VLDB 2026 Research / reviewers in the wild / expert
Charalampos Rotsos
dblp:17/8276
· DBLP profile ↗
24ranked-venue papers
4as first author
10since 2021 · last 2026
0000-0003-0252-9373ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 2 first-authorSoftware engineering, systems software and programming languages · 4 · 2 since 2021Systems, architecture and hardware · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Security and privacy · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Wayfinder: Automated Operating System SpecializationabstractOperating system specialization is a well-known approach to optimize a specific application's performance, memory usage, security, or other important metrics. Specializing an OS for an application is typically a manual process that requires great expertise. Specialization through configuration lends itself well to automation; however, it is challenging due to the sheer size of the configuration space of modern OSes, the difficulty to quantify that space, the long time it takes to evaluate a configuration, and the large number of invalid configurations. Hence, existing attempts at specializing OSes automatically are limited to switching features on and off to minimize memory consumption or attack surface, and cannot target metrics such as performance. Alexander Jung 0002, Cezar Craciunoiu, Nikolaos Karaolidis, Hugo Lefeuvre, Daniel Oñoro-Rubio, Felipe Huici, Charalampos Rotsos, Pierre Olivier |
EuroSys | 7 |
| 2025 | SWIFT: Semantic Web Intent Framework for Intent TranslationabstractIntent-based networking (IBN) has emerged as a promising paradigm to simplify the management of network infrastructures. At the heart of IBN systems lies the intent handler, a management entity that transforms declarative network goals into imperative network configuration that meets specific policy and optimization requirements. Practical research has produced a number of intent handler implementations, that exhibit specialized use-cases with limited extensibility. This paper presents SWIFT, a framework to simplify the development of custom intent scenarios. To support this capability, SWIFT delivers two main contributions. Firstly, it employs an ontology to abstract several standardized and open network data models (3GPP Core Configuration, ETSI NFV-MANO, ONOS NBI) and support the translation of slice delivery intents, modelled using the TMForum common intent model, into effective infrastructure configurations. Secondly, SWIFT offers a reasoning framework for network operators to implement custom intent handling logic using logical programming. The reasoner can use the rich information of the ontology both to automate the translation of intent requirements, and validate intent goals based on the current network state. Our proof-of-concept SWIFT implementation can automate and optimize the delivery of private 5G network slices. Furthermore, we demonstrate the optimal planning and delivery of mobile slice intents in a real mobile network topology with minimal processing overheads. Paul Alcock, Revika Anand, Charalampos Rotsos, Nicholas J. P. Race |
NOMS | 3 |
| 2024 | Oz: Towards an Extensible Intent Handler Architecture with Semantic ReasoningabstractIntent-based networking (IBN) has emerged as a promising paradigm to improve management automation in network infrastructures. At the heart of IBN systems lies the intent handler, an intelligent translation process that transforms declarative network goals into imperative network configurations. Although IBN research has demonstrated the ability to support complex automation scenarios, existing intent handlers have limited scope, targeting specialized use cases and optimizations, and offering limited extensibility. This paper presents Oz, an intent framework baed on Semantic Web technologies. Oz uses an ontology to combine several standardized data models and support the translation of TMForum common intent model expressions into effective infrastructure configurations. Furthermore, Oz implements a semantic web reasoner that allows operators to realize intents using logic rules that interpret intent requirements into configuration and validate intent fulfillment based on the current network state. Using a production network topology, we demonstrate that Oz can plan the deployment of a cache service intent on a busy network in less than 10 seconds, by using a contextual state exploration intent implementation. Paul Alcock, Charalampos Rotsos, Nicholas J. P. Race |
NOMS | 2 |
