VLDB 2026 Research / reviewers in the wild / expert
Mattia Giovanni Spina
dblp:298/0445
· DBLP profile ↗
32ranked-venue papers
15as first author
32since 2021 · last 2026
0009-0000-8407-2551ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 5 first-author · 10 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Mitigating Retransmission Attack in MQTTv5 Shared Subscription via Trust-Based Message SchedulingabstractThe growth of massive IoT (m-IoT) has introduced new challenges in ensuring scalable and secure communication. MQTTv5 addresses scalability through features like shared subscriptions, which distribute messages among multiple subscribers based on load-balancing policies. Furthermore, existing Quality of Service (QoS) mechanisms in MQTT can be leveraged to improve the reliability of data exchange within this large and heterogeneous ecosystem. However, when combined with higher Quality of Service (QoS) levels, these features can be exploited by malicious subscribers to trigger excessive and redundant retransmissions and degrade system performance. In light of these considerations, this paper analyzes the associated threats and proposes a mitigation strategy that profiles the number of retransmissions generated by each subscriber to identify anomalous behavior. Subscriber activity is evaluated using a trust-based approach, which isolates potentially malicious subscribers into a SUSPICIOUS group. A token bucket-based message delivery scheduler is then applied to this group to regulate and limit the rate of message delivery accordingly. The approach enhances security and efficiency in MQTT-based m-IoT deployments by mitigating protocol-level abuse. Simulation results confirm the effectiveness of the proposed solution – in terms of data extraction rate, queuing time, and retransmission – in comparison with the traditional strategies available in the MQTTv5 standard, such as random and round-robin message scheduling strategies. Graziano Rizzo, Mattia Giovanni Spina, Floriano De Rango |
CCNC | 2 |
| 2026 | A Dynamic Entropy-Based Approach for DDoS Protection in Software-Defined Networksabstract5G has initiated a strong trend toward network softwarization, which is expected to intensify with 6G. At the core of this shift, Software-Defined Networking (SDN) enables a programmable control plane but also broadens the attack surface. This work examines volumetric random-source Distributed Denial of Service (DDoS) attacks in SDN, where the exploitation of table misses in OpenFlow devices generates massive PACKET-IN floods toward the controller, potentially disrupting flow rule management or even compromising network stability. To address this security issue, an entropy-based detection mechanism is proposed, also introducing a dynamic and network-aware computation of the proposal’s hyper-parameters, such as the entropy threshold and the PACKET-IN message window used to analyse the network behavior. Additionally, a mitigation technique is applied by exploiting the meter table provided by the OpenFlow specification, limiting the impact of malicious entities. Experiments show that the proposed solution adapts to network conditions and attack rates, outperforming static entropy-based approaches that ignore traffic dynamics. Mattia Giovanni Spina, Mauro Tropea, Floriano De Rango |
CCNC | 1 |
| 2026 | Optimal in-network distribution of learning functions for a secure-by-design programmable data plane of next-generation networks
Mattia Giovanni Spina, Edoardo Scalzo, Floriano De Rango, Francesca Guerriero, Antonio Iera |
Comput. Networks | 1 |
| 2025 | MuRA-LB: A Multi-Resources Aware Load-Balancing Strategy Exploiting Software-Defined NetworkingabstractIn the new Software-Defined Networking (SDN) paradigm some challenges such as suitable traffic load distribution strategies, which can negatively affect the network performance, are faced. In this paper, a Multi-Resource Aware Load-Balancing strategy exploiting Software Defined Networking (SDN) programmability is presented. Our approach, leveraging the SDN controller, distributes the web requests to a web server cluster according to four metrics: CPU, Memory, Network Traffic, and Response Time of each web server. Through a comprehensive experimental campaign, we evaluated and assessed the advantages of the proposed load-balancing approach against basic methods like random selection and round-robin and also against recent advancements in load-balancing strategies that are considered more sophisticated and intelligent. Alex Ramiro Masaquiza Caiza, Mattia Giovanni Spina, Mauro Tropea, Floriano De Rango |
CCNC | 2 |
