Rafael Hengen Ribeiro

dblp:246/9450 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
5since 2021 · last 2025
0000-0003-4196-3359ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 2 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Establishing Trust for Using Natural Language for Intent-Based Networking
abstract
Todays enterprise networks wrestle with accommodating an ever-growing number of devices of different types, supporting increasingly demanding applications and ever more complex services, and protecting their users from sophisticated and disrupting cyber threats. In response, a proposed architectural approach for improving network management, referred to as Intent-Based Networking (IBN), has attracted significant attention. It is built on the premise that network operators specify network policies in natural language and the network correctly translates these spoken intents (e.g., policies) into proper device-specific configurations that are then deployed across the network to reliably act on the operators expressed intents. Unfortunately, IBN has not yet fully delivered on its promise of automated, fast, and reliable policy deployment, mainly due to the significant challenges that the reliance on methods from Natural Language Processing (NLP) or more recent techniques from Machine Learning (ML) and Artificial Intelligence (AI) poses for unambiguously and accurately translating the myriad of intents that operators can express in natural language into “trustworthy” device configurations. This paper uses LUMI, a recently designed end-to-end prototype of a system that allows operators “to manage their network by talking to the network”, as an illustrative case study. In particular, we use it to elaborate on the different functionalities such systems should have to realize IBNs vision of automating the fast deployment of policies. At the same time, we leverage LUMI to highlight the extra efforts that are required to ensure that the deployed policies can be entrusted to accurately express and execute the operators original intents.
Arthur Selle Jacobs, Ricardo J. Pfitscher, Rafael Hengen Ribeiro, Lisandro Z. Granville, Ronaldo A. Ferreira, Walter Willinger, Sanjay G. Rao
IEEE Trans. Netw. Serv. Manag.3
2023 Demo: Utilizing SRv6 to Optimize the Routing Behavior for Tactical Networks
Eryk Schiller, Chao Feng 0001, Rafael Hengen Ribeiro, Martin Buck, Burkhard Stiller
WoWMoM3
2022 A deterministic approach for extracting network security intents
abstract
Intents brought significant improvements in network management by the use of intent-level languages. Despite these improvements, intents are not yet fully integrated and deployed in most large-scale networks. As a result, network operators may still experience problems when deploying new intents, for instance, learning a vendor-specific language to understand previously deployed configurations of a network device. Additionally, traditional configurations are distributed across multiple devices, each configured using low-level, vendor-specific languages. As a result, inferring intents from these low-level configurations is a time-consuming process. Furthermore, current solutions for deriving high-level representations from bottom-up configuration analysis do not provide results as intents or have a very limited scope, missing essential details that enhance the representation. In the solution to these shortcomings, a deterministic bottom-up approach was developed to extract intents from network configuration files, which translates them into a high-level intent-defined language. By parsing security configurations from various network devices and translating them into an extended version of the Nile (Jacobs et al. 2018) language, an intent-defined language, the prototype demonstrates the concept of this approach. While three case studies illustrate the effectiveness of the approach proposed in real-world scenarios, additional evaluations exploit dumps of real-world firewall and Network Address Translator (NAT) configurations consisting of rules from different servers and institutions. These evaluations demonstrate that the proposed solution can represent configurations at an intent-level language, maintaining high accuracy while representing key details of low-level configurations.
Rafael Hengen Ribeiro, Arthur Selle Jacobs, Luciano Zembruzki, Ricardo Parizotto, Eder J. Scheid, Alberto E. Schaeffer Filho, Lisandro Z. Granville, Burkhard Stiller
Comput. Networks1
2021 ASIMOV: a Fully Passive WiFi Device Tracking
abstract
Mobile devices expose information about their hardware and manufacturer while searching for available WiFi networks via a Media Access Control (MAC) protocol. Thus, to protect the users' privacy and prevent MAC address tracking, manufacturers typically provide anonymity through MAC randomization techniques by randomly and periodically modifying the MAC address. This paper presents the ASIMOV tracking approach, which shows through the correlation of randomized information concerning the displacement of devices in space-time dimensions that it is possible to gain insights into identifiable device information. The proposed system is entirely passive and uses a combined Received Signal Strength Indicator (RSSI) value-based localization and the Information Elements (IE) transmitted in every IEEE 802.11 probe request frame.
Rafael Hengen Ribeiro, Bruno Rodrigues 0001, Christian Killer, Lenz Baumann, Muriel Figueredo Franco, Eder J. Scheid, Burkhard Stiller
Networking1
2021 Hey, Lumi! Using Natural Language for Intent-Based Network Management
Arthur Selle Jacobs, Ricardo J. Pfitscher, Rafael Hengen Ribeiro, Ronaldo A. Ferreira, Lisandro Z. Granville, Walter Willinger, Sanjay G. Rao
USENIX ATC3
2020 A Bottom-Up Approach for Extracting Network Intents
Rafael Hengen Ribeiro, Arthur Selle Jacobs, Ricardo Parizotto, Luciano Zembruzki, Alberto E. Schaeffer Filho, Lisandro Z. Granville
AINA1
2020 ShadowFS: Speeding-up Data Plane Monitoring and Telemetry using P4
abstract
Programmable Data Planes (PDPs) provide software abstractions for network operators to dynamically modify the data plane behavior. This behavior can be described in specification languages, such as P4, and deployed into programmable switches our routers. The degree of innovation enabled by PDPs allowed network operators to create new protocols and applications. Despite the high degree of innovation brought to data plane packet processing, this programmability may have a negative effect on the forwarding delay and update times of flow tables. Previous works have attempted to overcome these limitations, e.g., through caching mechanisms, however they do not provide efficient replacement primitives and incur large overhead for monitored traffic. In this paper we present the design and evaluation of ShadowFS, a system to speed-up monitoring and telemetry on the data plane. ShadowFS manages the replacement of table entries using smaller caches without requiring the programmer to specify the behavior of these tables or how to steer traffic through them. Different from previous work, ShadowFS builds a new data plane program that monitors flows and replaces rules between tables automatically. Evaluation results demonstrate that ShadowFS can increase the throughput of frequently monitored flows.
Ricardo Parizotto, Lucas Castanheira, Rafael Hengen Ribeiro, Luciano Zembruzki, Arthur Selle Jacobs, Lisandro Z. Granville, Alberto E. Schaeffer Filho
ICC3