Francesco Gringoli

dblp:59/4302 · DBLP profile ↗
← Back
83ranked-venue papers
4as first author
32since 2021 · last 2026
0000-0003-2621-582XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 56 · 3 first-author · 20 since 2021Security and privacy · 10 · 2 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 2Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Crafting Adversarial Attacks to MU-MIMO OFDMA Transmissions in Wi-Fi Networks
abstract
The exponential growth of Wi-Fi-enabled devices and the changing nature of online activities highlight the urgent need to find innovative solutions to solve the ever-growing spectrum crunch. To address this challenge, the IEEE 802.11ax standard breaks away from traditional approaches leveraged in previous standards by jointly enabling orthogonal frequency-division multiple-access (OFDMA) and multi-user MIMO (MU-MIMO). While IEEE standardization groups are working to increase the network capacity (IEEE 802.11be) and its reliability (IEEE 802.11bn), there are still serious security issues in Wi-Fi. Some recent work has revealed that MU-MIMO transmissions can be thwarted by a malicious user that interferes with the procedure followed to set up simultaneous transmissions to multiple stations (STAs). In this work, we show that a similar attack is also effective in OFDMA MU-MIMO transmissions. Specifically, a malicious user in the network can alter the precoding procedure by transmitting adversarial feedback during the channel sounding phase, thus increasing the bit error rate (BER) experienced by legitimate STAs to up to 0.5 depending on the portion of feedback that is poisoned. We shared the code to implement our attack for reproducibility purposes and to ease its integration into digital twin frameworks of Wi-Fi networks to study and evaluate effective countermeasures.
Linda Traverso, Francesco Gringoli, Francesco Restuccia 0001, Francesca Meneghello 0001
CCNC2
2026 Rethinking Power Allocation in OFDMA: A Throughput-Optimized Multi-User Strategy
abstract
Modern networks rely on orthogonal frequency division multiple access (OFDMA) to efficiently allocate bandwidth among multiple users. While resource allocation mechanisms primarily focus on bandwidth distribution, transmit power is typically flat along the spectrum, potentially limiting achievable data rates due to heterogeneous channel conditions. In this paper, we investigate the impact of power allocation on modulation and coding scheme (MCS) selection. Specifically, we formulate an optimization problem aimed at maximizing the aggregate data rate in a wireless local area network (WLAN), subject to constraints on minimum packet delivery ratio (PDR). The key insight is that reallocating transmit power across users can alter the signal-to-noise ratio (SNR), enabling higher MCS levels and improving throughput without modifying bandwidth assignments. Due to the discrete nature of MCS levels, the problem is inherently combinatorial and difficult to solve optimally. To address this, we propose a practical heuristic inspired by water-filling principles, combined with a Knapsack-based selection strategy to prioritize users that yield the highest rate gains per unit of power. The approach redistributes power from users with excess margin to those who can benefit from an MCS upgrade. Simulation results based on IEEE 802.11ax settings show that the proposed method improves the aggregate throughput while preserving reliability constraints.
Giovanni Perin, Giovanni Angelo Alghisi, Aaron Kweku Amankwah, Francesco Gringoli
WiOpt4
2026 A survey on CSI-based Wi-Fi sensing datasets and models with a focus on reproducibility
abstract
Wi-Fi sensing based on Channel State Information (CSI) has witnessed considerable research activity in recent years. However, a critical literature analysis reveals that only a limited amount of proposals are potentially reproducible, with many works lacking essential experimental details, publicly available datasets, or accessible analysis code. This may impede the research progress and the subsequent transition of promising findings into practical applications. The objective of this work is to identify CSI-based sensing proposals that are potentially reproducible based on the published information. Our goal is to provide a focused review of resources that can serve as a concrete starting point for researchers and practitioners seeking to experiment with and advance the field of Wi-Fi sensing. We perform a comprehensive analysis of publicly available datasets (encompassing both the collection methodologies and the environmental characteristics) and existing sensing models, accompanied by their code, pre-processing steps, and evaluation procedures. Finally, we discuss what are the minimum requirements for truly verifiable contributions in this field, and outline the best practices for creating and sharing reproducible CSI-based sensing datasets and models.
Idio Guarino, Damiano Carra, Marco Cominelli, Francesco Gringoli, Renato Lo Cigno
Comput. Commun.4
2026 Same Signal, Different Story: Demystifying Receiver Effects in Wi-Fi Channel State Information
abstract
Wi-Fi sensing has emerged as a versatile tool for tasks such as localization, gesture recognition, and vital-sign monitoring, enabling applications from smart environments to personalized healthcare. However, sensing accuracy often significantly degrades when pretrained models are deployed across different commodity receivers. We present the first systematic comparison of Channel State Information (CSI) across diverse Commercial Off-The-Shelf Wi-Fi sensing platforms. Using a unified experimental setup delivering precisely precoded signals simultaneously to multiple receivers, we isolate receiver-specific variability. We find that dominant cross-device differences arise from Automatic Gain Control and consistent subcarrier non-linearities. We propose a simple gain-alignment preprocessing step, recovering most of the lost accuracy (up to 75%) in cross-device Human Activity Recognition model deployments. Without preprocessing, model accuracy sharply drops—effectively breaking practical deployments. Additional analyses reveal measurable inherent differences in receiver faithfulness, sensitivity and noise. While these receiver-induced differences do not significantly affect robust sensing tasks such as Human Activity Recognition, they become relevant in scenarios demanding high precision (e.g., single-shot time of flight). Our findings demonstrate that cross-device variability in CSI is real but manageable, and we provide tools and guidelines for robust, hardware-agnostic Wi-Fi sensing.
Fabian Portner, Francesco Gringoli, Matthias Hollick, Arash Asadi
IEEE Internet Things J.2
2025 EgoLife: Towards Egocentric Life Assistant
abstract
We introduce EgoLife, a project to develop an egocentric life assistant that accompanies and enhances personal efficiency through AI-powered wearable glasses. To lay the foundation for this assistant, we conducted a comprehensive data collection study where six participants lived together for one week, continuously recording their daily activities—including discussions, shopping, cooking, social-izing, and entertainment—using AI glasses for multimodal person-view video references. This effort resulted in EgoLife Dataset, a comprehensive 300-hour egocentric, terpersonal, multiview, and multimodal daily life with intensive annotation. Leveraging this dataset, we troduce EgoLifeQA, a suite of long-context, life-oriented question-answering tasks designed to provide meaningful sistance in daily life by addressing practical questions as recalling past relevant events, monitoring health and offering personalized recommendations.To address the key technical challenges of 1) developing robust visual-audio models for egocentric data, 2) enabling identity recognition, and 3) facilitating long-context question answering over extensive temporal information, we introduce EgoBulter, an integrated system comprising EgoGPT and EgoRAG. EgoGPT is an omni-modal model trained on egocentric datasets, achieving state-of-the-art performance on egocentric video understanding. EgoRAG is a retrieval-based component that supports answering ultra-long-context questions. Our experimental studies verify their working mechanisms and reveal critical factors and bottlenecks, guiding future improvements. By releasing our datasets, models, and benchmarks, we aim to stimulate further research in egocentric AI assistants.
Shuai Liu 0002, Hongming Guo, Yuhao Dong, Xiamengwei Zhang, Pengyun Wang, Zitang Zhou, Binzhu Xie, Bei Ouyang, Zhengyu Lin, Marco Cominelli, Zhongang Cai, Bo Li 0080, Yuanhan Zhang, Peiyuan Zhang, Fangzhou Hong, Jörg Widmer, Francesco Gringoli, Lei Yang 0059, Ziwei Liu 0002
CVPR20
2025 Preliminary Insights Into Resource-Constrained Neuro-Symbolic Causal Complex Event Processing
abstract
We propose a neuro-symbolic approach for learning causal complex event models from multi-source data, integrating causal discovery and temporal logic. Given resource constraints, we employ signal-level fusion by averaging the data from different antennas of the same WiFi receiver, followed by downsampling to reduce computational overhead. We consider a dataset of WiFi Channel State Information capturing human activities alongside video data from which we extract atomic symbolic activities such as “moving the upper arm.” The extracted symbolic information is processed through LPCMCI (Latent PCMCI). This causal discovery method extends PCMCI (Peter and Clark Momentary Conditional Independence) to handle latent dependencies across multiple time steps while mitigating false discoveries due to auto-correlations. The resulting causal structure is then translated into a temporal logic formula, which serves as a symbolic constraint in a neuro-symbolic learning pipeline. To efficiently process and learn from these structured constraints under resource limitations, we leverage Spiking Neural Networks, which offer energy-efficient computation while preserving temporal dynamics.
Christian Bresciani, Luca Lavazza, Marco Cominelli, Liying Han, Gaofeng Dong, Francesco Gringoli, Lance M. Kaplan, Mani Srivastava 0001, Trevor J. Bihl, Erik Blasch, Felix J. Knutson, Federico Cerutti 0001
FUSION6
2025 How to BREAK MU-MIMO Precoding in IEEE 802.11 Wi-Fi Networks
Francesca Meneghello 0001, Francesco Gringoli, Marco Cominelli, Michele Rossi, Francesco Restuccia 0001
INFOCOM2
2025 SHRINK: Reducing MIMO Feedback Overhead in Wi-Fi with Dynamic Data-Driven Channel Sounding
abstract
The performance of multiple-input, multiple-output (MIMO) systems highly depends on the precision of channel estimates provided by the mobile users. However, the current Wi-Fi standard requires an update interval of 10 ms, irrespective of the channel dynamics. This imposes a substantial overhead for the MIMO channel estimation. Recent work mainly targets different compression strategies, potentially compromising precoding accuracy and, in turn, the network performance. In stark opposition, we propose SHRINK, a framework to dynamically adapt the feedback transmission rate to the propagation environments and performance requirements. SHRINK determines whether the users should send back their channel estimates by predicting network performance through a data-driven analysis of prior and current channel estimates. We have experimentally evaluated SHRINK using off-the-shelf Wi-Fi devices in multiple environments, including an anechoic chamber, and benchmarked its performance against several state-of-the-art approaches. Experimental results show that SHRINK reduces airtime and data overhead by 81% on average compared to the IEEE 802.11 standard without impacting the precoding performance. Moreover, SHRINK outperforms state-of-the-art approaches by an average gain of 33.6% in airtime and data overhead reduction, corresponding to an increase in throughput of 24.5%.