| 2025 | Improving IoT System Resilience through Secure MQTTv5 Shared SubscriptionsabstractIn the rapidly evolving landscape of the IoT, the deployment of Wireless Sensor Networks (WSNs) plays a crucial role in enabling smart environments. Future WSN IoT deploy-ments are characterized by a massive number of interconnected devices, necessitating robust communication protocols to handle the vast amount of data generated and transmitted in the so-called Massive IoT (M-IoT) context. Focusing on the con-strained nature of sensors, the MQTT protocol introduces, with the MQTTv5 specification, a pivotal technology for enhancing resource utilization and connectivity efficiency in WSN IoT scenarios: the shared subscription mechanism. In the context of M-IoT WSNs, security vulnerabilities are further exacerbated, potentially leading to high-scale damage. Based on these consider-ations, the objective of this work is to provide a security-oriented examination of the shared subscription feature proving how malicious users can exploit it to induce an indefinite starvation status among the legacy subscribers of the IoT deployment. We highlighted the extent of the damage of the shared subscription attack proposing a countermeasure that takes into account both the light nature of MQTT and the impact that it could have in future M-IoT deployment testing it under real IoT traffic patterns. Graziano Rizzo, Mattia Giovanni Spina, Floriano De Rango |
CCNC | 2 |
| 2025 | Integrating Statistical Methods and Game Theory for Enhanced IoT Intrusion DetectionabstractIntrusion Detection Systems (IDS) are widely used to secure networks and detect malicious traffic. The proliferation of IoT devices has heightened the focus on protecting these vulnerable devices. Modern IDSs leverage AI to enhance attack detection, but the complexity of network traffic poses challenges in identifying attack traits, which are crucial for reliable and confident classification. In light of these considerations, this work introduces a new comprehensive framework for analyzing datasets, first reducing features using statistical methods like the Pearson Correlation Coefficient, and then applying the Shapley Value from game theory to better understand attacks. This approach standardizes dataset analysis and enhances the reproducibility of machine learning experiments, addressing a key challenge in AI-based IDS research. Giovanni Rocca, Mattia Giovanni Spina, Floriano De Rango |
CCNC | 2 |
| 2025 | Traffic Load-Balancing Over IDS-Onboard Drones in 6G NetworksabstractFlying Ad-hoc Networks (FANETs) are a key technology for 6G networks due to their flexibility and rapid deployment, but ensuring security remains a challenge. The integration of programmable 6G networks with FANETs offers a promising solution to enhance network security. This paper proposes a resource-aware load-balancing strategy using Software-Defined Networking (SDN) to distribute network flows across drones running a Virtualized Intrusion Detection Function (VIDF). Additionally, a dynamic activation approach is introduced, enabling the SDN controller to quickly activate VIDF functions on drones in a 6G-enabled FANET. Performance evaluations demonstrate the benefits of the proposed strategy. Mattia Giovanni Spina, Alex Ramiro Masaquiza Caiza, Mauro Tropea, Floriano De Rango |
CCNC | 1 |
| 2025 | GPU-accelerated In-Network Computing for Split-AI in 6G: A Trade-Off Between Inference Time and Energy ConsumptionabstractFuture 6G networks will be called upon to support increasingly sophisticated applications based on the massive use of Artificial Intelligence (AI). This poses serious challenges to mobile devices that do not have adequate computational and energy capacity to support the effective execution of AI tasks. According to the emerging Split-AI paradigm, 6G networks can help user devices to perform complex AI tasks by distributing and executing a Neural Network (NN) collaboratively among different processing nodes, including network nodes in the 6G User Plane (UP). However, the extent to which these offloading mechanisms can improve the end-to-end latency of AI tasks is limited by the computational resources available in an operator’s network. The presence of Graphical Processing Units (GPUs) in some elements of the UP can certainly help, but it is necessary to quantify the cost of the task acceleration in terms of increased energy consumption entailed by GPU usage. In this work, we study on the example of Split-AI, the impact of GPU acceleration on inference time and energy consumption. Thereby, we demonstrate that GPU inclusion can reduce the latency induced by the DNN computation by up to 90%, with moderate energy consumption increase of 22% at most. Mattia Giovanni Spina, D. V. Soto Lebron, Susanna Schwarzmann, Riccardo Guerzoni, Riccardo Trivisonno, Floriano De Rango, R. Silva, Andres Meseguer Valenzuela, Antonio Iera |
GLOBECOM | 1 |
