VLDB 2026 Research / reviewers in the wild / expert
Matteo Repetto
dblp:48/6909
· DBLP profile ↗
32ranked-venue papers
10as first author
18since 2021 · last 2026
0000-0001-8478-2633ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 1 first-author · 5 since 2021Software engineering, systems software and programming languages · 10 · 3 first-author · 7 since 2021Systems, architecture and hardware · 4 · 2 first-author · 2 since 2021Security and privacy · 4 · 4 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Cybersecurity Digital Twins: Concept, blueprint, and challenges for multi-ownership digital service chainsabstractThe growing level of interconnectedness of digital services and infrastructures creates tight and recursive security inter-dependencies between their providers. However, cybersecurity operations remain highly fragmented, since common tasks like disclosing vulnerabilities, reporting alerts, and suggesting remediation are largely restricted within the boundaries of the administrative domain of each provider, while cooperation is usually limited to paperwork and human interactions. This practice has already demonstrated to be inadequate and risky, because it cannot effectively address multi-step attacks and kill chains that propagate across multiple domains. In this position paper, we elaborate on the concept, blueprint, and usage of a Cyber-security Digital Twin that models and captures the security posture of such interconnected systems. Differently from existing models, our work explicitly addresses the challenges brought by multi-ownership, by focusing on the overall architecture to build cooperative, agile, adaptive and autonomous processes for threat hunting, detection of lateral movements, and eradication of attacks among multiple domains. For this reason, our framework takes into account the necessary federation mechanisms that address trust and confidentiality concerns. • Concept and purpose of Cybersecurity Digital Twin. • Architecture of a Cybersecurity Digital Twin. • Improving security operations by a Cybersecurity Digital Twin. • Available technologies for the implementation of a Cybersecurity Digital Twin, research gaps, and open issues. Matteo Repetto |
J. Inf. Secur. Appl. | 1 |
| 2025 | Context Discovery for Digital Service Chain with OpenC2abstractRecent management paradigms for software-defined infrastructures bring more agility in the creation and operation of digital services, but also introduce new cyber-security issues due to fast-changing environments and dynamic topologies. Rigid and statically-configured architectures are no more suitable for managing cyber-security functions in mixed cloud/6G/IoT environments, since the number, capabilities, and providers of such functions are expected to change at run-time. In this paper, we propose a context discovery protocol based on the OpenC2 language. It recursively queries Context Providers that describe services, relationships, and cyber-security functions, in order to build the whole service context graph, also encompassing multiple networks and domains. We provide a working implementation that covers OpenStack and Kubernetes environments, and we validate it in a software-defined 5 G testbed. Our approach provides a more general context and uniform interface than existing service discovery protocols; furthermore, the domain-specific language enables seamless integration in cyber-security frameworks. Silvio Tanzarella, Matteo Repetto |
NetSoft | 2 |
| 2025 | Otupy: A flexible, portable, and extensible framework for remote control of security functionsabstractThe growing proliferation of heterogeneous security functions ensures diversity, robustness, and adaptivity in addressing cyber-threats, but also poses management and integration challenges. OpenC2 defines a vendor- and application-agnostic abstract language for remote command and control of cyber-defense technologies. Its architecture supports multiple encoding and transfer options, but this might complicate its implementation and usage. This paper describes Otupy, a flexible and extensible implementation of the OpenC2 language specification. Otupy defines an Application Programming Interface (API) that allows programmers to focus on the control and business logic of security functions, rather than the communication syntax, protocol, and encoding. The design of Otupy leverages an abstract data notation, an inheritance model, and meta-serialization to simplify the development of extensions for specific profiles of security functions, as well as additional encoding and transfer protocols. We evaluate the correctness of our implementation by validating its output against both a syntax schema and external good and bad samples provided by a third party. Our analysis points out unclear and ambiguous aspects of OpenC2 that deserve further attention by its technical committee. Matteo Repetto |
Comput. Secur. | 1 |
