VLDB 2026 Research / reviewers in the wild / expert
Fulvio Risso
dblp:49/1360
· DBLP profile ↗
67ranked-venue papers
5as first author
15since 2021 · last 2025
0000-0001-6134-7890ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 38 · 5 first-author · 4 since 2021Software engineering, systems software and programming languages · 14 · 6 since 2021Systems, architecture and hardware · 5 · 3 since 2021Human-computer interaction and ubiquitous computing · 2Applied, interdisciplinary, general and emerging computing · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Revisiting WireGuard for Line-rate, Scalable TunnelingabstractDespite widespread adoption, the WireGuard tunneling mechanism available in the Linux kernel is unable to provide high-speed connectivity in a site-to-site setup when leveraging a standard single-tunnel configuration. In fact, its capability to scale with the number of available CPU cores is limited, even in the presence of a software architecture that is intrinsically parallel.This paper proposes multiple techniques to increase the throughput of the WireGuard technology. We show how greater control over the scheduling of WireGuard tasks enables performance optimizations such as NUMA awareness, in both single- and multi-tunnel setups. Finally, we further improve the scalability when leveraging multiple tunnels by proposing a custom Inline architecture tailored to this configuration. This architecture shows an almost 2x performance improvement over a multi-tunnel deployment of vanilla WireGuard, and supports 18x times the throughput of a single tunnel setup on our machines. Mirco Barone, Davide Miola, Federico Parola, Fulvio Risso |
HPSR | 4 |
| 2025 | Sharing GPUs and Programmable Switches in a Federated Testbed with SHARYabstractFederated testbeds enable collaborative research by providing access to diverse resources, including computing power, storage, and specialized hardware like GPUs, programmable switches and smart Network Interface Cards (NICs). Efficiently sharing these resources across federated institutions is challenging, particularly when resources are scarce and costly. GPUs are crucial for AI and machine learning research, but their high demand and expense make efficient management essential. Similarly, advanced experimentation on programmable data plane requires very expensive programmable switches (e.g., based on P4) and smart NICs. This paper introduces SHARY (SHaring Any Resource made easY), a dynamic reservation system that simplifies resource booking and management in federated environments. We show that SHARY can be adopted for heterogenous resources, thanks to an adaptation layer tailored for the specific resource considered. Indeed, it can be integrated with FIGO (Federated Infrastructure for GPU Orchestration), which enhances GPU availability through a demand-driven sharing model. By enabling real-time resource sharing and a flexible booking system, FIGO improves access to GPUs, reduces costs, and accelerates research progress. SHARY can be also integrated with SUP4RNET platform to reserve the access of P4 switches. Stefano Salsano, Andrea Mayer, Paolo Lungaroni, Pierpaolo Loreti, Lorenzo Bracciale, Andrea Detti, Marco Orazi, Paolo Giaccone, Fulvio Risso, Alessandro Cornacchia, Carla Fabiana Chiasserini |
NOMS | 9 |
| 2024 | SURE: Secure Unikernels Make Serverless Computing Rapid and EfficientabstractCurrent serverless platforms introduce non-trivial overheads when chaining and orchestrating loosely-coupled microservices. Containerized function runtimes are also constrained by insufficient isolation and excessive startup time. This motivates our exploration of a more efficient, secure, and rapid serverless design. We describe SURE, a unikernel-based serverless framework for fast function startup, equipped with a high-performance and secure data plane. SURE's data plane supports distributed zero-copy communication via the seamless interaction between zero-copy protocol stack (Z-stack) and local shared memory processing. To establish a lightweight service mesh, SURE uses library-based sidecars instead of individual userspace sidecars. We leverage Intel's Memory Protection Keys (MPK) as a lightweight capability to ensure safe access to the shared memory data plane. It also isolates the Trusted Computing Base (TCB) components in SURE's function runtime (e.g., library-based sidecar, scheduler, etc) from untrusted user code, while preserving the efficient single-address-space nature of unikernels. In particular, SURE prevents unintended privilege escalation involving MPK with an enhanced TCB. These combined efforts create a more secure and robust data plane while improving throughput up to 79X over Knative, a representative open-source serverless platform. Federico Parola, Shixiong Qi, Anvaya B. Narappa, K. K. Ramakrishnan, Fulvio Risso |
SoCC | 5 |
| 2024 | A Next Generation Architecture for Internet of Things in the Automotive Supply Chain for Electric VehiclesabstractThis paper presents a next-generation architecture that focuses on the advancement of edge computing and Internet of Things (IoT) technologies in the context of the automotive supply value chain for electric vehicles (EVs). First, we outline the general architecture design, the specific layers and their goals. Based on the principles of the proposed architecture, we also give a use case for improving the traceability, monitoring and efficiency of EV battery transportation using innovative approaches in federated data spaces, AI-powered inference and orchestration of a multi-objective computational continuum. The automotive supply chain use case is presented with potential Key Performance Indicators (KPIs) while emphasizing the potential impact on operational efficiency, cost reduction and sustainability. By addressing the current limitations in distributed intelligence, data governance, and cross-domain interoperability, we emphasize the importance of real-time data processing, dynamic field governance, and energy-efficient machine learning in the context of the electric vehicle supply chain. At the end of the paper, a discussion and comparative analysis highlights the advances over existing technologies and frameworks and identifies future directions to further improve innovations and applications in this area. Panagiotis Kapsalis, Giovanni Rimassa, Engin Zeydan, Selva Vía, Fulvio Risso, Carla Fabiana Chiasserini, Giulio Vivo |
MobiHoc | 5 |
| 2024 | Benchmarking Different Strategies for Offloading ROS2 Computation to the EdgeabstractMobile robots suffer from inherent limitations due to the tradeoff in the amount of energy consumed by their on-board processing components, and the need to increase their operational time. On the communication side, the volatility of communication links severely hinders the ability of a mobile device to rely on computation offloading. The challenge addressed by this paper is the development of a methodology and framework to effectively migrate the location of a service from a system to another, minimizing downtime and striving to reduce any side-effects that may be perceived by the system. Solving this challenge will pave the way for more effective computation offloading solutions that can cope with the unpredictability of the edge systems. Four different approaches are compared, analyzing their performance via an empirical approach. The insights gathered from data allow the identification of the most promising solution to address the aforementioned challenge. Daniele Cacciabue, Jacopo Marino, Francesco Aglieco, Marco Levorato, Domenico Perroni, Fulvio Risso |
NetSoft | 6 |