| 2024 | Katoptron: Efficient State Mirroring for Middlebox ResilienceabstractThe increasing demand for low-latency, high-bandwidth connectivity has introduced novel challenges to delivering strong resilience guarantees in production network environments. Closed hardware platforms, known as middleboxes, that lack visibility and support for state retention remain a key challenge for continuous service delivery during network failures. These middleboxes rarely employ recovery mechanisms of their own, inspiring renewed interest in the field of NFV in recent years due to this gap within the industry. The increasing availability of VNF capabilities in modern infrastructures offers an opportunity to exploit the flexibility of software and use hybrid architectures to improve resilience. Katoptron is a high-availability service that propagates state between unmodified hardware middleboxes and backup PNF or VNF appliances. The platform utilises targeted packet mirroring to allow network devices to organically construct equivalent state and thus allow an easy transition between hardware and software. To demonstrate its viability, we have evaluated Katoptron against a wide range of common hardware middlebox use cases built using multiple open-source packet processing frameworks. Results show upwards of 90% matching state with no observable delay to normal traffic or impact on its functionality. Lyn Hill, Charalampos Rotsos, Christopher Edwards, David Hutchison 0001 |
NOMS | 2 |
| 2024 | Adaptive Energy Theft Detection in Smart Grids Using Self-Learning With Dual Neural NetworkabstractEnergy theft is an extremely prominent challenge causing significant energy and revenue losses for utility providers worldwide. The introduction of advanced metering infrastructures consisting of smart meter deployments has undeniably extended the attack surface, enabling individual consumers or prosumers to trigger composite energy theft attack vectors. In this work, we introduce an energy theft detection system capable of distinguishing properties of power consumption and generation theft with possible misconfigurations caused by nonmalicious intent. The proposed approach is adaptive through a self-learning operation that is updated continuously as new measurements become available. With the synergistic use of measurements collected by real PV installations and openly available weather information, the system achieves high accuracy and precision result in theft identification over streamed data measurements. Thus, it promotes low computational costs and its architecture can be easily integrated within smart grid infrastructures to realize next-generation cross-batch energy theft detection. Ahlam Althobaiti, Charalampos Rotsos, Angelos K. Marnerides |
IEEE Trans. Ind. Informatics | 2 |
| 2023 | NES: Towards Lifecycle Automation for Emulation-Based ExperimentationabstractNetwork softwarization has revitalized the interest of the network community towards emulation as an effective mechanism for network experimentation. Relevant platforms automate the deployment of virtual network topologies on a host, providing users the ability to manually run experimental scenarios. Whilst this may suit prototyping, modern development and deployment practices such as CI/CD depend on fully automated testing processes, built around high-level testing APIs and abstracting the challenges involved with synchronizing complex node interaction scenarios. In this paper, we present Network Emulation System (NES): a cloud-native, and highly-parallelizable Network Emulation as a Service (NEaaS) platform designed from the ground up to facilitate codeless experiment specification and to automate network testing workflows in cloud CI/CD environments. We demonstrate that NES offers a 8x speedup improvement in topology instantiation times in comparison to existing emulation platforms, and its life-cycle model can automate testing processes for complex service configurations using existing CI/CD platforms such as GitHub Actions. William Fantom, Eleanor Davies, Charalampos Rotsos, Paul Veitch, Stephen A. Cassidy, Nicholas J. P. Race |
NOMS | 3 |
| 2022 | Improving Intent Correctness with Automated TestingabstractIntent-based networking (IBN) systems have become the de-facto control abstraction to drive self-service, self-healing, and self-optimized capabilities in service delivery processes. Nonetheless, the operation complexity of modern network infrastructures make network practitioners apprehensive towards adoption in production, requiring further evidence for correctness. In this paper, we argue that testing, verification and monitoring should become first-class citizens in reference IBN architecture, in order to improve the detection errors during operations. Towards this goal, we present an extension for an intent architecture that allows IBN system to validate the correctness of network configuration using realistic network emulation. Furthermore, we present an intent use-case that ensure correct operation in hybrid networks. Paul Alcock, Ben Simms, William Fantom, Charalampos Rotsos, Nicholas J. P. Race |
NetSoft | 4 |