K. M. Rumman, Francesca Meneghello 0001, Khandaker Foysal Haque, Francesco Gringoli, Francesco Restuccia 0001
MobiHoc4
2025 A Glimpse into IEEE 802.11be Channels: Can They Improve CSI-Based Sensing?
abstract
Wireless sensing based on Channel State Information (CSI) is rapidly spreading with the advent of 6G and newer Wi-Fi versions. Today, the CSI is regarded as one of the most promising elements for boosting service innovation on indoor device-free sensing. In addition, the wide adoption of the latest IEEE 802.11be standard, commonly known as Wi-Fi 7, might open up new possibilities for Wi-Fi sensing applications with even larger bandwidths, up to 320 MHz, and 4096 sub-carriers per spatial stream. However, researchers have still limited access to CSI extraction tools for such systems. In this work, we devise a framework based on software-defined radios to investigate the potential implications of the new Wi-Fi features, namely the wider channels and the higher number of sub-carriers, on a device-free positioning system based on position fingerprinting. In particular, we analyze the impact and the performance variations of this new technology across different bands in a position classification system, which has proven to be very accurate with previous versions of Wi-Fi. Our preliminary findings set some clear guidelines to direct future research efforts towards a better usage of newer Wi-Fi channels for sensing purposes. Furthermore, we publicly release our framework to the community of researchers and engineers for developing better Wi-Fi sensing solutions for smart homes, health care, and Internet-of- Things applications in general.
Marco Cominelli, Shabbir Raza, Renato Lo Cigno, Francesco Gringoli
WCNC4
2025 Towards a Quantitative Analysis of CSI for AI/ML Based Sensing
abstract
Channel State Information (CSI) sensing is now an established element of Integrated Sensing and Communication (ISAC) operations, but what is its real potential, and what are its limits? The literature focused more on sophisticated AI systems to exploit CSI variations imposed by different propagation scenarios, indeed achieving amazing results, but few, if any works tackled the topic of characterizing the long-term CSI behavior, its stability, and its stochastic properties to achieve insight in the potential and limits of CSI sensing. This work presents a first attempt in this direction, providing a framework that allows the comparison of CSIs quantifying the difference between CSI collected in different scenarios and showing that a quantitative analysis of the CSI is possible, and it can also help to explain the accuracy difference observed between distinct experiments with a CNN-based localization method taken from the literature.
Elena Tonini, Francesco Gringoli, Renato Lo Cigno, Marco Cominelli
WCNC2
2025 Scalable Multi-Modal Learning for Cross-Link Channel Prediction in Massive IoT Networks
abstract
Tomorrow’s massive-scale Internet-of-Things (IoT) sensor networks are poised to drive uplink traffic demand, especially in areas of dense deployment. To meet this demand, however, network designers leverage tools that often require accurate estimates of Channel State Information (CSI), which incurs a high overhead and thus reduces network throughput. Furthermore, the overhead generally scales with the number of clients, and so is of special concern in such massive IoT sensor networks. While prior work has used transmissions over one frequency band to predict the channel of another frequency band on the same link, this paper takes the next step in the effort to reduce CSI overhead: predict the CSI of a nearby but distinct link. We proposeCross-Link Channel Prediction(CLCP), a technique that leverages multi-view representation learning to predict the channel response of a large number of users, thereby reducing channel estimation overhead further than previously possible. CLCP’s design is highly practical, exploiting existing transmissions rather than dedicated channel sounding or extra pilot signals. We have implemented CLCP for two different Wi-Fi versions, namely 802.11n and 802.11ax, the latter being the leading candidate for future IoT networks. We evaluate CLCP in two large-scale indoor scenarios involving both line-of-sight and non-line-of-sight transmissions with up to 144 different 802.11ax users. Moreover, we measure its performance with four different channel bandwidths, from 20 MHz up to 160 MHz. Our results show that CLCP provides a 2x throughput gain over baseline and a 30% throughput gain over existing prediction algorithms.
Kun Woo Cho, Marco Cominelli, Francesco Gringoli, Jörg Widmer, Kyle Jamieson
IEEE Trans. Netw.3
2024 Wherever I May Roam: Stealthy Interception and Injection Attacks Through Roaming Agreements
Swantje Lange, Francesco Gringoli, Matthias Hollick, Jiska Classen
ESORICS (4)2
2024 Neuro-Symbolic Fusion of Wi-Fi Sensing Data for Passive Radar with Inter-Modal Knowledge Transfer
abstract
Wi-Fi devices, akin to passive radars, can discern human activities within indoor settings due to the human body’s interaction with electromagnetic signals. Current Wi-Fi sensing applications predominantly employ data-driven learning techniques to associate the fluctuations in the physical properties of the communication channel with the human activity causing them. However, these techniques often lack the desired flexibility and transparency. This paper introduces DeepProbHAR, a neuro-symbolic architecture for Wi-Fi sensing, providing initial evidence that Wi-Fi signals can differentiate between simple movements, such as leg or arm movements, which are integral to human activities like running or walking. The neuro-symbolic approach affords gathering such evidence without needing additional specialised data collection or labelling. The training of DeepProbHAR is facilitated by declarative domain knowledge obtained from a camera feed and by fusing signals from various antennas of the Wi-Fi receivers. DeepProbHAR achieves results comparable to the state-of-the-art in human activity recognition. Moreover, as a by-product of the learning process, DeepProbHAR generates specialised classifiers for simple movements that match the accuracy of models trained on finely labelled datasets, which would be particularly costly.
Marco Cominelli, Francesco Gringoli, Lance M. Kaplan, Mani Srivastava 0001, Trevor J. Bihl, Erik Blasch, Nandini Iyer, Federico Cerutti 0001
FUSION2
2024 Physical-Layer Privacy via Randomized Beamforming Against Adversarial Wi-Fi Sensing: Analysis, Implementation, and Evaluation
abstract
Wi-Fi sensing applications have achieved remarkable results over the last decade, offering accurate device-free localization and gesture recognition capabilities. Indeed, Wi-Fi sensing has quickly become a critical field of research for future communication systems under the paradigm known as joint communication and sensing. However, device-free wireless sensing can also be exploited for malign purposes against unaware victims, and the omnipresence of Wi-Fi transceivers poses a significant threat to people’s privacy. Therefore, it is essential to develop functional solutions that can effectively thwart wireless sensing. All the current attempts to hinder illegitimate wireless sensing rely on specialized hardware deployed in the environment, but their cost and complexity can undermine widespread deployment. In this paper, we explore the possibility of using native capabilities of Wi-Fi systems, namely beamforming, to thwart wireless sensing. To this end, we propose for the first time a solution that enables complete control over the beamforming in commercial Wi-Fi devices. On top of that, we build BeamDancer, which randomizes beamforming vectors to inhibit channel fingerprinting. We empirically demonstrate the effectiveness of the proposed solution against three different wireless sensing techniques, both data-driven and model-based, while preserving almost entirely the legitimate Wi-Fi traffic at the same time.
Marco Cominelli, Shaghayegh Shahcheraghi, Jakob Link, Matthias Hollick, Federico Cerutti 0001, Francesco Gringoli, Arash Asadi
IEEE Trans. Wirel. Commun.6
2023 Accurate Passive Radar via an Uncertainty-Aware Fusion of Wi-Fi Sensing Data
abstract
Wi-Fi devices can effectively be used as passive radar systems that sense what happens in the surroundings and can even discern human activity. We propose, for the first time, a principled architecture which employs Variational Auto-Encoders for estimating a latent distribution responsible for generating the data, and Evidential Deep Learning for its ability to sense out-of-distribution activities. We verify that the fused data processed by different antennas of the same Wi-Fi receiver results in increased accuracy of human activity recognition compared with the most recent benchmarks, while still being informative when facing out-of-distribution samples and enabling semantic interpretation of latent variables in terms of physical phenomena. The results of this paper are a first contribution toward the ultimate goal of providing a flexible, semantic characterisation of black-swan events, i.e., events for which we have limited to no training data.
