Franco Callegati

dblp:73/340 · DBLP profile ↗
← Back
52ranked-venue papers
19as first author
17since 2021 · last 2026
0000-0002-6669-8072ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 33 · 15 first-author · 7 since 2021Security and privacy · 4 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 4 · 2 first-author · 3 since 2021
YearPublicationVenuePosition
2026 In-Network Security for Smart Buildings BACnet Communications
abstract
Building Automation and Control Systems increasingly rely on BACnet/IP to interconnect heterogeneous field devices and supervisory applications. Although BACnet Secure Connect provides end-to-end protection via TLS, its adoption in smart-building deployments is hindered by the limited capabilities of legacy devices and the additional communication overhead. In this paper, we propose an in-network security approach for BACnet/IP communications based on two P4-programmable boundary switches that transparently provide confidentiality, integrity, and authentication across exposed network segments without requiring modifications to BACnet endpoints. The solution combines AES-based encryption with support for 128-, 192-, and 256-bit keys and SHA-256 HMAC protection. The proposed approach is validated on a virtualized testbed that we developed on top of the NIST Net-Zero Energy Residential Test Facility (NZERTF) HVAC reference scenario. Experimental results show that the proposed in-network approach achieves a mean RTT between 1393μs and 1541μs, thus reducing latency by 22.8%−30.2%with respect to BACnet/SC (1995 μ s), while remaining above plaintext BACnet/IP (951 μs) by 46.5%−62.0%.
Lorenzo Rinieri, Antonio Iacobelli, Andrea Melis 0001, Roberto Girau, Franco Callegati, Marco Prandini
NetSoft5
2026 P4ICS: P4 in-network security for Industrial Control Systems networks
abstract
Industrial Control Systems (ICS) are increasingly interconnected with enterprise IT and cloud services, yet their communications remain largely unprotected due to the limited adoption of Transport Layer Security (TLS) and other cryptographic standards. Legacy devices often lack the resources to support TLS, and operators face performance constraints and complex certificate management. To address this gap, we present P4ICS, a framework that provides confidentiality, integrity, and replay protection for industrial protocols by shifting security functions from endpoints into P4-programmable switches. P4ICS transparently parses and protects Modbus, DNP3, EtherNet/IP, and MQTT traffic, establishing switch-to-switch encrypted tunnels that secure untrusted network segments while preserving interoperability with legacy equipment. Our evaluation on an ad hoc physical testbed shows that P4ICS introduces only a modest overhead compared to plaintext communication, while consistently outperforming TLS, reducing delays by about 12% for Modbus and DNP3, 43% for EtherNet/IP, and 47% for MQTT. By leveraging in-network computing, P4ICS delivers a practical and deployable security layer for Industry 4.0 communications, narrowing the gap between available secure protocol profiles and their limited use in operational ICS.
Lorenzo Rinieri, Andrea Melis 0001, Roberto Girau, Giovanni Pau 0001, Marco Prandini, Franco Callegati
Comput. Networks6
2026 PLC-Defuser: Detecting hidden Ladder Logic Bombs in PLCs via Control Flow Graph and model checking
abstract
Industrial Control Systems (ICS) are responsible for the operations of critical industrial infrastructures such as water treatment facilities and nuclear plants. To control sensors and actuators, ICSs rely on Programmable Logic Controllers (PLCs), which have become the target of an increasing number of cyberattacks, particularly since the appearance of Stuxnet. In response, numerous anomaly detection methods have been proposed in the literature to identify stealthy attacks targeting ICS sensors and actuators. However, no existing method specifically addresses the detection of Ladder Logic Bombs (LLBs), a class of attacks designed to disrupt the normal operation of PLCs. In this work, we introduce PLC-Defuser, an automated framework specifically tailored to the task of LLB detection. PLC-Defuser first employs static analysis through Control Flow Graphs (CFG) to identify possible LLB triggers within the PLC control logic. It then performs model checking to formally verify whether the identified suspicious triggers activate malicious LLBs. We evaluate PLC-Defuser considering a simplified version of the Secure Water Treatment System (SWaT), for which we built a dataset of PLC programs containing 150 malicious and 150 legitimate samples. Our results demonstrate that PLC-Defuser effectively protects industrial plants without producing false positives and achieves an average execution time of less than 0.5 s.
Lorenzo Rinieri, Antonio Iacobelli, Andrea Melis 0001, Marco Prandini, Franco Callegati
Comput. Secur.5
2026 SIP-Classifier: Unsupervised Classification of SIP-IMS Signaling With Transformer and Clustering
abstract
Ensuring the reliability of voice services in 5G networks requires effective detection of anomalies in IMS signaling. However, this task remains challenging due to the architectural complexity of IMS and the large volume of signaling data. In this paper, we propose SIP-Classifier, an unsupervised methodology that combines Transformer-based representation learning with clustering to identify anomalous SIP sequences. The approach encodes SIP messages through protocol-aware tokenization, learns latent representations via an autoregressive Transformer, and clusters them to distinguish valid from anomalous flows. We evaluate the method on real-world IMS data collected from operational 5G networks. It achieves 98% accuracy, 98% precision, 95% recall, and a 96% F1-score, significantly outperforming state-of-the-art approaches.
