VLDB 2026 Research / reviewers in the wild / expert
Ítalo S. Cunha
dblp:80/186 · also Ítalo Cunha
· DBLP profile ↗
60ranked-venue papers
9as first author
15since 2021 · last 2025
0000-0002-5756-7775ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 44 · 6 first-author · 10 since 2021Security and privacy · 5 · 2 first-authorGraphics, computer vision, multimedia, augmented reality and games · 4 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | RemapRoute: Local Remapping of Internet Path ChangesabstractSeveral systems rely on traceroute to track a large number of Internet paths as they change over time. Monitoring systems perform this task by remapping paths periodically or whenever a change is detected. This paper shows that such complete remapping is inefficient, because most path changes are localized to a few hops of a path. We develop RemapRoute, a tool to remap a path locally given the previously known path and a change point. RemapRoute sends targeted probes to locate and remap the often few hops that have changed. Our evaluation with trace-driven simulations and in a real deployment shows that local remapping reduces the average number of probes issued during remapping by 63% and 79%, respectively, when compared with complete remapping. At the same time, our results show that local remapping has little impact on the accuracy of inferred paths. Elverton C. Fazzion, Giancarlo Oliveira Teixeira, Darryl Veitch, Christophe Diot, Renata Teixeira, Ítalo S. Cunha |
IMC | 6 |
| 2025 | Distributed Graph Neural Networks in Programmable Data PlanesabstractThe ability to redefine the data plane behavior with programmable network devices provides a plethora of novel possibilities for in-network computing. One of these possibilities is embedding Artificial Intelligence (AI) and Machine Learning (ML) techniques directly in the data plane. Motivations include reducing decision latency and closing the control loop-i.e., performing measurements, learning, decisions, and actions directly in the data plane. However, running entire AI/ML algorithms in a single device might be infeasible due to memory and computing constraints. This work addresses the research challenges of running a Graph Neural Network (GNN) in a set of devices of a programmable data plane. Our hypothesis is that by distributing the GNN processing across the devices, the GNN uses instantaneous snapshots of the global network state and can act more quickly. As a proof of concept, we trained and evaluated a distributed GNN to perform explicit congestion notifications based on Data Center Transmission Control Protocol (DCTCP). We verified the feasibility of GNN classification in the data plane through simulations and both software and hardware switch experiments with bmv2 and Intel Tofino. Ivan Peter Lamb, Pedro Arthur Pinheiro Rosa Duarte, Jonatas Adilson Marques, Marcelo Caggiani Luizelli, Luciano Paschoal Gaspary, Anderson Tavares, Ronaldo A. Ferreira, Ítalo S. Cunha, José Rodrigo Azambuja, Weverton Luis da Costa Cordeiro |
NOMS | 8 |
| 2025 | Automatic Inference of BGP Community SemanticsabstractThe Border Gateway Protocol (BGP) enables communication between Autonomous Systems (ASes) and is the de facto interdomain routing protocol of the Internet. BGP offers significant flexibility for traffic engineering through BGP communities, which are operator-defined tags that convey information or requests in route announcements between ASes. Unfortunately, the absence of standardized semantics or centralized repositories for BGP communities complicates and limits their use, hindering the effective management of interdomain routing. This thesis develops techniques to infer BGP community semantics using public BGP data from routing collectors, overcoming the lack of documentation and providing datasets that can be automatically updated. We first propose a set of techniques to infer location communities, which are communities related to entities or locations traversed by a route. We apply our techniques to billions of routing records from public BGP collectors and show that they produce high precision (ranging from 86% to 93%) and recall (ranging from 72% to 81%). We also design and evaluate algorithms to automatically uncover BGP action communities and ASes that violate standard practices, revealing undocumented relationships between them (e.g., sibling relationships). Our experimental evaluation uncovers previously unknown AS relationships and shows that our algorithm to identify action communities achieves average precision and recall of 92.5% and 86.5%, respectively. Brivaldo Alves da Silva, Ítalo S. Cunha, Ronaldo A. Ferreira |
NOMS | 2 |
| 2024 | RPSLyzer: Characterization and Verification of Policies in Internet Routing RegistriesabstractThe Routing Policy Specification Language (RPSL) enables operators to specify routing policies in public registries. These policies contain information for traffic engineering, troubleshooting routing incidents, and automatically configuring route filters to improve security. RPSL information is also valuable for researchers to better understand the Internet. However, the RPSL's complexities make these policies challenging to interpret programmatically. We introduce RPSLyzer, a tool that can parse and interpret 99.99% of RPSL policies. We use RPSLyzer to characterize the RPSL policies of 78,701 Autonomous Systems (ASes) and verify 779 million BGP routes against these policies. We find RPSL usage varies widely among ASes, identify common RPSL misuses that explain most route verification failures, and offer operators recommendations to improve RPSL usage. Sichang Steven He, Ítalo S. Cunha, Ethan Katz-Bassett |
IMC | 2 |
| 2024 | metAScritic: Reframing AS-Level Topology Discovery as a Recommendation SystemabstractDespite prior efforts, the vast majority of the AS-level topology of the Internet remains hidden from BGP and traceroute vantage points. In this work, we introduce metAScritic, a novel system inspired by recommender system literature, designed to infer interconnections within a given metro. metAScritic uses the intuition that the connectivity matrix at a given metro is a low-rank system, since ASes employ similar peering strategies according to their infrastructures, traffic profiles, and business models. This approach allows metAScritic to accurately reconstruct the complete peering connectivity by measuring a strategic subset of interconnections that capture ASes' underlying peering strategies. We evaluate metAScritic's performance across six large metropolitan areas, achieving an average F-score of 0.88 on various validation datasets, including ground truth. metAScritic measures more than 86K edges and infers more than 368K edges, compared to the 13K edges observed for this subset of ASes in public BGP feeds -- an increase of (24X) what is currently seen. We study the impact of our inferred links on Internet properties, illustrating the extent of the Internet's flattening and demonstrating our ability to better predict the impact of route leaks and prefix hijacks, compared to relying only on the existing public view. Loqman Salamatian, Kevin Vermeulen, Ítalo S. Cunha, Vasileios Giotsas, Ethan Katz-Bassett |
