Pere Barlet-Ros

dblp:54/4261 · DBLP profile ↗
← Back
63ranked-venue papers
5as first author
28since 2021 · last 2026
0000-0001-7837-0886ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 41 · 4 first-author · 18 since 2021Software engineering, systems software and programming languages · 4 · 3 since 2021Systems, architecture and hardware · 3 · 1 first-author · 1 since 2021Security and privacy · 3Databases, data management, data science and information retrieval · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 AutoGraphAD: Unsupervised Network Anomaly Detection Using Variational Graph Autoencoders
abstract
Network Intrusion Detection Systems (NIDS) are essential tools for detecting network attacks and intrusions. While extensive research has explored the use of supervised Machine Learning for attack detection and characterisation, these methods require accurately labelled datasets, which are very costly to obtain. Moreover, existing public datasets have limited and/or outdated attacks, and many of them suffer from mislabelled data. To reduce the reliance on labelled data, we propose AutoGraphAD, a novel unsupervised anomaly detection approach based on a Heterogeneous Variational Graph Autoencoder. AutoGraphAD operates on heterogeneous graphs, made from connection and IP nodes that represent network activity. The model is trained using unsupervised and contrastive learning, without relying on any labelled data. The model's losses are then weighted and combined in an anomaly score used for anomaly detection. Overall, AutoGraphAD yields the same, and in some cases better, results than Anomal-E, but without requiring costly downstream anomaly detectors. As a result, AutoGraphAD achieves around 1.18 orders of magnitude faster training and 1.03 orders of magnitude faster inference, which represents a significant advantage for operational deployment.
Georgios Anyfantis, Pere Barlet-Ros
NetSoft2
2026 A Comparison of Different GNN Architectures for Network Traffic Classification
David Carela-Español, Ismael Castell-Uroz, Pere Barlet-Ros
NetSoft3
2026 Bridging the Gap between Simulated and Real Network Data Using Transfer Learning
abstract
Machine Learning (ML)-based network models provide fast and accurate predictions for complex network behaviors but require substantial training data. Collecting such data from real networks is often costly and limited, especially for critical scenarios like failures. As a result, researchers commonly rely on simulated data, which reduces accuracy when models are deployed in real environments. We propose a hybrid approach leveraging transfer learning to combine simulated and real-world data. Using RouteNet-Fermi, we show that fine-tuning a pre-trained model with a small real dataset significantly improves performance. Our experiments with OMNeT++ and a custom testbed reduce the Mean Absolute Percentage Error (MAPE) in packet delay prediction by up to 88%. With just 10 real scenarios, MAPE drops by 37%, and with 50 scenarios, by 48%.
Carlos Güemes-Palau, Miquel Ferriol, Jordi Paillisse, Albert Lopez-Bresco, Pere Barlet-Ros, Albert Cabellos-Aparicio
NetSoft5
2026 From simulation to deep learning: Survey on network performance modeling approaches
abstract
Network performance modeling is a field that predates early computer networks and the beginning of the Internet. It aims to predict the traffic performance of packet flows in a given network. Its applications range from network planning and troubleshooting to feeding information to network controllers for configuration optimization. Traditional network performance modeling has relied heavily on Discrete Event Simulation (DES) and analytical methods grounded in mathematical theories such as Queuing Theory and Network Calculus. However, as of late, we have observed a paradigm shift, with attempts to obtain efficient Parallel DES, the surge of Machine Learning models, and their integration with other methodologies in hybrid approaches. This has resulted in a great variety of modeling approaches, each with its strengths and often tailored to specific scenarios or requirements. In this paper, we comprehensively survey the relevant network performance modeling approaches for wired networks over the last decades. With this understanding, we also define a taxonomy of approaches, summarizing our understanding of the SotA and how both technology and the concerns of the research community evolve over time. Finally, we also consider how these models are evaluated, how their different nature results in different evaluation requirements and goals, and how this may complicate their comparison.
Carlos Güemes-Palau, Miquel Ferriol Galmés, Jordi Paillisse, Pere Barlet-Ros, Albert Cabellos-Aparicio
Comput. Networks4
2026 RouteNet-Gauss: Hardware-Enhanced Network Modeling With Machine Learning
abstract
Network simulation is pivotal in network modeling, assisting with tasks ranging from capacity planning to performance estimation. Traditional approaches such as Discrete Event Simulation (DES) face limitations in terms of computational cost and accuracy. This paper introduces RouteNet-Gauss, a novel integration of a testbed network with a Machine Learning (ML) model to address these challenges. By using the testbed as a hardware accelerator, RouteNet-Gauss generates training datasets rapidly and simulates network scenarios with high fidelity to real-world conditions. Experimental results show that RouteNet-Gauss significantly reduces prediction errors by up to 95% and achieves a 488x speedup in inference time compared to state-of-the-art DES-based methods. RouteNet-Gauss’s modular architecture is dynamically constructed based on the specific characteristics of the network scenario, such as topology and routing. This enables it to understand and generalize to different network configurations beyond those seen during training, including networks up to 10x larger. Additionally, it supports Temporal Aggregated Performance Estimation (TAPE), providing configurable temporal granularity and maintaining high accuracy in flow performance metrics. This approach shows promise in improving both simulation efficiency and accuracy, offering a valuable tool for network operators.
Carlos Güemes-Palau, Miquel Ferriol, Jordi Paillisse, Albert Lopez-Bresco, Pere Barlet-Ros, Albert Cabellos-Aparicio
IEEE Trans. Netw.5
2025 TSGFM - Graph Neural Networks for Zero-Shot Time Series Forecasting in Network Monitoring
abstract
We present TSGFM, a Time Series Graph Foundation Model for zero-shot network monitoring, leveraging spatiotemporal Graph Neural Networks (GNNs) to extract transferable representations across diverse multivariate time series (MTS) domains. Pretrained on heterogeneous time series datasets, TSGFM enables generalization without task-specific fine-tuning, addressing core challenges in dynamic network environments. TSGFM is benchmarked across five real-world MTS datasets and seven zero-shot forecasting scenarios, outperforming five state-of-the-art baselines in six out of seven tasks. Most notably, in zero-shot network monitoring analysis, TSGFM surpasses all competing models by at least 18%, even without any prior exposure to network monitoring data. We further compare TSGFM against leading Time Series Foundation Models (TSFMs), including TimeGPT and TimesFM. TSGFM achieves performance on par with TimeGPT, occasionally surpassing it, and consistently outperforms TimesFM, while using significantly less pretraining data and relying on a much simpler architecture. A detailed analysis of TSGFM’s learned spatial attention patterns reveals domain-specific connectivity structures. In particular, lower attention weights in network monitoring tasks suggest that dense spatial graphs may be unnecessary, opening opportunities for efficient spatial pruning without sacrificing accuracy. This challenges prevailing assumptions favoring fully connected spatiotemporal GNNs. To foster transparency and reproducibility, we release the complete implementation of TSGFM as open source, as well as the tested datasets.