| 2023 | Service Templates to Emulate Network Attacks in Cloud-Native 5G InfrastructuresabstractThanks to its cloud-native design, the 5G architecture can be easily deployed and operated with modern cloud paradigms. The availability of open-source implementations of both the 5G Core Network (5GC) and Radio Access Network (RAN) are of paramount importance to investigate management, performance, and security issues that arise from this new operational model. However, such software usually does not include the necessary deployment scripts to easily and quickly run it in Kubernetes clusters.In this paper, we describe our set of service templates for emulating network attacks in (and against) 5G systems deployed in the cloud. Our contribution consists of the necessary automation workflows for building manifest files, setting up and running research testbeds in a matter of minutes. The templates include a scenario with broad applicability, namely attacks to Internet services from botnets in the RAN, also taking into account the presence of traffic from licit users. Real-time scalability of the botnet and licit users allows to easily generate different workload conditions; additionally, different attacks can be reproduced by simply replacing the container images for the Internet service, licit clients, and botnet nodes. Evaluation considers the time to deploy the cloud-native application and verification of its correct operation. Matteo Repetto |
NetSoft | 1 |
| 2023 | Information Leakages of Docker Containers: Characterization and Mitigation StrategiesabstractCompared to classic virtual machines, containers offer lightweight and dynamic execution environments. Hence, they are core building blocks for the development of future softwarized networks and cloud-native applications. However, containers still pose many security challenges, which are less understood compared to other virtualization paradigms. An important aspect often neglected concerns techniques enabling containers to leak data outside their execution perimeters, e.g., to exfiltrate sensitive information or coordinate attacks. In this paper we investigate security impacts of covert communications based on the looser isolation of memory statistics information. Our characterization indicates that the investigation of system calls should be considered a prime tool to reveal the presence of collusive attack schemes. We also elaborate on two mitigation techniques: the first entails prevention via “hardening” configurations of containers, while the second implements a run-time disruption mechanism. Marco Zuppelli, Matteo Repetto, Luca Caviglione, Enrico Cambiaso |
NetSoft | 2 |
| 2023 | Adaptive monitoring, detection, and response for agile digital service chainsabstractModern business is increasingly adopting fully-digital workflows composed of complementary services (in terms of infrastructures, software, networks, data and devices) from different domains, hence giving rise to complex and heterogeneous digital chains. The substantial fragmentation in service operation and ownership between these domains impacts cybersecurity operations, by hindering a coherent and cooperative defense strategy for the entire chain. As a result, this situation gives attackers more opportunity to move laterally within the chain once they have found and compromised the weakest link. A ground-breaking evolution of legacy cybersecurity processes is necessary towards collaborative and adaptive models that fit the dynamic, agile, and heterogeneous nature of federated environments. In this paper, we elaborate on the necessary convergence between complementary workflows for response, analysis, and intelligence, by considering the peculiarity of these operations and the relevant threat scenario. Our analysis points out the main research challenges to fill the existing gap between management and protection practice for digital service chains. Moreover, we outline a reference architecture that combines such workflows. The objective is to foster researchers to broaden the scope of their work, in order to address open security issues for modern business and computing paradigms. Matteo Repetto |
Comput. Secur. | 1 |
| 2022 | A cybersecurity framework to guarantee reliability and trust for digital service chains - GUARDabstractEvolving computing paradigms are progressively introducing new design, development, and operation models for digital services, which increasingly leverage service-oriented architectures and microservices patterns to create data-centric applications. This approach eventually brings more agility in the overall service lifetime management, but also introduces additional security and privacy concerns that cannot be effectively addressed by legacy device- and infrastructure-centric models. The GUARD project developed an extensible platform for building detection and analytics services for advanced assurance and protection of trustworthy and reliable business chains which span multiple administrative domains and heterogeneous infras-tructures. GUARD advocates the implementation of embedded security capabilities in digital services, that can be accessed and orchestrated through API similar to what already happens for management and operation purposes. GUARD features are demonstrated on two challenging use cases, in the Smart Mobility and eHealth domains. Matteo Repetto, Armend Duzha, Joanna Kolodziej |