IMC | 3 |
| 2024 | The Resource Public Key Infrastructure (RPKI): A Survey on Measurements and Future ProspectsabstractThe adoption of the Resource Public Key Infrastructure (RPKI) is increasing. To better understand and improve RPKI deployment, measuring route origin authorization (ROA) objects, RPKI route origin validation (ROV), and RPKI resilience is essential. In this paper, we survey RPKI-related research that aims to understand RPKI deployment. Additionally, we enrich our survey with many industry and IETF-related contributions. Our work provides an in-depth analysis of the many ideas and challenges discussed in studies of the RPKI ecosystem and includes lessons from mistakes made in the past, which we should avoid in the future. Nils Rodday, Ítalo S. Cunha, Randy Bush, Ethan Katz-Bassett, Gabi Dreo Rodosek, Thomas C. Schmidt, Matthias Wählisch |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2024 | State Disaggregation for Dynamic Scaling of Network FunctionsabstractNetwork Function Virtualization promises better utilization of computational resources by dynamically scaling resources on demand. However, most network functions (NFs) are stateful and require state updates on a per-packet basis. During a scaling operation, cores need to synchronize access to a shared state to avoid race conditions and to guarantee that NFs process packets in arrival order. Unfortunately, the classic approach to control concurrent access to a shared state with locks does not scale to today’s throughput and latency requirements. Moreover, network traffic is highly skewed, leading to load imbalances in systems that use only sharding to partition the NF states. To address these challenges, we present Dyssect, a system that enables dynamic scaling of stateful NFs by disaggregating the states of network functions. By carefully coordinating actions between cores and a central controller, Dyssect migrates shards and flows between cores for load balancing or traffic prioritization without resorting to locks or reordering packets. Also, Dyssect’s state disaggregation allows the offloading of stateful network functions to programmable NICs and makes it easier for exploring hardware-software tradeoffs that better suit specific service chains and traffic loads. Our experimental evaluation shows that Dyssect reduces tail latency up to 32.04% and increases throughput up to 19.36% when compared to state-of-the-art competing solutions. Fabrício B. Carvalho, Ronaldo A. Ferreira, Ítalo S. Cunha, Marcos A. M. Vieira, Murali Krishna Ramanathan |
IEEE/ACM Trans. Netw. | 3 |
| 2022 | Characterizing Low Credibility Websites in Brazil through Computer Networking AttributesabstractA key gear in most misinformation ecosystems is the deployment of fake news web sites that publish news in a similar fashion to how news articles are put out by credible sources. The content offered by these sites is disseminated in a complex process that may involve automation, exploitation of message apps and social network algorithms, political bias, and targeted ads to reach large and niche audiences. Due to this high complexity and the rapidly evolving nature of the problem, we are just beginning to understand patterns in the various misinformation ecosystems on the Web. In this work, we offer a first step towards understanding network properties, including data from DNS records, domain registration, TLS certificates, and hosting infrastructure of Brazilian web sites associated with the dissemination of misinformation content on digital platforms. Our findings, in addition to providing a better understanding of the misinformation ecosystem in Brazil, also reveal a novel set of features useful to distinguish low credibility web sites from others. João M. M. Couto, Julio C. S. Reis, Ítalo S. Cunha, Leandro Araújo, Fabrício Benevenuto |
ASONAM | 3 |
| 2022 | Internet scale reverse tracerouteabstractKnowledge of Internet paths allows operators and researchers to better understand the Internet and troubleshoot problems. Paths are often asymmetric, so measuring just the forward path only gives partial visibility. Despite the existence of Reverse Traceroute, a technique that captures reverse paths (the sequence of routers traversed by traffic from an arbitrary, uncontrolled destination to a given source), this technique did not fulfill the needs of operators and the research community, as it had limited coverage, low throughput, and inconsistent accuracy. In this paper we design, implement and evaluate revtr 2.0, an Internet-scale Reverse Traceroute system that combines novel measurement approaches and studies with a large-scale deployment to improve throughput, accuracy, and coverage, enabling the first exploration of reverse paths at Internet scale. revtr 2.0 can run 15M reverse traceroutes in one day. This scale allows us to open the system to external sources and users, and supports tasks such as traffic engineering and troubleshooting. Kevin Vermeulen, Ege Gürmeriçliler, Ítalo S. Cunha, David R. Choffnes, Ethan Katz-Bassett |
IMC | 3 |
| 2022 | The best of both worlds: high availability CDN routing without compromising controlabstractContent delivery networks (CDNs) provide fast service to clients by replicating content at geographically distributed sites. Most CDNs route clients to a particular site using anycast or unicast with DNS-based redirection. We analyze anycast and unicast and explain why neither of them provides both precise control of user-to-site mapping and high availability in the face of failures, two fundamental goals of CDNs. Anycast compromises control (and hence performance), and unicast compromises availability. We then present new hybrid techniques and demonstrate via experiments on the real Internet that these techniques provide both a high level of traffic control and fast failover following site failures. Jiangchen Zhu, Kevin Vermeulen, Ítalo S. Cunha, Ethan Katz-Bassett, Matt Calder |
IMC | 3 |
| 2022 | Dyssect: Dynamic Scaling of Stateful Network FunctionsabstractNetwork Function Virtualization promises better utilization of computational resources by dynamically scaling resources on demand. However, most network functions (NFs) are stateful and require state updates on a per-packet basis. During a scaling operation, cores need to synchronize access to a shared state to avoid race conditions and to guarantee that NFs process packets in arrival order. Unfortunately, the classic approach to control concurrent access to a shared state with locks does not scale to today’s throughput and latency requirements. Moreover, network traffic is highly skewed, leading to load imbalances in systems that use only sharding to partition the NF states. To address these challenges, we present Dyssect, a system that enables dynamic scaling of stateful NFs by disaggregating the states of network functions. By carefully coordinating actions between cores and a central controller, Dyssect migrates shards and flows between cores for load balancing or traffic prioritization without resorting to locks or reordering packets. Our experimental evaluation shows that Dyssect reduces tail latency up to 32% and increases throughput up to 19.36% when compared to state-of-the-art competing solutions. Fabrício B. Carvalho, Ronaldo A. Ferreira, Ítalo S. Cunha, Marcos A. M. Vieira, Murali Krishna Ramanathan |
