Domenico Siracusa

dblp:88/10062 · DBLP profile ↗
← Back
46ranked-venue papers
2as first author
23since 2021 · last 2026
0000-0002-5640-6507ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 20 · 2 first-author · 8 since 2021Software engineering, systems software and programming languages · 9 · 7 since 2021Security and privacy · 5 · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Sharpening Kubernetes audit logs with context awareness
abstract
Kubernetes (K8s) has emerged as the de facto orchestrator of microservices, providing scalability and extensibility to a highly dynamic environment. It builds an intricate and deeply connected system that requires extensive monitoring capabilities to be properly managed. To this account, K8s natively offers audit logs, a powerful feature for tracking Application Programming Interface (API) interactions in the cluster. Audit logs provide a detailed and chronological record of all activities in the system. Unfortunately, K8s auditing suffers from several practical limitations: it generates large volumes of data continuously, as all components within the cluster interact and respond to user actions. Moreover, each action can trigger a cascade of secondary events dispersed across the log, with little to no explicit linkage, making it difficult to reconstruct the context behind user-initiated operations. In this paper, we introduce K8NTEXT, a novel approach for streamlining K8s audit logs by reconstructing contexts , i.e., grouping actions performed by actors on the cluster with the subsequent events these actions cause. Correlated API calls are automatically identified, labeled, and consistently grouped using a combination of inference rules and a Machine Learning (ML) model, largely simplifying data consumption. We evaluate K8NTEXT’s performance, scalability, and expressiveness both in systematic tests and with a series of use cases. We show that it consistently provides accurate context reconstruction, even for complex operations involving 50, 100 or more correlated actions, achieving over 95 % accuracy across the entire spectrum, from simple to highly composite actions.
Matteo Franzil, Valentino Armani, Luis Augusto Dias Knob, Domenico Siracusa
Comput. Networks4
2026 INTELLECT: From federated training to resource-aware cyber threat detection
Simone Magnani, Liubov Nedoshivina, Roberto Doriguzzi Corin, Stefano Braghin, Domenico Siracusa
Comput. Networks5
2026 Exploiting Kubernetes' Image Pull Implementation to Deny Node Availability
abstract
Kubernetes (K8s) has grown in popularity over the past few years to become thede-factostandard for container orchestration in cloud-native environments. While research is not new to topics such as containerization and access control security, the Application Programming Interface (API) interactions between K8s and its runtime interfaces have not been studied thoroughly. In particular, the CRI-API is responsible for abstracting the container runtime, managing the creation and lifecycle of containers along with the downloads of the respective images. However, this decoupling of concerns and the abstraction of the container runtime renders K8s unaware of the status of the downloading process of the container images, obstructing the monitoring of the resources allocated to such process. In this paper, we discuss how this lack of status information can be exploited as a Denial of Service attack in a K8s cluster. We show how such attacks can impact worker nodes, generating up to 95% average CPU usage, prevent downloads of new container images, and increase I/O and network usage for a potentially unlimited amount of time.We argue that solving this problem would require a radical architectural change in the relationship between K8s and the CRI-API, which would be unfeasible in the short term. Thus, as a stopgap solution, we propose MAGI: an eBPF-based, proof-of-concept mitigation that detects and terminates potential attacks.
Luis Augusto Dias Knob, Matteo Franzil, Domenico Siracusa
IEEE Trans. Dependable Secur. Comput.3
2025 Rethinking NIDS Rule-Based Pre-Filtering
abstract
Surging network traffic is pushing signature-based Network Intrusion Detection Systems (NIDSs) to their limits, as they struggle to inspect every incoming packet. The high computational cost of analyzing each packet and matching it against large rulesets can lead to system saturation and missed attacks. Rule-based pre-filtering can reduce this cost by forwarding only potentially malicious packets to the NIDS. However, existing work has largely overlooked the impact of pre-filtering on the NIDS’s attack detection performance. Our analysis shows that current methods disrupt attack detection because they discard packets that do not match the pre-filtering rules, ignoring the fact that NIDSs require additional flow information (e.g., the TCP handshake) beyond the malicious packets to process flows and detect attacks properly. To address this, we propose eRBF, a new rule-based pre-filtering approach that pre-filters traffic not only according to the rules but also based on the NIDSs’ flow processing requirements. Experimental results with Snort demonstrate that eRBF achieves the desired balance, forwarding less than 22% of all packets across two well-known datasets while maintaining the attack detection above 95%.
Henrique B. Brum, Luis Augusto Dias Knob, Tiago Ferreto, Domenico Siracusa
CNSM4
2025 A Proactive Decoy Selection Scheme for Cyber Deception using MITRE ATT&CK
Marco Zambianco, Claudio Facchinetti, Domenico Siracusa
Comput. Secur.3
2025 Disruption-Aware Microservice Re-Orchestration for Cost-Efficient Multi-Cloud Deployments
abstract
Multi-cloud environments enable a cost-efficient scaling of cloud-native applications across geographically distributed virtual nodes with different pricing models. In this context, the resource fragmentation caused by frequent changes in the resource demands of deployed microservices, along with the allocation or termination of new and existing microservices, increases the deployment cost. Therefore, re-orchestrating deployed microservices on a cheaper configuration of multi-cloud nodes offers a practical solution to restore the cost efficiency of deployment. However, the rescheduling procedure causes frequent service interruptions due to the continuous termination and rebooting of the containerized microservices. Moreover, it may potentially interfere with and delay other deployment operations, compromising the stability of the running applications. To address this issue, we formulate a multi-objective integer linear programming (ILP) problem that computes a microservice rescheduling solution capable of providing minimum deployment cost without significantly affecting the service continuity. At the same time, the proposed formulation also preserves the quality of service (QoS) requirements, including latency, expressed through microservice co-location constraints. Additionally, we present a heuristic algorithm to approximate the optimal solution, striking a balance between cost reduction and service disruption mitigation. We integrate the proposed approach as a custom plugin of the Kubernetes (K8s) scheduler. Results reveal that our approach significantly reduces multi-cloud deployment costs and service disruptions compared to the benchmark schemes, while ensuring QoS requirements are consistently met.
