VLDB 2026 Research / reviewers in the wild / expert
Fernando M. V. Ramos
dblp:21/8398 · also Fernando Manuel Valente Ramos
· DBLP profile ↗
22ranked-venue papers
2as first author
7since 2021 · last 2025
0000-0003-3585-8587ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 13 · 5 since 2021Security and privacy · 3 · 1 since 2021Systems, architecture and hardware · 2Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Poster: SALAD-Nets: Synthesizing Adaptive, Accelerated, and Distributed Network FunctionsabstractNetwork service providers rely on network functions (NFs) for security, performance optimization, and traffic management. User traffic typically traverses a chain of these functions to satisfy both user-level and infrastructure requirements. Traditionally, NFs have been implemented either in flexible software or in high-performance fixed-function hardware, leading to a tradeoff between agility and efficiency. The advent of programmable networking hardware offers a new balance between flexibility and performance, enabling the deployment of NFs directly on commodity devices such as programmable switches, SmartNICs, and DPUs. However, programming these devices remains challenging due to limited compute and memory resources and the diversity of their architectures and abstractions.We introduce SALAD-Nets, a framework that automatically maps virtual NF chains onto heterogeneous programmable infrastructures. Given a high-level specification of a virtual network of NFs, SALAD-Nets generates both the deployment plan and the acceleration code for each target device, respecting infrastructure constraints and user objectives. The poster presents the architecture and workflow of SALAD-Nets, showing how it addresses the dual challenges of automatic NF code generation and distributed deployment across diverse programmable hardware. Rui Miguel, Luis Pedrosa, Fernando M. V. Ramos |
NCA | 3 |
| 2024 | Internet Architecture Evolution: Found in TranslationabstractThe success of the Internet is undeniable, but so are its limitations. Over the past two decades, the research community has responded with clean-slate redesigns, proposing innovative architectures focused on issues like security and information dissemination, among others. Unfortunately, these efforts have had limited impact on the commercial Internet, if any. The reason is that the Internet architecture is deeply entrenched, making a complete replacement elusive. Luis Pedrosa, Salvatore Signorello, Fernando M. V. Ramos |
HotNets | 4 |
| 2024 | P4chaskey: an Efficient Mac Algorithm for Pisa SwitchesabstractCryptographic primitives are of paramount importance to guarantee security properties in communication networks. The associated computational complexity of cryptography standards makes it prohibitive to execute these primitives at line rate in the network core. Existing implementations of cryptographic MAC algorithms in$\mathbf{P 4}$for programmable switches impose a severe performance penalty due to packet recirculation, which may not be tolerable at those network speeds. In this paper, we propose the first data plane design in$\mathbf{P 4}$of the Chaskey algorithm, a widely used secure and lightweight cryptographic MAC algorithm, tailored for the PISA switch architecture. Our P4Chaskey is the first solution to compute MACs using 128-bit keys without packet recirculation, guaranteeing line rate Terabit speeds. As state-of-the-art solutions require recirculations for the same key size (reducing throughput performance) or offer weaker security (smaller keys), P4CHASKEY is now, to our knowledge, the most efficient MAC design for the target switch architecture. Martim Francisco, Bernardo Ferreira, Fernando M. V. Ramos, Eduard Marin, Salvatore Signorello |
ICNP | 3 |
| 2024 | Automatic Parallelization of Software Network Functions
Francisco Chamiça Pereira, Fernando M. V. Ramos, Luis Pedrosa |
NSDI | 2 |
| 2023 | Poster: In-Network ML Feature Computation for Malicious Traffic DetectionabstractWe present Peregrine, a malicious traffic detector that offloads part of its computation to a programmable switch. The idea is to partition detection, by moving the ML feature computation module from a middlebox server to a switch data plane. The key innovation unlocked---computing the ML input features over all traffic---results in a significant improvement in detection performance: in our evaluation, up to 5.7x over the state of the art. João Romeiras Amado, Francisco Chamiça Pereira, Salvatore Signorello, Miguel Correia 0001, Fernando M. V. Ramos |
SIGCOMM | 5 |