INFOCOM | 3 |
| 2021 | Corrigendum: cloud provider connectivity in the flat internetabstractThis corrigendum corrects and extends our results on the benefit of peer locking in mitigating the propagation of route leaks on the Internet, originally published in [2]. The updated results show even higher benefits of peer locking than originally reported, and an extended analysis covering additional peer locking deployment scenarios shows partial deployments also yield significant reduction in propagation of leaked routes. Todd Arnold, Weifan Jiang, Matt Calder, Ítalo S. Cunha, Vasileios Giotsas, Ethan Katz-Bassett |
Internet Measurement Conference | 5 |
| 2021 | Modeling large-scale live video streaming client behavior
Thiago A. Guarnieri, Idilio Drago, Ítalo S. Cunha, Breno Almeida, Jussara M. Almeida, Alex Borges Vieira |
Multim. Syst. | 3 |
| 2021 | Construction and maintenance of P2P overlays for live streaming
Eliseu César Miguel, Cristiano M. Silva, Fernando Carvalho 0003, Ítalo S. Cunha, Sérgio Vale Aguiar Campos |
Multim. Tools Appl. | 4 |
| 2021 | Identifying Networks Vulnerable to IP SpoofingabstractThe lack of authentication in the Internet's data plane allows hosts to falsify (spoof) the source IP address in packet headers. IP source spoofing is the basis for amplification denial-of-service (DoS) attacks. Current approaches to locate sources of spoofed traffic lack coverage or are not deployable today. We propose a mechanism that a network with multiple peering links can use to coarsely locate the sources of spoofed traffic in the Internet. The idea behind our approach is that a network can monitor and map spoofed traffic arriving on a peering link to the set of sources routed toward that link. We propose mechanisms the network can use to systematically vary BGP announcement configurations to induce changes to Internet routes and to the set of sources routed to each peering link. A network using our technique can correlate observations over multiple configurations to more precisely delineate regions sending spoofed traffic. Evaluation of our techniques on the Internet shows that they can partition the Internet into small regions, allowing targeted intervention. Osvaldo L. H. M. Fonseca, Ítalo S. Cunha, Elverton C. Fazzion, Wagner Meira Jr., Brivaldo Alves da Silva, Ronaldo A. Ferreira, Ethan Katz-Bassett |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2020 | Cloud Provider Connectivity in the Flat InternetabstractThe Tier-1 ISPs have been considered the Internet's backbone since the dawn of the modern Internet 30 years ago, as they guarantee global reachability. However, their influence and importance are waning as Internet flattening decreases the demand for transit services and increases the importance of private interconnections. Conversely, major cloud providers -- Amazon, Google, IBM, and Microsoft-- are gaining in importance as more services are hosted on their infrastructures. They ardently support Internet flattening and are rapidly expanding their global footprints, which enables them to bypass the Tier-1 ISPs and other large transit providers to reach many destinations. Todd Arnold, Weifan Jiang, Matt Calder, Ítalo S. Cunha, Vasileios Giotsas, Ethan Katz-Bassett |
Internet Measurement Conference | 5 |
| 2020 | Reduce, Reuse, Recycle: Repurposing Existing Measurements to Identify Stale TraceroutesabstractMany systems rely on traceroutes to monitor or characterize the Internet. The quality of the systems' inferences depends on the completeness and freshness of the traceroutes, but the refreshing of traceroutes is constrained by limited resources at vantage points. Previous approaches predict which traceroutes are likely out-of-date in order to allocate measurements, or monitor BGP feeds for changes that overlap traceroutes. Both approaches miss many path changes for reasons including the difficulty in predicting changes and the coarse granularity of BGP paths. Vasileios Giotsas, Elverton C. Fazzion, Ítalo S. Cunha, Matt Calder, Harsha V. Madhyastha, Ethan Katz-Bassett |
Internet Measurement Conference | 4 |
| 2020 | Classification of Load Balancing in the InternetabstractRecent advances in programmable data planes, software-defined networking, and the adoption of IPv6 support novel, more complex load balancing strategies. We introduce the Multipath Classification Algorithm (MCA), a probing algorithm that extends traceroute to identify and classify load balancing in Internet routes. MCA extends existing formalism and techniques to consider that load balancers may use arbitrary combinations of bits in the packet header for load balancing. We propose optimizations to reduce probing cost that are applicable to MCA and existing load balancing measurement techniques. Through large-scale measurement campaigns, we characterize and study the evolution of load balancing on the IPv4 and IPv6 Internet with multiple transport protocols. Our results show that load balancing is more prevalent and that load balancing strategies are more mature than previous characterizations have found. Rafael Almeida, Ítalo S. Cunha, Renata Teixeira, Darryl Veitch, Christophe Diot |
INFOCOM | 2 |
| 2020 | DISCO: Sidestepping RPKI's Deployment Barriers
Tomas Hlavacek, Ítalo S. Cunha, Yossi Gilad, Amir Herzberg, Ethan Katz-Bassett, Michael Schapira, Haya Schulmann |
NDSS | 2 |
| 2020 | Tracking Down Sources of Spoofed IP Packets
Osvaldo L. H. M. Fonseca, Ítalo S. Cunha, Elverton C. Fazzion, Wagner Meira Jr., Brivaldo Junior, Ronaldo A. Ferreira, Ethan Katz-Bassett |
Networking | 2 |
| 2019 | PEERING: virtualizing BGP at the edge for researchabstractInternet routing research has long been hindered by obstacles to executing the wide class of experiments necessary to characterize problems and opportunities, and evaluate candidate solutions. Prior works proposed a platform that would provide experiments with control of an Internet-connected AS. However, because BGP does not natively support multiplexing or the requisite security policies for building such a platform, prior works were ultimately unable to realize this vision. Brandon Schlinker, Todd Arnold, Ítalo S. Cunha, Ethan Katz-Bassett |
CoNEXT | 3 |
