Alberto E. Schaeffer Filho

dblp:89/1649 · also Alberto E. Schaeffer-Filho, Alberto Egon Schaeffer Filho, Alberto Schaeffer-Filho · DBLP profile ↗
← Back
73ranked-venue papers
3as first author
20since 2021 · last 2026
0000-0003-1780-9060ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 38 · 2 first-author · 8 since 2021Systems, architecture and hardware · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 since 2021Security and privacy · 2Software engineering, systems software and programming languages · 2Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Keep Calm But Log for Trouble: Coordination-Free Fault-Tolerance for In-Switch Applications
abstract
In-network computing (INC) offloads parts of the functionality of a distributed system to programmable switches. Once we move the computation into the network, failures may cause loss of essential information and disrupt the operation of these systems. To ensure high availability in the event of switch failures, the current state-of-the-art replicates state across multiple INCs. They achieve this by usingstate-machine replication, ensuring that INC replicas are consistent bycoordinatingthe replication between multiple INC nodes. In this paper, we demonstrate that decoupling the consistency guarantees from the replication reduces the overhead of INC fault tolerance. We presentRESIST, a system for building fault-tolerant INC using asynchronous replication and replay-based recovery. We propose new techniques for logging information and different replay techniques to restore INC systems according to consistency semantics. Furthermore, we applyRESISTtechniques to existing INC functionalities, including event synchronization for distributed simulations and aggregation for distributed training. Our prototype ofRESISTenables fault tolerance for INC applications on BMv2 and in a testbed with Tofino ASICs. Experiments show that the system provides fault tolerance with negligible overhead for non-failure scenarios and recovers from failures in less than 0.2 s.
Ricardo Parizotto, Israat Haque 0001, Alberto E. Schaeffer Filho
IEEE Trans. Cloud Comput.3
2026 Reinforcement Learning-Based In-Network Load Balancing
abstract
Ensuring consistent performance becomes increasingly challenging with the growing complexity of applications in data centers. This is where load balancing emerges as a vital component. A load balancer distributes network or application traffic across various servers, resources, or pathways. In this article, we present P4WISE, a load balancer designed for software-defined networks. Operating on both the data and control planes, it employs reinforcement learning to distribute computational loads with granularity at inter and intra-server levels. Evaluation results demonstrate a remarkable 90% accuracy in predicting the optimal load balancing strategy of P4WISE in dynamic scenarios. Notably, unlike supervised or unsupervised methods, it eliminates the need for retraining when the environment undergoes minor or major changes. Instead, P4WISE autonomously adjusts and retrains itself based on observed states within the data center.
Hesam Tajbakhsh, Ricardo Parizotto, Alberto E. Schaeffer Filho, Israat Haque 0001
IEEE Trans. Netw. Serv. Manag.3
2025 NetFeatureXtract: Efficient Traffic Feature Extraction using eBPF
Gustavo Henrique Ellwanger Einsfeldt, Alberto E. Schaeffer Filho
AINA (1)2
2025 XFAST: Efficient Feature Selection for High-Performance Network Traffic Analysis using eBPF/XDP and Genetic Algorithms
abstract
Intrusion Detection Systems (IDS) rely heavily on feature-rich data and dimensionality reduction to identify anomalies in high-throughput networks. However, traditional approaches to feature selection are often computationally expensive user-space processes that limit real-time use. In this paper, we present XFAST, a novel in-kernel feature extraction and selection framework built using eBPF/XDP and Genetic Algorithms (GA). XFAST enables low-latency, real-time analysis of network traffic by efficiently computing and refining flow-level features entirely within the Linux kernel. Our system introduces a lightweight, tail-call-based GA execution model that distributes the evolutionary process across multiple packets, using a hitbased fitness function to optimize feature subsets. Our evaluation shows that XFAST improves the F1-score of an Isolation Forest model from 0.80 to 0.85 while maintaining negligible CPU and memory overhead, demonstrating its scalability and efficiency for deployment in edge and cloud-native environments.