| 2021 | Generic change detection (almost entirely) in the dataplaneabstractIdentifying traffic changes accurately sits at the core of many network tasks, from congestion analysis to intrusion detection. Modern systems leverage sketch-based structures that achieve favourable memory-accuracy tradeoffs by maintaining compact summaries of traffic data. Mainly used to detect heavy-hitters (usually the major source of network congestion), some can be adapted to detect traffic changes, but they fail on generality. As their core data structures track elephant flows, they miss to identify mice traffic that may be the main cause of change (e.g., microbursts or low-volume attacks). Gonçalo Matos, Salvatore Signorello, Fernando M. V. Ramos |
ANCS | 3 |
| 2021 | FlowLens: Enabling Efficient Flow Classification for ML-based Network Security Applications
Diogo Barradas, Nuno Santos 0001, Luís E. T. Rodrigues, Salvatore Signorello, Fernando M. V. Ramos, André Madeira |
NDSS | 5 |
| 2020 | Poster: Speeding Up Network Intrusion DetectionabstractModern network data planes have enabled new measurement approaches, including efficient sketch-based techniques with provable trade-offs between memory and accuracy, directly in the data plane, at line rate. We thus ask the question: can one leverage this richer measurement plane to improve network intrusion detection? Our answer is SPID, a push-based, feature-rich network monitoring approach to assist learning-based attack detection. SPID switches run a diverse set of measurement primitives and proactively push measurements to the monitoring system when relevant changes occur. Network measurements are then fed as input features to a classifier based on unsupervised learning to detect ongoing attacks, as they occur. In consequence, SPID aims to reduce attack detection time, when comparing to existing solutions present in large scale networks. João Romeiras Amado, Salvatore Signorello, Miguel Correia 0001, Fernando M. V. Ramos |
ICNP | 4 |
| 2020 | Elastic Network VirtualizationabstractNetwork virtualization allows multiple tenant networks to coexist on a shared infrastructure. Core to its realization is the embedding of virtual networks onto the underlying substrate. Existing approaches are not suitable for cloud environments as they lack a fundamental requirement: elasticity. To address this issue we explore the capacity of flexibly changing the topology of a virtual network by proposing an embedding solution that adds elasticity to the tenant's virtual infrastructures. For this purpose, we introduce four primitives to tenants' virtual networks - including scale in and scale out - and propose new algorithms to materialize them. The main challenge is to enable these new services while maximizing resource efficiency and without impacting service quality. Instead of further improving existing online embedding algorithms - always limited by the inability to predict future demand - we follow a different approach. Specifically, we leverage network migration for our embedding procedures and to introduce a new reconfiguration primitive for the infrastructure provider. As migration introduces network churn, our solution uses this technique judiciously, to limit the impact to running services. Our solution improves on network efficiency over the state-of-the-art, while reducing the migration footprint by at least one order of magnitude. Max Alaluna, Nuno Neves 0001, Fernando M. V. Ramos |
INFOCOM | 3 |
| 2020 | Secure multi-cloud virtual network embedding
Max Alaluna, Luís Ferrolho, José Rui Figueira, Nuno Neves 0001, Fernando M. V. Ramos |
Comput. Commun. | 5 |
| 2019 | Random Linear Network Coding on Programmable SwitchesabstractBy extending the traditional store-and-forward mechanism, network coding has the capability to improve a network's throughput, robustness, and security. Given the fundamentally different packet processing required by this new paradigm and the inflexibility of hardware, existing solutions are based on software. As a result, they have limited performance and scalability, creating a barrier to its wide-spread adoption. By leveraging the recent advances in programmable networking hardware, in this paper we propose a random linear network coding data plane written in P4, as a first step towards a production-level platform. Our solution includes the ability to combine the payload of multiple packets and of executing the required Galois field operations, and shows promise to be practical even under the strict memory and processing constraints of switching hardware. Diogo Gonçalves 0002, Salvatore Signorello, Fernando M. V. Ramos, Muriel Médard |
ANCS | 3 |
| 2019 | Secure Multi-Cloud Network Virtualization
Max Alaluna, Eric Vial, Nuno Neves 0001, Fernando M. V. Ramos |
Comput. Networks | 4 |