Marco Cominelli, Francesco Gringoli, Lance M. Kaplan, Mani Srivastava 0001, Federico Cerutti 0001
FUSION2
2023 Scalable Multi-Modal Learning for Cross-Link Channel Prediction in Massive IoT Networks
abstract
Tomorrow's massive-scale IoT sensor networks are poised to drive uplink traffic demand, especially in areas of dense deployment. To meet this demand, however, network designers leverage tools that often require accurate estimates of Channel State Information (CSI), which incurs a high overhead and thus reduces network throughput. Furthermore, the overhead generally scales with the number of clients, and so is of special concern in such massive IoT sensor networks. While prior work has used transmissions over one frequency band to predict the channel of another frequency band on the same link, this paper takes the next step in the effort to reduce CSI overhead: predict the CSI of a nearby but distinct link. We propose Cross-Link Channel Prediction (CLCP), a technique that leverages multi-view representation learning to predict the channel response of a large number of users, thereby reducing channel estimation overhead further than previously possible. CLCP's design is highly practical, exploiting existing transmissions rather than dedicated channel sounding or extra pilot signals. We have implemented CLCP for two different Wi-Fi versions, namely 802.11n and 802.11ax, the latter being the leading candidate for future IoT networks. We evaluate CLCP in two large-scale indoor scenarios involving both line-of-sight and non-line-of-sight transmissions with up to 144 different 802.11ax users and four different channel bandwidths, from 20 MHz up to 160 MHz. Our results show that CLCP provides a 2× throughput gain over baseline and a 30% throughput gain over existing prediction algorithms.
Kun Woo Cho, Marco Cominelli, Francesco Gringoli, Jörg Widmer, Kyle Jamieson
MobiHoc3
2023 Exposing the CSI: A Systematic Investigation of CSI-based Wi-Fi Sensing Capabilities and Limitations
abstract
Thanks to the ubiquitous deployment of Wi-Fi hotspots, channel state information (CSI)-based Wi-Fi sensing can unleash game-changing applications in many fields, such as healthcare, security, and entertainment. However, despite one decade of active research on Wi-Fi sensing, most existing work only considers legacy IEEE 802.11n devices, often in particular and strictly-controlled environments. Worse yet, there is a fundamental lack of understanding of the impact on CSI-based sensing of modern Wi-Fi features, such as 160-MHz bandwidth, multiple-input multiple-output (MIMO) transmissions, and increased spectral resolution in IEEE 802.11ax (Wi-Fi 6). This work aims to shed light on the impact of Wi-Fi 6 features on the sensing performance and to create a benchmark for future research on Wi-Fi sensing. To this end, we perform an extensive CSI data collection campaign involving 3 individuals, 3 environments, and 12 activities, using Wi-Fi 6 signals. An anonymized ground truth obtained through video recording accompanies our 80-GB dataset, which contains almost two hours of CSI data from three collectors. We leverage our dataset to dissect the performance of a state-of-the-art sensing framework across different environments and individuals. Our key findings suggest that (i) MIMO transmissions and higher spectral resolution might be more beneficial than larger bandwidth for sensing applications; (ii) there is a pressing need to standardize research on Wi-Fi sensing because the path towards a truly environment-independent framework is still uncertain. To ease the experiments' replicability and address the current lack of Wi-Fi 6 CSI datasets, we release our 80-GB dataset to the community.
Marco Cominelli, Francesco Gringoli, Francesco Restuccia 0001
PERCOM2
2023 Wi-Fi Localization Obfuscation: An implementation in openwifi
Lorenzo Ghiro, Marco Cominelli, Francesco Gringoli, Renato Lo Cigno
Comput. Commun.3
2023 Attacks and vulnerabilities of Wi-Fi Enterprise networks: User security awareness assessment through credential stealing attack experiments
abstract
Enterprise Wi-Fi networks are essential for businesses and public administrations as they provide a perfectly scalable and secure system. In the university environment, they are often deployed to offer services to students. One of the most famous university Wi-Fi Enterprise networks is Eduroam, which stands for education roaming; it is a worldwide Wi-Fi access and roaming service widely adopted by the international research and education community. It is based on 802.1x mechanisms that use TLS tunnels for achieving mutual authentication goals, and, as such, it requires careful configuration of mobile devices and responsible users’ behaviors to avoid trivial attacks carried out with rogue Access Points (APs). Differently than employees in a corporate network whose devices are properly configured by ICT teams, the user base of Eduroam consists of (likely) millions of students and professors around the world, with a myriad of different and uncontrolled devices. To assess the security of 802.1x in general, and more specifically that of Eduroam, we ran attacks against two communities of students of increasing size in order to test how users (and their devices) react when rogue 802.1x APs appear in the list of available networks. We then focused our attention on devices, and investigated their detailed dependence on different WPA-Enterprise configurations and certificate settings. The aftermath is that, even with a completely passive attack (users are keeping devices in their pockets), it is possible to steal credentials from more than one-third of the students. While most of the 802.1x vulnerabilities employed in this work should be considered somewhat known (being disclosed in former technical papers), our work appears to raise a threefold concern: (i) most pragmatic 802.1x configurations appear to be grossly insecure; (ii) no Apple’s iPhone felt in our attack unless explicitly forced by the user, owing to its reduced possibility for a user to misconfigure the terminal; and (iii) the awareness of Wi-Fi authentication threats even in relatively skilled end users is close to zero.
Ivan Palamà, Alessandro Amici, Gabriele Bellicini, Francesco Gringoli, Fabio Pedretti, Giuseppe Bianchi 0001
Comput. Commun.4
2023 Enabling Time-Synchronized Hybrid Networks With Low-Cost IoT Modules
abstract
Precisely synchronized communication is a major precondition for many industrial applications. At the same time, hardware cost and power consumption need to be kept as low as possible in the Internet of Things (IoT) paradigm. While many wired solutions on the market achieve these requirements, wireless alternatives are an interesting field for research and development. This article presents a novel IEEE802.11n/ac wireless solution, exhibiting several advantages over state-of-the-art competitors. It is based on a market-available wireless System on a Chip with modified low-level communication firmware combined with a low-cost field-programmable gate array. By achieving submicrosecond synchronization accuracy, our solution outperforms the precision of low-cost products by almost four orders of magnitude. Based on inexpensive hardware, the presented wireless module is up to 20 times cheaper than software-defined-radio solutions with comparable timing accuracy. Moreover, it consumes three to five times less power. To back up our claims, we report data that we collected with a high sampling rate (2000 samples per second) during an extended measurement campaign of more than 120 h, which makes our experimental results far more representative than others reported in the literature. Additional support is provided by the size of the testbed we used during the experiments, composed of a hybrid network with nine nodes divided into two independent wireless segments connected by a wired backbone. In conclusion, we believe that our novel Industrial IoT module architecture will have a significant impact on the future technological development of high-precision time-synchronized communication for the cost-sensitive industrial IoT market.
Alexey M. Romanov, Francesco Gringoli, Kamil Alkhouri, Pavel E. Tripolskiy, Axel Sikora
IEEE Internet Things J.2
2022 Looking for Criminal Intents in JavaScript Obfuscated Code
abstract
The majority of websites incorporate JavaScript for client-side execution in a supposedly protected environment. Unfortunately, JavaScript has also proven to be a critical attack vector for both independent and state-sponsored groups of hackers. On the one hand, defenders need to analyze scripts to ensure that no threat is delivered and to respond to potential security incidents. On the other, attackers aim to obfuscate the source code in order to disorient the defenders or even to make code analysis practically impossible. Since code obfuscation may also be adopted by companies for legitimate intellectual-property protection, a dilemma remains on whether a script is harmless or malignant, if not criminal. To help analysts deal with such a dilemma, a methodology is proposed, called JACOB, which is based on five steps, namely: (1) source code parsing, (2) control flow graph recovery, (3) region identification, (4) code structuring, and (5) partial evaluation. These steps implement a sort of decompilation for control flow fattened code, which is progressively transformed into something that is close to the original JavaScript source, thereby making eventual code analysis possible. Most relevantly, JACOB has been successfully applied to uncover unwanted user tracking and fingerprinting in e-commerce websites operated by a well-known Chinese company.
Federico Cerutti 0002, Daniele Barattieri di San Pietro, Francesco Gringoli, Gianfranco Lamperti
KES3
2022 Augmenting mmWave localization accuracy through sub-6 GHz on off-the-shelf devices
abstract
Millimeter-wave (mmWave) technology is an important element to increase the throughput and reduce latency of future wireless networks. At the same time, its high bandwidth and highly directional antennas allow for unprecedented accuracy in wireless sensing and localization applications. In this paper, we thoroughly analyze mmWave localization and find that it is either extremely accurate or has a very high error, since there is significant mmWave coverage via reflections and even through walls. As a consequence, sub-6 GHz technology can not only provide (coarse) localization where mmWave is not available, but is also critical to decide among multiple candidate antennas and APs for accurate mmWave localization.
Alejandro Blanco, Pablo Jiménez Mateo, Francesco Gringoli, Jörg Widmer
MobiSys3
2022 Attacks on Wireless Coexistence: Exploiting Cross-Technology Performance Features for Inter-Chip Privilege Escalation
abstract
Modern mobile devices feature multiple wireless technologies, such as Bluetooth, Wi-Fi, and LTE. Each of them is implemented within a separate wireless chip, sometimes packaged as combo chips. However, these chips share components and resources, such as the same antenna or wireless spectrum. Wireless coexistence interfaces enable them to schedule packets without collisions despite shared resources, essential to maximizing networking performance. Today's hardwired coexistence interfaces hinder clear security boundaries and separation between chips and chip components. This paper shows practical coexistence attacks on Broadcom, Cypress, and Silicon Labs chips deployed in billions of devices. For example, we demonstrate that a Bluetooth chip can directly extract network passwords and manipulate traffic on a Wi-Fi chip. Coexistence attacks enable a novel type of lateral privilege escalation across chip boundaries. We responsibly disclosed the vulnerabilities to the vendors. Yet, only partial fixes were released for existing hardware since wireless chips would need to be redesigned from the ground up to prevent the presented attacks on coexistence.