Gustavo Henrique Ellwanger Einsfeldt, Alberto E. Schaeffer Filho
CNSM2
2025 SafeNetCC: Towards Safety-Oriented Congestion Control
abstract
Congestion control mechanisms limit the end hosts' transmission rates, preventing the depletion of network resources. Typically, these systems focus only on fair resource allocation between competing flows. However, thinking only about fairness is insufficient: novel ML-powered congestion control mechanisms may be unpredictable, and even some of the already widely adopted congestion control mechanisms may still harm the network operation in some scenarios. In this context, it is important to also think about the safety of those systems. In this work, we present and analyze formally the concept of safety in congestion control. We use this formalization to design and implement SafeNetCC, a system capable of improving safety of potentially unsafe congestion control mechanisms. Our preliminary results show that SafeNetCC can improve network safety, reducing delays and improving fairness, even when incompatible congestion controls coexist in the same network. In an emulated scenario, we observed an RTT reduction of up to 80% and fairness improvements for incompatible congestion controls.
Diego Cardoso Nunes, Theophilus Benson, Alberto E. Schaeffer Filho
NOMS3
2025 Composing Fault Tolerant In-Network Computing Systems via High-Level Intents
abstract
The performance benefits of data plane programmability have motivated many researchers to offload the computation of applications that previously operated only on servers to the network, creating the notion of in-network computing (INC). Because failures can occur in the data plane, fault tolerance mechanisms are essential for INC. However, INC operators and developers must manually set fault tolerance requirements using domain knowledge to change the source code. These manually set requirements may take time and lead to errors in case of misconfiguration. In this work, we present ARAUCARIA, a system that composes fault tolerance building blocks for INC based on high-level intents. The system allows the specification of requirements using an intent language, which allows the expression of consistency and availability requirements in a constrained natural language. A refinement process translates the intent and instruments the INC with essential building blocks and configurations. Our prototype of ARAUCARIA enables fault tolerance for INC applications on BMv2 and in a testbed with Tofino ASICs. Experiments show that the system provides fault tolerance with negligible overhead.
Ricardo Parizotto, Israat Haque 0001, Alberto E. Schaeffer Filho
NOMS3
2025 Hidden Impact of Hardware Technologies on Throughput: a Case Study on a Brazilian Mobile Web Network
abstract
The Web has shifted towards a mobile-first ecosystem with tools, frameworks, and forums explicitly discussing and catering for the mobile users, both mobile apps and mobile web-pages. Unfortunately, much of the studies and designs are often based on analysis and findings from developed regions (e.g., N. America and Europe) or based on user-generated data (introducing bias). In this paper, we present one of the first studies to understand the interplay between hardware characteristics (e.g., cellular and mobile) on expected network and application level performance in Brazil (the largest developing region in S. America). We analyze more than 170 million measurement sessions collected from within the network of one of the largest Mobile Network Operators in Brazil. Our findings (1) illustrate limitations of existing crowdsourced measurements and inaccuracies in assumptions about adoption patterns and performance in the global south, (2) highlight the differences between recommendations made by standardization bodies and real world performance, (3) disclose a significant change pre- and post-pandemic, and (4) quantify the benefits of using both client side and network data for analysis.
Eduardo C. Paim, Roberto Irajá Tavares da Costa Filho, Valter Roesler, Theophilus Benson, Alberto E. Schaeffer Filho
WWW5
2024 P4Hauler: An Accelerator-Aware In-Network Load Balancer for Applications Performance Boosting
abstract
Programmable accelerators enable the execution of applications intended for running in usual servers. However, inappropriately running applications on these devices can lead to load imbalance and performance degradation. An alternative to tackle this problem is load balancing, but existing in-network load balancers typically have no visibility of accelerators and often hard code policies in the switch source code. In this article, we presentP4Hauler, an accelerator-aware in-network load balancer. In particular, our design discusses how to enforce load-balancing decisions in a programmable switch in a resource-aware manner, allowing different policies to handle traffic according to applications' needs. We use monitoring and compression techniques to store application resources in a programmable switch for resource-aware decisions. In addition, we propose building blocks that operators can dynamically choose to realize different load balancing policies on-the-fly. We implemented and evaluated a prototype ofP4Hauleron a testbed to show its efficiency and deployment feasibility. Our results indicate thatP4Haulercan support 27% more load and decrease the flow completion time by around 13% using only a single accelerator. Also, extensive simulations confirm the performance gain ofP4Haulerat scale compared to the state-of-the-art.
