VLDB 2026 Research / reviewers in the wild / expert
Francesco Paolucci
dblp:74/6741
· DBLP profile ↗
36ranked-venue papers
4as first author
21since 2021 · last 2026
0000-0003-4821-5193ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 27 · 4 first-author · 16 since 2021Systems, architecture and hardware · 2 · 2 since 2021Security and privacy · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Multi-Partner Project: Enhancing Resilience, Efficiency, and Trustworthiness of Edge AI in Safety-Critical Systems (GuardAI)abstractAI at the network edge promises real-time perception and decision-making in safety-critical domains such as aerial robotics, autonomous vehicles, and 5G-enabled infrastructures. Yet, operating under resource constraints, dynamic, and adversarial conditions exposes edge AI systems to fragility, inefficiency, and security risks that threaten their safe operation. GuardAI, a Horizon Europe project, introduces a framework for resilient and trustworthy edge AI that unites three pillars: adversarial robustness, context-enhanced inference, and security-by-design. Initial project results include a diffusion-based adversarial purification framework optimized for real-time operation, lightweight deep unrolling architectures for LiDAR super-resolution with built-in outlier removal, and robust uncertainty quantification modules to improve confidence calibration. It further develops a context-enhanced inference engine that integrates visual, spatial, and operational context across multi-agent systems, and a risk-aware defense recommender that autonomously selects mitigation strategies based on evolving threat landscapes. Through representative Use Cases, covering monitoring with Unmanned Aerial Vehicle, decentralized 5G network analytics, and secure perception in connected autonomous vehicles, GuardAI demonstrates how robust and adaptive AI can be achieved within stringent edge constraints. Together, these technologies lay the groundwork for a new generation of secure, context-aware, and certifiable AI systems that can be trusted to operate autonomously in the physical world. Antonis D. Savva, Mehmet Demirel, Yeshwanth Kumar Adimoolam, Rafaella Elia, Alexandros Gkillas, Erion-Vasilis M. Pikoulis, Amalia Damianou, Charmaine Barker, Daniel Bethell, Ahmed Salah Tawfik Ibrahim, Filippo Cugini, Francesco Paolucci, Kyriakos Vlachos, Simos Gerasimou, Antonios Lalas, Konstantinos Votis, Aris S. Lalos, Christos Kyrkou, Theocharis Theocharides |
DATE | 13 |
| 2026 | P4 Semantic Steering for Serverless Environments
Layal Ismail, István Pelle, Francesco Paolucci, Balázs Sonkoly, Filippo Cugini |
ICC | 3 |
| 2026 | PQKE-hCPABE: A Hybrid CP-ABE Scheme with Post‑Quantum Key Exchange for Secure Multicast
Matteo Sandrucci, Rana Abubakar, Abraham Cano Aguilera, Francesco Fumagalli, Francesco Paolucci, Juan Jose Vegas Olmos, Piero Castoldi, Filippo Cugini |
SECRYPT (1) | 5 |
| 2026 | From packets to predictions on GPU: Accelerated graph-based intrusion detection systemabstract• From Packets to Predictions On GPU: accelerated Graph-based Intrusion Detection System Ahmed Salah Tawfik Ibrahim, Emilio Paolini, Filippo Cugini, Francesco Paolucci This manuscript presents an In-GPU GNN-based intrusion detection system. Below, we summarize the novel contributions introduced in this work: • End-to-End In-GPU Pipeline - Problem: CPU-side graph construction and host-device memory transfers dominate prediction latency in GNN-based IDS pipelines, hindering real-time deployment. - New contribution: We redesign node aggregation and adjacency generation as CUDA kernels and execute both graph construction and GNN inference entirely on the GPU. This eliminates copy overheads and exploits thread-level parallelism to reduce end-to-end latency while preserving detection accuracy. • Reduced Memory Requirements - Problem: Previous GNN-based intrusion detection systems are memory-hungry. - New contribution: In this version, this problem is mitigated by exploiting the sparse properties of the input graph to reduce the memory size required for the system to run. • Optimized Memory Access Pattern - Problem: GPU memory accesses patterns are typically not considered. - New contribution: Accesses to GPU global memory are optimized achieving better performance and lower execution time especially after reducing the memory requirements. Graph Neural Networks (GNNs) are effective in detecting cyberattacks thanks to their ability to model network traffic, capturing structural relationships within the network. However, the high latency of the graph construction phase directly translates into higher overall prediction time, posing a challenge to real-time deployment. Therefore, an optimized GPU-accelerated framework that leverages the structural properties of the traffic graph is proposed in this work. It builds upon the notion of a precomputed adjacency matrix that gets modified by each graph instance. GPU threads are further used to construct the nodes, achieving an end-to-end graph generation and inference fully within the GPU. The sparsity of the graph and the coalesced memory access pattern within the GPU threads are further exploited to optimize the process. This allows the GPU to build large graphs much faster than the CPU without affecting the classification accuracy. This speedup is prominent for large graphs of 700 packets with the GPU being almost 4.3 times faster, highlighting the effectiveness of the proposed approach in real-time deployments. Ahmed Salah Tawfik Ibrahim, Emilio Paolini, Filippo Cugini, Francesco Paolucci |
Comput. Networks | 4 |
