VLDB 2026 Research / reviewers in the wild / expert
Ronaldo A. Ferreira
dblp:63/3999 · also Ronaldo Alves Ferreira
· DBLP profile ↗
27ranked-venue papers
9as first author
13since 2021 · last 2025
0000-0002-9144-7187ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 12 · 3 first-author · 7 since 2021Systems, architecture and hardware · 9 · 6 first-author · 1 since 2021Security and privacy · 1 · 1 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Scaling Stateful Network Services on Multicore ArchitecturesabstractThis thesis investigates the effective scheduling of TCP stacks alongside applications on multicore architectures, focusing on the trade-offs in allocating workers for both TCP and application processing. It explores the interplay between stateful network protocols with strong guarantees and the challenges of scheduling such protocols alongside multicore applications. To allow fair comparisons, we design and implement Demieagle, a benchmark framework that allows the execution of “apples-to-apples” experiments to uncover the trade-offs of different multicore scheduling policies and architectures. We also address the complexity of scaling stateful network functions, which require per-packet state updates. During a scaling operation, workers need to synchronize access to a shared state to avoid race conditions and to guarantee that network functions process packets in arrival order. Unfortunately, the classic approach to control concurrent access to a shared state with locks does not scale to today's throughput and latency requirements. To address these challenges, we design, implement, and evaluate Dyssect, a system that enables dynamic scaling of stateful network functions by disaggregating their states. Dyssect's state disaggregation allows the offloading of stateful network functions to programmable NICs and makes it easier to explore hardware-software trade-offs that better suit specific network functions and traffic loads. Our experimental evaluation shows that Dyssect reduces tail latency up to 32.04% and increases throughput up to 19.36% compared to state-of-the-art competing solutions. Fabrício B. Carvalho, Ronaldo A. Ferreira |
NOMS | 2 |
| 2025 | Distributed Graph Neural Networks in Programmable Data PlanesabstractThe ability to redefine the data plane behavior with programmable network devices provides a plethora of novel possibilities for in-network computing. One of these possibilities is embedding Artificial Intelligence (AI) and Machine Learning (ML) techniques directly in the data plane. Motivations include reducing decision latency and closing the control loop-i.e., performing measurements, learning, decisions, and actions directly in the data plane. However, running entire AI/ML algorithms in a single device might be infeasible due to memory and computing constraints. This work addresses the research challenges of running a Graph Neural Network (GNN) in a set of devices of a programmable data plane. Our hypothesis is that by distributing the GNN processing across the devices, the GNN uses instantaneous snapshots of the global network state and can act more quickly. As a proof of concept, we trained and evaluated a distributed GNN to perform explicit congestion notifications based on Data Center Transmission Control Protocol (DCTCP). We verified the feasibility of GNN classification in the data plane through simulations and both software and hardware switch experiments with bmv2 and Intel Tofino. Ivan Peter Lamb, Pedro Arthur Pinheiro Rosa Duarte, Jonatas Adilson Marques, Marcelo Caggiani Luizelli, Luciano Paschoal Gaspary, Anderson Tavares, Ronaldo A. Ferreira, Ítalo S. Cunha, José Rodrigo Azambuja, Weverton Luis da Costa Cordeiro |
NOMS | 7 |
| 2025 | Automatic Inference of BGP Community SemanticsabstractThe Border Gateway Protocol (BGP) enables communication between Autonomous Systems (ASes) and is the de facto interdomain routing protocol of the Internet. BGP offers significant flexibility for traffic engineering through BGP communities, which are operator-defined tags that convey information or requests in route announcements between ASes. Unfortunately, the absence of standardized semantics or centralized repositories for BGP communities complicates and limits their use, hindering the effective management of interdomain routing. This thesis develops techniques to infer BGP community semantics using public BGP data from routing collectors, overcoming the lack of documentation and providing datasets that can be automatically updated. We first propose a set of techniques to infer location communities, which are communities related to entities or locations traversed by a route. We apply our techniques to billions of routing records from public BGP collectors and show that they produce high precision (ranging from 86% to 93%) and recall (ranging from 72% to 81%). We also design and evaluate algorithms to automatically uncover BGP action communities and ASes that violate standard practices, revealing undocumented relationships between them (e.g., sibling relationships). Our experimental evaluation uncovers previously unknown AS relationships and shows that our algorithm to identify action communities achieves average precision and recall of 92.5% and 86.5%, respectively. Brivaldo Alves da Silva, Ítalo S. Cunha, Ronaldo A. Ferreira |
