Marco Tambasco

dblp:198/1948 · DBLP profile ↗
← Back
11ranked-venue papers
0as first author
5since 2021 · last 2022
0000-0003-0213-7062ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021Software engineering, systems software and programming languages · 2Human-computer interaction and ubiquitous computing · 2Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2022 Performability Analysis of Containerized IMS through Queueing Networks and Stochastic Models
abstract
As a case study of a novel approach to characterize service chains in terms of performance and availability, we consider a containerized IP Multimedia Subsystem (cIMS) infrastructure. The performance analysis is carried out by exploiting the queueing network decomposition method useful to model each cIMS node as a realistic M/G/c system, jointly with the solution of a convex optimization problem for containers allocation. Such a solution is used to feed the availability analysis (faced through the Stochastic Reward Network technique) amenable to derive a set of configurations guaranteeing a given availability target at minimum cost. The whole analysis is supported by a testbed based on the Clearwater platform used to derive some experimental parameters values.
Mario Di Mauro, Giovanni Galatro, Maurizio Longo, Fabio Postiglione, Marco Tambasco
NOMS5
2022 Performability of Network Service Chains: Stochastic Modeling and Assessment of Softwarized IP Multimedia Subsystem
abstract
Service provisioning mechanisms implemented across 5G infrastructures take broadly into use the network service chain concept. Typically, it is coupled with Network Function Virtualization (NFV) paradigm, and consists in defining a pre-determined path traversed by a set of softwarized network nodes to provide specific services. A well known chain-like framework is the IP Multimedia Subsystem (IMS), a key infrastructure of 5G networks, that we characterize both by a performance and an availability perspective. Precisely, supported by a designed from scratch testbed realized throughClearwaterplatform, we perform a stochastic assessment of a softwarized IMS (softIMS) architecture where two main stages stand out: i) a performance analysis, where, exploiting the queueing network decomposition method, we formalize an optimization problem of resource allocation by modeling each softIMS node as an$M/G/c$system; ii) an availability assessment, where, adopting the Stochastic Reward Net methodology, we are able to characterize the behavior of softIMS in terms of failure/repair events, and to derive a set of optimal configurations satisfying a given availability requirement (e.g., five nines) while minimizing deployment costs. Two routines dubbedOptCNTandOptSearchChainhave been devised to govern the performance and availability analyses, respectively.
Mario Di Mauro, Giovanni Galatro, Fabio Postiglione, Marco Tambasco
IEEE Trans. Dependable Secur. Comput.4
2021 Application-Layer DDOS Attacks with Multiple Emulation Dictionaries
abstract
We consider the problem of identifying the members of a botnet under an application-layer (L7) DDoS attack, where a target site is flooded with a large number of requests that emulate legitimate users’ patterns. This challenging problem has been recently addressed with reference to two simplified scenarios, where either all bots pick requests from the same emulation dictionary (total overlap), or they are divided in separate clusters corresponding to distinct emulation dictionaries (no overlap at all). However, over real networks these two extreme conditions are difficult to realize, and the intermediate situation is observed where the emulation patterns of distinct bots belong to partially overlapped dictionaries. This intermediate situation introduces significant sophistication in the bot identification problem. In order to address this issue, we provide an analytical characterization of the pairwise cluster interaction, which is exploited to devise an identification rule to discriminate legitimate users from bots and to identify the individual bot clusters.
