Alessandro Carrega

dblp:69/11510 · DBLP profile ↗
← Back
14ranked-venue papers
5as first author
8since 2021 · last 2025
0000-0002-5944-7582ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 B5G/6G Cyber Security Testbed
abstract
The evolution of mobile communication technologies to Beyond 5G (B5G) and Sixth-Generation (6 G) introduces significant advancements but also new cybersecurity vulnerabilities. This paper details the National Inter-university Consortium for Telecommunications (CNIT) National Laboratory of Smart and Secure Networks (S2N) testbed in Genoa, Italy, a state-of-the-art facility for research and development in B5G/6G technologies with a focus on cybersecurity. The testbed’s modular architecture, including isolated “islands” and advanced HardWare/SoftWare (HW/SW), enables the simulation and analysis of cyber threats like Application Programming Interface (API) exposure, and Distributed Denial of Service (DDoS) attacks. It supports the testing of security measures, including Artificial Intelligence (AI)/Machine Learning (ML)-based solutions, and facilitates comprehensive vulnerability assessments and penetration testing for next-generation networks.
Alessandro Carrega, Franco Davoli, Ramin Rabbani
MASCOTS1
2024 Efficient. Reliable and Secure Framework for the 5G Virtualization of the UltraSound Medical System
abstract
The virtualization of UltraSound (US) medical imaging systems through cloud-edge computing offers a transformative approach to healthcare, overcoming limitations of traditional on-premises systems. By dematerializing US system functions and migrating them to the cloud, barriers related to hardware and localization are eliminated, enabling a more agile and scalable approach to medical imaging. This paradigm shift leverages virtual objects and composite virtual objects to intelligently manage and orchestrate physical and virtual components, optimizing system performance and meeting service requirements.
Alessandro Carrega, Roberto Bruschi, Raffaele Bolla, Antonio Passalacqua
HealthCom1
2022 Trading off Power Consumption and Delay in the Execution of Network Functions by Dynamic Activation of Processing Units
abstract
Beside increasing flexibility and programmability, the current network “softwarization” trend is believed to be beneficial also in respect of energy efficiency, owing to the consolidation of resources made possible by virtualized networking components. However, the widespread use of general-purpose hardware may jeopardize energy saving, unless proper control strategies are put in operation. In this context, the paper addresses a “smart sleeping” control problem, where computing resources in multi-core processors executing network functions are modelled as multi-server queues, and the number of active processing units (either physical or virtual) can be dynamically adjusted by parametric control over a time scale compatible with the long-term dynamics of the traffic flows that require processing. We show that, on average, up to 25% of processing capacity of a network node can be turned off in the presence of bursty traffic with low load without significantly affecting packet latency.
Raffaele Bolla, Roberto Bruschi, Alessandro Carrega, Franco Davoli, Chiara Lombardo
NetSoft3
2022 Automating Mitigation of Amplification Attacks in NFV Services
abstract
The combination of virtualization techniques with capillary computing and storage resources allows the instantiation of Virtual Network Functions throughout the network infrastructure, which brings more agility in the development and operation of network services. Beside forwarding and routing, this can be also used for additional functions, e.g., for security purposes. In this paper, we present a framework to systematically create security analytics for virtualized network services, specifically targeting the detection of cyber-attacks. Our framework largely automates the deployment of security sidecars into existing service templates and their interconnection to an external analytics platform. Notably, it leverages code augmentation techniques to dynamically inject and remove inspection probes without affecting service operation. We describe the implementation of a use case for the detection of DNS amplification attacks in virtualized 5G networks, and provide extensive evaluation of our innovative inspection and detection mechanisms. Our results demonstrate better efficiency with respect to existing network monitoring tools in terms of CPU usage, as well as good accuracy in detecting attacks even with variable traffic patterns.
Matteo Repetto, Gianmarco Bruno, Jalolliddin Yusupov, Guerino Lamanna, Benjamin Ertl, Alessandro Carrega
IEEE Trans. Netw. Serv. Manag.6
2021 Feature Selection Evaluation towards a Lightweight Deep Learning DDoS Detector
abstract
Today’s networks and services undoubtedly require a high level of protection from cyber threats and attacks. State-of-the-art solutions that implement Machine Learning (ML) have shown to improve the accuracy and confidence in threat detection compared to previous approaches, making it suitable for detecting today’s sophisticated attacks such as Distributed Denial of Service (DDoS). However, in real-world deployments, input data streams take large bandwidth and processing capacity, especially for Deep Learning (DL) solutions that require extensive input data. On the other hand, deployment environments usually have limited bandwidth and computing resources, such as in the Internet of Things (IoT). Thus, a lightweight detection solution that satisfies such constraints is needed. In this paper, we utilize a feature reduction approach for our DL-based DDoS detector based on the Analysis of Variance (ANOVA), which is used to identify important data features and reduce the data inputs needed for detection. Our result shows that we can reduce the data input needed by up to 84.21% while only reducing 0.1% detection accuracy. We also provide a detailed analysis of the characteristics of DDoS attacks using ANOVA and compared our work with recent DL-based DDoS detection systems to demonstrate that our results are comparable to existing approaches.
Odnan Ref Sanchez, Matteo Repetto, Alessandro Carrega, Raffaele Bolla, Jane Frances Pajo
ICC3
2021 Leveraging the 5G architecture to mitigate amplification attacks
abstract
Volumetric (Distributed) Denial of Service attacks remain one of the major threats for any organization, capable of saturating most Internet access links through the usage of botnets and amplification techniques. The only effective mitigation mechanism today is the redirection of the network traffic towards scrubbing centers; this protects the Internet pipe of the victim, but does not prevent wasting resources in other parts of the network.In this paper, we leverage the cloud-native design of the 5G architecture to monitor traffic statistics at the edge of the network, which are then processed by a powerful Analytics ToolKit (ATk). Our work is based on the framework designed by the ASTRID project, which allows to automatically change the inspection probes while chasing a better balance between the granularity of the collected data and the overhead. We demonstrate our approach for an NTP amplification attack; the ATk is first trained with historical data and then used to detect deviations from the expected traffic profile, by switching between normal/warning/alert states. Our preliminary results show that it can correctly distinguish between periodical fluctuations of requests and attacks and tolerate a few data losses.