| 2025 | An Orchestration Platform for In-Network DDoS Attack Detection with P4 Programmable SwitchesabstractThe growing reliance on digital connectivity has made Internet Service Provider (ISP) networks a critical component of modern society, yet they remain a prime target for cyber threats. In recent years, cyberattacks against ISPs have increased in scale and sophistication, posing severe risks to national security, economic stability, and user privacy. The advent of in-network computing and programmable data plane presents a paradigm shift in network security, offering the flexibility to define, modify, and optimize packet processing logic dynamically. Among these advancements, the P4 programming language plays a crucial role, allowing network operators to implement fine-grained traffic monitoring directly within network devices. By leveraging in-network computation, P4 facilitates real-time anomaly detection, making it a powerful tool for mitigating Distributed Denial of Service (DDoS) attacks. However, orchestrating security functions across a distributed network of P4 switches remains a challenge, requiring an efficient and scalable deployment framework.In this paper, we present an open-source orchestration platform for managing and deploying P4-based security programs to enable real-time DDoS detection. Our solution leverages dynamic programmability to enhance network security. By integrating a novel queue monitoring mechanism directly into the data plane, our approach enables the collection of fine-grained network performance metrics in real-time, facilitating faster and more precise attack detection and mitigation. The proposed framework is highly scalable and adaptable, strengthening ISP networks against evolving cyber threats. Sebastian Troia, Mattia Giovanni Spina, Gianluca Davoli, Nicolò Giannini, Antonio Iera, Guido Maier |
HPSR | 2 |
| 2025 | QoS and Trust aware Mitigation of MQTT Shared Subscription Channel Saturation Attack over 5G NetworksabstractThe software-driven and virtualized architecture of modern networks-pioneered by 5G and evolving toward 6G-enables novel applications such as Massive IoT (mIoT), characterized by numerous resource-constrained and heterogeneous devices. This surge in connected devices demands new network designs and communication protocols. MQTT version 5 (MQTTv5) addresses flexibility and scalability but lacks built-in security measures. Features like Quality of Service (QoS) can be exploited by malicious devices to induce retransmissions and disrupt operations. While MQTTv5 introduces the shared subscription mechanism with load-balancing to mitigate such risks, standard strategies (e.g., Random, Round Robin) are inadequate. Hence, a security-and network-aware load-balancing policy is needed. To this end, this paper proposes QTM-MQTT (QoS-aware Trust-based Mitigation for MQTT Channel Saturation): an intelligent, informed load-balancing mechanism designed for shared subscription scenarios. The proposed strategy prioritizes message delivery to high-trust subscriber nodes while isolating low-trust, potentially malicious ones, thereby reducing unnecessary retransmissions and mitigating channel saturation. The mechanism is evaluated through simulations conducted in a realistic Urban Macro Cell (UMa) 5G channel scenario, as specified by the 5G NR TR 38.901 3GPP standard. Simulation results confirm the effectiveness of the proposed solution in terms of improvements in Signal-to-Interference-plus-Noise Ratio (SINR), Data Extraction Rate (DER), and channel overhead reduction in comparison with the strategies available in the MQTTv5 standard, namely Round Robin and Random. Mattia Giovanni Spina, Graziano Rizzo, Floriano De Rango |
MSWiM | 1 |
| 2025 | An Adaptive and Blockchain-based Reputation Mechanism in SDN Multi-Controller ScenarioabstractThe convergence of blockchain technology and software-defined networking (SDN) presents a promising solution for enhancing network security. Leveraging the decentralized architecture of blockchain and its inherent security properties, this work proposes a blockchain-based framework to strengthen trust and secure communication among SDN controllers in a multi-domain environment. The framework employs a decentral-ized reputation mechanism based on an adaptive approach that dynamically adjusts reputation parameters based on network status and the average reputation of participating nodes. This system uses the Practical Byzantine Fault Tolerance (PBFT) consensus protocol to implement a reliable process for rewarding and penalizing controllers based on their behavior, thus identifying and excluding potentially malicious nodes. Simulation results confirm that the adaptive reputation metric effectively captures node behavior by incorporating network conditions and node-specific data, leading to a more responsive and precise detection process. This dynamic approach improves detection precision, minimizes false positives, and reduces response delays, making it well-suited for diverse and evolving network environments. Mattia Giovanni Spina, Mauro Tropea, Floriano De Rango |