NOMS | 3 |
| 2025 | Scaling SCIERA: A Journey Through the Deployment of a Next-generation NetworkabstractThe SCION Next-Generation Network (NGN) architecture has expanded steadily since 2017, with today 20+ ISPs offering SCION connectivity. In production, IP-to-SCION-to-IP translation by SCION-IP-Gateways (SIGs) is used, such that applications are unaware of the NGN communication. To accelerate innovation and deployments, our aim is to increase the number of native SCION use cases, where the application is fully SCION-aware and optimizes communication across all path choices offered by the network. We set out to achieve two core objectives: (1) facilitating simple native connectivity for applications, and (2) enhancing the scalability of SCION deployment at academic sites. François Wirz, Marten Gartner, Jelte van Bommel, Elham Ehsani Moghadam, Grace H. Cimaszewski, Anxiao He, Yizhe Zhang 0006, Henry Birge-Lee, Felix Kottmann, Cyrill Krähenbühl, Jonghoon Kwon, Kyveli Mavromati, Liang Wang 0054, Daniel Bertolo, Marco Canini, Buseung Cho, Ronaldo A. Ferreira, Simon Peter Green, David Hausheer, Junbeom Hur, Xiaohua Jia, Heejo Lee, Prateek Mittal, Omo Oaiya, Chanjin Park, Adrian Perrig, Jerry Sobieski, Yixin Sun 0004, Cong Wang 0001, Klaas Wierenga |
SIGCOMM | 17 |
| 2025 | Establishing Trust for Using Natural Language for Intent-Based NetworkingabstractTodays enterprise networks wrestle with accommodating an ever-growing number of devices of different types, supporting increasingly demanding applications and ever more complex services, and protecting their users from sophisticated and disrupting cyber threats. In response, a proposed architectural approach for improving network management, referred to as Intent-Based Networking (IBN), has attracted significant attention. It is built on the premise that network operators specify network policies in natural language and the network correctly translates these spoken intents (e.g., policies) into proper device-specific configurations that are then deployed across the network to reliably act on the operators expressed intents. Unfortunately, IBN has not yet fully delivered on its promise of automated, fast, and reliable policy deployment, mainly due to the significant challenges that the reliance on methods from Natural Language Processing (NLP) or more recent techniques from Machine Learning (ML) and Artificial Intelligence (AI) poses for unambiguously and accurately translating the myriad of intents that operators can express in natural language into “trustworthy” device configurations. This paper uses LUMI, a recently designed end-to-end prototype of a system that allows operators “to manage their network by talking to the network”, as an illustrative case study. In particular, we use it to elaborate on the different functionalities such systems should have to realize IBNs vision of automating the fast deployment of policies. At the same time, we leverage LUMI to highlight the extra efforts that are required to ensure that the deployed policies can be entrusted to accurately express and execute the operators original intents. Arthur Selle Jacobs, Ricardo J. Pfitscher, Rafael Hengen Ribeiro, Lisandro Z. Granville, Ronaldo A. Ferreira, Walter Willinger, Sanjay G. Rao |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2024 | State Disaggregation for Dynamic Scaling of Network FunctionsabstractNetwork Function Virtualization promises better utilization of computational resources by dynamically scaling resources on demand. However, most network functions (NFs) are stateful and require state updates on a per-packet basis. During a scaling operation, cores need to synchronize access to a shared state to avoid race conditions and to guarantee that NFs process packets in arrival order. Unfortunately, the classic approach to control concurrent access to a shared state with locks does not scale to today’s throughput and latency requirements. Moreover, network traffic is highly skewed, leading to load imbalances in systems that use only