Salvatore Signorello

dblp:147/7546 · DBLP profile ↗
← Back
10ranked-venue papers
1as first author
5since 2021 · last 2024
0000-0001-6628-0541ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 4 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Internet Architecture Evolution: Found in Translation
abstract
The success of the Internet is undeniable, but so are its limitations. Over the past two decades, the research community has responded with clean-slate redesigns, proposing innovative architectures focused on issues like security and information dissemination, among others. Unfortunately, these efforts have had limited impact on the commercial Internet, if any. The reason is that the Internet architecture is deeply entrenched, making a complete replacement elusive.
Luis Pedrosa, Salvatore Signorello, Fernando M. V. Ramos
HotNets3
2024 P4chaskey: an Efficient Mac Algorithm for Pisa Switches
abstract
Cryptographic primitives are of paramount importance to guarantee security properties in communication networks. The associated computational complexity of cryptography standards makes it prohibitive to execute these primitives at line rate in the network core. Existing implementations of cryptographic MAC algorithms in$\mathbf{P 4}$for programmable switches impose a severe performance penalty due to packet recirculation, which may not be tolerable at those network speeds. In this paper, we propose the first data plane design in$\mathbf{P 4}$of the Chaskey algorithm, a widely used secure and lightweight cryptographic MAC algorithm, tailored for the PISA switch architecture. Our P4Chaskey is the first solution to compute MACs using 128-bit keys without packet recirculation, guaranteeing line rate Terabit speeds. As state-of-the-art solutions require recirculations for the same key size (reducing throughput performance) or offer weaker security (smaller keys), P4CHASKEY is now, to our knowledge, the most efficient MAC design for the target switch architecture.
Martim Francisco, Bernardo Ferreira, Fernando M. V. Ramos, Eduard Marin, Salvatore Signorello
ICNP5
2023 Poster: In-Network ML Feature Computation for Malicious Traffic Detection
abstract
We present Peregrine, a malicious traffic detector that offloads part of its computation to a programmable switch. The idea is to partition detection, by moving the ML feature computation module from a middlebox server to a switch data plane. The key innovation unlocked---computing the ML input features over all traffic---results in a significant improvement in detection performance: in our evaluation, up to 5.7x over the state of the art.
João Romeiras Amado, Francisco Chamiça Pereira, Salvatore Signorello, Miguel Correia 0001, Fernando M. V. Ramos
SIGCOMM3
2021 Generic change detection (almost entirely) in the dataplane
abstract
Identifying traffic changes accurately sits at the core of many network tasks, from congestion analysis to intrusion detection. Modern systems leverage sketch-based structures that achieve favourable memory-accuracy tradeoffs by maintaining compact summaries of traffic data. Mainly used to detect heavy-hitters (usually the major source of network congestion), some can be adapted to detect traffic changes, but they fail on generality. As their core data structures track elephant flows, they miss to identify mice traffic that may be the main cause of change (e.g., microbursts or low-volume attacks).
Gonçalo Matos, Salvatore Signorello, Fernando M. V. Ramos
ANCS2
2021 FlowLens: Enabling Efficient Flow Classification for ML-based Network Security Applications
Diogo Barradas, Nuno Santos 0001, Luís E. T. Rodrigues, Salvatore Signorello, Fernando M. V. Ramos, André Madeira
NDSS4
2020 Poster: Speeding Up Network Intrusion Detection
abstract
Modern network data planes have enabled new measurement approaches, including efficient sketch-based techniques with provable trade-offs between memory and accuracy, directly in the data plane, at line rate. We thus ask the question: can one leverage this richer measurement plane to improve network intrusion detection? Our answer is SPID, a push-based, feature-rich network monitoring approach to assist learning-based attack detection. SPID switches run a diverse set of measurement primitives and proactively push measurements to the monitoring system when relevant changes occur. Network measurements are then fed as input features to a classifier based on unsupervised learning to detect ongoing attacks, as they occur. In consequence, SPID aims to reduce attack detection time, when comparing to existing solutions present in large scale networks.