MSWiM | 1 |
| 2025 | Federated vs Transfer Learning Technique for Traffic Sign Recognition in Internet of VehiclesabstractThis study explores the integration of Machine Learning (ML) techniques for the classification of traffic signs within simulated vehicular environments. Specifically, the research investigates and compares two training paradigms: centralized learning, enhanced through Transfer Learning (TL) to leverage pre-trained knowledge and reduce training time, and Federated Learning (FL), a decentralized method that allows for collaborative training across distributed nodes. The work involves the implementation and evaluation of two deep learning (DL) models: a classical CNN architecture from existing literature (LeNet-5) and a custom-designed CNN model tailored for vehicular contexts. This study contributes to developing cooperative learning frameworks between vehicles and infrastructure, aiming to enhance traffic safety and efficiency. Mauro Tropea, Mattia Giovanni Spina, Azzedine Boukerche, Floriano De Rango |
MSWiM | 2 |
| 2025 | FedAECS: a Federated Learning Adversary-aware and Efficient Client SelectionabstractAs artificial intelligence gains popularity, concerns over regulation — particularly data privacy — are also growing. Federated Learning (FL) has emerged as a solution to address data privacy concerns through its distributed learning approach, enabling collaboration across diverse data sources without centralized data pooling. FL is increasingly valued for its adaptability to complex, large-scale scenarios but also faces significant challenges. In particular, this paradigm can be vulnerable to poisoning attacks, where adversaries may compromise data or local updates to disrupt the learning process and can suffer from resource limitations, as many clients have constrained energy and communication capacities, further complicating robust implementation. This paper presents FedAECS, an Adversary-aware and Efficient Client Selection algorithm designed to address these challenges. Experimental results on the MNIST dataset demonstrate FedAECS’s superior performance over state-of-the-art aggregation methods in accuracy, robustness against Byzantine and backdoor attacks, and energy efficiency. Francesco Colosimo, Mattia Giovanni Spina, Floriano De Rango |
PIMRC | 2 |
| 2025 | QLB-MSS: Queuing-Based Load Balancing for MQTTv5 Shared Subscriptions to Prevent DDoS StarvationabstractThe forthcoming sixth generation (6G) of networks is expected to enable disruptive Internet of Things (IoT) applications by fostering a seamless integration between networking and Artificial Intelligence (AI). In addition, the exponential increase in interconnected devices is challenging the current 5G networks, urgently requiring a redesign of current networking architectures and communication protocols. To address these challenges, IoT application-layer protocols are undergoing significant redesigns to enhance scalability, efficiency, and adaptability. A prominent example is MQTTv5, which introduces several advanced features, including shared subscriptions. While these advancements contribute to more efficient resource utilization and network scalability, they also introduce new security and reliability concerns that must be carefully addressed. Based on a previous work of the same authors that found a vulnerability in the shared subscription mechanism that makes it prone to a Distributed Denial of Service (DDoS) Starvation attack, this paper proposes QLB-MSS: Queuing-Based Load Balancing for MQTTv5 Shared Subscriptions, a load balancing mechanism to Prevent DDoS Starvation. This approach allows the MQTT broker to intelligently allocate messages within a shared subscription group, ensuring balanced load distribution and preventing device overload while effectively mitigating the considered attack. Graziano Rizzo, Mattia Giovanni Spina, Floriano De Rango |
PIMRC | 2 |
| 2025 | Designing Conflicting-Rule Attacks Detection through Trust-based Penalty System in SDNabstractThe emergence of the SDN paradigm represents a pivotal milestone in the development and realization of programmable networks. This paper explores the severity of the malicious flow rules injection attack over SDN controllers. More specifically, the paper focuses on injecting malicious flow rules with the objective of causing flow rule conflicts as a mean to induce ambiguity in the SDN controller decision-making process and, therefore, diverting the expected behavior of the whole network. Building on these considerations and leveraging a rigorous existing definition of various types of flow rule conflicts, this work proposes CRAD-TPS: Conflicting Rule Attacks Detection through Trust-based Penalty System, a trust-based detection mechanism to identify sources of conflicting flow rules. The obtained results shows the benefits of the proposed detection, which is crucial to allow for a prompt action to restore the expected behavior of the network. Mattia Giovanni Spina, Mauro Tropea, Floriano De Rango |