| 2019 | Beating BGP is Harder than we ThoughtabstractOnline services all seek to provide their customers with the best Quality of Experience (QoE) possible. Milliseconds of delay can cause users to abandon a cat video or move onto a different shopping site, which translates into lost revenue. Thus, minimizing latency between users and content is crucial. To reduce latency, content and cloud providers have built massive, global networks. However, their networks must interact with customer ISPs via BGP, which has no concept of performance. Todd Arnold, Matt Calder, Ítalo S. Cunha, Arpit Gupta, Harsha V. Madhyastha, Michael Schapira, Ethan Katz-Bassett |
HotNets | 3 |
| 2019 | Internet Performance from Facebook's EdgeabstractWe examine the current state of user network performance and opportunities to improve it from the vantage point of Facebook, a global content provider. Facebook serves over 2 billion users distributed around the world using a network of PoPs and interconnections spread across 6 continents. In this paper, we execute a large-scale, 10-day measurement study of metrics at the TCP and HTTP layers for production user traffic at all of Facebook's PoPs worldwide, collecting performance measurements for hundreds of trillions of sampled HTTP sessions. We discuss our approach to collecting and analyzing measurements, including a novel approach to characterizing user achievable goodput from the server side. We find that most user sessions have MinRTT less than 39ms and can support HD video. We investigate if it is possible to improve performance by incorporating performance information into Facebook's routing decisions; we find that default routing by Facebook is largely optimal. To our knowledge, our measurement study is the first characterization of user performance on today's Internet from the vantage point of a global content provider. Brandon Schlinker, Ítalo S. Cunha, Yi-Ching Chiu, Srikanth Sundaresan, Ethan Katz-Bassett |
Internet Measurement Conference | 2 |
| 2019 | Identifying and Characterizing Bashlite and Mirai C&C ServersabstractIoT devices are often a vector for assembling massive botnets, as a consequence of being broadly available, having limited security protections, and significant challenges in deploying software upgrades. Such botnets are usually controlled by centralized Command-and-Control (C&C) servers, which need to be identified and taken down to mitigate threats. In this paper we propose a framework to infer C&C server IP addresses using four heuristics. Our heuristics employ static and dynamic analysis to automatically extract information from malware binaries. We use active measurements to validate inferences, and demonstrate the efficacy of our framework by identifying and characterizing C&C servers for 62% of 1050 malware binaries collected using 47 honeypots. Gabriel Bastos, Wagner Meira Jr., Artur Marzano, Osvaldo L. H. M. Fonseca, Elverton C. Fazzion, Cristine Hoepers, Klaus Steding-Jessen, Marcelo H. P. Chaves, Ítalo S. Cunha, Dorgival O. Guedes |
ISCC | 9 |
| 2018 | Attributed-based authentication and access control for IoT home devices: demo abstractabstractWe demonstrate attribute-based authentication and access control schemes tailored to resource-constrained devices typical of IoT home environments. The demo shows how IoT devices would be managed and controlled in such scenario. The underlying cryptographic scheme relies on an Attribute-Based Cryptosystem (ABC) to cryptographically implement an authenticated Attribute-Based Access Control (ABAC) mechanism. Antonio Maia, Yuri L. Pereira, Artur L. F. Souza, Ítalo S. Cunha, Leonardo B. Oliveira |
IPSN | 4 |
| 2018 | An SDN-based Framework for Managing Internet Exchange PointsabstractInternet Exchange Points (IXP) have become crucial building blocks of today's networked services, localizing traffic, improving performance, and reducing costs. IXPs span a wide range of business models-for-profit, not-for-profit, and freeof-charge-and thus have diverse business goals. As a result, different IXPs have different requirements on their infrastructure and want to enforce different policies. Unfortunately, despite their success, IXPs face significant infrastructure management challenges like scalability limitations or lack of security. In this paper we present SDIX, an infrastructure management framework for IXPs that uses software-defined networking functionality to provide efficient and flexible primitives that IXPs can use and extend to implement policies. We evaluate SDIX on a realistic IXP infrastructure emulated on Mininet and show how it achieves different goals while simplifying management. We also show that SDIX is deployable on current hardware and can scale to IXPs with thousands of member networks. Luis Felipe Cunha Martins, Ítalo S. Cunha, Dorgival O. Guedes |
ISCC | 2 |
| 2018 | The Evolution of Bashlite and Mirai IoT BotnetsabstractVulnerable IoT devices are powerful platforms for building botnets that cause billion-dollar losses every year. In this work, we study Bashlite botnets and their successors, Mirai botnets. In particular, we focus on the evolution of the malware as well as changes in botnet operator behavior. We use monitoring logs from 47 honeypots collected over 11 months. Our results shed new light on those botnets, and complement previous findings by providing evidence that malware, botnet operators, and malicious activity are becoming more sophisticated. Compared to its predecessor, we find Mirai uses more resilient hosting and control infrastructures, and supports more effective attacks. Artur Marzano, David Alexander, Osvaldo L. H. M. Fonseca, Elverton C. Fazzion, Cristine Hoepers, Klaus Steding-Jessen, Marcelo H. P. Chaves, Ítalo S. Cunha, Dorgival O. Guedes, Wagner Meira Jr. |
ISCC | 8 |
| 2017 | Characterizing QoE in Large-Scale Live StreamingabstractUnderstanding the impact of performance degradation on users' QoE during live Internet streaming is key to maximize the audience and increase content providers' revenues. It is known that some problems have a strong correlation with low QoE--e.g., users experiencing video stalls tend to leave video sessions earlier. It is, however, mostly unknown whether such observations hold for live streaming of large-scale events (e.g., the FIFA World Cup). Such events are particular due to the widespread interest in the streamed content, reaching an impressively high audience worldwide. We study whether and to what extent performance degradation during live streaming of large-scale events affects users' QoE. We leverage a unique dataset collected from a major content provider in South America during the 2014 FIFA Soccer World Cup. We first extract performance metrics from the logs: stream bitrate, bitrate switches, playback stalls, and playback startup latency. We then correlate these performance metrics with session duration, which we use as a QoE indicator. We confirm the strong correlations between the metrics and QoE indicators; in particular, frequent stalls are often accompanied by higher probability of early session termination. Moreover, we quantify how such correlations vary according to broadcast matches and client terminals. Some of our findings challenge intuition--e.g., we find that PC users seem more tolerant to problems than users on mobile terminals. Our results provide better understanding of user QoE and are an important step towards user QoE models in large-scale events. Thiago A. Guarnieri, Idilio Drago, Alex Borges Vieira, Ítalo S. Cunha, Jussara M. Almeida |