sharding to partition the NF states. To address these challenges, we present Dyssect, a system that enables dynamic scaling of stateful NFs by disaggregating the states of network functions. By carefully coordinating actions between cores and a central controller, Dyssect migrates shards and flows between cores for load balancing or traffic prioritization without resorting to locks or reordering packets. Also, Dyssect’s state disaggregation allows the offloading of stateful network functions to programmable NICs and makes it easier for exploring hardware-software tradeoffs that better suit specific service chains and traffic loads. Our experimental evaluation shows that Dyssect reduces tail latency up to 32.04% and increases throughput up to 19.36% when compared to state-of-the-art competing solutions. Fabrício B. Carvalho, Ronaldo A. Ferreira, Ítalo S. Cunha, Marcos A. M. Vieira, Murali Krishna Ramanathan |
IEEE/ACM Trans. Netw. | 2 |
| 2023 | Enabling Self-Driving Networks with Machine LearningabstractThis work aims to enable self-driving networks by tackling the lack of trust that network operators have in Machine Learning (ML) models. We assess and scrutinize the decision-making process of ML-based classifiers used to compose a self-driving network. First, we investigate and evaluate the accuracy and credibility of classifications made by ML models used to process high-level management intents. We propose a novel conversational interface (LUMI) that allows operators to use natural language to describe how the network should behave. Second, we analyze and assess the accuracy and credibility of existing ML models’ for network security and performance. We also uncover the need to reinvent how researchers apply ML to networking problems, so we propose a new ML pipeline that introduces steps to scrutinize models using techniques from the emerging field of eXplainable Artificial Intelligence (XAI). Finally, we investigate whether there is a viable method to improve the trust of operators in the decisions made by ML models that enable self-driving networks. Our investigation led us to propose a new XAI method to extract explanations from any given black-box ML model in the form of decision trees while maintaining a manageable size, which we called TRUSTEE. Our results show that ML models widely applied to solve networking problems have not been put under proper scrutiny and can easily break when put under real-world traffic. Such models, therefore, need to be corrected to fulfill their given tasks properly. Arthur Selle Jacobs, Ronaldo A. Ferreira, Lisandro Z. Granville |
NOMS | 2 |
| 2022 | AI/ML for Network Security: The Emperor has no ClothesabstractSeveral recent research efforts have proposed Machine Learning (ML)-based solutions that can detect complex patterns in network traffic for a wide range of network security problems. However, without understanding how these black-box models are making their decisions, network operators are reluctant to trust and deploy them in their production settings. One key reason for this reluctance is that these models are prone to the problem of underspecification, defined here as the failure to specify a model in adequate detail. Not unique to the network security domain, this problem manifests itself in ML models that exhibit unexpectedly poor behavior when deployed in real-world settings and has prompted growing interest in developing interpretable ML solutions (e.g., decision trees) for "explaining'' to humans how a given black-box model makes its decisions. However, synthesizing such explainable models that capture a given black-box model's decisions with high fidelity while also being practical (i.e., small enough in size for humans to comprehend) is challenging. Arthur Selle Jacobs, Roman Beltiukov, Walter Willinger, Ronaldo A. Ferreira, Arpit Gupta, Lisandro Z. Granville |
CCS | 4 |
| 2022 | DWT in P4: Periodicity Detection in the Data PlaneabstractThis paper presents a P4 implementation of the (1-D) Discrete Wavelet Transform (DWT) method. As a mathe-matical tool for analyzing signals such as packet-level traces, the DWT divides a given signal into different frequency components and analyzes each component with a resolution matched to its scale. We develop an efficient online algorithm that circumvents various limitations of existing P4-programmable data plane devices and performs the DWT decomposition entirely in the data plane. Our evaluation of a hardware implementation (i.e., Netronome NFP-4000 SmartNIC) of the algorithm shows that it results in only minimal throughput overhead (less than 1% for average-sized packets) and operates within constraints imposed by the limited available data plane resources. As an application, we use our lightweight P4 implementation of the DWT and describe a novel threshold-based approach for detecting periodic behavior in a signal in real-time, at line rate in the data plane (40 Gbps). We illustrate our approach with different examples of synthetic and real-world packet-level traffic traces that exhibit periodic patterns of either benign or malicious origins. Briggette Olenka Roman Huaytalla, Arthur Selle Jacobs, Marcus V. B. Silva, Fabrício B. Carvalho, Ronaldo A. Ferreira, Walter Willinger, Lisandro Z. Granville |
