Roberto Bifulco

dblp:81/8239 · DBLP profile ↗
← Back
33ranked-venue papers
4as first author
8since 2021 · last 2025
0000-0002-9403-0336ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 12 · 3 first-author · 2 since 2021Software engineering, systems software and programming languages · 6 · 2 since 2021Systems, architecture and hardware · 4 · 3 since 2021Security and privacy · 4 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 What Did I Do Wrong? Quantifying LLMs' Sensitivity and Consistency to Prompt Engineering
abstract
Federico Errica, Davide Sanvito, Giuseppe Siracusano, Roberto Bifulco. Proceedings of the 2025 Conference of the Nations of the Americas Chapter of the Association for Computational Linguistics: Human Language Technologies (Volume 1: Long Papers). 2025.
Federico Errica, Davide Sanvito, Giuseppe Siracusano, Roberto Bifulco
NAACL (Long Papers)4
2023 eHDL: Turning eBPF/XDP Programs into Hardware Designs for the NIC
abstract
Scaling network packet processing performance to meet the increasing speed of network ports requires software programs to carefully leverage the network devices’ hardware features. This is a complex task for network programmers, who need to learn and deal with the heterogeneity of device architectures, and re-think their software to leverage them. In this paper we make first steps to reverse this design process, enabling the automatic generation of tailored hardware designs starting from a network packet processing program. We introduce eHDL, a high-level synthesis tool that automatically generates hardware pipelines from unmodified Linux’s eBPF/XDP programs. eHDL is designed to enable software developers to directly define and implement the hardware functions they need in the NIC. We prototype eHDL targeting a Xilinx Alveo U50 FPGA NIC, and evaluate it with a set of 5 eBPF/XDP programs. Our results show that the generated pipelines are efficient in terms of required hardware resources, using only 6.5%-13.3% of the FPGA, and always achieve the line rate forwarding throughput with about 1 microsecond of per-packet forwarding latency. Compared to other network-specific high-level synthesis tool, eHDL enables software programmers with no hardware expertise to describe stateful functions that operate on the entire packet data. Compared to alternative processor-based solutions that perform eBFP/XDP offloading to a NIC, eHDL provides 10-100x higher throughput.
Alessandro Rivitti, Roberto Bifulco, Angelo Tulumello, Marco Bonola, Salvatore Pontarelli
ASPLOS (3)2
2023 Automatic Kernel Offload Using BPF
abstract
BPF support in Linux has made kernel extensions easier. Recent efforts have shown that using BPF to offload portions of server applications, e.g., memcached and service proxies, can improve application performance and efficiency. However, thus far, the community has not looked at the question of what parts of an application should be offloaded? This paper first shows that blindly offloading application functionality to the kernel is neither beneficial nor desirable, and care must be taken when deciding what to offload. Furthermore, when deciding what to offload, developers must consider not just the application, but also the workload being handled, and the kernel being targetted, Therefore, we advocate automating this decision process in a compiler, that can analyze application code, and produce two executables, a kernel offload and a userspace program, that jointly implement the application's functionality. This paper discusses the challenges that must be addressed to build such a compiler, and why they can be feasibly addressed.
Farbod Shahinfar, Sebastiano Miano, Giuseppe Siracusano, Roberto Bifulco, Aurojit Panda, Gianni Antichi
HotOS4
2022 Poster: MUSTARD - Adaptive Behavioral Analysis for Ransomware Detection
abstract
Behavioural analysis based on filesystem operations is one of the most promising approaches for the detection of ransomware. Nonetheless, tracking all the operations on all the files for all the processes can introduce a significant overhead on the monitored system. We present MUSTARD, a solution to dynamically adapt the degree of monitoring for each process based on their behaviour to achieve a reduction of monitoring resources for the benign processes.
Davide Sanvito, Giuseppe Siracusano, Roberto Gonzalez, Roberto Bifulco
CCS4
2022 Re-architecting Traffic Analysis with Neural Network Interface Cards
Giuseppe Siracusano, Salvator Galea, Davide Sanvito, Mohammad Malekzadeh, Gianni Antichi, Paolo Costa, Hamed Haddadi 0001, Roberto Bifulco
NSDI8
2022 Faster Software Packet Processing on FPGA NICs with eBPF Program Warping
Marco Bonola, Giacomo Belocchi, Angelo Tulumello, M. Spaziani Brunella, Giuseppe Siracusano, Giuseppe Bianchi 0001, Roberto Bifulco
USENIX ATC7
2021 The case for network functions decomposition
abstract
This paper makes a case for writing unrestricted eBPF network functions which then get automatically decomposed between kernel and user-space.