CCGRID | 1 |
| 2022 | Evaluation of the data handling pipeline of the ASTRID frameworkabstractEffective attack detection and security analytics rely on the availability of timely and fine-grained information about the evolving context of the protected environment. The data handling process entails collection from heterogeneous sources, local aggregation and transformation operations before transmission, and finally collection and delivery to multiple processing engines for analysis and correlation. Many Security Information and Event Management (SIEM) tools work according to the “funnel” principle: gather as much data as possible and then filter it to keep the relevant information. However, this might lead to unacceptable overhead, especially when monitoring containerized environments. As part of our activity in ASTRID, we therefore conducted experimental investigation on resource consumption of the data handling pipeline, starting from embedded agents up to delivery to the Context Broker. Matteo Repetto, Guerino Lamanna |
NetSoft | 1 |
| 2022 | Automating Mitigation of Amplification Attacks in NFV ServicesabstractThe combination of virtualization techniques with capillary computing and storage resources allows the instantiation of Virtual Network Functions throughout the network infrastructure, which brings more agility in the development and operation of network services. Beside forwarding and routing, this can be also used for additional functions, e.g., for security purposes. In this paper, we present a framework to systematically create security analytics for virtualized network services, specifically targeting the detection of cyber-attacks. Our framework largely automates the deployment of security sidecars into existing service templates and their interconnection to an external analytics platform. Notably, it leverages code augmentation techniques to dynamically inject and remove inspection probes without affecting service operation. We describe the implementation of a use case for the detection of DNS amplification attacks in virtualized 5G networks, and provide extensive evaluation of our innovative inspection and detection mechanisms. Our results demonstrate better efficiency with respect to existing network monitoring tools in terms of CPU usage, as well as good accuracy in detecting attacks even with variable traffic patterns. Matteo Repetto, Gianmarco Bruno, Jalolliddin Yusupov, Guerino Lamanna, Benjamin Ertl, Alessandro Carrega |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2022 | Code Layering for the Detection of Network Covert Channels in Agentless SystemsabstractThe growing interest in agentless and serverless environments for the implementation of virtual/container network functions makes monitoring and inspection of network services challenging tasks. A major requirement concerns the agility of deploying security agents at runtime, especially to effectively address emerging and advanced attack patterns. This work investigates a framework leveraging the extended Berkeley Packet Filter to create ad-hoc security layers in virtualized architectures without the need of embedding additional agents. To prove the effectiveness of the approach, we focus on the detection of network covert channels, i.e., hidden/parasitic network conversations difficult to spot with legacy mechanisms. Experimental results demonstrate that different types of covert channels can be revealed with a good accuracy while using limited resources compared to existing cybersecurity tools (i.e., Zeek and libpcap). Marco Zuppelli, Matteo Repetto, Andreas Schaffhauser, Wojciech Mazurczyk, Luca Caviglione |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2021 | bccstego: A Framework for Investigating Network Covert ChannelsabstractModern malware increasingly exploits information hiding to remain undetected while attacking. To this aim, network covert channels, i.e., hidden communication paths established within legitimate flows, can be used to exfiltrate data or exchange commands without getting noticed by firewalls, antivirus, and intrusion detection systems. Since the secret data can be directly injected in various portions of the stream or encoded via suitable alterations of the traffic, spotting hidden communications is a challenging and poorly generalizable task. Moreover, the majority of works addressed IPv4, thus leaving the detection of covert channels targeting IPv6 almost unexplored. Matteo Repetto, Luca Caviglione, Marco Zuppelli |
