universal Generating Function (MUGF) technique. Finally, we solve an optimization problem to minimize the SFC cost under an availability constraint. As a relevant example of SFC, we consider a containerized version of IP Multimedia Subsystem, whose parameters have been estimated through fault injection techniques and load tests.
Luigi De Simone, Mario Di Mauro, Roberto Natella, Fabio Postiglione
IEEE Trans. Serv. Comput.2
2022 Performability Assessment of Containerized Multi-Tenant IMS through Multidimensional UGF
abstract
We advance a performability assessment of a multi- tenant containerized IP Multimedia Subsystem (cIMS), i.e.: one and the same infrastructure is shared among different providers (or tenants). Specifically, we: i) model each cIMS node (a.k.a. Containerized Network Function - CNF) through the Multi-State System (MSS) formalism to capture the dimensionality of the multi-tenant arrangement, and characterize each tenant through queueing theory attributes to catch latency-dependent performance aspects; ii) afford an availability analysis of cIMS by means of an extended version of the Universal Generating Function (UGF) technique, dubbed Multidimensional UGF (MUGF); iii) solve an optimization problem to retrieve the cIMS deployment minimizing costs while guaranteeing high availability requirements. The whole assessment is supported by an experiment based on the containerized IMS platform Clearwater which we deploy to derive some realistic system parameters by means of fault injection techniques.
Luigi De Simone, Mario Di Mauro, Maurizio Longo, Roberto Natella, Fabio Postiglione
CNSM2
2022 Cyber-Threat Propagation over Network-Slicing Architectures
abstract
This work deals with cyber-threat propagation across a communication network designed according to the network-slicing paradigm. Exploiting the multi-dimensional Birth-Death-Immigration model, we examine threat percolation from a vulnerable slice to a virtually secured slice. The analysis quantifies the role played by slice-coupling on threat propagation, revealing how cross-slice attacks can be particularly dangerous in applications where the attacker opens a door in some slice relative, e.g., to ordinary services, breaking through into a slice that delivers critical services such as healthcare or financial services.
Michele Cirillo, Mario Di Mauro, Vincenzo Matta, Giuseppe Basileo
ICASSP2
2022 Efficient Subjective Video Quality Assessment Based on Active Learning and Clustering
Wei Song 0007, Wenbo Zhang 0004, Mario Di Mauro, Antonio Liotta
MoMM4
2022 Performability Analysis of Containerized IMS through Queueing Networks and Stochastic Models
abstract
As a case study of a novel approach to characterize service chains in terms of performance and availability, we consider a containerized IP Multimedia Subsystem (cIMS) infrastructure. The performance analysis is carried out by exploiting the queueing network decomposition method useful to model each cIMS node as a realistic M/G/c system, jointly with the solution of a convex optimization problem for containers allocation. Such a solution is used to feed the availability analysis (faced through the Stochastic Reward Network technique) amenable to derive a set of configurations guaranteeing a given availability target at minimum cost. The whole analysis is supported by a testbed based on the Clearwater platform used to derive some experimental parameters values.
Mario Di Mauro, Giovanni Galatro, Maurizio Longo, Fabio Postiglione, Marco Tambasco
NOMS1
2022 Performability of Network Service Chains: Stochastic Modeling and Assessment of Softwarized IP Multimedia Subsystem
abstract
Service provisioning mechanisms implemented across 5G infrastructures take broadly into use the network service chain concept. Typically, it is coupled with Network Function Virtualization (NFV) paradigm, and consists in defining a pre-determined path traversed by a set of softwarized network nodes to provide specific services. A well known chain-like framework is the IP Multimedia Subsystem (IMS), a key infrastructure of 5G networks, that we characterize both by a performance and an availability perspective. Precisely, supported by a designed from scratch testbed realized throughClearwaterplatform, we perform a stochastic assessment of a softwarized IMS (softIMS) architecture where two main stages stand out: i) a performance analysis, where, exploiting the queueing network decomposition method, we formalize an optimization problem of resource allocation by modeling each softIMS node as an$M/G/c$system; ii) an availability assessment, where, adopting the Stochastic Reward Net methodology, we are able to characterize the behavior of softIMS in terms of failure/repair events, and to derive a set of optimal configurations satisfying a given availability requirement (e.g., five nines) while minimizing deployment costs. Two routines dubbedOptCNTandOptSearchChainhave been devised to govern the performance and availability analyses, respectively.
