VLDB 2026 Research / reviewers in the wild / expert
Maurizio M. Munafò
dblp:65/4645 · also Maurizio Matteo Munafò
· DBLP profile ↗
44ranked-venue papers
0as first author
10since 2021 · last 2026
0000-0002-4884-7310ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 34 · 6 since 2021Artificial intelligence and machine learning · 2Systems, architecture and hardware · 2Databases, data management, data science and information retrieval · 2Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | One Is Enough: Efficient Modeling of RTP Traffic for QoS Predictions in Real-Time CommunicationsabstractIn recent years, we have witnessed an unprecedented upsurge in popularity and advancement of Real-time Transport Protocol (RTP)-based real-time communication (RTC) applications. For the sake of their optimizations, Quality of Service (QoS) prediction serves as a viable venue for enhancing network monitoring and enabling preemptive solutions. However, existing methodologies are typically tailored and constrained to individual traffic flows and QoS metrics, lagging in correlation capturing and computational efficiency. In light of this, we argue that “one model is enough” to conquer these challenges, and propose a novel deep learning (DL) framework namelyOh, employing a teacher-student scheme with two training stages. The first (teacher) involves a sophisticated Long Short-Term Memory (LSTM) neural network (NN) empowered by a customized attention structure, and the second (student) comprises simple feedforward NNs to distill knowledge and reduce complexity. Specifically,Ohleverages a multi-task learning paradigm, mapping extracted features to four key QoS indicators. It is capable of simultaneously handling unlimited amount of concurrent RTP flows with packet-level information and performing end-to-end predictions of multiple QoS metrics in one single shot. Our work is based on massive traffic collected during real video-teleconferencing calls using various software, and benchmarked against multiple other machine learning (ML)/DL algorithms. As a result,Oh-teacher yields superior prediction performance, whereasOh-student achieves distinctly enhanced temporal efficiency with comparable forecasting outcomes. Tailai Song, Paolo Garza, Michela Meo, Maurizio M. Munafò |
IEEE Trans. Netw. | 4 |
| 2025 | Packet Loss in Real-Time Communications: Can ML Tame Its Unpredictable Nature?abstractDue to the flourishing development of networks, and abetted by the Covid-19 pandemic, we have witnessed an exponential surge in the global proliferation of Real-Time Communications (RTC) applications in recent years. In light of this, the necessity for robust, scalable, and intelligent network infrastructures and technologies has become increasingly apparent. Among the principal challenges encountered in RTC lies the issue of packet loss. Indeed, the occurrence of losses leads to communication degradation and reallocation that adversely affect the Quality of Experience (QoE). In this paper, we investigate the feasibility of predicting packet loss phenomena through the utilization of machine learning techniques, solely based on statistics derived directly from packets. We provide different definitions of packet loss, subsequently focusing on the most critical scenario, which is defined as the first loss of a series. By delineating the concept of loss, we propose different problem formulations to determine whether there exists a mathematically advantageous scenario over others. To substantiate our analysis, we demonstrate that these phenomena can be correctly identified with a recall up to 66%, leveraging three ample datasets of RTC traffic, which were collected under distinct conditions at different times, further solidifying the validity of our findings. Tailai Song, Gianluca Perna, Paolo Garza, Michela Meo, Maurizio M. Munafò |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2024 | BitFormer: Transformer-Based Neural Network for Bitrate Prediction in Real-Time CommunicationsabstractIn recent years, an exponential upsurge in the global proliferation of Real-Time Communications (RTC) applications has been witnessed, due to the prosperous development of networks and further fueled by the ramifications of the COVID-19 pandemic. Consequently, the imperative for development of intelligent, resilient, and scalable network infrastructures and technologies has grown significantly. Real-time bitrate prediction could play a crucial role, offering network observability and bolstering proactive system management. By accurately forecasting bitrate, it becomes possible to implement improvements at either application level or network level, such as swift and appropriate bandwidth adaptation. In this paper, we propose a novel Transformer-based deep learning framework called BitFormer designed to predict the short-term bitrate. Our work is based on extensive traffic data collected under various conditions using two prevalent RTC applications, and our model relies solely on packet-level information, which contains the fundamental traffic characteristics and facilitates effortless feature extraction. Through comprehensive evaluations and comparisons, we achieve a superior accuracy of 74% in identifying peak bitrates, while simultaneously ensuring commendable overall performance. Tailai Song, Gianluca Perna, Paolo Garza, Michela Meo, Maurizio M. Munafò |
CCNC | 5 |