Marco Zambianco, Silvio Cretti, Domenico Siracusa
IEEE Trans. Serv. Comput.3
2024 Demo: Cloud-native Cyber Deception with Decepto
abstract
The disaggregation of monolithic applications in containerized microservices inevitably weaken their security posture. In this context, leveraging the cloning feature of containerized environments, we propose Decepto, a software platform that integrates a high-interaction cyber deception mechanism within cloud-native applications using Kubernetes (K8s). In particular, our deception solution automatically generates decoys as clones of production microservices and deploys them to look like legitimate microservices. Attackers that unknowingly interact with such deceptive artifacts are reliably detected and monitored. In this work, we first present Decepto technical implementation, then we demonstrate its functionalities and related computational performance overhead emulating a practical attack scenario on a real K8s cluster.
Daniele Santoro, Marco Zambianco, Claudio Facchinetti, Domenico Siracusa
ISCC4
2024 Resource-Efficient Federated Learning for Network Intrusion Detection
abstract
Maintaining up-to-date attack profiles is a critical challenge for Network Intrusion Detection Systems (NIDSs). State-of-the-art solutions based on Machine Learning (ML) algorithms often rely on public datasets, which can be outdated or anonymised, hindering their effectiveness in real-world scenarios. Collaborative learning tackles data limitations by enabling multiple parties to jointly train and update their NIDSs through sharing recent attack information. However, directly sharing network traffic data can compromise the participants’ privacy. Federated Learning (FL) addresses this concern: it allows participants to collaboratively improve their NIDS models by sharing only the trained model parameters, not the raw data itself. Nevertheless, recent studies have proven that the Federated Averaging (FedAvg) algorithm at the core of FL can be inefficient with heterogeneous and unbalanced datasets. A recent solution called FLAD addresses the limitations of FedAvg, resulting in higher accuracy of the final ML model on out-of-distribution data. This work focuses on the resource usage of the FL process, demonstrating the superiority of FLAD over FedAvg in computational efficiency and convergence time, showcasing its potential to enhance NIDS effectiveness.
Roberto Doriguzzi Corin, Silvio Cretti, Domenico Siracusa
NetSoft3
2024 Building the Cloud Continuum with REAR
abstract
The computing continuum combines computational resources and services from edge to cloud, promising enhanced efficiency and resilience with respect to the traditional siloed-based approach. This study presents the REAR (Resource Advertisement and Reservation) protocol, which tackles the complexities of managing resources within this continuum. REAR establishes standardized interfaces to enable interoperability, enhances resource allocation efficiency, and maintains security measures for workload execution. The paper details the protocol’s design, key components, operational workflows, and potential uses, contributing to the optimization of resource use across the computing continuum.
Stefano Galantino, Elisa Albanese, Nasir Asadov, Stefano Braghin, Francesco Cappa, Andrea Colli-Vignarelli, Amjad Yousef Majid, Eduard Marin, Jacopo Marino, Lorenzo Moro, Liubov Nedoshivina, Fulvio Risso, Domenico Siracusa, Antonio F. Skarmeta, Luca Zuanazzi
NetSoft13
2024 Online Learning and Model Pruning Against Concept Drifts in Edge Devices
abstract
The proliferation of Internet of Things sensors has driven the adoption of the edge computing paradigm, which prioritizes processing the data close to the source to minimize data transfer to cloud servers, reduce latency, and enhance privacy and robustness. However, edge computing environments present limited computational power, storage capacity, and a non-negligible risk of cyber-attacks.This paper tackles the challenges of deploying Intrusion and/or Anomaly Detection Systems (I/ADSs) at the network’s edge, particularly for environments with evolving network attack patterns (concept drift). To this aim, we propose a methodology that leverages both Neural Network (NN) pruning and online learning. We empirically evaluate the proposed methodology under attack scenarios with concept drift in network traffic, where adaptation to new data trends is crucial. We also demonstrate that NN pruning leads to more energy-efficient and lightweight I/ADSs, which can be adopted also in devices with strict resource requirements.
