VLDB 2026 Research / reviewers in the wild / expert
Guido Marchetto
dblp:18/4780
· DBLP profile ↗
70ranked-venue papers
7as first author
39since 2021 · last 2026
0000-0003-3588-9367ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 32 · 3 first-author · 18 since 2021Software engineering, systems software and programming languages · 10 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 3 first-author · 4 since 2021Systems, architecture and hardware · 7 · 2 since 2021Security and privacy · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MERGE: Multi-Scenario Embedding for Robust Generalization in Network Anomaly Detection
Christian Colella, Cristiano Serra, Alessio Sacco, Guido Marchetto |
NetSoft | 4 |
| 2026 | CROWN: Cross-attention reinforcement learning for O-RAN wireless networksabstractFifth-generation (5G) cellular networks promise unprecedented connectivity through ultra-low latency and high-speed mobile broadband, driving the need for intelligent slice placement strategies in Open Radio Access Network (O-RAN) architectures. O-RAN promotes openness and vendor interoperability, but existing Machine Learning (ML)-based embedding solutions often prioritize performance metrics such as delay and availability while neglecting energy efficiency. To address this gap, we propose Crown, a Reinforcement Learning (RL)-based service placement framework that jointly optimizes Service Level Agreement (SLA) compliance and power consumption. Crown extends a traditional Deep Q-Network (DQN) by integrating cross-attention layers to model complex dependencies between virtualized O-RAN functions and heterogeneous physical servers, enabling more informed placement decisions. We evaluate Crown in a simulated O-RAN environment and compare it against state-of-the-art RL approaches and heuristic baselines. Results demonstrate that Crown reduces power consumption by 57% compared to a fixed deployment and by 15% relative to a DQN without cross‑attention, while meeting stringent latency and bandwidth requirements through action masking and achieving high slice admission rates and low deployment cost via its cost‑aware reward design. Furthermore, we measure the inference time, showing that the attention-enhanced RL design remains practical for large-scale deployments. Doriana Monaco, Alessio Sacco, Guido Marchetto |
Comput. Networks | 3 |
| 2026 | AgriSmart: An IoT-enabled framework for agricultural resource optimization
Jackson Butcher, Christian Cumini, Mounica Talasila, Montserrat Salmeron Cortasa, Alessio Sacco, Michael Popp, Guido Marchetto, Simone Silvestri |
Comput. Commun. | 8 |
| 2026 | TCP-HAR: On-Device Transferable and Copyright-Preserving Human Activity RecognitionabstractTeaching a machine to accurately identify human activities from sensor data poses a significant challenge, which is further compounded by considerations of data privacy, resource costs, and responsiveness, particularly within the constraints of devices like smartphones. While current solutions efficiently identify activities, trained models are barely portable in scenarios composed of diverse activities and limited battery life devices, such as smartphones. This paper introduces Transferable and Copyright-Preserving Human Activity Recognition (TCP-HAR), a mobile-based HAR system that integrates digital watermarking, Federated Learning (FL), Transfer Learning (TL), and compression techniques to provide efficient human activity recognition while providing copyright protection of deep neural network models over Android smartphones. Our solution optimizes the utilization of FL, TL, and their combination (FTL) by extensively testing standalone TL models in offline contexts and comparing these results with FL across a network of mobile devices. Our findings highlight the benefits of TCP-HAR for mobile environments in terms of accuracy, F1-score, and training time. In addition, our proposed watermarking mechanism is robust yet computationally efficient, ensuring ownership verification without compromising the scalability of the TFL process. Alessio Sacco, Bruno Palermo, Giulio Figliolino, Chiara Contoli, Guido Marchetto, Flavio Esposito |
Pervasive Mob. Comput. | 5 |
| 2026 | Adaptive SDN Autoscaling via Generalizable Multi-Agent Reinforcement Learning With EAGLE
Doriana Monaco, Alessio Sacco, Flavio Esposito, Guido Marchetto |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2025 | MARS: Multi-Agent Deep Reinforcement Learning for Complex Environment ExplorationabstractAutonomous exploration of complex, unknown environments is a cutting-edge task not entirely solved by the scientific community. When an agent needs to explore a maze without any a priori information about the environment, the lack of proper destinations and explicit task objectives make traditional navigation policies inappropriate. While the literature presents some sporadic deterministic systems able to face the tasks, learning approaches still need an adequate investigation which could prove them to be more suitable and versatile for this purpose. In this paper, we present MARS, a path planner that exploits swarms of robots to optimize the exploration of complex unknown environments, such as mazes. To make the solution scalable, the proposed method exploits two cooperating modules: local and global planners. The local planner is modeled as a Markov Decision Process (MDP) and trained as a Reinforcement Learning (RL) multi-agent system. Each agent has access to image representations of a section of the global map, always centered in the robot reference frame, and decides the next navigation goal to complete the local exploration. The global planner is a deterministic system that recovers the navigation when a local solution is unavailable. The robots share the explored section with peers when they meet in a rendez-vous. We compared our approach to a single deterministic agent, a single RL agent and a close-to-optimal deterministic approach which deploys five greedy agents. The simulation results demonstrate MARS' efficiency, reaching near-optimal levels in significantly less time. Francesco Gervino, Andrea Eirale, Marcello Chiaberge, Alessio Sacco, Guido Marchetto, Claudio Casetti |
CCNC | 5 |
| 2025 | Enforcing Security Policies in the Application Layer and the Data PlaneabstractNetwork traffic is now largely encrypted. Yet analysis of side-channel features-packet sizes, timings, and directions-can still reveal patterns about encrypted flows. Recent machine learning (ML) techniques have made such traffic analysis more powerful, and they can be applied both offensively (e.g., inference attacks) and defensively (e.g., intrusion detection). This raises the need for protections that keep pace with MLenabled capabilities without exacerbating resource overhead and reaction delays. My research explores new opportunities, such as application-agnostic defenses, offered by data-plane programmability (e.g., eBPF/XDP at hosts and P4 in switches) to reshape observable traffic patterns and fast feature extraction for advanced detection mechanisms. My PhD also focuses on designing and prototyping the combination of ML together with programmable data planes to both mitigate traffic analysis and harness it for defense, while clarifying the trade-offs between privacy, performance, and deployability. Federico Rinaudi, Alessio Sacco, Guido Marchetto |
CNSM | 3 |
| 2025 | Flecto: Cross-Layer Adaptive Congestion Control with Reinforcement LearningabstractEffective congestion control is critical for wireless networks, where rapidly varying channel conditions and diverse traffic demands can severely degrade performance. Traditional congestion control algorithms rely on static heuristics that are often ill-suited for dynamic wireless environments. In this paper, we introduce Flecto, a Reinforcement Learning (RL)-based congestion control solution integrated into the QUIC protocol that, leveraging cross-layer metrics, including Signal-to-Noise Ratio, Block Error Rates, and Round-Trip Time measurements, can take decisions using a comprehensive view of network conditions. We implemented Flecto on a 5G testbed using OpenAirInterface and ETTUS USRP B210 radios, showing how it adapts transmission rates in real-time to maximize throughput and minimize latency while maintaining stability. Experimental results show that Flecto achieves an average throughput of 4539.5 KB/s approximately 6% higher both than Cubic (4267.2 KB/s) and New Reno (2674.1 KB/s) while reducing the average Round-Trip Time to 21.8 ms, significantly lower than Cubic’s 27.6 ms and New Reno’s 174.9 ms. These performance gains underscore the promise of integrating RL with cross-layer feedback for adaptive, efficient congestion control in next-generation wireless networks. Moreover, the modular design of Flecto facilitates its extension to other transport protocols and multi-user scheduling frameworks, paving the way for broader adoption in future wireless systems. Cristiano Serra, Emilio Paolini, Roger Immich, Alessio Sacco, Guido Marchetto, Flavio Esposito |
HPSR | 5 |
| 2025 | RobinHood: Collaborative Burst Mitigation Through in-Network Packet DeflectionabstractMicrobursts - microsecond-scale congestion events - are a major cause of packet loss and performance degradation in modern datacenter networks. While packet deflection techniques can help manage microbursts, current implementations lead to excessive packet reordering, exacerbated congestion under high load, and head-of-line blocking in switch buffers. In this paper, we design and implement RobinHood, a novel in-network burst-tolerant protocol. At its core, the protocols mechanisms and policies are based on work-stealing, a technique originally designed to reduce job completion times in operating systems. Through extensive trace-driven simulations on leaf-spine and fattree topologies, we show that RobinHood improves flow completion times up to 22% over Equal-Cost Multi-Path (ECMP), and up to 7% over recent solutions, DIBS and Vertigo, under high load scenarios. Lorenzo Pantano, Cristian Zilli, Lorenzo Pappone, Alessio Sacco, Guido Marchetto, Flavio Esposito |
ICC | 5 |