Jiska Classen, Francesco Gringoli, Michael Hermann, Matthias Hollick
SP2
2022 AntiSense: Standard-compliant CSI obfuscation against unauthorized Wi-Fi sensing
Marco Cominelli, Francesco Gringoli, Renato Lo Cigno
Comput. Commun.2
2022 On the properties of device-free multi-point CSI localization and its obfuscation
Marco Cominelli, Francesco Gringoli, Renato Lo Cigno
Comput. Commun.2
2022 Enhanced Self-Synchronized Reduced Media-Independent Interface for Robotic and Automotive Applications
abstract
The increasing pervasiveness of control systems used in robotic and automotive applications requires the installation of a growing number of sensors and actuators. In parallel to the downsizing of all the components, new techniques for tracing versatile printed circuit boards (PCBs) are emerging: a 3-D molded interconnection device, for example, creates the opportunity to reduce up to 75% of weight by combining a single-layer PCB with mechanical parts. Getting rid of unnecessary wires, hence, becomes indispensable, and new on-board interfaces with fewer pins must be designed. This article proposes a novel encoding scheme and the corresponding interface that reduces the number of wires between automotive Ethernet (100BASE-T1) MAC and PHY down to 2 and corrects up to 37.8% of single-bit errors. As this interface can be clocked at 33.33 MHz, it does not require differential transmitters, receivers, or any other special block, and for this reason, it can be easily implemented on a small-sized field-programmable gate array.
Alexey M. Romanov, Francesco Gringoli
IEEE Trans. Ind. Informatics2
2021 Accurate ubiquitous localization with off-the-shelf IEEE 802.11ac devices
abstract
WiFi location systems are remarkably accurate, with decimeter-level errors for recent CSI-based systems. However, such high accuracy is achieved under Line-of-Sight (LOS) conditions and with an access point (AP) density that is much higher than that typically found in current deployments that primarily target good coverage. In contrast, when many of the APs within range are in Non-Line-of-Sight (NLOS), the location accuracy degrades drastically. In this paper we present UbiLocate, a WiFi location system that copes well with common AP deployment densities and works ubiquitously, i.e., without excessive degradation under NLOS. UbiLocate demonstrates that meter-level median accuracy NLOS localization is possible through (i) an innovative angle estimator based on a Nelder-Mead search, (ii) a fine-grained time of flight ranging system with nanosecond resolution, and (iii) the accuracy improvements brought about by the increase in bandwidth and number of antennas of IEEE 802.11ac. In combination, they provide superior resolvability of multipath components, significantly improving location accuracy over prior work. We implement our location system on off-the-shelf 802.11ac devices and make the implementation, CSI-extraction tool and custom Fine Timing Measurement design publicly available to the research community. We carry out an extensive performance analysis of our system and show that it outperforms current state-of-the-art location systems by a factor of 2--3, both under LOS and NLOS.
Alejandro Blanco, Joan Palacios Beltran, Marco Cominelli, Francesco Gringoli, Jörg Widmer
MobiSys4
2021 IEEE 802.11 CSI randomization to preserve location privacy: An empirical evaluation in different scenarios
Marco Cominelli, Felix Kosterhon, Francesco Gringoli, Renato Lo Cigno, Arash Asadi
Comput. Networks3
2021 Low-delay high-rate operation of 802.11ac WLAN downlink: Nonlinear controller analysis & design
Francesco Gringoli, Douglas J. Leith
Comput. Networks1
2021 Quick & plenty: Achieving low delay & high rate in 802.11ac edge networks
Hamid Hassani, Francesco Gringoli, Douglas J. Leith
Comput. Networks2
2021 IMSI Catchers in the wild: A real world 4G/5G assessment
Ivan Palamà, Francesco Gringoli, Giuseppe Bianchi 0001, Nicola Blefari-Melazzi
Comput. Networks2
2021 A Precise Synchronization Method for Future Wireless TSN Networks
abstract
Time-sensitive networking (TSN) is the most promising time-deterministic wired communication approach for industrial applications. To extend TSN to “IEEE 802.11” wireless networks, two challenging problems must be solved: synchronization and scheduling. This article is focused on the first one. Even though a few solutions already meet the required synchronization accuracies, they are built on expensive hardware that is not suited for mass market products. While next Wi-Fi generation might support the required functionalities, this article proposes a novel method that makes high-precision wireless synchronization using commercial low-cost components possible. With the proposed solution, a standard deviation of synchronization error of less than 500 ns can be achieved for many use cases and system loads on both CPU and network. This performance is comparable to modern wired real-time field buses, which makes the developed method a significant contribution for the extension of the TSN protocol to the wireless domain.
Alexey M. Romanov, Francesco Gringoli, Axel Sikora
IEEE Trans. Ind. Informatics2
2020 Even Black Cats Cannot Stay Hidden in the Dark: Full-band De-anonymization of Bluetooth Classic Devices
abstract
Bluetooth Classic (BT) remains the de facto connectivity technology in car stereo systems, wireless headsets, laptops, and a plethora of wearables, especially for applications that require high data rates, such as audio streaming, voice calling, tethering, etc. Unlike in Bluetooth Low Energy (BLE), where address randomization is a feature available to manufactures, BT addresses are not randomized because they are largely believed to be immune to tracking attacks. We analyze the design of BT and devise a robust de-anonymization technique that hinges on the apparently benign information leaking from frame encoding, to infer a piconet's clock, hopping sequence, and ultimately the Upper Address Part (UAP) of the master device's physical address, which are never exchanged in clear. Used together with the Lower Address Part (LAP), which is present in all frames transmitted, this enables tracking of the piconet master, thereby debunking the privacy guarantees of BT. We validate this attack by developing the first Software-defined Radio (SDR) based sniffer that allows full BT spectrum analysis (79 MHz) and implements the proposed de-anonymization technique. We study the feasibility of privacy attacks with multiple testbeds, considering different numbers of devices, traffic regimes, and communication ranges. We demonstrate that it is possible to track BT devices up to 85 meters from the sniffer, and achieve more than 80% device identification accuracy within less than 1 second of sniffing and 100% detection within less than 4 seconds. Lastly, we study the identified privacy attack in the wild, capturing BT traffic at a road junction over 5 days, demonstrating that our system can re-identify hundreds of users and infer their commuting patterns.
Marco Cominelli, Francesco Gringoli, Paul Patras, Margus Lind, Guevara Noubir
SP2
2020 Frankenstein: Advanced Wireless Fuzzing to Exploit New Bluetooth Escalation Targets
Jan Ruge, Jiska Classen, Francesco Gringoli, Matthias Hollick
USENIX Security Symposium3
2020 Experimenting with open source tools to deploy a multi-service and multi-slice mobile network
Gines Garcia-Aviles, Marco Gramaglia, Pablo Serrano 0001, Francesco Gringoli, Sergio Fuente-Pascual, Ignacio Labrador Pavón
Comput. Commun.4
2019 Experimental QoE Evaluation of Multicast Video Delivery over IEEE 802.11aa WLANs
abstract
The IEEE 802.11aa amendment standardised the Group Addressed Transmission Service (GATS), which extends 802.11 WLANs with a novel set of MAC mechanisms to support an effective and efficient multicast video service. The key challenge with GATS is the selection of the best scheme and its configuration for a given network scenario, as the standard does not provide any guidelines nor any assessment of the performance of each mechanism. Although some previous studies have addressed this challenge, their evaluation is either via analysis or simulations under non-realistic assumptions, or based on Quality of Service (QoS) metrics instead of video quality metrics, which are required for a proper video performance assessment. In this paper, we deploy a mid-size real-life testbed and develop a thoughtful methodology to perform an extensive Quality of Experience (QoE) evaluation of GATS under a variety of scenarios. We analyse the performance of the novel schemes under ideal conditions, as well as under controlled and non-controlled interference, assessing their ability to provide an adequate QoE and quantifying the resources left for other type of traffic. Ours is the first thorough QoE evaluation of GATS in a real-life scenario, providing key insights on their performance, and can be used to derive configuration guidelines for the schemes.
Francesco Gringoli, Pablo Serrano 0001, Iñaki Ucar, Nicolò Facchi, Arturo Azcorra
IEEE Trans. Mob. Comput.1
2019 XTRA: Towards Portable Transport Layer Functions
abstract
XTRA (XFSM for Transport) aims at providing a first attempt towards a “code-once-port-everywhere” platform-agnostic programming abstraction tailored to the deployment of transport layer functions. XTRA's programming abstraction not only fits SW platforms, but is specifically designed to harness, with no re-coding effort, the offloading opportunities offered by CPU-less HW boards or smart NICs. We demonstrate the viability of XTRA with three completely different implementations of the underlying execution engine (HW proof-of-concept on a NetFPGA board, User-space SW over Linux' Open Data Plane, and NS3 emulator). Flexibility is shown via a number of example applications, ranging from a variety of congestion control algorithms, to a middlebox-type TCP proxy functionality, up to a customized “Timer-Based” (TB) TCP which leverages the native reliance of XTRA on timers, so as to produce a loss recovery operation which, despite being formalized only via a handful of code lines, performs almost comparable with the highly optimized Linux and FreeBSD implementations.