| 2022 | A NEAT way to test-driven network managementabstractThe increasing softwarization of network infrastructures introduces an important challenge for network configuration. The growth of the network configuration space as a result of new device types and the expanding inter-dependence of network service components increases the network configuration complexity. Compounding this issue, new service deployment architectures lack mechanisms to validate the impact of service configuration on network resilience. Network operators need to adopt new mechanisms to validate and verify network configuration changes, taking inspiration from popular Continuous Integration/Continuous Development (CI/CD) mechanisms. This paper introduces Network Emulation-based Automated Testing (NEAT), an automated testing framework for network configuration. NEAT allows network managers to define network topologies and tests through YAML files, to then be later executed by NEAT within realistic network topologies. Furthermore, network managers can control the fidelity of their network tests and bound the execution time of testing suites, as well as exploit parallelization of modern servers to speedup test execution. William Fantom, Paul Alcock, Ben Simms, Charalampos Rotsos, Nicholas J. P. Race |
NOMS | 4 |
| 2022 | Improving network resilience with Middlebox MinionsabstractResilience in networks has often relied on high availability to ensure minimal disruption to end users when faults occur, but this has grown difficult for retaining state with the growing popularity of hardware middleboxes – blackbox hardware network functions that have served as an important part of network design in recent years. There is potential room for the introduction of Network Function Virtualisation (NFV) in the field of resilience in connection with middlebox usage. Rather than relying on overprovisioning, we propose Middlebox Minion (MiMi) VNF, a system design that can be inserted around inaccessible hardware. This recreates state in accordance with the middlebox function, using NFV to establish stateful failover mechanisms without the need to replace existing hardware. The experiment we present is a failover analogy examining the importance of state retention and the complexities involved with inaccessible hardware. Results suggest a promising improvement of connection quality and up to 60% lower loss when state can be preserved across failover instances, as well as potential for further exploration of the topic area. Lyn Hill, Charalampos Rotsos, William Fantom, Christopher Edwards, David Hutchison 0001 |
NOMS | 2 |
| 2021 | To All Intents and Purposes: Towards Flexible Intent ExpressionabstractIntent-based networking provides an efficient mechanism to manage complexity in network management. The paradigm allows users to express their network requirements, and an autonomic framework translates them into a network configuration. Existing efforts focus primarily on modeling connectivity intents for end-users. Nonetheless, in order to deliver autonomic behavior in network management, an intent system must support a wider range of network management processes and model human-to-human interactions, essential for network operation. Furthermore, such interactions may involve nontechnical users and require the design of novel interfaces, supporting free-text and conversational intent expression. Towards this goal, we present an intent architecture that supports novel network management intents, such as network path rerouting and applying periods of ’service protection’. The paper includes details of our prototype implementation that is capable of deploying such intents in under five seconds in a large mininet topology. Mehdi Bezahaf, Eleanor Davies, Charalampos Rotsos, Nicholas J. P. Race |
NetSoft | 3 |
| 2020 | λBGP: Rethinking BGP programmabilityabstractBGP has long been the de-facto control plane protocol for inter-network connectivity. Although initially designed to provide best-effort routing between ASes, the evolution of Internet services has created a demand for more complex control functionalities using the protocol. At the heart of this challenge lies the static nature of configuration mechanisms and the limited programmability of existing BGP speakers. Meanwhile, the SDN paradigm has demonstrated that open and generic network control APIs can greatly improve network functionality and seamlessly enable greater flexibility in network management. In this paper, we argue that BGP speaking systems can and should provide an open and rich control and configuration mechanism, in order to address modern era network control requirements. Towards this goal, we present λBGP, a modular and extensible BGP framework written in Haskell. The framework offers an extensible integration model for reactive BGP control that remains backward compatible with existing BGP standards and allows network managers to define route processing policies using a high-level language and to dynamically inject information sources into the path selection logic. Using a high-performance BGP traffic generator, we demonstrate that λBGP offers performance comparable to production BGP speakers, while dynamic AS route processing policies can be written in just a few lines of code. Nicholas Hart, Charalampos Rotsos, Vasileios Giotsas, Nicholas J. P. Race, David Hutchison 0001 |
NOMS | 2 |