| 2024 | Throughput Prediction in Real-Time Communications: Spotlight on Traffic ExtremesabstractAmidst the thriving advancement of networks, further catalyzed by the COVID-19 pandemic, we have witnessed a marked escalation in the worldwide adoption of Real-Time Communications (RTC) applications. In this context, there is a compelling necessity to cultivate intelligent and robust network infrastructures and technologies. Real-time throughput prediction emerges as a promising candidate for this purpose to foster network observability and provide preemptive functions, supporting advanced system management, e.g., bandwidth allocation and adaptive streaming. Nonetheless, contemporary solutions grapple with predicting extreme conditions in traffic throughput, notably peaks, valleys, and abrupt changes. To address the challenges, we propose a Transformer-based Deep Learning (DL) Neural Network (NN), leveraging solely packet-level information and adopting a multi-task learning paradigm, to predict short-term throughput, with an emphasis on critical values. In particular, our work is grounded in voluminous traffic traces procured from real video-teleconferencing sessions, and we formulate a time-series regression problem, comparing numerous technologies, from an adaptive filter to Machine Learning (ML) and DL approaches. Conclusively, our methodology exhibits superior efficacy, especially in forecasting traffic extremities. Tailai Song, Paolo Garza, Michela Meo, Maurizio M. Munafò |
ISCC | 4 |
| 2024 | Modelling Concurrent RTP Flows for End-to-end Predictions of QoS in Real Time CommunicationsabstractThe Real-time Transport Protocol (RTP)-based real-time communications (RTC) applications, exemplified by video conferencing, have experienced an unparalleled surge in popularity and development in recent years. In pursuit of optimizing their performance, the prediction of Quality of Service (QoS) metrics emerges as a pivotal endeavor, bolstering network monitoring and proactive solutions. However, contemporary approaches are confined to individual RTP flows and metrics, falling short in relationship capture and computational efficiency. To this end, we propose Packet-to-Prediction (P2P), a novel deep learning (DL) framework that hinges on raw packets to simultaneously process concurrent RTP flows and perform end-to-end prediction of multiple QoS metrics. Specifically, we implement a streamlined architecture, namely length-free Transformer with cross and neighbourhood attention, capable of handling an unlimited number of RTP flows, and employ a multi-task learning paradigm to forecast four key metrics in a single shot. Our work is based on extensive traffic collected during real video calls, and conclusively, P2P excels comparative models in both prediction performance and temporal efficiency. Tailai Song, Paolo Garza, Michela Meo, Maurizio M. Munafò |
ISM | 4 |
| 2024 | Towards the Detection of Unobservable Losses in Real-Time CommunicationsabstractPacket loss, an omnipresent issue that degrades the QoE in Real-time Transport Protocol (RTP)-based real-time communications (RTC) applications, serves as a pivotal indicator for gauging network performance. Conventionally, loss detection hinges on sequence number irregularities. However, many contemporary applications incorporate customized mechanisms that diverge from the standard, confounding loss identification. Although the actual losses are transparent to applications themselves, they remain unobservable to other entities such as network operators, hampering the prospect of overall network management and performance optimization. To address this challenge, we investigate multitudinous RTC traffic gathered across various locations and times. Consequently, we uncover two types of anomalous patterns pertaining to sequence numbers. To discern between factual losses and aberrations in RTP flows, i.e., to detect the unobservable losses, we curate three distinct datasets, aggregating packets into time bins and calculating multiple traffic statistics. Subsequently, we leverage Machine Learning (ML) technologies, training the algorithm on one dataset while testing the remaining two, to classify the loss presence in a bin. Despite the inherent hurdles posed by class imbalance and intricate traffic dynamics, we achieve decent outcomes (0.64 Fl-score), effectively identifying the majority of lossy bins (0.64 recall) while guaranteeing the performance for lossless scenarios (0.94 recall). Tailai Song, Paolo Garza, Michela Meo, Maurizio M. Munafò |
LANMAN | 4 |
| 2024 | DeX: Deep learning-based throughput prediction for real-time communications with emphasis on traffic eXtremesabstractRecent years have witnessed a remarkable upsurge in the global proliferation of Real-Time Communications (RTC) applications, a trend propelled by the flourishing advancement of network technologies and further amplified by the COVID-19 pandemic. Within this context, there is a burgeoning interest in the innovation of sophisticated and intelligent network infrastructures and technologies. Positioned as a promising candidate for this purpose, real-time throughput prediction emerges as a key enabler to foster network observability and offer proactive functions, upholding advanced system management, including but not limited to, bandwidth allocation and adaptive streaming. Nonetheless, existing methodologies struggle with predicting extreme conditions of throughput, notably peaks, valleys, and abrupt changes, that are critical in RTC traffic. To surmount these obstacles, we introduce DeX, a Deep Learning (DL)-based framework, designed to predict short-term throughput, with a dexterous proficiency and dedicated focus