Antonio Iacobelli, Giorgio Franceschelli, Lorenzo Rinieri, Mirco Musolesi, Marco Prandini, Franco Callegati
IEEE Trans. Netw. Serv. Manag.6
2025 Digital Twin for Sustainable Manufacturing: Integrating Networking and Factory Assets
abstract
The novel Industry 5.0 concept leverages data gathering and communication between the Information Technology (IT) and Operation Technology (OT) segments to drive efficient and sustainable manufacturing processes. However, how to properly integrate IT and OT ecosystems to achieve effective industrial asset management has to be further investigated. We propose an architecture that provides an integrated view and unified control of networking and industrial equipment. This paper describes how the proposed architecture can enable energy-saving decision-making policies and support sustainable predictive maintenance in manufacturing through the Asset Administration Shell concept. Part of the architecture is implemented using the Eclipse BaSyx tool, an Asset Administration Shell-compliant framework, to bridge the IT and OT segments by providing a virtual representation of both network and factory assets and a unified control interface.
Chiara Grasselli, Chiara Contoli, Franco Callegati
CCNC3
2025 CLO5ER: a Composable Lightweight Observability for 5g RAN Environment Inside Near RT RIC
abstract
The Open RAN specification introduces the Near Real-Time RAN Intelligent Controller (Near-RT RIC) as a closer point of orchestration, providing real-time analysis and control of gNBs through Operator-defined Near-Real Time Applications (xApps). The continuous gathering, storing, and processing of metrics and logs from various hardware and software components of the network is a complex task. In the cloud community, this complexity has been addressed through approaches and tools under the umbrella of observability. An observation framework applied to O-RAN can assure a holistic view of the infrastructure and services running on it, helping optimize performance, ensure interoperability among multi-vendor systems, enhance scalability, bolster security, and reduce operational costs by providing realtime insights. However, existing observability frameworks poorly fit O-RAN use cases due to their service-oriented architecture, which impacts performance and scalability. To fill this gap, we propose CLO5ER, a framework that facilitates the creation of observability workflows through the composition of O-xApp. Our solution integrates seamlessly with existing observability frameworks, providing an accelerated alternative path for processing signals from gNBs. Additionally, we introduce a novel xApp controller that optimizes O-xApp placement and instrumentation. Furthermore, our solution features a hierarchical message-oriented middleware that enhances xApp composability and data exchange.
Sofia Montebugnoli, Andrea Sabbioni, Franco Callegati, Luca Foschini 0001, Paolo Bellavista
ICC3
2025 SAFARI: A Scalable Air-Gapped Framework for Automated Ransomware Investigation
abstract
Ransomware poses a significant threat to individuals and organisations, creating a need for tools to investigate its behaviour and the effectiveness of mitigations. To address this need, we present SAFARI, an open-source framework designed for safe and efficient ransomware analysis. SAFARI’s design emphasises scalability, air-gapped security, and automation, democratising access to safe ransomware investigation tools and fostering collaborative efforts. SAFARI leverages virtualisation, Infrastructure-as-Code, and OS-agnostic task automation to create isolated environments for controlled ransomware execution and analysis. The framework enables researchers to profile ransomware behaviour and evaluate mitigation strategies through automated, reproducible experiments. We demonstrate SAFARI’s capabilities by building a proof-of-concept implementation and using it to conduct two case studies: the first analyses seven ransomware strains – including WannaCry and LockBit – to identify their encryption patterns and file-targeting strategies; the second evaluates Ranflood, a countermeasure tool, against five dangerous strains. Our results provide insights into ransomware behaviour and the effectiveness of countermeasures, showcasing SAFARI’s potential to advance ransomware research and defence development.
Tommaso Compagnucci, Franco Callegati, Saverio Giallorenzo, Andrea Melis 0001, Simone Melloni, Alessandro Vannini
SEC (1)2
2025 Investigating operational technology attacks as code
abstract
Abstract Industrial Operational Technology (OT) environments face escalating cybersecurity challenges due to increasing interconnectedness, device heterogeneity, and the integration of legacy systems not designed with modern security requirements. Operators struggle with security validation in OT settings due to the complexity of static reasoning across multilayered architectures and the impracticality of in-production testing, which risks operational disruptions and safety hazards. To address these limitations, we propose SAFARI, a framework that leverages the concepts of digital twin and cyber range to enable Security-Investigation-as-Code for OT environments, automating the creation, deployment, and security testing of faithful OT architecture replicas. SAFARI uses technologies such as Terraform, Proxmox SDN, and MITRE Caldera to provide scalable, reproducible security assessment capabilities while maintaining complete air-gapping for safe malware testing. We demonstrate SAFARI’s effectiveness through a comprehensive case study examining three industrial network architectures exhibiting increasing segmentation. Our results show that SAFARI successfully automates complex security scenarios, enables regression testing of architectural refinements, and provides quantifiable insights into attack resistance improvements. The framework represents a significant advancement in OT security testing methodology, offering security operators a practical tool for systematic vulnerability assessment and architectural validation without compromising operational continuity.