Farbod Shahinfar, Sebastiano Miano, Alireza Sanaee, Giuseppe Siracusano, Roberto Bifulco, Gianni Antichi
CoNEXT5
2021 Flynn's Reconciliation: Automating the Register Cache Idiom for Cross-accelerator Programming
abstract
A large portion of the recent performance increase in the High Performance Computing (HPC) and Machine Learning (ML) domains is fueled by accelerator cards. Many popular ML frameworks support accelerators by organizing computations as a computational graph over a set of highly optimized, batched general-purpose kernels. While this approach simplifies the kernels’ implementation for each individual accelerator, the increasing heterogeneity among accelerator architectures for HPC complicates the creation of portable and extensible libraries of such kernels. Therefore, using a generalization of the CUDA community’s warp register cache programming idiom, we propose a new programming idiom (CoRe) and a virtual architecture model (PIRCH), abstracting over SIMD and SIMT paradigms. We define and automate the mapping process from a single source to PIRCH’s intermediate representation and develop backends that issue code for three different architectures: Intel AVX512, NVIDIA GPUs, and NEC SX-Aurora. Code generated by our source-to-source compiler for batched kernels, borG, competes favorably with vendor-tuned libraries and is up to 2× faster than hand-tuned kernels across architectures.
Daniel Thürck, Nicolas Weber, Roberto Bifulco
ACM Trans. Archit. Code Optim.3
2020 hXDP: Efficient Software Packet Processing on FPGA NICs
M. Spaziani Brunella, Giacomo Belocchi, Marco Bonola, Salvatore Pontarelli, Giuseppe Siracusano, Giuseppe Bianchi 0001, Aniello Cammarano, Alessandro Palumbo, Luca Petrucci, Roberto Bifulco
OSDI10
2019 Poster: On the Application of NLP to Discover Relationships between Malicious Network Entities
abstract
The increase in network traffic volumes challenges the scalability of security analysis tools. In this paper, we present NetLearn, a solution to identify potentially malicious network entities from large amounts of network traffic data. NetLearn applies recently developed natural language processing algorithms to discover security-relevant relationships between the observed network entities, e.g., domain names and IP addresses, without requiring external sources of information for its analysis.
Giuseppe Siracusano, Martino Trevisan, Roberto Gonzalez, Roberto Bifulco
CCS4
2019 FlowBlaze: Stateful Packet Processing in Hardware
Salvatore Pontarelli, Roberto Bifulco, Marco Bonola, Carmelo Cascone, M. Spaziani Brunella, Valerio Bruschi, Davide Sanvito, Giuseppe Siracusano, Antonio Capone, Michio Honda, Felipe Huici
NSDI2
2019 Survey of Performance Acceleration Techniques for Network Function Virtualization
abstract
The ongoing network softwarization trend holds the promise to revolutionize network infrastructures by making them more flexible, reconfigurable, portable, and more adaptive than ever. Still, the migration from hard-coded/hard-wired network functions toward their software-programmable counterparts comes along with the need for tailored optimizations and acceleration techniques so as to avoid or at least mitigate the throughput/latency performance degradation with respect to fixed function network elements. The contribution of this paper is twofold. First, we provide a comprehensive overview of the host-based network function virtualization (NFV) ecosystem, covering a broad range of techniques, from low-level hardware acceleration and bump-in-the-wire offloading approaches to high-level software acceleration solutions, including the virtualization technique itself. Second, we derive guidelines regarding the design, development, and operation of NFV-based deployments that meet the flexibility and scalability requirements of modern communication networks.
