Giuseppe Aceto

dblp:64/9720 · DBLP profile ↗
← Back
37ranked-venue papers
21as first author
14since 2021 · last 2024
0000-0002-4445-6259ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 31 · 17 first-author · 13 since 2021Security and privacy · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-author
YearPublicationVenuePosition
2024 MEMENTO: A novel approach for class incremental learning of encrypted traffic
abstract
In the ever-changing digital environment, ensuring the ongoing effectiveness of traffic analysis and security measures is crucial. Therefore, Class Incremental Learning (CIL) in encrypted Traffic Classification (TC) is essential for adapting to evolving network behaviors and the rapid development of new applications. However, the application of CIL techniques in the TC domain is not straightforward, usually leading to unsatisfactory performance figures. Specifically, the improvement goal is to reduce forgetting on old apps and increase the capacity in learning new ones, in order to improve overall classification performance— reducing the drop from a model “trained-from-scratch”. The contribution of this work is the design of a novel fine-tuning approach called MEMENTO, which is obtained through the careful design of different building blocks: memory management, model training, and rectification strategies. In detail, we propose the application of traffic biflows augmentation strategies to better capitalize on old apps biflows, we introduce improvements in the distillation stage, and we design a general rectification strategy that includes several existing proposals. To assess our proposal, we leverage two publicly-available encrypted network traffic datasets, i.e., MIRAGE19 and CESNET-TLS22. As a result, on both datasets MEMENTO achieves a significant improvement in classifying new apps (w.r.t. the best-performing alternative, i.e., BiC) while maintaining stable performance on old ones. Equally important, MEMENTO achieves satisfactory overall TC performance, filling the gap toward a trained-from-scratch model and offering a considerable gain in terms of time (up to 10× speed-up) to obtain up-to-date and running classifiers. The experimental evaluation relies on a comprehensive performance evaluation workbench for CIL proposals, which is based on a wider set of metrics (as opposed to the existing literature in TC).
Francesco Cerasuolo, Alfredo Nascita, Giampaolo Bovenzi, Giuseppe Aceto, Domenico Ciuonzo, Antonio Pescapè, Dario Rossi 0001
Comput. Networks4
2024 Synthetic and privacy-preserving traffic trace generation using generative AI models for training Network Intrusion Detection Systems
abstract
Network Intrusion Detection Systems (NIDS) are crucial tools for protecting networked devices from cyberattacks. Recent development in the field of Artificial Intelligence (AI) has provided tremendous advantages in implementing NIDSs able to monitor network traffic and block cyberattacks in real-time. In the literature, it is widely recognized that the effective training of a NIDS requires a large quantity of labeled traffic, representative of attacks. Nonetheless, the availability of public and abundant datasets remains remarkably restricted due to the cost of gathering and labeling real traffic traces and privacy concerns for sharing them. To tackle these challenges, in this paper we present a generative AI model capable of synthesizing anonymized traffic traces from real ones, thus dealing with privacy, abundance, and representativeness. The proposal is based on a Conditional Variational Autoencoder (CVAE) and a preprocessing procedure specifically designed for the generation of new traffic traces. To validate our solution, we conduct an extensive empirical study leveraging three recent and publicly-available datasets, containing benign and malicious traffic. The validation is carried out from both the perspectives of classification performance of a robust NIDS and the quality of synthetic data, in comparison to the utilization of real data. We compare our CVAE with two state-of-the-art AI-based traffic data generators and prove that, trained with traces emitted by our generative model, a NIDS has a limited F1-score loss compared to training on real data; competing models instead struggle or fail to generate traces that are as effective for NIDS training and as statistically similar to the original. We make the synthetic datasets available in both PCAP and tabular formats, to facilitate the reproducibility of our findings and encourage further exploration in the field of generative AI for networking.
