Antonio Pescapè

dblp:58/1789 · DBLP profile ↗
← Back
152ranked-venue papers
2as first author
45since 2021 · last 2026
0000-0002-0221-7444ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 102 · 1 first-author · 29 since 2021Security and privacy · 15 · 1 first-author · 5 since 2021Systems, architecture and hardware · 10 · 2 since 2021Artificial intelligence and machine learning · 8 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 since 2021Software engineering, systems software and programming languages · 3 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Theory of computation · 1
YearPublicationVenuePosition
2026 Cross-network transferability of AI-based network intrusion detection systems in heterogeneous Internet of Things environments
abstract
The rapid expansion of Internet of Things (IoT) ecosystems has amplified the demand for robust cybersecurity solutions, with Artificial Intelligence (AI)-based Network Intrusion Detection System (NIDS) emerging as a promising component of modern defense strategies. Despite their strong performance when trained and evaluated on traffic collected within the same IoT environment, a critical open question remains: can these systems transfer effectively when deployed in different IoT networks? In this work, we present a comprehensive experimental study evaluating the cross-network transferability of AI-based NIDS built using Machine Learning (ML) and Deep Learning (DL), including attention-based architectures. Our analysis spans eight heterogeneous IoT network environments, represented by publicly available datasets. Specifically, we ( i ) assess attack-level transferability across networks, ( i i ) quantify the impact of feature informativeness on cross-network performance, ( i i i ) leverage eXplainable Artificial Intelligence (XAI) to interpret decisions in cross-network scenarios, ( i v ) investigate design principles for universal NIDS, and ( v ) evaluate edge-device deployment feasibility. Our findings provide systematic insight into the limits of AI-driven NIDS. Notably, cross-network transferability is highly variable and strongly influenced by attack semantics and dataset characteristics: volumetric attacks transfer effectively, whereas others remain dataset-dependent. Transferability benefits from generalizable feature design and multi-domain training, yet universal robustness remains challenging. Finally, while edge deployment is feasible from a memory perspective, Convolutional Neural Network (CNN) architectures offer substantially lower inference latency than Transformers on resource-constrained devices.
Francesco Cerasuolo, Giampaolo Bovenzi, Antonio Pescapè
Comput. Networks3
2026 A multimodal and perturbation-aware learning approach for robust traffic classification
abstract
Traffic Classification (TC) is pivotal for network management, cybersecurity, and Quality of Experience (QoE) monitoring. However, while Deep Learning (DL) has significantly advanced TC, most existing works assume static, idealized conditions, overlooking key challenges of real-world deployments—such as traffic variability, routing asymmetries, out-of-order packet arrivals, and partial visibility at the Vantage Points (VPs). This motivates the need for robustness evaluations under such scenarios. In this work, we investigate the robustness of state-of-the-art (SOTA) TC models under realistic, yet controlled, perturbation scenarios. Specifically, we introduce novel, model-agnostic traffic perturbations—simulating time jitter, retransmissions, and partial visibility—to reflect conditions commonly encountered in live network traffic. We evaluate our approach on three public datasets—i.e., VPN-16 , MIRAGE-19 , and MIRAGE-24 —and show how Mimetic-Enhanced , a multimodal model, tends to outperform two representative single-modal counterparts both in terms of TC effectiveness on clean traffic and robustness under perturbations. Nonetheless, our analysis also reveals that multimodal models remain vulnerable under specific perturbation settings. To address this limitation, we propose a model-agnostic perturbation-aware training framework based on Supervised Data Augmentation ( Aug ) and Contrastive Learning ( CL )—considering both self-supervised and supervised variants. Unlike architecture-specific solutions, our approach operates at the learning strategy level , allowing it to be seamlessly applied to diverse classifiers without requiring structural modifications. Adopting Mimetic-Enhanced as a primary multimodal case study, we integrate the proposed strategies into its two-stage training pipeline. Experimental results demonstrate that perturbation-aware training not only improves TC effectiveness on clean (i.e., unperturbed) traffic—particularly when applied across both training stages—but also significantly strengthens the model’s robustness under diverse and realistic perturbation scenarios. Furthermore, we investigate Out-of-Distribution (OOD) detection, model calibration, and TC effectiveness in low-data regimes. Finally, we explicitly demonstrate the framework’s generalizability by validating it on other SOTA architectures, spanning both single- and multi-modal approaches.
Idio Guarino, Giampaolo Bovenzi, Alfredo Nascita, Domenico Ciuonzo, Damiano Carra, Antonio Pescapè
Comput. Networks6
2026 Analyzing the impact of shifts in encrypted mobile-app traffic on multimodal few-shot learning
abstract
Network management is essential for ensuring efficient and secure Internet operations, with traffic classification serving as a core element. Currently, traffic classification is facing increasing challenges due to the growing presence of highly dynamic mobile-app traffic , being fueled by the continuous release of new apps, frequent updates, evolving communication patterns, and stricter encrypted protocols. These shifts can significantly alter traffic patterns, making it difficult to keep state-of-the-art machine and deep learning-based traffic classifiers up to date, due to the severe lack of current, high-quality traffic datasets needed to train and adapt such data-driven models. Few-Shot Learning ( FSL ) offers a promising solution by enabling classification even when only a limited amount of labeled traffic data is available. However, the investigation of FSL in the domain of traffic classification is still in its early stages, with the impact of traffic shifts being largely underexplored. In this paper, we evaluate how the traffic from new apps (those unseen during training) and shifted apps (those affected by traffic changes) impacts classification performance by leveraging Meta Mimetic , a state-of-the-art multimodal FSL approach. Meta Mimetic exploits multiple views of traffic data and integrates an ad-hoc learning procedure to adapt to the evolving mobile-app traffic using minimal supervised data. Our experiments are conducted on two publicly available datasets, encompassing both new apps and shifted apps. First, we assess the presence of traffic changes in shifted apps through Markov-based statistical modeling and evaluate the impact on the performance of Meta Mimetic when considering such traffic. We then show that Meta Mimetic exhibits strong adaptability to shifts introduced by stricter encrypted protocols, having a performance degradation 2 × lower than single-modal baselines, as further validated using eXplainable AI (XAI) . Finally, in case of extreme data scarcity, we show that Meta Mimetic can effectively use old traffic for data augmentation, regardless of shifts, achieving up to a + 12 % F1-score improvement over alternative methods.
Davide Di Monda, Giampaolo Bovenzi, Antonio Montieri, Valerio Persico, Antonio Pescapè
Comput. Networks5
2026 From prompts to packets: A view from the network on ChatGPT, Copilot, and Gemini
abstract
Generative AI (GenAI) chatbots are now pervasive in digital ecosystems, fundamentally reshaping user interactions over the Internet. Their reliance on an always-online, cloud-centric operating model introduces novel traffic dynamics that challenge practical network management. Despite the critical need to anticipate these changes in network demand, the traffic characterization of these chatbots remains largely underexplored. To fill this gap, this study presents an in-depth traffic analysis of ChatGPT , Copilot , and Gemini used via Android mobile apps. Using a dedicated capture architecture, we collect two complementary datasets, combining unconstrained user interactions with a controlled workload of selected prompts for both text and image generation. This dual design allows us to address practical research questions on the distinctiveness of chatbot traffic, its divergence from that of conventional messaging apps, and its novel implications for network usage. To this end, we provide a multi-granular traffic characterization and model packet-sequence dynamics to uncover the underlying transmission mechanisms. Our analysis reveals app-/content-specific traffic patterns and distinctive protocol footprints. We highlight the predominance of TLS, with Gemini extensively leveraging QUIC, ChatGPT exclusively using TLS 1.3, and characteristic Server Name Indication (SNI) values. Through occlusion analysis, we quantify the reliance on SNI for traffic visibility, demonstrating that masking this field reduces classification performance by up to 20 percentage points. Finally, the comparison with conventional messaging apps confirms that GenAI workloads introduce novel stress factors, such as sustained upstream activity and high-rate bursts, with direct implications for capacity planning and network management. We publicly release the datasets to support reproducibility and foster extensions to other use cases.
Antonio Montieri, Alfredo Nascita, Antonio Pescapè
Comput. Networks3
2026 A Federated and Incremental Network Intrusion Detection System for IoT Emerging Threats
abstract
Ensuring network security is increasingly challenging, especially in the Internet of Things (IoT) domain, where threats are diverse, rapidly evolving, and often device-specific. Hence, Network Intrusion Detection Systems (NIDSs) require(i)being trained on network traffic gathered in different collection points to cover the attack traffic heterogeneity,(ii)continuously learning emerging threats (viz., 0-day attacks), and(iii)be able to take attack countermeasures as soon as possible. In this work, we aim to improve Artificial Intelligence (AI)-based NIDS design & maintenance by integrating Federated Learning (FL) and Class Incremental Learning (CIL). Specifically, we devise a Federated Class Incremental Learning (FCIL) framework–suited for early-detection settings—that supports decentralized and continual model updates, investigating the non-trivial intersection of FL algorithms with state-of-the-art CIL techniques to enable scalable, privacy-preserving training in highly non-IID environments. We evaluate FCIL on three IoT datasets across different client scenarios to assess its ability to learn new threats and retain prior knowledge. The experiments assess potential key challenges in generalization and few-sample training, and compare NIDS performance to monolithic and centralized baselines.
Raffaele Carillo, Francesco Cerasuolo, Giampaolo Bovenzi, Domenico Ciuonzo, Antonio Pescapè
IEEE Trans. Netw. Serv. Manag.5
2025 Enhancing Data Offloading in Urban Networks via Machine Learning-based Mobility Prediction
Ilaria Mangiacapra, Paulo Carvalho 0002, Antonio Montieri, Antonio Pescapè, Emanuel Lima, Solange Rito Lima
CNSM4
2025 Rapid Few-Shot Learning for Resilient Multi-Domain Intrusion Detection
abstract
Modern networking infrastructures—composed of heterogeneous architectures and configurations, i.e. domains—introduce complexity that significantly amplifies the potential attack surface. Machine and deep learning-based Network Intrusion Detection Systems (NIDS), though promising, (i) require extensive labeled datasets and (ii) must undergo complete re-training when adapting to novel network domains, making them impractical in dynamic multi-domain environments. To address these challenges, we propose MD-RFS, a Few-Shot Learning NIDS based on the Rethinking Few-Shot approach, specifically designed for multiple network domains. MD-RFS employs a 2-step learning procedure that quickly adapts from a source domain to a target domain using only a limited number of labeled traffic data, while crucially preserving its detection capabilities on the original source domain. An extensive experimental evaluation—spanning three heterogeneous domains (viz. traditional IP, IoT, and SDN), each represented by a recent and publicly-available dataset—demonstrates the efficacy of MD-RFS. In ideal conditions, MD-RFS maintains near upper-bound detection performance on the source domain while having good adaptation performance. In a realistic few-shot scenarios, MD-RFS achieves adaptation results comparable to the best baseline competitor, yet significantly reduces adaptation time by 2 orders of magnitude. These findings are further validated through visual explainability analysis. The implementation is publicly available to foster reproducibility and further research.
Davide Di Monda, Furquan Rustam, Anca Jurcut, Antonio Pescapè
GLOBECOM4
2025 Localizing and Exploiting Concept Areas in LLMs for Downstream Classification Tasks
abstract
Localizing knowledge within Large Language Models (LLMs) is crucial for interpreting their mechanisms and outcomes. Whereas knowledge attribution has so far provided local sample-level explanations, in this work we argue that whenever LLMs are used for classification tasks, a class-level explanation is preferable. We therefore define broader concept areas, i.e., regions of the LLM comprising a small set of neurons that contains the most salient knowledge pertaining to each class and propose methods to identify such areas. We apply our methodology to BERT-based LLMs fine-tuned for downstream classification tasks such as sentiment analysis and attack classification: our results show that it is possible to (i) identify crucial sets of neurons that determine the behaviour of fine-tuned LLMs for explanation purposes, as well as (ii) exploit such concept areas to improve their classification outcomes-yielding up to 6% macro F1-Score improvement on sentiment analysis (public dataset) and 2% on attack classification (private dataset) without requiring further fine-tuning.
Alfredo Nascita, Jonatan Krolikowski, Valerio Persico, Antonio Pescapè, Dario Rossi 0001
IJCNN4
2025 Analyzing the Impact of Encryption on Traffic Classification through Explainable AI
Davide Di Monda, Alfredo Nascita, Raffaele Carillo, Antonio Pescapè
Networking4
2025 Explainable federated class incremental learning for Encrypted Network Traffic classification
abstract
Network traffic has experienced substantial growth in recent years, requiring the implementation of more advanced techniques for effective management. In this context, Traffic Classification (TC) helps in successfully handling the network by identifying what is flowing through it. Nowadays, data-driven approaches—viz., Machine Learning (ML) and Deep Learning (DL)—are widely employed to address this task. However, these approaches struggle to keep pace with the ever-changing nature of traffic due to the introduction of new or updated services/apps and exhibit a decision-making process not interpretable. Furthermore, network traffic can vary significantly by geographic area , requiring a decentralized privacy-preserving approach to update classifiers collaboratively. In this work, we propose a Federated Class Incremental Learning (FCIL) framework that integrates Class Incremental Learning (CIL) and Federated Learning (FL) for network TC while incorporating a comprehensive eXplainable Artificial Intelligence (XAI) methodology, tackling the challenges of updating traffic classifiers, managing the geographic diversity of traffic along with data privacy, and interpreting the decision-making process, respectively. To assess our proposal, we leverage two publicly available encrypted network traffic datasets. Our findings uncover that, in small networks, fewer synchronizations facilitate retaining old knowledge, while larger networks reveal an approach-dependent pattern, yet still exhibiting good retention performance. Moreover, in both small and larger networks, frequent updates enhance the assimilation of new information . Notably, B i C + is the most effective approach in small networks (i.e., 2 clients) while i C a R L + performs best in larger networks (i.e., 10 clients), obtaining 82% and 79% F1 on C E S N E T - T L S 2 2 , respectively. Leveraging XAI techniques, we analyze the effect of incorporating a per-client bias correction layer. By integrating sample-based and attribution-based explanations, we provide detailed insights into the decision-making process of FCIL approaches .
Raffaele Carillo, Francesco Cerasuolo, Giampaolo Bovenzi, Domenico Ciuonzo, Antonio Pescapè
Comput. Networks5
2025 Attack-adaptive network intrusion detection systems for IoT networks through class incremental learning
abstract
The advent of the Internet of Things (IoT) has ushered in an era of unprecedented connectivity and convenience, enabling everyday objects to gather and share data autonomously, revolutionizing industries, and improving quality of life. However, this interconnected landscape poses cybersecurity challenges, as the expanded attack surface exposes vulnerabilities ripe for exploitation by malicious actors. The surge in network attacks targeting IoT devices underscores the urgency for robust and evolving security measures. Class Incremental Learning (CIL) emerges as a dynamic strategy to address these challenges, empowering Machine Learning (ML) and Deep Learning (DL) models to adapt to evolving threats while maintaining proficiency in detecting known ones. In the context of IoT security, characterized by the constant emergence of novel attack types, CIL offers a powerful means to enhance Network Intrusion Detection Systems (NIDS) resilience and network security. This paper aims to investigate how CIL methods can support the evolution of NIDS within IoT networks ( i ) by evaluating both attack detection and classification tasks — optimizing hyperparameters associated with the incremental update or to the traffic input definition—and ( i i ) by addressing also key research questions related to real-world NIDS challenges —such as the explainability of decisions, the robustness to perturbation of traffic inputs, and scenarios with a scarcity of new-attack samples. Leveraging 4 recently-collected and comprehensive IoT attack datasets , the study aims to evaluate the effectiveness of CIL techniques in classifying 0-day attacks.