| 2026 | End-to-end latency assurance for distributed augmented reality over programmable 6G networks: A DESIRE6G demonstrationabstract6G networks are expected to deliver ultra-low latency, high reliability, and real-time intelligence for emerging services such as interactive Augmented Reality (AR), autonomous robotics, and digital twins. Achieving these requirements in practice demands tight coordination between networking, computing, and control domains, spanning RAN, transport, edge, and cloud. However, current 5G deployments lack pervasive telemetry, fine-grained observability, and automated control mechanisms capable of reacting at the time scales required by latency-sensitive applications. This paper presents a full integrated demonstration of DESIRE6G, a cloud-native 6G-ready architecture that leverages programmable data planes with P4 for flexible routing and telemetry using an implementation of novel data plane protocols, achieves distributed optimization of service deployment and runtime monitoring and reconfiguration via secure multi-agent systems (MAS), combined with intent-based orchestration layer for end-to-end service assurance. The system is validated on the federated ARNO testbed using a real distributed AR application involving a remotely-controlled drone as a User-Equipment that is equipped with a camera streaming a live video through the DESIRE6G network to a Kubernetes edge cluster that executes serverless inference functions for object detection and recognition, the video is then augmented with object information and shown on a Quest 3 AR headset. The MAS monitors the end-to-end latency in real time through P4 Telemetry and responds to changes in network conditions by reconfiguring the affected segments, while the Kubernetes monitoring provides real-time visibility and scalability across different segments. Overall, three hierarchical service assurance loops are demonstrated: (i) In-Network Control (INC) executing microsecond-scale congestion recovery in the P4 data plane, (ii) Infrastructure Management Layer (IML) performing millisecond-scale function migration and scaling, and (iii) MAS-driven cross-domain optimization operating at sub-second time scales to resolve RAN latency anomalies. Evaluation results show stable end-to-end latency in the 15–25 ms range in steady-state conditions, with fast recovery during induced congestion ≤ 1 . 5 ms data plane reroute via P4 INC. Francesco Paolucci, Emilio Paolini, Faris Alhamed, Massimo Satler, Domenico Uomo, Michelangelo Guaitolini, Pol González, Marc Ruiz 0001, Luis Velasco 0001, Sándor Laki, Dávid Kis, Gergely Pongrácz, Attila Mihály, Anestis Dalgkitsis, Chrysa Papagianni, Anastassios Nanos, Stephen Parker, Vincent Lefebvre, M. Angoustures, Juan Jose Vegas Olmos, Andrea Sgambelluri |
Comput. Networks | 1 |
| 2025 | 6GUPF: A DPU-based Programmable User Plane Function for Enhanced Flow-based QoSabstractTraditional 5G user plane function (UPF) architectures are software-based implementations that struggle to maintain performance. To meet the stringent quality of service (QoS) and scalability requirements of 5G under high session and data plane loads, a highly efficient next-generation UPF is required. In this paper, we present a next-generation 6GUPF that fully leverages the hardware acceleration of SmartNICs/DPUs. The 6GUPF is developed using DOCA Flow API, which enables fast, programmable packet processing directly in the data path, specifically for the N3 gNB network and N6 interfaces of datanet. The architecture integrates flow-based acceleration for stateful flow tracking and symmetric Receive Side Scaling (RSS) to utilize cores and manage non-blocking states efficiently. This will help minimize latency and avoid contention in multi-core environments. Our experiments show that hardware-offloaded UPF achieves an aggregate line rate of 400 Gbit/s, supports 1 million concurrent data streams, and scales up to 500,000 active User Equipment (UE) instances while maintaining QoS and session isolation. It also enables 40% lower latency compared to traditional software UPFs. Unlike Tofino-based P4 switch UPF designs, which are limited by SRAM and TCAM constraints when storing large-scale data streams, our DPU-based solution is ideal for high-density Protocol Data Unit (PDU) deployments without sacrificing programmability and performance. It creates a path for cloud-native, 6G UPF deployments that can scale to a wide range of workloads, from ultra-low-latency applications to large-scale IoT backhaul. Rana Abubakar, Ahmed Salah Tawfik Ibrahim, Francesco Paolucci, Andrea Sgambelluri, Piero Castoldi, Filippo Cugini, Juan Jose Vegas Olmos |
GLOBECOM | 3 |
| 2025 | IDS-NGNN: A SmartNIC-based Intrusion Detection System Based on Reduce and Merge Nested Graph Neural NetworksabstractThe growing complexity of network attacks has outpaced the capabilities of traditional intrusion detection systems (IDS), which often rely on flat data structures that fail to capture complex relationships within networks. To address this limitation, we propose IDS-NGNN, a novel IDS that integrates hardware-offload SmartNIC preprocessing with a nested graph neural network (NGNN) architecture. Unlike standard Graph Neural Networks (GNN), IDS-NGNN jointly captures local and global dependencies using a three-layer design: an internal GNN for host-level activity, a nested graph module for hierarchical aggregation, and an external GNN for inter-host communication. SmartNIC acceleration enables efficient real-time processing of large-scale graph-structured network data at the edge. We evaluate IDS-NGNN on six public IDS datasets, including CIC-IDS-2017, CSE-CIC-IDS-2018, and ToN-IoT. Experimental results demonstrate that IDS-NGNN achieves up to 95% accuracy and 92% F1-score, while maintaining efficiency suitable for real-time 100 Gbps deployments. Rana Abubakar, Francesco Paolucci, Filippo Cugini, Juan Jose Vegas Olmos, Lorenzo De Marinis |
GLOBECOM | 2 |