| 2019 | ANCHOR: Logically Centralized Security for Software-Defined NetworksabstractSoftware-defined networking (SDN) decouples the control and data planes of traditional networks, logically centralizing the functional properties of the network in the SDN controller. While this centralization brought advantages such as a faster pace of innovation, it also disrupted some of the natural defenses of traditional architectures against different threats. The literature on SDN has mostly been concerned with the functional side, despite some specific works concerning non-functional properties such as security or dependability. Though addressing the latter in an ad-hoc, piecemeal way may work, it will most likely lead to efficiency and effectiveness problems. We claim that the enforcement of non-functional properties as a pillar of SDN robustness calls for a systemic approach. We further advocate, for its materialization, the reiteration of the successful formula behind SDN: ‘logical centralization’. As a general concept, we propose anchor , a subsystem architecture that promotes the logical centralization of non-functional properties. To show the effectiveness of the concept, we focus on security in this article: we identify the current security gaps in SDNs and we populate the architecture middleware with the appropriate security mechanisms in a global and consistent manner. Essential security mechanisms provided by anchor include reliable entropy and resilient pseudo-random generators, and protocols for secure registration and association of SDN devices. We claim and justify in the article that centralizing such mechanisms is key for their effectiveness by allowing us to define and enforce global policies for those properties; reduce the complexity of controllers and forwarding devices; ensure higher levels of robustness for critical services; foster interoperability of the non-functional property enforcement mechanisms; and promote the security and resilience of the architecture itself. We discuss design and implementation aspects, and we prove and evaluate our algorithms and mechanisms, including the formalisation of the main protocols and the verification of their core security properties using the T amarin prover. Diego Kreutz, Jiangshan Yu, Fernando M. V. Ramos, Paulo Veríssimo |
ACM Trans. Priv. Secur. | 3 |
| 2018 | Named Data Networking with Programmable SwitchesabstractThe Internet today is mainly used for distributing content, in a fundamental departure from its original goal of enabling communication between endpoints. As a response to this change, Named Data Networking (NDN) is a new architecture rooted on the concept of naming data, in contrast to the original paradigm based on naming hosts. This radical architectural shift results in packet processing in NDN to differ substantially from IP. As a consequence, current network equipment cannot be seamlessly extended to offer NDN data-plane functions. To address this challenge, available NDN router solutions are usually software-based, and even the highly-optimised designs tailored to specific hardware platforms present limited performance, hindering adoption. In addition, these tailor-made solutions are hardly reusable in research and production networks. The emergence of programmable switching chips and of languages to program them, like P4, brings hope for the state of affairs to change. In this paper, we present the design of an NDN router written in P4. We improve over the state-of-the-art solution by extending the NDN functionality, and by addressing its scalability limitations. A preliminary evaluation of our open-source solution running on a software target demonstrates its feasibility. Rui Miguel, Salvatore Signorello, Fernando M. V. Ramos |
ICNP | 3 |
| 2017 | Chrysaor: Fine-Grained, Fault-Tolerant Cloud-of-Clouds MapReduceabstractMapReduce is a framework for processing large data sets much used in the context of cloud computing. MapReduce implementations like Hadoop can tolerate crashes and file corruptions, but not arbitrary faults. Unfortunately, there is evidence that arbitrary faults do occur and can affect the correctness of MapReduce job executions. Furthermore, many outages of major cloud offerings have been reported, raising concerns about the dependence on a single cloud. In this paper we propose a novel execution system that allows to scale out MapReduce computations to a cloud-of-clouds and tolerate arbitrary faults, malicious faults, and cloud outages. Our system, Chrysaor, is based on a fine-grained replication scheme that tolerates faults at the task level. Our solution has three important properties: it tolerates the above-mentioned classes of faults at reasonable cost, it requires minimal modifications to the users' applications, and it does not involve changes to the Hadoop source code. We performed an extensive evaluation of our system in Amazon EC2, showing that our fine-grained solution is efficient in terms of computation by recovering only faulty tasks. This is achieved without incurring a significant penalty for the baseline case (i.e., without faults) in most workloads. Pedro A. R. S. Costa, Fernando M. V. Ramos, Miguel Correia 0001 |
