Giacomo Giuliari

dblp:220/1469 · DBLP profile ↗
← Back
11ranked-venue papers
4as first author
10since 2021 · last 2025
0009-0008-0626-6236ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 1 first-author · 5 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Theory of computation · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Inter-domain Routing with Extensible Criteria
abstract
With the rapid evolution and diversification of Internet applications, their communication-quality criteria are continuously evolving. To globally optimize communication quality, the Internet's control plane thus needs to optimize inter-domain paths on diverse criteria, and should provide extensibility for adding new criteria or modifying existing ones. However, current inter-domain routing protocols and proposals satisfy these requirements at best to a limited degree.
Seyedali Tabaeiaghdaei, Jelte van Bommel, Marc Wyss, João L. Sobrinho, Giovanni Barbiero, Giacomo Giuliari, Ahad N. Zehmakan, Adrian Perrig
SIGCOMM6
2025 Hummingbird: Fast, Flexible, and Fair Inter-Domain Bandwidth Reservations
abstract
To realize the long-standing vision of providing quality-of-service (QoS) guarantees on a public Internet, this paper introduces Hummingbird: a lightweight QoS-system that provides fine-grained inter-domain reservations for end hosts.
Karl Wüst, Giacomo Giuliari, Markus Legner, Jean-Pierre Smith, Marc Wyss, Jules Bachmann, Juan A. García-Pardo, Adrian Perrig
SIGCOMM2
2025 BGP Vortex: Update Message Floods Can Create Internet Instabilities
Felix Stöger, Henry Birge-Lee, Giacomo Giuliari, Jordi Subirà Nieto, Adrian Perrig
USENIX Security Symposium3
2024 An Empirical Study of Consensus Protocols' DoS Resilience
abstract
With the proliferation of blockchain technology in high-value sectors, consensus protocols are becoming critical infrastructures. The rapid innovation cycle in Byzantine fault tolerant (BFT) consensus protocols has culminated in HotStuff, which provides linear message complexity in the partially synchronous setting. To achieve this, HotStuff leverages a leader that collects, aggregates, and broadcasts the messages of other validators. This paper analyzes the security implications of such approaches in practice, from the perspective of liveness and availability.
Giacomo Giuliari, Alberto Sonnino, Marc Frei, Fabio Streun, Eleftherios Kokoris-Kogias, Adrian Perrig
AsiaCCS1
2022 Protecting Critical Inter-Domain Communication through Flyover Reservations
abstract
To protect against naturally occurring or adversely induced congestion in the Internet, we propose the concept of flyover reservations, a fundamentally new approach for addressing the availability demands of critical low-volume applications. In contrast to path-based reservation systems, flyovers are fine-grained "hop-based" bandwidth reservations on the level of individual autonomous systems. We demonstrate the scalability of this approach experimentally through simulations on large graphs. Moreover, we bring the flyovers' potential to full fruition by introducing Helia, a protocol for secure flyover reservation setup and data transmission. We evaluate Helia's performance based on an implementation in DPDK, demonstrating authentication and forwarding of reservation traffic at 160 Gbps. Our security analysis shows that Helia can resist a large variety of powerful attacks against reservation admission and traffic forwarding. Despite its simplicity, Helia outperforms current state-of-the-art reservation systems in many key metrics.
Marc Wyss, Giacomo Giuliari, Jonas Mohler, Adrian Perrig
CCS2
2022 DoCile: Taming Denial-of-Capability Attacks in Inter-Domain Communications
abstract
In recent years, much progress has been made in the field of Internet bandwidth reservation systems. While early designs were neither secure nor scalable, newer proposals promise attack resilience and Internet-wide scalability by using cryptographic access tokens (capabilities) that represent permissions to send at a guaranteed rate. Once a capability-based bandwidth reservation is established, the corresponding traffic is protected from both naturally occurring congestion and distributed denialof-service attacks, with positive consequences on the end-to-end quality of service (QoS) of the communication. However, high network utilization—possibly caused by adversaries—can still preclude the initial unprotected establishment of capabilities. To prevent such denial-of-capability (DoC) attacks, we present DoCile, a framework for the protection of capability establishment on Internet paths, irrespective of network utilization. We believe that DoCile, deployed alongside a capability-based bandwidth reservation system, can be the foundation of the next generation of secure and scalable QoS protocols.
Marc Wyss, Giacomo Giuliari, Markus Legner, Adrian Perrig
IWQoS2
2021 Colibri: a cooperative lightweight inter-domain bandwidth-reservation infrastructure
abstract
Guarantees for traffic traversing the public Internet are hard to come by, as service-level agreements are typically only available for traffic within a single autonomous system or towards direct neighbors. This deficiency leads to unpredictable performance already under normal conditions and can cause outages in the face of networklevel distributed-denial-of-service (DDoS) attacks. In this paper, we present an architecture achieving guaranteed bandwidth properties for global inter-domain network traffic. The control plane of our architecture is based on a distributed server infrastructure, while the data plane enables efficient packet forwarding on per-flow stateless routers. Our implementation demonstrates the technical feasibility and scalability of the design.
Giacomo Giuliari, Dominik Roos, Marc Wyss, Juan A. García-Pardo, Markus Legner, Adrian Perrig
CoNEXT1
2021 Secure and Scalable QoS for Critical Applications
abstract
With the proliferation of online payment systems, the emergence of globally distributed consensus algorithms, and the increase of remotely managed critical IoT infrastructure, the need for critical-yet-frugal communication—high-availability and low-rate—is becoming increasingly pressing. For many of these applications, the use of leased lines or SD-WAN solutions is impractical due to their inflexibility and high costs, while standard Internet communication lacks the necessary reliability and attack resilience.To address this rising demand for strong quality-of-service (QoS) guarantees, we develop the GMA-based light-weight communication protocol (GLWP), building on a recent theoretical result, the GMA algorithm. GLWP is a capability-based protocol which is able to bootstrap network-wide bandwidth allocations in single round-trip times, and achieves high availability even under active attacks. Due to its clever use of cryptographic mechanisms, GLWP introduces minimal state in the network and causes low computation and communication overhead. We implement a GLWP prototype using Intel DPDK and show that it achieves line rate on a 40 Gbps link running on commodity hardware, thus showing that GLWP is a viable solution to provide strong QoS guarantees for critical-yet-frugal communications.
Marc Wyss, Giacomo Giuliari, Markus Legner, Adrian Perrig
IWQoS2
2021 GMA: A Pareto Optimal Distributed Resource-Allocation Algorithm
Giacomo Giuliari, Marc Wyss, Markus Legner, Adrian Perrig
SIROCCO1
2021 ICARUS: Attacking low Earth orbit satellite networks
Giacomo Giuliari, Tommaso Ciussani, Adrian Perrig, Ankit Singla
USENIX ATC1
2018 Networking in Heaven as on Earth
abstract
The Internet will undergo a major transformation as satellite-based Internet service providers start to disrupt the market. Constellations of hundreds to thousands of satellites promise to offer low-latency Internet to even the most remote areas. We anticipate exciting business and research opportunities.
Tobias Klenze, Giacomo Giuliari, Christos Pappas, Adrian Perrig, David A. Basin
HotNets2