Hamid Latif-Martínez, Juan Vanerio, Pedro Casas, José Suárez-Varela, Albert Cabellos-Aparicio, Pere Barlet-Ros
CNSM6
2025 Proximal Policy Optimization with Graph Neural Networks for Optimal Power Flow
Ángela López-Cardona, Guillermo Bernárdez, Pere Barlet-Ros, Albert Cabellos-Aparicio
DATA3
2025 GraphCC: A practical graph learning-based approach to Congestion Control in datacenters
abstract
Congestion Control (CC) plays a fundamental role in optimizing traffic in Datacenter Networks (DCNs). Currently, DCNs implement two main CC protocols: DCTCP and DCQCN. Both protocols are based on Explicit Congestion Notification (ECN), where switches mark packets when they detect congestion. Nowadays, network experts carefully set ECN parameters to optimize the average network performance. However, today’s DCNs experience rapid and abrupt changes that severely affect the network state (e.g., dynamic workloads, incasts), which leads to under-utilization and sub-optimal performance. In this paper we present GraphCC , a framework for in-network CC optimization. GraphCC relies on Multi-agent Reinforcement Learning (MARL) and Graph Neural Networks (GNN), and is compatible with widely deployed ECN-based CC protocols. The proposed solution deploys distributed agents on switches that communicate with their neighbors to cooperate and optimize the global ECN configuration. In our evaluation, we test GraphCC with three real-world traffic workloads, focusing on its capability to accommodate scenarios unseen during training (e.g., traffic changes, failures). We compare GraphCC with a state-of-the-art MARL solution for ECN tuning, and observe that our method outperforms the state-of-the-art baseline in all evaluation scenarios, with improvements up to 20% in average Flow Completion Time, similar mean throughput (within 1%), and significant reductions in buffer occupancy (38.0–85.7%).
Guillermo Bernárdez, José Suárez-Varela, Shihan Xiao, Xiangle Cheng, Pere Barlet-Ros, Albert Cabellos-Aparicio
Comput. Networks6
2025 BGP anomaly detection using the raw internet topology
abstract
The Border Gateway Protocol (BGP) is central to the global connectivity of the Internet, enabling fast and efficient dissemination of routing information. Hence, detecting any anomaly concerning BGP announcements is of critical importance to ensure the continuous operation of Internet services. Typically, BGP anomaly detection algorithms have relied on features of the BGP messages, such as the average length of the AS_PATH attribute, the volume of messages, or the type of message (announcement or withdrawal). Even though these algorithms provide good performance, they do not take into account the Internet topology, that is, the graph of Autonomous Systems (AS) created by the BGP announcements. In addition, some of the existing algorithms can detect only specific types of anomalies, while others require retraining them to support new scenarios. In this paper we propose detecting BGP anomalies by leveraging the raw BGP topology graph, instead of manually curated features of the BGP messages. We implement a Machine Learning algorithm to process the entire BGP topology and evaluate it with real-world data from 4 well-known incidents. We compare our proposal against two state-of-the-art solutions and a classical method that use BGP features and features of the BGP topology, not the topology itself. Our results show that our solution obtains remarkable performance identifying the incidents. Finally, we test our model with regular data (non-anomalous) to prove that it can be used in a production scenario, with samples processed on the fly and guaranteeing a low false alarm rate.
Hamid Latif-Martínez, Jordi Paillisse, Pere Barlet-Ros, Albert Cabellos-Aparicio
Comput. Networks3
2024 Circuit Partitioning for Multi-Core Quantum Architectures with Deep Reinforcement Learning
abstract
Quantum computing holds immense potential for solving classically intractable problems by leveraging the unique properties of quantum mechanics. The scalability of quantum architectures remains a significant challenge. Multi-core quantum architectures are proposed to solve the scalability problem, arising a new set of challenges in hardware, communications and compilation, among others. One of these challenges is to adapt a quantum algorithm to fit within the different cores of the quantum computer. This paper presents a novel approach for circuit partitioning using Deep Reinforcement Learning, contributing to the advancement of both quantum computing and graph partitioning. This work is the first step in integrating Deep Reinforcement Learning techniques into Quantum Circuit Mapping, opening the door to a new paradigm of solutions to such problems.
Arnau Pastor, Pau Escofet, Sahar Ben Rached, Eduard Alarcón, Pere Barlet-Ros, Sergi Abadal
ISCAS5
2023 ASTrack: Automatic Detection and Removal of Web Tracking Code with Minimal Functionality Loss
abstract
Recent advances in web technologies make it more difficult than ever to detect and block web tracking systems. In this work, we propose ASTrack, a novel approach to web tracking detection and removal. ASTrack uses an abstraction of the code structure based on Abstract Syntax Trees to selectively identify web tracking functionality shared across multiple web services. This new methodology allows us to: (i) effectively detect web tracking code even when using evasion techniques (e.g., obfuscation, minification, or webpackaging); and (ii) safely remove those portions of code related to tracking purposes without affecting the legitimate functionality of the website. Our evaluation with the top 10k most popular Internet domains shows that ASTrack can detect web tracking with high precision (98%), while discovering about 50k tracking code pieces and more than 3,400 new tracking URLs not previously recognized by most popular privacy-preserving tools (e.g., uBlock Origin). Moreover, ASTrack achieved a 36% reduction in functionality loss in comparison with the filter lists, one of the safest options available. Using a novel methodology that combines computer vision and manual inspection, we estimate that full functionality is preserved in more than 97% of the websites.
Ismael Castell-Uroz, Kensuke Fukuda, Pere Barlet-Ros
INFOCOM3
2023 TrackSign-labeled web tracking dataset
abstract
Recent studies [8] show that more than 95% of the websites available on the Internet contain at least one of the so-called web tracking systems. These systems are specialized in identifying their users by means of a plethora of different methods. Some of them (e.g., cookies) are very well known by most Internet users. However, the percentage of websites including more "obscure" and privacy-threatening systems, such as fingerprinting methods identifying a user's computer, is constantly increasing. Detecting those methods on today's Internet is very difficult, as almost any website modifies its content dynamically and minimizes its code in order to speed up loading times. This minimization and dynamicity render the website code unreadable by humans. Thus, the research community is constantly looking for new ways to discover unknown web tracking systems running under the hood. In this paper, we present a new dataset containing tracking information for more than 76 million URLs and 45 million online resources, extracted from 1.5 million popular websites. The tracking labeling process was done using a state-of-the-art discovery web tracking algorithm called TrackSign [8]. The dataset also contains information about online security and the relation between the domains, the loaded URLs, and the online resource behind each URL. This information can be useful for different kinds of experiments, such as locating privacy-threatening resources, identifying security threats, or determining characteristics of the URL network graph.