Giuseppe Bianchi 0001, Michael Welzl, Angelo Tulumello, Francesco Gringoli, Giacomo Belocchi, Marco Faltelli, Salvatore Pontarelli
IEEE Trans. Netw. Serv. Manag.4
2018 Shadow Wi-Fi: Teaching Smartphones to Transmit Raw Signals and to Extract Channel State Information to Implement Practical Covert Channels over Wi-Fi
abstract
Wi-Fi chips offer vast capabilities, which are not accessible through the manufacturers' official firmwares. Unleashing those capabilities can enable innovative applications on off-the-shelf devices. In this work, we demonstrate how to transmit raw IQ samples from a large buffer on Wi-Fi chips. We further show how to extract channel state information (CSI) on a per frame basis. As a proof-of-concept application, we build a covert channel on top of Wi-Fi to stealthily exchange information between two devices by prefiltering Wi-Fi frames prior to transmission. On the receiver side, the CSI is used to extract the embedded information. By means of experimentation, we show that regular Wi-Fi clients can still demodulate the underlying Wi-Fi frames. Our results show that covert channels on the physical layer are practical and run on off-the-shelf smartphones. By making available our raw signal transmitter, the CSI extractor, and the covert channel application to the research community, we ensure reproducibility and offer a platform for further innovative applications on Wi-Fi devices.
Matthias Schulz 0001, Jakob Link, Francesco Gringoli, Matthias Hollick
MobiSys3
2018 Maximising the utility of enterprise millimetre-wave networks
Nicolò Facchi, Francesco Gringoli, Paul Patras
Comput. Commun.2
2018 Position and Velocity Estimation of a Non-Cooperative Source From Asynchronous Packet Arrival Time Measurements
abstract
We tackle the problem of identifying the trajectory of a moving radio source from Time of Arrival (TOA) measurements collected by a set of cooperating receivers. The considered system is completely asynchronous: nodes clocks are affected by unknown time and frequency offsets, and no control is exerted over packet transmission times. In the proposed solution, the receiver clock offset terms are estimated from TOA measurements on packets originated by non-cooperative reference transmitters, possibly but not necessarily coincidental with reference receivers. Transmission time ambiguity is resolved by exploiting the redundancy associated to the reception of the same packet at multiple receivers. A distinguishing feature of the proposed solution is that it seeks to identify the parameters of the trajectory as a whole, rather than the individual points of transmission as done in traditional point-based approaches. This allows the effective exploitation of TOA measurements collected in lossy scenarios, where the generic packet is received by a smaller subset of the available receivers (at least two). For the problem at hand, we provide distinct estimators based on TOA and Time-Difference of Arrival (TDOA) and prove their equivalence. Numerical results from simulations and from a real WiFi testbed are provided to validate the effectiveness of the proposed method.
Fabio Ricciato, Savio Sciancalepore, Francesco Gringoli, Nicolò Facchi, Gennaro Boggia
IEEE Trans. Mob. Comput.3
2017 Demonstrating reactive smartphone-based jamming: demo
abstract
Reactive Wi-Fi jammers on off-the-shelf hardware that may facilitate mobile friendly jamming applications have only been shown recently. Until now, no demonstrators existed to reproduce the results obtained with these systems, hence, inhibiting re-use for further research or educational applications. In this work, we present an Android app that allows to create advanced jamming scenarios with four Nexus 5 smartphones. We use two of them to inject Wi-Fi frames with UDP payload, one to receive frames and analyze if they were corrupted and one that acts as a reactive jammer that selectively jams according to a UDP port. The user can choose between a simple reactive jammer and an acknowledging jammer. All jammers are implemented as Wi-Fi firmware patches by using the Nexmon framework. During the demonstration, users may adjust parameters of transmitted frames and observe the throughputs of correct and corrupted frames as bar graphs at the receiver. At the jamming node, users may design an arbitrary jamming signal in the frequency domain and adjust the jamming power, the target UDP port and the jammer type. The MAC addresses used during the experiments are hard coded to hinder users from simply abusing the app in other setups. Overall, the demonstration proofs that highly sophisticated Wi-Fi jammers can run on smartphones.
Matthias Schulz 0001, Efstathios Deligeorgopoulos, Matthias Hollick, Francesco Gringoli
WISEC4
2017 Massive reactive smartphone-based jamming using arbitrary waveforms and adaptive power control
abstract
It is not commonly known that off-the-shelf smartphones can be converted into versatile jammers. To understand how those jammers work and how well they perform, we implemented a jamming firmware for the Nexus 5 smartphone. The firmware runs on the real-time processor of the Wi-Fi chip and allows to reactively jam Wi-Fi networks in the 2.4 and 5 GHz bands using arbitrary waveforms stored in IQ sample buffers. This allows us to generate a pilot-tone jammer on off-the-shelf hardware. Besides a simple reactive jammer, we implemented a new acknowledging jammer that selectively jams only targeted data streams of a node while keeping other data streams of the same node flowing. To lower the increased power consumption of this jammer, we implemented an adaptive power control algorithm. We evaluated our implementations in friendly jamming scenarios to oppress non-compliant Wi-Fi transmissions and to protect otherwise vulnerable devices in industrial setups. Our results show that we can selectively hinder Wi-Fi transmissions in the vicinity of our jamming smartphone leading to an increased throughput for other nodes or no blockage of non-targeted streams on a jammed node. Consuming less than 300 mW when operating the reactive jammer allows mobile operation for more than 29 hours. Our implementation demonstrates that jamming communications was never that simple and available for every smartphone owner, while still allowing surgical jamming precision and energy efficiency. Nevertheless, it involves the danger of abuse by malicious attackers that may take over hundreds of devices to massively jam Wi-Fi networks in wide areas.
Matthias Schulz 0001, Francesco Gringoli, Daniel Steinmetzer, Michael Koch 0005, Matthias Hollick
WISEC2
2017 μNap: Practical micro-sleeps for 802.11 WLANs
Arturo Azcorra, Iñaki Ucar, Francesco Gringoli, Albert Banchs, Pablo Serrano 0001
Comput. Commun.3
2017 Imola: A decentralised learning-driven protocol for multi-hop White-Fi
Nicolò Facchi, Francesco Gringoli, David Malone, Paul Patras
Comput. Commun.2
2017 A High Efficiency MAC Protocol for WLANs: Providing Fairness in Dense Scenarios
abstract
Collisions are a main cause of throughput degradation in wireless local area networks. The current contention mechanism used in the IEEE 802.11 networks is called carrier sense multiple access with collision avoidance (CSMA/CA). It uses a binary exponential backoff technique to randomize each contender attempt of transmitting, effectively reducing the collision probability. Nevertheless, CSMA/CA relies on a random backoff that while effective and fully decentralized, in principle is unable to completely eliminate collisions, therefore degrading the network throughput as more contenders attempt to share the channel. To overcome these situations, carrier sense multiple access with enhanced collision avoidance (CSMA/ECA) is able to create a collision-free schedule in a fully decentralized manner using a deterministic backoff after successful transmissions. Hysteresis and fair share are two extensions of CSMA/ECA to support a large number of contenders in a collision-free schedule. CSMA/ECA offers better throughput than CSMA/CA and short-term throughput fairness. This paper describes CSMA/ECA and its extensions. In addition, it provides the first evaluation results of CSMA/ECA with non-saturated traffic, channel errors, and its performance when coexisting with CSMA/CA nodes. Furthermore, it describes the effects of imperfect clocks over CSMA/ECA and presents a mechanism to leverage the impact of channel errors and the addition/withdrawal of nodes over collision-free schedules. Finally, the experimental results on throughput and lost frames from a CSMA/ECA implementation using commercial hardware and open-source firmware are presented.
Luis Sanabria-Russo, Jaume Barceló, Boris Bellalta, Francesco Gringoli
IEEE/ACM Trans. Netw.4
2016 An application of IEEE 802.11ac to Smart Grid automation based on IEC 61850
abstract
Smart Grids deployment is growing around the world. The expansion of the existing Smart Grid network infrastructure in order to connect new electrical substations (or end-users) may be impaired by difficult cable deployment. For this reason, recently, wireless communication links have also been used. This paper deals with the deployment, and the first characterization, of an IEEE 802.11ac connection between IEC 61850 electrical automation devices. Some configurations of IEEE 802.11ac have been tested and compared with usual cable connection. The use of GPS based instrumentation combined with IEEE 1588 clock synchronization allows reducing measurement uncertainty and producing meaningful results. For instance, the IEC 61850 Transfer Time between GOOSE (Generic Object Oriented Substation Event) publisher and subscriber over an IEEE 802.11ac wireless link, loaded with 80Mbit/s of traffic, has an average value of 5.4 ms and a maximum value of 10 ms.
Stefano Rinaldi, Paolo Ferrari 0001, Alessandra Flammini, Francesco Gringoli, Matteo Loda, Nahla M. Ali
IECON4
2016 When is the right time to transmit in multi-hop White-Fi?
abstract
While Western societies are becoming increasingly connected, many developing regions lack basic Internet connectivity, primarily due to the high costs associated with infrastructure deployment and maintenance. Potential exists for the TV white-space (TVWS) wireless technology to bridge this digital divide, though efficient channel access mechanisms suited to multi-hop networks that operate in sub-gigahertz bands are yet to be developed. Using a small test bed, we demonstrate a prototype implementation of a medium access protocol that learns appropriate transmission opportunities in such settings, achieving pseudo-scheduled behaviour ex tempore and providing substantial gains over the de facto IEEE 802.11af protocol.