GLOBECOM | 5 |
| 2022 | Dyssect: Dynamic Scaling of Stateful Network FunctionsabstractNetwork Function Virtualization promises better utilization of computational resources by dynamically scaling resources on demand. However, most network functions (NFs) are stateful and require state updates on a per-packet basis. During a scaling operation, cores need to synchronize access to a shared state to avoid race conditions and to guarantee that NFs process packets in arrival order. Unfortunately, the classic approach to control concurrent access to a shared state with locks does not scale to today’s throughput and latency requirements. Moreover, network traffic is highly skewed, leading to load imbalances in systems that use only sharding to partition the NF states. To address these challenges, we present Dyssect, a system that enables dynamic scaling of stateful NFs by disaggregating the states of network functions. By carefully coordinating actions between cores and a central controller, Dyssect migrates shards and flows between cores for load balancing or traffic prioritization without resorting to locks or reordering packets. Our experimental evaluation shows that Dyssect reduces tail latency up to 32% and increases throughput up to 19.36% when compared to state-of-the-art competing solutions. Fabrício B. Carvalho, Ronaldo A. Ferreira, Ítalo S. Cunha, Marcos A. M. Vieira, Murali Krishna Ramanathan |
INFOCOM | 2 |
| 2021 | Hey, Lumi! Using Natural Language for Intent-Based Network Management
Arthur Selle Jacobs, Ricardo J. Pfitscher, Rafael Hengen Ribeiro, Ronaldo A. Ferreira, Lisandro Z. Granville, Walter Willinger, Sanjay G. Rao |
USENIX ATC | 4 |
| 2021 | Identifying Networks Vulnerable to IP SpoofingabstractThe lack of authentication in the Internet's data plane allows hosts to falsify (spoof) the source IP address in packet headers. IP source spoofing is the basis for amplification denial-of-service (DoS) attacks. Current approaches to locate sources of spoofed traffic lack coverage or are not deployable today. We propose a mechanism that a network with multiple peering links can use to coarsely locate the sources of spoofed traffic in the Internet. The idea behind our approach is that a network can monitor and map spoofed traffic arriving on a peering link to the set of sources routed toward that link. We propose mechanisms the network can use to systematically vary BGP announcement configurations to induce changes to Internet routes and to the set of sources routed to each peering link. A network using our technique can correlate observations over multiple configurations to more precisely delineate regions sending spoofed traffic. Evaluation of our techniques on the Internet shows that they can partition the Internet into small regions, allowing targeted intervention. Osvaldo L. H. M. Fonseca, Ítalo S. Cunha, Elverton C. Fazzion, Wagner Meira Jr., Brivaldo Alves da Silva, Ronaldo A. Ferreira, Ethan Katz-Bassett |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2021 | A Verified Session Protocol for Dynamic Service ChainingabstractMiddleboxes are crucial for improving network security and performance, but only if the right traffic goes through the right middleboxes at the right time. Existing traffic-steering techniques rely on a central controller to install fine-grained forwarding rules in network elements-at the expense of a large number of rules, a central point of failure, challenges in ensuring all packets of a session traverse the same middleboxes, and difficulties with middleboxes that modify the “five tuple.” We argue that a session-level protocol is a fundamentally better approach to traffic steering, while naturally supporting host mobility and multihoming in an integrated fashion. In addition, a session-level protocol can enable new capabilities like dynamic service chaining, where the sequence of middleboxes can change during the life of a session, e.g., to remove a load-balancer that is no longer needed, replace a middlebox undergoing maintenance, or add a packet scrubber when traffic looks suspicious. Our Dysco