Ismael Castell-Uroz, Pere Barlet-Ros
Comput. Networks2
2023 Early detection of new web tracking methods across 1.5 million sites
abstract
Current web tracking practices pose a constant threat to the privacy of Internet users. As a result, the research community has recently proposed different tools to combat well-known tracking methods. However, the early detection of new, previously unseen tracking systems is still an open research problem. In this paper, we present TrackSign+ , a novel approach to discovering new web tracking methods. The main idea behind TrackSign+ is the use of code fingerprinting to identify common pieces of code shared across multiple domains. To detect tracking fingerprints, TrackSign+ builds a novel 4-mode network graph that captures the relationship between domains, URLs, online resources, and code fingerprints. We evaluated TrackSign+ with the 1.5M most popular Internet domains, including more than 45M web resources from almost 77M HTTP requests. Our results show that our method can detect new web tracking resources with high precision (over 92%). TrackSign+ was able to detect more than 300k new trackers, 800k new tracking resources, and 4.5M new tracking URLs, not yet detected by most popular pattern lists at the time. Finally, we also validated the effectiveness of TrackSign+ with more than 20 years of historical data from the Internet Archive.
Ismael Castell-Uroz, Óscar Sánchez-de-Mingo, Pere Barlet-Ros
Comput. Commun.3
2023 A One-Pass Clustering Based Sketch Method for Network Monitoring
abstract
Network monitoring solutions need to cope with increasing network traffic volumes, as a result, sketch-based monitoring methods have been extensively studied to trade accuracy for memory scalability and storage reduction. However, sketches are sensitive to skewness in network flow distributions due to hash collisions, and need complicated performance optimization to adapt to line-rate packet streams. We provide Jellyfish, an efficient sketch method that performs one-pass clustering over the network stream. One-pass clustering is realized by adapting the monitoring granularity from the whole network flow to fragments called subflows, which not only reduces the ingestion rate but also provides an efficient intermediate representation for the input to the sketch. Jellyfish provides the network-flow level query interface by reconstructing the network-flow level counters by merging subflow records from the same network flow. We provide probabilistic analysis of the expected accuracy of both existing sketch methods and Jellyfish. Real-world trace-driven experiments show that Jellyfish reduces the average estimation errors by up to six orders of magnitude for per-flow queries, by six orders of magnitude for entropy queries, and up to ten times for heavy-hitter queries.
Yongquan Fu, Lun An, Kai Chen 0005, Pere Barlet-Ros
IEEE/ACM Trans. Netw.5
2023 RouteNet-Fermi: Network Modeling With Graph Neural Networks
abstract
Network models are an essential block of modern networks. For example, they are widely used in network planning and optimization. However, as networks increase in scale and complexity, some models present limitations, such as the assumption of Markovian traffic in queuing theory models, or the high computational cost of network simulators. Recent advances in machine learning, such as Graph Neural Networks (GNN), are enabling a new generation of network models that are data-driven and can learn complex non-linear behaviors. In this paper, we present RouteNet-Fermi, a custom GNN model that shares the same goals as Queuing Theory, while being considerably more accurate in the presence of realistic traffic models. The proposed model predicts accurately the delay, jitter, and packet loss of a network. We have tested RouteNet-Fermi in networks of increasing size (up to 300 nodes), including samples with mixed traffic profiles — e.g., with complex non-Markovian models — and arbitrary routing and queue scheduling configurations. Our experimental results show that RouteNet-Fermi achieves similar accuracy as computationally-expensive packet-level simulators and scales accurately to larger networks. Our model produces delay estimates with a mean relative error of 6.24% when applied to a test dataset of 1,000 samples, including network topologies one order of magnitude larger than those seen during training. Finally, we have also evaluated RouteNet-Fermi with measurements from a physical testbed and packet traces from a real-life network.
Miquel Ferriol, Jordi Paillisse, José Suárez-Varela, Krzysztof Rusek, Shihan Xiao, Xiangle Cheng, Pere Barlet-Ros, Albert Cabellos-Aparicio
IEEE/ACM Trans. Netw.8
2022 Fast Traffic Engineering by Gradient Descent with Learned Differentiable Routing
abstract
Emerging applications such as the metaverse, telesurgery or cloud computing require increasingly complex operational demands on networks (e.g., ultra-reliable low latency). Likewise, the ever-faster traffic dynamics will demand network control mechanisms that can operate at short timescales (e.g., sub-minute). In this context, Traffic Engineering (TE) is a key component to efficiently control network traffic according to some performance goals (e.g., minimize network congestion).This paper presents Routing By Backprop (RBB), a novel TE method based on Graph Neural Networks (GNN) and differentiable programming. Thanks to its internal GNN model, RBB builds an end-to-end differentiable function of the target TE problem (MinMaxLoad). This enables fast TE optimization via gradient descent. In our evaluation, we show the potential of RBB to optimize OSPF-based routing (≈25% of improvement with respect to default OSPF configurations). Moreover, we test the potential of RBB as an initializer of computationally-intensive TE solvers. The experimental results show promising prospects for accelerating this type of solvers and achieving efficient online TE optimization.
Krzysztof Rusek, Paul Almasan, José Suárez-Varela, Piotr Cholda, Pere Barlet-Ros, Albert Cabellos-Aparicio
CNSM5
2022 FlowDT: A Flow-Aware Digital Twin for Computer Networks
abstract
Network modeling is an essential tool for network planning and management. It allows network administrators to explore the performance of new protocols, mechanisms, or optimal configurations without the need for testing them in real production networks. Recently, Graph Neural Networks (GNNs) have emerged as a practical solution to produce network models that can learn and extract complex patterns from real data without making any assumptions. However, state-of-the-art GNN-based network models only work with traffic matrices, this is a very coarse and simplified representation of network traffic. Although this assumption has shown to work well in certain use-cases, it is a limiting factor because, in practice, networks operate with flows. In this paper, we present FlowDT a new DL-based solution designed to model computer networks at the fine-grained flow level. In our evaluation, we show how FlowDT can accurately predict relevant per-flow performance metrics with an error of 3.5%, FlowDT’s performance is also benchmarked against vanilla DL models as well as with Queuing Theory.
Miquel Ferriol, Xiangle Cheng, Shihan Xiao, Pere Barlet-Ros, Albert Cabellos-Aparicio
ICASSP5
2022 RouteNet-Erlang: A Graph Neural Network for Network Performance Evaluation
abstract
Network modeling is a fundamental tool in network research, design, and operation. Arguably the most popular method for modeling is Queuing Theory (QT). Its main limitation is that it imposes strong assumptions on the packet arrival process, which typically do not hold in real networks. In the field of Deep Learning, Graph Neural Networks (GNN) have emerged as a new technique to build data-driven models that can learn complex and non-linear behavior. In this paper, we present RouteNet-Erlang, a pioneering GNN architecture designed to model computer networks. RouteNet-Erlang supports complex traffic models, multi-queue scheduling policies, routing policies and can provide accurate estimates in networks not seen in the training phase. We benchmark RouteNet-Erlang against a state-of-the-art QT model, and our results show that it outperforms QT in all the network scenarios.