PIMRC | 1 |
| 2025 | A Scalable and Efficient Intrusion Detection System Based on a Shapley Value Driven Feature SelectionabstractThe proliferation of IoT devices, amplified by 6G, has heightened security risks. To counter these, experts are improving Intrusion Detection Systems (IDSs) using Machine Learning (ML) and Deep Learning (DL) algorithms, which rely on Feature Selection (FS) to identify key features and optimize performance in detecting attacks. In this context, this paper proposes a novel informed FS technique that exploits XAI (eXplainable Artificial Intelligence). The proposed algorithm extends the use of Shapley Value in XAI by enhancing it with an accuracy-driven binary search with the aim of finding the most representative feature and therefore reducing the dimensionality of a Network Intrusion Dataset, improving its detection ability. Through a comprehensive experimental campaign, the proposal has been validated and its benefits, which are not only limited to reduced training and testing time, but also drastically streamlining the AI model complexity. Finally, a comparison with other standard FS techniques is also provided to further highlight the advantages of the proposed algorithm. The proposal has been validated through a comprehensive experimental campaign in which results show the benefits. The experimental section shows the performance of the model when trained on the set of features returned by DeepSHAP and on the set returned by our framework, showing a drastic reduction in training and testing time. Giovanni Rocca, Mattia Giovanni Spina, Floriano De Rango |
WiMob | 2 |
| 2025 | Security-Oriented Load Distribution in MQTTv5: A Token Bucket and Trust Evaluation ApproachabstractThe advent of fifth-generation (5G) networks has enabled the rise of the massive IoT (mIoT) paradigm, characterized by large-scale, heterogeneous, and interconnected devices leading to breakthrough applications like telemedicine, AR/VR, and autonomous systems. In this context, the security of communication protocols becomes critical. Among these, MQTT is a widely adopted protocol for IoT communications. Its latest specification, MQTTv5, introduces the shared subscription feature to improve scalability and reduce message overhead on constrained devices. However, prior work by the same authors revealed a critical vulnerability in this mechanism, allowing attackers to induce starvation of legitimate subscribers. An initial mitigation was proposed, based on limiting the number of subscribers per group using fixed statistical thresholds. While effective, this approach compromises scalability by potentially excluding legitimate nodes. To address this, we propose a novel adaptive, trustbased token bucket mechanism that regulates message delivery without restricting group size. By dynamically adjusting delivery rates based on subscriber trust, the system mitigates attacks while preserving scalability. Experimental results demonstrate the superior effectiveness and efficiency of the proposed solution compared to the previous approach. Mattia Giovanni Spina, Graziano Rizzo, Floriano De Rango |
WiMob | 1 |
| 2025 | Distributed Denial of Service attack analysis and mitigation for MQTTv5 shared subscription
Graziano Rizzo, Mattia Giovanni Spina, Floriano De Rango |
Comput. Commun. | 2 |
| 2025 | DLST-MQTT: Dynamic and lightweight security over topics MQTTabstractRecent advances in hardware and software technologies have led to the design of many pervasively distributed IoT devices that can generate/consume data and manage multiple sensors and actuators, paving the way for new applications and services. However, these new features, at the same time, can easily become an enticing “grab point” for attackers, unlocking a newer and larger attack space and exposing things to greater vulnerability. In this perspective, the objective of this document is the improvement of the IoT publish/subscribe architecture and the MQTT protocol with more scalable and dynamic additional security mechanisms, which can provide end-to-end security while reducing overhead and traffic load on the broker. Building upon our prior published research, the proposal further extends and advances the concept of “security layers” between which devices with priority-aware topics can easily switch to reduce protocol overhead and increase flexibility. Each topic has associated security characteristics that clients negotiate with each other, thus saving the broker from managing any security primitives. The proposed security mechanism called Dynamic and Lightweight Security over Topics MQTT (DLST-MQTT), is compared with the standard MQTT and TLS-MQTT in terms of bandwidth consumed, CPU, and RAM usage. Additionally, security levels with relevant scores are defined, and two security update procedures taking advantage of topic priorities are designed and evaluated. • A lightweight ECC-based security reduces the overhead for constrained IoT devices. • End-to-end security management in MQTT can improve system scalability. • Security levels linked to topics allow a compromise between security and resources. • Dynamic security allows adapting to changing risks, preserving device resources. • Security hierarchy linked to topic/sub-topic allows different connections/clients establishment. Floriano De Rango, Mattia Giovanni Spina, Antonio Iera |