Franco Callegati, Saverio Giallorenzo, Andrea Melis 0001, Simone Melloni, Marco Prandini, Alessandro Vannini
Empir. Softw. Eng.1
2024 In-Network Encryption for Secure Industrial Control Systems Communications
abstract
In this manuscript, we present a solution to provide secure communication in Industry 4.0 environments. Legacy ICS components that do not have encryption capabilities will be able to communicate using secured channels by means of P4 programmable switches that implement security in the data plane. We will compare the proposed solution with TLS end-to-end encryption, showing that it offers similar performance with no need to interact with the end hosts.
Lorenzo Rinieri, Antonio Iacobelli, Amir Al Sadi, Andrea Melis 0001, Franco Callegati, Marco Prandini
NetSoft5
2024 Unleashing Dynamic Pipeline Reconfiguration of P4 Switches for Efficient Network Monitoring
abstract
As it is happening in many fields that need efficient and effective classification of data, Machine Learning (ML) is becoming increasingly popular in network management and monitoring. In general we can say that ML algorithms are complex, therefore better suited for execution in the centralized control plane of modern networks, but are also heavily reliant on data, that are necessarily collected in the data plane. The inevitable consequence is that may arise the need to transfer lots of data from the data plane to the control plane, with the risk to cause congestion on the control communication channel. This may turn into a major drawback, since congestion on the control channel may have a significant impact on network operations. Therefore it is of paramount importance to design systems capable of minimizing the interaction between data and control planes while ensuring good monitoring performance. The most recent generation of data plane programmable switches supporting the P4 language can help mitigate this problem by preprocessing traffic data at line rate. In this manuscript we follow this approach and propose P4RTHENON: an architecture to distill in the data plane the relevant information to be mirrored to the control plane, where complex analysis can be performed. P4RTHENON leverages the P4-native support for runtime data plane pipeline reconfiguration to minimize the interaction between data and control planes while ensuring good monitoring performance. We tested our scheme on the volumetric DDoS detection use case: P4RTHENON reduces the volume of exchanged data by almost 75% compared to a pure control-plane-based solution, guarantees low memory consumption in the data plane, and does not degrade the overall DDoS detection capabilities.
Amir Al Sadi, Marco Savi, Andrea Melis 0001, Marco Prandini, Franco Callegati
IEEE Trans. Netw. Serv. Manag.5
2023 Towards the Creation of Interdisciplinary Consumer-Oriented Security Metrics
abstract
Information systems are evolving: IoT devices and Cyber-physical systems (CPS) impact on the security of assets and people in the real world. Old cybersecurity approaches, which focused on seeing humans “as a problem”, could be substitute by new paradigms of seeing humans “as a solution”. Therefore, consumers awareness will be one of the building blocks, as well as initiative that aim to create a set of standardized security metrics that can evaluate the security of systems. In order to do that, researchers need to study which are the essential factors that our future metrics should focus on. In this paper we analyzed this problem over CPS while assuming the consumer perspective. We summarize the state of the art in security metrics and advocate the need for a research effort aimed at taking the field to a new level of formal soundness and practical usability by considering interdisciplinary implications on cybersecurity.
Giacomo Gori, Andrea Melis 0001, Davide Berardi, Marco Prandini, Amir Al Sadi, Franco Callegati
CCNC6
2023 A Structured Approach to Insider Threat Monitoring for Offensive Security Teams
abstract
In many countries, government agencies resort to third parties to acquire security services of many kinds, including Red Team operations to test the effectiveness of own defenses mechanisms. Absolute trust is a key requirement, lest a potentially devastating finding be exploited by a treacherous Red Team against the same entity which commissioned the operation, or sold to its adversaries. In our endeavour as a joint private-academic initiative to address this peculiar market, we observed that a structured approach to this issue is much less common than we would have expected. In this work, we outline the process we are devising to offer customers a verified environment, but integrating it with an evidence-based proof of their correct behavior during the operation, striving to solve the “Quis custodiet ipsos custodes” struggle in an offensive setting.
Amir Al Sadi, Davide Berardi, Franco Callegati, Andrea Melis 0001, Marco Prandini, Luca Tolomei
CCNC3
2023 Time sensitive networking security: issues of precision time protocol and its implementation
abstract
Abstract Time Sensitive Networking (TSN) will be an integral component of industrial networking. Time synchronization in TSN is provided by the IEEE-1588, Precision Time Protocol (PTP) protocol. The standard, dating back to 2008, marginally addresses security aspects, notably not encompassing the frames designed for management purposes (Type Length Values or TLVs). In this work we show that the TLVs can be abused by an attacker to reconfigure, manipulate, or shut down time synchronization. The effects of such an attack can be serious, ranging from interruption of operations to actual unintended behavior of industrial devices, possibly resulting in physical damages or even harm to operators. The paper analyzes the root causes of this vulnerability, and provides concrete examples of attacks leveraging it to de-synchronize the clocks, showing that they can succeed with limited resources, realistically available to a malicious actor.