Miquel Ferriol, Krzysztof Rusek, José Suárez-Varela, Shihan Xiao, Xiangle Cheng, Pere Barlet-Ros, Albert Cabellos-Aparicio
INFOCOM8
2022 Accelerating Deep Reinforcement Learning for Digital Twin Network Optimization with Evolutionary Strategies
abstract
The recent growth of emergent network applications (e.g., satellite networks, vehicular networks) is increasing the complexity of managing modern communication networks. As a result, the community proposed the Digital Twin Networks (DTN) as a key enabler of efficient network management. Network operators can leverage the DTN to perform different optimization tasks (e.g., Traffic Engineering, Network Planning).Deep Reinforcement Learning (DRL) showed a high performance when applied to solve network optimization problems. In the context of DTN, DRL can be leveraged to solve optimization problems without directly impacting the real-world network behavior. However, DRL scales poorly with the problem size and complexity. In this paper, we explore the use of Evolutionary Strategies (ES) to train DRL agents for solving a routing optimization problem. The experimental results show that ES achieved a training time speed-up of 128 and 6 for the NSFNET and GEANT2 topologies respectively.
Carlos Güemes-Palau, Paul Almasan, Shihan Xiao, Xiangle Cheng, Pere Barlet-Ros, Albert Cabellos-Aparicio
NOMS6
2022 ENERO: Efficient real-time WAN routing optimization with Deep Reinforcement Learning
abstract
Wide Area Networks (WAN) are a key infrastructure in today’s society. During the last years, WANs have seen a considerable increase in network’s traffic and network applications, imposing new requirements on existing network technologies (e.g., low latency and high throughput). Consequently, Internet Service Providers (ISP) are under pressure to ensure the customer’s Quality of Service and fulfill Service Level Agreements. Network operators leverage Traffic Engineering (TE) techniques to efficiently manage the network’s resources. However, WAN’s traffic can drastically change during time and the connectivity can be affected due to external factors (e.g., link failures). Therefore, TE solutions must be able to adapt to dynamic scenarios in real-time. In this paper we propose Enero, an efficient real-time TE solution based on a two-stage optimization process. In the first one, Enero leverages Deep Reinforcement Learning (DRL) to optimize the routing configuration by generating a long-term TE strategy. To enable efficient operation over dynamic network scenarios (e.g., when link failures occur), we integrated a Graph Neural Network into the DRL agent. In the second stage, Enero uses a Local Search algorithm to improve DRL’s solution without adding computational overhead to the optimization process. The experimental results indicate that Enero is able to operate in real-world dynamic network topologies in 4.5 s on average for topologies up to 100 links.
Paul Almasan, Shihan Xiao, Xiangle Cheng, Pere Barlet-Ros, Albert Cabellos-Aparicio
Comput. Networks5
2022 Amazon Alexa traffic traces
abstract
The number of devices that make up the Internet of Things (IoT) has been increasing every year, including smart speakers such as Amazon Echo devices. These devices have become very popular around the world where users with a smart speaker are estimated to be about 83 million in 2020. However, there has also been great concern about how they can affect the privacy and security of their users [1]. Responding to voice commands requires devices to continuously listen for the corresponding wake word, with the privacy implications that this entails. Additionally, the interactions that users may have with the virtual assistant can reveal private information about the user. In this document we publicly share two datasets that can help conduct privacy and security studies from the Amazon Echo Dot smart speaker. The included data contains 300.000 raw PCAP traces containing all the communications between the device and Amazon servers from 100 different voice commands on two different languages. The data can be used to train machine learning algorithms in order to find patterns that can characterize both, the voice commands and people using the device as well as Alexa as the device generating the traffic.
Rubén Barceló-Armada, Ismael Castell-Uroz, Pere Barlet-Ros
Comput. Networks3
2022 Building a Digital Twin for network optimization using Graph Neural Networks
abstract
Network modeling is a critical component of Quality of Service (QoS) optimization. Current networks implement Service Level Agreements (SLA) by careful configuration of both routing and queue scheduling policies. However, existing modeling techniques are not able to produce accurate estimates of relevant SLA metrics, such as delay or jitter, in networks with complex QoS-aware queueing policies (e.g., strict priority, Weighted Fair Queueing, Deficit Round Robin). Recently, Graph Neural Networks (GNNs) have become a powerful tool to model networks since they are specifically designed to work with graph-structured data. In this paper, we propose a GNN-based network model able to understand the complex relationship between (i) the queueing policy (scheduling algorithm and queue sizes), (ii) the network topology, (iii) the routing configuration, and (iv) the input traffic matrix. We call our model TwinNet, a Digital Twin that can accurately estimate relevant SLA metrics for network optimization. TwinNet can generalize to its input parameters, operating successfully in topologies, routing, and queueing configurations never seen during training. We evaluate TwinNet over a wide variety of scenarios with synthetic traffic and validate it with real traffic traces. Our results show that TwinNet can provide accurate estimates of end-to-end path delays in 106 unseen real-world topologies, under different queuing configurations with a Mean Absolute Percentage Error (MAPE) of 3.8%, as well as a MAPE of 6.3% error when evaluated with a real testbed. We also showcase the potential of the proposed model for SLA-driven network optimization and what-if analysis.
Miquel Ferriol, José Suárez-Varela, Jordi Paillisse, Shihan Xiao, Xiangle Cheng, Pere Barlet-Ros, Albert Cabellos-Aparicio
Comput. Networks7
2022 Deep reinforcement learning meets graph neural networks: Exploring a routing optimization use case
Paul Almasan, José Suárez-Varela, Krzysztof Rusek, Pere Barlet-Ros, Albert Cabellos-Aparicio
Comput. Commun.4
2022 Demystifying Content-Blockers: Measuring Their Impact on Performance and Quality of Experience
abstract
With the evolution of the online advertisement and tracking ecosystem, content-blockers have become the reference tool for improving the security, privacy and browsing experience when surfing the Internet. It is also commonly believed that using content-blockers to stop unsolicited content decreases the time needed for loading websites. In this work, we perform a large-scale study on the actual improvements of using content-blockers in terms of performance and quality of experience. For measuring it, we analyze the page size and loading times of the 100K most popular websites, as well as the most relevant QoE metrics, such as the Speed Index, Time to Interactive or the Cumulative Layout Shift, for the subset of the top 10K of them. Our experiments show that using content-blockers results in small improvements in terms of performance. However, contrary to popular belief, this has a negligible impact in terms of loading time and quality of experience. Moreover, in the case of small and lightweight websites, the overhead introduced by content-blockers can even result in decreased performance. Finally, we evaluate the improvement in terms of QoE based on the Mean Opinion Score (MOS) and find that two of the three studied content-blockers present an overall decrease between 3% and 5% instead of the expected improvement.