| 2025 | Intent-Based Kubernetes Configuration via LLMs: Current Trends and Open ChallengesabstractThe advent of Large Language Models (LLMs) is progressively transforming how complex tasks across various domains can be automated, with a notable potential impact on cloud computing operations. In this domain, LLMs might be used, for example, to configure Kubernetes (K8s) clusters via the generation of manifest files – structured configuration files defining the containerized environment. However, despite the considerable advances in LLMs’ text generation, this task conceals several challenges that prevent operators from achieving a fully automated process. In this paper, we present the current trends in solving these gaps, quantitatively evaluate the accuracy of LLM-based approaches to generate K8s manifests starting from human intents, and discuss open challenges that make benchmarking and automation still complex. Experiments over three open-source LLMs demonstrate how intent-based K8s manifest generation can be effectively achieved through model fine-tuning, but also what open issues remain and must be addressed prior to having an autonomous and self-healing K8s infrastructure managed via Agentic AI. Alessio Sacco, Cristian Zilli, Guido Marchetto |
LCN | 3 |
| 2025 | Optimizing Model Pruning in Decentralized Learning Networks with DFL-TrimabstractIn recent decades, applications in environmental sustainability, education, and housekeeping have become increasingly distributed and sophisticated, leveraging a wide range of devices to perform complex tasks. While a large number of agents can reduce computation time, managing these distributed systems presents significant challenges due to resource constraints such as power consumption and storage. To address this, the literature has explored various model compression techniques, such as pruning, to optimize performance in distributed environments. In this paper, we propose DFL-Trim, a solution for trimming models in Decentralized Federated Learning (FL) that meets network constraints while maintaining satisfactory performance. We demonstrate how pruning can be implemented in decentralized settings, analyze its effect on bandwidth usage, and discuss the trade-offs between compression and model accuracy. Andrea Pinto, Alessandro Masci 0003, Alessio Sacco, Guido Marchetto, Flavio Esposito |
NetSoft | 4 |
| 2025 | Scheduling Latency-Sensitive Tasks in the Cloud Continuum with Hierarchical Reinforcement LearningabstractService orchestrators such as Kubernetes are widely employed to automate the handling and scheduling of workloads, which involves determining the most suitable physical node on which to start a new task. The expanding application of Machine Learning (ML) algorithms, and in particular Reinforcement Learning (RL), opens up new development opportunities to make runtime decisions that can account for multiple metrics and varying network conditions. However, current RL-based solutions are unable to fit the growing complexity of distributed applications and infrastructure, characterized by a more heterogeneous resource continuum and the increasing need to minimize energy consumption while satisfying tasks' requirements. To fill this gap, we propose RL-ICE as an innovative scheduler that can work in such a cloud continuum by leveraging a multi-cluster and hierarchical RL to satisfy both user Quality of Experience (QoE) metrics and tenant's costs. We test RL-ICE in a simulated large-scale environment and in a real-world Kubernetes setup. In both scenarios, our solution effectively balances user-perceived latency, energy consumption, and deployment costs. Additionally, RL-ICE can dynamically respond to network failures by migrating microservices to maintain efficient management of resources. Doriana Monaco, Alessio Sacco, Claudio Casetti, Guido Marchetto |
NOMS | 4 |
| 2025 | Real-time latency prediction for cloud gaming applicationsabstractCloud gaming represents a rapidly growing segment in the entertainment industry, allowing users to stream and interact with high-quality games over the Internet. However, the problem of maintaining a seamless gaming experience is inherent to minimizing user-perceived latency. In this paper, we present CLoud Application lAtency Prediction (CLAAP), a novel solution that, to tolerate challenged network conditions in gaming, predicts such latency via a Machine Learning (ML) model and forecasts future network evolution. The model, trained over diverse network conditions and gaming scenarios, can then update its parameters via a concept drift detection algorithm that suggests a re-training action, reducing the prediction error up to 21% with minimal overhead. We then integrate this network metrics predictor into a game state prediction to further tolerate network latency spikes even from the user perspective, who can continue playing even in adversarial conditions without session interruptions. The results suggest the potential of advanced predictive analytics in mitigating latency issues, thereby setting the stage for more responsive and immersive cloud gaming services. Doriana Monaco, Alessio Sacco, Daniele Spina, Francesco Strada, Andrea Bottino, Tania Cerquitelli, Guido Marchetto |
Comput. Networks | 7 |
| 2025 | Dealing With Challenged IoT Networks in Hierarchical Federated LearningabstractFederated Learning has revolutionized the way in which mobile devices and IoT can share common knowledge in data analytics. However, some challenges arise when dealing with heterogeneous and challenged networks, especially in gradient synchronization. For example, some clients (referred to as stragglers) may take much longer to report their output than other nodes. Current solutions addressing the straggling problems either propose a distributed coordination (but introduce new synchronization issues) or deadline-based approaches to discard clients after a fixed deadline (but introduce the problem of determining a suitable deadline). To this end, we propose to set a dynamic deadline in which the central server selects the best IoT nodes via an online learning approach based on predicting the response time of each client. Moreover, to further mitigate synchronization and scalability issues, we also consider a hierarchical approach in which clients send model parameters to intermediate aggregation edge servers. Our results demonstrate that this approach can lower network overhead by 78% compared to the widely adopted FedAvg and 49% to the best alternative. At the same time, the model accuracy is preserved, and the training time in challenged networks is reduced by 52% w.r.t. FedAvg and 32% w.r.t. recent solutions. Alessio Sacco, Doriana Monaco, Guido Marchetto, Paolo Montuschi |
IEEE Internet Things J. | 3 |
| 2025 | LLNet: An Intent-Driven Approach to Instructing Softwarized Network Devices Using a Small Language ModelabstractTraditional network management requires manual coding and expertise, making it challenging for non-specialists and experts to handle increasing devices and applications. In response, Intent-Based Networking (IBN) has been proposed to simplify network operations by allowing users to express in natural language the program objective (or intent), which is then translated into device-specific configurations. The emergence of Large Language Models (LLMs) has boosted the capabilities to interpret human intents, with recent IBN solutions embracing LLMs for a more accurate translation. However, while these solutions excel at intent comprehension, they lack a complete pipeline that can receive user intents and deploy network programs across devices programmed in multiple languages. In this paper, we present LLNeT, our IBN solution that, within the context of Software-Defined Networking (SDN), can translate seamlessly intent-to-program. First, leveraging LLMs, we convert network intents into an intermediate representation by extracting key information; then, using this output, the system can tailor the network code for any topology using the specific language calls. At the same time, we address the challenge of a more sustainable IBN approach to reduce its energy consumption, and we experience how even a Small Language Model (SLM) can efficiently help LLNeT for input translation. Results across multiple use cases demonstrated how our solution can guarantee adequate translation accuracy while reducing operator expenses compared to other LLM-based approaches. Antonino Angi, Alessio Sacco, Guido Marchetto |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2025 | Guest Editors' Introduction: Special section on Research Advances Toward Effective and Sustainable Next Generation Networks
Alessio Sacco, Kohei Shiomoto, Mohamed Faten Zhani, Guido Marchetto, Shahid Mumtaz, Michael Welzl, Ramón J. Durán |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2025 | ClearNET: Enhancing Transparency in Opaque Network Models Using Explainable AI (XAI) for Efficient Traffic EngineeringabstractAI/ML has enhanced computer networking, aiding administrators in decision-making and automating tasks for optimized performance. Despite such advances in network automation, there remains limited trust in these uninterpretable models due to their inherent complexity. To this aim, eXplainable AI (XAI) has emerged as a critical area to demystify (deep) neural network models and to provide more transparent decision-making processes. While other fields have embraced XAI more prominently, the use of these techniques in computer network management remains largely unexplored. In this paper, we shed some light by presenting, an XAI-based approach designed to clarify the opaque nature of data-driven traffic engineering solutions in general, and efficient network telemetry, in particular. It does so by examining the intrinsic behavior of the adopted models, thereby reducing the volume of data needed for effective learning. Our extensive evaluation revealed how our approach not only reduces training time and overhead in network telemetry models but also maintains or improves model accuracy, leading, in turn, to more efficient and clear ML models for network management. Cristian Zilli, Alessio Sacco, Flavio Esposito, Guido Marchetto |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2024 | Routing with ART: Adaptive Routing for P4 Switches With In-Network Decision TreesabstractRecent advances in Machine Learning (ML) brought several advantages also within computer network management. For programmable data planes, however, it is more challenging to benefit from these advantages, given their limited resource capabilities colliding with the complexity of ML models. In this paper, we propose ART, an attempt to simplify ML-based solutions for routing, so that they can "fit", i.e., be executed, on P4 switches. To provide such model simplification, ART relies on efficient knowledge distillation techniques, converting, in particular, Deep Reinforcement Learning (DRL) models into a simpler Decision Tree (DT). Our evaluation results validate the accuracy of the extracted model and the application of the model logic directly into switches with little impact, paving the way for a more reactive data plane programmability via machine learning integration. Antonino Angi, Alessio Sacco, Flavio Esposito, Guido Marchetto |