Francesco Cerasuolo, Giampaolo Bovenzi, Domenico Ciuonzo, Antonio Pescapè
Comput. Networks4
2025 An integration perspective of security, privacy, and resource efficiency in IoT-Fog networks: A comprehensive survey
Saeed Javanmardi, Alfredo Nascita, Antonio Pescapè, Giovanni Merlino, Marco Scarpa
Comput. Networks3
2025 Adaptable, incremental, and explainable network intrusion detection systems for internet of things
Francesco Cerasuolo, Giampaolo Bovenzi, Domenico Ciuonzo, Antonio Pescapè
Eng. Appl. Artif. Intell.4
2025 Generative AI-Empowered Digital Twin: A Comprehensive Survey With Taxonomy
abstract
Generative artificial intelligence (GenAI) and digital twin (DT) technologies have individually demonstrated valuable capabilities across a range of fields. Their integration, however, offers a unique synergy with the potential to bring meaningful advancements in various sectors. In this survey, we explore the fusion of GenAI and DT, highlighting their combined ability to enhance insights, optimizations, and innovative solutions. We begin by clarifying the core principles of each technology and then outline their collaborative applications. Furthermore, we provide a detailed taxonomy of areas where GenAI has been leveraged within the realm of DT, and conversely, where DT technology has been enhanced through GenAI techniques. By systematically categorizing these applications, we aim to offer a clear perspective on the interplay between GenAI and DT across different sectors.
Diletta Chiaro, Pian Qi, Antonio Pescapè, Francesco Piccialli
IEEE Trans. Ind. Informatics3
2025 Mapping the Landscape of Generative AI in Network Monitoring and Management
abstract
Generative Artificial Intelligence (GenAI) models such as LLMs, GPTs, and Diffusion Models have recently gained widespread attention from both the research and the industrial communities. This survey explores their application in network monitoring and management, focusing on prominent use cases, as well as challenges and opportunities. We discuss how network traffic generation and classification, network intrusion detection, networked system log analysis, and network digital assistance can benefit from the use of GenAI models. Additionally, we provide an overview of the available GenAI models, datasets for large-scale training phases, and platforms for the development of such models. Finally, we discuss research directions that potentially mitigate the roadblocks to the adoption of GenAI for network monitoring and management. Our investigation aims to map the current landscape and pave the way for future research in leveraging GenAI for network monitoring and management.
Giampaolo Bovenzi, Francesco Cerasuolo, Domenico Ciuonzo, Davide Di Monda, Idio Guarino, Antonio Montieri, Valerio Persico, Antonio Pescapè
IEEE Trans. Netw. Serv. Manag.8
2024 Explainable Few-Shot Class Incremental Learning for Mobile Network Traffic Classification
abstract
Mobile Traffic Classification (TC) increasingly relies on Machine Learning (ML) and Deep Learning (DL) to enhance network management. Yet, these methods face challenges in (i) classifying new apps, (ii) handling data scarcity from frequent app releases/updates, and (iii) explaining their decisions due to their opaqueness. Class Incremental Learning (CIL) and Few-Shot Learning (FSL) enable to quickly update models and learn with very limited data, respectively, while eXplainable AI (XAI) enhances decision transparency. In this work, we merge CIL and FSL to update models with new apps under few sample constraints. First, we introduce SWEET, a CIL-originated approach that flexibly accommodates different few-sample scenarios via adaptive traffic augmentation. Second, we devise an XAI methodology based on visualization-, sample-, and attribution-based techniques to explore practical incremental learning. We evaluate both contributions on the public mobile traffic dataset MIRAGE19.
Francesco Cerasuolo, Giampaolo Bovenzi, Vincenzo Spadari, Domenico Ciuonzo, Antonio Pescapè
GLOBECOM5
2024 A Comparison Between Classical and Quantum Machine Learning for Mobile App Traffic Classification
abstract
Network traffic analysis is essential for modern communication systems, focusing on tasks like traffic classification, prediction, and anomaly detection. While classical Machine Learning (ML) and Deep Learning (DL) methods have proven effective, their scalability and real-time performance can be limited by evolving traffic patterns and computational demands. Quantum Machine-Learning (QML) offers a promising alternative by utilizing quantum computing's parallelism. This paper examines QML's application in mobile traffic classification, comparing classical methods such as Multi-layer Perceptron (MLP) and Convolutional Neural Networks (CNNs) with Quantum Neural Networks (QNNs) using different embedding types. Our experiments, conducted on the MIRAGE-COVID-CCMA-2022 dataset, show that QNNs achieve competitive performance, indicating QML's potential for efficient large-scale traffic classification in future networks.
Vincenzo Spadari, Idio Guarino, Domenico Ciuonzo, Antonio Pescapè
SEC4
2024 An MLOps Framework for Explainable Network Intrusion Detection with MLflow
abstract
The surge in network traffic has required advanced techniques to ensure network security. Network Intrusion Detection Systems (NIDSs), which increasingly employ Machine Learning (ML) and Deep Learning (DL) methodologies, play a pivotal role in this task by continuously monitoring network traffic patterns and identifying suspicious activities. To address the complexities of developing ML- and DL-based NIDS, MLOps tools have been designed to optimize model deployment, monitoring, and management in production environments, streamlining model development. These tools enable efficient experimentation, version management, and logging of artifacts for network administrators and data scientists. In this work, we design a framework powered by MLflow to manage the ML pipeline from data handling to results visualization. To show the effectiveness of our framework, we conducted an experimental campaign on 4 broadly used security datasets (viz. NSL-KDD, IoT-23, Kitsune, and TON_IoT) performing crucial tasks for intrusion detection, namely anomaly detection, binary misuse detection, and multiclass misuse detection.
Vincenzo Spadari, Francesco Cerasuolo, Giampaolo Bovenzi, Antonio Pescapè
ISCC4
2024 Mirage-App×Act-2024: A Novel Dataset for Mobile App and Activity Traffic Analysis
Idio Guarino, Domenico Ciuonzo, Antonio Montieri, Antonio Pescapè
WiMob4
2024 MEMENTO: A novel approach for class incremental learning of encrypted traffic
abstract
In the ever-changing digital environment, ensuring the ongoing effectiveness of traffic analysis and security measures is crucial. Therefore, Class Incremental Learning (CIL) in encrypted Traffic Classification (TC) is essential for adapting to evolving network behaviors and the rapid development of new applications. However, the application of CIL techniques in the TC domain is not straightforward, usually leading to unsatisfactory performance figures. Specifically, the improvement goal is to reduce forgetting on old apps and increase the capacity in learning new ones, in order to improve overall classification performance— reducing the drop from a model “trained-from-scratch”. The contribution of this work is the design of a novel fine-tuning approach called MEMENTO, which is obtained through the careful design of different building blocks: memory management, model training, and rectification strategies. In detail, we propose the application of traffic biflows augmentation strategies to better capitalize on old apps biflows, we introduce improvements in the distillation stage, and we design a general rectification strategy that includes several existing proposals. To assess our proposal, we leverage two publicly-available encrypted network traffic datasets, i.e., MIRAGE19 and CESNET-TLS22. As a result, on both datasets MEMENTO achieves a significant improvement in classifying new apps (w.r.t. the best-performing alternative, i.e., BiC) while maintaining stable performance on old ones. Equally important, MEMENTO achieves satisfactory overall TC performance, filling the gap toward a trained-from-scratch model and offering a considerable gain in terms of time (up to 10× speed-up) to obtain up-to-date and running classifiers. The experimental evaluation relies on a comprehensive performance evaluation workbench for CIL proposals, which is based on a wider set of metrics (as opposed to the existing literature in TC).
Francesco Cerasuolo, Alfredo Nascita, Giampaolo Bovenzi, Giuseppe Aceto, Domenico Ciuonzo, Antonio Pescapè, Dario Rossi 0001
Comput. Networks6
2024 MCOTM: Mobility-aware computation offloading and task migration for edge computing in industrial IoT
Haiming Chen 0002, Lei Wang 0195, Yinshui Xia, Alfredo Nascita, Antonio Pescapè
Future Gener. Comput. Syst.6
2024 Classifying attack traffic in IoT environments via few-shot learning
abstract
The Internet of Things (IoT) is a key enabler for critical systems, but IoT devices are increasingly targeted by cyberattacks due to their diffusion and hardware and software limitations. This calls for designing and evaluating new effective approaches for protecting IoT systems at the network level. While recent proposals based on machine- and deep-learning provide effective solutions to the problem of attack-traffic classification, their adoption is severely challenged by the amount of labeled traffic they require to train the classification models. In fact, this results in the need for collecting and labeling large amounts of malicious traffic, which may be hindered by the nature of the malware possibly generating little and hard-to-capture network activity. To tackle this challenge, we adopt few-shot learning approaches for attack-traffic classification, with the objective to improve detection performance for attack classes with few labeled samples. We leverage advanced deep-learning architectures to perform feature extraction and provide an extensive empirical study—using recent and publicly available datasets—comparing the performance of an ample variety of solutions based on different learning paradigms, and exploring a number of design choices in depth (impact of embedding function, number of classes of attacks, or number of attack samples). In comparison to non-few-shot baselines, we achieve a relative improvement in the F1-score ranging from 8% to 27%.
Giampaolo Bovenzi, Davide Di Monda, Antonio Montieri, Valerio Persico, Antonio Pescapè
J. Inf. Secur. Appl.5
2024 Synthetic and privacy-preserving traffic trace generation using generative AI models for training Network Intrusion Detection Systems
abstract
Network Intrusion Detection Systems (NIDS) are crucial tools for protecting networked devices from cyberattacks. Recent development in the field of Artificial Intelligence (AI) has provided tremendous advantages in implementing NIDSs able to monitor network traffic and block cyberattacks in real-time. In the literature, it is widely recognized that the effective training of a NIDS requires a large quantity of labeled traffic, representative of attacks. Nonetheless, the availability of public and abundant datasets remains remarkably restricted due to the cost of gathering and labeling real traffic traces and privacy concerns for sharing them. To tackle these challenges, in this paper we present a generative AI model capable of synthesizing anonymized traffic traces from real ones, thus dealing with privacy, abundance, and representativeness. The proposal is based on a Conditional Variational Autoencoder (CVAE) and a preprocessing procedure specifically designed for the generation of new traffic traces. To validate our solution, we conduct an extensive empirical study leveraging three recent and publicly-available datasets, containing benign and malicious traffic. The validation is carried out from both the perspectives of classification performance of a robust NIDS and the quality of synthetic data, in comparison to the utilization of real data. We compare our CVAE with two state-of-the-art AI-based traffic data generators and prove that, trained with traces emitted by our generative model, a NIDS has a limited F1-score loss compared to training on real data; competing models instead struggle or fail to generate traces that are as effective for NIDS training and as statistically similar to the original. We make the synthetic datasets available in both PCAP and tabular formats, to facilitate the reproducibility of our findings and encourage further exploration in the field of generative AI for networking.
Giuseppe Aceto, Fabio Giampaolo, Ciro Guida, Stefano Izzo, Antonio Pescapè, Francesco Piccialli, Edoardo Prezioso
J. Netw. Comput. Appl.5
2024 Benchmarking Class Incremental Learning in Deep Learning Traffic Classification
abstract
Traffic Classification (TC) is experiencing a renewed interest, fostered by the growing popularity of Deep Learning (DL) approaches. In exchange for their proved effectiveness, DL models are characterized by a computationally-intensive training procedure that badly matches the fast-paced release of new (mobile) applications, resulting in significantly limited efficiency of model updates. To address this shortcoming, in this work we systematically explore Class Incremental Learning (CIL) techniques, aimed at adding new apps/services to pre-existing DL-based traffic classifiers without a full retraining, hence speeding up the model’s updates cycle. We investigate a large corpus of state-of-the-art CIL approaches for the DL-based TC task, and delve into their working principles to highlight relevant insight, aiming to understand if there is a case for CIL in TC. We evaluate and discuss their performance varying the number of incremental learning episodes, and the number of new apps added for each episode. Our evaluation is based on the publicly available$\mathtt {MIRAGE19}$dataset comprising traffic of 40 popular Android applications, fostering reproducibility. Despite our analysis reveals their infancy, CIL techniques are a promising research area on the roadmap towards automated DL-based traffic analysis systems.
Giampaolo Bovenzi, Alfredo Nascita, Lixuan Yang, Alessandro Finamore, Giuseppe Aceto, Domenico Ciuonzo, Antonio Pescapè, Dario Rossi 0001
IEEE Trans. Netw. Serv. Manag.7
2023 Adaptive Intrusion Detection Systems: Class Incremental Learning for IoT Emerging Threats
abstract
In the evolving landscape of Internet of Things (IoT) security, the need for continuous adaptation of defenses is critical. Class Incremental Learning (CIL) can provide a viable solution by enabling Machine Learning (ML) and Deep Learning (DL) models to $( i)$ learn and adapt to new attack types (0-day attacks), $( ii)$ retain their ability to detect known threats, (iii) safeguard computational efficiency (i.e. no full re-training). In IoT security, where novel attacks frequently emerge, CIL offers an effective tool to enhance Intrusion Detection Systems (IDS) and secure network environments. In this study, we explore how CIL approaches empower DL-based IDS in IoT networks, using the publicly-available IoT-23 dataset. Our evaluation focuses on two essential aspects of an IDS: $( a)$ attack classification and $( b)$ misuse detection. A thorough comparison against a fully-retrained IDS, namely starting from scratch, is carried out. Finally, we place emphasis on interpreting the predictions made by incremental IDS models through eXplainable AI (XAI) tools, offering insights into potential avenues for improvement.
Francesco Cerasuolo, Giampaolo Bovenzi, Christian Marescalco, Francesco Cirillo, Domenico Ciuonzo, Antonio Pescapè
IEEE Big Data6
2023 IoT Botnet-Traffic Classification Using Few-Shot Learning
abstract
The Internet of Things (IoT) is experiencing a constant expansion, embedding connectivity into everyday objects for increased efficiency. Despite this, security vulnerabilities pose a growing concern because IoT devices often lack robust security measures, leaving room for IoT botnet malware action and underlining the critical need for increased IoT security. During the last years, Machine Learning (ML) and Deep Learning (DL) have offered effective tools against IoT attacks, but these solutions struggle with identifying novel threats. In fact, the dynamic nature of IoT ecosystems requires data-driven systems capable of responding promptly to emerging threats, characterized by the limited availability of samples for training.In this context, we exploit Few-Shot Learning (FSL) to effectively identify emerging network attacks within the traffic generated by IoT devices by performing botnet-traffic classification. In detail, FSL enables ML and DL models to recognize and adapt to novel classes of attack traffic with minimal available samples, tackling class imbalance issues between high-frequency and lowfrequency attacks (which generate high and low network traffic, respectively). This strategic integration of FSL is crucial in enhancing overall IoT security, providing a proactive approach to handle dynamic and imbalanced scenarios, and ensuring the resilience of interconnected systems. The experimental evaluation is conducted on the publicly available IoT-23 dataset. The results highlight that the best FSL approach obtains the highest performance figures with just 3 shots, scoring 92% F1-score when discriminating low-frequency botnet malware. Noteworthy, satisfactory performance (up to 93% F1-score) is achieved also in misuse detection, proving the capability to distinguish between legitimate and malicious traffic.