Nicolò Facchi, Francesco Gringoli, David Malone, Paul Patras
WoWMoM2
2016 Friendly Jamming on Access Points: Analysis and Real-World Measurements
abstract
Frequency jamming is known as an efficient attack tool to disrupt wireless communication. This efficiency can also be exploited for the benefit of a network—an idea often referred to as friendly jamming. A prominent application case is the blocking of unauthenticated or malicious communication, such as injection attacks. In this paper, we propose access points as a natural place to implement friendly jamming functionality. We analyze this proposal using simulations, introduce an implementation on customer-grade access points, and report measurement results from the first real-world study of friendly jamming in an IEEE 802.11 campus network. We discover a fundamental tradeoff between the effectiveness of friendly jamming and the orthogonal aspect of having minimal side-effects to the campus network’s traffic. In particular, we observed what we call the power amplification phenomenon. This effect aggravates the known hidden station problem when the number of jammers increases. We also find evidence that the collaboration between jammers can enable friendly jamming, which is both effective and minimally invasive.
Daniel S. Berger, Francesco Gringoli, Nicolò Facchi, Ivan Martinovic, Jens B. Schmitt
IEEE Trans. Wirel. Commun.2
2015 Fault-Tolerant Streaming Computation with BlockMon
abstract
As the amount of data being exchanged over the network increases, algorithms originally implemented for running on a single machine have been re-designed to work in a distributed manner, with a processing platform that splits tasks among machines and cores. Brand new frameworks have emerged for the analysis of unbound streams of data, aiming at processing data and retrieving information nearly real-time by using clusters of machines. Node failure and recovery are crucial issues related to distributed systems, especially when using commodity hardware and when continuously processing data coming real- time into the system. In this paper we present the performance of the distributed stream-processing platform Blockmon, with the novel fault-tolerant mechanism that we implement on top, and compare it against Spark, the state-of-the art in terms of fault-tolerant stream-processing platform. Our experimental results suggest that Blockmon performs around two times faster than Spark, with a twenty times reduced memory footprint, showing the feasibility of using Blockmon on popular energy- efficient architectures such as the ARM ones.
Eduardo Costa Alfaia, Maurizio Dusi, Luca Fiori, Francesco Gringoli, Saverio Niccolini
GLOBECOM4
2015 Making a case for flexible 802.11 architectures
abstract
In the past years, researchers have been advocating for flexible 802.11 devices that dynamically adapt to the varying network conditions, looking for efficient alternatives to the 802.11 standard MAC. In this work we demonstrate that this flexibility is readily available at the MAC level, and its operation can be tuned by re-programming the firmware inside the wireless chipsets that are built on relatively generic hardware modules. We show this by implementing the new amendment IEEE 802.11aa in legacy equipments by simply coding the frame exchange schemes at the firmware level. Nevertheless, we claim that the lack of flexibility in the way these modules interact results in a bottleneck that severely degrades performance. In our work, we prove this inefficiency of the 802.11 hardware architecture that hinders high throughput features, as in our case study of 802.11aa reliable multicast. To solve this problem, we provide new directions for the revision of the current hardware architecture and propose a new vision for the future design of wireless chipsets.
Pablo Salvador, Francesco Gringoli, Pablo Serrano 0001, Nicolò Facchi, Stefano Paris
ICC2
2015 Implementation and experimental evaluation of a Collision-Free MAC protocol for WLANs
abstract
Collisions are a main cause of throughput degradation in Wireless LANs. The current contention mechanism for these networks is based on a random backoff strategy to avoid collisions with other transmitters. Even though it can reduce the probability of collisions, the random backoff prevents users from achieving Collision-Free schedules, where the channel would be used more efficiently. Modifying the contention mechanism by waiting for a deterministic timer after successful transmissions, users would be able to construct a Collision-Free schedule among successful contenders. This work shows the experimental results of a Collision-Free MAC (CF-MAC) protocol for WLANs using commercial hardware and open firmware for wireless network cards which is able to support many users. Testbed results show that the proposed CF-MAC protocol leads to a better distribution of the available bandwidth among users, higher throughput and lower losses than the unmodified WLANs clients using a legacy firmware.
Luis Sanabria-Russo, Francesco Gringoli, Jaume Barceló, Boris Bellalta
ICC2
2015 IEC 61850 for micro grid automation over heterogeneous network: Requirements and real case deployment
abstract
Micro grids are localized groups of electricity generators, energy storage systems, and loads with the possibility of operating both connected and disconnected from the distribution grid. This paper is focused on the automation of micro grids using heterogeneous communication networks; the new approach takes into account the need of reusing existing wired and wireless technologies and assets when planning and deploying new renewable power sources or energy storage systems into traditional (old) grids. The proposed system uses the IEC 61850 in order to guarantee the interoperability with the distribution grid. In addition, the possible synergies with industrial and building automation have been investigated using well-known automation protocols (such as PROFINET and Modbus TCP). The proposed system has been installed and tested in a real micro grid inside the campus of the University of Brescia. Design description, deployment report and result analysis are given, showing that the performance of the real system (i.e. reaction time less than 30 ms at grid level network over heterogeneous links) is in line with the application requirements.
Stefano Rinaldi, Paolo Ferrari 0001, Nahla M. Ali, Francesco Gringoli
INDIN4
2015 Emitter localisation from reception timestamps in asynchronous networks
Nicolò Facchi, Francesco Gringoli, Fabio Ricciato, Andrea Toma
Comput. Networks2
2014 Reactive logic in software-defined networking: Measuring flow-table requirements
abstract
The capability of a network is ultimately bounded by limitations of the devices that compose it. In this paper we argue that Software-Defined Networking (SDN) can increase the importance of certain limitations, such as the size and the flexibility of switches forwarding tables. In particular we focus on the implications of reactive installation of flow entries in the switch fabric: by analyzing traffic traces captured in different scenarios we show the existence of a trade-off between the size of the flow table and the rate of dynamic installation of a missing or expired rule. We leverage on this finding to further show that reactive flow (re-)configuration is a promising mechanism for improving the traffic engineering flexibility with no additional requirement in terms of flow table size. We examine links located in various parts of the network and we consider different flow definitions to evaluate the feasibility of using SDN controllers in both access and core network scenarios.
Maurizio Dusi, Roberto Bifulco, Francesco Gringoli, Fabian Schneider 0001
IWCMC3
2014 Gaining insight on friendly jamming in a real-world IEEE 802.11 network
abstract
Frequency jamming is the fiercest attack tool to disrupt wireless communication and its malicious aspects have received much attention in the literature. Yet, several recent works propose to turn the table and employ so-called friendly jamming for the benefit of a wireless network. For example, recently proposed friendly jamming applications include hiding communication channels, injection attack defense, and access control. This work investigates the practical viability of friendly jamming by applying it in a real-world network. To that end, we implemented a reactive and frame-selective jammer on a consumer grade IEEE 802.11 access point. Equipped with this, we conducted a three weeks real-world study on the jammer's performance and side-effects on legitimate traffic (the cost of jamming) in a university office environment. Our results provide detailed insights on crucial factors governing the trade-off between the effectiveness of friendly jamming (we evaluated up to 13 jammers) and its cost. In particular, we observed -- what we call the power amplification phenomenon -- an effect that aggravates the known hidden station problem when the number of jammers increases. However, we also find evidence that this effect can be alleviated by collaboration between jammers, which again enables effective and minimally invasive friendly jamming.
Daniel S. Berger, Francesco Gringoli, Nicolò Facchi, Ivan Martinovic, Jens B. Schmitt
WISEC2
2014 VoIPiggy: Analysis and Implementation of a Mechanism to Boost Capacity in IEEE 802.11 WLANs Carrying VoIP Traffic
abstract
Handling voice traffic in existing WLANs is extremely inefficient, due to the large overhead of the protocol operation as well as the time spent in contention. In this paper, we propose a simple scheme (VoIPiggy) to improve the efficiency of WLANs with voice traffic. The key idea of the mechanism is to piggyback voice frames onto the MAC layer acknowledgments, which reduces both the frame overhead and the time wasted in contention. To quantify the gains of our proposal, we first study its performance by means of a capacity and delay analysis of a WLAN operating under the VoIPiggy mechanism. Then, we present an implementation of the mechanism using commercial off-the-shelf devices, which involves programming at the driver and firmware levels. The performance of the proposed scheme is evaluated in a large-scale testbed consisting of 30 devices. Our extensive measurements, which are comprised of different network conditions in terms of number of active nodes, traffic load and transmission rates, confirm that the experimental results match the analytical ones, and show a dramatic performance improvement for both “voice only” and “voice and data” scenarios.
Pablo Salvador, Vincenzo Mancuso, Pablo Serrano 0001, Francesco Gringoli, Albert Banchs
IEEE Trans. Mob. Comput.4
2013 Scaling Out the Performance of Service Monitoring Applications with BlockMon
Davide Simoncelli, Maurizio Dusi, Francesco Gringoli, Saverio Niccolini
PAM3
2013 An Innovative Rate Adaptation Algorithm for Multicast Transmissions in Wireless LANs
abstract
Rate adaptation represents a key functionality of the 802.11 MAC protocol for performance enhancement. Several solutions have been proposed for improving the transmission rate of unicast communications using frame receptions/losses, BER (Bit Error Rate) and SNR (Signal to Noise Ratio) measurements. Nevertheless, rate adaptation for multicast transmissions represents a more challenging tasks due to the complexity of estimating the reception correlation of wireless links. This paper presents a novel scheme for selecting the best transmission rate for multicast communications using the packet reception correlation of the links established among the nodes of the multicast group with the access point. The proposed algorithm has been evaluated on a real-life testbed using commercial wireless cards. The results show that our solution accurately estimates the reception correlation of wireless links, thus considerably increasing the performance of multicast transmissions up to 3x and 5x in terms of throughput and delay, respectively.