| 2024 | Building the Cloud Continuum with REARabstractThe computing continuum combines computational resources and services from edge to cloud, promising enhanced efficiency and resilience with respect to the traditional siloed-based approach. This study presents the REAR (Resource Advertisement and Reservation) protocol, which tackles the complexities of managing resources within this continuum. REAR establishes standardized interfaces to enable interoperability, enhances resource allocation efficiency, and maintains security measures for workload execution. The paper details the protocol’s design, key components, operational workflows, and potential uses, contributing to the optimization of resource use across the computing continuum. Stefano Galantino, Elisa Albanese, Nasir Asadov, Stefano Braghin, Francesco Cappa, Andrea Colli-Vignarelli, Amjad Yousef Majid, Eduard Marin, Jacopo Marino, Lorenzo Moro, Liubov Nedoshivina, Fulvio Risso, Domenico Siracusa, Antonio F. Skarmeta, Luca Zuanazzi |
NetSoft | 12 |
| 2024 | Measuring the Cost of the Linux Network Stack in Real-TimeabstractAs network interfaces in the data center get faster and faster, and an increasingly big portion of the services is implemented in software, we must wonder just how much time our servers’ CPUs are spending handling network traffic. This paper explores the feasibility of measuring the cost of the entire in-kernel network stack in real-time on production systems by relying on the eBPF tracing capabilities instead of utilizing custom logic or kernel patching. We describe two methods that have been attempted, respectively based on an "exact" instrumentation of the stack and sampling, along with the advantages and defects of each approach. Davide Miola, Fulvio Risso, Federico Parola |
NetSoft | 2 |
| 2024 | Morpheus: A Run Time Compiler and Optimizer for Software Data PlanesabstractState-of-the-art approaches to design, develop and optimize software packet-processing programs are based on static compilation: the compiler’s input is a description of the forwarding plane semantics and the output is a binary that can accommodate any control plane configuration or input traffic. In this paper, we demonstrate that tracking control plane actions and packet-level traffic dynamics at run time opens up new opportunities for code specialization. We present Morpheus, a system working alongside static compilers that continuously optimizes the targeted networking code. We introduce a number of new techniques, from static code analysis to adaptive code instrumentation, and we implement a toolbox of domain specific optimizations that are not restricted to a specific data plane framework or programming language. We apply Morpheus to several systems, from eBPF and DPDK programs including Katran, Meta’s production-grade load balancer to container orchestration solutions such a Kubernets. We compare Morpheus to state-of-the-art optimization frameworks and show that it can bring up to 2x throughput improvement, while halving the 99th percentile latency. Sebastiano Miano, Alireza Sanaee, Fulvio Risso, Gábor Rétvári, Gianni Antichi |
IEEE/ACM Trans. Netw. | 3 |
| 2023 | Platoon-Local Dynamic Map: Micro cloud support for platooning cooperative perceptionabstractPlatooning is a popular vehicular application for autonomous driving on which the Platoon Leader (PL) manages all maneuvers using context information from Vehicle-to-Vehicle (V2V) messages. However, redundant context information from nearby vehicles in the platoon can increase computational costs for the PL. To solve this issue, vehicular micro-clouds can be formed to enable collective data processing and aggregation, thus reducing the PL’s perception workload. The proposed solution, called Platoon Local Dynamic Map (P-LDM), creates a single database of context information, distributing the data aggregation load among all members of the platoon. Simulation results evaluate the effectiveness of the proposed solution and compare it to typical Cooperative Perception mechanisms. Carlos Mateo Risma Carletti, Claudio Casetti, Jérôme Härri, Fulvio Risso |
WiMob | 4 |
| 2023 | Computing Without Borders: The Way Towards Liquid ComputingabstractDespite the de-facto technological uniformity fostered by the cloud and edge computing paradigms, resource fragmentation across isolated clusters hinders the dynamism in application placement, leading to suboptimal performance and operational complexity. Building upon and extending these paradigms, we propose a novel approach envisioning a transparent continuum of resources and services on top of the underlying fragmented infrastructure, calledliquid computing. Fully decentralized, multi-ownership-oriented and intent-driven, it enables an overarching abstraction for improved applications execution, while at the same time opening up for new scenarios, including resource sharing and brokering. Following the above vision, we presentliqo, an open-source project that materializes this approach through the creation of dynamic and seamless Kubernetes multi-cluster topologies. Extensive experimental evaluations have shown its effectiveness in different contexts, both in terms of Kubernetes overhead and compared to other open-source alternatives. Marco Iorio, Fulvio Risso, Alex Palesandro, Leonardo Camiciotti, Antonio Manzalini |
IEEE Trans. Cloud Comput. | 2 |
| 2022 | Domain specific run time optimization for software data planesabstractState-of-the-art approaches to design, develop and optimize software packet-processing programs are based on static compilation: the compiler's input is a description of the forwarding plane semantics and the output is a binary that can accommodate any control plane configuration or input traffic. Sebastiano Miano, Alireza Sanaee, Fulvio Risso, Gábor Rétvári, Gianni Antichi |
ASPLOS | 3 |
| 2022 | Creating Disaggregated Network Services with eBPF: the Kubernetes Network Provider Use CaseabstractThe eBPF technology enables the creation of custom and highly efficient network services, running in the Linux kernel, tailored to the precise use case under consideration. However, the most prominent examples of such network services in eBPF follow a monolithic approach, in which all required code is created within the same program block. This makes the code hard to maintain, to extend, and difficult to reuse in other use cases. This paper leverages the Polycube framework to demonstrate that a disaggregated approach is feasible also with eBPF, with minimal overhead, introducing a larger degree of code reusability. This paper considers a complex network scenario, such as a complete network provider for Kubernetes, presenting the resulting architecture and a preliminary performance evaluation. Federico Parola, Leonardo Di Giovanna, Giuseppe Ognibene, Fulvio Risso |
NetSoft | 4 |
| 2021 | Assessing the performance of XDP and AF_XDP based NFs in edge data center scenariosabstractWhile servers in traditional data centers can be specialized to run either CPU-intensive or network-intensive workloads, edge data centers need to consolidate both on the same machine(s) due to the reduced number of servers. This paper presents some preliminary experiments to determine how to improve the overall throughput of the above servers, being XDP and AF_XDP the two main technologies into play. Federico Parola, Roberto Procopio, Fulvio Risso |
CoNEXT | 3 |
| 2021 | Providing Telco-oriented Network Services with eBPF: the Case for a 5G Mobile GatewayabstractAlthough several technologies exist for high-speed data plane processing, such as DPDK, the above technologies require a rigid partitioning of the resources of the system, such as dedicated CPU cores and network interfaces. Unfortunately, this is not always possible when running at the edge of the network, in which a few servers are available in each cluster and a mixture of data and control plane services must coexist on the same hardware. In this respect, eBPF can become a better alternative thanks to its integration in the vanilla Linux kernel, which enables contemporary support for data and control plane services, hence enabling a more efficient usage of the (scarce) computing resources. This paper proposes the first proof-of-concept open-source implementation of a 5G Mobile Gateway based on eBPF/XDP, highlighting the possible challenges (e.g., to create traffic policers, as buffering is not available in eBPF) and the resulting architecture. The result is characterized in terms of performance and scalability and compared with alternative technologies, showing that it outperforms other in-kernel solutions (e.g., Open vSwitch) and is comparable with DPDK-based platforms. Federico Parola, Fulvio Risso, Sebastiano Miano |