Davide Di Monda, Giampaolo Bovenzi, Antonio Montieri, Valerio Persico, Antonio Pescapè
IEEE Big Data5
2023 Fine-Grained Traffic Prediction of Communication-and-Collaboration Apps Via Deep-Learning: A First Look at Explainability
abstract
The lifestyle change originated from the COVID-19 pandemic has caused a measurable impact on Internet traffic in terms of volume and application mix, with a sudden increase in usage of communication-and-collaboration apps. In this work, we focus on four of these apps (Skype, Teams, Webex, and Zoom), whose traffic we collect, reliably label at fine (i.e. per-activity) granularity, and analyze from the viewpoint of traffic prediction. The outcome of this analysis is informative for a number of network management tasks, including monitoring, planning, resource provisioning, and (security) policy enforcement. To this aim, we employ state-of-the-art multitask deep learning approaches to assess to which degree the traffic generated by these apps and their different use cases (i.e. activities: audio-call, video-call, and chat) can be forecast at packet level. The experimental analysis investigates the performance of the considered deep learning architectures, in terms of both traffic-prediction accuracy and complexity, and the related trade-off. Equally important, our work is a first attempt at interpreting the results obtained by these predictors via eXplainable Artificial Intelligence (XAI).
Idio Guarino, Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Valerio Persico, Antonio Pescapè
ICC6
2023 Network anomaly detection methods in IoT environments via deep learning: A Fair comparison of performance and robustness
abstract
The Internet of Things (IoT) is a key enabler in closing the loop in Cyber-Physical Systems, providing “smartness” and thus additional value to each monitored/controlled physical asset. Unfortunately, these devices are more and more targeted by cyberattacks because of their diffusion and of the usually limited hardware and software resources. This calls for designing and evaluating new effective approaches for protecting IoT systems at the network level (Network Intrusion Detection Systems, NIDSs). These in turn are challenged by the heterogeneity of IoT devices and the growing volume of transmitted data. To tackle this challenge, we select a Deep Learning architecture to perform unsupervised early anomaly detection. With a data-driven approach, we explore in-depth multiple design choices and exploit the appealing structural properties of the selected architecture to enhance its performance. The experimental evaluation is performed on two recent and publicly available IoT datasets (IoT-23 and Kitsune). Finally, we adopt an adversarial approach to investigate the robustness of our solution in the presence of Label Flipping poisoning attacks. The experimental results highlight the improved performance of the proposed architecture, in comparison to both well-known baselines and previous proposals.
Giampaolo Bovenzi, Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Valerio Persico, Antonio Pescapè
Comput. Secur.6
2023 S-FoS: A secure workflow scheduling approach for performance optimization in SDN-based IoT-Fog networks
Saeed Javanmardi, Mohammad Shojafar, Reza Mohammadi 0003, Valerio Persico, Antonio Pescapè
J. Inf. Secur. Appl.5
2023 Improving Performance, Reliability, and Feasibility in Multimodal Multitask Traffic Classification with XAI
abstract
The promise of Deep Learning (DL) in solving hard problems such as network Traffic Classification (TC) is being held back by the severe lack of transparency and explainability of this kind of approaches. To cope with this strongly felt issue, the field of eXplainable Artificial Intelligence (XAI) has been recently founded, and is providing effective techniques and approaches. Accordingly, in this work we investigate interpretability via XAIbased techniques to understand and improve the behavior of state-of-the-art multimodal and multitask DL traffic classifiers. Using a publicly available security-related dataset (ISCX VPNNONVPN), we explore and exploit XAI techniques to characterize the considered classifiers providing global interpretations (rather than sample-based ones), and define a novel classifier, DISTILLER-EVOLVED, optimized along three objectives: performance, reliability, feasibility. The proposed methodology proves as highly appealing, allowing to much simplify the architecture to get faster training time and shorter classification time, as fewer packets must be collected. This is at the expenses of negligible (or even positive) impact on classification performance, while understanding and controlling the interplay between inputs, model complexity, performance, and reliability.
Alfredo Nascita, Antonio Montieri, Giuseppe Aceto, Domenico Ciuonzo, Valerio Persico, Antonio Pescapè
IEEE Trans. Netw. Serv. Manag.6
2022 Data Poisoning Attacks against Autoencoder-based Anomaly Detection Models: a Robustness Analysis
abstract
The Internet of Things (IoT) is experiencing a strong growth in both industrial and consumer scenarios. At the same time, the devices taking part in delivering IoT services—usually characterized by limited hardware and software resources—are more and more targeted by cyberattacks. This calls for designing and evaluating new approaches for protecting IoT systems, which are challenged by the limited computational capabilities of devices and by the scarce availability of reliable datasets. In line with this need, in this paper we compare three state-of-the-art machine-learning models used for Anomaly Detection based on autoencoders, i.e. shallow Autoencoder, Deep Autoencoder (DAE), and Ensemble of Autoencoders (viz. KitNET). In addition, we evaluate the robustness of such solutions when Data Poisoning Attack (DPA) occurs, to assess the detection performance when the benign traffic used for learning the legitimate behavior of devices is mixed to malicious traffic. The evaluation relies on the public Kitsune Network Attack Dataset. Results reveal that the models do not differ in performance when trained with unpoisoned benign traffic, reaching (at 1% FPR) an F1 score of ≈ 97%. However, when DPA occurs, DAE proves to be the more robust in detection, showing more than 50% of F1 Score with 10% poisoning. Instead, the other models show strong performance drops (down to ≈ 20% F1 Score) by injecting only 0.5% of the malicious traffic.
Giampaolo Bovenzi, Alessio Foggia, Salvatore Santella, Alessandro Testa, Valerio Persico, Antonio Pescapè
ICC6
2022 A First Look at Accurate Network Traffic Generation in Virtual Environments
abstract
The generation of synthetic network traffic is necessary to several fundamental networking activities, ranging from device testing to path monitoring, with implications on security and management. While literature focused on high-rate traffic generation, for many use cases accurate traffic generation is of importance instead. These scenarios have expanded with Network Function Virtualization, Software Defined Networking, and Cloud applications, which introduce further causes for alterations of generated traffic. Such causes are described and experimentally evaluated in this work, where the generation accuracy of D-ITG, an open-source software generator, is investigated in a virtualized environment. A definition of accuracy in terms of Mean Absolute Percentage Error of the sequences of Payload Lengths (PLs) and Inter-Departure Times (IDTs) is exploited to this end. The tool is found accurate for all PLs and for IDTs greater than one millisecond, and after the correction of a systematic error, also from 100 us.
Giuseppe Aceto, Ciro Guida, Antonio Montieri, Valerio Persico, Antonio Pescapè
ISCC5
2022 A Comparison of Machine and Deep Learning Models for Detection and Classification of Android Malware Traffic
abstract
With the increasing popularity of mobile-app services, malicious software is increasing as well. Accordingly, the interest of the scientific community in Machine and Deep Learning solutions for detecting and classifying malware traffic is growing. In this work, we provide a fair assessment of the performance of a number of data-driven strategies to detect and classify Android malware traffic. Three models are taken into account (Decision Tree, Random Forest, and 1-D Convolutional Neural Network) considering both flat (i.e. non-hierarchical) and hierarchical approaches. The experimental analysis performed using a state-of-art dataset (CIC-AAGM2017) reports that Random Forest exhibits the best performance in a flat setup, while moving to a hierarchical approach could cause significant variation in precision and recall. Such results push for further investigating advanced hierarchical setups and learning schemes.
Giampaolo Bovenzi, Francesco Cerasuolo, Antonio Montieri, Alfredo Nascita, Valerio Persico, Antonio Pescapè
ISCC6
2022 Hierarchical Classification of Android Malware Traffic
abstract
In the last few years, Android mobile devices have encountered a large spread and nowadays a huge part of the traffic traversing the Internet is related to them. In parallel, the number of possible threats and attacks has also increased, thus emphasizing the need for accurate automatic malware detection systems. In this paper, we design and evaluate a system to detect whether a traffic object (biflow) is benign or malicious, possibly understanding its specific nature in the latter case. The proposal leverages machine learning in a hierarchical fashion, in order to capitalize on the structure of the traffic data and reap both design and performance benefits. The comparative evaluation—performed considering the public CICAndMal2017 dataset—assesses the performance of several machine-learning algorithms and witnesses that the hierarchical approach leads to improved performance w.r.t. the flat approach (up to +0.18 F1-score, depending on the granularity of the analysis and the machine learning algorithm considered). In addition, we evaluate the impact of a reject-option mechanism, showing the trade-off between classification accuracy and ratio of classified biflows.
Giampaolo Bovenzi, Valerio Persico, Antonio Pescapè, Anna Piscitelli, Vincenzo Spadari
TrustCom3
2022 Contextual counters and multimodal Deep Learning for activity-level traffic classification of mobile communication apps during COVID-19 pandemic
Idio Guarino, Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Valerio Persico, Antonio Pescapè
Comput. Networks6
2021 Encrypted Multitask Traffic Classification via Multimodal Deep Learning
abstract
Traffic Classification (TC), i.e. the collection of procedures for inferring applications and/or services generating network traffic, represents the workhorse for service management and the enabler for valuable profiling information. Sadly, the growing trend toward encrypted protocols (e.g. TLS) and the evolving nature of network traffic make TC design solutions based on payload-inspection and machine learning, respectively, unsuitable. Conversely, Deep Learning (DL) is currently foreseen as a viable means to design traffic classifiers based on automatically-extracted features, reflecting the complex patterns distilled from the multifaceted (encrypted) traffic nature, implicitly carrying information in "multimodal" fashion. To this end, in this paper a novel multimodal DL approach for multitask TC is explored. The latter is able to capitalize traffic data heterogeneity (by learning both intra- and inter-modality dependencies), overcome performance limitations of existing (myopic) single-modality DL-based TC proposals, and solve different traffic categorization problems associated with different providers’ desiderata. Based on a real dataset of encrypted traffic, we report performance gains of our proposal over (a) state-of-art multitask DL architectures and (b) multitask extensions of single-task DL baselines (both based on single-modality philosophy).
Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Alfredo Nascita, Antonio Pescapè
ICC5
2021 Packet-level prediction of mobile-app traffic using multitask Deep Learning
Antonio Montieri, Giampaolo Bovenzi, Giuseppe Aceto, Domenico Ciuonzo, Valerio Persico, Antonio Pescapè
Comput. Networks6
2021 Characterization and analysis of cloud-to-user latency: The case of Azure and AWS
Fabio Palumbo, Giuseppe Aceto, Alessio Botta, Domenico Ciuonzo, Valerio Persico, Antonio Pescapè
Comput. Networks6
2021 FUPE: A security driven task scheduling approach for SDN-based IoT-Fog networks
Saeed Javanmardi, Mohammad Shojafar, Reza Mohammadi 0003, Amin Nazari, Valerio Persico, Antonio Pescapè
J. Inf. Secur. Appl.6
2021 DISTILLER: Encrypted traffic classification via multimodal multitask deep learning
Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Antonio Pescapè
J. Netw. Comput. Appl.4
2021 FPFTS: A joint fuzzy particle swarm optimization mobility-aware approach to fog task scheduling algorithm for Internet of Things devices
abstract
Summary In the Internet of Things (IoT) scenario, the integration with cloud‐based solutions is of the utmost importance to address the shortcomings resulting from resource‐constrained things that may fall short in terms of processing, storing, and networking capabilities. Fog computing represents a more recent paradigm that leverages the wide‐spread geographical distribution of the computing resources and extends the cloud computing paradigm to the edge of the network, thus mitigating the issues affecting latency‐sensitive applications and enabling a new breed of applications and services. In this context, efficient and effective resource management is critical, also considering the resource limitations of local fog nodes with respect to centralized clouds. In this article, we present FPFTS, fog task scheduler that takes advantage of particle swarm optimization and fuzzy theory, which leverages observations related to application loop delay and network utilization. We evaluate FPFTS using an IoT‐based scenario simulated within iFogSim, by varying number of moving users, fog‐device link bandwidth, and latency. Experimental results report that FPFTS compared with first‐come first‐served (respectively, delay‐priority) allows to decrease delay‐tolerant application loop delay by 85.79% (respectively, 86.36%), delay sensitive application loop delay by 87.11% (respectively, 86.61%), and network utilization by 80.37% (respectively, 82.09%), on average.
Saeed Javanmardi, Mohammad Shojafar, Valerio Persico, Antonio Pescapè
Softw. Pract. Exp.4
2021 A Secure Adaptive Control for Cooperative Driving of Autonomous Connected Vehicles in the Presence of Heterogeneous Communication Delays and Cyberattacks
abstract
The development of autonomous connected vehicles, moving as a platoon formation, is a hot topic in the intelligent transportation system (ITS) research field. It is on the road and deployment requires the design of distributed control strategies, leveraging secure vehicular ad-hoc networks (VANETs). Indeed, wireless communication networks can be affected by various security vulnerabilities and cyberattacks leading to dangerous implications for cooperative driving safety. Control design can play an important role in providing both resilience and robustness to vehicular networks. To this aim, in this article, we tackle and solve the problem of cyber-secure tracking for a platoon that moves as a cohesive formation along a single lane undergoing different kinds of cyber threats, that is, application layer and network layer attacks, as well as network induced phenomena. The proposed cooperative approach leverages an adaptive synchronization-based control algorithm that embeds a distributed mitigation mechanism of malicious information. The closed-loop stability is analytically demonstrated by using the Lyapunov-Krasovskii theory, while its effectiveness in coping with the most relevant type of cyber threats is disclosed by using PLEXE, a high fidelity simulator which provides a realistic simulation of cooperative driving systems.
Alberto Petrillo, Antonio Pescapè, Stefania Santini
IEEE Trans. Cybern.2
2021 Characterization and Prediction of Mobile-App Traffic Using Markov Modeling
abstract
Modeling network traffic is an endeavor actively carried on since early digital communications, supporting a number of practical applications, that range from network planning and provisioning to security. Accordingly, many theoretical and empirical approaches have been proposed in this long-standing research, most notably, Machine Learning (ML) ones. Indeed, recent interest from network equipment vendors is sparking around the evaluation of solid information-theoretical modeling approaches complementary to ML ones, especially applied to new network traffic profiles stemming from the massive diffusion of mobile apps. To cater to these needs, we analyze mobile-app traffic available in the public dataset MIRAGE-2019 adopting two related modeling approaches based on the well-known methodological toolset of Markov models (namely, Markov Chains and Hidden Markov Models). We propose a novel heuristic to reconstruct application-layer messages in the common case of encrypted traffic. We discuss and experimentally evaluate the suitability of the provided modeling approaches for different tasks: characterization of network traffic (at different granularities, such as application, application category, and application version), and prediction of network traffic at both packet and message level. We also compare the results with several ML approaches, showing performance comparable to a state-of-the-art ML predictor (Random Forest Regressor). Also, with this work we provide a viable and theoretically sound traffic-analysis toolset to help improving ML evaluation (and possibly its design), and a sensible and interpretable baseline.
Giuseppe Aceto, Giampaolo Bovenzi, Domenico Ciuonzo, Antonio Montieri, Valerio Persico, Antonio Pescapè
IEEE Trans. Netw. Serv. Manag.6
2021 The Art of Detecting Forwarding Detours
abstract
The full Internet feed, reaching ~867K prefixes as of March 2021, has been growing at ≈50K prefixes/year over the last 10 years. To counterbalance this sustained increase, Autonomous Systems (ASes) may filter prefixes, perform prefix aggregation and use default routes. Despite being effective, such workarounds may result in routing inconsistencies, i.e., in routers along a forwarding route mapping the same IP addresses to different IP prefixes. In turn, the exit AS border routers associated with these distinct prefixes may potentially differ. For some prefixes, forwarding detours (FDs) may occur, i.e., traffic may deviate from best IGP paths. In this work we investigate the phenomenon of FDs and derive a methodology to detect them. In particular, our tool is able to pinpoint cases where multiple prefixes are subject to FDs. We run measurements from 100 vantage points of the NLNOG RING monitoring infrastructure and find FDs in 25 out of 54 ASes. We see that FDs are heterogeneous, i.e., the number of prefixes and AS border routers in between which we detect FDs strongly depend on the studied AS. Finally, we discover a remarkable binary effect such that either all transit traffic traversing between two border routers of an AS detours, or none does.