GLOBECOM | 4 |
| 2024 | Latency-aware Scheduling in the Cloud-Edge ContinuumabstractIn recent years, containerized deployment models have gained favor across many domain of applications. Kubernetes, the de-facto standard for containers orchestration, can efficiently manage heterogeneous devices, but fails to adapt to possibly stringent requirements, as it only considers computing metrics for scheduling decisions. In addition, the rising prominence of distributed cloud environments, which enable the development of highly available, performant solutions, requires modifications to the default Kubernetes scheduler. To address these challenges, we introduce LAIS, a multi-cluster Kubernetes scheduler optimized for end-to-end latency measurements to enhance user Quality of Experience (QoE). Unlike existing approaches, we define a geographically distributed environment and deploy a solution that satisfies user-specified intents in terms of latency. Depending on user needs, LAIS can either meet a specific latency constraint or schedule pods in the cluster with the lowest latency. After implementing LAIS in a multi-cluster environment, we found it highly effective in accommodating a range of user intents, outperforming the default Kubernetes scheduler in this regard. Cristopher Chiaro, Doriana Monaco, Alessio Sacco, Claudio Casetti, Guido Marchetto |
NOMS | 5 |
| 2024 | Inferring Visibility of Internet Traffic Matrices Using eXplainable AIabstractA large fraction of recent network management tasks rely on Internet traffic matrices, ranging from planning and troubleshooting to routing and anomaly detection. Despite extensive research efforts over the years, acquiring a comprehensive overview of network traffic remains a difficult and error-prone task. While the literature has mostly proposed increasingly accurate and complex Machine Learning (ML) models to reconstruct missing information, in this paper we propose an alternative approach to further enhance this process: combining the ML model with eXplainable AI (XAI) to analyze the model behavior, detect most significant features, and limit the reconstruction process to such reduced input. With this methodology, not only we simplify the problem, but the entire solution finds greater deployability as the data acquisition phase is also simplified. Numerical results demonstrate that, with our solution on a Convolution Neural Network model, the error during completion can be lowered by 80% for a network telemetry traffic reduction of 75%. Cristian Zilli, Alessio Sacco, Doriana Monaco, Okwudilichukwu Okafor, Flavio Esposito, Guido Marchetto |
NOMS | 6 |
| 2024 | A Software Platform for Testing Multi-Link Operation in Industrial Wi-Fi NetworksabstractMulti-Link Operation (MLO) in Wi-Fi 7 is expected to tangibly boost throughput while lowering transmission latency at the same time. This is very relevant in industrial scenarios and makes MLO suitable, e.g., to support seamless device mobility. Benefits depend on the ability of multi-link devices to select at run-time the best link, among the available ones, in order to maximize both communication performance and reliability.In this paper an experimental platform is proposed, with the aim of leveraging commercial hardware and open source software, and easing prototyping and evaluation of MLO techniques. The platform has been employed to analyze the transmission quality of two pairs of non-overlapping channels, and in particular to assess whether or not adequate diversity is provided, so that those channels can be exploited to improve reliability. Results point out that correlation between different links is, in most cases, limited, which makes MLO a valuable approach. Matteo Rosani, Gianluca Cena, Dave Cavalcanti 0001, Valerio Frascolla, Guido Marchetto, Stefano Scanzio |
WFCS | 5 |
| 2024 | Multi-Link Operation and Wireless Digital Twin to Support Enhanced Roaming in Next-Gen Wi-FiabstractThe next generation of Wi-Fi is meant to achieve ultra-high reliability for wireless communication. Several approaches are available to this extent, some of which are being considered for inclusion in standards specifications, including coordination of access points to reduce interference.In this paper, we propose a centralized architecture based on digital twins, called WiTwin, with the aim of supporting wireless stations in selecting the optimal association according to a set of parameters. Unlike prior works, we assume that Wi-Fi 7 features like multi-link operation (MLO) are available. Moreover, one of the main goals of this architecture is to preserve communication quality in the presence of mobility, by helping stations to perform reassociation at the right time and in the best way. Stefano Scanzio, Matteo Rosani, Gabriele Formis, Dave Cavalcanti 0001, Valerio Frascolla, Guido Marchetto, Gianluca Cena |
WFCS | 6 |
| 2024 | Load Profiling via In-Band Flow Classification and P4 With HowdahabstractData center traffic management challenges increase with the complexity and variety of new Internet and Web applications. Efficient network management systems are often needed to thwart delays and minimize failures. In this regard, it seems helpful to identify in advance the different classes of flows that (co)exist in the network, characterizing them into different types based on different latency/bandwidth requirements. In this paper, we propose Howdah, a traffic identification and profiling mechanism that uses Machine Learning and a load-aware forwarding strategy to offer adaptation to different classes of traffic with the support of programmable data planes. With Howdah, the sender and gateway elements inject in-band traffic information obtained by a supervised learning algorithm. When a switch or router receives a packet, it exploits this host-based traffic classification to adapt to a desirable traffic profile, for example, to balance the traffic load. We compare our solution against recent traffic engineering proposals and demonstrate the effectiveness of the cooperation between host traffic classification and P4-based switch forwarding policies, reducing packet transmission time in data center scenarios. Antonino Angi, Alessio Sacco, Flavio Esposito, Guido Marchetto, Alexander Clemm |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2023 | Hide & Seek: Traffic Matrix Completion and Inference Using Hidden InformationabstractTraffic matrices are used for many network management operations, from planning to repairing. Despite years of research on the topic, their estimation and inference on the Internet are still challenging and error-prone. For example, missing values are unavoidable due to flaws in the measurement systems and possible failure in data collection systems. It is thus helpful for many network operators to recover the missing data from the partial direct measurements. Some existing matrix completion methods do not fully consider network traffic behavior and hidden traffic characteristics, showing the inability to adapt to multiple scenarios. Others instead make assumptions on the matrix structure that may be invalid or impractical, curtailing the applicability. In this paper, we propose Hide & Seek, a novel matrix completion and prediction algorithm based on a combination of generative autoencoders and Hidden Markov Models. We demonstrate with an extensive experimental evaluation on real-world datasets how our algorithm can accurately reconstruct missing values while predicting their short-term evolution. Alessio Sacco, Flavio Esposito, Guido Marchetto |
CCNC | 3 |
| 2023 | HINT: Supporting Congestion Control Decisions with P4-driven In-Band Network TelemetryabstractYears of research on congestion controls have highlighted how end-to-end and in-network protocols might perform poorly in some contexts. Recent advances in data plane network programmability could also bring advantages in transport protocols, enabling mining and processing in-network congestion signals. However, the new machine learning-based congestion control class has only partially used data from the network, favoring a more sophisticated model design but neglecting possibly precious pieces of data. In this paper, we present HINT, an in-band network telemetry architecture designed to provide insights into network congestion to the end-host TCP algorithm during the learning process. In particular, the key idea is to adapt switches’ behavior via P4 and instruct them to insert simple device information, such as processing delay and queue occupancy, directly into transferred packets. Initial experimental results show that this approach comes with a little network overhead but can improve the visibility and, consequently, the accuracy of TCP decisions of the end-host. At the same time, the programmability of both switches and hosts also enables customization of the default behavior as the user’s needs change. Alessio Sacco, Antonino Angi, Flavio Esposito, Guido Marchetto |
HPSR | 4 |