João Romeiras Amado, Salvatore Signorello, Miguel Correia 0001, Fernando M. V. Ramos
ICNP2
2019 Random Linear Network Coding on Programmable Switches
abstract
By extending the traditional store-and-forward mechanism, network coding has the capability to improve a network's throughput, robustness, and security. Given the fundamentally different packet processing required by this new paradigm and the inflexibility of hardware, existing solutions are based on software. As a result, they have limited performance and scalability, creating a barrier to its wide-spread adoption. By leveraging the recent advances in programmable networking hardware, in this paper we propose a random linear network coding data plane written in P4, as a first step towards a production-level platform. Our solution includes the ability to combine the payload of multiple packets and of executing the required Galois field operations, and shows promise to be practical even under the strict memory and processing constraints of switching hardware.
Diogo Gonçalves 0002, Salvatore Signorello, Fernando M. V. Ramos, Muriel Médard
ANCS2
2018 Named Data Networking with Programmable Switches
abstract
The Internet today is mainly used for distributing content, in a fundamental departure from its original goal of enabling communication between endpoints. As a response to this change, Named Data Networking (NDN) is a new architecture rooted on the concept of naming data, in contrast to the original paradigm based on naming hosts. This radical architectural shift results in packet processing in NDN to differ substantially from IP. As a consequence, current network equipment cannot be seamlessly extended to offer NDN data-plane functions. To address this challenge, available NDN router solutions are usually software-based, and even the highly-optimised designs tailored to specific hardware platforms present limited performance, hindering adoption. In addition, these tailor-made solutions are hardly reusable in research and production networks. The emergence of programmable switching chips and of languages to program them, like P4, brings hope for the state of affairs to change. In this paper, we present the design of an NDN router written in P4. We improve over the state-of-the-art solution by extending the NDN functionality, and by addressing its scalability limitations. A preliminary evaluation of our open-source solution running on a software target demonstrates its feasibility.
Rui Miguel, Salvatore Signorello, Fernando M. V. Ramos
ICNP2
2017 Advanced interest flooding attacks in named-data networking
abstract
The Named-Data Networking (NDN) has emerged as a clean-slate Internet proposal on the wave of Information-Centric Networking. Although the NDN's data-plane seems to offer many advantages, e.g., native support for multicast communications and flow balance, it also makes the network infrastructure vulnerable to a specific DDoS attack, the Interest Flooding Attack (IFA). In IFAs, a botnet issuing unsatisfiable content requests can be set up effortlessly to exhaust routers' resources and cause a severe performance drop to legitimate users. So far several countermeasures have addressed this security threat, however, their efficacy was proved by means of simplistic assumptions on the attack model. Therefore, we propose a more complete attack model and design an advanced IFA. We show the efficiency of our novel attack scheme by extensively assessing some of the state-of-the-art countermeasures. Further, we release the software to perform this attack as open source tool to help design future more robust defense mechanisms.
Salvatore Signorello, Samuel Marchal, Jérôme François, Olivier Festor, Radu State
NCA1
2011 Enabling remote access to a wireless sensor network by exploiting IPv6 capabilities
abstract
One of the most important applications of wireless sensor networks (WSNs) undoubtedly is the emergency management. In particular, sensor nodes can be helpful for both preventing and recovering emergency situations. During critical emergency situations, having a WSN easy to access and manage is a mandatory requirement. So far, sensor networks have been based on custom protocols that make difficult to access and configure sensors by users that are different from the original designers. Today, with the advent of IPv6, integration between a sensor network and Internet becomes feasible. In this paper, we discuss the IPv6 capabilities that can be effectively exploited jointly with 6LoWPAN, and we illustrate a testbed based on an implementation of IPv6 over IEEE 802.15.4. We demonstrate that, by using an open source module we have purposely developed to run over 6LoWPAN, a user equipped with some few common network utilities can remotely access the WSN and change run-time the state and configuration of every single sensor node.
Alessandro Leonardi, Sergio Palazzo, Francesco Scoto, Salvatore Signorello
IWCMC4