Ismael Castell-Uroz, Rubén Sanz-García, Josep Solé-Pareta, Pere Barlet-Ros
IEEE Trans. Netw. Serv. Manag.4
2021 Towards Real-Time Routing Optimization with Deep Reinforcement Learning: Open Challenges
abstract
The digital transformation is pushing the existing network technologies towards new horizons, enabling new applications (e.g., vehicular networks). As a result, the networking community has seen a noticeable increase in the requirements of emerging network applications. One main open challenge is the need to accommodate control systems to highly dynamic network scenarios. Nowadays, existing network optimization technologies do not meet the needed requirements to effectively operate in real time. Some of them are based on hand-crafted heuristics with limited performance and adaptability, while some technologies use optimizers which are often too time-consuming. Recent advances in Deep Reinforcement Learning (DRL) have shown a dramatic improvement in decision-making and automated control problems. Consequently, DRL represents a promising technique to efficiently solve a variety of relevant network optimization problems, such as online routing. In this paper, we explore the use of state-of-the-art DRL technologies for real-time routing optimization and outline some relevant open challenges to achieve production-ready DRL-based solutions.
Paul Almasan, José Suárez-Varela, Shihan Xiao, Pere Barlet-Ros, Albert Cabellos-Aparicio
HPSR5
2021 Is Machine Learning Ready for Traffic Engineering Optimization?
abstract
Traffic Engineering (TE) is a basic building block of the Internet. In this paper, we analyze whether modern Machine Learning (ML) methods are ready to be used for TE optimization. We address this open question through a comparative analysis between the state of the art in ML and the state of the art in TE. To this end, we first present a novel distributed system for TE that leverages the latest advancements in ML. Our system implements a novel architecture that combines Multi-Agent Reinforcement Learning (MARL) and Graph Neural Networks (GNN) to minimize network congestion. In our evaluation, we compare our MARL+GNN system with DEFO, a network optimizer based on Constraint Programming that represents the state of the art in TE. Our experimental results show that the proposed MARL+GNN solution achieves equivalent performance to DEFO in a wide variety of network scenarios including three real-world network topologies. At the same time, we show that MARL+GNN can achieve significant reductions in execution time (from the scale of minutes with DEFO to a few seconds with our solution).
Guillermo Bernárdez, José Suárez-Varela, Albert López, Shihan Xiao, Xiangle Cheng, Pere Barlet-Ros, Albert Cabellos-Aparicio
ICNP7
2021 TrackSign: Guided Web Tracking Discovery
abstract
Current web tracking practices pose a constant threat to the privacy of Internet users. As a result, the research community has recently proposed different tools to combat well-known tracking methods. However, the early detection of new, previously unseen tracking systems is still an open research problem. In this paper, we present TrackSign, a novel approach to discover new web tracking methods. The main idea behind TrackSign is the use of code fingerprinting to identify common pieces of code shared across multiple domains. To detect tracking fingerprints, TrackSign builds a novel 3-mode network graph that captures the relationship between fingerprints, resources and domains. We evaluated TrackSign with the top-100K most popular Internet domains, including almost 1M web resources from more than 5M HTTP requests. Our results show that our method can detect new web tracking resources with high precision (over 92%). TrackSign was able to detect 30K new trackers, more than 10K new tracking resources and 270K new tracking URLs, not yet detected by most popular blacklists. Finally, we also validate the effectiveness of TrackSign with more than 20 years of historical data from the Internet Archive.
Ismael Castell-Uroz, Josep Solé-Pareta, Pere Barlet-Ros
INFOCOM3
2021 Jellyfish: Locality-Sensitive Subflow Sketching
abstract
To cope with increasing network rates and massive traffic volumes, sketch-based methods have been extensively studied to trade accuracy for memory scalability and storage cost. However, sketches are sensitive to hash collisions due to skewed keys in real world environment, and need complicated performance control for line-rate packet streams.We present Jellyfish, a locality-sensitive sketching framework to address these issues. Jellyfish goes beyond network flow-based sketching towards fragments of network flows called subflows. First, Jellyfish splits consecutive packets from each network flow to subflow records, which not only reduces the rate contention but also provides intermediate subflow representations in form of truncated counters. Next, Jellyfish maps similar subflow records to the same bucket array and merges those from the same network flow to reconstruct the network-flow level counters. Real-world trace-driven experiments show that Jellyfish reduces the average estimation errors by up to six orders of magnitude for per-flow queries, by six orders of magnitude for entropy queries, and up to ten times for heavy-hitter queries.
Yongquan Fu, Lun An, Kai Chen 0005, Pere Barlet-Ros
INFOCOM5
2020 URL-based Web Tracking Detection Using Deep Learning
abstract
The pervasiveness of online web tracking poses a constant threat to the privacy of Internet users. Millions of users currently employ content-blockers in their web browsers to block tracking resources in real time. Although content-blockers are based on blacklists, which are known to be difficult to maintain and easy to evade, the research community has not succeeded in replacing them with better alternatives yet. Most of the methods recently proposed in the literature obtain good detection accuracy, but at the expense of increasing their complexity and making them more difficult to maintain and configure by the end user. In this paper, we present a new web tracking detection method, called Deep Tracking Detector (DTD), that analyzes the properties of URL strings to detect tracking resources, without using any other external features. Consequently, DTD can easily be implemented in a browser plugin and operate in real time. Our experimental results, with more than 5M HTTP requests from 100K websites, show that DTD achieves a detection accuracy higher than 97% by looking only at the URL of the resources.
Ismael Castell-Uroz, Théo Poissonnier, Pierre Manneback, Pere Barlet-Ros
CNSM4
2020 Demystifying Content-blockers: A Large-scale Study of Actual Performance Gains
abstract
With the evolution of the online advertisement and tracking ecosystem, content-filtering has become the reference tool for improving the security, privacy and browsing experience when surfing the Internet. It is also commonly believed that using content-blockers to stop unsolicited content decreases the time needed for loading websites. In this work, we perform a large-scale study with the 100K most popular websites on the actual performance improvements of using content-blockers. We focus our study on two relevant metrics for measuring the browsing performance; page size and loading time. Our results show that using such tools results in small improvements in terms of page size but, contrary to popular belief, it has a negligible impact in terms of loading time. We also find that, in the case of small and lightweight websites, the use of content-blockers can even result in increased loading times.