| 2018 | OFLOPS-SUME and the Art of Switch CharacterizationabstractThe philosophy of software-defined networking (SDN) has introduced new challenges in network system management. In contrast to traditional network devices that contained both the control and the data plane functionality in a tightly coupled manner, SDN technologies separate the two network planes and define a remote API for low-level device configuration. Nonetheless, the enhanced flexibility of the SDN paradigm is prone to create novel performance and scalability bottlenecks in the network. To help network managers and application developers better understand the actual behavior of SDN implementations, we present a hardware/software co-design that enables switch characterization at 40 Gbps and beyond. We conduct an evaluation of both software and hardware switches. We expose the unwanted effects of the OpenFlow barrier primitive, potential misbehaviors when adding or modifying a batch of rules, and how simple operations, such as packet modification, can impact the switch forwarding performance. We release the code publicly as open source to promote experiments reproducibility as well as encourage the network community to evolve our solution. Rémi Oudin, Gianni Antichi, Charalampos Rotsos, Andrew W. Moore 0002, Steve Uhlig |
IEEE J. Sel. Areas Commun. | 3 |
| 2015 | Blueswitch: Enabling Provably Consistent Configuration of Network SwitchesabstractPrevious research on consistent updates for distributed network configurations has focused on solutions for centralized networkconfiguration controllers. However, such work does not address the complexity of modern switch datapaths. Modern commodity switches expose opaque configuration mechanisms, with minimal guarantees for datapath consistency and with unclear configuration semantics. Furthermore, would-be solutions for distributed consistent updates must take into account the configuration guarantees provided by each individual switch - plus the compositional problems of distributed control and multi-switch configurations that considerably transcend the single-switch problems. In this paper, we focus on the behavior of individual switches, and demonstrate that even simple rule updates result in inconsistent packet switching in multi-table datapaths. We demonstrate that consistent configuration updates require guarantees of strong switch-level atomicity from both hardware and software layers of switches - even in a single switch. In short, the multiple-switch problems cannot be reasonably approached until single-switch consistency can be resolved. We present a hardware design that supports a transactional configuration mechanism, and provides packet-consistent configuration: all packets traversing the datapath will encounter either the old configuration or the new one, and never an inconsistent mix of the two. Unlike previous work, our design does not require modifications to network packets. We precisely specify the hardwaresoftware protocol for switch configuration; this enables us to prove the correctness of the design, and to provide well-specified invariants that the software driver must maintain for correctness. We implement our prototype switch design using the NetFPGA-10G hardware platform, and evaluate our prototype against commercial off-the-shelf switches. Jong Hun Han, Prashanth Mundkur, Charalampos Rotsos, Gianni Antichi, Nirav Dave, Andrew W. Moore 0002, Peter G. Neumann |
ANCS | 3 |
| 2015 | OFLOPS-Turbo: Testing the next-generation OpenFlow switchabstractThe heterogeneity barrier breakthrough achieved by the OpenFlow protocol is currently paced by the variability in performance semantics among network devices, which reduces the ability of applications to take complete advantage of programmable control. As a result, control applications remain conservative on performance requirements in order to be generalizable and trade performance for explicit state consistency in order to support varying performance behaviours. In this paper we argue that network control must be optimized towards network device capabilities and network managers and application developers must perform informed design decision using accurate switch performance profiles. This becomes highly critical for modern OpenFlow-enabled 10 GbE optical switches which significantly elevate switch performance requirements. We present OFLOPS-Turbo, the integration of the OFLOPS switch evaluation platform, with the OSNT platform, a hardware-accelerated traffic generation and capture system supporting lossless 10 GbE functionality. Using OFLOPS-Turbo, we conduct an evaluation of flow table manipulation capabilities in a representative collection of 10 GbE production OpenFlow switch devices and interpret the evolution of OpenFlow support by comparison with historical data. Charalampos Rotsos, Gianni Antichi, Marc Bruyere, Philippe Owezarski, Andrew W. Moore 0002 |
ICC | 1 |
| 2015 | An integrated environment for open-source network softwarizationabstractNetwork softwarization drives innovation both in software and hardware. This demo introduces a highly integrated environment that enables open source solutions for software defined network (SDN) in both hardware and software. This environment is built upon the NetFPGA platform for rapid prototyping of networking devices. It showcases tools (OSNT and OFLOPS) for evaluating the performance of networking devices, and demonstrates them using a pipelined multi-table OpenFlow enabled switch application. An open-source environment integrating both software and hardware that fully inter-operate, as demonstrated here, is essential for high-quality software defined networking solutions. Jong Hun Han, Gianni Antichi, Noa Zilberman, Charalampos Rotsos, Andrew W. Moore 0002 |