Leonardo Linguaglossa, Stanislav Lange, Salvatore Pontarelli, Gábor Rétvári, Dario Rossi 0001, Thomas Zinner, Roberto Bifulco, Michael Jarschel, Giuseppe Bianchi 0001
Proc. IEEE7
2018 A Survey on the Programmable Data Plane: Abstractions, Architectures, and Open Problems
abstract
Programmable switches allow the packet processing behavior to be applied to transmitted packets, including the type, sequence, and semantics of processing operations, to be reconfigured on the fly in a systematic fashion. As such, programmable switches are the key to realize the next-generation of network services and applications, including software-defined networking, 5G, IoT, and massive-scale cloud computing. This paper presents a survey on the recent trends and issues in the design and implementation of programmable network devices, focusing on the prominent abstractions and architectures proposed, debated, realized, and deployed during the last 10 years. First we describe the anatomy of a programmable switch, then we highlight the most important pointers from the literature and cast different taxonomies for the field, and finally we sketch open issues and possible future research directions.
Roberto Bifulco, Gábor Rétvári
HPSR1
2017 Implementing advanced network functions for datacenters with stateful programmable data planes
abstract
Programmable dataplanes are emerging as a disruptive technology to implement network function virtualization in an SDN environment. This technology can be further enhanced by using data plane abstraction with stateful processing. In this paper we focus on real world use cases with stateful forwarding requirements to validate Open Packet Processor data plane abstraction. We first demonstrate the suitability of OPP for implementing complex stateful network functions by providing the detailed implementation of three use cases. Second, we assess the scalability of the use case implementations in the context of a datacenter deployment.
Marco Bonola, Roberto Bifulco, Luca Petrucci, Salvatore Pontarelli, Angelo Tulumello, Giuseppe Bianchi 0001
LANMAN2
2017 Demo: Implementing advanced network functions with stateful programmable data planes
abstract
Stateful programmable dataplanes are emerging as a disruptive technology and an enabler factor for network function virtualization in SDN environments. In this demo paper we show three real world use cases with stateful forwarding requirements to validate both the hardware and software implementations of the Open Packet Processor data plane.
Marco Bonola, Roberto Bifulco, Luca Petrucci, Salvatore Pontarelli, Angelo Tulumello, Giuseppe Bianchi 0001
LANMAN2
2017 A unifying operating platform for 5G end-to-end and multi-layer orchestration
abstract
Heterogeneity of current software solutions for 5G is heading for complex and costly situations, with high fragmentation, which in turn creates uncertainty and the risk of delaying 5G innovations. This context motivated the definition of a novel Operating Platform for 5G (5G-OP), a unifying reference functional framework supporting end-to-end and multi-layer orchestration. 5G-OP aims at integrated management, control and orchestration of computing, storage, memory, networking core and edge resources up to the end-user devices and terminals (e.g., robots and smart vehicles). 5G-OP is an overarching architecture, with agnostic interfaces and well-defined abstractions, offering the seamless integration of current and future infrastructure control and orchestration solutions (e.g., OpenDaylight, ONOS, OpenStack, Apache Mesos, OpenSource MANO, Docker, LXC, etc.) The paper provides also the description of a prototype that can be seen as a simplified version of a 5G-OP, whose feasibility has been demonstrated in Focus Group IMT2020 of ITU-T.
Antonio Manzalini, Diego R. López, Håkon Lønsethagen, Lucian Suciu, Roberto Bifulco, Marie-Paule Odini, Giuseppe Celozzi, Barbara Martini, Fulvio Risso, Jokin Garay, Vassilis Foteinos, Panagiotis Demestichas, Giuliana Carullo, Marco Tambasco, Gino Carrozzo
NetSoft5
2017 Re-Designing Dynamic Content Delivery in the Light of a Virtualized Infrastructure
abstract
We explore the opportunities and design options enabled by novel SDN and NFV technologies, by re-designing a dynamic content delivery network (CDN) service. Our system, named MOSTO, provides performance levels comparable to that of a regular CDN, but does not require the deployment of a large distributed infrastructure. In the process of designing the system, we identify relevant functions that could be integrated in the future Internet infrastructure. Such functions greatly simplify the design and effectiveness of services, such as MOSTO. We demonstrate our system using a mixture of simulation, emulation, testbed experiments, and by realizing a proof-of-concept deployment in a planet-wide commercial cloud system.