Giuseppe Aceto, Fabio Giampaolo, Ciro Guida, Stefano Izzo, Antonio Pescapè, Francesco Piccialli, Edoardo Prezioso
J. Netw. Comput. Appl.1
2024 Benchmarking Class Incremental Learning in Deep Learning Traffic Classification
abstract
Traffic Classification (TC) is experiencing a renewed interest, fostered by the growing popularity of Deep Learning (DL) approaches. In exchange for their proved effectiveness, DL models are characterized by a computationally-intensive training procedure that badly matches the fast-paced release of new (mobile) applications, resulting in significantly limited efficiency of model updates. To address this shortcoming, in this work we systematically explore Class Incremental Learning (CIL) techniques, aimed at adding new apps/services to pre-existing DL-based traffic classifiers without a full retraining, hence speeding up the model’s updates cycle. We investigate a large corpus of state-of-the-art CIL approaches for the DL-based TC task, and delve into their working principles to highlight relevant insight, aiming to understand if there is a case for CIL in TC. We evaluate and discuss their performance varying the number of incremental learning episodes, and the number of new apps added for each episode. Our evaluation is based on the publicly available$\mathtt {MIRAGE19}$dataset comprising traffic of 40 popular Android applications, fostering reproducibility. Despite our analysis reveals their infancy, CIL techniques are a promising research area on the roadmap towards automated DL-based traffic analysis systems.
Giampaolo Bovenzi, Alfredo Nascita, Lixuan Yang, Alessandro Finamore, Giuseppe Aceto, Domenico Ciuonzo, Antonio Pescapè, Dario Rossi 0001
IEEE Trans. Netw. Serv. Manag.5
2023 Fine-Grained Traffic Prediction of Communication-and-Collaboration Apps Via Deep-Learning: A First Look at Explainability
abstract
The lifestyle change originated from the COVID-19 pandemic has caused a measurable impact on Internet traffic in terms of volume and application mix, with a sudden increase in usage of communication-and-collaboration apps. In this work, we focus on four of these apps (Skype, Teams, Webex, and Zoom), whose traffic we collect, reliably label at fine (i.e. per-activity) granularity, and analyze from the viewpoint of traffic prediction. The outcome of this analysis is informative for a number of network management tasks, including monitoring, planning, resource provisioning, and (security) policy enforcement. To this aim, we employ state-of-the-art multitask deep learning approaches to assess to which degree the traffic generated by these apps and their different use cases (i.e. activities: audio-call, video-call, and chat) can be forecast at packet level. The experimental analysis investigates the performance of the considered deep learning architectures, in terms of both traffic-prediction accuracy and complexity, and the related trade-off. Equally important, our work is a first attempt at interpreting the results obtained by these predictors via eXplainable Artificial Intelligence (XAI).
Idio Guarino, Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Valerio Persico, Antonio Pescapè
ICC2
2023 Network anomaly detection methods in IoT environments via deep learning: A Fair comparison of performance and robustness
abstract
The Internet of Things (IoT) is a key enabler in closing the loop in Cyber-Physical Systems, providing “smartness” and thus additional value to each monitored/controlled physical asset. Unfortunately, these devices are more and more targeted by cyberattacks because of their diffusion and of the usually limited hardware and software resources. This calls for designing and evaluating new effective approaches for protecting IoT systems at the network level (Network Intrusion Detection Systems, NIDSs). These in turn are challenged by the heterogeneity of IoT devices and the growing volume of transmitted data. To tackle this challenge, we select a Deep Learning architecture to perform unsupervised early anomaly detection. With a data-driven approach, we explore in-depth multiple design choices and exploit the appealing structural properties of the selected architecture to enhance its performance. The experimental evaluation is performed on two recent and publicly available IoT datasets (IoT-23 and Kitsune). Finally, we adopt an adversarial approach to investigate the robustness of our solution in the presence of Label Flipping poisoning attacks. The experimental results highlight the improved performance of the proposed architecture, in comparison to both well-known baselines and previous proposals.