Michele Cirillo, Mario Di Mauro, Vincenzo Matta, Marco Tambasco
ICASSP4
2021 Botnet Identification in DDoS Attacks With Multiple Emulation Dictionaries
abstract
In a Distributed Denial of Service (DDoS) attack, a network (botnet) of dispersed agents (bots) sends requests to a website to saturate its resources. Since the requests are sent by automata, the typical way to detect them is to look for some repetition pattern or commonalities between requests of the same user or from different users. For this reason, recent DDoS variants exploit communication layers that offer broader possibility in terms of admissible request patterns, such as, e.g., the application layer. In this case, the malicious agents can pick legitimate messages from an emulation dictionary, and each individual agent sends a relatively low number of admissible requests, so as to make its activity non suspicious. This problem has been recently addressed under the assumption that all the members of the botnet use the same emulation dictionary. This situation is an idealization of what occurs in practice, since different clusters of agents are typically sharing only part of a global emulation dictionary. The diversity among the emulation dictionaries across different clusters introduces significant complexity in the botnet identification challenge. This work tackles this issue and provides the following main contributions. We obtain an analytical characterization of the message innovation rate of the DDoS attack with multiple emulation dictionaries. Exploiting this result, we design a botnet identification algorithm equipped with a cluster expurgation rule, which, under appropriate technical conditions, is shown to provide exact classification of bots and normal users as the observation window size increases. Then, an experimental campaign over real network traces is conducted to assess the validity of the theoretical analysis, as well as to examine the effect of a number of non-ideal effects that are unavoidably observed in practical scenarios.
Michele Cirillo, Mario Di Mauro, Vincenzo Matta, Marco Tambasco
IEEE Trans. Inf. Forensics Secur.4
2021 Comparative Performability Assessment of SFCs: The Case of Containerized IP Multimedia Subsystem
abstract
The failure of a single network element composing a Service Function Chain (SFC) unavoidably leads to some degradation in terms of availability (ability of guaranteeing working conditions), and/or performance (ability of sustaining a certain workload) for the whole SFC. By considering both of these aspects, we propose, as a case study, a joint analysis of availability and performance (a.k.a. performability) of IP Multimedia Subsystem, an SFC infrastructure which plays a key role in the all-IP convergence of telecommunication services, especially as per prospects of 5G . We refer to an implementation of IMS based on container technology (containerized IMS, or cIMS) which allows to decouple the application layer from the underlying hardware infrastructure more efficiently than classic virtualization schemes. We model the probabilistic behavior of a cIMS by means of Stochastic Reward Networks (SRN) and Reliability Block Diagram (RBD) formalisms to take into account failure and repair events. Then, with the assistance of a designed-from-scratch algorithm (OptChains+), we carry on a performability analysis: i) to evaluate and compare series/parallel cIMS configurations (or settings), and ii) to find settings with minimum cost and maximum availability, given a performance level. The proposed assessment lends itself to a sensitivity analysis, here demonstrated by examples, useful for robustness evaluation.
Mario Di Mauro, Giovanni Galatro, Maurizio Longo, Fabio Postiglione, Marco Tambasco
IEEE Trans. Netw. Serv. Manag.5
2020 Automated Generation of Availability Models for SFCs: The case of Virtualized IP Multimedia Subsystem
abstract
The reputation of network providers strongly depends on their ability to guarantee high performance levels of virtualized infrastructures, and to maintain strict Quality-of-Service (QoS) requirements, thus, the concept of "five nines" or high availability (HA) is critical. It means that, on average, the continuity of a provided service cannot be violated for more than about five minutes per year. In this direction, we propose a framework useful to design and model, from a HA perspective, the Service Function Chains (SFCs) whose chained software logic is embodied in many softwarized telco infrastructures (e.g. IP Multimedia Subsystem elected here as a representative use case). The proposed framework interacts with TimeNET tool, and offers interesting functionalities such as: i) generating stochastic models of SFCs based on the SRN (Stochastic Reward Nets) formalism; ii) deploying network scenarios via drag-and-drop operations for basic users, or modifying the underlying SRN models for advanced users; iii) setting a variety of parameters (mean-time-to-failure/repair, software/hardware specs, redundancy, etc.); iv) presenting availability results in tabular and/or graphical forms.