NetSoft | 2 |
| 2021 | A Framework for eBPF-Based Network Functions in an Era of MicroservicesabstractBy moving network functionality from dedicated hardware to software running on end-hosts, Network Functions Virtualization (NFV) pledges the benefits of cloud computing to packet processing. While most of the NFV frameworks today rely on kernel-bypass approaches, no attention has been given to kernel packet processing, which has always proved hard to evolve and to program. In this article, we present Polycube, a software framework whose main goal is to bring the power of NFV to in-kernel packet processing applications, enabling a level of flexibility and customization that was unthinkable before. Polycube enables the creation of arbitrary and complex network function chains, where each function can include an efficient in-kernel data plane and a flexible user-space control plane with strong characteristics of isolation, persistence, and composability. Polycube network functions, called Cubes, can be dynamically generated and injected into the kernel networking stack, without requiring custom kernels or specific kernel modules, simplifying the debugging and introspection, which are two fundamental properties in recent cloud environments. We validate the framework by showing significant improvements over existing applications, and we prove the generality of the Polycube programming model through the implementation of complex use cases such as a network provider for Kubernetes. Sebastiano Miano, Fulvio Risso, Mauricio Vásquez Bernal, Matteo Bertrone, Yunsong Lu |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2019 | A Service-Agnostic Software Framework for Fast and Efficient in-Kernel Network ServicesabstractThis paper presents Polycube, an open-source software framework based on eBPF, that enables the creation of arbitrary and complex network function chains. Each function can include an efficient in-kernel data plane and a flexible user-space control plane with strong characteristics of isolation, persistence (e.g., across server reboots)and composability. In addition, a generic model for the control and management plane of each network function simplifies the manageability and accelerates the development of new network services. We validate the framework by creating different network services and benchmarking their performance in a complex scenario, namely a network provider for Kubernetes. Results show that Polycube programs are about 20x shorter than equivalent programs implemented with vanilla-eBPF. Sebastiano Miano, Matteo Bertrone, Fulvio Risso, Mauricio Vásquez Bernal, Yunsong Lu, Jianwen Pi, Aasif Shaikh |
ANCS | 3 |
| 2019 | A Distributed Orchestration Algorithm for Edge Computing Resources with GuaranteesabstractEdge Computing brings flexibility and scalability of virtualization technologies at the edge of the network, enabling service providers to deploy new applications over a richer network infrastructure. However, the coexistence of such variety of applications on the same infrastructure exacerbates the already challenging problem of coordinating resource allocation while preserving the resource assignment optimality. In fact, (i) each application can potentially require different optimization criteria due to their heterogeneous requirements, and (ii) we may not count on a centralized orchestrator due to the highly dynamic nature of edge networks. To solve this problem, we present DRAGON, a Distributed Resource AssiGnment and OrchestratioN algorithm that seeks optimal partitioning of shared resources between different applications running over a common edge infrastructure. We designed DRAGON to guarantee both a bound on convergence time and an optimal (1-1/e)-approximation with respect to the Pareto optimal resource assignment. We evaluate convergence and performance of DRAGON on a prototype implementation, assessing the benefits compared to traditional orchestration approaches. Gabriele Castellano, Flavio Esposito, Fulvio Risso |
INFOCOM | 3 |
| 2019 | A Disaggregated MEC Architecture Enabling Open Services and Novel Business ModelsabstractNetwork and Service Providers are exploring different exploitation strategies for the Multi-access Edge Computing (MEC), mainly motivated by the opportunities for saving costs and generating new revenues (e.g., through new business models). On the other hand, the overall standardization picture is still very fragmented, delaying or even jeopardizing the real exploitation of MEC; furthermore, current standardization efforts are mainly envisioning a traditional monolithic architecture, with many technological partners but a single administrative domain. This paper argues that a clear separation of IaaS, PaaS and SaaS levels for MEC, together with standardized interfaces, will help accelerating the development of new business roles (e.g., IaaS, PaaS and SaaS providers) and models, possibly replacing the current competition-oriented practices in the telco domain with new forms of cooperation, which are already starting to appear in the IT sector. In this direction, this paper proposes a disaggregated MEC architecture and presents two use cases that show how different categories of resources and services could be provided by infrastructure, platform and software providers in an evolutionary scenario towards 5G. Gabriele Castellano, Antonio Manzalini, Fulvio Risso |
NetSoft | 3 |
| 2019 | A Service-Defined Approach for Orchestration of Heterogeneous Applications in Cloud/Edge PlatformsabstractEdge Computing is moving resources toward the network borders, thus enabling the deployment of a pool of new applications that benefit from the new distributed infrastructure. However, due to the heterogeneity of such applications, specific orchestration strategies need to be adopted for each deployment request. Each application can potentially require different optimization criteria and may prefer particular reactions upon the occurrence of the same event. This paper presents a Service-Defined approach for orchestrating cloud/edge services in a distributed fashion, where each application can define its own orchestration strategy by means of declarative statements, which are parsed into a Service-Defined Orchestrator (SDO). Moreover, to coordinate the coexistence of a variety of SDOs on the same infrastructure while preserving the resource assignment optimality, we present DRAGON, a Distributed Resource AssiGnment and OrchestratioN algorithm that seeks optimal partitioning of shared resources between different actors. We evaluate the advantages of our novel Service-Defined orchestration approach over some representative edge use cases, as well as measure convergence and performance of DRAGON on a prototype implementation, assessing the benefits compared to conventional orchestration approaches. Gabriele Castellano, Flavio Esposito, Fulvio Risso |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2018 | A New Paradigm to Address Threats for Virtualized ServicesabstractWith the uptaking of virtualization technologies and the growing usage of public cloud infrastructures, an ever larger number of applications run outside of the traditional enterprise's perimeter, and require new security paradigms that fit the typical agility and elasticity of cloud models in service creation and management. Though some recent proposals have integrated security appliances in the logical application topology, we argue that this approach is sub-optimal. Indeed, we believe that embedding security agents in virtualization containers and delegating the control logic to the software orchestrator provides a much more effective, flexible, and scalable solution to the problem. In this paper, we motivate our mindset and outline a novel framework for assessing cyber-threats of virtualized applications and services. We also review existing technologies that build the foundation of our proposal, which we are going to develop in the context of a joint research project. Stefan Covaci, Matteo Repetto, Fulvio Risso |