NetSoft | 4 |
| 2015 | Enabling Performance Evaluation Beyond 10 GbpsabstractDespite network monitoring and testing being critical for computer networks, current solutions are both extremely expensive and inflexible. This demo presents OSNT (www.osnt.org), a community-driven, high-performance, open-source traffic generator and capture system built on top of the NetFPGA-10G board which enables flexible network testing. The platform supports full line-rate traffic generation regardless of packet size across the four card ports, packet capture filtering and packet thinning in hardware and sub-msec time precision in traffic generation and capture, corrected using an external GPS device. Furthermore, it provides a software APIs to test the dataplane performance of multi-10G switches, providing a starting point for a number of different test cases. OSNT flexibility is further demonstrated through the OFLOPS-turbo platform: an integration of OSNT with the OFLOPS OpenFlow switch performance evaluation platform, enabling control and data plane evaluation of 10G switches. This demo showcases the applicability of the OSNT platform to evaluate the performance of legacy and OpenFlow-enabled networking devices, and demonstrates it using commercial switches. Gianni Antichi, Charalampos Rotsos, Andrew W. Moore 0002 |
SIGCOMM | 2 |
| 2015 | Reconfigurable Network Systems and Software-Defined NetworkingabstractModern high-speed networks have evolved from relatively static networks to highly adaptive networks facilitating dynamic reconfiguration. This evolution has influenced all levels of network design and management, introducing increased programmability and configuration flexibility. This influence has extended from the lowest level of physical hardware interfaces to the highest level of network management by software. A key representative of this evolution is the emergence of software-defined networking (SDN). In this paper, we review the current state of the art in reconfigurable network systems, covering hardware reconfiguration, SDN, and the interplay between them. We take a top-down approach, starting with a tutorial on software-defined networks. We then continue to discuss programming languages as the linking element between different levels of software and hardware in the network. We review electronic switching systems, highlighting programmability and reconfiguration aspects, and describe the trends in reconfigurable network elements. Finally, we describe the state of the art in the integration of photonic transceiver and switching elements with electronic technologies, and consider the implications for SDN and reconfigurable network systems. Noa Zilberman, Philip M. Watts, Charalampos Rotsos, Andrew W. Moore 0002 |
Proc. IEEE | 3 |
| 2014 | Faithful reproduction of network experimentsabstractThe proliferation of cloud computing has compelled the research community to rethink fundamental design aspects of networked systems. However, the tools commonly used to evaluate new ideas have not kept abreast of the latest developments. Common simulation and emulation frameworks fail to provide scalability, fidelity, reproducibility and execute unmodified code, all at the same time. We present SELENA, a Xen-based network emulation framework that offers fully reproducible experiments via its automation interface and supports the use of unmodified guest operating systems. This allows out-of-the-box compatibility with common applications and OS components, such as network stacks and filesystems. In order to faithfully emulate faster and larger networks, SELENA adopts the technique of time dilation and transparently slows down the passage of time for guest operating systems. This technique effectively virtualizes the availability of host's hardware resources and allows the replication of scenarios with increased I/O and computational demands. Users can directly control the trade-off between fidelity and running-times via intuitive tuning knobs. We evaluate the ability of SELENA to faithfully replicate the behavior of real systems and compare it against existing popular experimentation platforms. Our results suggest that SELENA can ac-curately model networks with aggregate link speeds of 44 Gbps or more, while improving by four times the execution time in comparison to ns3 and exhibits near-linear scaling properties. Dimosthenis Pediaditakis, Charalampos Rotsos, Andrew W. Moore 0002 |
ANCS | 2 |
