VLDB 2026 Research / reviewers in the wild / expert
Damu Ding
dblp:247/7628
· DBLP profile ↗
10ranked-venue papers
9as first author
7since 2021 · last 2026
0000-0001-9692-7756ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 4 first-author · 4 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Net-P4ct: Enhanced WAN Bandwidth Fair Sharing Using P4 Programmable Switches
Mingwei Cui, Yihan Zou, Yihang Miao, Suhan Jiang, Damu Ding, Lirong Lai, Shengyuan He, Anjian Chen, Jiaming Shi, Junjie Wan, Yandong Duan, Ruomin Fang, Yongping Tang, Qiao Kang, Guangrui Wu, Xiyun Xu |
NSDI | 6 |
| 2024 | INDDoS+: Secure DDoS Detection Mechanism in Programmable SwitchesabstractVolumetric distributed Denial-of-Service (DDoS) attack is a key issue in modern telecommunication networks since it can exhaust the resources of legitimate users and cripple network services. Recently, with the emergence of high-throughput and low-latency programmable switches, DDoS detection mechanisms have been designed and implemented in an in-network manner, that is, DDoS detection executed directly within programmable switches. State-of-the-art works use advanced data structures to monitor the number of connections targeting destination hosts: if there is sudden increase of connections and the number exceeds a given threshold, the destination host is most likely under DDoS attack. However, while this approach is efficient in DDoS victims identification, it has inherent vulnerabilities in the detection mechanism that may lead to security issues. In this paper, we study two possible vulnerabilities in DDoS detection data structures, showing the possibilities to break DDoS detection mechanisms in programmable switches. To mitigate the constructed attacks, we propose a solution called INDDoS+. The results show that INDDoS+ is robust to attacks and can accurately detect DDoS attempts when limited hardware resources are assigned. Damu Ding, Ozlem Kesgin, Noa Zilberman |
HPSR | 1 |
| 2024 | CARBINE: Exploring Additional Properties of HyperLogLog for Secure and Robust Flow Cardinality EstimationabstractCounting distinct elements (also named flow cardinality) of large data streams in the network is of primary importance since it can be used for many practical monitoring applications, including DDoS attack and malware spread detection. However, modern intrusion detection systems are struggling to reduce both memory and computational overhead for such measurements. Many algorithms are designed to estimate flow cardinality, in which HyperLogLog has been proven the most efficient due to its high accuracy and low memory usage. While HyperLogLog provides good performance on flow cardinality estimation, it has inherent algorithmic vulnerabilities that lead to both security and robustness issues. To overcome these issues, we first investigate two possible threats in HyperLogLog, and propose corresponding detection and protection solutions. Lever-aging proposed solutions, we introduce CARBINE, an approach that aims at identifying and eliminating the threats that most probably mislead the output of HyperLogLog. We implement our CARBINE to evaluate the threat detection performance, especially in case of a practical network scenario under volumetric DDoS attack. The results show that our CARBINE can effectively detect different kinds of threats while performing even higher accuracy and update speed than original HyperLogLog. Damu Ding |
INFOCOM | 1 |
| 2022 | Design and Development of Network Monitoring Strategies in P4-enabled Programmable SwitchesabstractNetwork monitoring is of paramount importance for effective network management: it allows to constantly observe a network’s behavior to ensure it is working as intended, and can trigger both automated and manual remediation procedures in case of failures and anomalies. Software-Defined Networking (SDN) decouples the control plane of network infrastructure from its data plane to perform centralized control on the multiple switches in a network. In this context, the responsibility of switches is only to forward packets according to the instructions provided by a controller. The lack of programmability in the data plane of SDNs prompted the advent of data-plane programmable switches, which allow developers to customize the data-plane pipeline (e.g. match-action tables) by using a domain specific language named P4, and implement novel programs and protocols operating at wire speed directly in the switches. This unlocks the possibility to offload some monitoring tasks to the programmable data plane, and to perform fine-grained monitoring at very high packet processing speeds. Given the central importance of this topic, the principal goal of this thesis is to enable a wide range of monitoring tasks in data-plane programmable switches, with a focus on the ones equipped with programmable Application-Specific Integrated Circuits (ASICs). To achieve this goal, this thesis makes three main contributions: (i.) We enhance P4-supported data plane programmability for network monitoring; (ii.) We design and develop several network monitoring tasks in programmable data planes; (iii.) We combine multiple tasks in a single commodity switch to collect various metrics for different monitoring purposes. Our evaluations show that our solutions can be exploited by network administrators, operators and security engineers to better track and understand the current network status, and thus prevent infrastructure and service failures. Damu Ding, Marco Savi, Federico Pederzolli, Domenico Siracusa |