CCGrid | 2 |
| 2016 | Medusa: An Efficient Cloud Fault-Tolerant MapReduceabstractApplications such as web search and social networking have been moving from centralized to decentralized cloud architectures to improve their scalability. MapReduce, a programming framework for processing large amounts of data using thousands of machines in a single cloud, also needs to be scaled out to multiple clouds to adapt to this evolution. The challenge of building a multi-cloud distributed architecture is substantial. Notwithstanding, the ability to deal with the new types of faults introduced by such setting, such as the outage of a whole datacenter or an arbitrary fault caused by a malicious cloud insider, increases the endeavor considerably. In this paper we propose Medusa, a platform that allows MapReduce computations to scale out to multiple clouds and tolerate several types of faults. Our solution fulfills four objectives. First, it is transparent to the user, who writes her typical MapReduce application without modification. Second, it does not require any modification to the widely used Hadoop framework. Third, the proposed system goes well beyond the fault-tolerance offered by MapReduce to tolerate arbitrary faults, cloud outages, and even malicious faults caused by corrupt cloud insiders. Fourth, it achieves this increased level of fault tolerance at reasonable cost. We performed an extensive experimental evaluation in the ExoGENI testbed, demonstrating that our solution significantly reduces execution time when compared to traditional methods that achieve the same level of resilience. Pedro A. R. S. Costa, Xiao Bai 0002, Fernando M. V. Ramos, Miguel Correia 0001 |
CCGrid | 3 |
| 2015 | Software-Defined Networking: A Comprehensive SurveyabstractThe Internet has led to the creation of a digital society, where (almost) everything is connected and is accessible from anywhere. However, despite their widespread adoption, traditional IP networks are complex and very hard to manage. It is both difficult to configure the network according to predefined policies, and to reconfigure it to respond to faults, load, and changes. To make matters even more difficult, current networks are also vertically integrated: the control and data planes are bundled together. Software-defined networking (SDN) is an emerging paradigm that promises to change this state of affairs, by breaking vertical integration, separating the network's control logic from the underlying routers and switches, promoting (logical) centralization of network control, and introducing the ability to program the network. The separation of concerns, introduced between the definition of network policies, their implementation in switching hardware, and the forwarding of traffic, is key to the desired flexibility: by breaking the network control problem into tractable pieces, SDN makes it easier to create and introduce new abstractions in networking, simplifying network management and facilitating network evolution. In this paper, we present a comprehensive survey on SDN. We start by introducing the motivation for SDN, explain its main concepts and how it differs from traditional networking, its roots, and the standardization activities regarding this novel paradigm. Next, we present the key building blocks of an SDN infrastructure using a bottom-up, layered approach. We provide an in-depth analysis of the hardware infrastructure, southbound and northbound application programming interfaces (APIs), network virtualization layers, network operating systems (SDN controllers), network programming languages, and network applications. We also look at cross-layer problems such as debugging and troubleshooting. In an effort to anticipate the future evolution of this new paradigm, we discuss the main ongoing research efforts and challenges of SDN. In particular, we address the design of switches and control platforms - with a focus on aspects such as resiliency, scalability, performance, security, and dependability - as well as new opportunities for carrier transport networks and cloud providers. Last but not least, we analyze the position of SDN as a key enabler of a software-defined environment. Diego Kreutz, Fernando M. V. Ramos, Paulo Veríssimo, Christian Esteve Rothenberg, Siamak Azodolmolky, Steve Uhlig |
Proc. IEEE | 2 |