Mario Di Mauro, Giovanni Galatro, Fabio Postiglione, Marco Tambasco
IEEE Trans. Dependable Secur. Comput.1
2021 Application-Layer DDOS Attacks with Multiple Emulation Dictionaries
abstract
We consider the problem of identifying the members of a botnet under an application-layer (L7) DDoS attack, where a target site is flooded with a large number of requests that emulate legitimate users’ patterns. This challenging problem has been recently addressed with reference to two simplified scenarios, where either all bots pick requests from the same emulation dictionary (total overlap), or they are divided in separate clusters corresponding to distinct emulation dictionaries (no overlap at all). However, over real networks these two extreme conditions are difficult to realize, and the intermediate situation is observed where the emulation patterns of distinct bots belong to partially overlapped dictionaries. This intermediate situation introduces significant sophistication in the bot identification problem. In order to address this issue, we provide an analytical characterization of the pairwise cluster interaction, which is exploited to devise an identification rule to discriminate legitimate users from bots and to identify the individual bot clusters.
Michele Cirillo, Mario Di Mauro, Vincenzo Matta, Marco Tambasco
ICASSP2
2021 Supervised feature selection techniques in network intrusion detection: A critical review
Mario Di Mauro, Giovanni Galatro, Giancarlo Fortino, Antonio Liotta
Eng. Appl. Artif. Intell.1
2021 Adversarial Kendall's Model Towards Containment of Distributed Cyber-Threats
abstract
This work examines propagation of cyber-threats over networks under an adversarial formulation. Exploiting Kendall's birth-death-immigration model, we propose an analytical framework to describe the stochastic dynamics of cyber-threat propagation in a collection of heterogeneous sub-networks characterized by different attributes. We propose two formalisations of the problem as zero-sum games involving two adversaries: an attacker, who launches cyber-threats across the distinct sub-networks; and a defender, who tries to mitigate the threats by delivering suitable countermeasures. According to the first formalisation, the interplay between the defender and the attacker is modelled as a Stackelberg leader-follower game, while the second formalisation considers a strategic game wherein the two contenders play simultaneously without knowing the choice of the other player. We derive the equilibrium strategies for both versions of the game, and discuss a number of insightful interplays and ramifications of the different equilibrium points for the problem at hand. The equilibrium strategies depend on three fundamental attributes: i) the available resource budget of the attacker and the defender; ii) the capacity of the legitimate nodes to (unintentionally) forward the threat across the network, after they have been compromised during the propagation of the threat; iii) the intrinsic characteristics of the sub-networks, namely, their immunity to the attacks, their inertia in responding to the countermeasures, and the importance of the individual sub-networks. The relevance of the proposed solution is illustrated through a series of examples and numerical simulations.
Paolo Addesso, Mauro Barni, Mario Di Mauro, Vincenzo Matta
IEEE Trans. Inf. Forensics Secur.3
2021 Botnet Identification in DDoS Attacks With Multiple Emulation Dictionaries
abstract
In a Distributed Denial of Service (DDoS) attack, a network (botnet) of dispersed agents (bots) sends requests to a website to saturate its resources. Since the requests are sent by automata, the typical way to detect them is to look for some repetition pattern or commonalities between requests of the same user or from different users. For this reason, recent DDoS variants exploit communication layers that offer broader possibility in terms of admissible request patterns, such as, e.g., the application layer. In this case, the malicious agents can pick legitimate messages from an emulation dictionary, and each individual agent sends a relatively low number of admissible requests, so as to make its activity non suspicious. This problem has been recently addressed under the assumption that all the members of the botnet use the same emulation dictionary. This situation is an idealization of what occurs in practice, since different clusters of agents are typically sharing only part of a global emulation dictionary. The diversity among the emulation dictionaries across different clusters introduces significant complexity in the botnet identification challenge. This work tackles this issue and provides the following main contributions. We obtain an analytical characterization of the message innovation rate of the DDoS attack with multiple emulation dictionaries. Exploiting this result, we design a botnet identification algorithm equipped with a cluster expurgation rule, which, under appropriate technical conditions, is shown to provide exact classification of bots and normal users as the observation window size increases. Then, an experimental campaign over real network traces is conducted to assess the validity of the theoretical analysis, as well as to examine the effect of a number of non-ideal effects that are unavoidably observed in practical scenarios.