Simone Magnani, Seshu Tirupathi, Roberto Doriguzzi Corin, Liubov Nedoshivina, Stefano Braghin, Domenico Siracusa
NetSoft6
2024 Introducing packet-level analysis in programmable data planes to advance Network Intrusion Detection
Roberto Doriguzzi Corin, Luis Augusto Dias Knob, Luca Mendozzi, Domenico Siracusa, Marco Savi
Comput. Networks4
2024 FLAD: Adaptive Federated Learning for DDoS attack detection
Roberto Doriguzzi Corin, Domenico Siracusa
Comput. Secur.2
2024 Resource-Aware Cyber Deception for Microservice-Based Applications
abstract
Cyber deception can be a valuable addition to traditional cyber defense mechanisms, especially for modern cloud-native environments with a fading security perimeter. However, pre-built decoys used in classical computer networks are not effective in detecting and mitigating malicious actors due to their inability to blend with the variety of applications in such environments. On the other hand, decoys cloning the deployed microservices of an application can offer a high-fidelity deception mechanism to intercept ongoing attacks within production environments. However, to fully benefit from this approach, it is essential to use a limited amount of decoy resources and devise a suitable cloning strategy to minimize the impact on legitimate services performance. Following this observation, we formulate a non-linear integer optimization problem that maximizes the number of attack paths intercepted by the allocated decoys within a fixed resource budget. Attack paths represent the attacker's movements within the infrastructure as a sequence of violated microservices. We also design a heuristic decoy placement algorithm to approximate the optimal solution and overcome the computational complexity of the proposed formulation. We evaluate the performance of the optimal and heuristic solutions against other schemes that use local vulnerability metrics to select which microservices to clone as decoys. Our results show that the proposed allocation strategy achieves a higher number of intercepted attack paths compared to these schemes while requiring approximately the same number of decoys.
Marco Zambianco, Claudio Facchinetti, Roberto Doriguzzi Corin, Domenico Siracusa
IEEE Trans. Serv. Comput.4
2023 Pruning Federated Learning Models for Anomaly Detection in Resource-Constrained Environments
abstract
The evolving complexity of modern IT infrastructures has paved the way for malicious actors to exploit a wide array of vulnerabilities that can compromise the integrity of these systems. Monitoring complex IT systems is expensive and often requires dedicated infrastructure for deploying Intrusion and/or Anomaly Detection Systems. Moreover, ML-based solutions need large training sets, which add to the overall cost. To tackle these challenges we present INTELLECT, a novel approach to Intrusion and/or Anomaly Detection System, which leverages Federated Learning and model pruning techniques to cooperatively train high-accuracy models using distributed datasets and derive a fleet of lightweight models, which can be deployed without incurring additional costs for dedicated infrastructure. INTELLECT expands on the state-of-the-art techniques for feature selection, model pruning, and model distillation to create an interconnected pipeline. We empirically demonstrate the effectiveness of the methodology on benchmark datasets, and we present guidelines for the deployment in production systems.
Simone Magnani, Stefano Braghin, Ambrish Rawat, Roberto Doriguzzi Corin, Mark Purcell, Domenico Siracusa
IEEE Big Data6
2023 Enhancing Network Intrusion Detection: An Online Methodology for Performance Analysis
abstract
Machine learning models have been extensively proposed for classifying network flows as benign or malicious, either in-network or at the endpoints of the infrastructure. Typically, the performance of such models is assessed by evaluating the trained model against a portion of the available dataset. However, in a production scenario, these models are fed by a monitoring stage that collects information from flows and provides inputs to a filtering stage that eventually blocks malicious traffic. To the best of our knowledge, no work has analysed the entire pipeline, focusing on its performance in terms of both inputs (i.e., the information collected from each flow) and outputs (i.e., the system’s ability to prevent an attack from reaching the application layer).In this paper, we propose a methodology for evaluating the effectiveness of a Network Intrusion Detection System (NIDS) by placing the model evaluation test alongside an online test that simulates the entire monitoring-detection-mitigation pipeline. We assess the system’s outputs based on different input configurations, using state-of-the-art detection models and datasets. Our results highlight the importance of inputs for the throughput of the NIDS, which can decrease by more than 50% with heavier configurations. Furthermore, our research indicates that relying solely on the performance of the detection model may not be enough to evaluate the effectiveness of the entire NIDS process. Indeed, even when achieving near-optimal False Negative Rate (FNR) values (e.g., 0.01), a substantial amount of malicious traffic (e.g., 70%) may still successfully reach its target.
Simone Magnani, Roberto Doriguzzi Corin, Domenico Siracusa
NetSoft3
2023 Locality-aware deployment of application microservices for multi-domain fog computing
Francescomaria Faticanti, Marco Savi, Francesco De Pellegrini, Domenico Siracusa
Comput. Commun.4
2022 Towards Application-Aware Provisioning of Security Services with Kubernetes
abstract
In network security, Network Function Virtualization can be exploited to implement flexible security services tailored to specific user needs. However, in practice this is hard to achieve due to the limitations of reference software platforms, such as Kubernetes, which are designed to orchestrate cloud-native services. In this work, we complement Kubernetes with a state-of-the-art algorithm for application-aware provisioning of security services. We demonstrate that the proposed solution improves basic provisioning mechanisms, such as the default Kubernetes scheduler, in terms of Quality of Service and security guarantees for the users.