Julián Martin Del Fiore, Valerio Persico, Pascal Mérindol, Cristel Pelsser, Antonio Pescapè
IEEE Trans. Netw. Serv. Manag.5
2021 XAI Meets Mobile Traffic Classification: Understanding and Improving Multimodal Deep Learning Architectures
abstract
The increasing diffusion of mobile devices has dramatically changed the network traffic landscape, with Traffic Classification (TC) surging into a fundamental role while facing new and unprecedented challenges. The recent and appealing adoption of Deep Learning (DL) techniques has risen as the solution overcoming the performance of ML techniques based on tedious and time-consuming handcrafted feature design. Still, the black-box nature of DL models prevents its practical and trustful adoption in critical scenarios where the reliability/interpretation of results/policies is of key importance. To cope with these limitations, eXplainable Artificial Intelligence (XAI) techniques have recently acquired the interest of the community. Accordingly, in this work we investigate trustworthiness and interpretability via XAI-based techniques to understand, interpret and improve the behavior of state-of-the-art multimodal DL traffic classifiers. The proposed methodology, as opposed to common results seen in XAI, attempts to provide global interpretation, rather than sample-based ones. Results, based on an open dataset, allow to complement the above findings with domain knowledge.
Alfredo Nascita, Antonio Montieri, Giuseppe Aceto, Domenico Ciuonzo, Valerio Persico, Antonio Pescapè
IEEE Trans. Netw. Serv. Manag.6
2020 A Hierarchical Hybrid Intrusion Detection Approach in IoT Scenarios
abstract
Internet of Things (IoT) fosters unprecedented network heterogeneity and dynamicity, thus increasing the variety and the amount of related vulnerabilities. Hence, traditional security approaches fall short, also in terms of resulting scalability and privacy. In this paper we propose H2ID, a two-stage hierarchical Network Intrusion Detection approach. H2ID performs (i) anomaly detection via a novel lightweight solution based on a MultiModal Deep AutoEncoder (M2-DAE), and (ii) attack classification, using soft-output classifiers. We validate our proposal using the recently-released Bot-IoT dataset, inferring among four relevant categories of attack (DDoS, DoS, Scan, and Theft) and unknown attacks. Results show gains of the proposed M2-DAE in the case of simple anomaly detection (up to -40% false-positive rate when compared with several baselines at same true positive rate) and for H2ID as a whole when compared to the best-performing misuse detector approach (up to ≈ +5% F1 score). Besides the performance advantages, our system is suitable for distributed and privacy-preserving deployments while limiting re-training necessities, in line with the high efficiency as well as the flexibility required in IoT scenarios.
Giampaolo Bovenzi, Giuseppe Aceto, Domenico Ciuonzo, Valerio Persico, Antonio Pescapè
GLOBECOM5
2020 A network performance view of a biobanking system for diagnostic images
abstract
A significant contribution of ICT to healthcare is constituted by systems automating and enhancing the management of research and clinical data. More specifically, PACS (Picture Archiving ad Communication Systems) have improved the efficiency of diagnostic images and clinical data management. Their evolution (image biobanks) are now enabling new collaborations and analysis possibilities similarly to—and beyond—the biobanks (their biologic samples analogous and complement). In this work we describe and evaluate the network performance of a biobanking system for diagnostic images, based on the XNAT open source platform, as implemented and operated by Bio Check Up Srl. The point of view of the user is adopted, in assessing the performance in three setups: local (virtual machines communicating in a single host), LAN (organization-local access), and VPN (remote secure access through the Internet). Both upload and download usage cases are considered, with both a medium-sized and big-sized set of diagnostic images. Several metrics are extracted from traffic traces captured in the experimental campaign, and discussed. Results show that the current setup is well provisioned for satisfying the planned number of concurrent users, and point to further experimental campaigns.
Giusy Esposito, Giulio Pagliari, Gianluca Coppola, Marco Aiello 0003, Marco Salvatore, Giuseppe Aceto, Antonio Pescapè
ISCC7
2020 Performance-based service-level agreement in cloud computing to optimise penalties and revenue
abstract
Cost, performance, and penalties are the key factors to revenue generation and customer satisfaction. They have a complex correlation, that gets more complicated when missing a proper framework that unambiguously defines these factors. Service‐level agreement (SLA) is the initial document discussing selected parameters as a precondition to business initialisation. The clear definition and application of the SLA is of paramount importance as for modern as a Service online businesses no direct communication between provider and consumer is expected. For the proper implementation of SLA, there should be a satisfactory approach for measuring and monitoring quality of service metrics. This study investigated these issues and proposed performance‐based SLA (PerSLA) framework for cost, performance, penalties and revenue optimisation. PerSLA optimises these parameters and maximises both provider revenue and customers satisfaction. Simulation results confirm that the proposed framework is adequate in revenue generation and customers satisfaction. Customers and providers monitor the business with respect to agreed terms and conditions. On violation, the provider is penalised. This agreement increases the trust in relationship between provider and consumer.
Afzal Badshah, Anwer Ghani, Shahab B. Band, Giuseppe Aceto, Antonio Pescapè
IET Commun.5
2020 Toward effective mobile encrypted traffic classification through deep learning
Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Antonio Pescapè
Neurocomputing4
2020 Computational intelligence intrusion detection techniques in mobile cloud computing environments: Review, taxonomy, and open research issues
Shahab B. Band, Mahdis Fathi, Anthony T. Chronopoulos, Antonio Montieri, Fabio Palumbo, Antonio Pescapè
J. Inf. Secur. Appl.6
2020 Anonymity Services Tor, I2P, JonDonym: Classifying in the Dark (Web)
abstract
Traffic Classification (TC) is an important tool for several tasks, applied in different fields (security, management, traffic engineering, R&D). This process is impaired or prevented by privacy-preserving protocols and tools, that encrypt the communication content, and (in case of anonymity tools) additionally hide the source, the destination, and the nature of the communication. In this paper, leveraging a public dataset released in 2017, we provide classification results with the aim of investigating to which degree the specific anonymity tool (and the traffic it hides) can be identified, when compared to the traffic of other considered anonymity tools, using five machine learning classifiers. Initially, flow-based TC is considered, and the effects of feature importance and temporal-related features to the network are investigated. Additionally, the role of finer-grained features, such as the (joint) histogram of packet lengths (and inter-arrival times), is determined. Successively, “early” TC of anonymous networks is analyzed. Results show that the considered anonymity networks (Tor, I2P, JonDonym) can be easily distinguished (with an accuracy of 99.87% and 99.80%, in case of flow-based and early-TC, respectively), telling even the specific application generating the traffic (with an accuracy of 73.99% and 66.76%, in case of flow-based and early-TC, respectively).
Antonio Montieri, Domenico Ciuonzo, Giuseppe Aceto, Antonio Pescapè
IEEE Trans. Dependable Secur. Comput.4
2019 Characterizing Cloud-to-User Latency as Perceived by AWS and Azure Users Spread over the Globe
abstract
With the growing adoption of cloud infrastructures to deliver a variety of IT services, monitoring cloud network performance has become crucial. However, cloud providers only disclose qualitative info about network performance, at most. This hinders efficient cloud adoption, resulting in no performance guarantees, uncertainties about the behavior of hosted services, and sub-optimal deployment choices. In this work, we focus on cloud-to-user latency, i.e. the latency of network paths interconnecting datacenters to worldwide-spread cloud users accessing their services. In detail, we performed a 14-day measurement campaign from 25 vantage points deployed via Planetlab infrastructure (emulating spatially- spread users) and considering services running in distinct locations on the infrastructures of the two most popular public-cloud providers, namely Amazon Web Services and Microsoft Azure. Our experimentation allows to provide an in-depth performance characterization (based on multiple probing methods and fine-grained sampling rate) of such networks as perceived by users spread worldwide. Results show the presence of both spatial and temporal latency trends. Finally, by evaluating the advantages of multi- cloud deployments, our results also provide useful guidelines to cloud customers.
Fabio Palumbo, Giuseppe Aceto, Alessio Botta, Domenico Ciuonzo, Valerio Persico, Antonio Pescapè
GLOBECOM6
2019 Scalable Provisioning of Virtual Network Functions via Supervised Learning
abstract
Network Function Virtualization (NFV) is opening new opportunities for both the business and the research community. As the need to softwarize functions grows, managing the underlying hosting infrastructure faces new challenges. In this paper, we focus on one of these challenges: the ability to provision enough virtualizable infrastructure resources to guarantee smooth and responsive network and application operations. To this aim, we learn from observed patterns of requests to an infrastructure hosting virtual network functions, and we model the problem of appropriately scaling resources to provision them. Using months of real Internet traffic requests, we train and compare the performance of several (classical and more recent) learning algorithms. Our goal is to predict future NFV requests to proactively provision our infrastructure using constraint optimization. Our results, obtained with simulations and with a prototype that deploys Linux containers, show both expected and surprising results, and aims at fostering debates on when and if the juice of (supervised) deep learning techniques is worth the squeeze.
Alessio Scalingi, Flavio Esposito, Waqar Muhammad, Antonio Pescapè
NetSoft4
2019 Decision Fusion Rules in Ambient Backscatter Wireless Sensor Networks
abstract
Ambient backscatter (AmBC) communications cap-italize on ambient radio-frequency (RF) signals to enable communications among ultra-low-power devices, thus representing a promising cost-effective solution for wireless sensor networks in the Internet of Things. In this paper, we study the scenario where single-antenna AmBC sensors are employed to perform decision fusion over multiple-access fading channels. Specifically, AmBC sensors detect the presence/absence of a phenomenon of interest and transmit their decisions to a multiple-antenna fusion center reader (FCR), by reflecting part of an incident RF ambient signal. In this scenario, we derive fusion rules at the FCR by considering both the cases of instantaneous and statistical channel state information, as well as their corresponding low-complexity alternatives. Numerical simulation results are provided to compare the proposed fusion rules and highlight the relevant trends.
Domenico Ciuonzo, Giacinto Gelli, Antonio Pescapè, Francesco Verde
PIMRC3
2019 MIMETIC: Mobile encrypted traffic classification using multimodal deep learning
Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Antonio Pescapè
Comput. Networks4
2019 Distributed detection with fuzzy censoring sensors in the presence of noise uncertainty
Abdolreza Mohammadi 0001, S. Hamed Javadi, Domenico Ciuonzo, Valerio Persico, Antonio Pescapè
Neurocomputing5
2019 A Formal Methodology for Easing Development and Maintenance of Entity Services in Service Oriented Software-Defined Internet of Things
abstract
Internet of Things (IoT) systems are usually built with entity services, which are those abstracting functionalities of sensing and executing devices in the physical space. As requirements of sensing or controlling the physical space can be varied with different systems, entity services are supposed to be easily adapted to meet such dynamicity. To ease updating and modification of entity services, although a software-defined network approach has been applied in building IoT systems, entity services developed with the same software architecture as traditional services on the Internet have an inherited problem in adaptability. In order to solve the problem, we abstract the functionalities of an entity service in social, cyber, and physical spaces into application model, sense-execute model, and physical model, respectively, and propose a physical model driven software architecture (PMDA) for guiding design of entity services. To ease development of entity services, we also propose a formal development method of entity services (fDES) to transform the abstracted models of PMDA into implementable software modules. Besides, to reduce maintenance cost of entity services when adapting them to different requirements from the social space, we propose a formal maintenance method of entity service (fMES). The correctness of fDES and fMES is verified by a case study, and their effectiveness in reducing cost of developing and maintaining IoT systems composed of large-scale frequently changed entity services is proved by analysis.
Haiming Chen 0002, Kaibin Xie, Antonio Pescapè
IEEE Internet Things J.4
2019 Mobile Encrypted Traffic Classification Using Deep Learning: Experimental Evaluation, Lessons Learned, and Challenges
abstract
The massive adoption of hand-held devices has led to the explosion of mobile traffic volumes traversing home and enterprise networks, as well as the Internet. Traffic classification (TC), i.e., the set of procedures for inferring (mobile) applications generating such traffic, has become nowadays the enabler for highly valuable profiling information (with certain privacy downsides), other than being the workhorse for service differentiation/blocking. Nonetheless, the design of accurate classifiers is exacerbated by the raising adoption of encrypted protocols (such as TLS), hindering the suitability of (effective) deep packet inspection approaches. Also, the fast-expanding set of apps and the moving-target nature of mobile traffic makes design solutions with usual machine learning, based on manually and expert-originated features, outdated and unable to keep the pace. For these reasons deep learning (DL) is here proposed, for the first time, as a viable strategy to design practical mobile traffic classifiers based on automatically extracted features, able to cope with encrypted traffic, and reflecting their complex traffic patterns. To this end, different state-of-the-art DL techniques from (standard) TC are here reproduced, dissected (highlighting critical choices), and set into a systematic framework for comparison, including also a performance evaluation workbench. The latter outcome, although declined in the mobile context, has the applicability appeal to the wider umbrella of encrypted TC tasks. Finally, the performance of these DL classifiers is critically investigated based on an exhaustive experimental validation (based on three mobile datasets of real human users' activity), highlighting the related pitfalls, design guidelines, and challenges.
Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Antonio Pescapè
IEEE Trans. Netw. Serv. Manag.4
2018 Evaluation of SDN-based bandwidth estimation in Mobile Broad Band networks
abstract
Mobile Broad Band (MBB) networks and Software-Defined Networking (SDN) are expected to strongly characterize the future evolution of global communications envisioned by the Fifth Generation mobile networks (5G). Although SDN has seen adoption and wide experimentation in data-center networks, its benefits and challenges in MBB has not received comparable coverage. In this work we experiment with a state-of-art SDN-based approach for passive monitoring available bandwidth and throughput with an OpenFlow switch in the mobile node. We evaluate the approach on a real-world commercial 4G network (leveraging the MONROE platform), considering two deployments (with an SDN controller local to the mobile node, and a remote one, whose control messages traverse the radio access network) and compare the results of the experiments against analogous deployments in a fully-wired testbed. For both the local and remote deployments, different polling periods, in different traffic conditions, are considered. Results show that, while further research is needed to investigate the variability of the relative error (standard deviation ranges between 1.21 and 8.65% in the worst case), its mean is very low, confirming the feasibility of the proposed estimation approach.
Giuseppe Aceto, Fabio Palumbo, Valerio Persico, Haiming Chen 0002, Antonio Pescapè
APCC5
2018 Available Bandwidth vs. Achievable Throughput Measurements in 4G Mobile Networks
Giuseppe Aceto, Fabio Palumbo, Valerio Persico, Antonio Pescapè
CNSM4
2018 Speeding-Up DPI Traffic Classification with Chaining
abstract
The importance of network traffic classification has grown over the last two decades in line with the increasing diver- sity of networked applications. Nowadays traditional approaches to traffic classification, relying on port numbers and on Deep Packet Inspection (DPI), are not very effective in real scenarios respectively due to the usage of random or non-standard port numbers and to the wide usage of end-to-end encryption. Despite their limitations, port- based and DPI approaches are still widely used in operational networks for a number of network monitoring and management tasks. This paper proposes a practical approach for improving the efficiency of traditional traffic classification techniques by chain- ing fast classification stages (port-based and machine-learning- based), combined to lower their false-positive rate, and a more precise - but time- and resource-demanding - stage based on DPI. Experimental results demonstrate that Chain obtains results in line with DPI approaches in term of Precision, Recall, Accuracy and Area Under the Curve (AUC), while it is 45% faster when compared to nDPIng, a well- known DPI implementation. The appealing of the proposed approach in Network Function Virtualization (NFV) contexts is also discussed.