Davide Berardi, Nils Ole Tippenhauer, Andrea Melis 0001, Marco Prandini, Franco Callegati
Cybersecur.5
2023 Mission Critical Communications Support With 5G and Network Slicing
abstract
Mission Critical (MC) communications take a pivotal role to achieve effective Public Protection and Disaster Relief (PPDR) actions. Even though 3GPP standards define MC applications and services in an architectural framework compatible with current 5G mobile networks, real-life experiments and applications of these concepts are still at the very beginning. In this paper, we present an architectural study and related experimental activity on network slicing for MC communications. We implemented these services in a fully virtualized environment, and deployed and tested them in a multi-domain network slicing scenario compliant with the ETSI NFV-MANO specifications. Our work aligns with the 5G approach separating control and data planes. The level of automation in service deployment and the slice isolation features are demonstrated, showing the benefits in terms of application performance, management flexibility, scalability, and quality of service differentiation capabilities.
Davide Borsatti, Chiara Grasselli, Chiara Contoli, Luigia Micciullo, Luca Spinacci, Marina Settembre, Walter Cerroni, Franco Callegati
IEEE Trans. Netw. Serv. Manag.8
2022 Metrics for Cyber-Physical Security: a call to action
abstract
Cyber-physical systems, by definition, have an effect on assets and people in the real world. Security factors, thus, should play a central role in every decision regarding their deployment and configuration, but this is possible only if said factors are properly defined and can be objectively measured. In this paper, we summarize the state of the art in security metrics, and advocate the need for a research effort aimed at taking the field to a new level of formal soundness and practical usability.
Giacomo Gori, Andrea Melis 0001, Lorenzo Rinieri, Marco Prandini, Amir Al Sadi, Franco Callegati
ISNCC6
2021 SDN-based Differentiated Traffic Flow Management for Industrial Internet of Things Environments
abstract
Today Industrial IoT environments are still based on traditional IP technologies, which makes difficult, if not impossible, to bridge the missing link between the application and the network layer. Indeed, IIoT applications should be able to ask for network services (with specific QoS guarantees) independently of the addressing at the network and transport layer. In this paper, we start from a novel patented method for routing packets to demonstrate with a prototype implementation the feasibility and efficiency of a software defined solution based on flow tagging with the purpose of supporting IIoT dynamic network programmability. We show how the combination of IP datagram options and SDN allows IIoT environments to reach per-device and per-application flow management granularity. The presented proof of concept prototype outlines the capability to dynamically program the network based on tagged flows and to differentiate network behaviors based on IIoT requirements together with the whole network state.
Franco Callegati, Aldo Campi, Chiara Contoli, Silvio Di Santi, Nicola Ghiselli, Carlo Giannelli, Alessandro Pernafini, Riccardo Zamagna
ISCC1
2021 P-SCOR: Integration of Constraint Programming Orchestration and Programmable Data Plane
abstract
In this manuscript we present an original implementation of network management functions in the context of Software Defined Networking. We demonstrate a full integration of an artificial intelligence driven management, an SDN control plane, and a programmable data plane. Constraint Programming is used to implement a management operating system that accepts high level specifications, via a northbound interface, in terms of operational objective and directives. These are translated in technology-specific constraints and directives for the SDN control plane, leveraging the programmable data plane, which is enriched with functionalities suited to feed data that enable the most effective operation of the “intelligent” control plane, by exploiting the P4 language.
Andrea Melis 0001, Siamak Layeghy, Davide Berardi, Marius Portmann, Marco Prandini, Franco Callegati
IEEE Trans. Netw. Serv. Manag.6
2020 TechNETium: Atomic Predicates and Model Driven Development to Verify Security Network Policies
abstract
Fifth-generation (5G) networks will deliver unprecedented levels of quality of service for online gaming and multimedia-rich social interaction, providing virtual environments optimized for vertical applications through innovative approaches to physical resource management. These techniques must consider security aspects in all phases and at every layer. Trusted communications between individuals and reliable platforms running services for social good depend on the resiliency to network-level attacks such as hijacking and denial-of-service. The verification of topological properties represents a well-suited approach to address these issues in a 5G environment. This paper illustrates moves from formal methods existing in literature, namely atomic predicates (AP) and header space analysis (HSA). It describes a method of integrating AP in Software Defined Network architectures, achieving the same expressive power as HSA without its performance hit, to make topology verification viable for real-time security applications.
Davide Berardi, Franco Callegati, Andrea Melis 0001, Marco Prandini
CCNC2
2020 Network Slicing for Mission Critical Communications
abstract
Mission Critical (MC) communications are key to effective Public Protection and Risk Reduction (PPRR) actions. The 3GPP standards include the definition of MC applications and services in an architectural framework compatible with current (LTE) and future (5G) mobile networks. In this paper we report an experimental activity where MC communication services are implemented in a fully virtualized environment, being deployed and tested in a multi-domain network slicing architecture compliant with the ETSI NFV MANO specifications. The level of automation in service deployment and the slice isolation features are demonstrated, in line with the 5G approach of separation between control and data plane, showing the benefits in terms of application performance and management flexibility.
Davide Borsatti, Chiara Grasselli, Luca Spinacci, Marina Sellembre, Walter Cerroni, Franco Callegati
WiMob6
2019 Service Function Chaining Leveraging Segment Routing for 5G Network Slicing
abstract
In this manuscript we describe an experimental work that integrates the NFV-MANO framework with segment routing to support 5G network slicing. The aim is to implement Service Function Chains spanning several cloud domains and the related interconnection transport network in a coordinated way. The manuscript shows the feasibility and the performance effectiveness of this approach, reporting numerical results from practical experiments.