on navigating the complexities of traffic eXtremes. In particular, DeX leverages solely packet-level information as features and is composed of three integral components: a packet selection module that opts for an optimal subset of input features, a feature extraction block that partially incorporates the Transformer architecture, and a multi-task learning pipeline that improves the proficiency in handling traffic extremes. Moreover, our work is anchored in extensive traffic traces garnered during actual video-teleconferencing calls, and we formulate a time-series regression problem, rigorously evaluating a spectrum of technologies ranging from an adaptive filter to diverse Machine Learning (ML) and DL approaches. Initially, we aim at predicting throughput within 500-ms time windows using historical 1024 packets out of 2048, and consequently, our methodology exhibits exceptional efficacy, especially in forecasting traffic extremities. Conclusively, we conduct a series of ablation experiments and thorough analyses to showcase the enhanced performance of various scenarios, further validating the effectiveness and robustness of DeX. Tailai Song, Paolo Garza, Michela Meo, Maurizio M. Munafò |
Comput. Networks | 4 |
| 2022 | Retina: An open-source tool for flexible analysis of RTC traffic
Gianluca Perna, Dena Markudova, Martino Trevisan, Paolo Garza, Michela Meo, Maurizio M. Munafò |
Comput. Networks | 6 |
| 2022 | Real-Time Classification of Real-Time CommunicationsabstractReal-time communication (RTC) applications have become largely popular in the last decade with the spread of broadband and mobile Internet access. Nowadays, these platforms are a fundamental means for connecting people and supporting businesses that increasingly rely on forms of remote work. In this context, it is of paramount importance to operate at the network level to ensure adequate Quality of Experience (QoE) for users, and appropriate traffic management policies are essential to prioritize RTC traffic. This in turn requires the network to be able to identify RTC streams and the type of content they carry. In this paper, we propose a machine learning-based application to classify media streams generated by RTC applications encapsulated in Secure Real-Time Protocol (SRTP) flows in real-time. Using carefully tuned features extracted from packet characteristics, we train models to classify streams into a variety of classes, including media type (audio/video), video quality, and redundant streams. We validate our approach using traffic from over 62 hours of multi-party meetings conducted using two popular RTC applications, namely Cisco Webex Teams and Jitsi Meet. We achieve an overall accuracy of 96% for Webex and 95% for Jitsi, using a lightweight decision tree model that makes decisions based solely on 1 second of real-time traffic. Our results show that models trained for a particular meeting software have difficulty when used with another one, although domain adaptation techniques facilitate the transfer of pre-trained models. Gianluca Perna, Dena Markudova, Martino Trevisan, Paolo Garza, Michela Meo, Maurizio M. Munafò, Giovanna Carofiglio |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2021 | Online Classification of RTC TrafficabstractReal-time communication (RTC) platforms have become increasingly popular in the last decade, together with the spread of broadband Internet access. They are nowadays a fundamental means for connecting people and supporting the economy, which relies more and more on forms of remote working. In this context, it is particularly important to act at the network level to ensure adequate Quality of Experience (QoE) to users, where proper traffic management policies are essential to prioritize RTC traffic. This, in turn, requires in-network devices to identify RTC streams and the type of content they carry. In this paper, we propose a machine learning-based application to classify, in real-time, the media streams generated by RTC applications encapsulated in Secure Real Time Protocol (SRTP) flows. Using carefully tuned features extracted from packet characteristics, we train a model to classify streams into an ample set of classes, including media type (audio/video), video quality and redundant streams. To validate our approach, we use traffic from more than 88 hours of multi-party meeting calls made using the Cisco Webex Teams application. We reach an overall accuracy of 97% with a light-weight decision tree model, which makes decisions using only 1 second of traffic. Gianluca Perna, Dena Markudova, Martino Trevisan, Paolo Garza, Michela Meo, Maurizio M. Munafò, Giovanna Carofiglio |
CCNC | 6 |
| 2020 | Five Years at the Edge: Watching Internet From the ISP NetworkabstractThe Internet and the way people use it are constantly changing. Knowing traffic is crucial for operating the network, understanding users' needs, and ultimately improving applications. Here, we provide an in-depth longitudinal view of Internet traffic during 5 years (from 2013 to 2017). We take the point of the view of a national-wide ISP and analyze rich flow-level measurements to pinpoint and quantify changes. We observe the traffic, both from a point of view of users and services. We show that an ordinary broadband subscriber downloaded in 2017 more than twice as much as they used to do 5 years before. Bandwidth hungry video services drove this change at the beginning, while recently social messaging applications contribute to increase of data consumption. We study how protocols and service infrastructures evolve over time, highlighting events that may challenge traffic management policies. In the rush to bring servers closer and closer to users, we witness the birth of the sub-millisecond Internet, with caches located directly at ISP edges. The picture we take shows a lively Internet that always evolves and suddenly changes. To support new analyses, we make anonymized data available at https://smartdata.polito.it/five-years-at-the-edge/. Martino Trevisan, Danilo Giordano, Idilio Drago, Maurizio M. Munafò, Marco Mellia |