Future Gener. Comput. Syst. | 2 |
| 2024 | Detecting DDoS Attacks Through AI driven SDN Intrusion Detection SystemabstractIn this paper, an AI-driven Intrusion Detection System (IDS) in an SDN environment is proposed exploiting the holist view of the SDN controller of the network. In order to detect malicious traffic, the proposed system makes use of Machine and Deep Learning (ML/DL) techniques and, based on a well-known network dataset called CSE-CIC-IDS2018, it trains Decision Tree (DT), Random Forest (RF), and Deep Neural Network (DNN) models. The main task of the proposal is a deep analysis of the network traffic features using two techniques, Pearson's correlation coefficient and the Mean Decrease Impurity (MDI), in order to find the most important features and reduce the dataset size and model complexity guaranteeing optimal system performance in terms of server's response time. Francesco Salatino, Mattia Giovanni Spina, Mauro Tropea, Floriano De Rango |
CCNC | 2 |
| 2024 | Securing MQTT-M2M Communications in a Food Retail DistributionabstractIoT devices are becoming more pervasive and integrated within our everyday lives, and networks of these devices are able to help humans accomplish complex and critical tasks. In such a network, IoT devices cooperate using Machine-to-Machine ($M2M$) communications to carry out such tasks. It becomes vital, therefore, to protect such a type of communication most often carried out by resource-constrained devices that cannot afford the overhead of a standard security protocol such as TLS. In this paper, a security framework for MQTT-M2M communications is proposed, considering a smart food retail shop use case. Specifically, we considered SlowIte, Data Forgery, Man-In-The-Middle, and Dictionary attacks that target the communication among the smart devices of food retail shop, proposing a mitigation method for each of them. To prove the benefits the proposal can provide, in terms of CPU/RAM utilization and network bandwidth consumption, we compared it with the baseline MQTT security standard, i.e. TLS. Mattia Giovanni Spina, Mauro Tropea, Floriano De Rango |
CCNC | 1 |
| 2024 | MQTTv5 Shared Subscription in IoT Systems: Vulnerability Analysis and MitigationabstractMessage Queuing Telemetry Transport (MQTT) protocol is a lightweight communication protocol, widely adopted in IoT applications. The last OASIS standard document defines the new MQTTv5 specification, introducing a breakthrough feature named shared subscriptions. It is meant to bolster and make the message distribution among the subscribers of an MQTT publisher-broker-subscriber deployment more efficient. The shared subscription mechanism leverages a load-balancing technique to guide the distribution of the messages leading to an overall saving that is not only limited to network resources but also extends to the workload imposed on the involved clients. Despite its benefits, shared subscriptions introduce new security vulnerabilities that must be carefully studied and analyzed as well as mitigated without burdening the lightweight nature of MQTT. In light of these considerations, this paper aims to provide an initial security-oriented point-of-view analysis of this new feature by means of a Proof-of-Concept experimental setup in which the load-balancing approach exploited by the shared subscription mechanism is maliciously leveraged to induce indefinite starvation among the legacy subscribers of the MQTT-enabled IoT deployment. After proving the shared subscription attack magnitude damage, we present a proposal for a potential countermeasure also designed to not affect the lightness of MQTT. Graziano Rizzo, Mattia Giovanni Spina, Floriano De Rango |
GLOBECOM | 2 |