Ismael Castell-Uroz, Josep Solé-Pareta, Pere Barlet-Ros
CNSM3
2020 RouteNet: Leveraging Graph Neural Networks for Network Modeling and Optimization in SDN
abstract
Network modeling is a key enabler to achieve efficient network operation in future self-driving Software-Defined Networks. However, we still lack functional network models able to produce accurate predictions of Key Performance Indicators (KPI) such as delay, jitter or loss at limited cost. In this paper we propose RouteNet, a novel network model based on Graph Neural Network (GNN) that is able to understand the complex relationship between topology, routing, and input traffic to produce accurate estimates of the per-source/destination per-packet delay distribution and loss. RouteNet leverages the ability of GNNs to learn and model graph-structured information and as a result, our model is able to generalize over arbitrary topologies, routing schemes and traffic intensity. In our evaluation, we show that RouteNet is able to predict accurately the delay distribution (mean delay and jitter) and loss even in topologies, routing and traffic unseen in the training (worst case MRE = 15.4%). Also, we present several use cases where we leverage the KPI predictions of our GNN model to achieve efficient routing optimization and network planning.
Krzysztof Rusek, José Suárez-Varela, Paul Almasan, Pere Barlet-Ros, Albert Cabellos-Aparicio
IEEE J. Sel. Areas Commun.4
2019 Feature Engineering for Deep Reinforcement Learning Based Routing
abstract
Recent advances in Deep Reinforcement Learning (DRL) techniques are providing a dramatic improvement in decision-making and automated control problems. As a result, we are witnessing a growing number of research works that are proposing ways of applying DRL techniques to network-related problems such as routing. However, such proposals failed to achieve good results, often under-performing traditional routing techniques. We argue that successfully applying DRL-based techniques to networking requires finding good representations of the network parameters: feature engineering. DRL agents need to represent both the state (e.g., link utilization) and the action space (e.g., changes to the routing policy). In this paper, we show that existing approaches use straightforward representations that lead to poor performance. We propose a novel representation of the state and action that outperforms existing ones and that is flexible enough to be applied to many networking use-cases. We test our representation in two different scenarios: (i) routing in optical transport networks and (ii) QoS-aware routing in IP networks. Our results show that the DRL agent achieves significantly better performance compared to existing state/action representations.
José Suárez-Varela, Albert Mestres, Junlin Yu, Li Kuang, Haoyu Feng, Pere Barlet-Ros, Albert Cabellos-Aparicio
ICC6
2019 A Skewness-Aware Matrix Factorization Approach for Mesh-Structured Cloud Services
abstract
Online cloud services need to fulfill clients' requests scalably and fast. State-of-the-art cloud services are increasingly deployed as a distributed service mesh. Service to service communication is frequent in the mesh. Unfortunately, problematic events may occur between any pair of nodes in the mesh, therefore, it is vital to maximize the network visibility. A state-of-the-art approach is to model pairwise RTTs based on a latent factor model represented as a low-rank matrix factorization. A latent factor corresponds to a rank-1 component in the factorization model, and is shared by all node pairs. However, different node pairs usually experience a skewed set of hidden factors, which should be fully considered in the model. In this paper, we propose a skewness-aware matrix factorization method named SMF. We decompose the matrix factorization into basic units of rank-one latent factors, and progressively combine rank-one factors for different node pairs. We present a unifying framework to automatically and adaptively select the rank-one factors for each node pair, which not only preserves the low rankness of the matrix model, but also adapts to skewed network latency distributions. Over real-world RTT data sets, SMF significantly improves the relative error by a factor of 0.2 x to 10 x, converges fast and stably, and compactly captures fine-grained local and global network latency structures.
Yongquan Fu, Dongsheng Li 0001, Pere Barlet-Ros, Chun Huang 0006, Zhen Huang 0006, Huayou Su
IEEE/ACM Trans. Netw.3
2018 Flow monitoring in Software-Defined Networks: Finding the accuracy/performance tradeoffs
José Suárez-Varela, Pere Barlet-Ros
Comput. Networks2
2018 Every Timestamp Counts: Accurate Tracking of Network Latencies Using Reconcilable Difference Aggregator
abstract
User-facing services deployed in data centers must respond quickly to user actions. The measurement of network latencies is of paramount importance. Recently, a new family of compact data structures has been proposed to estimate one-way latencies. In order to achieve scalability, these new methods rely on timestamp aggregation. Unfortunately, this approach suffers from serious accuracy problems in the presence of packet loss and reordering, given that a single lost or out-of-order packet may invalidate a huge number of aggregated samples. In this paper, we unify the problem to detect lost and reordered packets within the set reconciliation framework. Although the set reconciliation approach and the data structures for aggregating packet timestamps are previously known, the combination of these two principles is novel. We present a space-efficient synopsis called reconcilable difference aggregator (RDA). RDA maximizes the percentage of useful packets for latency measurement by mapping packets to multiple banks and repairing aggregated samples that have been damaged by lost and reordered packets. RDA simultaneously obtains the average and the standard deviation of the latency. We provide a formal guarantee of the performance and derive optimized parameters. We further design and implement a user-space passive latency measurement system that addresses practical issues of integrating RDA into the network stack. Our extensive evaluation shows that compared with existing methods, our approach improves the relative error of the average latency estimation in 10-15 orders of magnitude, and the relative error of the standard deviation in 0.5-6 orders of magnitude.
Yongquan Fu, Pere Barlet-Ros, Dongsheng Li 0001
IEEE/ACM Trans. Netw.2
2017 A Survey on Web Tracking: Mechanisms, Implications, and Defenses
abstract
Privacy seems to be the Achilles’ heel of today’s web. Most web services make continuous efforts to track their users and to obtain as much personal information as they can from the things they search, the sites they visit, the people they contact, and the products they buy. This information is mostly used for commercial purposes, which go far beyond targeted advertising. Although many users are already aware of the privacy risks involved in the use of internet services, the particular methods and technologies used for tracking them are much less known. In this survey, we review the existing literature on the methods used by web services to track the users online as well as their purposes, implications, and possible user’s defenses. We present five main groups of methods used for user tracking, which are based on sessions, client storage, client cache, fingerprinting, and other approaches. A special focus is placed on mechanisms that use web caches, operational caches, and fingerprinting, as they are usually very rich in terms of using various creative methodologies. We also show how the users can be identified on the web and associated with their real names, e-mail addresses, phone numbers, or even street addresses. We show why tracking is being used and its possible implications for the users. For each of the tracking methods, we present possible defenses. Some of them are specific to a particular tracking approach, while others are more universal (block more than one threat). Finally, we present the future trends in user tracking and show that they can potentially pose significant threats to the users’ privacy.
Tomasz Bujlow, Valentín Carela-Español, Beom-Ryeol Lee, Pere Barlet-Ros
Proc. IEEE4
2016 Measuring Video QoE from Encrypted Traffic
Giorgos Dimopoulos, Ilias Leontiadis, Pere Barlet-Ros, Konstantina Papagiannaki
Internet Measurement Conference3
2016 Machine learning, data mining and Big Data frameworks for network monitoring and troubleshooting
Alessandro D'Alconzo, Pere Barlet-Ros, Kensuke Fukuda, David R. Choffnes
Comput. Networks2
2016 Special section on selected papers from TMA 2015
Pere Barlet-Ros, Moritz Steiner
Comput. Commun.1
2015 Identifying the root cause of video streaming issues on mobile devices
abstract
Video streaming on mobile devices is prone to a multitude of faults and although well established video Quality of Experience (QoE) metrics such as stall frequency are a good indicator of the problems perceived by the user, they do not provide any insights about the nature of the problem nor where it has occurred. Quantifying the correlation between the aforementioned faults and the users' experience is a challenging task due the large number of variables and the numerous points-of-failure.