| 2023 | Towards Autonomous Computer Networks in Support of Critical SystemsabstractA recent trend dictating evolution of management and orchestration of computer networks is constituted by the softwarization and virtualization of them, which have drastically simplified the deployment and real-time reconfiguration of network functions, allowing them to continuously adapt and to deal with dynamic demands in an automated way. Alongside, recent management and orchestration approaches for softwarized networks employ Artificial Intelligence (AI) and Machine Learning (ML) to further reduce reaction time and improve the accuracy of decisions, where the network operations can be automated to the point of realizing autonomous driving networks. However, while automating operations can improve the overall system (it is acknowledged that 70% of network faults are caused by manual errors), AI/ML methods are not the panaceas, and we are still far from having a fully operating and efficient automated architecture. In this dissertation, we present a novel class of software network solutions that share the goal of enabling intelligent and autonomous computer networks, exploring how to exploit the power of AI/ML to handle the growing complexity of critical systems. We start with a new network management scheme for adaptive routing and autonomous scaling of virtual network resources. Then, acting on the hosts, we propose to adjust the TCP congestion control with a ML-based solution, whose goal is to select the proper congestion window learning from end-to-end features and (when available) network signals. We believe that the proposed solutions, and their combination, can lay the foundation for automated systems that better suit modern edge environments and cellular networks by providing unprecedented flexibility and adaptation to even unseen and unknown network conditions. Alessio Sacco, Guido Marchetto |
NOMS | 2 |
| 2023 | Automated Firewall Configuration in Virtual NetworksabstractThe configuration of security functions in computer networks is still typically performed manually, which likely leads to security breaches and long re-configuration times. This problem is exacerbated for modern networks based on network virtualization, because their complexity and dynamics make a correct manual configuration practically unfeasible. This article focuses on packet filters, i.e., the most common firewall technology used in computer networks, and it proposes a new methodology to automatically define the allocation scheme and configuration of packet filters in the logical topology of a virtual network. The proposed method is based on solving a carefully designed partial weighted Maximum Satisfiability Modulo Theories problem by means of a state-of-the-art solver. This approach formally guarantees the correctness of the solution, i.e., that all security requirements are satisfied, and it minimizes the number of needed firewalls and firewall rules. This methodology is extensively evaluated using different metrics and tests on both synthetic and real use cases, and compared to the state-of-the-art solutions, showing its superiority. Daniele Bringhenti, Guido Marchetto, Riccardo Sisto, Fulvio Valenza, Jalolliddin Yusupov |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Handling Privacy-Sensitive Medical Data With Federated Learning: Challenges and Future DirectionsabstractRecent medical applications are largely dominated by the application of Machine Learning (ML) models to assist expert decisions, leading to disruptive innovations in radiology, pathology, genomics, and hence modern healthcare systems in general. Despite the profitable usage of AI-based algorithms, these data-driven methods are facing issues such as the scarcity and privacy of user data, as well as the difficulty of institutions exchanging medical information. With insufficient data, ML is prevented from reaching its full potential, which is only possible if the database consists of the full spectrum of possible anatomies, pathologies, and input data types. To solve these issues, Federated Learning (FL) appeared as a valuable approach in the medical field, allowing patient data to stay where it is generated. Since an FL setting allows many clients to collaboratively train a model while keeping training data decentralized, it can protect privacy-sensitive medical data. However, FL is still unable to deliver all its promises and meets the more stringent requirements (e.g., latency, security) of a healthcare system based on multiple Internet of Medical Things (IoMT). For example, although no data are shared among the participants by definition in FL systems, some security risks are still present and can be considered as vulnerabilities from multiple aspects. This paper sheds light upon the emerging deployment of FL, provides a broad overview of current approaches and existing challenges, and outlines several directions of future work that are relevant to solving existing problems in federated healthcare, with a particular focus on security and privacy issues. Ons Aouedi, Alessio Sacco, Kandaraj Piamrat, Guido Marchetto |
IEEE J. Biomed. Health Informatics | 4 |
| 2023 | Completing and Predicting Internet Traffic Matrices Using Adversarial Autoencoders and Hidden Markov ModelsabstractInternet traffic matrices are used nowadays for a variety of network management operations, from planning to repairing. Despite years of research on the topic, obtaining a global view of traffic is still challenging and error-prone. Due to flaws in the measurement systems and possible failure in data collection tools, missing values are unavoidable. It is thus helpful for many network operators to recover the missing data from the partial direct measurements. While some existing matrix completion methods allowed this reconstruction, they do not fully consider network traffic behavior and hidden traffic characteristics, showing the inability to adapt to multiple scenarios. Others instead make assumptions about the matrix structure that may be invalid or impractical, curtailing the applicability. In this paper, we propose Hide & Seek, a novel matrix completion and prediction algorithm based on a combination of generative autoencoders and Hidden Markov Models. After an extensive experimental evaluation based on both real-world datasets and on a testbed, we demonstrated how our algorithm can accurately reconstruct missing values while also predicting their short-term evolution. Alessio Sacco, Flavio Esposito, Guido Marchetto |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | Partially Oblivious Congestion Control for the Internet via Reinforcement LearningabstractDespite years of research on transport protocols, the tussle between in-network and end-to-end congestion control has not been solved. This debate is due to the variance of conditions and assumptions in different network scenarios, e.g., cellular versus data center networks. Recently, the community has proposed a few transport protocols driven by machine learning, nonetheless limited to end-to-end approaches. In this paper, we present Owl, a transport protocol based on reinforcement learning, whose goal is to select the proper congestion window learning from end-to-end features and network signals, when available. We show that our solution converges to a fair resource allocation after the learning overhead. Our kernel implementation, deployed over emulated and large scale virtual network testbeds, outperforms all benchmark solutions based on end-to-end or in-network congestion control. Alessio Sacco, Matteo Flocco, Flavio Esposito, Guido Marchetto |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2022 | Howdah: Load Profiling via In-Band Flow Classification and P4abstractThe challenges of managing datacenter traffic increase with the complexity and variety of new Internet and Web applications. Efficient network management systems are often required to thwart delays and minimize failures. In this regard, it appears helpful to identify in advance the different classes of flows that (co)exist in the network, characterizing them into different types according to the different latency/bandwidth requirements. In this paper, we propose Howdah, a traffic identification and profiling mechanism that uses Machine Learning and a congestion-aware forwarding strategy to offer adaptation to different traffic classes with the support of programmable data-planes. With Howdah, sender and gateway elements inject in-band traffic information obtained using supervised learning. When a switch or a router receives a packet, it exploits such host-based traffic classification to adapt to a desirable traffic profile, for example, balancing the load. We compare our solutions against recent traffic engineering solutions and show the efficacy of cooperation between host traffic classification and P4-based switch forwarding policies, reducing packet transmission time in datacenter scenarios. Antonino Angi, Alessio Sacco, Flavio Esposito, Guido Marchetto, Alexander Clemm |
CNSM | 4 |
| 2022 | NLP4: An Architecture for Intent-Driven Data Plane ProgrammabilityabstractTranslating high-level policies to lower-level network rules is one of the main goals of control or data plane network programmability. To further abstract requirements and propel automation in networking, several industries have proposed the paradigm of “network intent”. However, the translation from intents to low-level policies is considered critical to program data planes and other network elements, especially when dealing with P4-enabled switches. In this paper, we present NLP4, an architecture that helps translate intents, in the form of human language, into data-plane programs, in the form of P4 rules. In particular, NLP4 uses Natural Language Processing (NLP) techniques to translate high-level human-language intents, a MultiLayer Perceptron (MLP) model for processing the NLP output and converting it into mid-level policy. An API then uses this information, which separates the intent from the network to generate commands readable by P4-enabled switches. Our initial prototype on a network emulator validates our architecture for a specific case: load profiling, demonstrating how even users with limited P4 expertise may customize their networks by merely specifying intents. Antonino Angi, Alessio Sacco, Flavio Esposito, Guido Marchetto, Alexander Clemm |
NetSoft | 4 |