| 2013 | Unikernels: library operating systems for the cloudabstractWe present unikernels, a new approach to deploying cloud services via applications written in high-level source code. Unikernels are single-purpose appliances that are compile-time specialised into standalone kernels, and sealed against modification when deployed to a cloud platform. In return they offer significant reduction in image sizes, improved efficiency and security, and should reduce operational costs. Our Mirage prototype compiles OCaml code into unikernels that run on commodity clouds and offer an order of magnitude reduction in code size without significant performance penalty. The architecture combines static type-safety with a single address-space layout that can be made immutable via a hypervisor extension. Mirage contributes a suite of type-safe protocol libraries, and our results demonstrate that the hypervisor is a platform that overcomes the hardware compatibility issues that have made past library operating systems impractical to deploy in the real-world. Anil Madhavapeddy, Richard Mortier, Charalampos Rotsos, David J. Scott, Balraj Singh, Thomas Gazagnaire, Steven Hand 0001, Jon Crowcroft |
ASPLOS | 3 |
| 2012 | Cost, performance & flexibility in OpenFlow: Pick threeabstractOS virtualization and cloud computing have radically changed the way Internet services are deployed: enterprises share third-party datacenters, deploying existing applications with minimal changes. Recent measurements reveal a lack of traffic isolation capabilities within the datacenter with network performance exhibiting high variability. We advocate addressing this problem by allowing applications to express their own forwarding logic using OpenFlow to achieve application specific optimal performance. We present an OpenFlow implementation within the Mirage application synthesis framework, in the form of library implementations of a modular controller and an extensible OpenFlow-enabled switch, able to expose the underlying network infrastructure to cloud applications. By linking into the application, this provides a safe yet highly extensible framework for programming network control that, although unoptimised, still provides reasonable performance when compared with existing controllers. Charalampos Rotsos, Richard Mortier, Anil Madhavapeddy, Balraj Singh, Andrew W. Moore 0002 |
ICC | 1 |
| 2012 | OFLOPS: An Open Framework for OpenFlow Switch Evaluation
Charalampos Rotsos, Nadi Sarrar, Steve Uhlig, Rob Sherwood, Andrew W. Moore 0002 |
PAM | 1 |
| 2012 | Signposts: end-to-end networking in a world of middleboxesabstractThis demo presents Signposts, a system to provide users with a secure, simple mechanism to establish and maintain communication channels between their personal cloud of named devices. Signpost names exist in the DNSSEC hierarchy, and resolve to secure end-points when accessed by existing DNS clients. Signpost clients intercept user connection intentions while adding privacy and multipath support. Signpost servers co-ordinate clients to dynamically discover routes and overcome the middleboxes that pervade modern edge networks. The demo will show a simple scenario where an individual's personal devices (phone, laptop) are interconnected via Signposts while sitting on different networks behind various middleboxes. As a result they will be able to fetch and push data between each other, demonstrated by, e.g., simple web browsing, even as the network configuration changes. Amir Chaudhry, Anil Madhavapeddy, Charalampos Rotsos, Richard Mortier, Andrius Aucinas, Jon Crowcroft, Sebastian Probst Eide, Steven Hand 0001, Andrew W. Moore 0002, Narseo Vallina-Rodriguez |
SIGCOMM | 3 |
| 2011 | Supporting novel home network management interfaces with openflow and NOXabstractThe Homework project has examined redesign of existing home network infrastructures to better support the needs and requirements of actual home users. Integrating results from several ethnographic studies, we have designed and built a home networking platform providing detailed per-flow measurement and management capabilities supporting several novel management interfaces. This demo specifically shows these new visualization and control interfaces (1), and describes the broader benefits of taking an integrated view of the networking infrastructure, realised through our router's augmented measurement and control APIs (2). Richard Mortier, Ben Bedwell, Kevin Glover, Tom Lodge, Tom Rodden, Charalampos Rotsos, Andrew W. Moore 0002, Alexandros Koliousis, Joseph S. Sventek |
SIGCOMM | 6 |
| 2010 | Probabilistic graphical models for semi-supervised traffic classificationabstractTraffic classification using machine learning continues to be an active research area. The majority of work in this area uses off-the-shelf machine learning tools and treats them as black-box classifiers. This approach turns all the modelling complexity into a feature selection problem. In this paper, we build a problem-specific solution to the traffic classification problem by designing a custom probabilistic graphical model. Graphical models are a modular framework to design classifiers which incorporate domain-specific knowledge. More specifically, our solution introduces semi-supervised learning which means we learn from both labelled and unlabelled traffic flows. We show that our solution performs competitively compared to previous approaches while using less data and simpler features. Copyright © 2010 ACM. Charalampos Rotsos, Jurgen Van Gael, Andrew W. Moore 0002, Zoubin Ghahramani |
IWCMC | 1 |