Giorgos Dimopoulos, Ilias Leontiadis, Pere Barlet-Ros, Konstantina Papagiannaki, Peter Steenkiste
CoNEXT3
2015 Independent comparison of popular DPI tools for traffic classification
Tomasz Bujlow, Valentín Carela-Español, Pere Barlet-Ros
Comput. Networks3
2014 Is Our Ground-Truth for Traffic Classification Reliable?
Valentín Carela-Español, Tomasz Bujlow, Pere Barlet-Ros
PAM3
2013 Analysis of YouTube user experience from passive measurements
abstract
In this paper, we analyze the YouTube service and the traffic generated from its usage. The purpose of this study is to identify by strictly using passive measurements the information that can be used as metrics or indicators of the progress of individual video sessions and to estimate the impact of these metrics in the user experience. We find a novel method to track the progress of the video playback that, in contrast to previous works, does not require instrumentation of the video player neither browser-based plug-ins. Instead, we extract important statistical information about the status of the playback by reverse engineering the metrics in related HTTP requests that are generated during playback. For the purpose of collecting these metrics, a tool was developed to perform YouTube traffic measurements by means of passive network monitoring in a large university campus network. The analysis of the obtained data revealed the most important sources of initial delay in the sessions as well as buffer outage events and download rate statistics. Further analysis revealed the impact of video advertisements and re-buffering events on the user experience in terms of video abandonment rate.
Giorgos Dimopoulos, Pere Barlet-Ros, Josep Sanjuàs-Cuxart
CNSM2
2013 ITMgen - A first-principles approach to generating synthetic interdomain traffic matrices
abstract
We present the design and evaluation of ITMgen, a tool for generating synthetic but representative Interdomain Traffic Matrices (ITMs). ITMgen is motivated by the observation that gravity-based models do not reflect application level or regional characteristics of Internet traffic. ITMgen works at the level of connections, taking into account the relative sizes of ASes, their popularity with respect to various applications, and the relation between forward and reverse traffic for different application types. The necessary parameters for integrating application types and the distribution of content popularity can be realistically estimated by combining public sources like Alexa that capture traffic trends at a macro level with local traffic sampling (NetFlow, DPI) for providing an additional enhancement layer at the micro level. Using the above philosophy we demonstrate that we can synthesize ITMs that match real-world measurements closer than the current state of the art. In addition, the modular design philosophy of ITMgen makes it easy to integrate additional enhancement layers that improve the accuracy of our existing implementation.
Jakub Mikians, Nikolaos Laoutaris, Amogh Dhamdhere, Pere Barlet-Ros
ICC4
2013 Empirical analysis of traffic to establish a profiled flow termination timeout
abstract
The exponential increase of bandwidth on the Internet has made the online traffic classification a highly exigent task. All the operations in the classification process must be efficiently implemented in order to deal with an enormous amount of data. A key point in this process is the selection of a flow termination, a decision that has important consequences for several traffic classification techniques (e.g., DPI-based, Machine Learning-based). For instance, properly expiring the flows reduces the amount of memory necessary and avoids erroneous computation of flow features. In addition, the heterogeneous behaviour of the applications on the Internet have dismissed the traditional techniques to determine the flow termination (i.e., TCP 3/4-way handshake, TCP timeout). In this paper, we first perform a comprehensive study of the flow termination by application groups. Results confirm that traditional techniques are no longer sufficient to determine the flow termination (i.e., <50% finish with TCP handshake for some groups). In order to address this new scenario we propose a profiled (i.e., by application group) flow termination timeout. This solution has been evaluated in a well-known commercial DPI tool (the Ipoque's PACE engine) achieving a drastic reduction of memory, while keeping the same computation cost and classification accuracy. In order to obtain representative results, two completely different traces have been analysed, one from the core network of a large ISP and another from the edge link of a mobile operator.
Juan Molina Rodriguez, Valentín Carela-Español, Pere Barlet-Ros, Ralf Hoffmann, Klaus Degner
IWCMC3
2013 FaRNet: fast recognition of high multi-dimensional network traffic patterns
abstract
Extracting knowledge from big network traffic data is a matter of foremost importance for multiple purposes ranging from trend analysis or network troubleshooting to capacity planning or traffic classification. An extremely useful approach to profile traffic is to extract and display to a network administrator the multi-dimensional hierarchical heavy hitters (HHHs) of a dataset. However, existing schemes for computing HHHs have several limitations: 1) they require significant computational overhead; 2) they do not scale to high dimensional data; and 3) they are not easily extensible. In this paper, we introduce a fundamentally new approach for extracting HHHs based on generalized frequent item-set mining (FIM), which allows to process traffic data much more efficiently and scales to much higher dimensional data than present schemes. Based on generalized FIM, we build and evaluate a traffic profiling system we call FaRNet. Our comparison with AutoFocus, which is the most related tool of similar nature, shows that FaRNet is up to three orders of magnitude faster.
Ignasi Paredes-Oliva, Pere Barlet-Ros, Xenofontas A. Dimitropoulos
SIGMETRICS2
2013 FaRNet: Fast recognition of high-dimensional patterns from big network traffic data
Ignasi Paredes-Oliva, Pere Barlet-Ros, Xenofontas A. Dimitropoulos
Comput. Networks2
2012 A lightweight algorithm for traffic filtering over sliding windows
abstract
The problem of testing whether a packet belongs to a set of filtered addresses has been traditionally addressed using Bloom filters. They have a small memory footprint and require few memory accesses per query and insertion, while presenting a small probability of false positive. The problem of automatic eviction of filtered addresses after a pre-configured time window is more challenging, since it requires tracking insertion times for later removal. This has been achieved in the literature by replacing the Bloom filter's vector of bits for a vector of timestamps. This approach precisely expires old items from the filter, but has a large memory footprint. We present a novel Bloom filter based data structure that features approximate information expiration. This small extra source of error allows for a more compact filter representation, thus becoming more suitable to fit in more expensive, faster memory. Additionally, our data structure is more flexible in that it allows for balancing the trade-off between filtering and expiration accuracy. Our experiments show that this method can obtain up to orders of magnitude higher overall accuracy than the time-stamp approach using the same amount of memory.