| 2025 | P4 programmability for fault-tolerant Software Defined Flying ad-hoc NetworkabstractThis paper introduces the issue of highly available Software Defined Flying ad-hoc Network for critical real-time applications. FANETs are a particular implementation of VANET (Vehicle Ad-hoc NETworks) where the vehicles, in the specific case, are Unmanned Aerial Vehicles (UAV), or drones. VANETs in general suffer from the mobility of the nodes, which can lead to continuous disconnections and topology changes. This issue becomes particularly troublesome for Flying ad-hoc networks (FANET), which are characterized by flying nodes, with low node density and a high rate of topology changes. On the other hand, nowadays, drones are widely used both in civil and industrial environments, and thus they may need to satisfy certain requirements in terms of the availability of communication. In the traditional distributed networks, the propagation of the information when there is a change in the topology, and the consequential update of the information in each switch, can introduce long periods of unavailability, which cannot be tolerated in certain contexts. For this reason, we decided to introduce an approach based on SND to manage FANET in an efficient and reliable way. The SDN architecture relies on a centralized controller to configure the network devices by exploiting a control plane channel. However, having a centralized controller implies a single point of failure. Moreover, control plane links are critical in SDN, since the controller uses those links to update the configuration of the switches. In order to efficiently introduce the SDN paradigm in a dependable FANET it is worth considering a novel approach, where the controller is responsible for the main routing decisions, but the network is able to operate autonomously and tolerate topology changes, within a certain degree, even when the SDN controller is not connected. The proposed architecture is a P4-SDN, that is capable of automatically rerouting traffic even when the controller can not communicate with the involved devices, providing then an additional level of redundancy. The programmable switches are instructed to take countermeasures when an unexpected link fault occurs and the controller is unreachable. In our solution, the controller configures both primary and backup actions for each expected flow, leveraging the programmability of P4-enabled devices. Thus, each switch can choose to forward the packets over the primary path or follow the backup action. Since these countermeasures are taken locally and independently from the controller, this approach allows the network to operate even when the control-plane link is unusable. It also improves the handover of the fault when the controller is reachable, minimizing critical application traffic disruptions. Domenico Uomo, Andrea Sgambelluri, Layal Ismail, Francesco Paolucci |
Comput. Networks | 4 |
| 2024 | Wire-speed DDoS Attack Mitigation using Hardware Acceleration of Programmable DPUsabstractService providers face significant challenges from Distributed Denial of Service (DDoS) attacks since existing mitigation techniques, including various Machine Learning and flow-based approaches, often lack efficiency due to high latency and inadequate filtering. This paper proposes a novel DDoS mitigation strategy using programmable Data Processing Units (DPUs) to offload detection and mitigation processes, utilizing hardware acceleration. Our approach leverages DPUs to execute flow-based filtering, focusing on mitigating TCP SYN flood attacks. We demonstrate that our DPU-based hardware-accelerated framework successfully eliminates, after a fast learning phase, all the malicious traffic while maintaining high data throughput up to 100 Gbps. Stefano Hinic, Rana Abubakar, Andrea Marotta, Francesco Paolucci |
GLOBECOM | 4 |
| 2024 | 5GDAD: A Deep Learning Approach for DDoS Attack Detection in 5G P4-based UPFabstractThe fast-paced growth of 5G networks, along with the emergence of 6G technology, has emphasized the crucial importance of strong security measures to safeguard communication infrastructures. A key security issue in 5G data networks is Distributed Denial-of-Service (DDoS) at tacks, which specifically target the GTP-based protocol which is a significant threat. However, network telemetry data provides a rich source of information about the nature of network traffic, which can be used to detect and predict DDoS attacks. We propose a novel framework for collecting and processing large amounts of telemetry data in 5G networks leveraging state-of-the-art technologies, including data-plane programmability in P4-based User-Plane Function (UPF) and Data Processing Unit (DPU). Furthermore, we propose an anomaly-detection method for performing live deep learning analysis on network traffic using a Convolutional Neural Network (CNN) to detect DDoS attacks. Our results demonstrate the effectiveness of our framework, achieving an impressive 98.6% accuracy and 98% F1-score. Rana Abubakar, Faris Alhamed, Piero Castoldi, Andrea Sgambelluri, Juan Jose Vegas Olmos, Filippo Cugini, Francesco Paolucci |
HPSR | 7 |
| 2024 | FTG-Net-E: A hierarchical ensemble graph neural network for DDoS attack detectionabstractDistributed Denial-of-Service (DDoS) attacks are a major threat to computer networks. These attacks can be carried out by flooding a network with malicious traffic, overwhelming its resources, and/or making it unavailable to legitimate users. Existing machine learning methods for DDoS attack detection typically use statistical features of network traffic, such as packet sizes and inter-arrival times. However, these methods often fail to capture the complex relationships between different traffic flows. This paper proposes a new DDoS attack detection approach that uses Graph Neural Networks (GNN) ensemble learning. GNN ensemble learning is a type of machine learning that combines multiple GNN models to improve the detection accuracy. We evaluated our approach on the Canadian Institute for Cybersecurity Intrusion Detection Evaluation Dataset (CICIDS2018) and CICIDS2017 datasets, a benchmark dataset for DDoS attack detection. Our work provides two main contributions. First, we extend our DDoS attack detection approach using GNN ensemble learning. Second, we explore the evaluation and fine-tuning of hyperparameter metrics through ensemble learning, significantly enhancing accuracy compared to a single GNN model and achieving an average 3.2% higher F1-score. Additionally, our approach effectively reduces overfitting by incorporating regularization techniques, such as dropout and early stopping. Specifically, we use a hierarchical ensemble of GNN, where each GNN learns the relationships between traffic flows at a different granularity level. We then use bagging and boosting to combine the predictions of the individual GNN, further improving detection accuracy. Results show that our system can achieve 99.67% accuracy, with a F1-score of 99.29%, which is better than state-of-the-art methods, even using single traffic architecture. Rana Abubakar, Lorenzo De Marinis, Filippo Cugini, Francesco Paolucci |