COMPSAC (2) | 3 |
| 2018 | Creating Complex Network Services with eBPF: Experience and Lessons LearnedabstractThe extended Berkeley Packet Filter (eBPF) is a recent technology available in the Linux kernel that enables flexible data processing. However, so far the eBPF was mainly used for monitoring tasks such as memory, CPU, page faults, traffic, and more, with a few examples of traditional network services, e.g., that modify the data in transit. In fact, the creation of complex network functions that go beyond simple proof-of-concept data plane applications has proven to be challenging due to the several limitations of this technology, but at the same time very promising due to some characteristics (e.g., dynamic recompilation of the source code) that are not available elsewhere. Based on our experience, this paper presents the most promising characteristics of this technology and the main encountered limitations, and we envision some solutions that can mitigate the latter. We also summarize the most important lessons learned while exploiting eBPF to create complex network functions and, finally, we provide a quantitative characterization of the most significant aspects of this technology. Sebastiano Miano, Matteo Bertrone, Fulvio Risso, Massimo Tumolo, Mauricio Vásquez Bernal |
HPSR | 3 |
| 2018 | Enabling precise traffic filtering based on protocol encapsulation rules
Ivano Cerrato, Fulvio Risso |
Comput. Networks | 2 |
| 2018 | COMPOSER: A compact open-source service platform
Ivano Cerrato, Fulvio Risso, Roberto Bonafiglia, Kostas Pentikousis, Gergely Pongrácz, Hagen Woesner |
Comput. Networks | 2 |
| 2018 | An efficient data exchange mechanism for chained network functions
Ivano Cerrato, Guido Marchetto, Fulvio Risso, Riccardo Sisto, Matteo Virgilio, Roberto Bonafiglia |
J. Parallel Distributed Comput. | 3 |
| 2017 | An adaptive scaling mechanism for managing performance variations in network functions virtualization: A case study in an NFV-based EPCabstractThe scaling is a fundamental task that allows addressing performance variations in Network Functions Virtualization (NFV). In the literature, several approaches propose scaling mechanisms that differ in the utilized technique (e.g., reactive, predictive and machine learning-based). The scaling in NFV must be accurate both at the time and the number of instances to be scaled, aiming at avoiding unnecessary procedures of provisioning and releasing of resources; however, achieving a high accuracy is a non-trivial task. In this paper, we propose for NFV an adaptive scaling mechanism based on Q-Learning and Gaussian Processes that are utilized by an agent to carry out an improvement strategy of a scaling policy, and therefore, to make better decisions for managing performance variations. We evaluate our mechanism by simulations, in a case study in a virtualized Evolved Packet Core, corroborating that it is more accurate than approaches based on static threshold rules and Q-Learning without a policy improvement strategy. Carlos Hernan Tobar Arteaga, Fulvio Risso, Oscar M. Caicedo |
CNSM | 2 |
| 2017 | A Unifying Orchestration Operating Platform for 5G
Antonio Manzalini, Marco Di Girolamo, Giuseppe Celozzi, Fulvio Bruno, Giuliana Carullo, Marco Tambasco, Gino Carrozzo, Fulvio Risso, Gabriele Castellano |
GPC | 8 |
| 2017 | NFV service dynamicity with a DevOps approach: Insights from a use-case realizationabstractThis experience paper describes the process of leveraging the NFV orchestration platform built in the EU FP7 project UNIFY to deploy a dynamic network service exemplified by an elastic router. Elasticity is realized by scaling dataplane resources as a function of traffic load. To achieve this, the service includes a custom scaling logic and monitoring capabilities. An automated monitoring framework not only triggers elastic scaling, but also a troubleshooting process which detects and analyzes anomalies, pro-actively aiding both dev and ops personnel. Such a DevOps-inspired approach enables a shorter update cycle to the running service. We highlight multiple learnings yielded throughout the prototype realization, focussing on the functional areas of service decomposition and scaling; programmable monitoring; and automated troubleshooting. Such practical insights will contribute to solving challenges such as agile deployment and efficient resource usage in future NFV platforms. Steven van Rossem, Xuejun Cai, Ivano Cerrato, Per Danielsson, Felician Németh, Bertrand Pechenot, István Pelle, Fulvio Risso, Sachin Sharma 0001, Pontus Sköldström, Wolfgang John |
IM | 8 |
| 2017 | NFV service dynamicity with a DevOps approachabstractNext generation network services will be realized by NFV-based microservices to enable greater dynamics in deployment and operations. Here, we present a demonstrator that realizes this concept using the NFV platform built in the EU FP7 project UNIFY. Using the example of an Elastic Router service, we show automated deployment and configuration of service components as well as corresponding monitoring components facilitating automated scaling of the entire service. We also demonstrate automatic execution of troubleshooting and debugging actions. Operations of the service are inspired by DevOps principles, enabling quick detection of operational conditions and fast corrective actions. This demo conveys essential insights on how the life-cycle of an NFV-based network service may be realized in future NFV platforms. Steven van Rossem, Xuejun Cai, Ivano Cerrato, Per Danielsson, Felician Németh, Bertrand Pechenot, István Pelle, Fulvio Risso, Sachin Sharma 0001, Pontus Sköldström, Wolfgang John |
IM | 8 |
| 2017 | End-to-end service orchestration across SDN and cloud computing domainsabstractThis paper presents an open-source orchestration framework that deploys end-to-end services across OpenStack-managed data centers and SDN networks controlled either by ONOS or OpenDaylight. The proposed framework improves existing software in two directions. First, it exploits SDN domains not only to implement traffic steering, but also to execute selected network functions (e.g., NAT). Second, it can deploy a service by partitioning the original service graph into multiple subgraphs, each one instantiated in a different domain, dynamically connected by means of traffic steering rules and parameters (e.g. VLAN IDs) negotiated at run-time. Roberto Bonafiglia, Gabriele Castellano, Ivano Cerrato, Fulvio Risso |
NetSoft | 4 |
| 2017 | Mimicking a compute domain orchestrator with the ONOS SDN controllerabstractWith the NFV paradigm, network services are usually instantiated in datacenters (e.g., as VMs), while software-defined networks provide just plain connectivity. However, common SDN controllers can do much more than just traffic steering; particularly they can execute network applications such as NAT, DHCP, and more. This paper presents a software architecture that can advertise an SDN domain as having compute capabilities, hence enabling an overarching multi-domain orchestrator to instantiate a network function either in a cloud or in an SDN domain. This allows an overarching orchestrator to fully exploit the processing capability of an SDN infrastructure and potentially enabling more aggressive optimization strategies across domains. Gabriele Castellano, Ivano Cerrato, Fulvio Risso, Davide Pezzolla, Antonio Manzalini |
NetSoft | 3 |