Davide Borsatti, Gianluca Davoli, Walter Cerroni, Franco Callegati
CNSM4
2018 Performance of Service Function Chaining on the OpenStack Cloud Platform
Davide Borsatti, Gianluca Davoli, Walter Cerroni, Chiara Contoli, Franco Callegati
CNSM5
2018 Improving OpenStack Networking: Advantages and Performance of Native SDN Integration
abstract
A key aspect that Telco operators must carefully consider when deploying Network Function Virtualization (NFV) solutions is the level of performance that cloud computing software platforms can guarantee in support of the offered network services. OpenStack is widely considered as one of the most relevant open-source frameworks that could accelerate the NFV adoption, also because the evolution of its networking components sees a progressive integration of SDN-based solutions that could significantly improve the performance of cloud-based connectivity services. In this paper, we discuss some of the most recent OpenStack innovations that enable a native SDN-like approach to firewalling functions in the data plane, as well as a native SDN-oriented control of the virtual network infrastructure. Then we present a detailed performance analysis of the aforementioned innovations at both the data and control/management plane, showing the potentials of native SDN adoption within OpenStack toward an integrated solution for production-level NFV deployments.
Francesco Foresta, Walter Cerroni, Luca Foschini 0001, Gianluca Davoli, Chiara Contoli, Antonio Corradi, Franco Callegati
ICC7
2018 On reliability improvement of Software-Defined Networks
Shadi Moazzeni, Mohammad Reza Khayyambashi, Naser Movahhedinia, Franco Callegati
Comput. Networks4
2018 Cloud-of-Things meets Mobility-as-a-Service: An insider threat perspective
Franco Callegati, Saverio Giallorenzo, Andrea Melis 0001, Marco Prandini
Comput. Secur.1
2018 Integrating Personalized and Accessible Itineraries in MaaS Ecosystems Through Microservices
Andrea Melis 0001, Silvia Mirri, Catia Prandi, Marco Prandini, Paola Salomoni, Franco Callegati
Mob. Networks Appl.6
2017 Performance of intent-based virtualized network infrastructure management
abstract
This paper presents the definition and a proof-of-concept implementation of an intent-based northbound interface (NBI) used to orchestrate dynamic service chaining of Virtualized Network Functions (VNFs) by actively controlling the underlying network infrastructure through vendor-independent, technology-agnostic policies. The proof of concept considers a general scenario where VNFs are hosted in different SDN domains, possibly interconnected by non-SDN domains. Being implemented as part of a Virtualized Infrastructure Manager, the proposed NBI is compliant with the ETSI NFV management and orchestration specifications, as well as with the recent ONF definition of intent-based NBI. The case of a network operator that provides adaptive quality of service enforcement in a multi-tenant scenario is considered. Responsiveness of the intent-based NBI is experimentally evaluated under increasing load, proving the correct functionality and the scalability potentials of the proposed approach.
Franco Callegati, Walter Cerroni, Chiara Contoli, Francesco Foresta
ICC1
2017 I want to ride my bicycle: A microservice-based use case for a MaaS architecture
abstract
This work presents a use case on multimodal urban paths in a smart mobility context. The proposed solution builds on the experience already matured and developed by the authors in different fields: crowdsourcing and sensing done by users to gather data related to urban barriers and facilities, computation of personalized paths for users with special needs, and integration of open data provided by bus companies to identify the actual accessibility features and estimate the real arrival time of vehicles at stops. In terms of functionality, the first “monolithic” prototype fulfilled the goal of composing the aforementioned pieces of information to support citizens with reduced mobility (users with disabilities and/or elderly people) in their urban movements. In this paper, we describe a service-oriented architecture that exploits the microservices orchestration paradigm to enable the creation of new services and to make the management of the various data sources easier and more effective. The manuscript demonstrates the effectiveness of the approach showing a successful use case of a service that take into account multimodal paths, by involving cyclists, bicycle lanes, and bike sharing services in a urban environments. Such a use case take into account the user's interface and interaction mechanisms, which are strongly affected by the context of use.
Franco Callegati, Giovanni Delnevo, Andrea Melis 0001, Silvia Mirri, Marco Prandini, Paola Salomoni
ISCC1
2015 Dynamic chaining of Virtual Network Functions in cloud-based edge networks
abstract
This manuscript investigates the issue of implementing chains of network functions in a “softwarized” environment where edge network middle-boxes are replaced by software appliances running in virtual machines within a data center. The primary goal is to show that this approach allows space and time diversity in service chaining, with a higher degree of dynamism and flexibility with respect to conventional hardware-based architectures. The manuscript describes implementation alternatives of the virtual function chaining in a SDN scenario, showing that both layer 2 and layer 3 approaches are functionally viable. A proof-of-concept implementation with the Mininet emulation platform is then presented to provide a practical example of the feasibility and degree of complexity of such approaches.