Matteo Repetto, Alessandro Carrega, Guerino Lamanna, Jalolliddin Yusupov, Orazio Toscano, Gianmarco Bruno, Michele Nuovo, Marco Cappelli
NetSoft2
2021 Evaluating ML-based DDoS Detection with Grid Search Hyperparameter Optimization
abstract
Distributed Denial of Service (DDoS) attacks disrupt global network services by mainly overwhelming the victim host with requests originating from multiple traffic sources. DDoS attacks are currently on the rise due to the ease of execution and rental of distributed architectures such as the Internet of Things (IoT) and cloud infrastructures, which could potentially result in substantial revenue losses. Therefore, the detection and prevention of DDoS attacks are currently topics of high interest. In this study, we use traffic flow information to determine if a specific flow is associated with a DDoS attack. We used traditional Machine Learning (ML) methods in developing our DDoS detector and applied an exhaustive hyperparameter search to optimize their detection capability. Using lightweight approaches is suitable for resource-constrained environments such as IoT to reduce computing overhead. Our evaluation shows that most algorithms provide satisfactory results, with Random Forests achieving as high as 99% of detection accuracy, which is similar to the performance of current deep learning solutions for DDoS detection.
Odnan Ref Sanchez, Matteo Repetto, Alessandro Carrega, Raffaele Bolla
NetSoft3
2021 An architecture to manage security operations for digital service chains
Matteo Repetto, Alessandro Carrega, Riccardo Rapuzzi
Future Gener. Comput. Syst.2
2020 Programmable Data Gathering for Detecting Stegomalware
abstract
The “arm race” against malware developers requires to collect a wide variety of performance measurements, for instance to face threats leveraging information hiding and steganography. Unfortunately, this process could be time-consuming, lack of scalability and cause performance degradations within computing and network nodes. Moreover, since the detection of steganographic threats is poorly generalizable, being able to collect attack-independent indicators is of prime importance. To this aim, the paper proposes to take advantage of the extended Berkeley Packet Filter to gather data for detecting stegomalware. To prove the effectiveness of the approach, it also reports some preliminary experimental results obtained as the joint outcome of two H2020 Projects, namely ASTRID and SIMARGL.
Alessandro Carrega, Luca Caviglione, Matteo Repetto, Marco Zuppelli
NetSoft1
2020 Coupling energy efficiency and quality for consolidation of cloud workloads
Alessandro Carrega, Matteo Repetto
Comput. Networks1
2019 Energy efficiency for edge multimedia elastic applications
Alessandro Carrega, Giancarlo Portomauro, Matteo Repetto, Giorgio Robino
Multim. Tools Appl.1
2014 A Closed-Form Model for the IEEE 802.3az Network and Power Performance
abstract
We propose an analytical model able to accurately estimate both power consumption and network performance indexes of Energy Efficient Ethernet (EEE) links working at the three available speeds under various traffic load patterns and packet size distributions. The model is sufficiently flexible and accurate to consider different traffic parameters; among others, the packet size distribution, the average burst inter-arrival rate, the burst size distribution, etc. With relatively low complexity, since it addresses stationary queue behavior, the analysis allows obtaining the average energy consumption of the link and, unlike previous works, the mean latency time experienced by incoming packets in closed form, without any upper or lower bound approximations. This aspect makes the model suitable to be adopted in optimization frameworks for network design and control purposes. The numerical results of the model are validated against measurements on a real test bench.
Raffaele Bolla, Roberto Bruschi, Alessandro Carrega, Franco Davoli, Paolo Lago
IEEE J. Sel. Areas Commun.3
2014 Green Networking With Packet Processing Engines: Modeling and Optimization
abstract
With the aim of controlling power consumption in metro/transport and core networks, we consider energy-aware devices able to reduce their energy requirements by adapting their performance. In particular, we focus on state-of-the-art packet processing engines, which generally represent the most energy-consuming components of network devices, and which are often composed of a number of parallel pipelines to “divide and conquer” the incoming traffic load. Our goal is to control both the power configuration of pipelines and the way to distribute traffic flows among them. We propose an analytical model to accurately represent the impact of green network technologies (i.e., low power idle and adaptive rate) on network- and energy-aware performance indexes. The model has been validated with experimental results, performed by using energy-aware software routers loaded by real-world traffic traces. The achieved results demonstrate how the proposed model can effectively represent energy- and network-aware performance indexes. On this basis, we propose a constrained optimization policy, which seeks the best tradeoff between power consumption and packet latency times. The procedure aims at dynamically adapting the energy-aware device configuration to minimize energy consumption while coping with incoming traffic volumes and meeting network performance constraints. In order to deeply understand the impact of such policy, a number of tests have been performed by using experimental data from software router architectures and real-world traffic traces.
Raffaele Bolla, Roberto Bruschi, Alessandro Carrega, Franco Davoli
IEEE/ACM Trans. Netw.3
2012 Cutting the energy bills of Internet Service Providers and telecoms through power management: An impact analysis
Raffaele Bolla, Roberto Bruschi, Alessandro Carrega, Franco Davoli, Diego Suino, Constantinos Vassilakis, Anastasios Zafeiropoulos
Comput. Networks3