Giampaolo Bovenzi, Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Valerio Persico, Antonio Pescapè
Comput. Secur.2
2023 Improving Performance, Reliability, and Feasibility in Multimodal Multitask Traffic Classification with XAI
abstract
The promise of Deep Learning (DL) in solving hard problems such as network Traffic Classification (TC) is being held back by the severe lack of transparency and explainability of this kind of approaches. To cope with this strongly felt issue, the field of eXplainable Artificial Intelligence (XAI) has been recently founded, and is providing effective techniques and approaches. Accordingly, in this work we investigate interpretability via XAIbased techniques to understand and improve the behavior of state-of-the-art multimodal and multitask DL traffic classifiers. Using a publicly available security-related dataset (ISCX VPNNONVPN), we explore and exploit XAI techniques to characterize the considered classifiers providing global interpretations (rather than sample-based ones), and define a novel classifier, DISTILLER-EVOLVED, optimized along three objectives: performance, reliability, feasibility. The proposed methodology proves as highly appealing, allowing to much simplify the architecture to get faster training time and shorter classification time, as fewer packets must be collected. This is at the expenses of negligible (or even positive) impact on classification performance, while understanding and controlling the interplay between inputs, model complexity, performance, and reliability.
Alfredo Nascita, Antonio Montieri, Giuseppe Aceto, Domenico Ciuonzo, Valerio Persico, Antonio Pescapè
IEEE Trans. Netw. Serv. Manag.3
2022 A First Look at Accurate Network Traffic Generation in Virtual Environments
abstract
The generation of synthetic network traffic is necessary to several fundamental networking activities, ranging from device testing to path monitoring, with implications on security and management. While literature focused on high-rate traffic generation, for many use cases accurate traffic generation is of importance instead. These scenarios have expanded with Network Function Virtualization, Software Defined Networking, and Cloud applications, which introduce further causes for alterations of generated traffic. Such causes are described and experimentally evaluated in this work, where the generation accuracy of D-ITG, an open-source software generator, is investigated in a virtualized environment. A definition of accuracy in terms of Mean Absolute Percentage Error of the sequences of Payload Lengths (PLs) and Inter-Departure Times (IDTs) is exploited to this end. The tool is found accurate for all PLs and for IDTs greater than one millisecond, and after the correction of a systematic error, also from 100 us.
Giuseppe Aceto, Ciro Guida, Antonio Montieri, Valerio Persico, Antonio Pescapè
ISCC1
2022 Contextual counters and multimodal Deep Learning for activity-level traffic classification of mobile communication apps during COVID-19 pandemic
Idio Guarino, Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Valerio Persico, Antonio Pescapè
Comput. Networks2
2021 Encrypted Multitask Traffic Classification via Multimodal Deep Learning
abstract
Traffic Classification (TC), i.e. the collection of procedures for inferring applications and/or services generating network traffic, represents the workhorse for service management and the enabler for valuable profiling information. Sadly, the growing trend toward encrypted protocols (e.g. TLS) and the evolving nature of network traffic make TC design solutions based on payload-inspection and machine learning, respectively, unsuitable. Conversely, Deep Learning (DL) is currently foreseen as a viable means to design traffic classifiers based on automatically-extracted features, reflecting the complex patterns distilled from the multifaceted (encrypted) traffic nature, implicitly carrying information in "multimodal" fashion. To this end, in this paper a novel multimodal DL approach for multitask TC is explored. The latter is able to capitalize traffic data heterogeneity (by learning both intra- and inter-modality dependencies), overcome performance limitations of existing (myopic) single-modality DL-based TC proposals, and solve different traffic categorization problems associated with different providers’ desiderata. Based on a real dataset of encrypted traffic, we report performance gains of our proposal over (a) state-of-art multitask DL architectures and (b) multitask extensions of single-task DL baselines (both based on single-modality philosophy).
Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Alfredo Nascita, Antonio Pescapè
ICC1
2021 Packet-level prediction of mobile-app traffic using multitask Deep Learning
Antonio Montieri, Giampaolo Bovenzi, Giuseppe Aceto, Domenico Ciuonzo, Valerio Persico, Antonio Pescapè
Comput. Networks3
2021 Characterization and analysis of cloud-to-user latency: The case of Azure and AWS
Fabio Palumbo, Giuseppe Aceto, Alessio Botta, Domenico Ciuonzo, Valerio Persico, Antonio Pescapè
Comput. Networks2
2021 DISTILLER: Encrypted traffic classification via multimodal multitask deep learning
Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Antonio Pescapè
J. Netw. Comput. Appl.1
2021 Characterization and Prediction of Mobile-App Traffic Using Markov Modeling
abstract
Modeling network traffic is an endeavor actively carried on since early digital communications, supporting a number of practical applications, that range from network planning and provisioning to security. Accordingly, many theoretical and empirical approaches have been proposed in this long-standing research, most notably, Machine Learning (ML) ones. Indeed, recent interest from network equipment vendors is sparking around the evaluation of solid information-theoretical modeling approaches complementary to ML ones, especially applied to new network traffic profiles stemming from the massive diffusion of mobile apps. To cater to these needs, we analyze mobile-app traffic available in the public dataset MIRAGE-2019 adopting two related modeling approaches based on the well-known methodological toolset of Markov models (namely, Markov Chains and Hidden Markov Models). We propose a novel heuristic to reconstruct application-layer messages in the common case of encrypted traffic. We discuss and experimentally evaluate the suitability of the provided modeling approaches for different tasks: characterization of network traffic (at different granularities, such as application, application category, and application version), and prediction of network traffic at both packet and message level. We also compare the results with several ML approaches, showing performance comparable to a state-of-the-art ML predictor (Random Forest Regressor). Also, with this work we provide a viable and theoretically sound traffic-analysis toolset to help improving ML evaluation (and possibly its design), and a sensible and interpretable baseline.
Giuseppe Aceto, Giampaolo Bovenzi, Domenico Ciuonzo, Antonio Montieri, Valerio Persico, Antonio Pescapè
IEEE Trans. Netw. Serv. Manag.1
2021 XAI Meets Mobile Traffic Classification: Understanding and Improving Multimodal Deep Learning Architectures
abstract
The increasing diffusion of mobile devices has dramatically changed the network traffic landscape, with Traffic Classification (TC) surging into a fundamental role while facing new and unprecedented challenges. The recent and appealing adoption of Deep Learning (DL) techniques has risen as the solution overcoming the performance of ML techniques based on tedious and time-consuming handcrafted feature design. Still, the black-box nature of DL models prevents its practical and trustful adoption in critical scenarios where the reliability/interpretation of results/policies is of key importance. To cope with these limitations, eXplainable Artificial Intelligence (XAI) techniques have recently acquired the interest of the community. Accordingly, in this work we investigate trustworthiness and interpretability via XAI-based techniques to understand, interpret and improve the behavior of state-of-the-art multimodal DL traffic classifiers. The proposed methodology, as opposed to common results seen in XAI, attempts to provide global interpretation, rather than sample-based ones. Results, based on an open dataset, allow to complement the above findings with domain knowledge.
Alfredo Nascita, Antonio Montieri, Giuseppe Aceto, Domenico Ciuonzo, Valerio Persico, Antonio Pescapè
IEEE Trans. Netw. Serv. Manag.3
2020 A Hierarchical Hybrid Intrusion Detection Approach in IoT Scenarios
abstract
Internet of Things (IoT) fosters unprecedented network heterogeneity and dynamicity, thus increasing the variety and the amount of related vulnerabilities. Hence, traditional security approaches fall short, also in terms of resulting scalability and privacy. In this paper we propose H2ID, a two-stage hierarchical Network Intrusion Detection approach. H2ID performs (i) anomaly detection via a novel lightweight solution based on a MultiModal Deep AutoEncoder (M2-DAE), and (ii) attack classification, using soft-output classifiers. We validate our proposal using the recently-released Bot-IoT dataset, inferring among four relevant categories of attack (DDoS, DoS, Scan, and Theft) and unknown attacks. Results show gains of the proposed M2-DAE in the case of simple anomaly detection (up to -40% false-positive rate when compared with several baselines at same true positive rate) and for H2ID as a whole when compared to the best-performing misuse detector approach (up to ≈ +5% F1 score). Besides the performance advantages, our system is suitable for distributed and privacy-preserving deployments while limiting re-training necessities, in line with the high efficiency as well as the flexibility required in IoT scenarios.