| 2017 | Per-user NFV services with mobility supportabstractThis paper presents an architecture to provide endto- end per-user services with support to client mobility, designed according to the SDN and NFV paradigms. Our service platform dynamically configures and launches service requests when the client connects to the network, which are used by a multidomain orchestration system to arrange the required network configuration and computational resources. Service configuration is dynamically updated when a movement of the client is detected, that is, when a client device changes its access point to the network. A prototype implementing the idea has been developed and validated over JOLNET, a real, geographical, OpenFlowbased experimental network connecting several sites in Italy and operated by Telecom Italia. Matteo D'Ambrosio, Mario Ullio, Vinicio Vercellone, Ivano Cerrato, Fulvio Risso |
NetSoft | 5 |
| 2017 | A unifying operating platform for 5G end-to-end and multi-layer orchestrationabstractHeterogeneity of current software solutions for 5G is heading for complex and costly situations, with high fragmentation, which in turn creates uncertainty and the risk of delaying 5G innovations. This context motivated the definition of a novel Operating Platform for 5G (5G-OP), a unifying reference functional framework supporting end-to-end and multi-layer orchestration. 5G-OP aims at integrated management, control and orchestration of computing, storage, memory, networking core and edge resources up to the end-user devices and terminals (e.g., robots and smart vehicles). 5G-OP is an overarching architecture, with agnostic interfaces and well-defined abstractions, offering the seamless integration of current and future infrastructure control and orchestration solutions (e.g., OpenDaylight, ONOS, OpenStack, Apache Mesos, OpenSource MANO, Docker, LXC, etc.) The paper provides also the description of a prototype that can be seen as a simplified version of a 5G-OP, whose feasibility has been demonstrated in Focus Group IMT2020 of ITU-T. Antonio Manzalini, Diego R. López, Håkon Lønsethagen, Lucian Suciu, Roberto Bifulco, Marie-Paule Odini, Giuseppe Celozzi, Barbara Martini, Fulvio Risso, Jokin Garay, Vassilis Foteinos, Panagiotis Demestichas, Giuliana Carullo, Marco Tambasco, Gino Carrozzo |
NetSoft | 9 |
| 2017 | Enforcement of dynamic HTTP policies on resource-constrained residential gateways
Roberto Bonafiglia, Amedeo Sapio, Mario Baldi, Fulvio Risso, Paolo C. Pomi |
Comput. Networks | 4 |
| 2016 | Modeling Native Software Components as Virtual Network FunctionsabstractVirtual Network Functions (VNFs) are often realized using virtual machines (VMs) because they provide an isolated environment compatible with classical cloud computing technologies. However, VMs are demanding in terms of required resources (CPU and memory) and therefore not suitable for low-cost devices like residential gateways. Such equipment often runs a Linux-based operating system that includes by default a (large) number of common network functions, which can provide some of the services otherwise offered by simple VNFs, but with reduced overhead. In this paper those native software components are made available through a Network Function Virtualization (NFV) platform, thus making their use transparent from the VNF developer point of view. Mario Baldi, Roberto Bonafiglia, Fulvio Risso, Amedeo Sapio |
SIGCOMM | 3 |
| 2016 | A Transparent Highway for inter-Virtual Network Function Communication with Open vSwitchabstractThis paper presents a software architecture that can dynamically and transparently establish direct communication paths between DPDK-based virtual network functions executed in virtual machines, by recognizing new point-to-point connections in traffic steering rules. We demonstrate the huge advantages of this architecture in terms of performance and the possibility to implement it with localized modifications in Open vSwitch and DPDK, without touching the VNFs. Mauricio Vásquez Bernal, Ivano Cerrato, Fulvio Risso, David Verbeiren |
SIGCOMM | 3 |
| 2016 | Scalable Algorithms for NFA Multi-Striding and NFA-Based Deep Packet Inspection on GPUsabstractFinite state automata (FSA) are used by many network processing applications to match complex sets of regular expressions in network packets. In order to make FSA-based matching possible even at the ever-increasing speed of modern networks, multi-striding has been introduced. This technique increases input parallelism by transforming the classical FSA that consumes input byte by byte into an equivalent one that consumes input in larger units. However, the algorithms used today for this transformation are so complex that they often result unfeasible for large and complex rule sets. This paper presents a set of new algorithms that extend the applicability of multi-striding to complex rule sets. These algorithms can transform nondeterministic finite automata (NFA) into their multi-stride form with reduced memory and time requirements. Moreover, they exploit the massive parallelism of graphical processing units for NFA-based matching. The final result is a boost of the overall processing speed on typical regex-based packet processing applications, with a speedup of almost one order of magnitude compared to the current state-of-the-art algorithms. Matteo Avalle, Fulvio Risso, Riccardo Sisto |
IEEE/ACM Trans. Netw. | 2 |
| 2015 | Offloading personal security applications to a secure and trusted network nodeabstractThe current device-centric protection model against security threats has serious limitations from the final user perspective, among the other the necessity to keep each device updated with the latest security updates and the necessity to replicate all the security polices across all devices. In our model, the protection is decoupled from the users terminals and it is provided through a Trusted Virtual Domain (TVD) instantiated in future edge routers. Each TVD provides unified and homogeneous security for a single user, irrespective of the terminal employed. This paper shows a first prototype implementing this concept through a network element, called Network Edge Device, capable of running the proposed virtualized architecture and making extensive use of SDN technologies, with the aim at providing a uniform security level for the final user. Roberto Bonafiglia, Francesco Ciaccia, Antonio Lioy, Mario Nemirovsky, Fulvio Risso |
NetSoft | 5 |
| 2015 | Introducing network-aware scheduling capabilities in OpenStackabstractThis paper motivates and describes the introduction of network-aware scheduling capabilities in OpenStack, the open-source reference framework for creating public and private clouds. This feature represents the key for properly supporting the Network Function Virtualization paradigm, particularly when the physical infrastructure features servers distributed across a geographical region. This paper also describes the modifications required to the compute and network components, Nova and Neutron, and the integration of a network controller into the cloud infrastructure, which is in charge of feeding the network-aware scheduler with the actual network topology. Francesco Lucrezia, Guido Marchetto, Fulvio Risso, Vinicio Vercellone |
NetSoft | 3 |
| 2015 | Multi-Domain Service Orchestration Over Networks and Clouds: A Unified ApproachabstractEnd-to-end service delivery often includes transparently inserted Network Functions (NFs) in the path. Flexible service chaining will require dynamic instantiation of both NFs and traffic forwarding overlays. Virtualization techniques in compute and networking, like cloud and Software Defined Networking (SDN), promise such flexibility for service providers. However, patching together existing cloud and network control mechanisms necessarily puts one over the above, e.g., OpenDaylight under an OpenStack controller. We designed and implemented a joint cloud and network resource virtualization and programming API. In this demonstration, we show that our abstraction is capable for flexible service chaining control over any technology domains. Balázs Sonkoly, János Czentye, Róbert Szabó, Dávid Jocha, János Elek, Sahel Sahhaf, Wouter Tavernier, Fulvio Risso |
SIGCOMM | 8 |
| 2015 | Toward dynamic virtualized network services in telecom operator networks