GLOBECOM | 4 |
| 2017 | AERO: Adaptive Emergency Request Optimization in CDN-P2P Live StreamingabstractLive streaming platforms employ advanced mechanisms to guarantee continuous and scalable video playback to large user bases. One such mechanism is CDN-P2P streaming, where servers are hosted on content distribution networks and client resources are used to help disseminate content in a peer-to-peer overlay. In CDN-P2P streaming, a peer that is about to miss the playback deadline of a content piece issues an emergency request to the CDN. Emergency requests allow the retrieval of nearly missed pieces and guarantee continuous playback. We show that emergency requests deliver a chunk close to its deadline and leave no time for dissemination through the peer-to-peer overlay, decreasing scalability. We present AERO, a mechanism that dynamically adjusts the rate at which CDN-hosted servers seed content pieces into the peer-to-peer overlay as a function of network conditions. Our evaluation of AERO under diverse conditions shows it reduces emergency requests, guarantees efficient peer-to-peer dissemination, and provides significant server upload bandwidth savings. João Ferreira A. e Oliveira, Ítalo S. Cunha, Eliseu César Miguel, Sérgio Vale Aguiar Campos |
GLOBECOM | 2 |
| 2017 | Resource-constrained P2P streaming overlay construction for efficient joining under flash crowdsabstractVideo streaming now amounts to the majority of traffic in the Internet. Media streaming relies on large-scale content distribution networks (CDNs), that incur significant costs to build or use. P2P distribution of video content reduce reliance on CDNs and costs. Unfortunately, P2P distribution is fraught with QoE problems, specially during flash crowds or in scenarios where users have limited bandwidth to contribute to the overlay. In this paper, we propose a new P2P overlay construction mechanism to speed up peer joining during flash crowd events while preserving QoE for peers already in the overlay. We also show that our techniques work on resource-constrained overlays where a fraction of peers lack resources to contribute to the overlay, e.g., users on mobile devices and metered connections. Eliseu César Miguel, Ítalo S. Cunha, Cristiano M. Silva, Fernando Carvalho 0003, Sérgio Vale Aguiar Campos |
ISCC | 2 |
| 2017 | A Characterization of Load Balancing on the IPv6 Internet
Rafael Almeida, Osvaldo L. H. M. Fonseca, Elverton C. Fazzion, Dorgival O. Guedes, Wagner Meira Jr., Ítalo S. Cunha |
PAM | 6 |
| 2017 | Engineering Egress with Edge Fabric: Steering Oceans of Content to the WorldabstractLarge content providers build points of presence around the world, each connected to tens or hundreds of networks. Ideally, this connectivity lets providers better serve users, but providers cannot obtain enough capacity on some preferred peering paths to handle peak traffic demands. These capacity constraints, coupled with volatile traffic and performance and the limitations of the 20 year old BGP protocol, make it difficult to best use this connectivity. Brandon Schlinker, Hyojeong Kim, Timothy Cui, Ethan Katz-Bassett, Harsha V. Madhyastha, Ítalo S. Cunha, James Quinn, Saif Hasan, Petr Lapukhov, Hongyi Zeng |
SIGCOMM | 6 |
| 2016 | NomadiKey: User authentication for smart devices based on nomadic keysabstractThe growing importance of smart devices calls for effective user authentication mechanisms. We argue that state-of-the-art authentication mechanisms are either vulnerable to known attacks or do not meet usability needs. To address this problem we designed NomadiKey, a user-to-device authentication mechanism based on nomadic keyboard keys. NomadiKey increases security level by placing keys at different screen coordinates each time NomadiKey is activated. Besides, NomadiKey preserves usability by maintaining the traditional relative position of keys. We compare NomadiKey with other user authentication mechanisms under different attacks using statistical models and simulation. We also evaluate NomadiKey's usability with 18 users. Our results show that NomadiKey increases security compared to widely-deployed PIN authentication with limited impact on authentication times. Leonardo Cotta, Artur Luis Fernandes, Leandro T. C. Melo, Luiz Felipe Z. Saggioro, Frederico Martins, Antonio Maia, Antonio Alfredo Ferreira Loureiro, Ítalo S. Cunha, Leonardo B. Oliveira |
ICC | 8 |
| 2016 | How and how much traceroute confuses our understanding of network pathsabstractTraceroute is largely considered as the number-one tool when troubleshooting the network, with innumerable applications, such as pinpointing the routing deficiencies or detecting and locating network outages. Previous works have extensively investigated pitfalls and flaws causing the measurements performed with this tool to be inaccurate or incomplete. In this paper, we show how, even in the absence of all these well-investigated pitfalls and flaws, our ability to properly troubleshoot the network with Traceroute is strongly limited. Indeed, by using state-of-the-art alias resolution techniques, we investigate how and how much the IP-level description provided by Traceroute can distort our understanding of the characteristics of Internet paths. We experimentally evaluate the impact on path properties like equal-cost multipaths, loops, routing cycles, load balancing, route prevalence and persistence. Our results confirm that researchers and network operators relying on Traceroute may poorly estimate (i) the number of multiple equal-cost routes to the destination; (ii) the presence of suboptimal routing in the network; (iii) the routing stability. Pietro Marchetta, Antonio Montieri, Valerio Persico, Antonio Pescapè, Ítalo S. Cunha, Ethan Katz-Bassett |
LANMAN | 5 |
| 2016 | Sibyl: A Practical Internet Route Oracle
Ítalo S. Cunha, Pietro Marchetta, Matt Calder, Yi-Ching Chiu, Brandon Schlinker, Bruno V. A. Machado, Antonio Pescapè, Vasileios Giotsas, Harsha V. Madhyastha, Ethan Katz-Bassett |
NSDI | 1 |