Hesam Tajbakhsh, Ricardo Parizotto, Alberto E. Schaeffer Filho, Israat Haque 0001
IEEE Trans. Cloud Comput.3
2023 CrossBal: Data and Control Plane Cooperation for Efficient and Scalable Network Load Balancing
abstract
Load balancing network traffic through multiple shortest-paths has become common practice to efficiently utilize the network infrastructure. Despite widespread adoption, Equal-Cost Multi-Path (ECMP) delivers performance far from optimal. Several load balancing solutions utilize Weighted-Cost Multi-Path (WCMP), splitting incoming traffic between links proportionally to link weights. However, implementing WCMP requires the controller to update match+action rules whenever the weights must be changed, introducing a delay before the appropriate traffic split can be applied. Additionally, weighted traffic splits are applied over network flows without regard to flow characteristics or needs. We propose CrossBal, a hybrid load balancing system based on Deep Reinforcement Learning (DRL) that focuses its efforts on high-impact elephant flows. The DRL agent is modeled to be able to efficiently utilize network links while minimizing the action space, allowing the agent to quickly learn how to load balance. Further, CrossBal can quickly react to network changes by monitoring and switching active routes directly in the data plane. Our evaluation shows that CrossBal can efficiently utilize network resources, using most available links, while also reducing link utilization imbalance. We also evaluate the elephant flow detection employed by CrossBal, showing how it can quickly identify elephant flows while efficiently utilizing switch resources.
Bruno Loureiro Coelho, Alberto E. Schaeffer Filho
CNSM2
2023 Foxhound: Server-Grade Observability for Network-Augmented Applications
abstract
There is a growing move to offload functionality, e.g., TCP or key-value stores, into programmable networks - either on SmartNICs or programmable switches. While offloading promises significant performance boosts, these programmable devices often provide little visibility into their performance. Moreover, many existing tools for analyzing and debugging performance problems, e.g., distributed tracing, do not extend into these devices.
Lucas Castanheira, Alberto E. Schaeffer Filho, Theophilus Benson
EuroSys2
2023 Serene: Handling the Effects of Stragglers in In-Network Machine Learning Aggregation
abstract
Achieving high-performance aggregation is essential to scale data-parallel distributed machine learning (ML) training. Recent research efforts in the area of in-network computing have shown that offloading the aggregation to the network data plane can accelerate the aggregation process compared to traditional server-only approaches, reducing the propagation delay and consequently speeding up distributed training. However, the existing literature on in-network aggregation does not provide ways to deal with slower workers (called stragglers). The presence of stragglers can negatively impact distributed training, increasing the time it takes to complete. In this paper, we present Serene, an in-network aggregation system capable of circumventing the effects of stragglers. Serene coordinates the ML workers to cooperate with a programmable switch according to a hybrid synchronization approach. We also employ an efficient data structure for managing synchronization. We implemented and evaluated a prototype using BMv2 and realistic ML workloads, including a neural network trained for image classification. Our preliminary results show that Serene can speed up training by up to 40% in emulation scenarios.
Diego Cardoso Nunes, Bruno Loureiro Coelho, Ricardo Parizotto, Alberto E. Schaeffer Filho
NOMS4
2023 Modular VNF Components Acceleration With FPGA Overlays
abstract
Network Functions Virtualization (NFV) is a novel paradigm that aims to minimize operational and capital expenditures, by decoupling network functions from dedicated hardware and implementing them as Virtualized Network Functions (VNFs) instead. However, to fulfill such expectations, VNFs must be implemented efficiently, offering high performance and energy efficiency, which is not always feasible on General-Purpose Processors (GPPs). Thus, the use of reconfigurable accelerators, typically based on Field-Programmable Gate Arrays (FPGAs), has been proposed to offer higher efficiency whilst not forsaking the flexibility that is the core of the NFV paradigm. Not all VNFs or even VNF Components (VNFCs), however, are suitable for FPGA acceleration. This leads to new challenges related to identifying those VNFCs that should be deployed in FPGAs, maximizing the reuse of developed FPGA accelerators, and managing this heterogeneous infrastructure. To address these challenges, in this paper we present an enhanced design of VNFAccel, a platform to manage VNFCs in heterogeneous NFV infrastructures. We evaluate the performance and energy efficiency of the implemented functions in comparison to GPP-based solutions, showing that, when properly used, FPGAs can provide relevant benefits while maintaining the flexibility and reuse potential envisioned for NFV.