IEEE/ACM Trans. Netw. | 4 |
| 2019 | Mining Patterns in Mobile Network Logs
Golnazsadat Zargarian, Luca Vassio, Maurizio M. Munafò, Marco Mellia |
IM | 3 |
| 2018 | Five years at the edge: watching internet from the ISP networkabstractThe Internet and the way people use it are constantly changing. Knowing traffic is crucial for operating the network, understanding users' need, and ultimately improving applications. Here, we provide an in-depth longitudinal view of Internet traffic in the last 5 years (from 2013 to 2017). We take the point of the view of a national-wide ISP and analyze flow-level rich measurements to pinpoint and quantify trends. We evaluate the providers' costs in terms of traffic consumption by users and services. We show that an ordinary broadband subscriber nowadays downloads more than twice as much as they used to do 5 years ago. Bandwidth hungry video services drive this change, while social messaging applications boom (and vanish) at incredible pace. We study how protocols and service infrastructures evolve over time, highlighting unpredictable events that may hamper traffic management policies. In the rush to bring servers closer and closer to users, we witness the birth of the sub-millisecond Internet, with caches located directly at ISP edges. The picture we take shows a lively Internet that always evolves and suddenly changes. Martino Trevisan, Danilo Giordano, Idilio Drago, Marco Mellia, Maurizio M. Munafò |
CoNEXT | 5 |
| 2017 | Automatic detection of DNS manipulationsabstractThe DNS is a fundamental service that has been repeatedly attacked and abused. DNS manipulation is a prominent case: Recursive DNS resolvers are deployed to explicitly return manipulated answers to users' queries. While DNS manipulation is used for legitimate reasons too (e.g., parental control), rogue DNS resolvers support malicious activities, such as malware and viruses, exposing users to phishing and content injection. We introduce REMeDy, a system that assists operators to identify the use of rogue DNS resolvers in their networks. REMeDy is a completely automatic and parameter-free system that evaluates the consistency of responses across the resolvers active in the network. It operates by passively analyzing DNS traffic and, as such, requires no active probing of third-party servers. REMeDy is able to detect resolvers that manipulate answers, including resolvers that affect unpopular domains. We validate REMeDy using large-scale DNS traces collected in ISP networks where more than 100 resolvers are regularly used by customers. REMeDy automatically identifies regular resolvers, and pinpoint manipulated responses. Among those, we identify both legitimate services that offer additional protection to clients, and resolvers under the control of malwares that steer traffic with likely malicious goals. Martino Trevisan, Idilio Drago, Marco Mellia, Maurizio M. Munafò |
IEEE BigData | 4 |
| 2016 | Towards web service classification using addresses and DNSabstractThe identification of the services that generate traffic is crucial for ISPs and companies to plan and monitor the network. The widespread deployment of encryption and the convergence of the web services towards HTTP/HTTPS challenge traditional classification techniques. Algorithms to classify traffic are left with little information, such as server IP addresses, flow characteristics and queries performed at the DNS. Moreover, due to the usage of Content Delivery Networks and cloud infrastructure, it is unclear whether such coarse metadata is sufficient to differentiate the traffic. This paper studies to what extent basic information visible at flow-level measurements is useful for traffic classification on the web. By analyzing a large dataset of flow measurements, we quantify how often the same server IP address is used by different services, and how services use hostnames. Our results show that a very simple classifier that relies only on server IP addresses and on lists of hostnames can distinguish up to 55% of the traffic volume. Yet, collisions of names and addresses are common among popular services, calling for more ingenuity. This paper is a preliminary step in the evaluation of classification algorithms that are suitable for the modern Internet, where only minimal metadata collection will be possible in the network. Martino Trevisan, Idilio Drago, Marco Mellia, Maurizio M. Munafò |
IWCMC | 4 |
| 2016 | Statistical network monitoring: Methodology and application to carrier-grade NAT
Enrico Bocchi, Ali Safari Khatouni, Stefano Traverso, Alessandro Finamore, Maurizio M. Munafò, Marco Mellia, Dario Rossi 0001 |
Comput. Networks | 5 |
| 2016 | Towards automatic protocol field inference
Ignacio Bermudez, Alok Tongaonkar, Marios Iliofotou, Marco Mellia, Maurizio M. Munafò |
Comput. Commun. | 5 |