Roberto Doriguzzi Corin, Silvio Cretti, Tiziana Catena, Simone Magnani, Domenico Siracusa
NetSoft5
2022 Design and Development of Network Monitoring Strategies in P4-enabled Programmable Switches
abstract
Network monitoring is of paramount importance for effective network management: it allows to constantly observe a network’s behavior to ensure it is working as intended, and can trigger both automated and manual remediation procedures in case of failures and anomalies. Software-Defined Networking (SDN) decouples the control plane of network infrastructure from its data plane to perform centralized control on the multiple switches in a network. In this context, the responsibility of switches is only to forward packets according to the instructions provided by a controller. The lack of programmability in the data plane of SDNs prompted the advent of data-plane programmable switches, which allow developers to customize the data-plane pipeline (e.g. match-action tables) by using a domain specific language named P4, and implement novel programs and protocols operating at wire speed directly in the switches. This unlocks the possibility to offload some monitoring tasks to the programmable data plane, and to perform fine-grained monitoring at very high packet processing speeds. Given the central importance of this topic, the principal goal of this thesis is to enable a wide range of monitoring tasks in data-plane programmable switches, with a focus on the ones equipped with programmable Application-Specific Integrated Circuits (ASICs). To achieve this goal, this thesis makes three main contributions: (i.) We enhance P4-supported data plane programmability for network monitoring; (ii.) We design and develop several network monitoring tasks in programmable data planes; (iii.) We combine multiple tasks in a single commodity switch to collect various metrics for different monitoring purposes. Our evaluations show that our solutions can be exploited by network administrators, operators and security engineers to better track and understand the current network status, and thus prevent infrastructure and service failures.
Damu Ding, Marco Savi, Federico Pederzolli, Domenico Siracusa
NOMS4
2022 Tracking Normalized Network Traffic Entropy to Detect DDoS Attacks in P4
abstract
Distributed Denial-of-Service (DDoS) attacks represent a persistent threat to modern telecommunications networks: detecting and counteracting them is still a crucial unresolved challenge for network operators. DDoS attack detection is usually carried out in one or more central nodes that collect significant amounts of monitoring data from networking devices, potentially creating issues related to network overload or delay in detection. The dawn of programmable data planes in Software-Defined Networks can help mitigate this issue, opening the door to the detection of DDoS attacks directly in the data plane of the switches. However, the most widely-adopted data plane programming language, namely P4, lacks supporting many arithmetic operations, therefore, some of the advanced network monitoring functionalities needed for DDoS detection cannot be straightforwardly implemented in P4. This work overcomes such a limitation and presents two novel strategies for flow cardinality and for normalized network traffic entropy estimation that only use P4-supported operations and guarantee a low relative error. Additionally, based on these contributions, we propose a DDoS detection strategy relying on variations of the normalized network traffic entropy. Results show that it has comparable or higher detection accuracy than state-of-the-art solutions, yet being simpler and entirely executed in the data plane.
Damu Ding, Marco Savi, Domenico Siracusa
IEEE Trans. Dependable Secur. Comput.3
2021 Community-based Placement of Registries to Speed up Application Deployment on Edge Computing
abstract
The use of virtualization techniques, such as containerization, is rapidly changing how the deployment of applications is performed at the network edge. Indeed, container images enable fast instantiation and small footprint. However, although having smaller size than VMs virtual disks, container images continue to have hundreds of megabytes and can take several seconds to be downloaded in an edge node. In fact, the heterogeneity and resource-constrained infrastructure, typical of an edge computing scenario, can also increase this latency, by the several bottlenecks that may occur on the network topology. We advocate that the use of well-positioned container registries on the topology can significantly improve the deployment process. To prove that, in this paper we focus our analysis on the network requirements of large amounts of container deployments, and the impact generated on two distinct edge topologies. We also present a new registries placement solution based on a fluid communities algorithm. We validated our proposal using simulation and results show that it validates the model and generality of the proposed solution, showing enhanced performance even with biased schedulers with large amounts of deployments in a concentrated set of nodes.
Luis Augusto Dias Knob, Francescomaria Faticanti, Tiago Ferreto, Domenico Siracusa
IC2E4
2021 Fog Orchestration meets Proactive Caching
Francescomaria Faticanti, Lorenzo Maggi, Francesco De Pellegrini, Daniele Santoro, Domenico Siracusa
IM5
2021 INVEST: Flow-based Traffic Volume Estimation in Data-plane Programmable Networks
abstract
The emergence of programmable data planes in Software-Defined Networks enables the execution of various monitoring tasks directly in network devices, overcoming the need to deliver huge amounts of information to a controller that must then process it at scale. In this paper, we aim to solve a fundamental problem arising when exploiting programmable data planes for network-wide monitoring: how to estimate the overall number of packets in the network (i.e., the traffic volume), and the related number and size of flows, while avoiding packet double counting. Most existing works solve this problem by ensuring that each packet is counted only once on its path, which limits routing or requires coordination among devices. We propose a different approach, INVEST, a flow-based traffic volume estimator for P4-based switches, that relies on and can reuse commonly employed data structures while naturally solving the double-counting problem. We theoretically analyze and experimentally evaluate our solution, which we implemented in a real P4 carrier-grade switch, finding that it is accurate, memory-efficient, and can process packets at line rate.
Damu Ding, Marco Savi, Federico Pederzolli, Domenico Siracusa
Networking4
2021 In-Network Volumetric DDoS Victim Identification Using Programmable Commodity Switches
abstract
Volumetric distributed Denial-of-Service (DDoS) attacks have become one of the most significant threats to modern telecommunication networks. However, most existing defense systems require that detection software operates from a centralized monitoring collector, leading to increased traffic load and delayed response. The recent advent of Data Plane Programmability (DPP) enables an alternative solution: threshold-based volumetric DDoS detection can be performed directly in programmable switches to skim only potentially hazardous traffic, to be analyzed in depth at the controller. In this paper, we first introduce the BACON data structure based on sketches, to estimate per-destination flow cardinality, and theoretically analyze it. Then we employ it in a simple in-network DDoS victim identification strategy, INDDoS, to detect the destination IPs for which the number of incoming connections exceeds a pre-defined threshold. We describe its hardware implementation on a Tofino-based programmable switch using the domain-specific P4 language, proving that some limitations imposed by real hardware to safeguard processing speed can be overcome to implement relatively complex packet manipulations. Finally, we present some experimental performance measurements, showing that our programmable switch is able to keep processing packets at line-rate while performing volumetric DDoS detection, and also achieves a high F1 score on DDoS victim identification.