Michele Cirillo, Mario Di Mauro, Vincenzo Matta, Marco Tambasco
IEEE Trans. Inf. Forensics Secur.2
2021 Comparative Performability Assessment of SFCs: The Case of Containerized IP Multimedia Subsystem
abstract
The failure of a single network element composing a Service Function Chain (SFC) unavoidably leads to some degradation in terms of availability (ability of guaranteeing working conditions), and/or performance (ability of sustaining a certain workload) for the whole SFC. By considering both of these aspects, we propose, as a case study, a joint analysis of availability and performance (a.k.a. performability) of IP Multimedia Subsystem, an SFC infrastructure which plays a key role in the all-IP convergence of telecommunication services, especially as per prospects of 5G . We refer to an implementation of IMS based on container technology (containerized IMS, or cIMS) which allows to decouple the application layer from the underlying hardware infrastructure more efficiently than classic virtualization schemes. We model the probabilistic behavior of a cIMS by means of Stochastic Reward Networks (SRN) and Reliability Block Diagram (RBD) formalisms to take into account failure and repair events. Then, with the assistance of a designed-from-scratch algorithm (OptChains+), we carry on a performability analysis: i) to evaluate and compare series/parallel cIMS configurations (or settings), and ii) to find settings with minimum cost and maximum availability, given a performance level. The proposed assessment lends itself to a sensitivity analysis, here demonstrated by examples, useful for robustness evaluation.
Mario Di Mauro, Giovanni Galatro, Maurizio Longo, Fabio Postiglione, Marco Tambasco
IEEE Trans. Netw. Serv. Manag.1
2021 Availability Evaluation of Multi-Tenant Service Function Chaining Infrastructures by Multidimensional Universal Generating Function
abstract
The Network Function Virtualization (NFV) paradigm has been devised as an enabler of next generation network infrastructures by speeding up the provisioning and the composition of novel network services. The latter are implemented via a chain of virtualized network functions, a process known as Service Function Chaining. In this paper, we evaluate the availability of multi-tenant SFC infrastructures, where every network function is modeled as a multi-state system and is shared among different and independent tenants. To this aim, we propose a Universal Generating Function (UGF) approach, suitably extended to handle performance vectors, that we call Multidimensional UGF. This novel methodology is validated in a realistic multi-tenant telecommunication network scenario, where the service chain is composed by the network elements of an IP Multimedia Subsystem implemented via NFV. A steady-state availability evaluation of such an exemplary system is presented and a redundancy optimization problem is solved, so providing the SFC infrastructure which minimizes deployment cost while respecting a given availability requirement.
Mario Di Mauro, Maurizio Longo, Fabio Postiglione
IEEE Trans. Serv. Comput.1
2020 Statistical Characterization of Containerized IP Multimedia Subsystem through Queueing Networks
abstract
Today, modern telco infrastructures are espousing softwarized paradigms (e.g. virtualization, containerization), which are necessary to implement the network slicing, and, consequently, to achieve a beneficial trade-off between service offered and costs. In particular, container-based technologies, when compared to classic virtualized frameworks, offer a lightweight environment to host novel network services. Inspired by these last trends, in this work we propose a statistical characterization of a containerized version of IP Multimedia Subsystem (cIMS), one of the crucial parts of 5G core network. Precisely, we: i) exploit the Queueing Networks (QN) formalism to model the chained behavior of a cIMS infrastructure; ii) perform a statistical assessment aimed at analyzing both the queueing dynamics in different scenarios (single/multi class), and at selecting the optimal cIMS deployment guaranteeing the minimum response time at a given cost; iii) carry on an experimental analysis through Clearwater platform to extract realistic estimates of system parameters.
Mario Di Mauro, Antonio Liotta, Maurizio Longo, Fabio Postiglione
NetSoft1
2020 Automated Generation of Availability Models for SFCs: The case of Virtualized IP Multimedia Subsystem
abstract
The reputation of network providers strongly depends on their ability to guarantee high performance levels of virtualized infrastructures, and to maintain strict Quality-of-Service (QoS) requirements, thus, the concept of "five nines" or high availability (HA) is critical. It means that, on average, the continuity of a provided service cannot be violated for more than about five minutes per year. In this direction, we propose a framework useful to design and model, from a HA perspective, the Service Function Chains (SFCs) whose chained software logic is embodied in many softwarized telco infrastructures (e.g. IP Multimedia Subsystem elected here as a representative use case). The proposed framework interacts with TimeNET tool, and offers interesting functionalities such as: i) generating stochastic models of SFCs based on the SRN (Stochastic Reward Nets) formalism; ii) deploying network scenarios via drag-and-drop operations for basic users, or modifying the underlying SRN models for advanced users; iii) setting a variety of parameters (mean-time-to-failure/repair, software/hardware specs, redundancy, etc.); iv) presenting availability results in tabular and/or graphical forms.