| 2024 | Native Support of AI Applications in 6G Mobile Networks Via an Intelligent User PlaneabstractWhile the concept of AI4Net has been widely discussed in the past decade and adopted in 5G, its counterpart, Net4AI, has not gained that much attention so far. This is mostly due to the absence of solutions for the network to support AI applications beyond providing the communication infrastructure. In-Network Computing (INC) is a promising paradigm, potentially being integrated into 6G, which opens new solutions for realizing Net4AI. This paper focuses on the specific case of INC-assisted Split-AI. A Neural Network (NN) is split vertically and the executions of some layers of the split NN are offloaded to the entities of an Intelligent 6G User Plane. With the example of INC-assisted Split-AI, we elaborate on the challenges of Net4AI and discuss key requirements for the 6G architecture in terms of novel capabilities and information exchange. Susanna Schwarzmann, Tugce Erkilic Civelek, Antonio Iera, Daniel Corujo, George T. Karetsos, Riccardo Guerzoni, Osama Abboud, Andres Meseguer Valenzuela, Riccardo Trivisonno, Mattia Giovanni Spina, Thomas Zinner, Toktam Mahmoodi |
WCNC | 10 |
| 2024 | Securing Shared Subscriptions in MQTTv5 for IoT Networks: Vulnerability Analysis and MitigationabstractMassive IoT (M-IoT) is a network paradigm introduced in the fifth-generation (5G) of networks to cope with a huge number of interconnected IoT devices that handle high volumes of data while providing fast and reliable IoT applications. Focusing on the constrained nature of sensors, the Message Queuing Telemetry Transport (MQTT) protocol introduces, with the MQTTv5 specification, a pivotal technology for enhancing resource utilization and connectivity efficiency in M-IoT scenarios: the shared subscription mechanism. However, due to the huge amount of interconnected IoT devices characterizing modern networks, security vulnerabilities are further exacerbated potentially leading to high-scale damage. Based on these considerations, the objective of this work is to provide a security-oriented examination of the shared subscription feature proving how malicious users can exploit it to induce an indefinite starvation status among the legacy subscribers of the IoT Wireless Sensor Network (WSN) deployment. We highlighted the extent of the damage of the shared subscription attack proposing a countermeasure that takes into account both the light nature of MQTT and the impact that it could have in future M-IoT deployment testing it under real IoT traffic patterns. Graziano Rizzo, Mattia Giovanni Spina, Floriano De Rango |
WiMob | 2 |
| 2024 | SURA-LB: Software-defined IDS with UAV Resource Aware Load-Balancing in FANET disaster scenariosabstractIn critical scenarios like natural disasters, the physical infrastructure of the network may be heavily damaged or completely torn down making difficult communications and rescue activities. In such cases, due to their nature, Unmanned Aerial Vehicles (UAVs) are usually employed to provide a temporary support network by forming a Flying Ad-Hoc Network (FANET). However, this network should be carefully monitored and safeguarded to guarantee its stability by deploying network security appliances, like Intrusion Detection Systems (IDSs). In the wake of these considerations, this paper delves into the utilization of IDS functions deployed on UAVs, named IDS-enabled UAVs, in emergencies leveraging the modern Software-Defined Network (SDN) paradigm. Specifically, the study proposes a dynamic approach to promptly activate IDS-enabled UAVs, in an SDN-FANET, responding to network traffic increasing and/or malicious activities taking place within the network. In order to achieve this objective, a Software-defined IDS with UAV Resource Aware Load Balancing strategy – SURA-LB – is proposed and implemented within the SDN controller, leveraging its programmable nature and its holistic view of the network. The SURA-LB strategy equally distributes the load among the set of IDS-enabled UAVs by considering their resources and energy utilization along with the experienced network traffic conditions. Finally, an extensive experimental campaign shows the benefits of the proposed load-balancing strategy in reducing and fairly distributing the workload among the IDS-enabled UAVs outperforming naive and baseline load-balancing strategies like Random and Round-Robin and, therefore, bolstering the resilience and the reliability of the set of IDS-enabled UAVs while the traffic to be monitored and analyzed increases. Mattia Giovanni Spina, Mauro Tropea, Floriano De Rango |
Comput. Commun. | 1 |
| 2023 | Entropy based DDoS Detection in Software Defined NetworksabstractSDN (Software Defined Networking) is a widely used networking technology aiming at decoupling control plane and data plane making network management more flexible and dynamic. This is possible thanks to the programmability feature that characterizes the SDN architecture. Despite all the benefits we can gain from the SDN technique, it is affected by some security issues and vulnerabilities. The main attack it suffers the most is DoS (Denial of Service) and its distributed evolution: DDoS (Distributed DDoS). In this work it is presented a DDoS detection mechanism based on a pillar of Information Theory, namely Shannon Entropy but adopted in SDN environment. To make the detection more accurate it is considered also the concept of packet_in window, which indicates the number of packet_in considered in a certain period of time during communications. The experimental results aim to show the best trade-off between the packet_in window size and the value of the measured entropy in each window leading to an as timeliness as possible detection of DDoS demonstrating that a proper tuning phase of the aforementioned parameters is needed to promptly detect a DDoS attack. Giovanni Fioravanti, Mattia Giovanni Spina, Floriano De Rango |