| 2022 | Restoring Application Traffic of Latency-Sensitive Networked Systems Using Adversarial AutoencodersabstractThe Internet of Things (IoT), coupled with the edge computing paradigm, is enabling several pervasive networked applications with stringent real-time requirements, such as telemedicine and haptic telecommunications. Recent advances in network virtualization and artificial intelligence are helping solve network latency and capacity problems, learning from several states of the network stack. However, despite such advances, a network architecture able to meet the demands of next-generation networked applications with stringent real-time requirements still has untackled challenges. In this paper, we argue that only using network (or transport) layer information to predict traffic evolution and other network states may be insufficient, and a more holistic approach that considers predictions of application-layer states is needed to repair the inefficiencies of the TCP/IP architecture. Based on this intuition, we present the design and implementation of Reparo. At its core, the design of our solution is based on the detection of a packet loss and its restoration using a Hidden Markov Model (HMM) empowered with adversarial autoencoders. In our evaluation, we considered a telemedicine use case, specifically a telepathology session, in which a microscope is controlled remotely in real-time to assess histological imagery. Our results confirm that the use of adversarial autoencoders enhances the accuracy of the prediction method satisfying our telemedicine application’s requirements with a notable improvement in terms of throughput and latency perceived by the user. Alessio Sacco, Flavio Esposito, Guido Marchetto |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2021 | On Control and Data Plane Programmability for Data-Driven NetworkingabstractThe soaring complexity of networks has led to more and more complex methods to manage and orchestrate efficiently the multitude of network environments. Several solutions exist, such as OpenFlow, NetConf, P4, DPDK, etc., that allow net-work programmability at both control and data plane level, driving innovation in many focused high-performance networked applications. However, with the increase of strict requirements in critical applications, also the networking architecture and its operations should be redesigned. In particular, recent advances in machine learning have opened new opportunities to the automation of network management, exploiting existing advances in software-defined infrastructures. We argue that the design of effective data-driven network management solutions needs to collect, merge, and process states from both data and control planes. This paper sheds light upon the benefits of utilizing such an approach to support feature extraction and data collection for network automation. Alessio Sacco, Flavio Esposito, Guido Marchetto |
HPSR | 3 |
| 2021 | Owl: Congestion Control with Partially Invisible Networks via Reinforcement LearningabstractYears of research on transport protocols have not solved the tussle between in-network and end-to-end congestion control. This debate is due to the variance of conditions and assumptions in different network scenarios, e.g., cellular versus data center networks. Recently, the community has proposed a few transport protocols driven by machine learning, nonetheless limited to end-to-end approaches.In this paper, we present Owl, a transport protocol based on reinforcement learning, whose goal is to select the proper congestion window learning from end-to-end features and network signals, when available. We show that our solution converges to a fair resource allocation after the learning overhead. Our kernel implementation, deployed over emulated and large scale virtual network testbeds, outperforms all benchmark solutions based on end-to-end or in-network congestion control. Alessio Sacco, Matteo Flocco, Flavio Esposito, Guido Marchetto |
INFOCOM | 4 |
| 2021 | A novel approach for security function graph configuration and deploymentabstractNetwork virtualization increased the versatility in enforcing security protection, by easing the development of new security function implementations. However, the drawback of this opportunity is that a security provider, in charge of configuring and deploying a security function graph, has to choose the best virtual security functions among a pool so large that makes manual decisions unfeasible. In light of this problem, the paper proposes a novel approach for synthesizing virtual security services by introducing the functionality abstraction. This new level of abstraction allows to work in the virtual level without considering the different function implementations, with the objective to postpone the function selection jointly with the deployment, after the configuration of the virtual graph. This novelty enables to optimize the function selection when the pool of available functions is very large. A framework supporting this approach has been implemented and it showed adequate scalability for the requirements of modern virtual networks. Daniele Bringhenti, Guido Marchetto, Riccardo Sisto, Fulvio Valenza |
NetSoft | 2 |
| 2021 | A Formal Approach to Verify Connectivity and Optimize VNF Placement in Industrial NetworksabstractThe increased flexibility and interconnectivity of modern industrial communication networks, obtained through the use of innovative technologies like network function virtualization and software-defined networking, require a secure and manageable framework to support the new communication and computing needs. To focus on these requirements, this article proposes a framework for reliable placement of services across physically separated locations, which offers both system optimization, in terms of latency and resource utilization, and connectivity policy enforcement to guarantee service reliability, safety, and security. This is achieved by exploiting a new approach to solve the virtual network embedding problem, using optimization modulo theories (MaxSMT), which allows the use of very expressive constraints. Guido Marchetto, Riccardo Sisto, Fulvio Valenza, Jalolliddin Yusupov, Adlen Ksentini |
IEEE Trans. Ind. Informatics | 1 |
| 2021 | Improving the Formal Verification of Reachability Policies in Virtualized NetworksabstractNetwork Function Virtualization (NFV) and Software Defined Networking (SDN) are new emerging paradigms that changed the rules of networking, shifting the focus on dynamicity and programmability. In this new scenario, a very important and challenging task is to detect anomalies in the data plane, especially with the aid of suitable automated software tools. In particular, this operation must be performed within quite strict times, due to the high dynamism introduced by virtualization. In this article, we propose a new network modeling approach that enhances the performance of formal verification of reachability policies, checked by solving a Satisfiability Modulo Theories (SMT) problem. This performance improvement is motivated by the definition of function models that do not work on single packets, but on packet classes. Nonetheless, the modeling approach is comprehensive not only of stateless functions, but also stateful functions such as NATs and firewalls. The implementation of the proposed approach achieves high scalability in complex networked systems consisting of several heterogeneous functions. Daniele Bringhenti, Guido Marchetto, Riccardo Sisto, Serena Spinoso, Fulvio Valenza, Jalolliddin Yusupov |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2021 | Supporting Sustainable Virtual Network Mutations With MystiqueabstractThe abiding attempt of automation has also permeated the networks, with the ability to measure, analyze, and control themselves in an automated manner, by reacting to changes in the environment (e.g., demand). When provided with these features, networks are often labeled as “self-driving” or “autonomous”. In this regard, the provision and orchestration of physical or virtual resources are crucial for both Quality of Service (QoS) guarantees and cost management in the edge/cloud computing environment. To effectively manage the lifecycle of these resources, an auto-scaling mechanism is essential. However, traditional threshold-based and recent Machine Learning (ML)-based policies are often unable to address the soaring complexity of networks due to their centralized approach. By relying on multi-agent reinforcement learning, we propose Mystique, a solution that learns from the load on links to establish the minimal set of active network resources. As traffic demands ebb and flow, our adaptive and self-driving solution can scale up and down and also react to failures in a fully automated, flexible, and efficient manner. Our results demonstrate that the presented solution can reduce network energy consumption while providing an adequate service level, outperforming other benchmark auto-scaling approaches. Alessio Sacco, Matteo Flocco, Flavio Esposito, Guido Marchetto |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2020 | A distributed reinforcement learning approach for energy and congestion-aware edge networksabstractThe abiding attempt of automation has also pervaded computer networks, with the ability to measure, analyze, and control themselves in an automated manner, by reacting to changes in the environment (e.g., demand) while exploiting existing flexibilities. When provided with these features, networks are often referred to as "self-driving". Network virtualization and machine learning are the drivers. In this regard, the provision and orchestration of physical or virtual resources are crucial for both Quality of Service guarantees and cost management in the edge/cloud computing ecosystem. Auto-scaling mechanisms are hence essential to effectively manage the lifecycle of network resources. In this poster, we propose Relevant, a distributed reinforcement learning approach to enable distributed automation for network orchestrators. Our solution aims at solving the congestion control problem within Software-Defined Network infrastructures, while being mindful of the energy consumption, helping resources to scale up and down as traffic demands fluctuate and energy optimization opportunities arise. Alessio Sacco, Flavio Esposito, Guido Marchetto |
CoNEXT | 3 |
| 2020 | Introducing programmability and automation in the synthesis of virtual firewall rulesabstractThe rise of new forms of cyber-threats is mostly due to the extensive use of virtualization paradigms and the increasing adoption of automation in the software life-cycle. To address these challenges we propose an innovative framework that leverages the intrinsic programmability of the cloud and software-defined infrastructures to improve the effectiveness and efficiency of reaction mechanisms. In this paper, we present our contributions with a demonstrative use case in the context of Kubernetes. By means of this framework, developers of cybersecurity appliances will not have any more to care about how to react to events or to struggle to define any possible security tasks at design time. In addition, automatic firewall ruleset generation provided by our framework will mostly avoid human intervention, hence decreasing the time to carry out them and the likelihood of errors. We focus our discussions on technical challenges: definition of common actions at the policy level and their translation into configurations for the heterogeneous set of security functions by means of a use case. Daniele Bringhenti, Guido Marchetto, Riccardo Sisto, Fulvio Valenza, Jalolliddin Yusupov |