Giampaolo Bovenzi, Giuseppe Aceto, Domenico Ciuonzo, Valerio Persico, Antonio Pescapè
GLOBECOM2
2020 A network performance view of a biobanking system for diagnostic images
abstract
A significant contribution of ICT to healthcare is constituted by systems automating and enhancing the management of research and clinical data. More specifically, PACS (Picture Archiving ad Communication Systems) have improved the efficiency of diagnostic images and clinical data management. Their evolution (image biobanks) are now enabling new collaborations and analysis possibilities similarly to—and beyond—the biobanks (their biologic samples analogous and complement). In this work we describe and evaluate the network performance of a biobanking system for diagnostic images, based on the XNAT open source platform, as implemented and operated by Bio Check Up Srl. The point of view of the user is adopted, in assessing the performance in three setups: local (virtual machines communicating in a single host), LAN (organization-local access), and VPN (remote secure access through the Internet). Both upload and download usage cases are considered, with both a medium-sized and big-sized set of diagnostic images. Several metrics are extracted from traffic traces captured in the experimental campaign, and discussed. Results show that the current setup is well provisioned for satisfying the planned number of concurrent users, and point to further experimental campaigns.
Giusy Esposito, Giulio Pagliari, Gianluca Coppola, Marco Aiello 0003, Marco Salvatore, Giuseppe Aceto, Antonio Pescapè
ISCC6
2020 Performance-based service-level agreement in cloud computing to optimise penalties and revenue
abstract
Cost, performance, and penalties are the key factors to revenue generation and customer satisfaction. They have a complex correlation, that gets more complicated when missing a proper framework that unambiguously defines these factors. Service‐level agreement (SLA) is the initial document discussing selected parameters as a precondition to business initialisation. The clear definition and application of the SLA is of paramount importance as for modern as a Service online businesses no direct communication between provider and consumer is expected. For the proper implementation of SLA, there should be a satisfactory approach for measuring and monitoring quality of service metrics. This study investigated these issues and proposed performance‐based SLA (PerSLA) framework for cost, performance, penalties and revenue optimisation. PerSLA optimises these parameters and maximises both provider revenue and customers satisfaction. Simulation results confirm that the proposed framework is adequate in revenue generation and customers satisfaction. Customers and providers monitor the business with respect to agreed terms and conditions. On violation, the provider is penalised. This agreement increases the trust in relationship between provider and consumer.
Afzal Badshah, Anwer Ghani, Shahab B. Band, Giuseppe Aceto, Antonio Pescapè
IET Commun.4
2020 Toward effective mobile encrypted traffic classification through deep learning
Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Antonio Pescapè
Neurocomputing1
2020 Anonymity Services Tor, I2P, JonDonym: Classifying in the Dark (Web)
abstract
Traffic Classification (TC) is an important tool for several tasks, applied in different fields (security, management, traffic engineering, R&D). This process is impaired or prevented by privacy-preserving protocols and tools, that encrypt the communication content, and (in case of anonymity tools) additionally hide the source, the destination, and the nature of the communication. In this paper, leveraging a public dataset released in 2017, we provide classification results with the aim of investigating to which degree the specific anonymity tool (and the traffic it hides) can be identified, when compared to the traffic of other considered anonymity tools, using five machine learning classifiers. Initially, flow-based TC is considered, and the effects of feature importance and temporal-related features to the network are investigated. Additionally, the role of finer-grained features, such as the (joint) histogram of packet lengths (and inter-arrival times), is determined. Successively, “early” TC of anonymous networks is analyzed. Results show that the considered anonymity networks (Tor, I2P, JonDonym) can be easily distinguished (with an accuracy of 99.87% and 99.80%, in case of flow-based and early-TC, respectively), telling even the specific application generating the traffic (with an accuracy of 73.99% and 66.76%, in case of flow-based and early-TC, respectively).