Mario Di Mauro, Giovanni Galatro, Maurizio Longo, Arcangelo Palma, Fabio Postiglione, Marco Tambasco
NOMS6
2020 Performability Management of Softwarized IP Multimedia Subsystem
abstract
IP Multimedia Subsystem (IMS) represents a crucial element for the convergence of telecommunication systems heading towards 5G solutions. Actually, IMS offers a standardized and vendor independent model allowing network providers to supply multimedia services such as video streaming or HD voice, with pressing QoS requirements. The IMS architecture can dramatically improve its flexibility when deployed within softwarized environments, in conjunction with virtual or container-based technologies. This latter, in particular, realizes an abstraction of software resources from the underlying hardware in a more efficient and resource saving manner than virtual machines. Inspired by this model, we propose a tool for the performability management of IMS architectures deployed in a containerized environment (dubbed cIMS). First, we model the stochastic behavior of a cIMS by means of two complementary formalisms: i) Reliability Block Diagram (RBD) amenable to model high level interconnections among cIMS nodes, and ii) Stochastic Reward Networks (SRN) useful to capture deeper details of a single node in terms of failure and repair events. Then, we develop an automated procedure aimed at supporting the performability management of cIMS deployments that must satisfy the optimal trade-off among high availability requirements, capacity load, and deployment costs.
Mario Di Mauro, Giovanni Galatro, Maurizio Longo, Fabio Postiglione, Marco Tambasco
NOMS5
2019 IP Multimedia Subsystem in a containerized environment: availability and sensitivity evaluation
abstract
Nowadays, telecom providers may benefit from the flexibility offered by Network Function Virtualization (NFV) paradigm that allows to decouple the service logic from the underlying hardware infrastructure. Thus, main functionalities of network nodes (e.g. routers, firewalls, load balancers etc.) can be deployed on a virtual machine (VM) with its own resources. On the other hand, deploying a whole VM (which hosts a single virtualized network service) can be expensive, since too many resources are uselessly wasted. A valuable alternative is offered by containers, namely, virtualized and lightweight processes that, differently from classical VMs, do not carry a whole operating system. In this work we consider a container-based version of IP Multimedia Subsystem (IMS) infrastructure, a crucial player within next generation telecommunication networks, a.k.a. 5G. More precisely, we offer an availability evaluation of a containerized IMS (cIMS) deployment through i) Reliability Block Diagram (RBD) formalism useful to model high-level interconnections among cIMS nodes, and ii) Stochastic Reward Networks (SRN) methodology which allows to analyze the evolution of the cIMS life cycle in presence of failure and repair events. Moreover, we perform a sensitivity analysis aimed at evaluating the whole cIMS robustness with respect to deviations of some critical parameters.
Mario Di Mauro, Giovanni Galatro, Maurizio Longo, Fabio Postiglione, Marco Tambasco
NetSoft5
2017 Object Storage in Cloud Computing Environments: An Availability Analysis
Giuliana Carullo, Mario Di Mauro, Michele Galderisi, Maurizio Longo, Fabio Postiglione, Marco Tambasco
GPC6
2017 A Unifying Orchestration Operating Platform for 5G
Antonio Manzalini, Marco Di Girolamo, Giuseppe Celozzi, Fulvio Bruno, Giuliana Carullo, Marco Tambasco, Gino Carrozzo, Fulvio Risso, Gabriele Castellano
GPC6
2017 A unifying operating platform for 5G end-to-end and multi-layer orchestration
abstract
Heterogeneity of current software solutions for 5G is heading for complex and costly situations, with high fragmentation, which in turn creates uncertainty and the risk of delaying 5G innovations. This context motivated the definition of a novel Operating Platform for 5G (5G-OP), a unifying reference functional framework supporting end-to-end and multi-layer orchestration. 5G-OP aims at integrated management, control and orchestration of computing, storage, memory, networking core and edge resources up to the end-user devices and terminals (e.g., robots and smart vehicles). 5G-OP is an overarching architecture, with agnostic interfaces and well-defined abstractions, offering the seamless integration of current and future infrastructure control and orchestration solutions (e.g., OpenDaylight, ONOS, OpenStack, Apache Mesos, OpenSource MANO, Docker, LXC, etc.) The paper provides also the description of a prototype that can be seen as a simplified version of a 5G-OP, whose feasibility has been demonstrated in Focus Group IMT2020 of ITU-T.
Antonio Manzalini, Diego R. López, Håkon Lønsethagen, Lucian Suciu, Roberto Bifulco, Marie-Paule Odini, Giuseppe Celozzi, Barbara Martini, Fulvio Risso, Jokin Garay, Vassilis Foteinos, Panagiotis Demestichas, Giuliana Carullo, Marco Tambasco, Gino Carrozzo
NetSoft14