Mario Di Mauro, Giovanni Galatro, Maurizio Longo, Arcangelo Palma, Fabio Postiglione, Marco Tambasco
NOMS1
2020 Performability Management of Softwarized IP Multimedia Subsystem
abstract
IP Multimedia Subsystem (IMS) represents a crucial element for the convergence of telecommunication systems heading towards 5G solutions. Actually, IMS offers a standardized and vendor independent model allowing network providers to supply multimedia services such as video streaming or HD voice, with pressing QoS requirements. The IMS architecture can dramatically improve its flexibility when deployed within softwarized environments, in conjunction with virtual or container-based technologies. This latter, in particular, realizes an abstraction of software resources from the underlying hardware in a more efficient and resource saving manner than virtual machines. Inspired by this model, we propose a tool for the performability management of IMS architectures deployed in a containerized environment (dubbed cIMS). First, we model the stochastic behavior of a cIMS by means of two complementary formalisms: i) Reliability Block Diagram (RBD) amenable to model high level interconnections among cIMS nodes, and ii) Stochastic Reward Networks (SRN) useful to capture deeper details of a single node in terms of failure and repair events. Then, we develop an automated procedure aimed at supporting the performability management of cIMS deployments that must satisfy the optimal trade-off among high availability requirements, capacity load, and deployment costs.
Mario Di Mauro, Giovanni Galatro, Maurizio Longo, Fabio Postiglione, Marco Tambasco
NOMS1
2020 ADVoIP: Adversarial Detection of Encrypted and Concealed VoIP
abstract
A network attacker wants to transmit Voice-over-IP (VoIP) traffic streams covertly. He tries to evade the detection system by manipulating the VoIP streams through padding, shifting, and splitting operations, so as to conceal them amidst the Internet traffic. A defender wants to detect the manipulated VoIP streams. Tackling this problem from an adversarial perspective, we provide two contributions: 1) we obtain a highly stylized representation of VoIP streams in terms of transmission frequency F and packet length L, and characterize the (F, L) region achievable by the attacker's transformation and 2) We formulate the VoIP detection game, and find both theoretical conditions and a practical algorithm to find the Nash equilibrium of the game. As a result, we are able to design an optimal (from the adversarial perspective) algorithm for VoIP detection, which is nicknamed as ADVoIP. Simulations over real network traces, and comparison with existing approaches, show the effectiveness of the proposed approach.
Paolo Addesso, Michele Cirillo, Mario Di Mauro, Vincenzo Matta
IEEE Trans. Inf. Forensics Secur.3
2020 Experimental Review of Neural-Based Approaches for Network Intrusion Management
abstract
The use of Machine Learning (ML) techniques in Intrusion Detection Systems (IDS) has taken a prominent role in the network security management field, due to the substantial number of sophisticated attacks that often pass undetected through classic IDSs. These are typically aimed at recognizing attacks based on a specific signature, or at detecting anomalous events. However, deterministic, rule-based methods often fail to differentiate particular (rarer) network conditions (as in peak traffic during specific network situations) from actual cyber attacks. In this article we provide an experimental-based review of neural-based methods applied to intrusion detection issues. Specifically, we i) offer a complete view of the most prominent neural-based techniques relevant to intrusion detection, including deep-based approaches or weightless neural networks, which feature surprising outcomes; ii) evaluate novel datasets (updated w.r.t. the obsolete KDD99 set) through a designed-from-scratch Python-based routine; iii) perform experimental analyses including time complexity and performance (accuracy and F-measure), considering both single-class and multi-class problems, and identifying trade-offs between resource consumption and performance. Our evaluation quantifies the value of neural networks, particularly when state-of-the-art datasets are used to train the models. This leads to interesting guidelines for security managers and computer network practitioners who are looking at the incorporation of neural-based ML into IDS.