ARES | 1 |
| 2021 | Feature Selection Evaluation towards a Lightweight Deep Learning DDoS DetectorabstractToday’s networks and services undoubtedly require a high level of protection from cyber threats and attacks. State-of-the-art solutions that implement Machine Learning (ML) have shown to improve the accuracy and confidence in threat detection compared to previous approaches, making it suitable for detecting today’s sophisticated attacks such as Distributed Denial of Service (DDoS). However, in real-world deployments, input data streams take large bandwidth and processing capacity, especially for Deep Learning (DL) solutions that require extensive input data. On the other hand, deployment environments usually have limited bandwidth and computing resources, such as in the Internet of Things (IoT). Thus, a lightweight detection solution that satisfies such constraints is needed. In this paper, we utilize a feature reduction approach for our DL-based DDoS detector based on the Analysis of Variance (ANOVA), which is used to identify important data features and reduce the data inputs needed for detection. Our result shows that we can reduce the data input needed by up to 84.21% while only reducing 0.1% detection accuracy. We also provide a detailed analysis of the characteristics of DDoS attacks using ANOVA and compared our work with recent DL-based DDoS detection systems to demonstrate that our results are comparable to existing approaches. Odnan Ref Sanchez, Matteo Repetto, Alessandro Carrega, Raffaele Bolla, Jane Frances Pajo |
ICC | 2 |
| 2021 | Code Augmentation for Detecting Covert Channels Targeting the IPv6 Flow LabelabstractInformation hiding is at the basis of a new-wave of malware able to elude common detection mechanisms or remain unnoticed for long periods. To this aim, a key approach exploits network covert channels, i.e., abusive communication paths nested within a legitimate traffic flow. The increasing diffusion of IPv6 makes it attractive for an attacker, especially for the presence of the Flow Label field, which can be manipulated to contain up to 20 secret bits per packet. Unfortunately, gathering data to implement a standalone detection mechanism or to support third-party security tools is a poorly generalizable process and often leads to scalability issues. This paper showcases how to take advantage of code augmentation features (i.e., the extended Berkeley Packet Filter) to detect covert channels targeting the IPv6 Flow Label. To prove its effectiveness, the proposed approach has been tested against Internet-wide traffic traces collected in the wild. Results indicate that it is possible to spot the channel while mitigating the memory footprint and the computational burden (e.g., the processed traffic only experience an additional delay of a few nanoseconds). Luca Caviglione, Marco Zuppelli, Wojciech Mazurczyk, Andreas Schaffhauser, Matteo Repetto |
NetSoft | 5 |
| 2021 | Leveraging the 5G architecture to mitigate amplification attacksabstractVolumetric (Distributed) Denial of Service attacks remain one of the major threats for any organization, capable of saturating most Internet access links through the usage of botnets and amplification techniques. The only effective mitigation mechanism today is the redirection of the network traffic towards scrubbing centers; this protects the Internet pipe of the victim, but does not prevent wasting resources in other parts of the network.In this paper, we leverage the cloud-native design of the 5G architecture to monitor traffic statistics at the edge of the network, which are then processed by a powerful Analytics ToolKit (ATk). Our work is based on the framework designed by the ASTRID project, which allows to automatically change the inspection probes while chasing a better balance between the granularity of the collected data and the overhead. We demonstrate our approach for an NTP amplification attack; the ATk is first trained with historical data and then used to detect deviations from the expected traffic profile, by switching between normal/warning/alert states. Our preliminary results show that it can correctly distinguish between periodical fluctuations of requests and attacks and tolerate a few data losses. Matteo Repetto, Alessandro Carrega, Guerino Lamanna, Jalolliddin Yusupov, Orazio Toscano, Gianmarco Bruno, Michele Nuovo, Marco Cappelli |
NetSoft | 1 |