Stefano Paris, Nicolò Facchi, Francesco Gringoli, Antonio Capone
VTC Spring3
2012 MAClets: active MAC protocols over hard-coded devices
abstract
We introduce MAClets, software programs uploaded and executed on-demand over wireless cards, and devised to change the card's real-time medium access control operation. MAClets permit seamless reconfiguration of the MAC stack, so as to adapt it to mutated context and spectrum conditions and perform tailored performance optimizations hardly accountable by an once-for-all protocol stack design. Following traditional active networking principles, MAClets can be directly conveyed within data packets and executed on hard-coded devices acting as virtual MAC machines. Indeed, rather than executing a pre-defined protocol, we envision a new architecture for wireless cards based on a protocol interpreter (enabling code portability) and a powerful API. Experiments involving the distribution of MAClets within data packets, and their execution over commodity WLAN cards, show the flexibility and viability of the proposed concept.
Giuseppe Bianchi 0001, Pierluigi Gallo, Domenico Garlisi, Fabrizio Giuliano, Francesco Gringoli, Ilenia Tinnirello
CoNEXT5
2012 MTCLASS: Traffic classification on high-speed links with commodity hardware
abstract
Statistical traffic classification on high-speed, multi-Gb/s links has up to now been possible only with specialized, often proprietary, always quite costly hardware. In this paper we present MTCLASS, a new, multi-threaded, modular Internet statistical traffic analysis engine capable of running in real-time on commodity hardware processing multi-Gb/s traffic aggregates. Experimental results show that our engine, running on a low cost dual Xeon PC with a total of 12 cores at 2.6GHz can classify in real time using a Support Vector Machine (SVM) algorithm aggregates of up to 1.14 million packets per second, corresponding in the traces we used to a bit rate of 5.3 Gbps. We make MTCLASS' source code available to the community under an open source license.
Francesco Gringoli, Alice Este, Luca Salgarelli
ICC1
2012 Wire-speed statistical classification of network traffic on commodity hardware
abstract
In this paper we present a software-based traffic classification engine running on commodity multi-core hardware, able to process in real-time aggregates of up to 14.2 Mpps over a single 10 Gbps interface -- i.e., the maximum possible packet rate over a 10 Gbps Ethernet links given the minimum frame size of 64 Bytes.
Pedro M. Santiago del Río, Dario Rossi 0001, Francesco Gringoli, Lorenzo Nava, Luca Salgarelli, Javier Aracil 0001
Internet Measurement Conference3
2012 VoIPiggy: Implementation and evaluation of a mechanism to boost voice capacity in 802.11WLANs
abstract
Supporting voice traffic in existing WLANs results extremely inefficient, given the large overheads of the protocol operation and the need to prioritize this traffic over, e.g., bulky transfers. In this paper we propose a simple scheme to improve the efficiency of WLANs when voice traffic is present. The mechanism is based on piggybacking voice frames over the acknowledgments, which reduces both frame overheads and time spent in contentions. We evaluate its performance in a large-scale testbed consisting on 33 commercial off-the-shelf devices. The experimental results show dramatic performance improvements in both voice-only and mixed voice-and-data scenarios.
Pablo Salvador, Francesco Gringoli, Vincenzo Mancuso, Pablo Serrano 0001, Andrea Mannocci, Albert Banchs
INFOCOM2
2012 Wireless MAC processors: Programming MAC protocols on commodity Hardware
abstract
Programmable wireless platforms aim at responding to the quest for wireless access flexibility and adaptability. This paper introduces the notion of wireless MAC processors. Instead of implementing a specific MAC protocol stack, Wireless MAC processors do support a set of Medium Access Control “commands” which can be run-time composed (programmed) through software-defined state machines, thus providing the desired MAC protocol operation. We clearly distinguish from related work in this area as, unlike other works which rely on dedicated DSPs or programmable hardware platforms, we experimentally prove the feasibility of the wireless MAC processor concept over ultra-cheap commodity WLAN hardware cards. Specifically, we reflash the firmware of the commercial Broadcom AirForce54G off-the-shelf chipset, replacing its 802.11 WLAN MAC protocol implementation with our proposed extended state machine execution engine. We prove the flexibility of the proposed approach through three use-case implementation examples.
Ilenia Tinnirello, Giuseppe Bianchi 0001, Pierluigi Gallo, Domenico Garlisi, Francesco Giuliano, Francesco Gringoli
INFOCOM6
2012 MTCLASS: Enabling statistical traffic classification of multi-gigabit aggregates on inexpensive hardware
abstract
Traffic classification on high-speed, multi-Gb/s links has up to now been demonstrated on complex Linux setups using multi-queue Ethernet cards, thread affinity, zero-copy buffers and specialized socket types. Although these approaches do work in principle, the complexity of the involved networking system ends up consuming almost all computational resources to pass packets between kernel and user space, leaving no CPU time to run any actual statistical classification algorithm. In this paper we present a new approach that harnesses a lightweight and inexpensive NetFPGA/1G to group incoming packets in jumboframes so that almost all CPU cycles of a commodity PC running a stock Linux kernel can be dedicated to run a statistical traffic classification algorithm. Experimental results show that our inexpensive setup can execute Support Vector Machine traffic classification in real time to aggregates of up to 7.44M pps. We make MTCLASS' source code available to the community under an open source license.
Francesco Gringoli, Lorenzo Nava, Alice Este, Luca Salgarelli
IWCMC1
2011 Taking a Peek at Bandwidth Usage on Encrypted Links
abstract
In this paper we describe a practical yet effective technique to monitor the amount of bytes that several classes of protocols, such as peer-to-peer, e-mail, etc., transmit over encrypted virtual links, such as IPSec tunnels. The experiments described in this paper demonstrate that our regression-tree-based bandwidth estimator is effective enough to create usage models inherently robust to changes in path, number of users and type of protocols multiplexed over the encrypted link. In other words, our experimental results indicate that training data obtained from a test IPSec tunnel can be successfully used to monitor bandwidth usage on other encrypted tunnels where only the ciphertext is available.
Maurizio Dusi, Alice Este, Francesco Gringoli, Luca Salgarelli
ICC3
2011 On-line SVM traffic classification
abstract
A wide range of traffic classification approaches has been proposed in the last few years by the scientific community. However, the development of complete classification architectures that work directly in real-time on high capacity links is limited. In this paper we present the implementation of a machine-learning technique (SVM), one of the most accurate but most computationally expensive mechanisms, on the CoMo project infrastructure. We show the computational time required to process different traffic traces and the optimization steps we adopted to improve the performance of the system and achieve real-time classification on high-speed links.
Alice Este, Francesco Gringoli, Luca Salgarelli
IWCMC2
2011 PP2db: A Privacy-Preserving, P2P-Based Scalable Storage System for Mobile Networks
Manuel Crotti, Diego Ferri, Francesco Gringoli, Manuel Peli, Luca Salgarelli
SecureComm3
2011 Quantifying the accuracy of the ground truth associated with Internet traffic traces
Maurizio Dusi, Francesco Gringoli, Luca Salgarelli
Comput. Networks2
2010 Comparing P2PTV Traffic Classifiers
abstract
Abstract—Peer-to-Peer IP Television (P2PTV) applications represent one of the fastest growing application classes on the Internet, both in terms of their popularity and in terms of the amount of traffic they generate. While network operators require monitoring tools that can effectively analyze the traffic produced by these systems, few techniques have been tested on these mostly closed-source, proprietary applications. In this paper we examine the properties of three traffic classifiers applied to the problem of identifying P2PTV traffic. We report on extensive experiments conducted on traffic traces with reliable ground truth information, highlighting the benefits and shortcomings of each approach. The results show that not only their performance in terms of accuracy can vary significantly, but also that their usability features suggest different effective aspects that can be integrated. I.
Niccolo Cascarano, Fulvio Risso, Alice Este, Francesco Gringoli, Luca Salgarelli, Alessandro Finamore, Marco Mellia
ICC4
2010 Coarse Classification of Internet Traffic Aggregates
abstract
This paper introduces a new statistical classification technique that allows a coarse but effective estimation of the amount of bytes that different classes of protocols, such as Peer-to-Peer, web, e-mail, etc., carry over a given communication link. The technique works by observing only IP-level information and without requiring the reconstruction of transport-layer sessions, making it amenable to the monitoring of both clear-text and encrypted traffic aggregates. Results of practical experiments demonstrate that our coarse classifier can estimate with reasonable accuracy the amount of bytes carried on a communication link by a given traffic class both cumulatively and punctually, i.e., over both long and short time periods. Furthermore, preliminary results demonstrate the effectiveness of the technique in monitoring encrypted links, albeit under restrictive assumptions.
Maurizio Dusi, Alice Este, Francesco Gringoli, Luca Salgarelli
ICC3
2010 Optimizing statistical classifiers of network traffic
abstract
Supervised statistical approaches for the classification of network traffic are quickly moving from research laboratories to advanced prototypes, which in turn will become actual products in the next few years. While the research on the classification algorithms themselves has made quite significant progress in the recent past, few papers have examined the problem of determining the optimum working parameters for statistical classifiers in a straightforward and foolproof way. Without such optimization, it becomes very difficult to put into practice any classification algorithm for network traffic, no matter how advanced it may be. In this paper we present a simple but effective procedure for the optimization of the working parameters of a statistical network traffic classifier. We put the optimization procedure into practice, and examine its effects when the classifier is run in very different scenarios, ranging from medium and large local area networks to Internet backbone links. Experimental results show not only that an automatic optimization procedure like the one presented in this paper is necessary for the classifier to work at its best, but they also shed some light on some of the properties of the classification algorithm that deserve further study.