Mario Di Mauro, Giovanni Galatro, Antonio Liotta
IEEE Trans. Netw. Serv. Manag.1
2020 An Experimental Evaluation and Characterization of VoIP Over an LTE-A Network
abstract
Mobile telecommunications are converging towards all-IP solutions. This is the case of the Long Term Evolution (LTE) technology that, having no circuit-switched bearer to support voice traffic, needs a dedicated VoIP infrastructure, which often relies on the IP Multimedia Subsystem architecture. Most telecom operators implement LTE-A, an advanced version of LTE often marketed as 4G+, which achieves data rate peaks of 300 Mbps. Yet, although such novel technology boosts the access to advanced multimedia contents and services, telco operators continue to consider the VoIP market as the major revenue for their business. In this work, the authors propose a detailed performance assessment of VoIP traffic by carrying out experimental trials across a real LTE-A environment. The experimental campaign consists of two stages. First, we characterize VoIP calls between fixed and mobile terminals, based on a data-set that includes more than 750,000 data-voice packets. We analyze quality-of-service metrics such as round-trip time (RTT) and jitter, to capture the influence of uncontrolled factors that typically appear in real-world settings. In the second stage, we further consider VoIP flows across a range of codecs, looking at the trade-offs between quality and bandwidth consumption. Moreover, we propose a statistical characterization of jitter and RTT (representing the most critical parameters), identifying the optimal approximating distribution, namely the Generalized Extreme Value (GEV). The estimation of parameters through the Maximum Likelihood criterion, leads us to reveal both the short- and long-tail behaviour for jitter and RTT, respectively.
Mario Di Mauro, Antonio Liotta
IEEE Trans. Netw. Serv. Manag.1
2019 IP Multimedia Subsystem in a containerized environment: availability and sensitivity evaluation
abstract
Nowadays, telecom providers may benefit from the flexibility offered by Network Function Virtualization (NFV) paradigm that allows to decouple the service logic from the underlying hardware infrastructure. Thus, main functionalities of network nodes (e.g. routers, firewalls, load balancers etc.) can be deployed on a virtual machine (VM) with its own resources. On the other hand, deploying a whole VM (which hosts a single virtualized network service) can be expensive, since too many resources are uselessly wasted. A valuable alternative is offered by containers, namely, virtualized and lightweight processes that, differently from classical VMs, do not carry a whole operating system. In this work we consider a container-based version of IP Multimedia Subsystem (IMS) infrastructure, a crucial player within next generation telecommunication networks, a.k.a. 5G. More precisely, we offer an availability evaluation of a containerized IMS (cIMS) deployment through i) Reliability Block Diagram (RBD) formalism useful to model high-level interconnections among cIMS nodes, and ii) Stochastic Reward Networks (SRN) methodology which allows to analyze the evolution of the cIMS life cycle in presence of failure and repair events. Moreover, we perform a sensitivity analysis aimed at evaluating the whole cIMS robustness with respect to deviations of some critical parameters.
Mario Di Mauro, Giovanni Galatro, Maurizio Longo, Fabio Postiglione, Marco Tambasco
NetSoft1
2019 Statistical Assessment of IP Multimedia Subsystem in a Softwarized Environment: A Queueing Networks Approach
abstract
The Next Generation 5G Networks can greatly benefit from the synergy between virtualization paradigms, such as the Network Function Virtualization (NFV), and service provisioning platforms such as the IP Multimedia Subsystem (IMS). The NFV concept is evolving towards a lightweight solution based on containers that, by contrast to classic virtual machines, do not carry a whole operating system and result in more efficient and scalable deployments. On the other hand, IMS has become an integral part of the 5G core network, for instance, to provide advanced services like Voice over LTE (VoLTE). In this paper we combine these virtualization and service provisioning concepts, deriving a containerized IMS infrastructure, dubbed cIMS, providing its assessment through statistical characterization and experimental measurements. Specifically, we: i) model cIMS through the queueing networks methodology to characterize the utilization of virtual resources under constrained conditions; ii) draw an extended version of the Pollaczek-Khinchin formula, which is useful to deal with bulk arrivals; iii) afford an optimization problem focused at maximizing the whole cIMS performance in the presence of capacity constraints, thus providing new means for the service provider to manage service level agreements (SLAs); iv) evaluate a range of cIMS scenarios, considering different queuing disciplines including also multiple job classes. An experimental testbed based on the open source platform Clearwater has been deployed to derive some realistic values of key parameters (e.g., arrival and service times).