Hossein Doroud, Giuseppe Aceto, Walter de Donato, Elnaz Alizadeh Jarchlo, Andrés Marín López, César D. Guerrero, Antonio Pescapè
GLOBECOM7
2018 A collaborative approach for improving the security of vehicular scenarios: The case of platooning
Alberto Petrillo, Antonio Pescapè, Stefania Santini
Comput. Commun.2
2018 Benchmarking big data architectures for social networks data processing using public cloud platforms
Valerio Persico, Antonio Pescapè, Antonio Picariello, Giancarlo Sperlì
Future Gener. Comput. Syst.2
2018 A comprehensive survey on internet outages
Giuseppe Aceto, Alessio Botta, Pietro Marchetta, Valerio Persico, Antonio Pescapè
J. Netw. Comput. Appl.5
2018 Multi-classification approaches for classifying mobile app traffic
Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Antonio Pescapè
J. Netw. Comput. Appl.4
2018 The role of Information and Communication Technologies in healthcare: taxonomies, perspectives, and challenges
Giuseppe Aceto, Valerio Persico, Antonio Pescapè
J. Netw. Comput. Appl.3
2017 Using fuzzy logic for improving clinical daily-care of β-thalassemia patients
abstract
The domain of medical decision making process is heavily affected by vagueness and uncertainty issues and - for copying with them - different type of Clinical Decision Support System (CDSS)s, simulating human expert clinician reasoning, have been designed in order to suggest decisions on treatment of patients. In this paper, we exploit fuzzy inference machines to improve the knowledge-based CDSS actually used in the day-by-day clinical care of β-thalassemia patients of the Rare Red Blood Cell Disease Unit (RRBCDU) at Cardarelli Hospital (Naples, Italy). All the designed functionalities were iteratively developed on the field, through requirement-adjustment/development/validation cycles executed by an interdisciplinary research team comprising doctors, clinicians and IT engineers. The paper shows exemplary results on the on-line evaluation of Iron Overload during the health status assessment and care management of β-Thalassemia patients.
Stefania Santini, Antonio Pescapè, Antonio Saverio Valente, V. Abate, Giovanni Improta, Maria Triassi, P. Ricchi, A. Filosa
FUZZ-IEEE2
2017 Traffic Classification of Mobile Apps through Multi-Classification
abstract
The wide spreading and growing usage of smartphones are deeply changing the kind of traffic that traverses home and enterprise networks and the Internet. Tools that base their functions on the knowledge of the application generating the traffic (performance enhancement proxies, network monitors, policy enforcement devices) imply traffic classification, and are thus limited or impaired when dealing with the daily expanding set of mobile apps. Besides the moving-target nature of mobile apps traffic, the increasing adoption of encrypted protocols (TLS) makes classification even more challenging, defeating established approaches (DPI, statistical classifiers). In this paper we aim to improve the classification performance of mobile apps classifiers adopting a multi-classification approach, intelligently-combining decisions from state-of-art classifiers proposed for mobile and encrypted traffic classification. Based on a dataset of users' activity collected by a mobile solutions provider, our results demonstrate that classification performance can be improved according to all considered metrics, up to +8.1% F-measure score with respect to the best base classifier. Further room for improvements is also evidenced by the ideal combiner performance (oracle).
Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Antonio Pescapè
GLOBECOM4
2017 Socio-technical approach to engineer gigabit app performance for physicaltherapy-as-a-service
abstract
The deployment of Gigabit Apps owing to their high-bandwidth and low-latency nature pushes the limits of today's end-to-end networking, and reveals new bottlenecks at multiple layers of networking, virtualization, application and user experience. In this paper, we use an exemplar smart health related Gigabit App use case viz., PhysicalTherapy-as-a-Service to show how a multi-layer instrumentation approach of measurement points was critical to successfully deploy our lab-tested App out to residential homes with Google Fiber connections. The salient instrumentation strategies involved an organized co-design method between the App Developer and Network Engineer roles, and a multi-domain network performance monitoring featuring perfSONAR extensions, both of which were realized through our Narada Metrics framework. Our instrumentation strategies engendered a “socio-technical tool” for co-ordination between multi-layer stakeholders in identifying and overcoming the intertwined bottlenecks, and in tuning the App performance. Our results highlight the new instrumentation and measurement challenges to foster multi-layer stakeholder collaboration, and provide rare insights to the budding Gigabit App developer community for performance engineering their Apps to serve residential users.
Ronny Bazan Antequera, Prasad Calyam, D. Yu. Chemodanov, Walter de Donato, Anup K. Mishra, Antonio Pescapè, Marjorie Skubic
Healthcom6
2017 Internet censorship in Italy: An analysis of 3G/4G networks
abstract
Users trying to access censored content may experience different results, depending on the technique adopted to enforce Internet Censorship, that in turn depends on different factors. Administrative control of the network (i.e. the entity managing network devices) is one of such factors. To the best of our knowledge, we are the first to focus on censorship detection on 3G/4G (hereafter mobile) network operators, investigating the extent of differences in applying censorship inside a single country. To do so we performed an experimental campaign in Italy using the five major mobile operators. We introduce the censorship detection platform and tests we adopted, and aggregate the results according to the outcome of the tests in classes, related with censoring techniques and circumvention capabilities. Overall 15 different aggregated behaviors have been found in the experimental campaign. The analysis of measurement results reveals wide dis-homogeneity of treatment for a given censored resource across different mobile operators, with 99.5% of resources showing at least two different behaviors when probed. The discussion of reported results informs about the unexpected variability on transparency and precision of censorship, and also on effective detection and circumvention strategies, as measured from mobile networks in a single country.
Giuseppe Aceto, Antonio Montieri, Antonio Pescapè
ICC3
2017 On the performance of the wide-area networks interconnecting public-cloud datacenters around the globe
Valerio Persico, Alessio Botta, Pietro Marchetta, Antonio Montieri, Antonio Pescapè
Comput. Networks5
2017 Challenges and solution for measuring available bandwidth in software defined networks
Péter Megyesi, Alessio Botta, Giuseppe Aceto, Antonio Pescapè, Sándor Molnár
Comput. Commun.4
2017 A sleep scheduling approach based on learning automata for WSN partial coverage
Habib Mostafaei, Antonio Montieri, Valerio Persico, Antonio Pescapè
J. Netw. Comput. Appl.4
2017 A Fuzzy Approach Based on Heterogeneous Metrics for Scaling Out Public Clouds
abstract
Thanks to resource elasticity, cloud systems allow to build high performance applications by dynamically adapting resources to workload dynamics. In this paper, we present a novel approach for horizontally scaling cloud resources. The approach is based on an optimized feedback control scheme that leverages fuzzy logic to self-adjust its parameters in order to cope with unpredictable and highly time-varying public-cloud operating conditions. The proposed approach takes as input heterogeneous monitoring metrics related to distinct aspects of interest (i.e., CPU and network load) merged through a fitness function. Therefore, it is able to accomplish the application needs from different viewpoints. The extensive experimental evaluation performed in the Amazon EC2 environment showed how the proposed approach is robust against a number of realistic workloads-also when VM failures happen- and that it is flexible, as being suitable for applications with different needs. Finally, it also achieves better performance when compared to previously proposed solutions.
Valerio Persico, Domenico Grimaldi, Antonio Pescapè, Alessandro Salvi, Stefania Santini
IEEE Trans. Parallel Distributed Syst.3
2016 Internet Censorship in Italy: A First Look at 3G/4G Networks
Giuseppe Aceto, Antonio Montieri, Antonio Pescapè
CANS3
2016 A First Look at Public-Cloud Inter-Datacenter Network Performance
abstract
Public-cloud providers do not disclose quantitative information about the performance of their inter- datacenter networks in spite of their importance and of the growing interest they are attracting. In this paper we propose an analysis of the inter-datacenter network of the two leading providers-Amazon Web Services and Microsoft Azure- only leveraging active monitoring approaches and thus not relying on information restricted to providers. Our results show that Azure inter- datacenter infrastructure performs better than Amazon's in terms of throughput (+52%, on average). On the other hand, the performance of the two providers is comparable in terms of latency, with the exception of isolated cases. Counterintuitively, lower performance may be even related to higher costs for the customer. Network management policies that may severely impact both the performance perceived by the customers and the results of the measurement activities have been observed and characterized. Finally, a comparison with previous works shows that TCP throughput has not improved recently.
Valerio Persico, Alessio Botta, Antonio Montieri, Antonio Pescapè
GLOBECOM4
2016 An efficient partial coverage algorithm for wireless sensor networks
abstract
Wireless sensor networks (WSNs) are currently adopted in a vast variety of domains. Due to practical energy constraints, in this field minimizing sensor energy consumption is a critical challenge. Sleep scheduling approaches give the opportunity of turning off a subset of the nodes of a network- without suspending the monitoring activities performed by the WSN-in order to save energy and increase the lifetime of the sensing system. Our study focuses on partial coverage, targeting scenarios in which the continuous monitoring of a limited portion of the area of interest is enough. In this paper, we present PCLA, an efficient algorithm based on Learning Automata that aims at minimizing the number of sensors to activate, such that a given portion of the area of interest is covered and connectivity among sensors is preserved. Simulation results show how PCLA can select sensors in an efficient way to satisfy the imposed constraints, thus guaranteeing better performance in terms of both working-node ratio and WSN lifetime. Also, we show how PCLA outperforms state-of-the-art partial-coverage algorithms.
Habib Mostafaei, Antonio Montieri, Valerio Persico, Antonio Pescapè
ISCC4
2016 How and how much traceroute confuses our understanding of network paths
abstract
Traceroute is largely considered as the number-one tool when troubleshooting the network, with innumerable applications, such as pinpointing the routing deficiencies or detecting and locating network outages. Previous works have extensively investigated pitfalls and flaws causing the measurements performed with this tool to be inaccurate or incomplete. In this paper, we show how, even in the absence of all these well-investigated pitfalls and flaws, our ability to properly troubleshoot the network with Traceroute is strongly limited. Indeed, by using state-of-the-art alias resolution techniques, we investigate how and how much the IP-level description provided by Traceroute can distort our understanding of the characteristics of Internet paths. We experimentally evaluate the impact on path properties like equal-cost multipaths, loops, routing cycles, load balancing, route prevalence and persistence. Our results confirm that researchers and network operators relying on Traceroute may poorly estimate (i) the number of multiple equal-cost routes to the destination; (ii) the presence of suboptimal routing in the network; (iii) the routing stability.
Pietro Marchetta, Antonio Montieri, Valerio Persico, Antonio Pescapè, Ítalo S. Cunha, Ethan Katz-Bassett
LANMAN4
2016 Sibyl: A Practical Internet Route Oracle
Ítalo S. Cunha, Pietro Marchetta, Matt Calder, Yi-Ching Chiu, Brandon Schlinker, Bruno V. A. Machado, Antonio Pescapè, Vasileios Giotsas, Harsha V. Madhyastha, Ethan Katz-Bassett
NSDI7
2016 Mining agile DNS traffic using graph analysis for cybercrime detection
Andreas Berger, Alessandro D'Alconzo, Wilfried N. Gansterer, Antonio Pescapè
Comput. Networks4
2016 Integration of Cloud computing and Internet of Things: A survey
Alessio Botta, Walter de Donato, Valerio Persico, Antonio Pescapè
Future Gener. Comput. Syst.4
2016 Internet of Things and Cloud Services
Muhammad Younas 0001, Irfan Awan, Antonio Pescapè
Future Gener. Comput. Syst.3
2015 A Feedback-Control Approach for Resource Management in Public Clouds
abstract
Nowadays, more and more the industry and market depend on cloud-based infrastructures for delivering IT services. To this aim cloud-based infrastructures are changing continuously, increasing their complexity especially for the management of cloud resources. Control and management of resources (e.g., virtual machines, VMs) are of paramount importance to adjust resources automatically allocated to an application and for delivering quality-assured services to final users. In this paper, we propose a feedback-based control approach for the management of VMs in the AWS EC2 public cloud. First, we evaluate the proposed Gain Scheduling policy against different workloads. Second, we provide results on the robustness of the proposed Gain Scheduling policy in presence of failures. Finally, we compare our approach to state-of-the-art control approaches for cloud resources. Our results indicate that the proposed control strategy guarantees, without the need of a priori information on system dynamics or complex estimations of the operating conditions, high performance with respect to both constant and time- varying workloads as well as in spite of sudden VM failures.
Domenico Grimaldi, Valerio Persico, Antonio Pescapè, Alessandro Salvi, Stefania Santini
GLOBECOM3
2015 On Network Throughput Variability in Microsoft Azure Cloud
abstract
The dependence of the industry on cloud-based infrastructures has grown much faster than our understanding of the performance limits and dynamics of these environments. An aspect only marginally analyzed in the past is related to the performance of the intra-cloud network connecting the virtual machines (VMs) deployed in the same data center. The few available works either do not exhaustively describe the adopted methodology or employed different approaches causing the analyses to be hard to replicate, and the results to be hard to compare. In addition, cloud customers can today highly customize their cloud environments while previous works considered only a few of the scenarios in which a customer may operate. In this paper, we provide an intra-cloud network performance characterization of Microsoft (MS) Azure, a leading provider only preliminary investigated from this angle. We first propose and thoroughly detail a methodology to carry out similar analyses, thus encouraging its replication also in other contexts; then we apply this methodology to characterize the intra-cloud network performance in terms of maximum network throughput. More specifically, we investigate whether and how the achievable throughput between two VMs varies (i) over time; (ii) when the customer operates different decisions on VM size, network configuration, geographic region, and transport protocol; and (iii) when the customer operates the same decisions on these factors. Our analysis aims at addressing the gap existing in the literature by providing the most exhaustive and detailed results about the intra-cloud network performance for MS Azure today available.
Valerio Persico, Pietro Marchetta, Alessio Botta, Antonio Pescapè
GLOBECOM4
2015 A consensus-based approach for platooning with inter-vehicular communications
abstract
Automated and coordinated vehicles' driving (platooning) is gaining more and more attention today and it represents a challenging scenario heavily relying on wireless Inter-Vehicular Communication (IVC). In this paper, we propose a novel controller for vehicle platooning based on consensus. Opposed to current approaches where the logical control topology is fixed a priori and the control law designed consequently, we design a system whose control topology can be reconfigured depending on the actual network status. Moreover, the controller does not require the vehicles to be radar equipped and automatically compensates outdated information caused by network delays. We define the control law and analyze it in both analytical and simulative way, showing its robustness in different network scenarios. We consider three different wireless network settings: uncorrelated Bernoullian losses, correlated losses using a Gilbert-Elliott channel, and a realistic traffic scenario with interferences caused by other vehicles. Finally, we compare our strategy with another state of the art controller. The results show the ability of the proposed approach to maintain a stable string of vehicles even in the presence of strong interference, delays, and fading conditions, providing higher comfort and safety for platoon drivers.