Manuel Crotti, Francesco Gringoli, Luca Salgarelli
IWCMC2
2010 Maranello: Practical Partial Packet Recovery for 802.11
Bo Han 0001, Aaron Schulman, Francesco Gringoli, Neil Spring, Bobby Bhattacharjee, Lorenzo Nava, Lusheng Ji, Seungjoon Lee, Robert R. Miller
NSDI3
2009 An Experimental Evaluation of the Computational Cost of a DPI Traffic Classifier
abstract
A common belief in the scientific community is that traffic classifiers based on deep packet inspection (DPI) are far more expensive in terms of computational complexity compared to statistical classifiers. In this paper we counter this notion by defining accurate models for a deep packet inspection classifier and a statistical one based on support vector machines, and by evaluating their actual processing costs through experimental analysis. The results suggest that, contrary to the common belief, a DPI classifier and an SVM-based one can have comparable computational costs. Although much work is left to prove that our results apply in more general cases, this preliminary analysis is a first indication of how DPI classifiers might not be as computationally complex, compared to other approaches, as we previously thought.
Niccolo Cascarano, Alice Este, Francesco Gringoli, Fulvio Risso, Luca Salgarelli
GLOBECOM3
2009 Impact of Asymmetric Routing on Statistical Traffic Classification
abstract
Statistical traffic classification techniques are often developed under the assumption that monitoring devices can observe the two half-flows composing each traffic session. However, the practice of asymmetric routing is rapidly moving from the Internet core to its edge. Forecasts [1] predict that in a few years even the last legs of Internet connectivity will experience some form of this practice. In this paper we study the effects that asymmetric routing can have on statistical traffic classifiers. We do so by comparing the capability of unidirectional classifiers with the ones of bidirectional classifiers in extracting information from the features of half-flows. Numerical results obtained by processing three heterogeneous traffic traces not only confirm the obvious assumption that bidirectional classifiers work better than unidirectional ones, but also shed some light on a few interesting facts. First, that the improvement introduced by bidirectional classifiers is not very significant in terms of increased true positives, while it is substantial in terms of decreased false positives. Furthermore, some protocols seem to exhibit, at least in some environments, the tendency to carry more information (relevant to traffic classification) in one direction than in the other.
Manuel Crotti, Francesco Gringoli, Luca Salgarelli
GLOBECOM2
2009 Using GMM and SVM-Based Techniques for the Classification of SSH-Encrypted Traffic
abstract
When employing cryptographic tunnels such as the ones provided by Secure Shell (SSH) to protect their privacy on the Internet, users expect two forms of protection. First, they aim at preserving the privacy of their data. Second, they expect that their behavior, e.g., the type of applications they use, also remains private. In this paper we report on two statistical traffic analysis techniques that can be used to break the second type of protection when applied to SSH tunnels, at least under some restricting hypothesis. Experimental results show how current implementations of SSH can be susceptible to this type of analysis, and illustrate the effectiveness of our two classifiers both in terms of their capabilities in analyzing encrypted traffic and in terms of their relative computational complexity.
Maurizio Dusi, Alice Este, Francesco Gringoli, Luca Salgarelli
ICC3
2009 Tunnel Hunter: Detecting application-layer tunnels with statistical fingerprinting
Maurizio Dusi, Manuel Crotti, Francesco Gringoli, Luca Salgarelli
Comput. Networks3
2009 Support Vector Machines for TCP traffic classification
Alice Este, Francesco Gringoli, Luca Salgarelli
Comput. Networks2
2008 A Model for the Study of Privacy Issues in Secure Shell Connections
abstract
The secure shell protocol strives to protect the privacy of its users in several ways. On one hand, the strong encryption and authentication algorithms that it adopts provide guarantees that the data exchanged between two SSH endpoints remain private to third parties. On the other hand, the type of traffic that each SSH channel transports, such as e-mail, remote shell activity, etc., is also supposed to be hidden from any observer that does not possess the necessary keys. This paper introduces a simple but accurate model of the SSH channel which can be used to study the level of privacy that SSH-protected traffic can achieve with respect to the users' activities. We think that the model can facilitate several types of projects. For example, network managers can detect traffic anomalies hidden by SSH connections more easily by relying on the output of our model. Another example, which we present in this paper, is the use of this model to derive accurate fingerprints of the type of applications run through an SSH channel by simply starting from the statistics of captured clear-text traffic. Such fingerprints can then be used to detect what type of activity, i.e., what type of traffic, is going on within an SSH channel, thereby breaking user privacy.
Maurizio Dusi, Francesco Gringoli, Luca Salgarelli
IAS2
2008 Detection of Encrypted Tunnels Across Network Boundaries
abstract
The use of covert application-layer tunnels to bypass security gateways has become quite popular in recent years. By encapsulating blocked or controlled protocols such as peer- to-peer, chat and e-mail into others allowed by the security policies, such as HTTP, SSH or even DNS, both legitimate and malicious users can effectively neutralize many security restrictions enforced at the network edge. Traditional firewalling techniques, based on Application Layer Gateways and even pattern-matching mechanisms are becoming practically useless as tunneling tools grow more sophisticated. In this paper we propose an effective solution to this problem based on a statistical traffic classification technique. Our mechanism relies on the creation of a statistical fingerprint of legitimate usage of a given protocol, such as regular remote interactive logins or secure copying activities. Such fingerprint can then be used to detect with high accuracy non-legitimate sessions, i.e., sessions that tunnel other protocols. Results from experiments conducted on a live network suggest that the technique can be very effective, even when the application layer protocol used as a tunnel is encrypted, such as in the case of SSH.
Maurizio Dusi, Manuel Crotti, Francesco Gringoli, Luca Salgarelli
ICC3
2008 A Preliminary Look at the Privacy of SSH Tunnels
abstract
Secure Shell (SSH) tunnels are commonly used to provide two types of privacy protection to clear-text application protocols. First and foremost, they aim at protecting the privacy of the data being exchanged between two peers, such as passwords, details of monetary transactions and so on. Second, they are supposed to protect the privacy of the behavior of end-users, by preventing an unauthorized observer from detecting which application protocol is being transported by an SSH tunnel. In this paper we introduce a GMM-based (Gaussian Mixture Model) technique that, under a set of reasonable assumptions, can be used to identify which application is being tunneled inside an SSH session by simply observing the stream of encrypted packets. This technique can therefore break the presumption of privacy in its second incarnation as described above. Although still preliminary, experimental results show that the technique can be quite effective, and that the standard bodies might need to take this approach under consideration when designing new obfuscation techniques for SSH.
Maurizio Dusi, Francesco Gringoli, Luca Salgarelli
ICCCN2
2008 IP Traffic Classification for QoS Guarantees: The Independence of Packets
abstract
The classification of IP flows according to the application that generated them has become a popular research subject in the last few years. Several recent papers based their studies on the analysis of features of flows such as the packet size and inter-arrival time, which are then used as input to classification techniques derived from various scientific areas such as pattern recognition. In this paper we analyze the impact on flow classification of a hypothesis that is often overlooked, i.e., the tenet that the features of consecutive packets of a given IP flow can be considered statistically independent. We compare two approaches, one based on a technique that considers consecutive packets statistically independent, and one that relies on the opposite assumption. These techniques are then applied to three different sets of traffic traces. Experimental results show that while assuming the independence of consecutive packets has relatively few effects on true positives, it can have a significant negative impact on the false positive and true negative rates, therefore lowering the precision of the classification process.
Maurizio Dusi, Francesco Gringoli, Luca Salgarelli
ICCCN2
2007 Detecting HTTP Tunnels with Statistical Mechanisms
abstract
Application level gateways and firewalls are commonly used to enforce security policies at network boundaries, especially in large-sized business networks. However, several mechanisms can be used to circumvent these policies and bypass the whole security infrastructure: for example, tunneling an (otherwise blocked) application layer protocol into another one allowed by the policy, such as HTTP. In this paper we propose the application of a statistically-based traffic classification technique to solve this problem. By the analysis of inter-arrival time, size and order of the packets crossing a gateway, we show that it is possible to detect with high accuracy whether an observed flow is carrying a legitimate HTTP session, or the flow is being used to tunnel another protocol. This paper describes how this technique can be used effectively to enhance application level gateways and firewalls, helping to better apply network security policies.
Manuel Crotti, Maurizio Dusi, Francesco Gringoli, Luca Salgarelli
ICC3
2006 A statistical approach to IP-level classification of network traffic
abstract
Correct classification of traffic flows according to the application layer protocols that generated them is essential for most network-management, resource allocation and intrusion detection systems in TCP/IP networks. With the ever increasing number of network protocols and services running on non-standard TCP ports, the classification methods based on the analysis of the transport layer header are rapidly becoming ineffective. On the other hand, mechanisms based on full payload analysis are too computationally demanding to be run on most high-bandwidth links. Here we present a novel classification technique based on the statistical analysis of network traffic performed at the IP-level. The key idea behind our approach is to build a set of protocol fingerprints that we believe summarize, in a compact and efficient way, the main IP-level statistical properties of application layer protocols. By means of a simple, lightweight algorithm based on the notion of anomaly scores, also presented in this paper, an unknown flow can be compared against known protocol fingerprints, detecting the application that generated the flow. Our methodology is completely based on IP-level analysis: no payload analysis or port analysis is required for the classification of an unknown flow. Besides introducing our approach, we describe preliminary experimental results that show how this technique is effective in correctly classifying network traffic in a real network environment.
Manuel Crotti, Francesco Gringoli, Paolo Pelosato, Luca Salgarelli
ICC2