Antonio Montieri, Domenico Ciuonzo, Giuseppe Aceto, Antonio Pescapè
IEEE Trans. Dependable Secur. Comput.3
2019 Characterizing Cloud-to-User Latency as Perceived by AWS and Azure Users Spread over the Globe
abstract
With the growing adoption of cloud infrastructures to deliver a variety of IT services, monitoring cloud network performance has become crucial. However, cloud providers only disclose qualitative info about network performance, at most. This hinders efficient cloud adoption, resulting in no performance guarantees, uncertainties about the behavior of hosted services, and sub-optimal deployment choices. In this work, we focus on cloud-to-user latency, i.e. the latency of network paths interconnecting datacenters to worldwide-spread cloud users accessing their services. In detail, we performed a 14-day measurement campaign from 25 vantage points deployed via Planetlab infrastructure (emulating spatially- spread users) and considering services running in distinct locations on the infrastructures of the two most popular public-cloud providers, namely Amazon Web Services and Microsoft Azure. Our experimentation allows to provide an in-depth performance characterization (based on multiple probing methods and fine-grained sampling rate) of such networks as perceived by users spread worldwide. Results show the presence of both spatial and temporal latency trends. Finally, by evaluating the advantages of multi- cloud deployments, our results also provide useful guidelines to cloud customers.
Fabio Palumbo, Giuseppe Aceto, Alessio Botta, Domenico Ciuonzo, Valerio Persico, Antonio Pescapè
GLOBECOM2
2019 MIMETIC: Mobile encrypted traffic classification using multimodal deep learning
Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Antonio Pescapè
Comput. Networks1
2019 Mobile Encrypted Traffic Classification Using Deep Learning: Experimental Evaluation, Lessons Learned, and Challenges
abstract
The massive adoption of hand-held devices has led to the explosion of mobile traffic volumes traversing home and enterprise networks, as well as the Internet. Traffic classification (TC), i.e., the set of procedures for inferring (mobile) applications generating such traffic, has become nowadays the enabler for highly valuable profiling information (with certain privacy downsides), other than being the workhorse for service differentiation/blocking. Nonetheless, the design of accurate classifiers is exacerbated by the raising adoption of encrypted protocols (such as TLS), hindering the suitability of (effective) deep packet inspection approaches. Also, the fast-expanding set of apps and the moving-target nature of mobile traffic makes design solutions with usual machine learning, based on manually and expert-originated features, outdated and unable to keep the pace. For these reasons deep learning (DL) is here proposed, for the first time, as a viable strategy to design practical mobile traffic classifiers based on automatically extracted features, able to cope with encrypted traffic, and reflecting their complex traffic patterns. To this end, different state-of-the-art DL techniques from (standard) TC are here reproduced, dissected (highlighting critical choices), and set into a systematic framework for comparison, including also a performance evaluation workbench. The latter outcome, although declined in the mobile context, has the applicability appeal to the wider umbrella of encrypted TC tasks. Finally, the performance of these DL classifiers is critically investigated based on an exhaustive experimental validation (based on three mobile datasets of real human users' activity), highlighting the related pitfalls, design guidelines, and challenges.
Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Antonio Pescapè
IEEE Trans. Netw. Serv. Manag.1
2018 Evaluation of SDN-based bandwidth estimation in Mobile Broad Band networks
abstract
Mobile Broad Band (MBB) networks and Software-Defined Networking (SDN) are expected to strongly characterize the future evolution of global communications envisioned by the Fifth Generation mobile networks (5G). Although SDN has seen adoption and wide experimentation in data-center networks, its benefits and challenges in MBB has not received comparable coverage. In this work we experiment with a state-of-art SDN-based approach for passive monitoring available bandwidth and throughput with an OpenFlow switch in the mobile node. We evaluate the approach on a real-world commercial 4G network (leveraging the MONROE platform), considering two deployments (with an SDN controller local to the mobile node, and a remote one, whose control messages traverse the radio access network) and compare the results of the experiments against analogous deployments in a fully-wired testbed. For both the local and remote deployments, different polling periods, in different traffic conditions, are considered. Results show that, while further research is needed to investigate the variability of the relative error (standard deviation ranges between 1.21 and 8.65% in the worst case), its mean is very low, confirming the feasibility of the proposed estimation approach.