Comput. Networks | 4 |
| 2024 | P4 FANET In-band Telemetry (FINT) for AI-assisted wireless link failure forecasting and recoveryabstractThis paper introduces a novel framework for enhancing quality of service predictability in Flying ad hoc Networks (FANET) by leveraging P4 data-plane programmability. The proposed solution, P4 FANET In-Band Telemetry (FINT), is specifically designed to tailor the limited resources in wireless networks and is extended to collect not only the standard INT metadata but also novel essential Unmanned Aerial Vehicles (UAV) real-time metrics, including Received Signal Strength Indicator (RSSI), geolocation information and CPU load. These parameters are then fed into an artificial intelligence (AI) system, enabling proactive prediction of FANET link failures. By integrating P4 FINT and AI, our framework aims to improve the availability and overall performance of UAV-based networks through advanced link failure forecasting. Layal Ismail, Domenico Uomo, Andrea Sgambelluri, Faris Alhamed, Francesco Paolucci |
Comput. Networks | 5 |
| 2023 | Cascaded Look Up Table Distillation of P4 Deep Neural Network SwitchesabstractIn-network function offloading represents a key enabler of the SDN-based data plane programmability to enhance network operation and awareness while speeding up applications and reducing the energy footprint. The offload of network functions exploiting machine learning and artificial intelligence has been recently considered with intermediate solutions such as feature extraction acceleration and mixed architectures including AI-specific platforms (e.g., GPU, FPGA). Indeed, the P4 language enables the programmability of deep neural networks inside the pipelines of both software and hardware switches and NICs. However, programmable hardware pipeline chipsets suffer from significant computing capability limitations (e.g., missing arithmetic logic units, limited and slow stateful registers) preventing the plain programmability of a deep neural network (DNN) operating at wirespeed. This paper proposes an innovative knowledge distillation technique that maps a DNN into a cascade of lookup tables (i.e., flow tables) with limited entry size. The proposed mapping avoids stateful elements and maths operators, whose requirement prevented the deployment of DNNs within hardware switches up to now. The evaluation is carried out considering a cyber security use case targeting a DDoS mitigator network function, showing negligible impact due to the lossless mapping reduction and feature quantization. Lorenzo De Marinis, Emilio Paolini, Rana Abubakar, Filippo Cugini, Francesco Paolucci |
GLOBECOM | 5 |
| 2023 | FTG-Net: Hierarchical Flow-to-Traffic Graph Neural Network for DDoS Attack DetectionabstractDistributed Denial of Service (DDoS) is one of the most common cyber-attacks and caused several damages in recent years. Such attacks can be executed either through the orchestration of multiple devices that synchronously send requests or through specific patterns followed by a single device to force the victim to keep resources overrun. It becomes crucial to develop robust techniques to promptly detect those two kinds of DDoS attacks and mitigate their consequences. Most of the existing Machine Learning (ML) methods are based on flow and traffic information aggregations expressed in the form of independent vectors of statistical data, ignoring topological connections. Few recent solutions try to exploit the structural information of the network to improve the classification results. In particular, Graph Neural Network (GNN) based models can process traffic-level or flow-level relationships, represented as graphs, to detect malicious patterns.The objective of this paper is to combine the relationships at both the traffic-level and the flow-level by developing a two-level hierarchical graph representation and a GNN model able to process it, maximizing the information brought by the traffic structure and removing the necessity of stateful features. Experiments on the CIC-IDS2017 dataset show that the performances are comparable to the state-of-the-art solutions even using only the traffic structure. Luca Barsellotti, Lorenzo De Marinis, Filippo Cugini, Francesco Paolucci |
HPSR | 4 |
| 2023 | Failure Prediction in Software Defined Flying Ad-hoc NetworkabstractThis research aims to propose an approach to address the unpredictability topology state issue of FANET. The mobility of the network can lead to frequent link disruptions, causing communication unavailability. To mitigate this, our goal is to implement an AI algorithm that can identify patterns in UAV mobility, predict potential disconnections, and trigger rerouting/forwarding algorithms in advance. This paper presents an example of an SD-FANET able to provide wireless in-band telemetry to the AI-equipped edge node placed at the ground station, discusses the design of subsystems hosting the AI process, and demonstrates how a machine learning model can recognize critical network situations without relying on complex neural networks. Domenico Uomo, Andrea Sgambelluri, Piero Castoldi, Emiliano De Paoli, Francesco Paolucci, Filippo Cugini |
MobiHoc | 5 |
| 2023 | P4 Telemetry collector
Faris Alhamed, Davide Scano, Piero Castoldi, Juan Jose Vegas Olmos, Ilya Vershkov, Francesco Paolucci, Filippo Cugini |
Comput. Networks | 6 |