NetSoft | 2 |
| 2020 | A Federated Learning Approach to Routing in Challenged SDN-Enabled Edge NetworksabstractThe edge computing paradigm allows computationally intensive tasks to be offloaded from small devices to nearby (more) powerful servers, via an edge network. The intersection between such edge computing paradigm and Machine Learning (ML), in general, and deep learning in particular, has brought to light several advantages for network operators: from automating management tasks, to gain additional insights on their networks. Most of the existing approaches that use ML to drive routing and traffic control decisions are valuable but rarely focus on challenged networks, that are characterized by continually varying network conditions and the high volume of traffic generated by edge devices. In particular, recently proposed distributed ML-based architectures require either a long synchronization phase or a training phase that is unsustainable for challenged networks. In this paper, we fill this knowledge gap with Blaster, a federated architecture for routing packets within a distributed edge network, to improve the application's performance and allow scalability of data-intensive applications. We also propose a novel path selection model that uses Long Short Term Memory (LSTM) to predict the optimal route. Finally, we present some initial results obtained by testing our approach via simulations and with a prototype deployed over the GENI testbed. By leveraging a Federated Learning (FL) model, our approach shows that we can optimize the communication between SDN controllers, preserving bandwidth for the data traffic. Alessio Sacco, Flavio Esposito, Guido Marchetto |
NetSoft | 3 |
| 2020 | Automated optimal firewall orchestration and configuration in virtualized networksabstractEmerging technologies such as Software-Defined Networking and Network Functions Virtualization are making the definition and configuration of network services more dynamic, thus making automatic approaches that can replace manual and error-prone tasks more feasible. In view of these considerations, this paper proposes a novel methodology to automatically compute the optimal allocation scheme and configuration of virtual firewalls within a user-defined network service graph subject to a corresponding set of security requirements. The presented framework adopts a formal approach based on the solution of a weighted partial MaxSMT problem, which also provides good confidence about the solution correctness. A prototype implementation of the proposed approach based on the z3 solver has been used for validation, showing the feasibility of the approach for problem instances requiring tens of virtual firewalls and similar numbers of security requirements. Daniele Bringhenti, Guido Marchetto, Riccardo Sisto, Fulvio Valenza, Jalolliddin Yusupov |
NOMS | 2 |
| 2020 | Work-in-Progress: A Formal Approach to Verify Fault Tolerance in Industrial Network SystemsabstractDistributed systems are extremely difficult to design and implement correctly because they must handle both system correctness and device failures. Most of the work focuses on the first aspect, and in particular, on the correctness of security and network configuration. The large demand for availability and reliability for critical services is actually pushing new architectures that tolerate faults, but a-priori analysis of redundancy and recovery features is still limited. To this end, we present a framework to design and formally verify the persistence of network properties, even in case of failures. The solution considers both nodes and links failure, and it is based on a formal model that takes both network topology and network device configurations into account. In contrast, most of the existing approaches only consider network topology. By analyzing the formal model, the framework can check whether the specified network services are still available after failures, and in case of success, it outputs a possible configuration of the devices to be used for automatic recovery. Alessio Sacco, Guido Marchetto, Riccardo Sisto, Fulvio Valenza |
WFCS | 2 |
| 2020 | An architecture for adaptive task planning in support of IoT-based machine learning applications for disaster scenarios
Alessio Sacco, Matteo Flocco, Flavio Esposito, Guido Marchetto |
Comput. Commun. | 4 |
| 2020 | On Edge Computing for Remote Pathology Consultations and ComputationsabstractTelepathology aims to replace the pathology operations performed on-site, but current systems are limited by their prohibitive cost, or by the adopted underlying technologies. In this work, we contribute to overcoming these limitations by bringing the recent advances of edge computing to reduce latency and increase local computation abilities to the pathology ecosystem. In particular, this paper presents LiveMicro, a system whose benefit is twofold: on one hand, it enables edge computing driven digital pathology computations, such as data-driven image processing on a live capture of the microscope. On the other hand, our system allows remote pathologists to diagnosis in collaboration in a single virtual microscope session, facilitating continuous medical education and remote consultation, crucial for under-served and remote hospital or private practice. Our results show the benefits and the principles underpinning our solution, with particular emphasis on how the pathologists interact with our application. Additionally, we developed simple yet effective diagnosis-aided algorithms to demonstrate the practicality of our approach. Alessio Sacco, Flavio Esposito, Guido Marchetto, Grant Kolar, Kate Schwetye |
IEEE J. Biomed. Health Informatics | 3 |
| 2020 | RoPE: An Architecture for Adaptive Data-Driven Routing Prediction at the EdgeabstractThe demand of low latency applications has fostered interest in edge computing, a recent paradigm in which data is processed locally, at the edge of the network. The challenge of delivering services with low-latency and high bandwidth requirements has seen the flourishing of Software-Defined Networking (SDN) solutions that utilize ad-hoc data-driven statistical learning solutions to dynamically steer edge computing resources. In this paper, we propose RoPE, an architecture that adapts the routing strategy of the underlying edge network based on future available bandwidth. The bandwidth prediction method is a policy that we adjust dynamically based on the required time-to-solution and on the available data. An SDN controller keeps track of past link loads and takes a new route if the current path is predicted to be congested. We tested RoPE on different use case applications comparing different well-known prediction policies. Our evaluation results demonstrate that our adaptive solution outperforms other ad-hoc routing solutions and edge-based applications, in turn, benefit from adaptive routing, as long as the prediction is accurate and easy to obtain. Alessio Sacco, Flavio Esposito, Guido Marchetto |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2019 | Steering Traffic via Recurrent Neural Networks in Challenged Edge ScenariosabstractWith edge computing, it is possible to offload computationally intensive tasks to closer and more powerful servers, passing through an edge network. This practice aims to reduce both response time and energy consumption of data-intensive applications, crucial constraints in mobile and IoT devices. In challenged networked scenarios, such as those deployed by first responders after a natural or human-made disaster, it is particularly challenging to achieve high levels of throughput due to scarce network conditions.In this paper, we present an algorithm for traffic management that takes advantage of a deep learning model to implement the forwarding mechanism during task offloading in these challenging scenarios. In particular, our work explores if and when it is worth using deep learning on a switch to route traffic generated by microservices and offloading requests. Our approach differs from classical ones in the design: we do not train centralized routing decisions. Instead, we let each router learn how to adapt to a lossy path without coordination, by merely using signals from standard performance-unaware protocols such as OSPF. Our results, obtained with a prototype and with simulations are encouraging, and uncover a few surprising results. Alessandro Gaballo, Matteo Flocco, Flavio Esposito, Guido Marchetto |
CNSM | 4 |
| 2019 | A Policy-Based Architecture for Container Migration in Software Defined InfrastructuresabstractSoftware-Defined Networking (SDN) is a paradigm that enables easier network programmability based on separation between network control plane and data plane. Network Function Virtualization (NFV) is another recent technology that has enabled design, deploy, and management of softwarized networking services. The vast majority of SDN and NFV based architectures, whether they use Virtual machines (VMs) or Lightweight Virtual Machines (LVMs), are designed to program forwarding, probably the most fundamental among all network mechanisms. In this paper instead we demonstrated that there are other (as important) networking mechanisms that need programmability. In particular, we designed, implemented and extensively tested an architecture that enables policy-programmability of (live) migration of LVMs. Migration is used for maintenance, load balancing, or as a security mechanism in what is called Moving Target Defence (a virtual host migrates to hide from an attacker). Our architecture is based on Docker and it is implemented within a Software-Defined Infrastructure. Migration mechanism can be set easily by means of configuration file, to make a novel policy-based architecture. We evaluated the performance of our system in several scenarios, over a local Mininet-based testbed. We analyzed the tradeoff between several Load Balancing policies as well as several Moving Target Defense solutions inspired by network coding. Flavio Esposito, Alessio Sacco, Guido Marchetto |
NetSoft | 4 |