| 2016 | AoT: Authentication and Access Control for the Entire IoT Device Life-CycleabstractThe consumer electronics industry is witnessing a surge in Internet of Things (IoT) devices, ranging from mundane artifacts to complex biosensors connected across disparate networks. As the demand for IoT devices grows, the need for stronger authentication and access control mechanisms is greater than ever. Legacy authentication and access control mechanisms do not meet the growing needs of IoT. In particular, there is a dire need for a holistic authentication mechanism throughout the IoT device life-cycle, namely from the manufacturing to the retirement of the device. As a plausible solution, we present Authentication of Things (AoT), a suite of protocols that incorporate authentication and access control during the entire IoT device life span. Primarily, AoT relies on Identity- and Attribute-Based Cryptography to cryptographically enforce Attribute-Based Access Control (ABAC). Additionally, AoT facilitates secure (in terms of stronger authentication) wireless interoperability of new and guest devices in a seamless manner. To validate our solution, we have developed AoT for Android smartphones like the LG G4 and evaluated all the cryptographic primitives over more constrained devices like the Intel Edison and the Arduino Due. This included the implementation of an Attribute-Based Signature (ABS) scheme. Our results indicate AoT ranges from highly efficient on resource-rich devices to affordable on resource-constrained IoT-like devices. Typically, an ABS generation takes around 27 ms on the LG G4, 282 ms on the Intel Edison, and 1.5 s on the Arduino Due. Antonio Maia, Artur L. F. Souza, Ítalo S. Cunha, Michele Nogueira Lima, Ivan Oliveira Nunes, Leonardo Cotta, Nicolas Gentille, Antonio Alfredo Ferreira Loureiro, Diego F. Aranha, Harsh Kupwade Patil, Leonardo B. Oliveira |
SenSys | 3 |
| 2016 | Efficient Remapping of Internet Routing EventsabstractRouting events impact multiple paths in the Internet, but current active topology mapping techniques monitor paths independently. Detecting a routing event on one Internet path does not trigger any measurements on other possibly-impacted paths. This approach leads to outdated and inconsistent routing information. We characterize routing events in the Internet and investigate probing strategies to efficiently identify paths impacted by a routing event. Our results indicate that targeted probing can help us quickly remap routing events and maintain more up-to-date and consistent topology maps. Elverton C. Fazzion, Ítalo S. Cunha, Dorgival O. Guedes, Wagner Meira Jr., Renata Teixeira, Darryl Veitch, Christophe Diot |
SIGCOMM | 2 |
| 2016 | Predicting the level of cooperation in a Peer-to-Peer live streaming application
Glauber D. Gonçalves, Ítalo S. Cunha, Alex Borges Vieira, Jussara M. Almeida |
Multim. Syst. | 2 |
| 2015 | Investigating Interdomain Routing Policies in the WildabstractModels of Internet routing are critical for studies of Internet security, reliability and evolution, which often rely on simulations of the Internet's routing system. Accurate models are difficult to build and suffer from a dearth of ground truth data, as ISPs often treat their connectivity and routing policies as trade secrets. In this environment, researchers rely on a number of simplifying assumptions and models proposed over a decade ago, which are widely criticized for their inability to capture routing policies employed in practice. Ruwaifa Anwar, Haseeb Niaz, David R. Choffnes, Ítalo S. Cunha, Phillipa Gill, Ethan Katz-Bassett |
Internet Measurement Conference | 4 |
| 2015 | Impact of provider failures on the traffic at a university campusabstractIn this paper we characterize the impact of failures in Brazil's national research network (RNP) on traffic at a large client university. We analyze reachability disruptions, caused by failures of RNP's interdomain links, that block all international traffic. We also analyze performance disruptions, caused by simultaneous failure of multiple RNP intradomain links, which result in congestion and performance degradation. We study the impact of disruptions on traffic, application mix, and user behavior. Our results show that users adapt their behavior when some applications become unavailable and when network performance degrades. For example, users tend to migrate to Youtube when Facebook becomes unavailable during reachability disruptions; similarly, users migrate to Facebook when congestion during performance disruptions severely degrade Youtube experience. We also correlate the impact of disruptions to network topology and show that performance during a performance disruption depends on the location and importance of failed links. Rodrigo Duarte, Alex Borges Vieira, Ítalo S. Cunha, Jussara M. Almeida |
Networking | 3 |
| 2014 | PEERING: An AS for UsabstractInternet routing suffers from persistent and transient failures, circuitous routes, oscillations, and prefix hijacks. A major impediment to progress is the lack of ways to conduct impactful interdomain research. Most research is based either on passive observation of existing routes, keeping researchers from assessing how the Internet will respond to route or policy changes; or simulations, which are restricted by limitations in our understanding of topology and policy. Brandon Schlinker, Kyriakos Zarifis, Ítalo S. Cunha, Nick Feamster, Ethan Katz-Bassett |
HotNets | 3 |
| 2014 | DTRACK: A System to Predict and Track Internet Path ChangesabstractIn this paper, we implement and evaluate a system that predicts and tracks Internet path changes to maintain an up-to-date network topology. Based on empirical observations, we claim that monitors can enhance probing according to the likelihood of path changes. We design a simple predictor of path changes and show that it can be used to enhance probe targeting. Our path tracking system, called DTRACK, focuses probes on unstable paths and spreads probes over time to minimize the chances of missing path changes. Our evaluations of DTRACK with trace-driven simulations and with a prototype show that DTRACK can detect up to three times more path changes than traditional trace-route-based topology mapping techniques. Ítalo S. Cunha, Renata Teixeira, Darryl Veitch, Christophe Diot |
IEEE/ACM Trans. Netw. | 1 |
| 2013 | ID-MAC: An identity-based MAC protocol for Wireless Sensor NetworksabstractWireless Sensor Networks (WSNs) are comprised mainly of resource-constrained sensor nodes that can be used to monitor areas of interest. In sensor networks, replacement of node batteries is usually infeasible and power consumption must be minimal to increase node lifetime. A large fraction of power consumption is controlled by the MAC layer, which orchestrates access to the wireless medium trading-off power consumption and throughput. Unfortunately, this orchestration requires exchange of additional data and itself ends up consuming energy. In this work we design a novel approach that does not require extra data to be exchanged. More precisely, we present ID-MAC: an identity-based MAC protocol for WSNs. In ID-MAC, sensor nodes compute when they should wake up in order to transmit and receive frames from their neighbors without exchanging coordination messages. Our evaluation shows that, by eliminating coordination messages, ID-MAC saves energy and prolongs the network's operating lifespan. Felipe D. da Cunha, Ítalo S. Cunha, Hao Chi Wong, Antonio Alfredo Ferreira Loureiro, Leonardo B. Oliveira |
ISCC | 2 |