| 2021 | Evaluating ML-based DDoS Detection with Grid Search Hyperparameter OptimizationabstractDistributed Denial of Service (DDoS) attacks disrupt global network services by mainly overwhelming the victim host with requests originating from multiple traffic sources. DDoS attacks are currently on the rise due to the ease of execution and rental of distributed architectures such as the Internet of Things (IoT) and cloud infrastructures, which could potentially result in substantial revenue losses. Therefore, the detection and prevention of DDoS attacks are currently topics of high interest. In this study, we use traffic flow information to determine if a specific flow is associated with a DDoS attack. We used traditional Machine Learning (ML) methods in developing our DDoS detector and applied an exhaustive hyperparameter search to optimize their detection capability. Using lightweight approaches is suitable for resource-constrained environments such as IoT to reduce computing overhead. Our evaluation shows that most algorithms provide satisfactory results, with Random Forests achieving as high as 99% of detection accuracy, which is similar to the performance of current deep learning solutions for DDoS detection. Odnan Ref Sanchez, Matteo Repetto, Alessandro Carrega, Raffaele Bolla |
NetSoft | 2 |
| 2021 | Kernel-level tracing for detecting stegomalware and covert channels in Linux environmentsabstractModern malware is becoming hard to spot since attackers are increasingly adopting new techniques to elude signature- and rule-based detection mechanisms. Among the others, steganography and information hiding can be used to bypass security frameworks searching for suspicious communications between processes or exfiltration attempts through covert channels. Since the array of potential carriers is very large (e.g., information can be hidden in hardware resources, various multimedia files or network flows), detecting this class of threats is a scarcely generalizable process and gathering multiple behavioral information is time-consuming, lacks scalability, and could lead to performance degradation. In this paper, we leverage the extended Berkeley Packet Filter (eBPF), which is a recent code augmentation feature provided by the Linux kernel, for programmatically tracing and monitoring the behavior of software processes in a very efficient way. To prove the flexibility of the approach, we investigate two realistic use cases implementing different attack mechanisms, i.e., two processes colluding via the alteration of the file system and hidden network communication attempts nested within IPv6 traffic flows. Our results show that even simple eBPF programs can provide useful data for the detection of anomalies, with a minimal overhead. Furthermore, the flexibility to develop and run such programs allows to extract relevant features that could be used for the creation of datasets for feeding security frameworks exploiting AI. Luca Caviglione, Wojciech Mazurczyk, Matteo Repetto, Andreas Schaffhauser, Marco Zuppelli |
Comput. Networks | 3 |
| 2021 | Guest editorial: Special issue on novel cyber-security paradigms for software-defined and virtualized systems
Fulvio Valenza, Matteo Repetto, Stavros Shiaeles |
Comput. Networks | 2 |
| 2021 | An architecture to manage security operations for digital service chains
Matteo Repetto, Alessandro Carrega, Riccardo Rapuzzi |
Future Gener. Comput. Syst. | 1 |
| 2020 | Programmable Data Gathering for Detecting StegomalwareabstractThe “arm race” against malware developers requires to collect a wide variety of performance measurements, for instance to face threats leveraging information hiding and steganography. Unfortunately, this process could be time-consuming, lack of scalability and cause performance degradations within computing and network nodes. Moreover, since the detection of steganographic threats is poorly generalizable, being able to collect attack-independent indicators is of prime importance. To this aim, the paper proposes to take advantage of the extended Berkeley Packet Filter to gather data for detecting stegomalware. To prove the effectiveness of the approach, it also reports some preliminary experimental results obtained as the joint outcome of two H2020 Projects, namely ASTRID and SIMARGL. Alessandro Carrega, Luca Caviglione, Matteo Repetto, Marco Zuppelli |
NetSoft | 3 |
| 2020 | Coupling energy efficiency and quality for consolidation of cloud workloads
Alessandro Carrega, Matteo Repetto |
Comput. Networks | 2 |
| 2019 | Energy efficiency for edge multimedia elastic applications
Alessandro Carrega, Giancarlo Portomauro, Matteo Repetto, Giorgio Robino |
Multim. Tools Appl. | 3 |
| 2018 | A New Paradigm to Address Threats for Virtualized ServicesabstractWith the uptaking of virtualization technologies and the growing usage of public cloud infrastructures, an ever larger number of applications run outside of the traditional enterprise's perimeter, and require new security paradigms that fit the typical agility and elasticity of cloud models in service creation and management. Though some recent proposals have integrated security appliances in the logical application topology, we argue that this approach is sub-optimal. Indeed, we believe that embedding security agents in virtualization containers and delegating the control logic to the software orchestrator provides a much more effective, flexible, and scalable solution to the problem. In this paper, we motivate our mindset and outline a novel framework for assessing cyber-threats of virtualized applications and services. We also review existing technologies that build the foundation of our proposal, which we are going to develop in the context of a joint research project. Stefan Covaci, Matteo Repetto, Fulvio Risso |