| 2019 | Multipoint Passive Monitoring in Packet NetworksabstractTraffic monitoring is essential to manage large networks and validate Service Level Agreements. Passive monitoring is particularly valuable to promptly identify transient fault episodes and react in a timely manner. This article proposes a novel, non-invasive and flexible method to passively monitor large backbone networks. By using only packet counters, commonly available on existing hardware, we can accurately measure packet losses, in different segments of the network, affecting only specific flows. We can monitor not only end-to-end flows, but any generic flow with packets following several different paths in the network (multipoint flows). We also sketch a possible extension of the method to measure average one-way delay for multipoint flows, provided that the measurement points are synchronized. Through various experiments we show that the method is effective and enables easy zooming in on the cause of packet losses. Moreover, the method can scale to very large networks with a very low overhead on the data plane and the management plane. Mauro Cociglio, Giuseppe Fioccola, Guido Marchetto, Amedeo Sapio, Riccardo Sisto |
IEEE/ACM Trans. Netw. | 3 |
| 2018 | HPC4AI: an AI-on-demand federated platform endeavourabstractIn April 2018, under the auspices of the POR-FESR 2014-2020 program of Italian Piedmont Region, the Turin's Centre on High-Performance Computing for Artificial Intelligence (HPC4AI) was funded with a capital investment of 4.5M€ and it began its deployment. HPC4AI aims to facilitate scientific research and engineering in the areas of Artificial Intelligence and Big Data Analytics. HPC4AI will specifically focus on methods for the on-demand provisioning of AI and BDA Cloud services to the regional and national industrial community, which includes the large regional ecosystem of Small-Medium Enterprises (SMEs) active in many different sectors such as automotive, aerospace, mechatronics, manufacturing, health and agrifood. Marco Aldinucci, Sergio Rabellino, Marco Pironti, Filippo Spiga, Paolo Viviani 0001, Maurizio Drocco, Marco Guerzoni, Guido Boella, Marco Mellia, Paolo Margara, Idilio Drago, Roberto Marturano, Guido Marchetto, Elio Piccolo, Stefano Bagnasco, Stefano Lusso, Sara Vallero, Giuseppe Attardi, Alex Barchiesi, Alberto Colla, Fulvio Galeazzi |
CF | 13 |
| 2018 | Virtual Network Embedding with Formal Reachability Assurance
Guido Marchetto, Riccardo Sisto, Jalolliddin Yusupov, Adlen Ksentini |
CNSM | 1 |
| 2018 | An efficient data exchange mechanism for chained network functions
Ivano Cerrato, Guido Marchetto, Fulvio Risso, Riccardo Sisto, Matteo Virgilio, Roberto Bonafiglia |
J. Parallel Distributed Comput. | 2 |
| 2017 | A Framework for User-Friendly Verification-Oriented VNF ModelingabstractNetwork Function Virtualization (NFV) architectures are emerging to increase networks flexibility. However, this renewed scenario poses new challenges, because virtualized networks, need to be carefully verified before being actually deployed in production environments in order to preserve network coherency (e.g., absence of forwarding loops, preservation of security on network traffic, etc.). Nowadays, model checking tools, SAT solvers, and Theorem Provers are available for formal verification of such properties in virtualized networks. Unfortunately, most of those verification tools accept input descriptions written in specification languages that are difficult to use for people not experienced in formal methods. Also, in order to enable the use of formal verification tools in real scenarios, vendors of Virtual Network Functions (VNFs) should provide abstract mathematical models of their functions, coded in the specific input languages of the verification tools. This process is error-prone, time-consuming, and often outside the VNF developers' expertise. This paper presents a framework that we designed for automatically extracting verification models starting from a Java based representation of a given VNF. It comprises a Java library of classes to define VNFs in a more developer-friendly way, and a tool to translate VNF definitions into formal verification models of different verification tools. Guido Marchetto, Riccardo Sisto, Matteo Virgilio, Jalolliddin Yusupov |
COMPSAC (1) | 1 |
| 2016 | Exploiting the transmission layer in logical topology design of flexible-grid optical networksabstractFlexible-grid optical networks are the most convincing candidate for the evolution of backbone optical networks thanks to their high spectral efficiency and flexibility. We propose an original approach to the logical topology design (LTD) problem in the offline planning phase. We deal with the LTD problem using heuristic algorithms incorporating a detailed transmission layer model. Several heuristic algorithms, allocating traffic demands in different orderings, are considered for lightpath provisioning. Traffic ordering schemes are mainly based on two parameters: traffic demands capacity and lightpath physical route length. Through simulative analyses, we provide a performance comparison of different heuristics, using parameters like spectral efficiency, amount of blocked traffic and total number of transceivers. We also show the importance of integrating a detailed physical layer modeling in the network design phase. Arsalan Ahmad, Andrea Bianco, Hussein Chouman, Guido Marchetto, Sarosh Tahir, Vittorio Curri |
ICC | 4 |
| 2015 | Formal verification of LTE-UMTS handover proceduresabstractLong Term Evolution (LTE) is the most recent standard in mobile communications, introduced by 3rd Generation Partnership Project (3GPP). Most of the formal security analysis works in literature about LTE analyze authentication procedures, while interoperability is far less considered. This paper presents a formal security analysis of the interoperability procedures between LTE and the older Universal Mobile Telecommunications System (UMTS) networks, when mobile devices seamlessly switch between the two technologies. The ProVerif tool has been used to conduct the verification. The analysis shows that security properties (secrecy of keys, including backward/forward secrecy, immunity from off-line guessing attacks and network components authentication) hold almost as expected, if all the protections allowed by the LTE standard are adopted. If backhauling traffic is not protected with IPSec, which is a common scenario since the use of IPSec is not mandatory, some security properties still hold while others are compromised. Consequently, user's traffic and network's nodes are exposed to attacks in this scenario. Piergiuseppe Bettassa Copet, Guido Marchetto, Riccardo Sisto, Luciana Costa |
ISCC | 2 |
| 2015 | Introducing network-aware scheduling capabilities in OpenStackabstractThis paper motivates and describes the introduction of network-aware scheduling capabilities in OpenStack, the open-source reference framework for creating public and private clouds. This feature represents the key for properly supporting the Network Function Virtualization paradigm, particularly when the physical infrastructure features servers distributed across a geographical region. This paper also describes the modifications required to the compute and network components, Nova and Neutron, and the integration of a network controller into the cloud infrastructure, which is in charge of feeding the network-aware scheduler with the actual network topology. Francesco Lucrezia, Guido Marchetto, Fulvio Risso, Vinicio Vercellone |
NetSoft | 2 |
| 2014 | An efficient data exchange algorithm for chained network functionsabstractIn-network function chaining often involves the deployment of multiple applications into a single, possibly multi-tenant, middlebox. This approach has gained much interest since new network paradigms, such as Software Defined Networking (SDN) and Network Function Virtualization (NFV), have been proposed to virtualize resources as well as network functions. In this scenario, it is very common to move data (e.g., packets) from an application to another by means of a switching module that is in charge of chaining network functions in the correct order, also ensuring an adequate level of isolation between any two virtualized components. With this purpose in mind, this paper proposes an efficient algorithm to handle the communication between the internal soft-switch and the heterogeneous network functions that are executed on the same server. Our proposal is designed with the aim of dealing with high speed packet processing, hence an extensive performance evaluation is also provided to prove the goodness of our solution in this context. Ivano Cerrato, Guido Marchetto, Fulvio Risso, Riccardo Sisto, Matteo Virgilio |
HPSR | 2 |
| 2013 | Time-Driven Priority Router Implementation: Analysis and ExperimentsabstractLow complexity solutions to provide deterministic quality over packet switched networks while achieving high resource utilization have been an open research issue for many years. Service differentiation combined with resource overprovisioning has been considered an acceptable compromise and widely deployed given that the amount of traffic requiring quality guarantees has been limited. This approach is not viable, though, as new bandwidth hungry applications, such as video on demand, telepresence, and virtual reality, populate networks invalidating the rationale that made it acceptable so far. Time-driven priority represents a potentially interesting solution. However, the fact that the network operation is based on a time reference shared by all nodes raises concerns on the complexity of the nodes, from the point of view of both their hardware and software architecture. This work analyzes the implications that the timing requirements of time-driven priority have on network nodes and shows how proper operation can be ensured even when system components introduce timing uncertainties. Experimental results on a time-driven priority router implementation based on a personal computer both validate the analysis and demonstrate the feasibility of the technology even on an architecture that is not designed for operating under timing constraints. Mario Baldi, Guido Marchetto |
IEEE Trans. Computers | 2 |