CCNC | 2 |
| 2023 | Lightweight, Dynamic and Energy Efficient Security Mechanism for constrained IoT devices using CoAPabstractSecurity and privacy issues are a great challenge in IoT systems. IoT security, of course, depends by the security level offered by communication protocols. In this paper we focus on a secure CoAP (Constrained Application Protocol) proposing a lightweight security mechanism for IoT devices characterized by limited resources. We introduce the feature of dynamic security, through a security levels scheme, to face the problem of devices heterogeneity and to provide more flexibility in choosing the security parameters that best suit the current state of the device, in terms of resources availability. Energy aspects are considered to evaluate the impact of the security on the devices' resources and to estimate the energy saving achieved by the dynamic approach. Performance evaluation has been led out comparing the dynamic Security supported by security levels with the classical secure COAP based on DTLS. Mattia Giovanni Spina, Floriano De Rango |
CCNC | 1 |
| 2023 | Supporting Dynamic IDS Deployment with Load Balancing Strategy for SDN-enabled Drones in Emergency ScenariosabstractA dynamic deployment of Intrusion Detection Systems (IDS) over drone networks exploiting the new Software-Defined Networking (SDN) paradigm in emergency scenarios is proposed. In such scenarios, maintaining network security can be a key element to consider for efficient and reliable communication. Drones equipped with IDS can play a vital role in monitoring and protecting the communication infrastructure in such scenarios. To this aim, a dynamic and time-sensitive deployment strategy for IDS on a fleet of drones is proposed to provide a high degree of fault tolerance regarding network defense. Moreover, a load-balancing strategy enabled by the SDN controller to better distribute the network traffic load to be analyzed by the IDS is designed. Mauro Tropea, Mattia Giovanni Spina, Floriano De Rango |
MSWiM | 2 |
| 2023 | Mitigation of LLDP Topological Poisoning Attack in SDN Environments Using Mininet Emulator
Mattia Giovanni Spina, Mauro Tropea, Floriano De Rango |
SIMULTECH | 1 |
| 2022 | Topic Load Balancing in a multi IoT Gateways Scenario under Publish/Subscribe ParadigmabstractPublish/Subscribe paradigm can support multi-broker management to increase network reliability and support more traffic load. However, in this context, efficient load balancing techniques need to be designed to try benefit by multiple IoT brokers. In this paper a novel optimization problem to minimize the number of topic migration has been formulated and a novel greedy-based load balancing strategy has been proposed to find a solution to the formulated problem. Performance evaluation has been considered in terms of number of topic migrations, traffic load and variance. Mattia Giovanni Spina, Gerardo Mario Marotta, Stefano Gualtieri, Floriano De Rango |
CCNC | 1 |
| 2021 | Lightweight Dynamic Topic-Centric End-to-End Security Mechanism for MQTTabstractThis paper proposes a lightweight security mechanism to manage security levels in MQTT protocol reducing the protocol overhead and using a flexible security negotiation in comparison with classical TLS solution applied to application layer protocol in the IoT context. Our proposal considers the security features around the topic and it involves the publishers as the main actors to negotiate the possible security levels on the topics. The proposal supports an end-to-end security features reducing the complexity of the broker that can only forward encrypted packet towards subscribers without performing ciphering or encryption/decryption. The performance of the proposed solutions has been tested considering increasing number of topics and clients and considering some metrics such as processed packets and bytes, processing time and RAM usage. A comparison between the dynamic security approach with MQTT and classical$\text{MQTT}+\text{TLS}$has been also considered. Mattia Giovanni Spina, Floriano De Rango, Gerardo Mario Marotta |
DS-RT | 1 |
| 2021 | Integrating ROS and Gazebo Tools with a Network Security Module to Support Secure Autonomous Robot Coordination
Mattia Giovanni Spina, Stefano Gualtieri, Floriano De Rango |
SIMULTECH | 1 |