| 2023 | P4-assisted seamless migration of serverless applications towards the edge continuumabstractServerless computing has recently been presented as an effective technology for handling short-lived compute tasks in the cloud. It has the potential of becoming an attractive option also in the context of edge computing where resource-aware deployment, constrained by both limited edge computing resources and experienced latency, plays a vital role. In this paper, we present and experimentally validate a framework that oversees serverless applications in an edge computing scenario. It completely automates serverless application deployment and provides hitless dynamic migration of application compute tasks between a pair of edge nodes, paving the way for handling significantly more complex cases. The framework relies on an integrated deployment, monitoring and offloading infrastructure that enhances AWS IoT Greengrass features and performance. Our implementation provides two separate options for relocating compute tasks by steering application traffic towards the most suitable node. One builds on an on-the-fly application component reconfiguration, while the other selects the suitable node through P4 in-network processing of resource metrics emitted by the nodes. Our experimental demonstration evaluates the migration performance using a latency-sensitive application decomposed to serverless functions. Results reveal extremely fast dynamic reconfiguration and traffic rerouting operations. The used methods avoid congestion peaks at the edge and show no end-to-end latency increase upon migration between the nodes. István Pelle, Francesco Paolucci, Balázs Sonkoly, Filippo Cugini |
Future Gener. Comput. Syst. | 2 |
| 2022 | Introducing Data Processing Units (DPU) at the Edge [Invited]abstractThe recent availability of smart network interface cards (smart NICs) and Data Processing units (DPUs) providing hardware-accelerated networking and computing functionalities is opening the way towards new applications and use cases beyond the traditional data center scenarios. In this paper, three different use cases for edge scenarios that leverage on the innovative programmability enabled by DPUs are presented and discussed. The first use case focuses on a pervasive monitoring infrastructure to support accurate and decentralized network awareness for low-latency 5G services. The second one focuses on the implementation of power-efficient edge-to-cloud continuum. The third use case refers to effective network security functions at the DPU. Luca Barsellotti, Faris Alhamed, Juan Jose Vegas Olmos, Francesco Paolucci, Piero Castoldi, Filippo Cugini |
ICCCN | 4 |
| 2022 | Latency control in service chaining using P4-based data plane programmability
Francesco Paolucci, Davide Scano, Piero Castoldi, Emiliano De Paoli |
Comput. Networks | 1 |
| 2021 | P4 Programmability at the Network Edge: the BRAINE Approach [Invited]abstractNetwork programmability based on the P4 language is gaining consensus in multiple scenarios, including edge computing. In this work, we present the P4-based edge networking solutions adopted in the framework of the EU-funded BRAINE Project. The project targets the design and development of a powerful edge micro data center (EMDC) aiming at boosting artificial intelligence (AI) at the network edge. The EMDC will encompass an embedded programmable P4 ASIC supporting unprecedented intra- and inter-edge/fog interconnection. In this paper, a selection of the solutions to be supported by the P4 switch embedded within the BRAINE EMDC is presented. They include decentralized traffic engineering solutions driven in-band telemetry (INT), quality of service enforcement and verification, 5G network function virtualization, and decentralized cyber-security at the edge. Filippo Cugini, Davide Scano, Alessio Giorgetti, Andrea Sgambelluri, Piero Castoldi, Francesco Paolucci |
ICCCN | 6 |
| 2021 | Latency-Sensitive Edge/Cloud Serverless Dynamic Deployment Over Telemetry-Based Packet-Optical NetworkabstractThe serverless technology, introduced for data center operation, represents an attractive technology for latency-sensitive applications operated at the edge, enabling a resource-aware deployment accounting for limited edge computing resources or end-to-end network congestion to the cloud. This paper presents and validates a framework for automated deployment and dynamic reconfiguration of serverless functions at either the edge or cloud. The framework relies on extensive telemetry data retrieved from both the computing and packet-optical network infrastructure and operates on diverse Amazon Web Services technologies, including Greengrass on the edge. Experimental demonstration with a latency-sensitive serverless application is then provided, showing fast dynamic reconfiguration capabilities, e.g., enabling even zero outage time under certain conditions. István Pelle, Francesco Paolucci, Balázs Sonkoly, Filippo Cugini |
IEEE J. Sel. Areas Commun. | 2 |
| 2020 | Machine-learning-assisted DDoS attack detection with P4 languageabstractWhile Software Defined Networking (SDN) provides well-known advantages in terms of network automation, flexibility and resources utilization, it has been observed that SDN controllers may represent critical points of failure for the entire network infrastructure, especially when they are targeted by malicious cyber attacks such as Distributed Denial of Service (DDoS). To address this issue, in this paper we exploit stateful data planes, as enabled by P4 programming language, where switches maintain persistent memory of handled packets to perform attack detection directly at the data plane, with only marginal involvement of the SDN controllers. As machine learning (ML) is recognized as primary anomaly detection methodology, we perform DDoS attack detection using a MLbased classification and compare different ML algorithms in terms of classification accuracy and train/test duration. Moreover, we combine ML and P4-enab1ed stateful data planes to design a real-time DDoS attack detection module, which we evaluate in terms of latency required for the detection. Three real-time scenarios are considered, where P4-enab1ed switches elaborate the received packets in different ways, namely, packet mirroring, header mirroring, and P4-metadata extraction. Numerical results show significant latency reduction when P4 is adopted. Francesco Musumeci 0001, Valentina Ionata, Francesco Paolucci, Filippo Cugini, Massimo Tornatore |