Damu Ding, Marco Savi, Federico Pederzolli, Mauro Campanella, Domenico Siracusa
IEEE Trans. Netw. Serv. Manag.5
2020 Estimating Logarithmic and Exponential Functions to Track Network Traffic Entropy in P4
abstract
The evaluation of network traffic entropy is very useful for management purposes, since it helps to keep track of changes in network flow distribution. Nowadays, network traffic entropy is usually estimated in centralized monitoring collectors, which require a significant amount of information to be retrieved from switches. The advent of programmable data planes in Software-Defined Networks helps mitigate this issue, opening the door to the possibility of estimating entropy directly in the switches’ data plane. Unfortunately, the most widely-adopted programming language used to program the data plane, called P4, lacks supporting many arithmetic operations such as logarithm and exponential function computation, which are necessary for entropy estimation. In this paper we propose two new algorithms, called P4Log and P4Exp, to fill this gap: these algorithms can estimate logarithms and exponential functions with a given precision by only using P4-supported arithmetic operations. Additionally, we leverage them to propose a novel strategy, called P4Entropy, to estimate traffic entropy entirely in the switch data plane. Results show that P4Entropy has comparable accuracy as an existing solution but without (i) constraining the number of packets in an observation interval and (ii) requiring the usage of TCAM, which is a scarce resource.
Damu Ding, Marco Savi, Domenico Siracusa
NOMS3
2020 Optimal Blind and Adaptive Fog Orchestration under Local Processor Sharing
Francesco De Pellegrini, Francescomaria Faticanti, Mandar Datar 0001, Eitan Altman, Domenico Siracusa
WiOpt5
2020 Smart Contracts for Service-Level Agreements in Edge-to-Cloud Computing
Petar Kochovski, Vlado Stankovski, Sandi Gec, Francescomaria Faticanti, Marco Savi, Domenico Siracusa
J. Grid Comput.6
2020 Lucid: A Practical, Lightweight Deep Learning Solution for DDoS Attack Detection
abstract
Distributed Denial of Service (DDoS) attacks are one of the most harmful threats in today's Internet, disrupting the availability of essential services. The challenge of DDoS detection is the combination of attack approaches coupled with the volume of live traffic to be analysed. In this paper, we present a practical, lightweight deep learning DDoS detection system called Lucid, which exploits the properties of Convolutional Neural Networks (CNNs) to classify traffic flows as either malicious or benign. We make four main contributions; (1) an innovative application of a CNN to detect DDoS traffic with low processing overhead, (2) a dataset-agnostic preprocessing mechanism to produce traffic observations for online attack detection, (3) an activation analysis to explain Lucid's DDoS classification, and (4) an empirical validation of the solution on a resource-constrained hardware platform. Using the latest datasets, Lucid matches existing state-of-the-art detection accuracy whilst presenting a 40x reduction in processing time, as compared to the state-of-the-art. With our evaluation results, we prove that the proposed approach is suitable for effective DDoS detection in resource-constrained operational environments.
Roberto Doriguzzi Corin, Stuart Millar, Sandra Scott-Hayward, Jesús Martínez del Rincón, Domenico Siracusa
IEEE Trans. Netw. Serv. Manag.5
2020 Dynamic and Application-Aware Provisioning of Chained Virtual Security Network Functions
abstract
A promising area of application for Network Function Virtualization (NFV) is in network security, where chains of Virtual Security Network Functions (VSNFs), i.e., security-specific virtual functions such as firewalls or Intrusion Prevention Systems, can be dynamically created and configured to inspect, filter or monitor the network traffic. However, the traffic handled by VSNFs could be sensitive to specific network requirements, such as minimum bandwidth or maximum end-to-end latency. Therefore, the decision on which VSNFs should apply for a given application, where to place them and how to connect them, should take such requirements into consideration. Otherwise, security services could affect the quality of service experienced by customers. In this paper, we propose PESS (Progressive Embedding of Security Services), a solution to efficiently deploy chains of virtualised security functions based on the security requirements of individual applications and operators' policies, while optimizing resource utilization. We provide the PESS mathematical model and heuristic solution. Simulation results show that, compared to state-of-the-art application-agnostic VSNF provisioning models, PESS reduces computational resource utilization by up to 50%, in different network scenarios. This result ultimately leads to a higher number of provisioned security services and to up to a 40% reduction in end-to-end latency of application traffic.
Roberto Doriguzzi Corin, Sandra Scott-Hayward, Domenico Siracusa, Marco Savi, Elio Salvadori
IEEE Trans. Netw. Serv. Manag.3
2020 An Incrementally-Deployable P4-Enabled Architecture for Network-Wide Heavy-Hitter Detection
abstract
The advent of Software-Defined Networking with OpenFlow first, and subsequently the emergence of programmable data planes, has boosted lots of research around many networking aspects: monitoring, security, traffic engineering. In the context of monitoring, most of the proposed solutions show the benefits of data plane programmability by simplifying the network complexity with a one big-switch abstraction. Only few papers look at network-wide solutions, but consider the network only composed by programmable devices. In this paper, we argue that the primary challenge for a successful adoption of those solutions is the deployment problem: how to compose and monitor a network consisting of both legacy and programmable switches? We propose an approach for incrementally deploy programmable devices in an ISP network with the goal of monitoring as many distinct network flows as possible. While assessing the benefits of our solution, we realized that proposed network-wide monitoring algorithms might not be optimized for a partial deployment scenario. We then also developed and implemented in P4 a novel strategy capable of detecting network-wide heavy flows: results show that it can achieve better accuracy than state-of-the-art solutions while relying on less information from the data plane and leading to only marginal additional packet processing time.