Franco Callegati, Walter Cerroni, Chiara Contoli, Giuliano Santandrea
NetSoft1
2015 Virtual network function embedding in real cloud environments
Paolo Bellavista, Franco Callegati, Walter Cerroni, Chiara Contoli, Antonio Corradi, Luca Foschini 0001, Alessandro Pernafini, Giuliano Santandrea
Comput. Networks2
2015 Cross-layer resource orchestration for cloud service delivery: A seamless SDN approach
Walter Cerroni, Molka Gharbaoui, Barbara Martini, Aldo Campi, Piero Castoldi, Franco Callegati
Comput. Networks6
2014 Live migration of virtual network functions in cloud-based edge networks
abstract
Emerging network paradigms, such as Software Defined Networking and Network Function Virtualization, represent the key enablers for efficient and cost-effective deployment and management of cloud-based edge networks, where a number of cooperating virtual machines can implement the tasks traditionally performed by expensive and disrupting network middleboxes. A key feature in such a scenario is the capability of live migrating a group of correlated virtual machines as a single entity representing a customer's profile. Multiple VM live migration is a topic that has not been thoroughly studied in the literature. This manuscript presents a relatively simple model that can be used to derive some performance indicators, such as the whole service downtime and the total migration time, and allows to properly design the cloud-based edge network. The model is used to compare some simple scheduling strategies for the VM migration and to provide guidelines to such implementation.
Walter Cerroni, Franco Callegati
ICC2
2012 Network resource allocation in data center interconnection with anycast service provisioning
abstract
The joint management of IT and network resources is a key aspect for dynamic inter-data center interconnection networks designed to work according to the cloud computing paradigm. Such a scenario calls for the anycast routing of service requests to find a data channel that best suits both connectivity and IT resource requirements. This paper presents different network resource allocation and release policies across an inter-data center interconnection network aimed at a balanced accommodation of network resources to improve performance. Such policies are evaluated and compared in terms of service set-up blocking probability considering also configuration latency of real network devices that play a significant role along with network bandwidth availability across the network. Results show that the best choice is to release network resources as soon as possible, even though this means increasing the service blocking due to network reconfiguration latency.
Molka Gharbaoui, Barbara Martini, Walter Cerroni, Piero Castoldi, Franco Callegati
GLOBECOM5
2011 Integrated Signaling Framework for Joint Reservation of Application and Network Resources for the Future Internet
abstract
This work presents a signaling framework for the Future Internet capable of enabling unified network and IT resource allocation. The proposed signaling scheme is based on existing technologies and carried out through extensions to protocols already operated in current Internet, i.e., SIP, and by resorting to source-initiated GMPLS signaling without introducing network technology- dependent mechanisms. The experimental validation presented in this work has been carried out on a real test-bed. Performance of the service set-up procedure are reported taking into account the response time of real life devices such as commercial routers and protocols. The results provided show that the architecture proposed is compliant with conventional performance levels such as those set by the ITU- T. Finally, scalability performance have been verified by stressing the system with increasing rate of simultaneous service requests.
Barbara Martini, Walter Cerroni, Molka Gharbaoui, Aldo Campi, Piero Castoldi, Franco Callegati
GLOBECOM6
2009 Dimensioning for in-band and out-of-band signalling protocols in OBS networks
abstract
Most of the previous works on optical burst switching (OBS) assume in their analysis that signalling does not affect network performance. It is analysed here, under which conditions the effect of signalling is actually negligible, taking into account the effect of signalling in the evaluation of burst discard probability. First, analytical models for two different signalling approaches in an OBS network are presented: ‘out-of-band’ and ‘in-band’ techniques. The impact of these two signalling strategies in terms of the probability of burst discard are evaluated, identifying the component of bursts discarded as a consequence of control message losses or of excessive signalling delay. A new method is also discussed, based on the previous models, to assign the correct amount of resources to the control plane. To verify the accuracy of the analytical results, these are compared with results based on discrete-event simulationns: results are found to be in a highly satisfactory agreement with simulations.
Antonio Pantaleo, Massimo Tornatore, Achille Pattavina, Carla Raffaelli, Franco Callegati
IET Commun.5
2008 H-SIP: Hybrid SIP Network
abstract
In this paper we propose a service-oriented networking architecture that, by exploiting the Session Initiation Protocol (SIP), is able to support a population of users moving within a network of trusted domains over wireless and/or wired connections. The proposed architecture combines the flexibility of a peer-to-peer connectivity network with the efficient signaling organization of a hierarchy of domains.
Franco Callegati, Aldo Campi, Walter Cerroni
GLOBECOM1
2008 SIP-enabled Optical Burst Switching architectures and protocols for application-aware optical networks
Georgios Zervas, Yixuan Qin, Reza Nejabati, Dimitra Simeonidou, Franco Callegati, Aldo Campi, Walter Cerroni
Comput. Networks5
2007 Key parameters for contention resolution in multi-fiber Optical Burst/Packet Switching nodes
abstract
Optical networking paradigms based on statistical multiplexing, such as Optical Burst Switching or Optical Packet Switching, require the adoption of suitable contention resolution mechanisms at the optical nodes due to packets/bursts attempting to get access to the shared output channel at the same time. In the most general case of multi-fiber output links, contentions are tried to be solved by exploiting different domains — namely space, wavelength and time — and by applying an optimal scheduling policy. This paper focuses on the key parameters that can be used to design and optimize an optical packet/burst contention resolution scheme and shows how such parameters should be correlated for a correct performance assessment, taking into account feasibility trade-offs due to limited optical buffering and wavelength conversion capability.