Ivano Cerrato, Alex Palesandro, Fulvio Risso, Marc Suñé, Vinicio Vercellone, Hagen Woesner |
Comput. Networks | 3 |
| 2015 | Modeling Complex Packet Filters With Finite State AutomataabstractDesigning an efficient and scalable packet filter for modern computer networks becomes more challenging each day: Faster link speeds, the steady increase in the number of encapsulation rules (e.g., tunneling), and the necessity to precisely isolate a given subset of traffic cause filtering expressions to become more complex than in the past. Most current packet filtering mechanisms cannot deal with those requirements because their optimization algorithms either cannot scale with the increased size of the filtering code or exploit simple domain-specific optimizations that cannot guarantee to operate properly in case of complex filters. This paper presents pFSA, a new model that transforms packet filters into finite state automata and guarantees the optimal number of checks on the packet, also in case of multiple filters composition, hence enabling efficiency and scalability without sacrificing filtering computation time. Marco Leogrande, Fulvio Risso, Luigi Ciminiera |
IEEE/ACM Trans. Netw. | 2 |
| 2014 | An efficient data exchange algorithm for chained network functionsabstractIn-network function chaining often involves the deployment of multiple applications into a single, possibly multi-tenant, middlebox. This approach has gained much interest since new network paradigms, such as Software Defined Networking (SDN) and Network Function Virtualization (NFV), have been proposed to virtualize resources as well as network functions. In this scenario, it is very common to move data (e.g., packets) from an application to another by means of a switching module that is in charge of chaining network functions in the correct order, also ensuring an adequate level of isolation between any two virtualized components. With this purpose in mind, this paper proposes an efficient algorithm to handle the communication between the internal soft-switch and the heterogeneous network functions that are executed on the same server. Our proposal is designed with the aim of dealing with high speed packet processing, hence an extensive performance evaluation is also provided to prove the goodness of our solution in this context. Ivano Cerrato, Guido Marchetto, Fulvio Risso, Riccardo Sisto, Matteo Virgilio |
HPSR | 3 |
| 2012 | Efficient multistriding of large non-deterministic finite state automata for deep packet inspectionabstractMultistride automata speed up input matching because each multistriding transformation halves the size of the input string, leading to a potential 2× speedup. However, up to now little effort has been spent in optimizing the building process of multistride automata, with the result that current algorithms cannot be applied to real-life, large automata such as the ones used in commercial IDSs, because the time and the memory space needed to create the new automaton quickly becomes unfeasible. In this paper, new algorithms for efficient building of multistride NFAs for packet inspection are presented, explaining how these new techniques can outperform the previous algorithms in terms of required time and memory usage. Matteo Avalle, Fulvio Risso, Riccardo Sisto |
ICC | 2 |
| 2012 | CLOSER: A Collaborative Locality-Aware Overlay SERviceabstractCurrent Peer-to-Peer (P2P) file sharing systems make use of a considerable percentage of Internet Service Providers (ISPs) bandwidth. This paper presents the Collaborative Locality-aware Overlay SERvice (CLOSER), an architecture that aims at lessening the usage of expensive international links by exploiting traffic locality (i.e., a resource is downloaded from the inside of the ISP whenever possible). The paper proves the effectiveness of CLOSER by analysis and simulation, also comparing this architecture with existing solutions for traffic locality in P2P systems. While savings on international links can be attractive for ISPs, it is necessary to offer some features that can be of interest for users to favor a wide adoption of the application. For this reason, CLOSER also introduces a privacy module that may arouse the users' interest and encourage them to switch to the new architecture. Marco Papa Manzillo, Luigi Ciminiera, Guido Marchetto, Fulvio Risso |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2011 | Modeling Filtering Predicates Composition with Finite State AutomataabstractNetwork virtualization has gained a lot of attention recently, because of some new interesting proposals in the field (i.e. Open Flow). This trend has had the effect of pushing some filtering operations up at the software level: i.e. extract a potentially large number of protocol fields from a packet, or dynamically combine different filters. The time constraints of working at line rate force the creation of a packet filter model that can guarantee the minimum number of packet checks. This poster proposes mp FSA, a packet filter model based on the Finite State Automata formalism, that aims at achieving optimality w.r.t. the number of packet accesses, without sacrificing efficiency and scalability. Marco Leogrande, Luigi Ciminiera, Fulvio Risso |
ANCS | 3 |
| 2011 | Robustness analysis of an unstructured overlay for media communicationabstractThe wide diffusion of network address translators (NATs) (and, in some respect, firewalls) may prevent some applications that require direct end-to-end connectivity (e.g. real-time media) from being able to connect to the remote party. Although the solutions currently adopted rely on centralised nodes as third party relays, the distributed connectivity service (DISCOS) architecture has been recently proposed and aims at distributing such functionalities across a peer-to-peer (P2P) overlay. The original study presented some performance characteristics of the overlay, but the ability to resist to both failures and attacks was not taken into consideration. This study illustrates the robustness feature of the DISCOS overlay and suggests some minor modifications to the original mechanisms, in order to improve the overall robustness. The key component of DISCOS is its dynamic scale-free topology. Hence, the study also extends the existing literature concerning the robustness of scale-free networks, which considers only static graphs. Guido Marchetto, Marco Papa Manzillo, Livio Torrero, Luigi Ciminiera, Fulvio Risso |
IET Commun. | 5 |
| 2011 | Locating Equivalent Servants over P2P NetworksabstractWhile peer-to-peer networks are mainly used to locate unique resources across the Internet, new interesting deployment scenarios are emerging. Particularly, some applications (e.g., VoIP) are proposing the creation of overlays for the localization of services based on equivalent servants (e.g., voice relays). This paper explores the possible overlay architectures that can be adopted to provide such services, showing how an unstructured solution based on a scale-free overlay topology is an effective option to deploy in this context. Consequently, we propose EQUATOR (EQUivalent servAnt locaTOR), an unstructured overlay implementing the above mentioned operating principles, based on an overlay construction algorithm that well approximates an ideal scale-free construction model. We present both analytical and simulation results which support our overlay topology selection and validate the proposed architecture. Guido Marchetto, Luigi Ciminiera, Marco Papa Manzillo, Fulvio Risso, Livio Torrero |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2011 | SPAF: stateless FSA-based packet filtersabstractWe propose a stateless packet filtering technique based on finite-state automata (FSA). FSAs provide a comprehensive framework with well-defined composition operations that enable the generation of stateless filters from high-level specifications and their compilation into efficient executable code without resorting to various opportunistic optimization algorithms. In contrast with most traditional approaches, memory safety and termination can be enforced with minimal run-time overhead even in cyclic filters, thus enabling full parsing of complex protocols and supporting recursive encapsulation relationships. Experimental evidence shows that this approach is viable and improves the state of the art in terms of filter flexibility, performance, and scalability without incurring in the most common FSA deficiencies, such as state-space explosion. Pierluigi Rolando, Riccardo Sisto, Fulvio Risso |