Damu Ding, Marco Savi, Gianni Antichi, Domenico Siracusa
IEEE Trans. Netw. Serv. Manag.4
2020 Throughput-Aware Partitioning and Placement of Applications in Fog Computing
abstract
Fog computing promises to extend cloud computing to match emerging demands for low latency, location-awareness and dynamic computation. It thus brings data processing close to the edge of the network by leveraging on devices with different computational characteristics. However, the heterogeneity, the geographical distribution, and the data-intensive profiles of IoT deployments render the placement of fog applications a fundamental problem to guarantee target performance figures. This is a core challenge for fog computing providers to offer fog infrastructure as a service, while satisfying the requirements of this new class of microservices-based applications. In this article we root our analysis on the throughput requirements of the applications while exploiting offloading towards different regions. The resulting resource allocation problem is developed for a fog-native application architecture based on containerised microservice modules. An algorithmic solution is designed to optimise the placement of applications modules either in cloud or in fog. Finally, the overall solution consists of two cascaded algorithms. The first one performs a throughput-oriented partitioning of fog application modules. The second one rules the orchestration of applications over a region-based infrastructure. Extensive numerical experiments validate the performance of the overall scheme and confirm that it outperforms state-of-the-art solutions adapted to our context.
Francescomaria Faticanti, Francesco De Pellegrini, Domenico Siracusa, Daniele Santoro, Silvio Cretti
IEEE Trans. Netw. Serv. Manag.3
2019 AADS: A Noise-Robust Anomaly Detection Framework for Industrial Control Systems
Maged AbdelAty, Roberto Doriguzzi Corin, Domenico Siracusa
ICICS3
2019 Incremental Deployment of Programmable Switches for Network-wide Heavy-hitter Detection
abstract
The advent of Software-Defined Networking with OpenFlow first, and subsequently the emergence of programmable data planes, has boosted lot of research around many networking aspects: monitoring, security, traffic engineering. In the context of network monitoring, most of the proposed solutions show the benefits of data plane programmability by simplifying the complexity of the network with a one big-switch abstraction. Only few papers look at network-wide solutions, but consider the network as non heterogeneous: only composed by programmable devices. In this paper, we argue that the primary challenge for a successful adoption of those solutions is the deployment problem: how to compose and monitor a network consisting of both legacy and programmable switches? We propose an approach for incrementally deploy programmable devices in an ISP network with the goal of monitoring as many distinct network flows as possible. While assessing the benefits of our solution, we realized that proposed network-wide monitoring algorithms might not be optimized for a partial deployment scenario. We then also developed a novel strategy capable of detecting network-wide heavy flows with the same accuracy of state-of-the-art solutions but by relying on less information from the data plane.
Damu Ding, Marco Savi, Gianni Antichi, Domenico Siracusa
NetSoft4
2017 An effective swapping mechanism to overcome the memory limitation of SDN devices
abstract
Thanks to its 1-cycle lookup performance, the Ternary Content Addressable Memory (TCAM) is considered an essential hardware component for the deployment of high-performance Software-Defined Networks (SDN). Unfortunately, in many network scenarios, TCAMs can quickly fill due to their limited memory size, thus preventing the installation of new flow-rules and leading to inefficient traffic forwarding. This issue has already been addressed in computer programming, where Virtual Memory is offered to applications to mimic a much larger physical memory, by swapping memory pages to disk. In a previous work, we proposed and discussed the architecture of a Memory Management System (MMS) for SDN controllers that, like the analogous process for computer Operating Systems, optimizes the memory usage and prevents anomalies due to lack of memory space. This work proposes a memory swapping mechanism for SDN controllers, a function of the MMS which gives SDN applications the illusion of unlimited memory space in the forwarding devices, without requiring any hardware modification or changes in the control protocol. The paper discusses the memory swapping mechanism design, its implementation and proves its quality using real traffic traces, demonstrating lower TCAM memory utilization and potentially increased network performance in terms of end-to-end throughput. A prototype of the MMS is available for testing as an open source project.
Antonio Marsico, Roberto Doriguzzi Corin, Domenico Siracusa
IM3
2017 Overcoming the memory limits of network devices in SDN-enabled data centers
abstract
In extremely connected and dynamic environments, such as data centers, SDN network devices can be exploited to simplify the management of network provisioning. However, they leverage on TCAMs to implement the flow tables, i.e., on size-limited memories that can be quickly filled up when fine-grained traffic control is required, eventually preventing the installation of new forwarding rules. In this work, we demonstrate how this issue can be mitigated by means of a novel flow rule swapping mechanism. Specifically, we first show the negative effects of a full TCAM on a video streaming service provided by an SDN-enabled data center. Then, we show that our swapping mechanism helps in overcoming the inability to properly access a media content available in the data center, by temporarily moving the least matched flow rules from the TCAM to a larger memory outside the SDN device.