protocol steers the packets of a TCP session through a service chain, and can dynamically reconfigure the chain for an ongoing session. Dysco requires no changes to end-host and middlebox applications, host TCP stacks, or IP routing. Dysco's distributed reconfiguration protocol handles the removal of proxies that terminate TCP connections, middleboxes that change the size of a byte stream, and concurrent requests to reconfigure different parts of a chain. Through formal verification using Spin and experiments with our prototype, we show that Dysco is provably correct, highly scalable, and able to reconfigure service chains across a range of middleboxes. Pamela Zave, Fabrício B. Carvalho, Ronaldo A. Ferreira, Jennifer Rexford, Masaharu Morimoto, Xuan Kelvin Zou |
IEEE/ACM Trans. Netw. | 3 |
| 2020 | Tracking Down Sources of Spoofed IP Packets
Osvaldo L. H. M. Fonseca, Ítalo S. Cunha, Elverton C. Fazzion, Wagner Meira Jr., Brivaldo Junior, Ronaldo A. Ferreira, Ethan Katz-Bassett |
Networking | 6 |
| 2017 | Dynamic Service Chaining with DyscoabstractMiddleboxes are crucial for improving network security and performance, but only if the right traffic goes through the right middleboxes at the right time. Existing traffic-steering techniques rely on a central controller to install fine-grained forwarding rules in network elements---at the expense of a large number of rules, a central point of failure, challenges in ensuring all packets of a session traverse the same middleboxes, and difficulties with middleboxes that modify the "five tuple." We argue that a session-level protocol is a fundamentally better approach to traffic steering, while naturally supporting host mobility and multihoming in an integrated fashion. In addition, a session-level protocol can enable new capabilities like dynamic service chaining, where the sequence of middleboxes can change during the life of a session, e.g., to remove a load-balancer that is no longer needed, replace a middlebox undergoing maintenance, or add a packet scrubber when traffic looks suspicious. Our Dysco protocol steers the packets of a TCP session through a service chain, and can dynamically reconfigure the chain for an ongoing session. Dysco requires no changes to end-host and middlebox applications, host TCP stacks, or IP routing. Dysco's distributed reconfiguration protocol handles the removal of proxies that terminate TCP connections, middleboxes that change the size of a byte stream, and concurrent requests to reconfigure different parts of a chain. Through formal verification using Spin and experiments with our Linux-based prototype, we show that Dysco is provably correct, highly scalable, and able to reconfigure service chains across a range of middleboxes. Pamela Zave, Ronaldo A. Ferreira, Xuan Kelvin Zou, Masaharu Morimoto, Jennifer Rexford |
SIGCOMM | 2 |
| 2017 | Approaches to strategic alignment of software process improvement: A systematic literature review
Francisco J. S. Vasconcellos, Geraldo B. Landre, José Adson O. G. da Cunha, Juliano Lopes de Oliveira, Ronaldo A. Ferreira, Auri M. R. Vincenzi |
J. Syst. Softw. | 5 |
| 2008 | Semantic indexing in structured peer-to-peer networks
Ronaldo A. Ferreira, Mehmet Koyutürk, Suresh Jagannathan, Ananth Grama |
J. Parallel Distributed Comput. | 1 |
| 2007 | Randomized leader election
Murali Krishna Ramanathan, Ronaldo A. Ferreira, Suresh Jagannathan, Ananth Grama, Wojciech Szpankowski |
Distributed Comput. | 2 |
| 2007 | Randomized Protocols for Duplicate Elimination in Peer-to-Peer Storage Systems
Ronaldo A. Ferreira, Murali Krishna Ramanathan, Ananth Grama, Suresh Jagannathan |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2006 | Locality in structured peer-to-peer networks
Ronaldo A. Ferreira, Suresh Jagannathan, Ananth Grama |
J. Parallel Distributed Comput. | 1 |
| 2006 | Unstructured peer-to-peer networks for sharing processor cycles
Asad Awan, Ronaldo A. Ferreira, Suresh Jagannathan, Ananth Grama |
Parallel Comput. | 2 |
| 2005 | Search with Probabilistic Guarantees in Unstructured Peer-to-Peer NetworksabstractSearch is a fundamental service in peer-to-peer (P2P) networks. However, despite numerous research efforts, efficient algorithms for guaranteed location of shared content in unstructured P2P networks are yet to be devised. In this paper, the authors presented a simple but highly effective protocol for object location that gives probabilistic guarantees of finding even rare objects independently of the network topology. The protocol relies on randomized techniques for replication of objects (or their references) and for query propagation. The authors proved analytically, and demonstrated experimentally, that this scheme provides high probabilistic guarantees of success, while incurring minimal overhead. The performance of this scheme was quantified in terms of network messages, probability of success, and response time. The robustness of this protocol was also evaluated in the presence of node failures (departures). Using simulation, it is shown that this scheme performs no worse than the best known access-frequency based protocols, without compromising access to rare objects. Ronaldo A. Ferreira, Murali Krishna Ramanathan, Asad Awan, Ananth Grama, Suresh Jagannathan |