ICC | 3 |
| 2016 | An incentive-compatible and trust-aware multi-provider path computation element (PCE)
Molka Gharbaoui, Barbara Martini, Carol J. Fung, Francesco Paolucci, Alessio Giorgetti, Piero Castoldi |
Comput. Networks | 4 |
| 2015 | Hierarchical OAM Infrastructure for Proactive Control of SDN-Based Elastic Optical NetworksabstractElastic Optical Networks will drive a high degree of flexibility enabling dynamic configurable lightpaths provisioning and re- optimization due to next generation bandwidth variable transponders and switches. In order to guarantee quality of transmission (QoT), novel Operation Administration and Maintenance (OAM) solutions are necessary with respect to existing standard management protocols. For optical networks, scalable mechanisms providing fast and effective QoT alarm information, including localization and, possibly, forecasting critical events, are needed. The introduction of the Application Based Network Operation (ABNO) architecture is pushing towards a dedicated OAM Handler, in charge of collecting OAM information from the network, performing correlations and triggering control plane reaction. However, serious scalability issues may arise since a centralized element would have to elaborate a potentially huge amount of data. In this paper, a novel hierarchical OAM architecture is proposed, that enables multi- level OAM entities to provide OAM Handler with effective information, obtained by filtering several OAM messages at each layer, so that the overload of OAM Handler is avoided. Moreover, the NETCONF protocol, typically used for SDN- based node configuration purposes, is proposed and utilized as OAM protocol, in order to achieve high degree of convergence and limit the number of utilized protocols. The proposed OAM architecture is implemented and experimentally evaluated in a QoT degradation use case, showing that multi-level localization and local correlation of events allow aggregated, fast and scalable OAM information set provided to the OAM Handler. Francesco Paolucci, Andrea Sgambelluri, Nicola Sambo, Filippo Cugini, Piero Castoldi |
GLOBECOM | 1 |
| 2014 | Quality of interaction among path computation elements for trust-aware inter-provider cooperationabstractPath Computation Element (PCE) architecture enables effective traffic engineering in multi-domain networks while limiting the exposure of intra-domain information. However, returned path computations might reveal confidential information if artfully correlated by a malicious PCE. Thus, the selection of domains sequence as the result of PCEs cooperation should depend not only on the capability of providing quality paths but also on factors related to expected revenues or perceived risks. In this scenario, cooperation among PCEs could benefit from a trust model by evaluating the quality of the past interactions. This work introduces the concepts of Quality of Interaction and trust ranking and elaborates a trust management model including effectiveness and security objectives regulating the cooperation among PCEs. Specifically, the proposed trust model aims at stimulating effective interactions among PCEs as a result of a common interest in contributing to successful and profitable path computations while avoiding misuse of path computation services. The simulation results show that our trust model is effective in detecting malicious PCE thereby tuning the amount of information returned in the path computation replies. Carol J. Fung, Barbara Martini, Molka Gharbaoui, Francesco Paolucci, Alessio Giorgetti, Piero Castoldi |
ICC | 4 |
| 2013 | Guaranteeing confidentiality in multi-domain networks: The PCE Anomaly Detector (PAD)
Molka Gharbaoui, Francesco Paolucci, Alessio Giorgetti, Piero Castoldi, Barbara Martini |
IM | 2 |
| 2013 | Performance Analysis of Media Redundancy Protocol (MRP)abstractThe International Electrotechnical Commission (IEC) recently standardized several Industrial Ethernet solutions that introduce the fieldbus concepts within Ethernet based networks. In addition, the IEC 62439 standardized a set of redundancy management protocols, including the Media Redundancy Protocol (MRP). In this way, IEC standards provide a variety of Ethernet-based solutions for satisfying both temporal and redundancy management requirements of Industrial Area Networks (IANs). In this paper, after a detailed study and implementation of MRP, two factors are identified that have an important impact on the protocol performance: the offset time and the physical detection time. A method is then provided to calculate a threshold to the network recovery time. Finally, extensive simulations and experimental measurements are performed to accurately evaluate the effect of the aforementioned factors on the protocol performance. Alessio Giorgetti, Filippo Cugini, Francesco Paolucci, Luca Valcarenghi, Alessia Pistone, Piero Castoldi |
IEEE Trans. Ind. Informatics | 3 |