IEEE/ACM Trans. Netw. | 3 |
| 2010 | A Tunnel-Aware Language for Network Packet FilteringabstractWhile in computer networks the number of possible protocol encapsulations is growing day after day, network admin- istrators face ever increasing difficulties in selecting accurately the traffic they need to inspect. This is mainly caused by the limited number of encapsulations supported by currently available tools and the difficulty to exactly specify which packets have to be analyzed, especially in presence of tunneled traffic. This paper presents a novel packet processing language that, besides Boolean filtering predicates, introduces special constructs for handling the more complex situations of tunneled and stacked encapsulations, giving the user a finer control over the semantics of a filtering expression. Even though this language is principally focused on packet filters, it is designed to support other advanced packet processing mechanisms such as traffic classification and field extraction. Luigi Ciminiera, Marco Leogrande, Fulvio Risso, Olivier Morandi |
GLOBECOM | 4 |
| 2010 | Comparing P2PTV Traffic ClassifiersabstractAbstract—Peer-to-Peer IP Television (P2PTV) applications represent one of the fastest growing application classes on the Internet, both in terms of their popularity and in terms of the amount of traffic they generate. While network operators require monitoring tools that can effectively analyze the traffic produced by these systems, few techniques have been tested on these mostly closed-source, proprietary applications. In this paper we examine the properties of three traffic classifiers applied to the problem of identifying P2PTV traffic. We report on extensive experiments conducted on traffic traces with reliable ground truth information, highlighting the benefits and shortcomings of each approach. The results show that not only their performance in terms of accuracy can vary significantly, but also that their usability features suggest different effective aspects that can be integrated. I. Niccolo Cascarano, Fulvio Risso, Alice Este, Francesco Gringoli, Luca Salgarelli, Alessandro Finamore, Marco Mellia |
ICC | 2 |
| 2009 | An Experimental Evaluation of the Computational Cost of a DPI Traffic ClassifierabstractA common belief in the scientific community is that traffic classifiers based on deep packet inspection (DPI) are far more expensive in terms of computational complexity compared to statistical classifiers. In this paper we counter this notion by defining accurate models for a deep packet inspection classifier and a statistical one based on support vector machines, and by evaluating their actual processing costs through experimental analysis. The results suggest that, contrary to the common belief, a DPI classifier and an SVM-based one can have comparable computational costs. Although much work is left to prove that our results apply in more general cases, this preliminary analysis is a first indication of how DPI classifiers might not be as computationally complex, compared to other approaches, as we previously thought. Niccolo Cascarano, Alice Este, Francesco Gringoli, Fulvio Risso, Luca Salgarelli |
GLOBECOM | 4 |
| 2009 | Increasing performances of TCP data transfers through multiple parallel connectionsabstractAlthough Transmission Control Protocol (TCP) is a widely deployed and successful protocol, it shows some limitations in present-day environments. In particular, it is unable to exploit multiple (physical or logical) paths between two hosts. This paper presents PATTHEL, a session-layer solution designed for parallelizing stream data transfers. Parallelization is achieved by striping the data flow among multiple TCP channels. This solution does not require invasive changes to the networking stack and can be implemented entirely in user space. Moreover, it is flexible enough to suit several scenarios - e.g. it can be used to split a data transfer among multiple relays within a peer-to-peer overlay network. Andrea Baldini, Lorenzo De Carli, Fulvio Risso |
ISCC | 3 |
| 2008 | Design and implementation of a framework for creating portable and efficient packet-processing applicationsabstractIt is a common belief that using a virtual machine for portable executions of data-plane packet-processing applications would introduce too many penalties in terms of performance, because of the assumed overhead caused by the presence of a hardware abstraction layer. Even if common sense proves true in the case of general purpose virtual machines, such as the JVM and the CLR, it may be wrong in case of a special-purpose network-oriented virtual machine. This paper describes the architecture of a run-time environment and a compiler infrastructure for the Network Virtual Machine (NetVM), showing that the portability of packet-processing programs can be achieved without additional penalties even over heterogeneous platforms. Our implementation supports three different target architectures: one with a general purpose processor (Intel x86), one with a multi-core network processor (Cavium Octeon) and one with a systolic-array network processor (Xelerated X11), and shows that the NetVM model (i) is able to abstract such heterogeneous platforms and (ii) enables the exploitation of hardware functionalities provided by the specific architecture; finally, it demonstrates that the performances of NetVM programs compiled into native code are comparable to those obtained using commercial general purpose compilers. Olivier Morandi, Fulvio Risso, Silvio Valenti, Paolo Veglia |
EMSOFT | 2 |
| 2008 | Providing End-to-End Connectivity to SIP User Agents Behind NATsabstractThe widespread diffusion of private networks in SOHO scenarios is fostering an increased deployment of network address translators (NATs). The presence of NATs seriously limits end-to-end connectivity and prevents protocols like the session initiation protocol (SIP) from working properly. This document shows how the address list extension (ALEX), which was originally developed to provide dual-stack and multi-homing support to SIP, can be used, with minor modifications, to ensure end-to-end connectivity for both media and signaling flows, without relying on intermediate relay nodes whenever it is possible. Mario Baldi, Luca De Marco, Fulvio Risso, Livio Torrero |
ICC | 3 |
| 2008 | Enabling Flexible Packet Filtering Through Dynamic Code GenerationabstractDespite its efficiency, the general approach of hardcoding protocol format descriptions in packet processing applications suffers from many limitations. Among the others, the lack of flexibility when needing to extend the software for supporting new protocols, and the proliferation of modules with similar functionality between different applications, resulting in decreased maintainability. The NetPDL language was defined for overcoming such limitations, allowing decoupling applications from the knowledge of the format of protocol headers. The main criticism to NetPDL relates to its supposed performance penalties; this paper demonstrates that this language can be effectively used for the dynamic generation of optimized, i.e. efficient and fast, packet-processing code, and presents the architecture of a compiler implemented for such purpose. Olivier Morandi, Fulvio Risso, Mario Baldi, Andrea Baldini |
ICC | 2 |