NOMS | 1 |
| 2022 | Tracking Normalized Network Traffic Entropy to Detect DDoS Attacks in P4abstractDistributed Denial-of-Service (DDoS) attacks represent a persistent threat to modern telecommunications networks: detecting and counteracting them is still a crucial unresolved challenge for network operators. DDoS attack detection is usually carried out in one or more central nodes that collect significant amounts of monitoring data from networking devices, potentially creating issues related to network overload or delay in detection. The dawn of programmable data planes in Software-Defined Networks can help mitigate this issue, opening the door to the detection of DDoS attacks directly in the data plane of the switches. However, the most widely-adopted data plane programming language, namely P4, lacks supporting many arithmetic operations, therefore, some of the advanced network monitoring functionalities needed for DDoS detection cannot be straightforwardly implemented in P4. This work overcomes such a limitation and presents two novel strategies for flow cardinality and for normalized network traffic entropy estimation that only use P4-supported operations and guarantee a low relative error. Additionally, based on these contributions, we propose a DDoS detection strategy relying on variations of the normalized network traffic entropy. Results show that it has comparable or higher detection accuracy than state-of-the-art solutions, yet being simpler and entirely executed in the data plane. Damu Ding, Marco Savi, Domenico Siracusa |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | INVEST: Flow-based Traffic Volume Estimation in Data-plane Programmable NetworksabstractThe emergence of programmable data planes in Software-Defined Networks enables the execution of various monitoring tasks directly in network devices, overcoming the need to deliver huge amounts of information to a controller that must then process it at scale. In this paper, we aim to solve a fundamental problem arising when exploiting programmable data planes for network-wide monitoring: how to estimate the overall number of packets in the network (i.e., the traffic volume), and the related number and size of flows, while avoiding packet double counting. Most existing works solve this problem by ensuring that each packet is counted only once on its path, which limits routing or requires coordination among devices. We propose a different approach, INVEST, a flow-based traffic volume estimator for P4-based switches, that relies on and can reuse commonly employed data structures while naturally solving the double-counting problem. We theoretically analyze and experimentally evaluate our solution, which we implemented in a real P4 carrier-grade switch, finding that it is accurate, memory-efficient, and can process packets at line rate. Damu Ding, Marco Savi, Federico Pederzolli, Domenico Siracusa |
Networking | 1 |
| 2021 | In-Network Volumetric DDoS Victim Identification Using Programmable Commodity SwitchesabstractVolumetric distributed Denial-of-Service (DDoS) attacks have become one of the most significant threats to modern telecommunication networks. However, most existing defense systems require that detection software operates from a centralized monitoring collector, leading to increased traffic load and delayed response. The recent advent of Data Plane Programmability (DPP) enables an alternative solution: threshold-based volumetric DDoS detection can be performed directly in programmable switches to skim only potentially hazardous traffic, to be analyzed in depth at the controller. In this paper, we first introduce the BACON data structure based on sketches, to estimate per-destination flow cardinality, and theoretically analyze it. Then we employ it in a simple in-network DDoS victim identification strategy, INDDoS, to detect the destination IPs for which the number of incoming connections exceeds a pre-defined threshold. We describe its hardware implementation on a Tofino-based programmable switch using the domain-specific P4 language, proving that some limitations imposed by real hardware to safeguard processing speed can be overcome to implement relatively complex packet manipulations. Finally, we present some