Josep Sanjuàs-Cuxart, Pere Barlet-Ros, Josep Solé-Pareta, Gabriella Andriuzzi
ICC2
2012 Cuckoo sampling: Robust collection of flow aggregates under a fixed memory budget
abstract
Collecting per-flow aggregates in high-speed links is challenging and usually requires traffic sampling to handle peak rates and extreme traffic mixes. Static selection of sampling rates is problematic, since worst-case resource usage is orders of magnitude higher than the average. To address this issue, adaptive schemes have been proposed in the last few years that periodically adjust packet sampling rates to network conditions. However, such proposals rely on complex algorithms and data structures of costly maintenance. As a consequence, adaptive sampling is still not widely implemented in routers.
Josep Sanjuàs-Cuxart, Pere Barlet-Ros, Nick G. Duffield, Ramana Rao Kompella
INFOCOM2
2012 Towards a Statistical Characterization of the Interdomain Traffic Matrix
Jakub Mikians, Amogh Dhamdhere, Constantinos Dovrolis, Pere Barlet-Ros, Josep Solé-Pareta
Networking (2)4
2012 Operational experiences with anomaly detection in backbone networks
Maurizio Molina, Ignasi Paredes-Oliva, Wayne Routly, Pere Barlet-Ros
Comput. Secur.4
2012 fHA: A flexible and distributed Home Agent architecture for Mobile-IP based networks
Albert Cabellos-Aparicio, Dorin-Mircea Cioran, Pere Barlet-Ros, Jordi Domingo-Pascual, Virgil Dobrota
Inf. Sci.3
2011 Sketching the delay: tracking temporally uncorrelated flow-level latencies
abstract
Packet delay is a crucial performance metric for real-time, network-based applications. Obtaining per-flow delay measurements is particularly important to network operators, but is computationally challenging in high-speed links. Recently, passive delay measurement techniques have been proposed that outperform traditional active probing in terms of accuracy and network overhead. However, such techniques rely on the empirical observation that packet delays across different flows are temporally correlated, an assumption that is not met in presence of traffic prioritization, load balancing policies, or due to intricacies of the switch fabric.
Josep Sanjuàs-Cuxart, Pere Barlet-Ros, Nick G. Duffield, Ramana Rao Kompella
Internet Measurement Conference2
2011 A Practical Approach to Portscan Detection in Very High-Speed Links
Jakub Mikians, Pere Barlet-Ros, Josep Sanjuàs-Cuxart, Josep Solé-Pareta
PAM2
2011 Analysis of the impact of sampling on NetFlow traffic classification
Valentín Carela-Español, Pere Barlet-Ros, Albert Cabellos-Aparicio, Josep Solé-Pareta
Comput. Networks2
2011 Predictive resource management of multiple monitoring applications
abstract
We propose a predictive resource management scheme for network monitoring systems that can proactively shed excess load while maintaining the accuracy of monitoring applications within bounds defined by the operator. The main novelty of our scheme is that it considers monitoring applications as black boxes, with arbitrary (and highly variable) input traffic and processing cost. This way, the monitoring system preserves a high degree of flexibility, increasing the range of applications and network scenarios where it can be used. We implemented our load-shedding-based resource management scheme in an existing network monitoring system and deployed it in a large research and educational network. We present experimental evidence of the performance and robustness of our system with multiple concurrent monitoring applications during long-lived executions and using real-world traffic traces.
Pere Barlet-Ros, Gianluca Iannaccone, Josep Sanjuàs-Cuxart, Josep Solé-Pareta
IEEE/ACM Trans. Netw.1
2010 Automating root-cause analysis of network anomalies using frequent itemset mining
abstract
Finding the root-cause of a network security anomaly is essential for network operators. In our recent work [1, 5], we introduced a generic technique that uses frequent itemset\nmining to automatically extract and summarize the traffic flows causing an anomaly. Our evaluation using two different\nanomaly detectors (including a commercial one) showed that our approach works surprisingly well extracting the anomalous\nflows in most studied cases using sampled and unsampled NetFlow traces from two networks. In this demonstration, we will showcase an open-source anomaly-extraction\nsystem based on our technique, which we integrated with a commercial anomaly detector and use in the NOC of the GÉANT network since late 2009. We will report a number of detected security anomalies and will illustrate how an operator can use our system to automatically extract and summarize anomalous flows.
Ignasi Paredes-Oliva, Xenofontas A. Dimitropoulos, Maurizio Molina, Pere Barlet-Ros, Daniela Brauckhoff
SIGCOMM4
2009 Counting Flows over Sliding Windows in High Speed Networks
Josep Sanjuàs-Cuxart, Pere Barlet-Ros, Josep Solé-Pareta
Networking2
2009 Robust network monitoring in the presence of non-cooperative traffic queries
Pere Barlet-Ros, Gianluca Iannaccone, Josep Sanjuàs-Cuxart, Josep Solé-Pareta
Comput. Networks1
2008 Distributed scheduling in large scale monitoring infrastructures
abstract
Network monitoring is becoming a necessity for network operators, who usually deploy several monitoring applications that aid in tasks such as traffic engineering, capacity planning and the detection of attacks or other anomalies. There is also an increasing interest in large-scale network monitoring infrastructures that can run multiple applications in several network viewpoints [4].
Josep Sanjuàs-Cuxart, Pere Barlet-Ros, Gianluca Iannaccone, Josep Solé-Pareta
CoNEXT2
2008 Distributed sampling for on-line SLA assessment
abstract
New business infrastructures over the Internet pose a new set of traffic constraints. In particular, multimedia and interactive contents require guarantees of bandwidth and delivery time. The broad deployment and real-time nature of this class of applications require the provisioning of specific resources in the network to guarantee a certain level of quality of service (QoS). QoS techniques need ways of obtaining feedback about the status of the QoS enabled paths, for example, for checking the fulfilment of service level agreements (SLA). A possible technique for obtaining such feedback is by passively monitoring the network traffic. The issue with traffic monitoring is the additional bandwidth needed by the control traffic generated by the different collection points in order to synchronise its acquired QoS metrics. Moreover, passive monitoring at line speed is an expensive process both in terms of resource consumption and price. However, some of these requirements can be significantly reduced by using traffic sampling. This paper presents a novel methodology for intra-domain on-line distributed QoS monitoring, which makes an efficient use of the network resources by employing distributed sampling mechanisms. The proposal is validated by performing real tests on an European-wide testbed. Our results show that the sampling technique can significantly reduce the traffic overhead, while obtaining very accurate estimations of the One Way Delay performance metric.
René Serral-Gracià, Pere Barlet-Ros, Jordi Domingo-Pascual
LANMAN2
2007 On-Line Predictive Load Shedding for Network Monitoring
Pere Barlet-Ros, Diego Amores-López, Gianluca Iannaccone, Josep Sanjuàs-Cuxart, Josep Solé-Pareta
Networking1
2007 Load Shedding in Network Monitoring Applications
Pere Barlet-Ros, Gianluca Iannaccone, Josep Sanjuàs-Cuxart, Diego Amores-López, Josep Solé-Pareta
USENIX ATC1