| 2013 | Effective Statistical Detection of Smart Confidentiality Attacks in Multi-Domain NetworksabstractThe need to preserve information confidentiality among network providers has prevented the actual deployment of effective Traffic Engineering (TE) solutions for QoS-enabled end-to-end connectivity services in multi-domain multi-provider networks. The use of Path Computation Element (PCE) architecture can foster the effective implementation of TE through a centralized engine devoted to end-to-end path computations. However, despite authentication, authorization and encryption, confidentiality issues may arise due to abuses of information included in path computation replies to bogus requests issued by malicious PCEs. This paper first demonstrates the security leak allowing the exposure of intra-domain information in current inter-PCE path computation procedures. Then it proposes an anomaly-based approach, namely PCE Anomaly Detector (PAD) in order to detect malicious utilization of path computation services. The proposed PAD employs a novel double-step multi-dimensional formulation based on the Sequential Hypothesis Testing (SHT) statistical classification procedure, able to recognize a suspicious sequence of requests while aiming at inferring confidential information about other domains. PAD is extensively evaluated through simulations. Results show good performance in terms of detection capabilities while guaranteeing the trade-off between accuracy and responsiveness, minimizing false alarm occurrences. Robustness against smart attacks is also proved with respect to a comprehensive set of attack patterns and under different network load conditions. Finally, intra-domain information exposition is evaluated, showing the PAD ability to preserve confidentiality. Molka Gharbaoui, Francesco Paolucci, Alessio Giorgetti, Barbara Martini, Piero Castoldi |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2012 | Experimenting push-pull defragmentation in flexible optical networks with direct detectionabstractIn flexi-grid optical networks, effective defragmentation (i.e., re-optimization) solutions are required to efficiently exploit network spectrum resources. However, current defragmentation solutions can only be implemented thanks to the presence of additional resources, such as spare extensive transponders. In this study, focusing on optically-amplified direct-detection systems, we experimentally demonstrate the feasibility of a novel defragmentation technique, called push-pull, based on dynamic lightpath frequency retuning upon proper reconfiguration of allocated spectrum resources. The technique does not require additional transponders and does not determine traffic disruption. All the relevant technological limitations that may affect the push-pull applicability are discussed. A simple yet effective closed-form expression is also proposed and experimentally validated to assess the maximum retuning range in a single push-pull operation, such that the quality of transmission during defragmentation is safely guaranteed. The technique is then successfully demonstrated in a flexi-grid network testbed. In particular the reoptimization of one lightpath is safely completed in few seconds (mainly due just to node configuration latencies) without experiencing any traffic disruption. Filippo Cugini, Francesco Paolucci, Gianluca Berrettini, Marco Secondini, Francesco Fresi, Gianluca Meloni, Nicola Sambo, Luca Potì, Piero Castoldi |
GLOBECOM | 2 |
| 2012 | Statistical approach for detecting malicious PCE activity in multi-domain networksabstractInter-domain traffic engineering solutions based on the Path Computation Element (PCE) architecture are exposed to information confidentiality issues between network carriers. Licit PCE Protocol (PCEP) request sequences may hide a malicious intention to discover critical intra-domain information through correlations among replies. This work presents an innovative anomaly-based statistical approach based on the Sequential Hypothesis Testing (SHT) aiming to detect malicious utilization of PCEP by peer clients. A novel combined multi-feature SHT formulation is presented in combination with different decision policies for definitely ascertaining whether the behavior of the Path Computation Client (PCC) is malicious or not. Simulation results show improved performance in terms of detection and falsealarms probabilities while guaranteeing a trade-off between detection accuracy and delay. Molka Gharbaoui, Francesco Paolucci, Alessio Giorgetti, Barbara Martini, Piero Castoldi |
HPSR | 2 |
| 2010 | Hierarchical Border Gateway Protocol (HBGP) for PCE-Based Multi-Domain Traffic EngineeringabstractIn multi-domain multi-carrier networks the effective use of network resources shall be achieved while guaranteeing an adequate level of confidentiality and scalability. A candidate solution to perform effective multi- domain Traffic Engineering (TE) is based on a combination of (i) hierarchical routing and (ii) path computation procedures. Hierarchical routing identifies the domain sequence to cross while path computation computes the strict end to end path. In this multi-domain study we first propose a hierarchical instance of BGP (HBGP) dedicated to TE information only. Then we propose and evaluate the integration of HBGP with path computation procedures based on IETF PCE architecture. Simulation results show that the hierarchical HBGP-PCE architecture, compared to current routing solutions based on BGP only, significantly improves the overall network resource utilization. In addition, this study identifies the network scenarios in which the aforementioned HBGP-PCE features provide significant advantages. Finally, the experimental implementation of the proposed HBGP-PCE architecture in a network testbed composed of commercially available routers shows the viability of the solution in real networks. Luca Buzzi, Matteo Conforto Bardellini, Domenico Siracusa, Guido Maier, Francesco Paolucci, Filippo Cugini, Luca Valcarenghi, Piero Castoldi |
ICC | 5 |
| 2009 | Experimental Evaluation of PCE-Based Batch Provisioning of Grid Service InterconnectionsabstractIf dynamic bandwidth-guaranteed connections between distributed services (e.g., grid services) are provisioned through a centralized system, the policy to serve connection requests might heavily impact both the success in and the time required for setting up user services (e.g., grid-enabled applications). In this paper, the implementation of a batch queue in the centralized system is proposed. By implementing different service policies for the queued requests, connections and, in consequence, user services can be set up with different guarantees. In this study, a bulk-service policy is proposed and implemented to maximize connection set up success. The experimental evaluation results show that the utilization of the proposed policy brings advantages in terms of percentage of accepted connection requests as the number of requests served in one batch increases. Moreover, the achieved improvement does not impact the time required to set up the connections because of the specific LSP set up procedures implemented in the utilized commercial routers. Luca Valcarenghi, Pawel Korus, Francesco Paolucci, Filippo Cugini, Miroslaw Kantor, Krzysztof Wajda, Piero Castoldi |