Mario Di Mauro, Antonio Liotta
IEEE Trans. Netw. Serv. Manag.1
2018 Improving SIEM capabilities through an enhanced probe for encrypted Skype traffic detection
Mario Di Mauro, Cesario Di Sarno
J. Inf. Secur. Appl.1
2018 Cyber-Threat Mitigation Exploiting the Birth-Death-Immigration Model
abstract
We consider the problem of mitigating the effect of malicious cyber-threats spreading across multiple subnets of a data network. Three fundamental issues arise: 1) providing a manageable model of threat propagation; 2) quantifying the danger associated to different subnets; and 3) optimizing the allocation of the countermeasures. We address these issues by providing the following novel contributions. First, a convenient mathematical abstraction of threat propagation is proposed, which employs the birth-and-death process with immigration pioneered by Kendall in his seminal work of 1948. Then, exploiting the notable properties of such a model, we show how to retrieve analytical solutions for optimal resource allocation across subnets, for the case where the parameters of the attack are perfectly known. Finally, the assumption of perfect knowledge is removed, and the unknown attack parameters are estimated using maximum-likelihood estimators.
Vincenzo Matta, Mario Di Mauro, Maurizio Longo, Alfonso Farina
IEEE Trans. Inf. Forensics Secur.2
2017 Object Storage in Cloud Computing Environments: An Availability Analysis
Giuliana Carullo, Mario Di Mauro, Michele Galderisi, Maurizio Longo, Fabio Postiglione, Marco Tambasco
GPC2
2017 DDoS Attacks With Randomized Traffic Innovation: Botnet Identification Challenges and Strategies
abstract
Distributed Denial-of-Service (DDoS) attacks are usually launched through the botnet, an “army” of compromised nodes hidden in the network. Inferential tools for DDoS mitigation should accordingly enable an early and reliable discrimination of the normal users from the compromised ones. Unfortunately, the recent emergence of attacks performed at the application layer has multiplied the number of possibilities that a botnet can exploit to conceal its malicious activities. New challenges arise, which cannot be addressed by simply borrowing the tools that have been successfully applied so far to earlier DDoS paradigms. In this paper, we offer basically three contributions: 1) we introduce an abstract model for the aforementioned class of attacks, where the botnet emulates normal traffic by continually learning admissible patterns from the environment; 2) we devise an inference algorithm that is shown to provide a consistent (i.e., converging to the true solution as time elapses) estimate of the botnet possibly hidden in the network; and 3) we verify the validity of the proposed inferential strategy on a test-bed environment. Our tests show that, for several scenarios of implementation, the proposed botnet identification algorithm needs an observation time in the order of (or even less than) 1 min to identify correctly almost all bots, without affecting the normal users' activity.
Vincenzo Matta, Mario Di Mauro, Maurizio Longo
IEEE Trans. Inf. Forensics Secur.2
2015 Revealing Encrypted WebRTC Traffic via Machine Learning Tools
abstract
The detection of encrypted real-time traffic, both streaming and conversational, is an increasingly important issue for agencies in charge of lawful interception. Aside from well established technologies used in real-time communication (e.g. Skype, Facetime, Lync etc.) a new one is recently spreading: Web Real-Time Communication (WebRTC), which, with the support of a robust encryption method such as DTLS, offers capabilities for encrypted voice and video without the need of installing a specific application but using a common browser, like Chrome, Firefox or Opera. Encrypted WebRTC traffic cannot be recognized through methods of semantic recognition since it does not exhibit a discernible sequence of information pieces and hence statistical recognition methods are called for. In this paper we propose and evaluate a decision theory based system allowing to recognize encrypted WebRTC traffic by means of an open-source machine learning environment: Weka. Besides, a reasoned comparison among some of the most credited algorithms (J48, Simple Cart, Naive Bayes, Random Forests) in the field of decision systems has been carried out, indicating the prevalence of Random Forests.
Mario Di Mauro, Maurizio Longo
SECRYPT1
2013 An Indoor Localization System within an IMS Service Infrastructure
abstract
The paper presents an architectural proposal that integrates a vehicle parking system, which offers a series of specific services (billing, targeted marketing, etc.), into the 3GPP IP Multimedia Subsystem (IMS), with a specific focus on the localization of the vehicle in indoor areas. The vehicle is equipped with a device hosting an ad-hoc software client exploiting the Wi-Fi network card. The solution takes advantage of the widespread adoption of the 802.11x WLAN technology in order to provide a value added service using already installed infrastructure. The testing area is an indoor parking lot and the IT infrastructure includes several Wi-Fi Access Points appropriately located inside the parking area, some user equipments interacting with them, a Location Server able to provide an estimate of a vehicle's position and a Presence Server offering specific location-based services on behalf of the IMS infrastructure.
Paolo Addesso, Mario Di Mauro, Maurizio Longo, G. Della Corte, Anton Luca Robustelli
MoMM2