experimental performance measurements, showing that our programmable switch is able to keep processing packets at line-rate while performing volumetric DDoS detection, and also achieves a high F1 score on DDoS victim identification. Damu Ding, Marco Savi, Federico Pederzolli, Mauro Campanella, Domenico Siracusa |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2020 | Estimating Logarithmic and Exponential Functions to Track Network Traffic Entropy in P4abstractThe evaluation of network traffic entropy is very useful for management purposes, since it helps to keep track of changes in network flow distribution. Nowadays, network traffic entropy is usually estimated in centralized monitoring collectors, which require a significant amount of information to be retrieved from switches. The advent of programmable data planes in Software-Defined Networks helps mitigate this issue, opening the door to the possibility of estimating entropy directly in the switches’ data plane. Unfortunately, the most widely-adopted programming language used to program the data plane, called P4, lacks supporting many arithmetic operations such as logarithm and exponential function computation, which are necessary for entropy estimation. In this paper we propose two new algorithms, called P4Log and P4Exp, to fill this gap: these algorithms can estimate logarithms and exponential functions with a given precision by only using P4-supported arithmetic operations. Additionally, we leverage them to propose a novel strategy, called P4Entropy, to estimate traffic entropy entirely in the switch data plane. Results show that P4Entropy has comparable accuracy as an existing solution but without (i) constraining the number of packets in an observation interval and (ii) requiring the usage of TCAM, which is a scarce resource. Damu Ding, Marco Savi, Domenico Siracusa |
NOMS | 1 |
| 2020 | An Incrementally-Deployable P4-Enabled Architecture for Network-Wide Heavy-Hitter DetectionabstractThe advent of Software-Defined Networking with OpenFlow first, and subsequently the emergence of programmable data planes, has boosted lots of research around many networking aspects: monitoring, security, traffic engineering. In the context of monitoring, most of the proposed solutions show the benefits of data plane programmability by simplifying the network complexity with a one big-switch abstraction. Only few papers look at network-wide solutions, but consider the network only composed by programmable devices. In this paper, we argue that the primary challenge for a successful adoption of those solutions is the deployment problem: how to compose and monitor a network consisting of both legacy and programmable switches? We propose an approach for incrementally deploy programmable devices in an ISP network with the goal of monitoring as many distinct network flows as possible. While assessing the benefits of our solution, we realized that proposed network-wide monitoring algorithms might not be optimized for a partial deployment scenario. We then also developed and implemented in P4 a novel strategy capable of detecting network-wide heavy flows: results show that it can achieve better accuracy than state-of-the-art solutions while relying on less information from the data plane and leading to only marginal additional packet processing time. Damu Ding, Marco Savi, Gianni Antichi, Domenico Siracusa |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2019 | Incremental Deployment of Programmable Switches for Network-wide Heavy-hitter DetectionabstractThe advent of Software-Defined Networking with OpenFlow first, and subsequently the emergence of programmable data planes, has boosted lot of research around many networking aspects: monitoring, security, traffic engineering. In the context of network monitoring, most of the proposed solutions show the benefits of data plane programmability by simplifying the complexity of the network with a one big-switch abstraction. Only few papers look at network-wide solutions, but consider the network as non heterogeneous: only composed by programmable devices. In this paper, we argue that the primary challenge for a successful adoption of those solutions is the deployment problem: how to compose and monitor a network consisting of both legacy and programmable switches? We propose an approach for incrementally deploy programmable devices in an ISP network with the goal of monitoring as many distinct network flows as possible. While assessing the benefits of our solution, we realized that proposed network-wide monitoring algorithms might not be optimized for a partial deployment scenario. We then also developed a novel strategy capable of detecting network-wide heavy flows with the same accuracy of state-of-the-art solutions but by relying on less information from the data plane. Damu Ding, Marco Savi, Gianni Antichi, Domenico Siracusa |
NetSoft | 1 |