Stefania Santini, Alessandro Salvi, Antonio Saverio Valente, Antonio Pescapè, Michele Segata, Renato Lo Cigno
INFOCOM4
2015 Experimenting with alternative path tracing solutions
abstract
Tracing Internet paths is essential for gathering knowledge about the complex, heterogeneous, highly dynamic, and largely opaque eco-system of networks the Internet is. Currently, only two practical solutions are available: (i) equipping packets with the Record Route IP option to register addresses of the traversed routers; (ii) eliciting ICMP Time Exceeded messages by limiting the Time-to-Live of the injected packets. In this paper, we investigate three alternative path tracing solutions eliciting ICMP Parameter Problem (PP) messages from the network through the injection of malformed packets. After having introduced them, we describe the experimental results of a first campaign aiming at evaluating their ability to collect replies from the traversed routers. Finally, thanks to a large-scale multi-vantage points measurement campaign, we evaluate the ability of the most promising ICMP PP-based solution to discover interfaces and routers not discovered by Paris-Traceroute Multipath Detection Algorithm (MDA). Experimental results (a) confirm the ability of this novel path tracing solution to report interfaces and routers that are not reported by the state of the art tools and also (b) uncover the scenarios in which this new solution appears more helpful.
Pietro Marchetta, Walter de Donato, Valerio Persico, Antonio Pescapè
ISCC4
2015 A map-based platform for smart mobility services
abstract
Nowadays smart mobility, a new vision of urban mobility, is a reality. To implement smart mobility scenarios a deep integration among citizens, private and public transportation systems and ICT is required. With the S2-Move project we propose an architecture able to collect, update, and process real-time and heterogeneous information from various sources (tablets, smart-phones, probe vehicles) and actors of the urban scenario (public/private vehicles, pedestrians, infrastructures) in order to provide innovative mobility services. In this paper, we present a core component of the S2-Move project: the map-based web platform designed and implemented for providing smart mobility services. We present use cases and detail the design and the implementation of the platform. Finally, we evaluate the accuracy and efficiency of the Map Matching and Traffic Monitoring algorithms we implemented in our platform by using realistic urban traffic data generated through simulations in SUMO.
Pietro Marchetta, Eduard Natale, Antonio Pescapè, Alessandro Salvi, Stefania Santini
ISCC3
2015 Internet Censorship detection: A survey
Giuseppe Aceto, Antonio Pescapè
Comput. Networks2
2015 Measuring network throughput in the cloud: The case of Amazon EC2
Valerio Persico, Pietro Marchetta, Alessio Botta, Antonio Pescapè
Comput. Networks4
2015 IP packet interleaving for UDP bursty losses
Alessio Botta, Antonio Pescapè
J. Syst. Softw.2
2015 Analysis of a "/0" Stealth Scan From a Botnet
abstract
Botnets are the most common vehicle of cyber-criminal activity. They are used for spamming, phishing, denial-of-service attacks, brute-force cracking, stealing private information, and cyber warfare. Botnets carry out network scans for several reasons, including searching for vulnerable machines to infect and recruit into the botnet, probing networks for enumeration or penetration, etc. We present the measurement and analysis of a horizontal scan of the entire IPv4 address space conducted by the Sality botnet in February 2011. This 12-day scan originated from approximately 3 million distinct IP addresses and used a heavily coordinated and unusually covert scanning strategy to try to discover and compromise VoIP-related (SIP server) infrastructure. We observed this event through the UCSD Network Telescope, a /8 darknet continuously receiving large amounts of unsolicited traffic, and we correlate this traffic data with other public sources of data to validate our inferences. Sality is one of the largest botnets ever identified by researchers. Its behavior represents ominous advances in the evolution of modern malware: the use of more sophisticated stealth scanning strategies by millions of coordinated bots, targeting critical voice communications infrastructure. This paper offers a detailed dissection of the botnet's scanning behavior, including general methods to correlate, visualize, and extrapolate botnet behavior across the global Internet.
Alberto Dainotti, Alistair King, K. C. Claffy, Ferdinando Papale, Antonio Pescapè
IEEE/ACM Trans. Netw.5
2014 Distributed Active Measurement of Internet Queuing Delays
Pellegrino Casoria, Dario Rossi 0001, Jordan Augé, Marc-Olivier Buob, Timur Friedman, Antonio Pescapè
PAM6
2014 Dissecting Round Trip Time on the Slow Path with a Single Packet
Pietro Marchetta, Alessio Botta, Ethan Katz-Bassett, Antonio Pescapè
PAM4
2014 Analysis of Country-Wide Internet Outages Caused by Censorship
abstract
In the first months of 2011, Internet communications were disrupted in several North African countries in response to civilian protests and threats of civil war. In this paper, we analyze episodes of these disruptions in two countries: Egypt and Libya. Our analysis relies on multiple sources of large-scale data already available to academic researchers: BGP interdomain routing control plane data, unsolicited data plane traffic to unassigned address space, active macroscopic traceroute measurements, RIR delegation files, and MaxMind's geolocation database. We used the latter two data sets to determine which IP address ranges were allocated to entities within each country, and then mapped these IP addresses of interest to BGP-announced address ranges (prefixes) and origin autonomous systems (ASs) using publicly available BGP data repositories in the US and Europe. We then analyzed observable activity related to these sets of prefixes and ASs throughout the censorship episodes. Using both control plane and data plane data sets in combination allowed us to narrow down which forms of Internet access disruption were implemented in a given region over time. Among other insights, we detected what we believe were Libya's attempts to test firewall-based blocking before they executed more aggressive BGP-based disconnection. Our methodology could be used, and automated, to detect outages or similar macroscopically disruptive events in other geographic or topological regions.
Alberto Dainotti, Claudio Squarcella, Emile Aben, K. C. Claffy, Marco Chiesa, Michele Russo, Antonio Pescapè
IEEE/ACM Trans. Netw.7
2013 Pythia: yet another active probing technique for alias resolution
abstract
An accurate and exhaustive knowledge of the Internet topology is essential for a deep understanding of such a complex and ever-evolving ecosystem. In this context, a well-known key challenge is represented by alias resolution, i.e. the process of grouping under a unique identifier the addresses owned by the same network layer device. While several techniques exist, each solution shows specific limitations such that the alias resolution problem appears far from being definitively solved. In this work, inspired by a previous technique and the lessons learned by experimenting with IP options, we present, evaluate and release Pythia, a novel active probing-based alias resolution technique. Pythia exploits a combination of (i) UDP packet probes and (ii) the IP Prespecified Timestamp option and it is purposely designed to reconstruct a specific category of routers. By using the reliable topological information provided by IGMP probing as a reference, we experimentally evaluate Pythia and compare it to previously proposed techniques according to multiple performance metrics. Experimental results show how Pythia reaches higher performance in terms of applicability and trustworthiness.
Pietro Marchetta, Valerio Persico, Antonio Pescapè
CoNEXT3
2013 Passive bufferbloat measurement exploiting transport layer information
abstract
“Bufferbloat” is the growth in buffer size that has led Internet delays to occasionally exceed the light propagation delay from the Earth to the Moon. Manufacturers have built in large buffers to prevent losses on Wi-Fi, cable and ADSL links. But the combination of some links' limited bandwidth with TCP's tendency to saturate that bandwidth results in excessive queuing delays. In response, new congestion control protocols such as BitTorrent's uTP/LEDBAT aim at explicitly limiting the delay that they add at the bottleneck link. This work proposes a methodology to monitor the upstream queuing delay experienced by remote hosts, both those using LEDBAT, through LEDBAT's native one-way delay measurements, and those using TCP, through the Timestamp Option. We report preliminary findings on bufferbloat-related queuing delays on an Internet measurement campaign involving a few thousand hosts.
Chiara Chirichella, Dario Rossi 0001, Claudio Testa, Timur Friedman, Antonio Pescapè
GLOBECOM5
2013 New generation satellite broadband Internet services: Should ADSL and 3G worry?
abstract
In the context of Internet access technologies, satellite networks have traditionally been considered for specific purposes or as a backup technology for users not reached by traditional access networks, such as 3G, cable or ADSL. In recent years, however, new satellite technologies have been introduced in the market, reopening the debate on the possibilities of having high-performance satellite access networks. In this paper, we describe the testbed we set up - in collaboration with one of the main satellite operators in Europe - and the experiments we performed to evaluate and analyze the performance of both Tooway and Tooway on KA-SAT (or KASAT for short), two satellite broadband Internet access services. Also, we build a simulator to study the behavior of the traffic shaping mechanism used by the satellite operator. In terms of performance, our results show how new generation Internet satellite services are a promising way to provide broadband Internet connection to users. In terms of traffic shaping, our results shed light on the mechanisms employed by the operator for shaping user traffic and the possibilities left for the users.
Alessio Botta, Antonio Pescapè
INFOCOM2
2013 DRAGO: Detecting, quantifying and locating hidden routers in Traceroute IP paths
abstract
Traceroute is probably the most famous networking tool widely adopted in both industry and research. Despite its long life, however, measurements based on Traceroute are potentially inaccurate, misleading or incomplete due to several unresolved issues. In this paper, we face the limitation represented by hidden routers-devices that do not decrement the TTL, being thus totally invisible to Traceroute. We present, evaluate and release DRAGO, a novel active probing technique composed of three main steps. First, a novel Traceroute enhanced by the IP Timestamp option is launched toward a destination. Second, a procedure is applied to quantify the hidden routers contained in the path, if any. Third, a last procedure is performed to identify the exact position in the path of the detected hidden routers. Experimental results demonstrate that the phenomenon is not uncommon: DRAGO detects the presence of hidden routers in at least 6% of the considered Traceroute IP paths and limits the affected area to one fifth of the trace containing these devices.
Pietro Marchetta, Antonio Pescapè
INFOCOM2
2013 Remotely Gauging Upstream Bufferbloat Delays
Chiara Chirichella, Dario Rossi 0001, Claudio Testa, Timur Friedman, Antonio Pescapè
PAM5
2013 Detecting Third-Party Addresses in Traceroute Traces with IP Timestamp Option
Pietro Marchetta, Walter de Donato, Antonio Pescapè
PAM3
2013 Cloud monitoring: A survey
Giuseppe Aceto, Alessio Botta, Walter de Donato, Antonio Pescapè
Comput. Networks4
2013 Efficient Storage and Processing of High-Volume Network Monitoring Data
abstract
Monitoring modern networks involves storing and transferring huge amounts of data. To cope with this problem, in this paper we propose a technique that allows to transform the measurement data in a representation format meeting two main objectives at the same time. Firstly, it allows to perform a number of operations directly on the transformed data with a controlled loss of accuracy, thanks to the mathematical framework it is based on. Secondly, the new representation has a small memory footprint, allowing to reduce the space needed for data storage and the time needed for data transfer. To validate our technique, we perform an analysis of its performance in terms of accuracy and memory footprint. The results show that the transformed data closely approximates the original data (within 5% relative error) while achieving a compression ratio of 20%; storage footprint can also be gradually reduced towards the one of the state-of-the-art compression tools, such as bzip2, if higher approximation is allowed. Finally, a sensibility analysis show that technique allows to trade-off the accuracy on different input fields so to accommodate for specific application needs, while a scalability analysis indicates that the technique scales with input size spanning up to three orders of magnitude.
Giuseppe Aceto, Alessio Botta, Antonio Pescapè, Cédric Westphal
IEEE Trans. Netw. Serv. Manag.3
2012 Quantifying and mitigating IGMP filtering in topology discovery
abstract
Recent developments in router level topology discovery have suggested the introduction of IGMP probing in addition to standard techniques such as traceroute and alias resolution. With a single IGMP probe, one can obtain all multicast interfaces and links of a multicast router. If such a probing is a promising approach, we noticed that IGMP probes are subject to filtering, leading so to the fragmentation of the collected multicast graph into several disjoint connected components. In this paper, we cope with the fragmentation issue. Our contributions are threefold: (i) we experimentally quantify the damages caused by IGMP filtering on collected topologies of large tier-1 ISPs; (ii) using traceroute data, we construct a hybrid graph and estimate how far each IGMP fragment is from each other; (iii) we provide and experimentally evaluate a recursive approach for reconnecting disjoint multicast components. The key idea of the third contribution is to recursively apply alias resolution to reassemble disjoint fragments and, thus, progressively extend the mapping of the targeted ISP. Data presented in the paper, as well as reconstructed topologies, are freely available at http://svnet.u-strasbg.fr/merlin.
Pietro Marchetta, Pascal Mérindol, Benoit Donnet, Antonio Pescapè, Jean-Jacques Pansiot
GLOBECOM4
2012 A Multi-Classification Approach for the Detection and Identification of eHealth Applications
abstract
eHealth services category has a diversified set of traffic patterns and demands in terms of QoS assurances. Existing QoS solutions were designed to support only aggregated classes of service and cannot differentiate traffic based on an application's behavioral pattern. In order to improve the performance of eHealth applications for home and mobile users there is a need to develop new traffic identification techniques, which would work at the edge of the network. This paper addresses the above problem by proposing machine learning-based approach for eHealth traffic identification. We investigate different techniques which combine the results from multiple machine learning classifiers and show which combination of techniques is best suited for identifying diverse eHealth traffic. Our approach is validated in a mobile e-health application context and the results prove that multi-classification techniques can be used in practice to provide application-based service differentiation.
Monika Grajzer, Michal Koziuk, Piotr Szczechowiak, Antonio Pescapè
ICCCN4
2012 Analysis of a "/0" stealth scan from a botnet
abstract
Botnets are the most common vehicle of cyber-criminal activity. They are used for spamming, phishing, denial of service attacks, brute-force cracking, stealing private information, and cyber warfare. Botnets carry out network scans for several reasons, including searching for vulnerable machines to infect and recruit into the botnet, probing networks for enumeration or penetration, etc. We present the measurement and analysis of a horizontal scan of the entire IPv4 address space conducted by the Sality botnet in February of last year. This 12-day scan originated from approximately 3 million distinct IP addresses, and used a heavily coordinated and unusually covert scanning strategy to try to discover and compromise VoIP-related (SIP server) infrastructure. We observed this event through the UCSD Network Telescope, a /8 darknet continuously receiving large amounts of unsolicited traffic, and we correlate this traffic data with other public sources of data to validate our inferences. Sality is one of the largest botnets ever identified by researchers, its behavior represents ominous advances in the evolution of modern malware: the use of more sophisticated stealth scanning strategies by millions of coordinated bots, targeting critical voice communications infrastructure. This work offers a detailed dissection of the botnet's scanning behavior, including general methods to correlate, visualize, and extrapolate botnet behavior across the global Internet.
Alberto Dainotti, Alistair King, K. C. Claffy, Ferdinando Papale, Antonio Pescapè
Internet Measurement Conference5
2012 Inferring the buffering delay of remote BitTorrent peers under LEDBAT vs TCP
abstract
Nowadays, due to excessive queuing, Internet delays grow sometimes as large as the propagation delay from moon to earth - for which the bufferbloat term was recently coined. Some points to active queue management (AQM) as its solution, others propose end-to-end congestion control techniques - like BitTorrent that recently replaced TCP with the LEDBAT transport protocol. In this demo, we implement a methodology to monitor the upstream queuing delay experienced by remote hosts, both those using LEDBAT, through LEDBAT's native one-way delay measurements, and those using TCP, through the timestamp option. By actively taking part into torrent downloads as leechers, our software is able to infer (and visualize) the amount of access delay suffered by the remote peers.
Chiara Chirichella, Dario Rossi 0001, Claudio Testa, Timur Friedman, Antonio Pescapè
P2P5
2012 A Hands-on Look at Active Probing Using the IP Prespecified Timestamp Option
Walter de Donato, Pietro Marchetta, Antonio Pescapè
PAM3
2012 Detecting third-party addresses in traceroute IP paths
abstract
Traceroute is probably the most famous computer networks diagnostic tool, widely adopted for both performance troubleshooting and research. Unfortunately, traceroute is not free of inaccuracies.