| 2013 | End-to-end authentication in Under-Water Sensor NetworksabstractUnder-Water Wireless Sensor Networks (UWSNs) are a particular class of Wireless Sensor Networks (WSNs) in which sensors are located, as the name suggests, underwater. Applications of UWSNs range from oceanographic data collection to disaster prevention. UWSNs are vulnerable to attacks and because of their idiosyncrasies, security solutions for ground WSNs might not be applicable underwater. As a result, there is a need for mechanisms exclusively tailored to underwater environments. In this work we address the problem of authentication in UWSNs. We evaluate energy costs for different digital signature schemes for end-to-end authentication and discuss the tradeoffs involved in a number of scenarios. Our results show that schemes that perform well in ground WSN do not necessarily do well in UWSNs; and shed light on characteristics of a digital signature scheme that make them particularly suited to underwater networks. Evaldo Souza, Hao Chi Wong, Ítalo S. Cunha, Antonio Alfredo Ferreira Loureiro, Luiz Filipe M. Vieira, Leonardo B. Oliveira |
ISCC | 3 |
| 2013 | Can Peer-to-Peer live streaming systems coexist with free riders?abstractPeer-to-Peer live streaming systems help content providers and distributors drastically reduce bandwidth costs by sharing costs among peers. Researchers have dedicated significant effort developing techniques to discourage or exclude uncooperative peers from peer-to-peer systems. However, users are often unable to cooperate, e.g., users using a mobile device with limited, costly bandwidth. We study the impact of uncooperative peers on video discontinuity and latency using PlanetLab. We find that simple mechanisms, like forwarding video data requests to cooperative peers instead of wasting effort sending requests to uncooperative peers, allows peer-to-peer live streaming to serve 50% of uncooperative peers without performance degradation. We argue that denying service to uncooperative peers may not be the best long-term approach; our findings suggest that peer-to-peer live streaming can support uncooperative peers. João Ferreira A. e Oliveira, Ítalo S. Cunha, Eliseu César Miguel, Marcus Vinicius de Melo Rocha, Alex Borges Vieira, Sérgio Vale Aguiar Campos |
P2P | 2 |
| 2013 | Estimating TCP Latency Approximately with Passive Measurements
Sriharsha Gangam, Jaideep Chandrashekar, Ítalo S. Cunha, James F. Kurose |
PAM | 3 |
| 2013 | PoiRoot: investigating the root cause of interdomain path changesabstractInterdomain path changes occur frequently. Because routing protocols expose insufficient information to reason about all changes, the general problem of identifying the root cause remains unsolved. In this work, we design and evaluate PoiRoot, a real-time system that allows a provider to accurately isolate the root cause (the network responsible) of path changes affecting its prefixes. First, we develop a new model describing path changes and use it to provably identify the set of all potentially responsible networks. Next, we develop a recursive algorithm that accurately isolates the root cause of any path change. We observe that the algorithm requires monitoring paths that are generally not visible using standard measurement tools. To address this limitation, we combine existing measurement tools in new ways to acquire path information required for isolating the root cause of a path change. We evaluate PoiRoot on path changes obtained through controlled Internet experiments, simulations, and "in-the-wild" measurements. We demonstrate that PoiRoot is highly accurate, works well even with partial information, and generally narrows down the root cause to a single network or two neighboring ones. On controlled experiments PoiRoot is 100% accurate, as opposed to prior work which is accurate only 61.7% of the time. Umar Javed, Ítalo S. Cunha, David R. Choffnes, Ethan Katz-Bassett, Thomas E. Anderson, Arvind Krishnamurthy |
SIGCOMM | 2 |
| 2012 | Using Centrality Metrics to Predict Peer Cooperation in Live Streaming Applications
Glauber D. Gonçalves, Anna Guimarães, Alex Borges Vieira, Ítalo S. Cunha, Jussara M. Almeida |
Networking (2) | 4 |
| 2012 | LIFEGUARD: practical repair of persistent route failuresabstractThe Internet was designed to always find a route if there is a policy-compliant path. However, in many cases, connectivity is disrupted despite the existence of an underlying valid path. The research community has focused on short-term outages that occur during route convergence. There has been less progress on addressing avoidable long-lasting outages. Our measurements show that long-lasting events contribute significantly to overall unavailability. Ethan Katz-Bassett, Colin Scott, David R. Choffnes, Ítalo S. Cunha, Vytautas Valancius, Nick Feamster, Harsha V. Madhyastha, Thomas E. Anderson, Arvind Krishnamurthy |
SIGCOMM | 4 |
| 2011 | Machiavellian routing: improving internet availability with BGP poisoningabstractWe propose a new approach to mitigate disruptions of Internet connectivity. The Internet was designed to always find a route if there is a policy-compliant path; however, in many cases, connectivity is disrupted despite the existence of an underlying valid path. The research community has done considerable work on this problem, much of it focused on short-term outages that occur during route convergence. There has been less progress on addressing avoidable long-lasting outages. Our measurements show that long-lasting events contribute significantly to overall unavailability. Ethan Katz-Bassett, David R. Choffnes, Ítalo S. Cunha, Colin Scott, Thomas E. Anderson, Arvind Krishnamurthy |
HotNets | 3 |
| 2011 | Measuring and Characterizing End-to-End Route Dynamics in the Presence of Load Balancing
Ítalo S. Cunha, Renata Teixeira, Christophe Diot |
PAM | 1 |
| 2011 | Predicting and tracking internet path changesabstractThis paper investigates to what extent it is possible to use traceroute-style probing for accurately tracking Internet path changes. When the number of paths is large, the usual traceroute based approach misses many path changes because it probes all paths equally. Based on empirical observations, we argue that monitors can optimize probing according to the likelihood of path changes. We design a simple predictor of path changes using a nearest neighbor model. Although predicting path changes is not very accurate, we show that it can be used to improve probe targeting. Our path tracking method, called DTrack, detects up to two times more path changes than traditional probing, with lower detection delay, as well as providing complete load-balancer information. Ítalo S. Cunha, Renata Teixeira, Darryl Veitch, Christophe Diot |
SIGCOMM | 1 |
| 2010 | Joint admission control and resource allocation in virtualized servers
Jussara M. Almeida, Virgílio A. F. Almeida, Danilo Ardagna, Ítalo S. Cunha, Chiara Francalanci, Marco Trubian |
J. Parallel Distributed Comput. | 4 |