| 2012 | Measuring and reducing the impact of the operating system kernel on end-to-end latencies in synchronous packet switched networksabstractSUMMARY This paper presents an evaluation of the impact of the so‐called operating system (OS) latencies on the performance of a synchronous network based on global time coordination. The concept of end‐to‐end latency was first defined by extending the concept of latency used to evaluate the performance of real‐time systems and the end‐to‐end latency provided by a general‐purpose OS was measured as a benchmark. Finally, real‐time techniques were used to reduce the worst‐case values of such a latency, showing how a gateway between synchronous and asynchronous networks can be implemented by using commercial‐off‐the‐shelf hardware and a proper software stack (based on a real‐time version of Linux). The use of a real‐time OS is still a nontrivial task, which requires experience and the analysis of the specific application to devise the proper techniques to be applied. This work dissects the problem of OS‐to‐network data transfer (and vice versa) identifying the key sources of latencies and delay jitter, and solving each problem with the application of a proper technique. Copyright © 2011 John Wiley & Sons, Ltd. Michele Welponer, Luca Abeni, Guido Marchetto, Renato Lo Cigno |
Softw. Pract. Exp. | 3 |
| 2012 | CLOSER: A Collaborative Locality-Aware Overlay SERviceabstractCurrent Peer-to-Peer (P2P) file sharing systems make use of a considerable percentage of Internet Service Providers (ISPs) bandwidth. This paper presents the Collaborative Locality-aware Overlay SERvice (CLOSER), an architecture that aims at lessening the usage of expensive international links by exploiting traffic locality (i.e., a resource is downloaded from the inside of the ISP whenever possible). The paper proves the effectiveness of CLOSER by analysis and simulation, also comparing this architecture with existing solutions for traffic locality in P2P systems. While savings on international links can be attractive for ISPs, it is necessary to offer some features that can be of interest for users to favor a wide adoption of the application. For this reason, CLOSER also introduces a privacy module that may arouse the users' interest and encourage them to switch to the new architecture. Marco Papa Manzillo, Luigi Ciminiera, Guido Marchetto, Fulvio Risso |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2011 | Robustness analysis of an unstructured overlay for media communicationabstractThe wide diffusion of network address translators (NATs) (and, in some respect, firewalls) may prevent some applications that require direct end-to-end connectivity (e.g. real-time media) from being able to connect to the remote party. Although the solutions currently adopted rely on centralised nodes as third party relays, the distributed connectivity service (DISCOS) architecture has been recently proposed and aims at distributing such functionalities across a peer-to-peer (P2P) overlay. The original study presented some performance characteristics of the overlay, but the ability to resist to both failures and attacks was not taken into consideration. This study illustrates the robustness feature of the DISCOS overlay and suggests some minor modifications to the original mechanisms, in order to improve the overall robustness. The key component of DISCOS is its dynamic scale-free topology. Hence, the study also extends the existing literature concerning the robustness of scale-free networks, which considers only static graphs. Guido Marchetto, Marco Papa Manzillo, Livio Torrero, Luigi Ciminiera, Fulvio Risso |
IET Commun. | 1 |
| 2011 | Locating Equivalent Servants over P2P NetworksabstractWhile peer-to-peer networks are mainly used to locate unique resources across the Internet, new interesting deployment scenarios are emerging. Particularly, some applications (e.g., VoIP) are proposing the creation of overlays for the localization of services based on equivalent servants (e.g., voice relays). This paper explores the possible overlay architectures that can be adopted to provide such services, showing how an unstructured solution based on a scale-free overlay topology is an effective option to deploy in this context. Consequently, we propose EQUATOR (EQUivalent servAnt locaTOR), an unstructured overlay implementing the above mentioned operating principles, based on an overlay construction algorithm that well approximates an ideal scale-free construction model. We present both analytical and simulation results which support our overlay topology selection and validate the proposed architecture. Guido Marchetto, Luigi Ciminiera, Marco Papa Manzillo, Fulvio Risso, Livio Torrero |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2009 | Time driven Access and Forwarding for industrial wireless multi-hop networksabstractThe deployment of wireless technologies in industrial networks is very promising mainly due to their inherent flexibility. However, current wireless solutions lack the capability to provide the deterministic, low delay service required by many industrial applications. Moreover, the high level of interference generated by industrial equipment limits the coverage that ensures acceptable performance. Multihop solutions, when combining frame forwarding with higher node density, have the potential to provide the needed coverage while keeping radio communication range short. However, in multihop solutions, the medium access time at each of the nodes traversed additively contributes to the end-to-end delay and the forwarding delay (i.e., the time required for packets to be processed, switched, and queued) at each node is to be added as well. This paper describes time-driven access and forwarding, a solution for guaranteeing deterministic delay, at both the access and forwarding level, in wireless multihop networks, analyzes its properties, and assesses its performance in industrial scenarios. Guido Marchetto, Mario Baldi, Riccardo Giacomelli |
IEEE Trans. Ind. Informatics | 1 |
| 2009 | Pipeline forwarding of packets based on a low-accuracy network-distributed common time reference
Mario Baldi, Guido Marchetto |
IEEE/ACM Trans. Netw. | 2 |
| 2008 | Minimizing Preemption Probabilityto Efficiently Support Service Differentiation in Just-in-Time Based OBS NetworksabstractPreemptive contention resolution schemes are very effective solutions for providing service differentiation in optical burst switching networks. However, they cannot be applied together with the just-in-time signaling protocol because of the great loss in efficiency in terms of wavelength utilization and maximum achieved throughput that results when the number of preemptions becomes too large. This paper presents a preemption based service differentiation solution that is suitable for the just-in-time optical burst switching paradigm thanks to the fact that it can minimize the preemption probability (i.e., the probability of observing a preemption when a contention occurs). The proposed technique combines a conventional preemption scheme at core nodes and an improvement of the recently proposed burst cluster transmission scheme at edge nodes. In particular, bursts are created at their ingress node and combined into chains, arranging them in order of decreasing priority. Some traffic scenarios are analyzed by simulation to evaluate the performance of the proposed method. Guido Marchetto |
ICC | 1 |
| 2007 | Scalable Switching Testbed not "Stopping" the Serial Bit StreamabstractIn order to achieve ultra scalable IP packet switching it is essential to minimize "stopping" of the serial bit streams. In our recent experimental work we demonstrated how this can be achieved with an ultra-scalable switching architecture reaching multi-terabits per second (10-100 Tb/s) in a single chassis. The implemented testbed uses only off-the-shelf optical and electronic components. The scalability of this architecture is the direct outcome of how global time (i.e., UTC - coordinated universal time) and pipeline forwarding are utilized. The paper presents the design of a prototype switch and experimental activity with it. Mario Baldi, Michele Corrà, Giorgio Fontana, Guido Marchetto, Viet Thang Nguyen, Yoram Ofek, Danilo Severina, Thu-Huong Truong, Olga Zadedyurina |
ICC | 5 |
| 2007 | A Scalable Approach for Supporting Streaming Media: Design, Implementation and ExperimentsabstractFuture Internet traffic will be dominated by on-demand streaming media flows, such as IPTV, 3D/HD video, gaming, virtual reality, and many more. Consequently, future network architectures will need to implementscalable IP packet switchingcapable of offeringpredictable performancesto such applications. Our recent experimental work demonstrated how an IP network can be implemented without "stopping" the serial bit streams. The deployed switch is very simple, scalable to 10-100 terabits per second in a single chassis, and suitable for all optical implementation. The implemented testbed uses only off-the-shelf optical and electronic components and was completed in 9-month. Mario Baldi, Michele Corrà, Giorgio Fontana, Guido Marchetto, Viet Thang Nguyen, Yoram Ofek, Danilo Severina, Thu-Huong Truong, Olga Zadedyurina |
ISCC | 5 |
| 2007 | A scalable solution for engineering streaming traffic in the future Internet
Mario Baldi, Guido Marchetto, Yoram Ofek |
Comput. Networks | 2 |
| 2006 | Time Driven Priority Router Implementation and First ExperimentsabstractThis paper reports on the implementation of Time-Driven Priority (TDP) scheduling on a FreeBSD platform. This work is part of a TDP prototyping and demonstration project aimed at showing the implications of TDP deployment in packet-switched networks, especially benefits for real-time applications. This paper focuses on practical aspects related to the implementation of the technology on a Personal Computer (PC)-based router and presents the experimental results obtained on a testbed network. The basic building blocks of a TDP router are described and implementation choices are discussed. The relevant results achieved and here presented can be categorized into two types: qualitative results, including the successful integration of all needed blocks and the insight obtained on the complexity related to the implementation of a TDP router, and quantitative ones, including measures of achievable network utilization and of jitter experienced on a fully-loaded TDP network. The outcome demonstrates the effectiveness of the presented implementation while confirming TDP points of strength. Mario Baldi, Guido Marchetto, Fulvio Risso, Giulio Galante, Riccardo Scopigno, Federico Stirano |
ICC | 2 |