| 2015 | Impact of Carrier-Grade NAT on web browsingabstractPublic IPv4 addresses are a scarce resource. While IPv6 adoption is lagging, Network Address Translation (NAT) technologies have been deployed over the last years to alleviate IPv4 exiguity and their high rental cost. In particular, Carrier-Grade NAT (CGN) is a well known solution to mask a whole ISP network behind a limited amount of public IP addresses, significantly reducing expenses. Enrico Bocchi, Ali Safari Khatouni, Stefano Traverso, Alessandro Finamore, Valeria Di Gennaro, Marco Mellia, Maurizio M. Munafò, Dario Rossi 0001 |
IWCMC | 7 |
| 2015 | Automatic protocol field inference for deeper protocol understandingabstractSecurity tools have evolved dramatically in the recent years to combat the increasingly complex nature of attacks, but to be effective these tools need to be configured by experts that understand network protocols thoroughly. In this paper we present FieldHunter, which automatically extracts fields and infers their types; providing this much needed information to the security experts for keeping pace with the increasing rate of new network applications and their underlying protocols. FieldHunter relies on collecting application messages from multiple sessions and then applying statistical correlations is able to infer the types of the fields. These statistical correlations can be between different messages or other associations with meta-data such as message length, client or server IPs. Our system is designed to extract and infer fields from both binary and textual protocols. We evaluated FieldHunter on real network traffic collected in ISP networks from three different continents. FieldHunter was able to extract security relevant fields and infer their nature for well documented network protocols (such as DNS and MSNP) as well as protocols for which the specifications are not publicly available (such as SopCast) and from malware such as (Ramnit). Ignacio Bermudez, Alok Tongaonkar, Marios Iliofotou, Marco Mellia, Maurizio M. Munafò |
Networking | 5 |
| 2014 | The Cost of the "S" in HTTPSabstractIncreased user concern over security and privacy on the Internet has led to widespread adoption of HTTPS, the secure version of HTTP. HTTPS authenticates the communicating end points and provides confidentiality for the ensuing communication. However, as with any security solution, it does not come for free. HTTPS may introduce overhead in terms of infrastructure costs, communication latency, data usage, and energy consumption. Moreover, given the opaqueness of the encrypted communication, any in-network value added services requiring visibility into application layer content, such as caches and virus scanners, become ineffective. David Naylor, Alessandro Finamore, Ilias Leontiadis, Yan Grunenberger, Marco Mellia, Maurizio M. Munafò, Konstantina Papagiannaki, Peter Steenkiste |
CoNEXT | 6 |
| 2014 | A Distributed Architecture for the Monitoring of Clouds and CDNs: Applications to Amazon AWSabstractClouds and CDNs are systems that tend to separate the content being requested by users from the physical servers capable of serving it. From the network point of view, monitoring and optimizing performance for the traffic they generate are challenging tasks, given that the same resource can be located in multiple places, which can, in turn, change at any time. The first step in understanding cloud and CDN systems is thus the engineering of a monitoring platform. In this paper, we propose a novel solution that combines passive and active measurements and whose workflow has been tailored to specifically characterize the traffic generated by cloud and CDN infrastructures. We validate our platform by performing a longitudinal characterization of the very well known cloud and CDN infrastructure provider Amazon Web Services (AWS). By observing the traffic generated by more than 50 000 Internet users of an Italian Internet Service Provider, we explore the EC2, S3, and CloudFront AWS services, unveiling their infrastructure, the pervasiveness of web services they host, and their traffic allocation policies as seen from our vantage points. Most importantly, we observe their evolution over a two-year-long period. The solution provided in this paper can be of interest for the following: 1) developers aiming at building measurement tools for cloud infrastructure providers; 2) developers interested in failure and anomaly detection systems; and 3) third-party service-level agreement certificators who can design systems to independently monitor performance. Finally, we believe that the results about AWS presented in this paper are interesting as they are among the first to unveil properties of AWS as seen from the operator point of view. Ignacio Bermudez, Stefano Traverso, Maurizio M. Munafò, Marco Mellia |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2013 | TUCAN: Twitter user centric ANalyzerabstractTwitter has attracted millions of users that generate a humongous flow of information at constant pace. The research community has thus started proposing tools to extract meaningful information from tweets. In this paper, we take a different angle from the mainstream of previous works: we explicitly target the analysis of the timeline of tweets from "single users". We define a framework - named TUCAN - to compare information offered by the target users over time, and to pinpoint recurrent topics or topics of interest. First, tweets belonging to the same time window are aggregated into "bird songs". Several filtering procedures can be selected to remove stop-words and reduce noise. Then, each pair of bird songs is compared using a similarity score to automatically highlight the most common terms, thus highlighting recurrent or persistent topics. TUCAN can be naturally applied to compare bird song pairs generated from timelines of different users. Luigi Grimaudo, Han Hee Song, Mario Baldi, Marco Mellia, Maurizio M. Munafò |