COMPSAC (2) | 2 |
| 2018 | Building situational awareness for network threats in fog/edge computing: Emerging paradigms beyond the security perimeter model
Riccardo Rapuzzi, Matteo Repetto |
Future Gener. Comput. Syst. | 2 |
| 2017 | A framework to correlate power consumption and resource usage in cloud infrastructuresabstractThe increasing demand of cloud services has rapidly raised the size of data centers, and consequently their power consumption. Data centers are usually over-sized, to be ready for further business increase; further, today many infrastructures are build as federation of multiple sites, to place the workload next to the user. Effective energy management policies are required in place to modulate power consumption according to the processing load to effectively tackle the dynamic fluctuations in workload. In this regard, service orchestrators and multi- and cross-cloud energy management systems need proper tools to understand how power consumption of cloud components would change with different placement decisions, both in the single as well as in federated clouds. In this paper, we describe a framework for drawing the relationship between resource usage such as CPU, memory and disk and energy consumption. Our work builds on the availability of both resource usage and power consumption measurements in Cloud Management Software, and makes proper correlation between these values to effectively support energy-efficiency strategies. Divya Kanapram, Riccardo Rapuzzi, Guerino Lamanna, Matteo Repetto |
NetSoft | 4 |
| 2016 | Assessing the Potential for Saving Energy by Impersonating Idle Networked DevicesabstractThe idea of proxying network connectivity has been proposed as an efficient mechanism to maintain network presence on behalf of idle devices, so that they can "sleep". The concept has been around for many years; alternative architectural solutions have been proposed to implement it, which lead to different considerations about capability, effectiveness and energy efficiency. However, there is neither a clear understanding of the potential for energy saving nor a detailed performance comparison among the different proxy architectures. In this paper, we estimate the potential energy saving achievable by different architectural solutions for proxying network connectivity. Our work considers the tradeoff between the saving achievable by putting idle devices to sleep and the additional power consumption to run the proxy. Our analysis encompasses a broad range of alternatives, taking into consideration both implementations already available in the market and prototypes built for research purposes. We remark that the main value of our work is the estimation under realistic conditions, taking into consideration power measurements, usage profiles, and proxying capabilities. Raffaele Bolla, Rafiullah Khan, Matteo Repetto |
IEEE J. Sel. Areas Commun. | 3 |
| 2014 | Seamless and transparent migration for TCP sessionsabstractPersonal communication devices are extensively used for mobile computing thanks to ever increasing wireless coverage and processing capability. However, they are constrained in terms of both human interaction (screen size and resolution, keyboard) and lifetime; hence mobile computing often relies on the possibility to migrate applications and communication sessions among several (fixed or mobile) devices. Session migration is a challenging feature, especially when communication with other hosts is involved, and the current Internet architecture does not support natively this paradigm. In this paper, we address seamless and transparent session migration for the Transmission Control Protocol (TCP) that maintains compatibility with current Internet; hence, our work keeps the remote TCP peer unaware of the migration process. We describe the latest features of the Linux kernel that allow the migration of a TCP session and a couple of alternatives to divert network packets towards the new destination. Raffaele Bolla, Marco Chiappero, Riccardo Rapuzzi, Matteo Repetto |
PIMRC | 4 |
| 2014 | User-centric mobility management for multimedia content access
Raffaele Bolla, Riccardo Rapuzzi, Matteo Repetto |
Multim. Tools Appl. | 3 |