Antonio Marsico, Roberto Doriguzzi Corin, Domenico Siracusa
IM3
2017 An interactive intent-based negotiation scheme for application-centric networks
abstract
The demonstration presents the first implementation of a resource negotiation scheme between users and a network for the provisioning of application-aware connectivity services. This active interaction enables the users, who request connectivity services with multiple application requirements, to select an alternative solution when the network does not have enough resources to satisfy the original requests.
Antonio Marsico, Michele Santuari, Marco Savi, Domenico Siracusa, Stéphane Junique, Pontus Sköldström
NetSoft4
2016 Dynamic strict fractional frequency reuse for software-defined 5G networks
abstract
The surge of mobile data traffic has spurred academia and industries to begin developing 5G networks. 5G is meant to overcome limitations of 4G cellular technology relying on the dominant trend of mobile network densification with the deployment of small cell base stations. To accelerate this process, low complexity and inexpensive remote radio heads (RRHs) are deployed massively and connected to a centralized pool of resources. In this work, we study the problem of inter-cell interference (ICI) which arises in frequency reuse one multi-tier 5G networks. We entrust the management of RRHs to a software-defined network controller and we take advantage of network functions virtualization. Our contributions consist of proposing Dynamic Strict Fractional Frequency Reuse (DSFFR), a method to relieve ICI which dynamically divides the small cell area in a different number of sectors. Furthermore, we formulate a joint scheduling problem composed of two schedulers which operate at different time granularity to transmit downlink packets. Modeling the coverage area with the tool of stochastic geometry and solving with simulations the joint scheduling problem, we are able to show that DSFFR outperforms the static scheme. Performances are addressed in terms of spectral efficiency and packet blocking probability.
Anteneh A. Gebremariam, Tingnan Bao, Domenico Siracusa, Tinku Rasheed, Fabrizio Granelli, Leonardo Goratti
ICC3
2016 Congestion control in the recursive InterNetworking Architecture (RINA)
abstract
RINA, the Recursive InterNetwork Architecture, is a novel “back to basics” type approach to networking. The recursive nature of RINA calls for radically different approaches to how networking is performed. It shows great potential in many aspects, e.g. by simplifying management and providing better security. However, RINA has not been explored for congestion control yet. In this paper, we take first steps to investigate how congestion control can be performed in RINA, and demonstrate that it can be very efficient because it is applied close to where the problem happens, and through its recursive architecture, interesting effects can be achieved. We also show how easily congestion control can be combined with routing, enabling a straightforward implementation of in-network resource pooling.
Peyman Teymoori, Michael Welzl, Stein Gjessing, Eduard Grasa, Roberto Riggio, Kewin Rausch, Domenico Siracusa
ICC7
2016 Empowering network operating systems with memory management techniques
abstract
Similarly to computer operating systems which guarantee safe access to memory resources, Network Operating Systems shall grant SDN applications a reliable access to neatly organized flow table resources. This paper presents the architecture for a controller-agnostic Memory Management System and some of its functionalities that aim at improving flow table usage and preventing network misconfigurations. From the implementation perspective, this work discusses the applicability of the proposed system, a strategy to evaluate it and current open challenges.
Roberto Doriguzzi Corin, Domenico Siracusa, Elio Salvadori, Arne Schwabe
NOMS2
2016 A non-disruptive automated approach to update SDN applications at runtime
abstract
The Memory Management Subsystem (MMS) provides automated services for SDN controllers that optimize the management of network devices' memory. Among other functions, it cleans the memory of network devices upon the update or the removal of SDN applications. The potential of this MMS function is demonstrated in a scenario where a critical security update for a network application would be otherwise ineffective.
Antonio Marsico, Roberto Doriguzzi Corin, Matteo Gerola, Domenico Siracusa, Arne Schwabe
NOMS4
2015 A framework for interference control in Software-Defined mobile radio networks
abstract
To cope up with the booming of data traffic and to accommodate new and emerging technologies such as machine-type communications, the 5th Generation (5G) of mobile networks must be empowered with efficient resource allocation schemes that benefit from the adoption of the Software-Defined networking (SDN) paradigm. In radio communications, allocation of resources is tightly connected with interference. In this paper, we revisit the way wireless interference is managed and avoided relying on the SDN paradigm for controlling the network. The SDN approach is exploited to expose the lower layers of the stack (e.g., Physical and Medium Access Control) to the controller and its applications by making system parameters available, such that it is possible to dynamically configure the network in a logically centralized fashion, by means of specifically designed algorithms. The contribution of this work is threefold. First, we show how to adapt the SDN paradigm to mobile networks. Second, we propose the interference graph as an abstraction that can be used to control interference. Last, we formulate a throughput optimization tool that uses the proposed interference graph as an input.
Anteneh A. Gebremariam, Leonardo Goratti, Roberto Riggio, Domenico Siracusa, Tinku Rasheed, Fabrizio Granelli
CCNC4
2014 The price of virtualization: Performance isolation in multi-tenants networks
abstract
Network virtualization sits firmly on the Internet evolutionary path allowing researchers to experiment with novel clean-slate designs over the production network and practitioners to manage multi-tenants infrastructures in a flexible and scalable manner. In such scenarios, isolation between virtual networks is often intended as purely logical: this is the case of address space isolation or flow space isolation. This approach neglects the effect that network virtualization has on resource allocation network-wide. In this work we investigate the price paid by a purely logical approach in terms of performance degradation. This performance loss is paid by the actual users of a multi-tenants datacenter network. We propose a solution to this problem leveraging on a new network virtualization primitive, namely an online link utilization feedback mechanism. It provides each tenant with the necessary information to make efficient use of network resources. We evaluate our solution trough a real implementation exploiting the OpenFlow protocol. Empirical results confirm that the proposed scheme is able to support tenants in exploiting virtualized network resources effectively.