ASONAM | 5 |
| 2013 | Exploring the cloud from passive measurements: The Amazon AWS caseabstractThis paper presents a characterization of Amazon's Web Services (AWS), the most prominent cloud provider that offers computing, storage, and content delivery platforms. Leveraging passive measurements, we explore the EC2, S3 and CloudFront AWS services to unveil their infrastructure, the pervasiveness of content they host, and their traffic allocation policies. Measurements reveal that most of the content residing on EC2 and S3 is served by one Amazon datacenter, located in Virginia, which appears to be the worst performing one for Italian users. This causes traffic to take long and expensive paths in the network. Since no automatic migration and load-balancing policies are offered by AWS among different locations, content is exposed to the risks of outages. The CloudFront CDN, on the contrary, shows much better performance thanks to the effective cache selection policy that serves 98% of the traffic from the nearest available cache. CloudFront exhibits also dynamic load-balancing policies, in contrast to the static allocation of instances on EC2 and S3. Information presented in this paper will be useful for developers aiming at entrusting AWS to deploy their contents, and for researchers willing to improve cloud design. Ignacio Bermudez, Stefano Traverso, Marco Mellia, Maurizio M. Munafò |
INFOCOM | 4 |
| 2013 | Characterization of community based-P2P systems and implications for traffic localization
Ruben Torres, Marco Mellia, Maurizio M. Munafò, Sanjay G. Rao |
Peer-to-Peer Netw. Appl. | 3 |
| 2012 | DNS to the rescue: discerning content and services in a tangled webabstractA careful perusal of the Internet evolution reveals two major trends - explosion of cloud-based services and video streaming applications. In both of the above cases, the owner (e.g., CNN, YouTube, or Zynga) of the content and the organization serving it (e.g., Akamai, Limelight, or Amazon EC2) are decoupled, thus making it harder to understand the association between the content, owner, and the host where the content resides. This has created a tangled world wide web that is very hard to unwind, impairing ISPs' and network administrators' capabilities to control the traffic flowing in their networks. Ignacio Bermudez, Marco Mellia, Maurizio M. Munafò, Ram Keralapura, Antonio Nucci |
Internet Measurement Conference | 3 |
| 2012 | Inside dropbox: understanding personal cloud storage servicesabstractPersonal cloud storage services are gaining popularity. With a rush of providers to enter the market and an increasing offer of cheap storage space, it is to be expected that cloud storage will soon generate a high amount of Internet traffic. Very little is known about the architecture and the performance of such systems, and the workload they have to face. This understanding is essential for designing efficient cloud storage systems and predicting their impact on the network. Idilio Drago, Marco Mellia, Maurizio M. Munafò, Anna Sperotto, Ramin Sadre, Aiko Pras |
Internet Measurement Conference | 3 |
| 2012 | Characterization of ISP Traffic: Trends, User Habits, and Access Technology ImpactabstractIn the recent years, the research community has increased its focus on network monitoring which is seen as a key tool to understand the Internet and the Internet users. Several studies have presented a deep characterization of a particular application, or a particular network, considering the point of view of either the ISP, or the Internet user. In this paper, we take a different perspective. We focus on three European countries where we have been collecting traffic for more than a year and a half through 5 vantage points with different access technologies. This humongous amount of information allows us not only to provide precise, multiple, and quantitative measurements of "What the user do with the Internet" in each country but also to identify common/uncommon patterns and habits across different countries and nations. Considering different time scales, we start presenting the trend of application popularity; then we focus our attention to a one-month long period, and further drill into a typical daily characterization of users activity. Results depict an evolving scenario due to the consolidation of new services as Video Streaming and File Hosting and to the adoption of new P2P technologies. Despite the heterogeneity of the users, some common tendencies emerge that can be leveraged by the ISPs to improve their service. José Luis García-Dorado, Alessandro Finamore, Marco Mellia, Michela Meo, Maurizio M. Munafò |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2012 | The internet-wide impact of P2P traffic localization on ISP profitabilityabstractWe conduct a detailed simulation study to examine how localizing P2P traffic within network boundaries impacts the profitability of an ISP. A distinguishing aspect of our work is the focus on Internet-wide implications, i.e., how adoption of localization within an ISP affects both itself and other ISPs. Our simulations are based on detailed models that estimate inter-autonomous-system (AS) P2P traffic and inter-AS routing, localization models that predict the extent to which P2P traffic is reduced, and pricing models that predict the