| 2009 | Measurement methods for fast and accurate blackhole identification with binary tomographyabstractAbstract: Binary tomography—the process of identifying faulty network links through coordinated end-to-end probes—is a promising method for detecting failures that the network does not automatically mask (e.g., network “blackholes”). Because tomography is sensitive to the quality of the input, however, naive end-to-end measurements can introduce inaccuracies. This paper develops two methods for generating inputs to binary tomography algorithms that improve their inference speed and accuracy. Failure confirmation is a per-path probing technique to distinguish packet losses caused by congestion from persistent link or node failures. Aggregation strategies combine path measurements from unsynchronized monitors into a set of consistent observations. When used in conjunction with existing binary tomography algorithms, our methods identify all failures that are longer than two measurement cycles while inducing relatively few false alarms. In two wide-area networks, our techniques decrease the number of alarms by as much as two orders of magnitude. Compared to the state of the art in Ítalo S. Cunha, Renata Teixeira, Nick Feamster, Christophe Diot |
Internet Measurement Conference | 1 |
| 2009 | Uncovering Artifacts of Flow Measurement Tools
Ítalo S. Cunha, Fernando Silveira, Renata Teixeira, Christophe Diot |
PAM | 1 |
| 2008 | Distinguishing persistent failures from transient lossesabstractNetwork tomography is a promising technique to identify the location of of IP faults. The goal of tomography is to infer the status of network internal characteristics based on end-to-end observations. In particular, binary tomography identifies the set of failed links from end-to-end path meausrments. Upon detecting the failure of one or more of the monitored paths, a monitor sends its measurements to a central coordinator. The coordinator then runs the binary tomography algorithm, which takes as input the topology of the network and the status (i.e., up or down) of all monitored paths and finds the minimum set of links that explain the observations. Ítalo S. Cunha, Renata Teixeira, Nick Feamster, Christophe Diot |
CoNEXT | 1 |
| 2008 | Analyzing security and energy tradeoffs in autonomic capacity managementabstractCapacity management of a hosting infrastructure has traditionally focused only on performance goals. However, the quality of service provided to the hosted applications, and ultimately the revenues achieved by the provider, depend also on other aspects, such as security and energy constraints. This paper extends our self-adaptive SLA-driven capacity management solution to capture, in an unified framework, key performance and cost tradeoffs that arise when operating under security attacks and energy constraints. A number of scenarios and strategies based on dynamic SLA contracts are designed to help uncover, via simulation experiments, the main tradeoffs, considering both the provider’s interests (i.e., revenues) and the customer’s interests (i.e., legitimate throughput, response time distribution and costs). Finally, we also assess the cost-effectiveness of our framework under highly variable application service times. Ítalo S. Cunha, Itamar Viana, João R. M. Palotti, Jussara M. Almeida, Virgílio A. F. Almeida |
NOMS | 1 |
| 2007 | Self-Adaptive Capacity Management for Multi-Tier Virtualized EnvironmentsabstractThis paper addresses the problem of hosting multiple applications on a provider's virtualized multi-tier infrastructure. Building from a previous model, we design a new self-adaptive capacity management framework, which combines a two-level SLA-driven pricing model, an optimization model and an analytical queuing-based performance model to maximize the provider's business objective. Our main contributions are the more accurate multi-queue performance model, which captures application specific bottlenecks and the parallelism inherent to multi-tier platforms, as well as the solution of the extended and much more complex optimization model. Our approach is evaluated via simulation with synthetic as well as realistic workloads, in various scenarios. The results show that our solution is significantly more cost-effective, in terms of the provider's achieved revenues, than the approach it is built upon, which uses a single-resource performance model. It also significantly outperforms a multi-tier static allocation strategy for heavy and unbalanced workloads. Finally, preliminary experiments assess the applicability of our framework to virtualized environments subjected to capacity variations caused by the processing of management and security-related tasks. Ítalo S. Cunha, Jussara M. Almeida, Virgílio A. F. Almeida, Marcos Santos |
Integrated Network Management | 1 |
| 2005 | Scalable media streaming to interactive usersabstractRecently, a number of scalable stream sharing protocols have been proposed with the promise of great reductions in the server and network bandwidth required for delivering popular media content. Although the scalability of these protocols has been evaluated mostly for sequential user accesses, a high degree of interactivity has been observed in the accesses to several real media servers. Moreover, some studies have indicated that user interactivity can severely penalize the scalability of stream sharing protocols.This paper investigates alternative mechanisms for scalable streaming to interactive users. We first identify a set of workload aspects that are determinant to the scalability of classes of streaming protocols. Using real workloads and a new interactive media workload generator, we build a rich set of realistic synthetic workloads. We evaluate Bandwidth Skimming and Patching, two state-of-the-art streaming protocols, covering, with our workloads, a larger region of the design space than previous work. Finally, we propose and evaluate five optimizations to Bandwidth Skimming, the most scalable of the two protocols. Our best optimization reduces the average server bandwidth required for interactive workloads in up to 54%, for unlimited client buffers, and 29%, if buffers are constrained to 25% of media size. Marcus Vinicius de Melo Rocha, Marcelo de Almeida Maia, Ítalo S. Cunha, Jussara M. Almeida, Sérgio Vale Aguiar Campos |
ACM Multimedia | 3 |
| 2004 | Analyzing client interactivity in streaming mediaabstractThis paper provides an extensive analysis of pre-stored streaming media workloads, focusing on the client interactive behavior. We analyze four workloads that fall into three different domains, namely, education, entertainment video and entertainment audio. Our main goals are: (a) to identify qualitative similarities and differences in the typical client behavior for the three workload classes and (b) to provide data for generating realistic synthetic workloads. Cristiano P. Costa, Ítalo S. Cunha, Alex Borges Vieira, Claudiney Vander Ramos, Marcus Vinicius de Melo Rocha, Jussara M. Almeida, Berthier A. Ribeiro-Neto |
WWW | 2 |