Giuseppe Aceto, Fabio Palumbo, Valerio Persico, Haiming Chen 0002, Antonio Pescapè
APCC1
2018 Available Bandwidth vs. Achievable Throughput Measurements in 4G Mobile Networks
Giuseppe Aceto, Fabio Palumbo, Valerio Persico, Antonio Pescapè
CNSM1
2018 Speeding-Up DPI Traffic Classification with Chaining
abstract
The importance of network traffic classification has grown over the last two decades in line with the increasing diver- sity of networked applications. Nowadays traditional approaches to traffic classification, relying on port numbers and on Deep Packet Inspection (DPI), are not very effective in real scenarios respectively due to the usage of random or non-standard port numbers and to the wide usage of end-to-end encryption. Despite their limitations, port- based and DPI approaches are still widely used in operational networks for a number of network monitoring and management tasks. This paper proposes a practical approach for improving the efficiency of traditional traffic classification techniques by chain- ing fast classification stages (port-based and machine-learning- based), combined to lower their false-positive rate, and a more precise - but time- and resource-demanding - stage based on DPI. Experimental results demonstrate that Chain obtains results in line with DPI approaches in term of Precision, Recall, Accuracy and Area Under the Curve (AUC), while it is 45% faster when compared to nDPIng, a well- known DPI implementation. The appealing of the proposed approach in Network Function Virtualization (NFV) contexts is also discussed.
Hossein Doroud, Giuseppe Aceto, Walter de Donato, Elnaz Alizadeh Jarchlo, Andrés Marín López, César D. Guerrero, Antonio Pescapè
GLOBECOM2
2018 A comprehensive survey on internet outages
Giuseppe Aceto, Alessio Botta, Pietro Marchetta, Valerio Persico, Antonio Pescapè
J. Netw. Comput. Appl.1
2018 Multi-classification approaches for classifying mobile app traffic
Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Antonio Pescapè
J. Netw. Comput. Appl.1
2018 The role of Information and Communication Technologies in healthcare: taxonomies, perspectives, and challenges
Giuseppe Aceto, Valerio Persico, Antonio Pescapè
J. Netw. Comput. Appl.1
2017 Traffic Classification of Mobile Apps through Multi-Classification
abstract
The wide spreading and growing usage of smartphones are deeply changing the kind of traffic that traverses home and enterprise networks and the Internet. Tools that base their functions on the knowledge of the application generating the traffic (performance enhancement proxies, network monitors, policy enforcement devices) imply traffic classification, and are thus limited or impaired when dealing with the daily expanding set of mobile apps. Besides the moving-target nature of mobile apps traffic, the increasing adoption of encrypted protocols (TLS) makes classification even more challenging, defeating established approaches (DPI, statistical classifiers). In this paper we aim to improve the classification performance of mobile apps classifiers adopting a multi-classification approach, intelligently-combining decisions from state-of-art classifiers proposed for mobile and encrypted traffic classification. Based on a dataset of users' activity collected by a mobile solutions provider, our results demonstrate that classification performance can be improved according to all considered metrics, up to +8.1% F-measure score with respect to the best base classifier. Further room for improvements is also evidenced by the ideal combiner performance (oracle).