impact of changes in traffic on the profit of an ISP. We evaluate our models by using a large-scale crawl of BitTorrent containing over 138 million users sharing 2.75 million files. Our results show that the benefits of localization must not be taken for granted. Some of our key findings include: 1) residential ISPs can actually lose money when localization is employed, and some of them will not see increased profitability until other ISPs employ localization; 2) the reduction in costs due to localization will be limited for small ISPs and tends to grow only logarithmically with client population; and 3) some ISPs can better increase profitability through alternate strategies to localization by taking advantage of the business relationships they have with other ISPs. Jeff Seibert, Ruben Torres, Marco Mellia, Maurizio M. Munafò, Cristina Nita-Rotaru, Sanjay G. Rao |
IEEE/ACM Trans. Netw. | 4 |
| 2011 | Predicting ADSL Lines Data Rate Using Neural NetworkabstractAsymmetric Digital Subscriber Line - ADSL - technology is the preferred high-speed access to the Internet, offering up to 24Mb/s on downlink channels. Exploiting the copper media already deployed by Telecom Operators, physical link quality often limits the maximum ADSL data rate, so that the actual bitrate of a line is often unpredictable. In this work, we analyze a large set of end-users' ADSL links, and try to correlate the effective bitrate with the physical measurements exposed by network devices. By exploiting a Neural Network (NN) predictor, we acquire knowledge about the behavior of ADSL lines from the huge amount of measured data. We show that NNs are good tools to automatically predict end-users' ADSL available bandwidth. However some ingenuity is required to guide the learning phase and to avoid misbehaving lines to fool the NN prediction. Florin Bota, Faheem Khuhawar, Marco Mellia, Maurizio M. Munafò |
GLOBECOM | 4 |
| 2011 | Dissecting Video Server Selection Strategies in the YouTube CDNabstractIn this paper, we conduct a detailed study of the YouTube CDN with a view to understanding the mechanisms and policies used to determine which data centers users download video from. Our analysis is conducted using week-long datasets simultaneously collected from the edge of five networks - two university campuses and three ISP networks - located in three different countries. We employ state-of-the-art delay-based geolocation techniques to find the geographical location of YouTube servers. A unique aspect of our work is that we perform our analysis on groups of related YouTube flows. This enables us to infer key aspects of the system design that would be difficult to glean by considering individual flows in isolation. Our results reveal that while the RTT between users and data centers plays a role in the video server selection process, a variety of other factors may influence this selection including load-balancing, diurnal effects, variations across DNS servers within a network, limited availability of rarely accessed video, and the need to alleviate hot-spots that may arise due to popular video content. Ruben Torres, Alessandro Finamore, Jin Ryong Kim, Marco Mellia, Maurizio M. Munafò, Sanjay G. Rao |
ICDCS | 5 |
| 2011 | YouTube everywhere: impact of device and infrastructure synergies on user experienceabstractIn this paper we present a complete measurement study that compares YouTube traffic generated by mobile devices (smart-phones,tablets) with traffic generated by common PCs (desktops, notebooks, netbooks). We investigate the users' behavior and correlate it with the system performance. Our measurements are performed using unique data sets which are collected from vantage points in nation-wide ISPs and University campuses from two countries in Europe and the U.S. Alessandro Finamore, Marco Mellia, Maurizio M. Munafò, Ruben Torres, Sanjay G. Rao |
Internet Measurement Conference | 3 |
| 2009 | Web user-session inference by means of clustering techniques
Andrea Bianco, Gianluca Mardente, Marco Mellia, Maurizio M. Munafò, Luca Muscariello |
IEEE/ACM Trans. Netw. | 4 |
| 2007 | DoWitcher: Effective Worm Detection and Containment in the Internet CoreabstractEnterprise networks are increasingly offloading the responsibility for worm detection and containment to the carrier networks. However, current approaches to the zero-day worm detection problem such as those based on content similarity of packet payloads are not scalable to the carrier link speeds (OC-48 and up-wards). In this paper, we introduce a new system, namely DoWitcher, which in contrast to previous approaches is scalable as well as able to detect the stealthiest worms that employ low-propagation rates or polymorphisms to evade detection. DoWitcher uses an incremental approach toward worm detection: First, it examines the layer-4 traffic features to discern the presence of a worm anomaly; Next, it determines a flow-filter mask that can be applied to isolate the suspect worm flows and; Finally, it enables full-packet capture of only those flows that match the mask, which are then processed by a longest common subsequence algorithm to extract the worm content signature. Via a proof-of-concept implementation on a commercially available network analyzer processing raw packets from an OC-48 link, we demonstrate the capability of DoWitcher to detect low-rate worms and extract signatures for even the polymorphic worms. Supranamaya Ranjan, Shaleen Shah, Antonio Nucci, Maurizio M. Munafò, Rene L. Cruz, S. Muthukrishnan 0001 |
INFOCOM | 4 |