Giuseppe Siracusano, Roberto Bifulco, Martino Trevisan, Tobias Jacobs, Simon Kuenzer, Stefano Salsano, Nicola Blefari-Melazzi, Felipe Huici
IEEE J. Sel. Areas Commun.2
2016 Dynamic M2M device attachment and redirection in virtual home gateway environments
abstract
Virtualized access to M2M (Machine-to-Machine) devices can offer to operators various benefits in terms of hardware and management costs. However, it is often impeded by the inability to efficiently handle the traffic from the devices towards servers that are appropriate to serve as virtual hosts for the given devices. In this paper we present a solution which can be applied in a virtual Home Gateway environment and is based on (i) encoding information about the device and its virtualization technology into TCP/IP packet headers, (ii) selecting virtual hosts based on their compatibility to certain virtualization technologies, and (iii) using Software-defined Networking to make this virtual host selection at the network level in a dynamic manner. Compared to the main alternatives, which are based either on Deep Packet Inspection or on homogeneous servers, our solution is the only one that combines a tailored and non-costly server infrastructure with low networking complexity.
Apostolos Papageorgiou, Roberto Bifulco, Ernö Kovacs, Hans-Jörg Kolbe
ICC2
2016 Better ARP handling with InSPired SDN switches
abstract
SDN research is moving towards enabling the delegation of parts of control functions to the network elements. In recent work we analytically evaluated the benefit in terms of ARP data traffic load reduction as well as control channel interaction reduction when delegating the generation of ARP replies. In this paper we describe the corresponding control program and network configuration to handle ARP traffic in a software-defined network leveraging programmable in-switch packet generation capabilities. We also discuss potential optimizations and implementation options.
Fabian Schneider 0001, Roberto Bifulco, Anton Matsiuk
LANMAN2
2016 Cases for Including a Reference Monitor to SDN
abstract
No abstract written
Dimitrios Gkounis, Felix Klaedtke, Roberto Bifulco, Ghassan Karame
SIGCOMM3
2016 On the Fingerprinting of Software-Defined Networks
abstract
Software-defined networking (SDN) eases network management by centralizing the control plane and separating it from the data plane. The separation of planes in SDN, however, introduces new vulnerabilities in SDN networks, since the difference in processing packets at each plane allows an adversary to fingerprint the network's packet-forwarding logic. In this paper, we study the feasibility of fingerprinting the controller-switch interactions by a remote adversary, whose aim is to acquire knowledge about specific flow rules that are installed at the switches. This knowledge empowers the adversary with a better understanding of the network's packet-forwarding logic and exposes the network to a number of threats. In this paper, we collect measurements from hosts located across the globe using a realistic SDN network comprising of OpenFlow hardware and software switches. We show that, by leveraging information from the RTT and packet-pair dispersion of the exchanged packets, fingerprinting attacks on SDN networks succeed with overwhelming probability. We additionally show that these attacks are not restricted to active adversaries, but can also be mounted by passive adversaries that only monitor traffic exchanged with the SDN network. Finally, we discuss the implications of these attacks on the security of SDN networks, and we present and evaluate an efficient countermeasure to strengthen SDN networks against fingerprinting. Our results demonstrate the effectiveness of our countermeasure in deterring fingerprinting attacks on SDN networks.
Heng Cui, Ghassan Karame, Felix Klaedtke, Roberto Bifulco
IEEE Trans. Inf. Forensics Secur.4
2015 In-Net: in-network processing for the masses
abstract
Network Function Virtualization is pushing network operators to deploy commodity hardware that will be used to run middlebox functionality and processing on behalf of third parties: in effect, network operators are slowly but surely becoming in-network cloud providers. The market for innetwork clouds is large, ranging from content providers, mobile applications and even end-users.
Radu Stoenescu, Vladimir Andrei Olteanu, Matei Popovici, Mohamed Ahmed 0001, Roberto Bifulco, Filipe Manco, Felipe Huici, Georgios Smaragdakis, Mark Handley, Costin Raiciu
EuroSys6
2015 Fingerprinting Software-Defined Networks
abstract
In this paper, we study the feasibility of fingerprinting of controller-switch interactions in SDN networks by a remote adversary whose aim is to acquire knowledge about specific flow rules that are installed at the switches. This knowledge empowers the adversary with a better understanding of the network's packet-forwarding logic and exposes the network to a number of threats. In our study, we collect measurements from hosts located across the globe using a realistic SDN network comprising of OpenFlow hardware switches. We show that, by leveraging information from the RTT and packet-pair dispersion of the exchanged packets, fingerprinting attacks on SDN networks succeed with overwhelming probability. We also show that these attacks are not restricted to active adversaries, but can be equally mounted by passive adversaries that only monitor traffic exchanged with the SDN network. Finally, we sketch an efficient countermeasure to strengthen SDN networks against fingerprinting.