Pietro Marchetta, Walter de Donato, Antonio Pescapè
SIGCOMM3
2012 A tool for the generation of realistic network workload for emerging networking scenarios
Alessio Botta, Alberto Dainotti, Antonio Pescapè
Comput. Networks3
2012 Unified architecture for network measurement: The case of available bandwidth
Giuseppe Aceto, Alessio Botta, Antonio Pescapè, Maurizio D'Arienzo
J. Netw. Comput. Appl.3
2011 Traffic Classification through Joint Distributions of Packet-Level Statistics
abstract
Interest in traffic classification, in both industry and academia, has dramatically grown in the past few years. Research is devoting great efforts to statistical approaches using robust features. In this paper we propose a classification approach based on the joint distribution of Packet Size (PS) and Inter-Packet Time (IPT) and on machine- learning algorithms. Provided results, obtained using different real traffic traces, demonstrate how the proposed approach is able to achieve high (byte) accuracy (till 98%) and how the new features we introduced show properties of robustness, which suggest their use in the design of classification/identification approaches robust to traffic encryption and protocol obfuscation.
Alberto Dainotti, Antonio Pescapè
GLOBECOM2
2011 Analysis of country-wide internet outages caused by censorship
abstract
In the first months of 2011, Internet communications were disrupted in several North African countries in response to civilian protests and threats of civil war. In this paper we analyze episodes of these disruptions in two countries: Egypt and Libya. Our analysis relies on multiple sources of large-scale data already available to academic researchers: BGP interdomain routing control plane data; unsolicited data plane traffic to unassigned address space; active macroscopic traceroute measurements; RIR delegation files; and MaxMind's geolocation database. We used the latter two data sets to determine which IP address ranges were allocated to entities within each country, and then mapped these IP addresses of interest to BGP-announced address ranges (prefixes) and origin ASes using publicly available BGP data repositories in the U.S. and Europe. We then analyzed observable activity related to these sets of prefixes and ASes throughout the censorship episodes. Using both control plane and data plane data sets in combination allowed us to narrow down which forms of Internet access disruption were implemented in a given region over time. Among other insights, we detected what we believe were Libya's attempts to test firewall-based blocking before they executed more aggressive BGP-based disconnection. Our methodology could be used, and automated, to detect outages or similar macroscopically disruptive events in other geographic or topological regions.
Alberto Dainotti, Claudio Squarcella, Emile Aben, K. C. Claffy, Marco Chiesa, Michele Russo, Antonio Pescapè
Internet Measurement Conference7
2011 IP packet interleaving: Bridging the gap between theory and practice
abstract
The bursty nature of losses over the Internet is constantly asking for effective solutions. Packet interleaving or time diversity allows to cope with loss burstiness, at the cost of an additional delay. In this work, after determining the loss burstiness degree of real networks, we implement a real interleaver (we called TimeD), and we tackle the problem of how to apply such a transmission schema to UDP flows in real networks. For this aim, we propose a methodology composed of the following steps: (i) firstly, we develop a simulator to study the potential benefits of TimeD, understanding its loss decorrelation power and determining the interleaving configurations most suited to different network conditions and loss burstiness degree; (ii) then, using an emulated network, we validate TimeD and derive important operating parameters; (iii) finally, we study TimeD over a real satellite network. Thanks to this multifarious analysis we are able to move step-by-step from the theory to the practice, showing how it is possible - using TimeD - to actually decorrelate bursty losses and increase the performance of real applications.
Alessio Botta, Antonio Pescapè
ISCC2
2011 Broadband internet performance: a view from the gateway
abstract
We present the first study of network access link performance measured directly from home gateway devices. Policymakers, ISPs, and users are increasingly interested in studying the performance of Internet access links. Because of many confounding factors in a home network or on end hosts, however, thoroughly understanding access network performance requires deploying measurement infrastructure in users' homes as gateway devices. In conjunction with the Federal Communication Commission's study of broadband Internet access in the United States, we study the throughput and latency of network access links using longitudinal measurements from nearly 4,000 gateway devices across 8 ISPs from a deployment of over 4,200 devices. We study the performance users achieve and how various factors ranging from the user's choice of modem to the ISP's traffic shaping policies can affect performance. Our study yields many important findings about the characteristics of existing access networks. Our findings also provide insights into the ways that access network performance should be measured and presented to users, which can help inform ongoing broader efforts to benchmark the performance of access networks.
Srikanth Sundaresan, Walter de Donato, Nick Feamster, Renata Teixeira, Sam Crawford, Antonio Pescapè
SIGCOMM6
2011 Topology Discovery at the Router Level: A New Hybrid Tool Targeting ISP Networks
abstract
For a long time, traceroute measurements combined with alias resolution methods have been the sole way to collect Internet router level maps. Recently, a new approach has been introduced with the use of a multicast management tool, mrinfo, and a recursive probing scheme. In this paper, after analyzing advantages and drawbacks of probing approaches based on traceroute and mrinfo, we propose a hybrid discovery tool, Merlin (MEasure the Router Level of the INternet), mixing mrinfo and traceroute probes. Using a central server controlling a set of distributed vantage points in order to increase the exploration coverage while limiting the probing redundancy, the purpose of Merlin is to provide an accurate router level map inside a targeted Autonomous System (AS). Merlin also takes advantage of alias resolution methods to reconnect scattered multicast components. To evaluate the performance of Merlin, we report experimental results describing its efficiency in topology exploration and reconstruction of several ASes.
Pietro Marchetta, Pascal Mérindol, Benoit Donnet, Antonio Pescapè, Jean-Jacques Pansiot
IEEE J. Sel. Areas Commun.4
2010 Identification of Traffic Flows Hiding behind TCP Port 80
abstract
Beyond Quality of Service and billing, one of the most important applications of traffic identification is in the field of network security. Despite their simplicity, current approaches based on port numbers are highly unreliable. This paper proposes an identification approach, based on a cascade of decision trees. The approach uses the sign pattern and payload size of the first four packets in each flow, thus remaining applicable to encrypted traffic too. The effectiveness of the proposed approach is evaluated on five real traffic traces collected in different time periods and over four different networks. The obtained overall accuracy gives us grounds to consider the adoption of this approach as stand-alone in on-line platforms for network traffic identification or in combination with classical firewall architectures.
Alberto Dainotti, Francesco Gargiulo 0001, Ludmila I. Kuncheva, Antonio Pescapè, Carlo Sansone
ICC4
2010 UANM: a platform for experimenting with available bandwidth estimation tools
abstract
In the field of network monitoring and measurement, the efficiency and accuracy of the adopted tools is strongly dependent on (i) structural and dynamic characteristics of the network scenario under measure and (ii) on manual fine tuning of the involved parameters. This is, for example, the case of the end-to-end available bandwidth estimation, in which the constraints of the measurement stage vary according to the use of the final results. In this work we present UANM (Unified Architecture for Network Measurement), a novel measurement infrastructure for an automatic management of measurement stages, tailored to the end-to-end available bandwidth estimation tools. We describe in details its architecture, illustrating the features we introduced to mitigate the problems affecting available bandwidth estimation in heterogeneous scenarios. Moreover, to provide evidences of UANM benefits, we present an experimental validation in three selected scenarios deployed over a real network testbed: (i) we show how UANM is able to alleviate the interferences among concurrent measures; (ii) we quantify the overhead introduced by the use of UANM; (iii) we illustrate how UANM is capable to provide more accurate results thanks to the knowledge of the network environment.
Giuseppe Aceto, Alessio Botta, Antonio Pescapè, Maurizio D'Arienzo
ISCC3
2010 Performance footprints of heavy-users in 3G networks via empirical measurement
Alessio Botta, Antonio Pescapè, Giorgio Ventre, Ernst W. Biersack, Stefan Rugel
WiOpt2
2010 Integration of 3G Connectivity in PlanetLab Europe
Alessio Botta, Roberto Canonico, Giovanni Di Stasi, Antonio Pescapè, Giorgio Ventre, Serge Fdida
Mob. Networks Appl.4
2010 A Markovian Approach to Multipath Data Transfer in Overlay Networks
abstract
The use of multipath routing in overlay networks is a promising solution to improve performance and availability of Internet applications, without the replacement of the existing TCP/IP infrastructure. In this paper, we propose an approach to distribute data over multiple overlay paths that is able to improve Quality of Service (QoS) metrics, such as the data transfer time, loss, and throughput. By using the Imbedded Markov Chain technique, we demonstrate that the system under analysis, observed at specific instants, possesses the Markov property. We therefore cast the data distribution problem into the Markov Decision Process (MDP) framework, and design a computationally efficient algorithm named Online Policy Iteration (OPI), to solve the optimization problem on the fly. The proposed approach is applied to the problem of multipath data distribution in various wired/wireless network scenarios, with the objective of minimizing the data transfer time as well as the delay and losses. Through both intensive ns-2 simulations with data collected from real heterogeneous networks and experiments over real networks, we show the superior performance of the proposed traffic control mechanism in comparison with two classical schemes, that are Weighted Round Robin and Join the Shortest Queue.
Vinh Bui, Weiping Zhu 0001, Alessio Botta, Antonio Pescapè
IEEE Trans. Parallel Distributed Syst.4
2009 Traffic classification and its applications to modern networks
Marco Mellia, Antonio Pescapè, Luca Salgarelli
Comput. Networks2
2009 Traffic analysis of peer-to-peer IPTV communities
Thomas Silverston, Olivier Fourmaux, Alessio Botta, Alberto Dainotti, Antonio Pescapè, Giorgio Ventre, Kavé Salamatian
Comput. Networks5
2009 A cascade architecture for DoS attacks detection based on the wavelet transform
abstract
In this paper we propose an automated system able to detect volume-based anomalies in network traffic caused by Denial of Service (DoS) attacks. We designed a system with a two-stage architecture that combines more traditional change point detection approaches (Adaptive Threshold and Cumulative Sum ) with a novel one based on the Continuous Wavelet Transform. The presented anomaly detection system is able to achieve good results in terms of the trade-off between correct detections and false alarms, estimation of anomaly duration, and ability to distinguish between subsequent anomalies. We test our system using a set of publicly available attack-free traffic traces to which we superimpose anomaly profiles obtained both as time series of known common behaviors and by generating traffic with real tools for DoS attacks. Extensive test results show how the proposed system accurately detects a wide range of DoS anomalies and how the performance indicators are affected by anomalies characteristics (i.e. amplitude and duration). Moreover, we separately consider and evaluate some special test-cases.
Alberto Dainotti, Antonio Pescapè, Giorgio Ventre
J. Comput. Secur.2
2008 Providing UMTS connectivity to PlanetLab nodes
abstract
Planetlab is widely recognized as being one of the most important Internet-scale testbeds. However, while allowing experimentations involving hundreds of hosts spread all over the world, PlanetLab still suffers of a few significant limitations. One of these limitations is the lack of heterogeneity, in particular in terms of access technologies. In this paper we describe the efforts we made, in the context of the OneLab European project, in order to mitigate this problem. In particular, we describe how we managed to integrate UMTS connectivity into a PlanetLab-based testbed. We illustrate the technical challenges we had to face, the final result we obtained, and present a case study meant to show the utility of having UMTS connectivity available in Planetlab.
Alessio Botta, Roberto Canonico, Giovanni Di Stasi, Antonio Pescapè, Giorgio Ventre
CoNEXT4
2008 Networked Embedded Systems: A Quantitative Performance Comparison
abstract
Networked embedded systems are gaining more and more attention and their use in current network scenarios is of indisputable importance. Research community and industry are proposing novel embedded solutions, often based on network processors, for network connectivity, data processing and service delivery. Despite this, quantitative performance comparisons of such systems seem to be very hard to find. In this paper, we describe an experimental analysis of different boards for networked embedded systems using both general-purpose and network processors, and running both commercial and open source operating systems. The results show that network-processor based boards are able to attain very high performance when compared to boards based on x86 processors, especially when running commercial operating systems. The analysis provides a reference for the design, development, and testing of novel networked embedded systems.
Alessio Botta, Walter de Donato, Antonio Pescapè, Giorgio Ventre
GLOBECOM3
2008 Classification of Network Traffic via Packet-Level Hidden Markov Models
abstract
Traffic classification and identification is a fertile research area. Beyond Quality of Service, service differentiation, and billing, one of the most important applications of traffic classification is in the field of network security. This paper proposes a packet-level traffic classification approach based on Hidden Markov Model (HMM). Classification is performed by using real network traffic and estimating - in a combined fashion - Packet Size (PS) and Inter Packet Time (IPT) characteristics, thus remaining applicable to encrypted traffic too. The effectiveness of the proposed approach is evaluated by considering several traffic typologies: we applied our model to real traffic traces of Age of Mythology and Counter Strike (two Multi Player Network Games), HTTP, SMTP, Edonkey, PPlive (a peer-to-peer IPTV application), and MSN Messenger. An analytical basis and the mathematical details regarding the model are given. Results show how the proposed approach is able to classify network traffic by using packet-level statistical properties and therefore it is a good candidate as a component for a multi-classification framework.
Alberto Dainotti, Walter de Donato, Antonio Pescapè, Pierluigi Salvo Rossi
GLOBECOM3
2008 An MDP-Based Approach for Multipath Data Transmission over Wireless Networks
abstract
Maintaining performance and reliability in wireless networks is a challenging task due to the nature of wireless channels. Multipath data transmission has been used in wired scenarios to reduce latency, improve throughput, and - when/where possible - balance the load. In this paper, we propose an approach for multipath data transmission over wireless networks. We demonstrate that the problem under study can be formulated as a Markov decision process (MDP) and we propose an algorithm called On-line Policy Iteration (OPI), to solve the formulated MDP in real time. We verified the proposed approach using simulations with ns-2 and data collected from real heterogeneous wired/wireless networks. The results indicate that we improve both delay and loss characteristics of end-to-end wireless communications outperforming the classical multi-path schemes including Round Robin and Join the Shortest Queue.
Vinh Bui, Weiping Zhu 0001, Alessio Botta, Antonio Pescapè
ICC4
2008 An approach to the identification of network elements composing heterogeneous end-to-end paths
Alessio Botta, Antonio Pescapè, Giorgio Ventre
Comput. Networks2
2008 Internet traffic modeling by means of Hidden Markov Models
Alberto Dainotti, Antonio Pescapè, Pierluigi Salvo Rossi, Francesco Palmieri 0001, Giorgio Ventre
Comput. Networks2
2008 High-speed backhaul networks: Myth or reality?
Roger P. Karrer, Alessio Botta, Antonio Pescapè
Comput. Commun.3
2008 Performance measurement of IEEE 802.11b-based networks affected by narrowband interference through cross-layer measurements
abstract
Researches and development efforts in wireless networking and systems are progressing at an incredible rate. Among them, measurement and analysis of performance achieved at network layer and perceived by end users is an important task. In particular, recent advances concerning IEEE 802.11b-based networks seem to be focused on the measurement of key parameters at different protocol levels in a cross-layered fashion, because of their inherent vulnerability to in-channel interference. By adopting a cross-layer approach on a real network set-up operating in a suitable experimental testbed, packet loss against signal-to-interference ratio in IEEE 802.11b-based networks is hereinafter assessed. Results of several measurements aimed at establishing the sensitivity of IEEE 802.11b carrier sensing mechanisms to continuous interfering signals and evaluating the effects of triggered interference on packet transmission.