| 2006 | Selected papers from the 3rd international workshop on QoS in multiservice IP networks (QoS-IP 2005)
Giuseppe Bianchi 0001, Marco Listanti, Michela Meo, Maurizio M. Munafò |
Comput. Networks | 4 |
| 2005 | Web user session characterization via clustering techniquesabstractWe focus on the identification and definition of "Web user-sessions", an aggregation of several TCP connections generated by the same source host on the basis of TCP connection opening time. The identification of a user session is non trivial; traditional approaches rely on threshold based mechanisms, which are very sensitive to the value assumed for the threshold and may be difficult to correctly set. By applying clustering techniques, we define a novel methodology to identify Web user-sessions without requiring an a priori definition of threshold values. We analyze the characteristics of user sessions extracted from real traces, studying the statistical properties of the identified sessions. From the study it emerges that Web user-sessions tend to be Poisson, but correlation may arise during periods of network/hosts anomalous functioning. Andrea Bianco, Gianluca Mardente, Marco Mellia, Maurizio M. Munafò, Luca Muscariello |
GLOBECOM | 4 |
| 2004 | Selected papers from the Second International Workshop on QoS in Multiservice IP Networks (QoS-IP 2003)
Marco Ajmone Marsan, Michela Meo, Maurizio M. Munafò |
Comput. Networks | 3 |
| 2003 | A new class of QoS routing strategies based on network graph reduction
Claudio Casetti, Renato Lo Cigno, Marco Mellia, Maurizio M. Munafò, Zoltán Zsóka |
Comput. Networks | 4 |
| 2002 | Design of optical packet switching networksabstractThe paper considers optical packet switching networks with slotted operation. A general model of network nodes is introduced, based upon a nonblocking switching fabric, and re-circulating fiber delay lines to solve contentions. Given the current large bandwidth availability in optical networks, and the projected limitations of electronic switches, a new approach to network design is proposed, aiming at balancing wavelength and buffer allocation taking the number of switch ports as a constraint. Given the problem complexity, a heuristic solution is proposed, using simple queuing theory to model network links. The effectiveness of the new network dimensioning approach is demonstrated by running a simulation program on manually dimensioned topologies, and on topologies dimensioned using the proposed approach. Andrea Bianco, Emilio Leonardi, Maurizio M. Munafò, Fabio Neri, W. Picco |
GLOBECOM | 3 |
| 2002 | A New Class of QoS Routing Strategies Based on Network Graph ReductionabstractThis paper discusses a new approach to QoS routing, introducing the notion of algorithm resilience (i.e., its capability to adapt to network and load modifications) as the performance index of the algorithm itself, for a given network topology, load and traffic pattern. The new approach can be summarized as network graph reduction, i.e., a modification of the graph describing the network before the routing path is computed, in order to exclude from the path selection over-congested portions of the network. This solution leads to a class of two-step routing algorithms, where both steps are simple, hence allowing efficient implementation. Simulation experiments, run on randomly-generated topologies and traffic patterns, show that these routing algorithms outperform both the standard minimum hop algorithm and those QoS-based algorithms based on the same metrics but not using the notion of network graph reduction. Claudio Casetti, Renato Lo Cigno, Marco Mellia, Maurizio M. Munafò, Zoltán Zsóka |
INFOCOM | 4 |
| 2001 | A realistic model to evaluate routing algorithms in the InternetabstractThis paper addresses the problem of evaluating routing algorithms via simulation in packet-switched networks when elastic traffic is involved. It highlights some deficiencies of classical approaches that fail to capture both the complex interactions of connections traversing multiple bottlenecks and common user behaviors. The paper describes an approach devised to overcome these limitations which is particularly suited for the evaluation of routing algorithms in presence of best-effort traffic. The simulation results presented offer a deeper insight into well-known routing algorithms. Through this analysis it is clear that quantitative and also qualitative behaviors of dynamic routing algorithms based on traffic measurements may be fairly different depending on the nature of the traffic loading the network, as well as depending on its interactions with the network parameters and behavior. Claudio Casetti, Renato Lo Cigno, Marco Mellia, Maurizio M. Munafò, Zoltán Zsóka |
GLOBECOM | 4 |
| 2001 | Supporting TCP connections in wormhole routing and ATM networks
Andrea Bianco, Emilio Leonardi, Maurizio M. Munafò, Fabio Neri |
Comput. Commun. | 3 |
| 2001 | Local and Global Handovers Based on In-Band Signaling in Wireless ATM Networks
Marco Ajmone Marsan, Carla Fabiana Chiasserini, Andrea Fumagalli, Renato Lo Cigno, Maurizio M. Munafò |
Wirel. Networks | 5 |
| 1998 | An integrated simulation environment for the analysis of ATM networks at multiple time scales
Marco Ajmone Marsan, Andrea Bianco, Claudio Casetti, Carla Fabiana Chiasserini, Andrea Francini, Renato Lo Cigno, Maurizio M. Munafò |
Comput. Networks ISDN Syst. | 7 |
| 1995 | ATM Simulation with CLASS
Marco Ajmone Marsan, Andrea Bianco, Tien Van Do 0001, László Jereb, Renato Lo Cigno, Maurizio M. Munafò |
Perform. Evaluation | 6 |