Franco Callegati, Walter Cerroni, Gustavo Sousa Pavani
BROADNETS1
2007 Dynamic service differentiation in OBS networks
abstract
In this paper we propose an edge-to-edge closed-loop scheme to provide Quality-of-Service (QoS) in Optical Burst Switching (OBS) networks. Performance parameters for each burst flow are exchanged by a feedback message called Service Control Message (SCM) which is processed only at the edge/ingress nodes. According to the information contained in the SCM the edge nodes could adapt the values of some flow parameters (typically burst assembly parameters and offset time) to apply differentiated quality of service to the various flows. Simulations results are presented to investigate the feasibility of this new proposal.
Antonio Pantaleo, Massimo Tornatore, Achille Pattavina, Carla Raffaelli, Franco Callegati
BROADNETS5
2007 SIP-enpowered OBS network architecture for future IT services and applications
abstract
This paper presents a novel application-aware network architecture for evolving and emerging IT services and applications. It proposes and analyses network architectures that integrate Session Initiation Protocol (SIP) with Optical Burst Switched (OBS) protocols on a unified manner. We suggest various SIP-OBS layering architectures for possible deployment as well as a number of end-to-end resource discovery protocols (both for network and non-network resources). Finally the paper reports of a SIP-enpowered OBS Testbed where this approach was experimentally validated.
Dimitra Simeonidou, Georgios Zervas, Reza Nejabati, Franco Callegati, Aldo Campi, Walter Cerroni
BROADNETS4
2007 A Cost-Effective Approach to Optical Packet/burst Scheduling
abstract
Optical burst and packet switching are being considered as the most promising paradigms to increase bandwidth efficiency in IP over DWDM networks. In both cases, due to statistical multiplexing, a scheduling policy is needed to solve contentions at the node level caused by more than one burst/packet directed to the same output channel. The scheduling may be performed in the wavelength, time and space domains, turning this problem into a choice of the best available resource in the different domains. Because of the very large bandwidth on the wavelength channels, the burst/packet arrival rate at the network nodes is very high and therefore the time available to take the scheduling decision is very limited. As a consequence, whatever scheduling policy is adopted, it must be implemented in an extremely effective way in terms of computational complexity. This paper is focused on a cost-effective solution to the scheduling problem, which is not based on typical search algorithms and whose complexity can be made almost independent of the dimension of the resource set to be searched.
Franco Callegati, Aldo Campi, Walter Cerroni
ICC1
2006 Congestion Resolution in Optical Burst/Packet Switching with Limited Wavelength Conversion
abstract
This paper proposes a methodology to compare scheduling algorithms for congestion resolution in optical burst switching or optical packet switching networks, focusing on the issue of wavelength conversion capabilities. The performance of such algorithms when full wavelength conversion is available at the switching nodes are compared with the case of conversion capabilities over a limited range of wavelengths. The results presented show that limited range wavelength conversion is not necessarily performing worse than full wavelength conversion, as long as the correct terms of comparison are considered.
Franco Callegati, Walter Cerroni, Luiz H. Bonani, Felipe Rudge Barbosa, Edson Moschim, Gustavo Sousa Pavani
GLOBECOM1
2006 Impact of Optical Packet Loss and Reordering on TCP Performance
abstract
Next generation optical network technologies such as OPS and OBS have a non-negligible impact on the performance of the transport layer. This is related to how a packet stream traversing the optical network is affected by random behaviors such as latency variability, out-of-sequence delivery and loss. This paper tries to better understand how the use of contention resolution schemes at the optical layer affects the TCP performance, focusing in particular on the impact of unordered delivery and loss of packets.
Franco Callegati, Walter Cerroni, Carla Raffaelli
GLOBECOM1
2006 Research on Optical Core Networks in the e-Photon/ONe Network of Excellence
abstract
This papers reports the advances in optical core networks research coordinated in the framework of the e- photon/ONe and e-photon/ONe+ networks of excellence.
Franco Callegati, Javier Aracil 0001, Lena Wosinska, Nicola Andriolli, Davide Careglio, Alessio Giorgetti, Juan P. Fernández Palacios, C. Gauger, Miroslaw Klinkowski, Óscar González de Dios, Guoqiang Hu 0002, Ezhan Karasan, Francesco Matera, Harald Øverby, Carla Raffaelli, Luca Rea, Namik Sengezer, Massimo Tornatore, Kyriakos Vlachos
INFOCOM1
2006 QoS differentiation in optical packet-switched networks
Franco Callegati, Walter Cerroni, Carla Raffaelli, Michele Savi
Comput. Commun.1
2004 Wavelength and time domain exploitation for QoS management in optical packet switches
Franco Callegati, Walter Cerroni, Carla Raffaelli, Paolo Zaffoni
Comput. Networks1
2003 The European IST project DAVID: a viable approach toward optical packet switching
abstract
In this paper, promising technologies and a network architecture are presented for future optical packet switched networks. The overall network concept is presented and the major choices are highlighted and compared with alternative solutions. Both long and shorter term approaches are considered, as well as both the wide-area network and multiple-area networks parts of the network. The results presented in this paper were developed in the frame of the research project DAVID (Data And Voice Integration over DWDM) project, funded by the European Commission through the IST-framework.