Leopoldo Angrisani, Antonio Pescapè, Giorgio Ventre, Michele Vadursi
IET Commun.2
2007 High-speed wireless backbones: measurements from MagNets
abstract
The long-standing vision of ubiquitous Internet access requires high-speed wireless networks that sustain 100 Mbps or more. While existing hardware already supports these speeds and they are available at single access points, measurement studies of existing mesh or multi-hop WiFi networks that cover and span larger areas report effective throughputs that are one or two orders of magnitude lower. We ask the question whether we can not already build high-speed wireless network that sustain high rates. To answer this question, we have built the MagNets high-speed WiFi backbone in the heart of Berlin. This paper presents an experimental evaluation of the single and multi-hop performance in terms of throughput, jitter, delay, packet loss, and assesses the impact of environmental factors on these parameters. Our results indicate, e.g. that some links achieve a sustained UDP throughput of up to 62 Mbps using off-the-shelf hardware supporting Super-AG modes, whereas others are limited to 4–5 Mbps due to interfering networks. In contrast, we show that the link performance is largely unaffected by environmental factors, such as day/night or social events (i.e. 2006 FIFA World Cup semi-final and final matches).
Alessio Botta, Antonio Pescapè, Giorgio Ventre, Roger P. Karrer
BROADNETS2
2007 Do you know what you are generating?
abstract
Software-based traffic generators are commonly used in experimental research on computer networks. However, there are no much studies focusing on how such instruments are accurate. Here we start a discussion reviewing the problem of using software-based traffic generators over common hardware/software, highlighting interesting issues that pose some threats to common beliefs. We started comparing the operator-requested traffic profile against the real behavior of commonly used software-based traffic generators. We aim at performing tests under different conditions and looking both at packet/bit rate and inter-packet time distribution. Preliminary results show notable differences in some cases, opening the way to interesting discussions and further investigations.
Alberto Dainotti, Alessio Botta, Antonio Pescapè
CoNEXT3
2007 Discovering Topologies at Router Level: Part II
abstract
Measurement and monitoring of network topologies are essential tasks in current network scenarios. Indeed, due to their utility in planning, management, security, and reliability of network infrastructures, effective and efficient approaches and tools for discovering large topologies are gaining more and more attention from both Application Service Providers and network administrators. In this paper we propose a hybrid methodology and its implementation in a software platform we calledHynetd. We present the architecture, some novel algorithms and methods adopted in the discovery chain, and a performance evaluation over two network scenarios: a small scale test-bed and a large scale MAN in the heart of Napoli (Italy). We provide experimental results confirming and improving those previously obtained by a prototype ofHynetd. In addition a comparison with a commercial tool is presented. Achieved results, in terms of accuracy, discovery time, and traffic injected, are very encouraging in both considered scenarios.
Alessio Botta, Walter de Donato, Antonio Pescapè, Giorgio Ventre
GLOBECOM3
2007 Reducing Network Traffic Data Sets
abstract
In the study of network traffic, the collection and the processing of measurement data sets play a fundamental role. Due to the large size of typical traffic traces, their analysis is often heavy in terms of computational time and resources. In addition, even when the data sets are small, due to the intrinsic redundancy of the data, there is no need to consider the entire data sets in the processing stages. To cope with these issues, we use anentropy-based methodology to reduce network traffic data sets obtained by measurements over real networks. The off-line approach we used is based on themarginalutilityconcept, and reveals encouraging results when applied to real data captured over real networks, especially when dealing with large amounts of data. To show the applicability of our approach, we present and discuss results obtained in the analysis and characterization, at packet-level, of traffic traces from two popular network games:Counter-StrikeandAgeofMythology. Thanks to the differences between the two considered on-line games and their traffic traces we can draw pros and cons in realistic scenarios.
Alessio Botta, Alberto Dainotti, Antonio Pescapè, Giorgio Ventre
ICC3
2007 Worm Traffic Analysis and Characterization
abstract
Internet worms are gaining ever more attention by the research community, representing one of the hot research topics in the field of network security. Our knowledge of phenomena related to Internet worms (from their intrinsic characteristics to their impact and to possible countermeasures) is still in its infancy. This is one of the main reasons for the existence of different kinds of research approaches. In this paper we focus on worm traffic analysis. We propose a general methodology, we discuss issues involved, and we present a software platform which can be used for this kind of study. Moreover, we show some interesting preliminary results from our traffic analysis of two of the most relevant worms that spread over the Internet: Witty and Slammer. Our results provide interesting evidences of (spatial and temporal) invariance and give some hints on worm traffic fingerprinting.
Alberto Dainotti, Antonio Pescapè, Giorgio Ventre
ICC2
2007 Long Horizon End-to-End Delay Forecasts: A Multi-Step-Ahead Hybrid Approach
abstract
A long horizon end-to-end delay forecast, if possible, will be a breakthrough in traffic engineering. This paper introduces a hybrid approach to forecast end-to-end delays using wavelet transforms in combination with neural network and pattern recognition techniques. The discrete wavelet transform is implemented to decompose delay time series into a set of wavelet components, which is comprised of an approximate component and a number of detail components. Thus, it turns the problem of long horizon delay forecasting into a set of shorter horizon wavelet coefficient forecasting problems. A recurrent multi-layered perceptron neural network is applied to forecast coefficients of the wavelet approximate component, which represents the trend of the delay series. The k-nearest neighbors technique is used to forecast coefficients of the wavelet detail components, which reflect the burstiness of background traffic. The proposed approach has been verified in both simulation and over real heterogeneous networks showing promising results in terms of averaged normalized root mean square error. In addition, when compared to some existing and well known approaches it presents the superior performance.
Vinh Bui, Weiping Zhu 0001, Antonio Pescapè, Alessio Botta
ISCC3
2007 SCTP performance evaluation over heterogeneous networks
abstract
Abstract Since its definition in 2000, the Stream Control Transmission Protocol (SCTP) has attracted increasing interest. Several research works, often validated through analytical and simulative analysis, have attempted to evaluate the benefits of substituting TCP with SCTP, both for signaling and data transfer. In this work, we present a traffic generation and performance analysis tool to test SCTP on real networks. We study the performance of SCTP on real heterogeneous (wired/wireless) scenarios, providing results in terms of throughput and jitter, and comparing its performance against TCP and UDP over the same conditions. Our experimental analysis shows that the current performance of SCTP (operating on a Linux platform) does not justify the use of SCTP as a simple substitute for TCP. Copyright © 2007 John Wiley & Sons, Ltd.
Alberto Dainotti, Salvatore Loreto, Antonio Pescapè, Giorgio Ventre
Concurr. Comput. Pract. Exp.3
2006 Measuring SCTP Throughput and Jitter over Heterogeneous Networks
abstract
Stream control transmission protocol (SCTP) is gaining ever more attention. Several proposals, based on simulation results, aiming to replace TCP with SCTP are present. To the best of our knowledge there are no available tools supporting SCTP traffic generation. In this work, to study the performance of SCTP in real heterogeneous (wired/wireless) scenarios, we provide some preliminary results in terms of throughput and jitter that we obtained using a tool we developed to support SCTP traffic generation in real networks. A comparison with TCP and UDP over the same scenarios is also present.
Donato Emma, Salvatore Loreto, Antonio Pescapè, Giorgio Ventre
AINA (2)3
2006 Searching for invariants in network games traffic
abstract
Even if Internet traffic analysis and characterization is a fertile research area, a lot of work still must be done to study and understand the traffic characteristics of new emerging multimedia applications. Among them, an interesting category is that of multiplayer network games. This paper aims at demonstrating that, at packet level, spatial and temporal invariants exist in the traffic of such applications. For this purpose, we study Counter-Strike, a popular client/server network game, comparing results from two different networks. The effectiveness of the proposed approach is evaluated by studying statistics of both packet size and inter-packet time. Results provide a view on packet-level game traffic and they confirm that the main traffic dynamics present properties that can be generalized, independently of the observation point and time.
Alberto Dainotti, Alessio Botta, Antonio Pescapè, Giorgio Ventre
CoNEXT3
2006 An HMM Approach to Internet Traffic Modeling
abstract
Traffic modeling is a fertile research area. This paper proposes a packet-level traffic model of traffic sources based on hidden Markov model. It has been developed by using real network traffic and estimating in a combined fashion packet size and inter packet time. The effectiveness of the proposed model is evaluated by studying several traffic types with strong differences in terms of both applications/users and protocol behavior. Indeed, we applied our model to real traffic traces of Age of Mythology (a Multi Player Network Game), SMTP, and HTTP. An analytical basis and the mathematical details regarding the model are given. Results show how the proposed model captures first-order statistics, as well as temporal dynamics via auto- and cross-correlation. Also, the capability to accurately replicate the considered traffic sources is shown. Finally, preliminary results for model-based traffic prediction reveal encouraging.
Alberto Dainotti, Antonio Pescapè, Pierluigi Salvo Rossi, Giulio Iannello, Francesco Palmieri 0001, Giorgio Ventre
GLOBECOM2
2006 Wavelet-based Detection of DoS Attacks
abstract
Automated detection of anomalies in network traffic is an important and challenging task. In this work we propose an automated system to detect volume-based anomalies in network traffic caused by denial of service (DoS) attacks. The system has a two-stage architecture that combines more traditional approaches (adaptive threshold and cumulative sum) with a novel one based on the continuous wavelet transform. Thanks to the proposed architecture, we obtain good results in terms of tradeoff between correct detections and false alarms, estimation of anomaly duration, and ability to distinguish between subsequent anomalies. We test our system using a set of publicly available traffic traces to which we superimpose anomalies related to real DoS attacks tools. Extensive test results show how the proposed system accurately detects a wide range of anomalies and how the performance indicators are affected by anomalies characteristics (i.e. amplitude and duration).
Alberto Dainotti, Antonio Pescapè, Giorgio Ventre
GLOBECOM2
2006 Identification of Network Bricks in Heterogeneous Scenarios
abstract
Accurate identification of network elements (network bricks) composing end-to-end paths represents a novel and interesting research topic. In heterogeneous scenarios, automatic network bricks identification can improve the performance of adaptive and network-aware applications. This work proposes an approach, based on Bayesian classifiers, for the identification of network bricks belonging to a large number of real heterogeneous end-to-end paths. The identification is performed by means of measurement and off-line observation of delay, jitter, and packet loss. We introduce the term "blind identification" meaning the capability to identify network bricks, by looking at quality of service (QoS) parameters observed on the end-to-end path. We propose first insights and preliminary results regarding the identification stage, based on both concise and detailed QoS parameters statistics. Moreover, we show some results of the identification performed using a reduced set of QoS parameters
Alessio Botta, Antonio Pescapè, Giorgio Ventre
LCN2
2006 An open source traffic engineering toolbox
Guy Leduc, Henrik Abrahamsson, Simon Balon, Sandford Bessler, Maurizio D'Arienzo, Olivier Delcourt, Jordi Domingo-Pascual, Selin Cerav-Erbas, Ivan Gojmerac, Xavier Masip-Bruin, Antonio Pescapè, Bruno Quoitin, S. F. Romano, E. Salvatori, Fabian Skivée, Hung Tuan Tran, Steve Uhlig, Hakan Ümit
Comput. Commun.11
2006 Systematic performance modeling and characterization of heterogeneous IP networks
Alessio Botta, Donato Emma, Antonio Pescapè, Giorgio Ventre
J. Comput. Syst. Sci.3
2006 High Performance Internet Traffic Generators
Stefano Avallone, Donato Emma, Antonio Pescapè, Giorgio Ventre
J. Supercomput.3
2005 End-to-end packet-channel Bayesian model applied to heterogeneous wireless networks
abstract
This paper proposes a source-traffic based model to estimate jointly packet losses and delays statistical behavior of a network path. The approach relies on a hidden Markov model built on real-traffic information. The effectiveness of the model is evaluated over different real heterogeneous network scenarios. Our experimental results show that the model captures average (long-term) and conditional (short-term) statistics that in most cases are typical of the single scenario. Preliminary results about prediction on a sample path as well as investigation on the use of the same model across different scenarios are given.
Giulio Iannello, Francesco Palmieri 0001, Antonio Pescapè, Pierluigi Salvo Rossi
GLOBECOM3
2005 Experimental analysis of attacks against intradomain routing protocols
abstract
Nowadays attacks against the routing infrastructure are gaining an impressive importance. Therefore, approaches to network security and reliability must take into account effects of routing protocols attacks and consequently must consider techniques to protect the network infrastructure. However, i n spite of an increasing attention by scientists and practitioners to this issue, there is still a lack of experimental quantitative studies on the effects of routing attacks. To cope with these deficiencies, in this work we present a framework to conduct experimental analysis of routing attacks, and to prove its usefulness we study three attacks against routing protocols: route flapping on RIP, Denial of Service on OSPF by means of the Max Age attack and, finally, route forcing on RIP. We present a qualitative analysis and a performance analysis that aims to quantify the effects of routing protocol attacks with respect to routers resources and network traffic over controlled test beds.
Antonio Pescapè, Giorgio Ventre
J. Comput. Secur.1
2005 Performance evaluation of an open distributed platform for realistic traffic generation
Stefano Avallone, Donato Emma, Antonio Pescapè, Giorgio Ventre
Perform. Evaluation3
2004 Experimental analysis of attacks against routing network infrastructures
abstract
At the present time, attacks against routing infrastructure are gaining an impressive importance. Currently an approach to network security and reliability must take into account the effects of routing protocols attacks and techniques for network infrastructure protection. This work presents an experimental analysis of three well know attacks against routing protocols: route flapping on RIP, denial of service on OSPF (max age attack) and finally route forcing on RIP. We also present this last attack in a rudimental traffic engineering mechanism.
Antonio Pescapè, Giorgio Ventre
IPCCC1
2004 An efficient approach to the network division problem, VLANs configuration and WLANs hosts grouping
abstract
Nowadays, network design and management can be considered as well understood topics. A thorough view of a complete project of a network infrastructure is definitely more important than its single details. Among the many innovations introduced in the IP networks, an interesting issue is represented by enhanced architectures where services like telephony and video transmission are provided on the same infrastructure used for data traffic. At the same time, actual networks are heterogeneous in terms of access network technologies, end user's device and finally operating systems. In these new scenarios innovative and efficient management's approaches are needed. This paper describes a proposal to improve the management of different network scenarios. This work presents a "partitioning algorithm" and some of its possible practical applications in the field of shared LANs, full switched LANs, VLANs (virtual local area networks) configuration, and in WLANs (wireless local area networks) environments.
Marcello Esposito, Antonio Pescapè, Giorgio Ventre
LANMAN2
2004 An architecture for automatic configuration of integrated networks
abstract
Configuration and management activities are frequently performed both in local area and campus networks due to the intrinsic variability characterizing such networks and the innovative services provided through them. Indeed, in order to benefit from services like voice over IP and multimedia content distribution, corporate users need to configure and manage their network appropriately. Suitable strategies have to be undertaken to fulfill stringent requirements imposed by such services on the underlying "integrated" transport infrastructure. These activities are both time and money consuming since they are usually under the responsibility of network administrators and managers. We present an architecture that allows the configuration of network devices in an automatic fashion in order to facilitate traffic management and prioritization in LANs. On one hand, traffic management is optimized through the segmentation of a corporate network into multiple virtual LANs via SNMP. On the other, traffic prioritization is carried out by grouping LAN packets into separate classes associated with different priority levels in compliance with 802.1p. The segmentation process is carried out in two steps: in the first, the network segmentation into "multimedia hosts" (i.e., IP phone and multimedia PC) and "data hosts" is accomplished (as well as traffic prioritization); in the second, the segmentation task is optimized in both VLANs thanks to the utilization of a "partitioning algorithm".
Salvatore D'Antonio, Maurizio D'Arienzo, Antonio Pescapè, Giorgio Ventre
NOMS (1)3