Giuseppe Aceto, Domenico Ciuonzo, Antonio Montieri, Antonio Pescapè
GLOBECOM1
2017 Internet censorship in Italy: An analysis of 3G/4G networks
abstract
Users trying to access censored content may experience different results, depending on the technique adopted to enforce Internet Censorship, that in turn depends on different factors. Administrative control of the network (i.e. the entity managing network devices) is one of such factors. To the best of our knowledge, we are the first to focus on censorship detection on 3G/4G (hereafter mobile) network operators, investigating the extent of differences in applying censorship inside a single country. To do so we performed an experimental campaign in Italy using the five major mobile operators. We introduce the censorship detection platform and tests we adopted, and aggregate the results according to the outcome of the tests in classes, related with censoring techniques and circumvention capabilities. Overall 15 different aggregated behaviors have been found in the experimental campaign. The analysis of measurement results reveals wide dis-homogeneity of treatment for a given censored resource across different mobile operators, with 99.5% of resources showing at least two different behaviors when probed. The discussion of reported results informs about the unexpected variability on transparency and precision of censorship, and also on effective detection and circumvention strategies, as measured from mobile networks in a single country.
Giuseppe Aceto, Antonio Montieri, Antonio Pescapè
ICC1
2017 Challenges and solution for measuring available bandwidth in software defined networks
Péter Megyesi, Alessio Botta, Giuseppe Aceto, Antonio Pescapè, Sándor Molnár
Comput. Commun.3
2016 Internet Censorship in Italy: A First Look at 3G/4G Networks
Giuseppe Aceto, Antonio Montieri, Antonio Pescapè
CANS1
2015 Internet Censorship detection: A survey
Giuseppe Aceto, Antonio Pescapè
Comput. Networks1
2013 Cloud monitoring: A survey
Giuseppe Aceto, Alessio Botta, Walter de Donato, Antonio Pescapè
Comput. Networks1
2013 Efficient Storage and Processing of High-Volume Network Monitoring Data
abstract
Monitoring modern networks involves storing and transferring huge amounts of data. To cope with this problem, in this paper we propose a technique that allows to transform the measurement data in a representation format meeting two main objectives at the same time. Firstly, it allows to perform a number of operations directly on the transformed data with a controlled loss of accuracy, thanks to the mathematical framework it is based on. Secondly, the new representation has a small memory footprint, allowing to reduce the space needed for data storage and the time needed for data transfer. To validate our technique, we perform an analysis of its performance in terms of accuracy and memory footprint. The results show that the transformed data closely approximates the original data (within 5% relative error) while achieving a compression ratio of 20%; storage footprint can also be gradually reduced towards the one of the state-of-the-art compression tools, such as bzip2, if higher approximation is allowed. Finally, a sensibility analysis show that technique allows to trade-off the accuracy on different input fields so to accommodate for specific application needs, while a scalability analysis indicates that the technique scales with input size spanning up to three orders of magnitude.
Giuseppe Aceto, Alessio Botta, Antonio Pescapè, Cédric Westphal
IEEE Trans. Netw. Serv. Manag.1
2012 Unified architecture for network measurement: The case of available bandwidth
Giuseppe Aceto, Alessio Botta, Antonio Pescapè, Maurizio D'Arienzo
J. Netw. Comput. Appl.1
2010 UANM: a platform for experimenting with available bandwidth estimation tools
abstract
In the field of network monitoring and measurement, the efficiency and accuracy of the adopted tools is strongly dependent on (i) structural and dynamic characteristics of the network scenario under measure and (ii) on manual fine tuning of the involved parameters. This is, for example, the case of the end-to-end available bandwidth estimation, in which the constraints of the measurement stage vary according to the use of the final results. In this work we present UANM (Unified Architecture for Network Measurement), a novel measurement infrastructure for an automatic management of measurement stages, tailored to the end-to-end available bandwidth estimation tools. We describe in details its architecture, illustrating the features we introduced to mitigate the problems affecting available bandwidth estimation in heterogeneous scenarios. Moreover, to provide evidences of UANM benefits, we present an experimental validation in three selected scenarios deployed over a real network testbed: (i) we show how UANM is able to alleviate the interferences among concurrent measures; (ii) we quantify the overhead introduced by the use of UANM; (iii) we illustrate how UANM is capable to provide more accurate results thanks to the knowledge of the network environment.
Giuseppe Aceto, Alessio Botta, Antonio Pescapè, Maurizio D'Arienzo
ISCC1