| 2009 | An Integrated Mobility Framework for Pervasive CommunicationsabstractPervasive communications are greatly affected by mobility issues. Users often move and that implies different devices and networks to become available dynamically. Terminal handovers and session migrations could negatively impact the enjoyment of multimedia content in such scenarios. In this paper, we introduce the concept of personal address and proposed a mobility framework around it, which accounts for all aspects of mobility. Moreover, we describe an implementation of this framework for interactive voice-over-IP and for streaming applications; finally, we report the results from our experimental testbed. Raffaele Bolla, Riccardo Rapuzzi, Matteo Repetto |
GLOBECOM | 3 |
| 2008 | A context-aware architecture for QoS and transcoding management of multimedia streams in smart homesabstractCurrent trends in smart homes suggest that several multimedia services will soon converge towards common standards and platforms. However this rapid evolution gives rise to several issues related to the management of a large number of multimedia streams in the home communication infrastructure. An issue of particular relevance is how a context acquisition system can be used to support the management of such a large number of streams with respect to the Quality of Service (QoS), to their adaptation to the available bandwidth or to the capacity of the involved devices, and to their migration and adaptation driven by the users’ needs that are implicitly or explicitly notified to the system. Under this scenario this paper describes the experience of the INTERMEDIA project in the exploitation of context information to support QoS, migration, and adaptation of multimedia streams. Raffaele Bolla, Matteo Repetto, Saar De Zutter, Rik Van de Walle, Stefano Chessa, Francesco Furfari, Bernhard Reiterer, Hermann Hellwagner, Mark Asbach, Mathias Wien |
ETFA | 2 |
| 2008 | Hybrid optimization for QoS control in IP Virtual Private Networks
Raffaele Bolla, Roberto Bruschi, Franco Davoli, Matteo Repetto |
Comput. Networks | 4 |
| 2007 | Chloe@University: an indoor, mobile mixed reality guidance systemabstractWith the advent of ubiquitous and pervasive computing environments, one of promising applications is a guidance system. In this paper, we propose a mobile mixed reality guide system for indoor environments, [email protected] A mobile computing device (Sony's Ultra Mobile PC) is hidden inside a jacket and a user selects a destination inside a building through voice commands. A 3D virtual assistant then appears in the see-through HMD and guides him/her to destination. Thus, the user simply follows the virtual guide. [email protected] also suggests the most suitable virtual character (e.g. human guide, dog, cat, etc.) based on user preferences and profiles. Depending on user profiles, different security levels and authorizations for content are previewed. Concerning indoor location tracking, WiFi, RFID, and sensor-based methods are integrated in this system to have maximum flexibility. Moreover smart and transparent wireless connectivity provides the user terminal with fast and seamless transition among Access Points (APs). Different AR navigation approaches have been studied: [Olwal 2006], [Elmqvist et al.] and [Newman et al.] work indoors while [Bell et al. 2002] and [Reitmayr and Drummond 2006] are employed outdoors. Accurate tracking and registration is still an open issue and recently it has mostly been tackled by no single method, but mostly through aggregation of tracking and localization methods, mostly based on handheld AR. A truly wearable, HMD based mobile AR navigation aid for both indoors and outdoors with rich 3D content remains an open issue and a very active field of multi-discipline research. Achille Peternier, Xavier Righetti, Mathieu Hopmann, Daniel Thalmann, Matteo Repetto, George Papagiannakis, Pierre Davy, Mingyu Lim, Nadia Magnenat-Thalmann, Paolo Barsocchi, Tasos Fragopoulos, Dimitrios Serpanos, Yiannis Gialelis, Anna Kirykou |
VRST | 5 |
| 2006 | Dynamic Bandwidth Allocation for Wireless Networks in High-Mobility EnvironmentsabstractScarceness of bandwidth is a common problem to all radio networks. The cellular structure with frequency reuse has been the solution for many years in the past; however, decreasing cell sizes results in increasing handoff requests and this could be critical in high mobility environments. Moreover, the cellular structure cannot ensure the best utilization of resources when the distribution of the users inside the system is not constant in time. In this paper we focus on handoff protection and efficient dynamic bandwidth allocation for multi-service networks in high- mobility environments, in presence of very simple strategies for the call admission control, in order to assure scalability. We propose to find an optimal solution by using a new simple heuristic which exploits the prediction of the system behaviour made by some suitable network model; moreover, a more traditional approach based on a stochastic algorithm is derived from the Monte Carlo methods for comparison. Simulation results show that the proposed heuristic approach performs better, especially in critical situations. Raffaele Bolla, Matteo Repetto |
GLOBECOM | 2 |