Peer-to-Peer Computing | 1 |
| 2005 | Randomized Protocols for Duplicate Elimination in Peer-to-Peer Storage SystemsabstractDistributed peer-to-peer storage systems rely on voluntary participation of peers to effectively manage a storage pool. Files are generally replicated in several sites to provide acceptable levels of availability. If disk space on these peers is not carefully monitored and provisioned, the system may not be able to provide availability for certain files. In particular, identification and elimination of redundant data are important problems that may arise in long-lived systems. Scalability and availability are competing goals in these networks: scalability concerns would dictate aggressive elimination of replicas, while availability considerations would argue conversely. In this paper, the authors provided a novel and efficient solution that addresses both these goals with respect to management of redundant data. Specifically, the problem of duplicate elimination in the context of systems connected over an unstructured peer-to-peer network in which there is no a priori binding between an object and its location was addressed. A new randomized protocol was proposed to solve this problem in a scalable and decentralized fashion that does not compromise availability requirements of the application. Performance results using both large-scale simulations, and a prototype built on PlanetLab, demonstrate that the protocols provide high probabilistic guarantees of success, while incurring minimal administrative overheads. Ronaldo A. Ferreira, Murali Krishna Ramanathan, Ananth Grama, Suresh Jagannathan |
Peer-to-Peer Computing | 1 |
| 2004 | Plethora: An EfficientWide-Area Storage System
Ronaldo A. Ferreira, Ananth Grama, Suresh Jagannathan |
HiPC | 1 |
| 2004 | Enhancing Locality in Structured Peer-to-Peer Networks
Ronaldo A. Ferreira, Suresh Jagannathan, Ananth Grama |
ICPADS | 1 |
| 2003 | A Transport Layer A straction for Peer-to-Peer NetworksabstractThe initially unrestricted host-to-host communication model provided by the Internet Protocol has deteriorated due to political and technical changes caused by Internet growth. While this is not a problem for most client-server applications, peer-to-peer networks frequently struggle with peers that are only partially reachable. We describe how a peer-to-peer framework can hide diversity and obstacles in the underlying Internet and provide peer-to-peer applications with abstractions that hide transport specific details. We present the details of an implementation of a transport service based on SMTP. Small-scale benchmarks are used to compare transport services over UDP, TCP, and SMTP. Ronaldo A. Ferreira, Christian Grothoff, Paul Ruth |
CCGRID | 1 |
| 2003 | An IP address based caching scheme for peer-to-peer networksabstractDistributed hash tables (DHTs), used in a number of current peer-to-peer systems, provide efficient mechanisms for resource location. Systems such as Chord, Pastry, CAN, and Tapestry provide strong guarantees that queries in the overlay network can be resolved in a bounded number of overlay hops, while preserving load balance among the peers. A key distinction in these systems is the way they handle locality in the underlying network. Topology-based node identifier assignment, proximity routing, and proximity neighbor selection are examples of heuristics used to minimize message delays in the underlying network. We investigate the use of source IP addresses to enhance locality in overlay networks based on DHTs. We first show that a naive use of source IP address potentially leads to severe resource imbalance due to nonuniformity of peers over the IP space. We then present an effective caching scheme that combines a segment of the source IP with the queried hash-code to localize access and affect replication effectively. Using detailed experiments, we show that this scheme achieves performance gains of up to 41%, when compared to Pastry in combination with the proximity neighbor selection heuristic. Ronaldo A. Ferreira, Ananth Grama, Suresh Jagannathan |
GLOBECOM | 1 |