Roberto Riggio, Francesco De Pellegrini, Domenico Siracusa
NOMS3
2014 Demonstration of proactive restoration in cognitive heterogeneous reconfigurable optical networks
abstract
An emulation study has been carried to demonstrate the benefit of a proactive restoration technique in cognitive heterogeneous optical networks. Results show the advantages of that method in terms of recovery percentage and disruption time.
Natalia Fernández, Ramón J. Durán, Ignacio de Miguel, Juan Carlos Aguado, Noemí Merayo, Rubén M. Lorenzo, Domenico Siracusa, Antonio Francescon, Elio Salvadori
QSHINE7
2012 On the energy consumption of IP-over-WDM architectures
abstract
Today's “green thrust” has been completely steering the evolution of our society. Therefore, since enhancements on telecommunication networks are expected to cope with the growth of traffic demand, energy consumption is becoming a crucial design metric. In this paper we focus on IP over Wavelength Division Multiplexing (IPoWDM) optical network architectures, where optical circuits (or lightpaths) interconnect IP routers. Various implementations of IPoWDM networks are possible, e.g., transparent, translucent or opaque each accounting different routing and switching constraints, in order to evolve from the classic IPoWDM approach, where only signal transmission is performed optically. Although it is a common belief that “more optical” architectures can generally guarantee a much lower total power consumption, we show that identifying the most energy-efficient IPoWDM architecture is not a trivial task. In fact we demonstrate that the most energy-efficient architecture depends on some network parameters such as number of nodes, link length and average distance between nodes. This work provide an analytical framework by which we draw guidelines to (a) assess under which conditions optical switching actually becomes more desirable than electronic switching and (b) evaluate which architecture, among those employing optical switching, is more energy-efficient under different parameter settings.
Francesco Musumeci 0001, Domenico Siracusa, Giuseppe Rizzelli, Massimo Tornatore, Riccardo Fiandra, Achille Pattavina
ICC2
2011 Hybrid Architecture for Optical Interconnection Based on Micro Ring Resonators
abstract
Future interconnection subsystems for switches and routers must overcome physical limitations of current electronic backplanes in order to achieve aggregate bandwidth much greater than today. Driven by this consideration we study the scalability of switching architectures implementing backplanes based on optical interconnection technology. In particular, this paper deals with the issue of interconnecting the line cards of a switch/router exploiting the wavelength agility of the transmitters and the switching/filtering capabilities of Micro Ring Resonators. To accomplish this task, the resonators deployed in the backplane are both tunable and fixed, thus defining a hybrid architecture. In our analysis we address feasibility and scalability issues in terms of maximum number of interconnected cards, taking various design parameters into account. Moreover, we perform a preliminary power consumption analysis of the proposed backplane architecture.
Domenico Siracusa, Vittorio Linzalata, Guido Maier, Achille Pattavina, Yabin Ye
GLOBECOM1
2010 Hierarchical Border Gateway Protocol (HBGP) for PCE-Based Multi-Domain Traffic Engineering
abstract
In multi-domain multi-carrier networks the effective use of network resources shall be achieved while guaranteeing an adequate level of confidentiality and scalability. A candidate solution to perform effective multi- domain Traffic Engineering (TE) is based on a combination of (i) hierarchical routing and (ii) path computation procedures. Hierarchical routing identifies the domain sequence to cross while path computation computes the strict end to end path. In this multi-domain study we first propose a hierarchical instance of BGP (HBGP) dedicated to TE information only. Then we propose and evaluate the integration of HBGP with path computation procedures based on IETF PCE architecture. Simulation results show that the hierarchical HBGP-PCE architecture, compared to current routing solutions based on BGP only, significantly improves the overall network resource utilization. In addition, this study identifies the network scenarios in which the aforementioned HBGP-PCE features provide significant advantages. Finally, the experimental implementation of the proposed HBGP-PCE architecture in a network testbed composed of commercially available routers shows the viability of the solution in real networks.
Luca Buzzi, Matteo Conforto Bardellini, Domenico Siracusa, Guido Maier, Francesco Paolucci, Filippo Cugini, Luca Valcarenghi, Piero Castoldi
ICC3
2010 Carrier Grade Ethernet Versus SDH in Optical Networks: Planning Methods and CAPEX Comparisons
abstract
The new Carrier Ethernet services offered by providers require not only a huge amount of bandwidth, but also a more flexible access to bandwidth that the traditional transport networks, based on circuit-switching, can hardly provide. Carriers have nowadays the option of migrating to new layer-2 frame-switched technologies developed ad hoc to support Carrier Ethernet. An important question is whether this migration is really cost effective. This paper deals with the problem of designing a transport network able to support Carrier Ethernet. We compare two network models, one based on layer-2 switching and Ethernet interfaces, the other based on legacy circuit switching and SDH interfaces. Minimization of investments for network interfaces is carried out for the two models, given the same static-traffic matrix to be supported. Both an ILP formulation and a heuristic method are proposed to solve the design problem. The results presented for comparison are obtained by applying the optimization procedures to a case-study network.
Domenico Siracusa, Guido Maier
ICC1