| 2008 | Lightweight, Payload-Based Traffic Classification: An Experimental EvaluationabstractWith the ever increasing amount of traffic, scalability is probably the most important factor that differentiates several existing approaches to traffic classification. This paper focuses on payload-based classification and compares the results obtained through a "lightweight" traffic classification approach with the ones obtained with a "completely stateful" approach, demonstrating that the first approach, albeit less precise, is still appropriate for a large class of applications. Fulvio Risso, Mario Baldi, Olivier Morandi, Andrea Baldini, Pere Monclus |
ICC | 1 |
| 2007 | Adding Multi-Homing and Dual-Stack Support to the Session Initiation ProtocolabstractAlthough the SIP protocol claims a complete dual-stack support, some aspects, such as interoperability between different address realms and support for multi-homed hosts, are not taken into consideration. This leads to an extensive usage of proxies as gateways, e.g., between different address realms. ALEX ("address list extension") is a simple extension to the SIP header that addresses these limitations, providing additional scalability for SIP proxies and allowing the establishment of direct channels between peers, while still guaranteeing backward compatibility with traditional SIP implementations. Mario Baldi, Fulvio Risso, Livio Torrero |
GLOBECOM | 2 |
| 2007 | Extending the NetPDL Language to Support Traffic ClassificationabstractDespite the importance of traffic classification in modern networks, the number of languages tailored to this task is extremely limited. These languages can be valuable, because they allow the update of an application (e.g. firewall) in terms of supported protocols by simply updating its protocol description database, instead of recompiling the application from scratch. This paper presents a set of extensions to the Network Protocol Description Language (NetPDL) allowing support of traffic classification from data-link to application-layer protocols. A set of preliminary experimental results obtained with these new extensions is presented as well. Fulvio Risso, Andrea Baldini, Flavio Bonomi |
GLOBECOM | 1 |
| 2006 | Time Driven Priority Router Implementation and First ExperimentsabstractThis paper reports on the implementation of Time-Driven Priority (TDP) scheduling on a FreeBSD platform. This work is part of a TDP prototyping and demonstration project aimed at showing the implications of TDP deployment in packet-switched networks, especially benefits for real-time applications. This paper focuses on practical aspects related to the implementation of the technology on a Personal Computer (PC)-based router and presents the experimental results obtained on a testbed network. The basic building blocks of a TDP router are described and implementation choices are discussed. The relevant results achieved and here presented can be categorized into two types: qualitative results, including the successful integration of all needed blocks and the insight obtained on the complexity related to the implementation of a TDP router, and quantitative ones, including measures of achievable network utilization and of jitter experienced on a fully-loaded TDP network. The outcome demonstrates the effectiveness of the presented implementation while confirming TDP points of strength. Mario Baldi, Guido Marchetto, Fulvio Risso, Giulio Galante, Riccardo Scopigno, Federico Stirano |
ICC | 3 |
| 2006 | NetPDL: An extensible XML-based language for packet header description
Fulvio Risso, Mario Baldi |
Comput. Networks | 1 |
| 2005 | Using XML for efficient and modular packet processingabstractXML is a technology that has been widely adopted for data exchange, particularly in Web and e-commerce applications. This paper proposes the use of XML also for network packet processing. It presents some XML-based languages for data exchange and it identifies some examples in which XML can enable a new, modular design of network applications while maintaining the required high processing efficiency. These technologies have been implemented in the NetBee library, which provides an excellent way to give an insight of the performance obtainable with the proposed approach. Mario Baldi, Fulvio Risso |
GLOBECOM | 2 |
| 2005 | Data mining techniques for effective and scalable traffic analysisabstractThis paper describes a novel approach to traffic analysis in high speed networks based on data mining techniques. Data mining techniques are here applied as a means to effectively process the significant amount of captured data. The paper provides a first evaluation of the proposed approach in terms of its ability of extracting relevant information and its computational requirements. Such evaluation is based on experiments run on a prototypal implementation of the proposed approach. Mario Baldi, Elena Baralis, Fulvio Risso |
Integrated Network Management | 3 |
| 2003 | Profiling and Optimization of Software-Based Network-Analysis ApplicationsabstractA large set of tools for network monitoring and accounting, security, traffic analysis and prediction - more broadly, for network operation and management - require direct and efficient real-time access to data traveling on the network. Software tools are often preferred because of their low cost and high versatility. However, these tools are often considered to suffer from performance problems on high-speed networks. We demonstrate that, despite the common belief, the performance limits for software real-time network analysis tools are still far from being reached and it can even be improved with limited hardware support. We analyze the performance of a widely used library for network analysis, WinPcap, highlight its bottlenecks, and propose some solutions that almost double the overall speed, thus enabling the deployment of software-based tools on high speed networks. Loris Degioanni, Mario Baldi, Fulvio Risso, Gianluca Varenni |
SBAC-PAD | 3 |
| 2003 | Optimizing Packet Capture on Symmetric Multiprocessing MachinesabstractTraffic monitoring and analysis based on general purpose systems with high speed interfaces, such as Gigabit Ethernet and 10 Gigabit Ethernet, requires carefully designed software in order to achieve the needed performance. One approach to attain such a performance relies on deploying multiple processors. This work analyses some general issues in multiprocessor systems that are particularly critical in the context of packet capture and network monitoring applications. More important, a new algorithm is proposed to coordinate multiple producers concurrently accessing a shared buffer, which is instrumental in packet capture on symmetrical multiprocessor machines. Gianluca Varenni, Mario Baldi, Loris Degioanni, Fulvio Risso |
SBAC-PAD | 4 |
| 2001 | Decoupling Bandwidth and Delay Properties in Class Based QueuingabstractThis paper presents the decoupled class based scheduling, a CBQ-derived scheduling algorithm. The main advantages of D-CBQ are a new set of rules for distributing excess bandwidth and the ability to guarantee bandwidth and delay in a separate way, whence the name "decoupled"; moreover D-CBQ guarantees better delay bounds and more precise bandwidth assignment. This paper presents D-CBQ main points and discusses the choices for the implementation of the algorithm. Fulvio Risso |
ISCC | 1 |
| 2001 | An Architecture for High Performance Network AnalysisabstractMost Unix systems provide a set of system calls that allow applications to interact with the network directly. These primitives are useful for example in packet capture applications, which need to grab the data flowing through the network without any further processing from the kernel. WinPcap is a newly proposed architecture that adds these functionalities to Win32 operating systems. WinPcap includes a set of innovative features (such as packet monitoring and packet injection) that are not available in previous systems. This paper presents the details of the architecture and it shows its excellent performance. Fulvio Risso, Loris Degioanni |
ISCC | 1 |
| 1998 | Designing a Videoconference System for Active Networks
Mario Baldi, Gian Pietro Picco, Fulvio Risso |
Pers. Ubiquitous Comput. | 3 |