GLOBECOM | 3 |
| 2009 | A Recursive Distributed Topology Discovery Service for Network-Aware Grid ClientsabstractDistributed application (e.g., grid-enabled application) performance is highly dependent on the information available when computational resources are chosen. A resource selection based on computational resource information complemented with network performance information has the potential to be optimal from the application performance viewpoint. This is particularly true for network-intensive distributed applications. This study proposes a recursive distributed topology discovery service (RD-TDS) that allows grid clients to retrieve network performance information (i.e., IP-level topology and link capacity) without the need of specific administrative privileges. The RD-TDS exploits a selected set of distributed beacons (i.e., measurement points) that recursively probe newly discovered nodes until no undiscovered nodes are found during an exploration step. The RD-TDS simulative and experimental evaluation confirms its expected qualities: a rapid and complete discovery of the network performance information with the utilization of a limited number of active beacons. In addition, the proposed method rationale can be easily applied to many current network exploration tools. Francesco Paolucci, Luca Valcarenghi, Piero Castoldi, Filippo Cugini |
ICC | 1 |
| 2007 | Topology discovery and performance information services for optical gridsabstractGlobal Grid Computing goal is to connect heterogeneous computational resources belonging to the same Virtual Organization (VO) through the Internet to form a single, more powerful virtual computer. However, to fulfill this goal it is necessary to develop services that provide the virtual computer with the same functionalities of individual end systems, such as security, interprocess communication, and resource management. Luca Valcarenghi, Francesco Paolucci, Piero Castoldi, Filippo Cugini, Davide Adami, Domenico Ficara, Stefano Giordano |
BROADNETS | 2 |
| 2007 | The Beacon Number Problem in a Fully Distributed Topology Discovery ServiceabstractIn grid computing the need for collecting information about both distributed computational resources and network topology and performance is constantly growing. Several tools are currently under development to provide such information. They are based either on a centralized or a distributed architecture. Distributed tools are commonly based on IP-level application- oriented network metrology. The measurements are done by means of beacons running in some network nodes (e.g., grid hosts) and collecting the required information. However, the number of utilized beacons might heavily impact the final result, i.e. the discovered topology and the collected performance information. In this study a model is developed to estimate the percentage of discovered links provided that a specific number of beacons is placed in the network. The model is developed for Erdos-Renyi (ER) graph network models but it can be applied also to other networks. Numerical evaluation shows that the model closely approximate the percentage of discovered links obtained through simulation for ER networks. For other theoretical and real networks the model overestimates the percentage of discovered links. However experimental results show that for networks with realistic average nodal degree the overestimate is less than 20%. Domenico Ficara, Francesco Paolucci, Luca Valcarenghi, Filippo Cugini, Piero Castoldi, Stefano Giordano |
GLOBECOM | 2 |
| 2006 | Network Resource Management in High-Quality NetworksabstractThis paper presents the architecture, some specific supporting functions and an experimental validation of a new functional plane, namely the service plane, for realizing an added-value service provisioning (e.g., grid connectivity) for telecommunication operators. First, it is shown as the service plane can be a viable solution for decoupling service and transport development, by masking the transport-related implementation details from the abstract request of a service by a customer or by a qualified application. To this purpose, the service plane exports a high-level interface for supporting application-initiated invocation of QoS-enabled virtual private networks (VPN) or connection-less services. As a significant use case for a grid user, a VPN set-up through the service plane is experimentally demonstrated. Second, some of the main functions that the service plane should support are presented in detail and experimentally assessed, namely a centralized topology discovery service (C-TDS) and path computation service (PCS). As an example, from a grid user perspective, the C-TDS can provide up-to-date information on the grid topology according to various levels of abstraction (physical topology, MPLS topology, and logical topology). Several techniques for the grid topology discovery and various update policies are investigated. PCS elaborates upon the logical topology obtained by TDS and runs linear programming (LP) formulations to identify optimal traffic engineering solutions according to specific objective functions. The combination of C-TDS and PCS represents an an enhanced level of network- awareness in the (network) middleware supporting global grid computing (i.e., grid computing in wide area networks). Experiments performed on IP/MPLS metropolitan network based on commercial routers exhibit a topology delivery performance within a time span in the order of a few seconds and a PCS operation in the order of ten seconds. Piero Castoldi, Luca Valcarenghi, Francesco Paolucci, Valerio Martini, Fabio Baroncelli, Filippo Cugini, Barbara Martini |
BROADNETS | 3 |