Roberto Bifulco, Heng Cui, Ghassan Karame, Felix Klaedtke
ICNP1
2015 Enhancing the BRAS through virtualization
abstract
Broadband Remote Access Servers (BRASes) are crucial middleboxes in DSL access networks, providing the first IP point in the network for subscribers and enforcing operator policies. The number of functions provided by BRASes, combined with the key role they play in the network, means that these devices are expensive, difficult to change, and constitute a single point of failure. In order to overcome these limitations, we propose to virtualize the BRAS and to enhance it with a control interface that can be exploited by management systems in order to introduce live session migration and higher reliability. Our proof-of-concept implementation shows that our virtual software BRAS is able to handle thousands of sessions while forwarding and shaping traffic at rates of millions of packets per second on commodity hardware, and that the live session migration feature enables the implementation of high-reliability scenarios.
Thomas Dietz, Roberto Bifulco, Filipe Manco, Hans-Jörg Kolbe, Felipe Huici
NetSoft2
2015 Towards an access control scheme for accessing flows in SDN
abstract
Sharing network resources with user groups, divisions, or even other companies in software defined networking promises better network utilization. Resource sharing is effectively realized by empowering these tenants at the control plane with permissions for administrating network components. However, since the network resources at the data plane are shared and different tenants can have competing objectives, mechanisms are needed to protect the network resources from unauthorized access. In this paper, we propose mechanisms that focus on protecting the network flows, which are determined by the entries installed in the flow tables of the shared switches. To this end, we present an access control scheme, based on the OpenFlow model, for accessing the switches' flow tables and their entries. Our scheme accounts for various security requirements in multi-tenant networks, including requirements on sharing flow table entries for handling network flows, and the resolution of conflicts originating from the reconfiguration of network components.
Felix Klaedtke, Ghassan Karame, Roberto Bifulco, Heng Cui
NetSoft3
2015 Towards Scalable SDN Switches: Enabling Faster Flow Table Entries Installation
abstract
No abstract available.
Roberto Bifulco, Anton Matsiuk
SIGCOMM1
2014 Reactive logic in software-defined networking: Measuring flow-table requirements
abstract
The capability of a network is ultimately bounded by limitations of the devices that compose it. In this paper we argue that Software-Defined Networking (SDN) can increase the importance of certain limitations, such as the size and the flexibility of switches forwarding tables. In particular we focus on the implications of reactive installation of flow entries in the switch fabric: by analyzing traffic traces captured in different scenarios we show the existence of a trade-off between the size of the flow table and the rate of dynamic installation of a missing or expired rule. We leverage on this finding to further show that reactive flow (re-)configuration is a promising mechanism for improving the traffic engineering flexibility with no additional requirement in terms of flow table size. We examine links located in various parts of the network and we consider different flow definitions to evaluate the feasibility of using SDN controllers in both access and core network scenarios.
Maurizio Dusi, Roberto Bifulco, Francesco Gringoli, Fabian Schneider 0001
IWCMC2
2014 Flexible traffic management in broadband access networks using Software Defined Networking
abstract
Over the years, the demand for high bandwidth services, such as live and on-demand video streaming, steadily increased. The adequate provisioning of such services is challenging and requires complex network management mechanisms to be implemented by Internet service providers (ISPs). In current broadband network architectures, the traffic of subscribers is tunneled through a single aggregation point, independent of the different service types it belongs to. While having a single aggregation point eases the management of subscribers for the ISP, it implies huge bandwidth requirements for the aggregation point and potentially high end-to-end latency for subscribers. An alternative would be a distributed subscriber management, adding more complexity to the management itself. In this paper, a new traffic management architecture is proposed that uses the concept of Software Defined Networking (SDN) to extend the existing Ethernet-based broadband network architecture, enabling a more efficient traffic management for an ISP. By using SDN-enabled home gateways, the ISP can configure traffic flows more dynamically, optimizing throughput in the network, especially for bandwidth-intensive services. Furthermore, a proof-of-concept implementation of the approach is presented to show the general feasibility and study configuration tradeoffs. Analytic considerations and testbed measurements show that the approach scales well with an increasing number of subscriber sessions.
