VLDB 2026 Research / reviewers in the wild / expert
Guerino Lamanna
dblp:67/7910
· DBLP profile ↗
6ranked-venue papers
0as first author
3since 2021 · last 2022
0000-0002-6930-4227ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 2 since 2021Computer networks · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Evaluation of the data handling pipeline of the ASTRID frameworkabstractEffective attack detection and security analytics rely on the availability of timely and fine-grained information about the evolving context of the protected environment. The data handling process entails collection from heterogeneous sources, local aggregation and transformation operations before transmission, and finally collection and delivery to multiple processing engines for analysis and correlation. Many Security Information and Event Management (SIEM) tools work according to the “funnel” principle: gather as much data as possible and then filter it to keep the relevant information. However, this might lead to unacceptable overhead, especially when monitoring containerized environments. As part of our activity in ASTRID, we therefore conducted experimental investigation on resource consumption of the data handling pipeline, starting from embedded agents up to delivery to the Context Broker. Matteo Repetto, Guerino Lamanna |
NetSoft | 2 |
| 2022 | Automating Mitigation of Amplification Attacks in NFV ServicesabstractThe combination of virtualization techniques with capillary computing and storage resources allows the instantiation of Virtual Network Functions throughout the network infrastructure, which brings more agility in the development and operation of network services. Beside forwarding and routing, this can be also used for additional functions, e.g., for security purposes. In this paper, we present a framework to systematically create security analytics for virtualized network services, specifically targeting the detection of cyber-attacks. Our framework largely automates the deployment of security sidecars into existing service templates and their interconnection to an external analytics platform. Notably, it leverages code augmentation techniques to dynamically inject and remove inspection probes without affecting service operation. We describe the implementation of a use case for the detection of DNS amplification attacks in virtualized 5G networks, and provide extensive evaluation of our innovative inspection and detection mechanisms. Our results demonstrate better efficiency with respect to existing network monitoring tools in terms of CPU usage, as well as good accuracy in detecting attacks even with variable traffic patterns. Matteo Repetto, Gianmarco Bruno, Jalolliddin Yusupov, Guerino Lamanna, Benjamin Ertl, Alessandro Carrega |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2021 | Leveraging the 5G architecture to mitigate amplification attacksabstractVolumetric (Distributed) Denial of Service attacks remain one of the major threats for any organization, capable of saturating most Internet access links through the usage of botnets and amplification techniques. The only effective mitigation mechanism today is the redirection of the network traffic towards scrubbing centers; this protects the Internet pipe of the victim, but does not prevent wasting resources in other parts of the network.In this paper, we leverage the cloud-native design of the 5G architecture to monitor traffic statistics at the edge of the network, which are then processed by a powerful Analytics ToolKit (ATk). Our work is based on the framework designed by the ASTRID project, which allows to automatically change the inspection probes while chasing a better balance between the granularity of the collected data and the overhead. We demonstrate our approach for an NTP amplification attack; the ATk is first trained with historical data and then used to detect deviations from the expected traffic profile, by switching between normal/warning/alert states. Our preliminary results show that it can correctly distinguish between periodical fluctuations of requests and attacks and tolerate a few data losses. Matteo Repetto, Alessandro Carrega, Guerino Lamanna, Jalolliddin Yusupov, Orazio Toscano, Gianmarco Bruno, Michele Nuovo, Marco Cappelli |
NetSoft | 3 |
| 2020 | Enabling Edge Computing Deployment in 4G and BeyondabstractWhile the integration of fourth-generation (4G) networks with Edge Computing technologies would anticipate the improvements foreseen by the coming of 5G, as well as smoothen the transition to the new technology, 4G does not natively support Edge Computing. Therefore, specific functionalities for user-plane integration and isolation of tenant spaces are required for effectively deploying Edge Computing in 4G networks. This paper describes the design of the end-point between the mobile and edge environments that has been integrated in the telecom layer platform of the MATILDA Project. Such end-point, designed in a Virtual Network Function (VNF), allows intercepting and forwarding data and control traffic towards external Data Networks. Instances of this VNF can be horizontally scaled according to a decision policy, which determines the minimum number of instances required for the current load. Results show that the latency ascribable to the VNF processing is sufficiently low to satisfy the delay budget for all 5G use cases up to 10 ms and that the decision policy based on the QoS Class Identifiers (QCIs) allows scaling with the traffic load, while still fulfilling the performance requirements of each application. Roberto Bruschi, Franco Davoli, Guerino Lamanna, Chiara Lombardo, Sergio Mangialardi, Jane Frances Pajo |
NetSoft | 3 |
| 2017 | A framework to correlate power consumption and resource usage in cloud infrastructuresabstractThe increasing demand of cloud services has rapidly raised the size of data centers, and consequently their power consumption. Data centers are usually over-sized, to be ready for further business increase; further, today many infrastructures are build as federation of multiple sites, to place the workload next to the user. Effective energy management policies are required in place to modulate power consumption according to the processing load to effectively tackle the dynamic fluctuations in workload. In this regard, service orchestrators and multi- and cross-cloud energy management systems need proper tools to understand how power consumption of cloud components would change with different placement decisions, both in the single as well as in federated clouds. In this paper, we describe a framework for drawing the relationship between resource usage such as CPU, memory and disk and energy consumption. Our work builds on the availability of both resource usage and power consumption measurements in Cloud Management Software, and makes proper correlation between these values to effectively support energy-efficiency strategies. Divya Kanapram, Riccardo Rapuzzi, Guerino Lamanna, Matteo Repetto |
NetSoft | 3 |
| 2009 | DROP: An Open-Source Project towards Distributed SW Router ArchitecturesabstractIn this work, our main objective is to explore how Software Routers (SRs) can deploy advanced and flexible paradigms for supporting novel control plane functionalities and applications. To this purpose, we investigate and study a new open-source SW framework, namely Distributed SW ROuter Project (DROP), which aims at developing and enabling a novel distributed paradigm for IP-router control and management. DROP is partially based on the main guidelines of the IETF ForCES standard, and it allows building logical network nodes through the aggregation of multiple SRs, which can be devoted to packet forwarding or control operations. In addition to the original ForCES design, DROP will aim at extending router distribution and aggregation concepts by moving them at a network-wide scale in order to enable and to support value-added services for next-generation networks. Raffaele Bolla, Roberto Bruschi, Guerino Lamanna, Andrea Ranieri |
GLOBECOM | 3 |