Lars Dittmann, Chris Develder, Dominique Chiaroni, Fabio Neri, Franco Callegati, W. Körber, Alexandros A. Stavdas, Monique Renaud, Albert Rafel, Josep Solé-Pareta, Walter Cerroni, Helen-Catherine Leligou, Lars Dembeck, B. Mortensen, Mario Pickavet, N. Le Sauze, M. Mahony, Bela Berde, Gert J. Eilenberger
IEEE J. Sel. Areas Commun.5
2002 Exploitation of DWDM for optical packet switching with quality of service guarantees
abstract
This paper addresses the problem of building optical packet switches that are able to effectively cope with variable length packet traffic and quality of service management, therefore able to support IP traffic. The paper aims at showing that the availability of dense wavelength division multiplexing is crucial. By suitably exploiting the wavelength dimension a multistage fiber delay line buffer can be implemented, with fine granularity and long delay with an architecture of limited complexity. This is necessary to fulfill the buffering requirements of variable length packets. Furthermore, the wavelength domain is proved to be more effective than the time domain to manage different levels of quality of service. Algorithms are presented that are peculiarly designed for this environment showing that they can effectively differentiate the packet loss probability between three priority classes.
Franco Callegati, Giorgio Corazza, Carla Raffaelli
IEEE J. Sel. Areas Commun.1
2001 Wavelength allocation algorithms in optical buffers
abstract
This paper addresses the problem of buffering performance optimization for asynchronous, variable length packets in a DWDM optical network. In the case of a multiplexing scheme that shares the wavelength resource among all packets regardless the connection they belong to, the problem of defining a wavelength allocation algorithm arises. Wavelength allocation has to be merged with delay allocation in buffers realized by means of fiber delay lines (FDLs). This paper proposes several allocation algorithms and compares their performance. It shows that the buffering performance strongly depends on the choice of the delay unit of the FDL's and that the algorithm aiming at reducing the artificial increase in the load due to the discrete time scale of the buffer gives best performance.
Franco Callegati, Walter Cerroni
ICC1
2000 Design of a WDM optical packet switch for IP traffic
abstract
This paper addresses the design of an optical packet switch able to effectively cope with variable length packet traffic, such as IP traffic. A switching architecture equipped with a multistage fiber delay line buffer is presented, that is able to realize fine time granularity and long delay. WDM is introduced to solve switch internal blocking and to enhance buffer exploitation. Packet loss performance, evaluated by simulation, is discussed in relation to the degrees of freedom available for switch design, to show the feasibility of a switch for the IP environment.
Franco Callegati, Giorgio Corazza, Carla Raffaelli
GLOBECOM1
2000 On the design of optical buffers for variable length packet traffic
abstract
This paper addresses the problem of dimensioning buffers realized by means of fiber delay lines in optical packet switches. The network scenario considered is such that packets have variable length and are sent asynchronously on the optical links. The role of the basic time unit of the fiber delay lines is discussed, showing that it is a crucial parameter to determine the queuing performance. The paper gives an approximate model that, in spite of being very simple, provides reasonable results to estimate the optimal choice of this time unit.
Franco Callegati
ICCCN1
1998 End-to-end performance of an optical transparent packet network
abstract
This paper investigates the overall traffic performance of a transparent optical network, suitable for high bit rate interconnection. The motivation of the introduction of such a transport network are discussed and the network architecture is presented. The performance is investigated in an end-to-end perspective. On one side the traffic resulting at the output of the interface with other networks, such as ATM for instance, is studied showing an interesting traffic shaping effect. Then this traffic is taken as the input to optical switches showing that the target performance in terms of the packet loss can be reached with present technology both in the access as well as in the core part of the network. An approximate evaluation of the end-to-end delay experienced by data crossing the optical network in a typical operating environment is given showing the effectiveness of the approach presented.
Franco Callegati, Carla Raffaelli
ICC1
1998 Transparent optical packet switching: network architecture and demonstrators in the KEOPS project
abstract
This paper reviews the work carried out in the ACTS KEOPS (Keys to Optical Packet Switching) project, describing the results obtained to date. The main objective of the project is the definition, development, and assessment of optical packet switching and routing networks, capable of providing transparency to the payload bit rate, using optical packets of fixed duration and low bit rate headers in order to enable easier processing at the network/node interfaces. The feasibility of the KEOPS concept is assessed by modeling, laboratory experiments, and testbed implementation of optical packet switching nodes and network/node interfacing blocks, including a fully equipped demonstrator. The demonstration relies on advanced optoelectronic components, developed within the project, which are described.
Piero Gambini, Monique Renaud, Christian Guillemot, Franco Callegati, Ivan Andonovic, Bruno Bostica, Dominique Chiaroni, Giorgio Corazza, Soeren Lykke Danielsen, Philippe Gravey, Peter Bukhave Hansen, Michel Henry, Christopher Janz, Allan Kloch, Roger Krähenbühl, Carla Raffaelli, Michael Schilling 0002, Anne Talneau, Libero Zucchelli
IEEE J. Sel. Areas Commun.4