Julius Rückert, Roberto Bifulco, Muhammad Rizwan-Ul-Haq, Hans-Jörg Kolbe, David Hausheer
NOMS2
2014 ClickOS and the Art of Network Function Virtualization
Mohamed Ahmed 0001, Costin Raiciu, Vladimir Andrei Olteanu, Michio Honda, Roberto Bifulco, Felipe Huici
NSDI6
2011 Transparent migration of virtual infrastructures in large datacenters for Cloud computing
abstract
Cloud-enabled datacenters need advanced support for an integrated management of platform virtualization technologies. The networking infrastructure of large-scale datacenters is implemented according to redundant multi-tiered architectures whose layers operate at Layer 3 of the networking stack. Splitting the network infrastructure of a datacenter in a number of IP subnets, however, creates limits to the migration of Virtual Machines, reducing the possibility for administrators to efficiently balance the load and reduce the energy consumption of the whole infrastructure. In this paper we propose an innovative solution that allows transparent migration of Virtual Machines across the whole datacenter, based on the coordinated use of NAT rules that need to be consistently managed across the layers of the datacenter networking infrastructure. We describe in details how our approach can be easily implemented with current network devices without any modification to their hardware and present an experimental evaluation of an early prototype of our solution.
Roberto Bifulco, Roberto Canonico, Giorgio Ventre, Vittorio Manetti
ISCC1
2011 Experimenting with P2P traffic optimization for wireless mesh networks in a federated OMF-PlanetLab environment
abstract
The ultimate success of the Wireless Mesh Network paradigm (WMN) in large scale deployments depends on the ability to test it in real world scenarios. A typical application scenario which is worth to be investigated in such a context is peer-to-peer traffic management. The creation of large scale testbeds for evaluating wireless mesh technologies and protocols, and for testing their ability to support real world applications in realistic environments, is then a crucial step. OMF (cOntrol and Management Framework) is a well-established control, measurement, and management framework for wireless testbeds. In this paper we present how we integrated an OMF-based wireless testbed in the planetary-scale PlanetLab testbed, making it possible for PlanetLab users to run experiments spanning on both PlanetLab and an OMF-based wireless testbed. In order to demonstrate the usefulness of such an integrated scenario, we tested on it an innovative peer-to-peer traffic optimization technique for the BitTorrent file sharing application. The possibility of running this kind of experiments highlighted several real-world issues which could be investigated thanks to our hybrid experimental scenario.
Giovanni Di Stasi, Roberto Bifulco, Francesco Paolo D'Elia, Stefano Avallone, Roberto Canonico, Apostolos Apostolaras, Nikolaos Giallelis, Thanasis Korakis, Leandros Tassiulas
WCNC2
2011 Interconnection of geographically distributed wireless mesh testbeds: Resource sharing on a large scale
Giovanni Di Stasi, Roberto Bifulco, Stefano Avallone, Roberto Canonico, Apostolos Apostolaras, Nikolaos Giallelis, Thanasis Korakis, Leandros Tassiulas
Ad Hoc Networks2
2010 Integrating a network IDS into an open source Cloud Computing environment
abstract
The success of the Cloud Computing paradigm may be jeopardized by concerns about the risk of misuse of this model aimed at conducting illegal activities. In this paper we address the issue of detecting Denial of Service attacks performed by means of resources acquired on-demand on a Cloud Computing platform. To this purpose, we propose to investigate the consequences of the use of a distributed strategy to detect and block attacks, or other malicious activities, originated by misbehaving customers of a Cloud Computing provider. In order to check the viability of our approach, we also evaluate the impact on performance of our proposed solution. This paper presents the installation and deployment experience of a distributed defence strategy and illustrates the preliminary results of the performance evaluation.
Claudio Mazzariello, Roberto Bifulco, Roberto Canonico
IAS2