| 2012 | On the Feasibility of Byzantine Fault-Tolerant MapReduce in Clouds-of-CloudsabstractMapReduce is a framework for processing large data sets largely used in cloud computing. MapReduce implementations like Hadoop can tolerate crashes and file corruptions, but there is evidence that general arbitrary faults do occur and can affect the correctness of job executions. Furthermore, many individual cloud outages have been reported, raising concerns about depending on a single cloud. We present a MapReduce runtime that tolerates arbitrary faults and runs in a set of clouds at a reasonable cost in terms of computation and execution time. The main challenge is to avoid sending through the internet the huge amount of data that would normally be exchanged between map and reduce tasks. Miguel Correia 0001, Pedro A. R. S. Costa, Marcelo Pasin, Alysson Neves Bessani, Fernando M. V. Ramos, Paulo Veríssimo |
SRDS | 5 |
| 2012 | Efficient channel selection using hierarchical clusteringabstractIncreases in the number of TV channels requires users to spend more time to select their preferred channels since the user interaction for browsing is practically limited to the conventional remote control with a two-way scrolling button. We formally define the problem to construct the optimal channel ordering which minimizes the seek distance in selecting channels and show this problem is NP-hard. In addition, we present a reasonable heuristic to solve this problem. The proposed method constructs an efficient channel ordering by applying a hierarchical clustering algorithm based on the frequencies of switching events between channels. We demonstrate the feasibility of this method by applying a number of well-known hierarchical clustering algorithms and evaluating the number of user inputs required for selecting channels. Our experimental results show that the proposed method significantly decreases the number of user inputs compared with the conventional methods. Hyoungshick Kim, Jon Crowcroft, Fernando M. V. Ramos |
WOWMOM | 3 |
| 2011 | Reducing channel change delay in IPTV by predictive pre-joining of TV channels
Fernando M. V. Ramos, Jon Crowcroft, Richard J. Gibbens, Pablo Rodriguez 0001, Ian H. White |
Signal Process. Image Commun. | 1 |
| 2010 | Relative Delay Estimator for SCTP-Based Concurrent Multipath TransferabstractBy identifying the shortcomings of using RTT to evaluate the quality of different paths in a multipath scenario, we propose a Relative Delay Estimator (RDE) to compare the relative one way delay of different paths without clock synchronisation. This estimator enables the comparison and selection of the best forward and backward paths, in terms of delay. As an initial application of RDE, we design a novel retransmission policy (NcRDE). The main novelty of this policy is that, from the multiple paths available, the path chosen for retransmission is according to the value of one way delay. We also present an extension to this scheme that takes path failures into account (PF-NcRDE). Simulation results show that, when compared with recently proposed retransmission policies, NcRDE can improve throughput when the different paths have different forward and backward delays. Also, in case of path failure PF-NcRDE enhances the performance significantly over NcRDE. Fei Song 0001, Hongke Zhang, Sidong Zhang, Fernando M. V. Ramos, Jon Crowcroft |
GLOBECOM | 4 |
| 2010 | Channel smurfing: Minimising channel switching delay in IPTV distribution networksabstractOne of the major concerns of IPTV network deployment is channel switching (or zapping) delay. This delay can add up to two seconds or more, and its main culprits are synchronisation and buffering. By analysing an extensive dataset - comprising 255 thousand users, 150 TV channels, and covering a 6-month period - we have observed that most channel switching events are linear: it is very common the user switching up or down to the next TV channel. This fact led us to the proposal, in this paper, of a simple mechanism to reduce channel switching delay. Our proposal is to send the neighbouring channels (i.e., channels adjacent to the requested one) to the Set Top Box (STB) during zapping periods. If the user switches to any of these channels the switching latency is virtually eliminated, not affecting therefore user's experience. Notwithstanding the simplicity of this scheme, trace-driven simulations show that the zapping delay can be virtually eliminated for a significant percentage of channel switching requests. As an example, by sending the previous and the next channel concurrently with the requested one, for only one minute after a zapping event, switching delay is eliminated for around 45% of all channel switching requests. Furthermore, this simple scheme has a performance close to that of an ideal predictor, while the increase of bandwidth utilisation in the access link is negligible. Fernando M. V. Ramos, Jon Crowcroft, Richard J. Gibbens, Pablo Rodriguez 0001, Ian H. White |
ICME | 1 |