Filipe Bachini Lopes, Alberto E. Schaeffer Filho, Gabriel L. Nazar
IEEE Trans. Netw. Serv. Manag.2
2022 HashCuckoo: Predicting Elephant Flows using Meta-Heuristics in Programmable Data Planes
abstract
Software-Defined Networking and programmable networks have lead to the development of novel solutions to identify and even predict critical network flows (i.e., flows that can more heavily impact network resources), so they can be properly handled. However, existing approaches found in the state-of-the-art typically incur delays because of the switch-controller communication or depend on thresholds being exceeded to identify flows of interest (e.g., elephant flows). In this paper, we present HashCuckoo, an approach to predict elephant flows that includes: (i) a hash-based mechanism to start the prediction process at line rate in P4 switches, based on the Cuckoo Search meta-heuristic; and (ii) a local prediction mechanism to infer the new flows' traffic behavior, confirming the classification, and handling elephant flows on-line before exceeding traditionally considered thresholds. We evaluate the trade-offs between HashCuckoo and state-of-the-art solutions, and show that HashCuckoo reduces elephant flow identification delay by 57%, from 102 ms to 43 ms, being the first solution to combine meta-heuristic optimization and prediction that can operate at line rate in programmable data planes.
Marcus Vinicius Brito da Silva, Alberto E. Schaeffer Filho, Lisandro Z. Granville
GLOBECOM2
2022 Look-Ahead Reinforcement Learning for Load Balancing Network Traffic
abstract
Given the growth in complexity and scale of computer networks and considering that the leading cause of failures is human error, there is an increasing interest in minimizing the role of humans in network management. In this context, we propose a two-step, machine learning approach for automatically balancing network flows. Firstly, we rely on identifying flows that can more heavily impact the network, i.e., elephant flows. Sec-ondly, we use reinforcement learning to determine the best action to be performed in the network, given its state. The intuition for this two-step approach is to amortize the computational costs of reinforcement learning and apply it only to flows that can cause a high impact on network performance. Our main contributions are (i) problem modeling as a function of states and actions to balance network traffic and (ii) an architecture that more judiciously uses reinforcement learning on flows of interest for load balancing.
Isadora P. Possebon, Bruno C. da Silva 0001, Alberto E. Schaeffer Filho
ISCC3
2022 NetWords: Enabling the Understanding of Network Property Violation Occurrences
abstract
A clear trend within the context of computer networks is the use of software as an alternative to specialized hardware. The benefit of this trend include an enhancement of flexibility, modularity, and maintainability of network components. Simultaneously, it is challenging to determine if everything is happening correctly in a computer network where software, possibly with bugs, is very present. Research in this field frequently tries to improve network testing with the use of formal verification techniques or network monitoring to detect property violations, such as configuration errors or policy conflicts. However, formal verification by itself cannot detect a property violation that was not anticipated and included in the model. Similarly, network monitoring needs to wait for a property violation to occur to detect it. Consequently, both enhancement efforts fail to achieve a complete result. In this paper, we investigate the problem of guaranteeing the absence of network connectivity property violations by combining the advantages of network monitoring for detecting property violations with the advantages of formal verification to model the network. A highlight related to the success of such a combination is the use of a model based on grammars to capture the communication patterns existing on the network. Our preliminary analysis allows the evaluation of high-level properties such as "Can network component x send HTTP packets?" and the detection of property violations, such as conflicting forwarding rules, as soon they occur in the network.
Anderson Santos da Silva, Alberto E. Schaeffer Filho
NOMS2
2022 A deterministic approach for extracting network security intents
abstract
Intents brought significant improvements in network management by the use of intent-level languages. Despite these improvements, intents are not yet fully integrated and deployed in most large-scale networks. As a result, network operators may still experience problems when deploying new intents, for instance, learning a vendor-specific language to understand previously deployed configurations of a network device. Additionally, traditional configurations are distributed across multiple devices, each configured using low-level, vendor-specific languages. As a result, inferring intents from these low-level configurations is a time-consuming process. Furthermore, current solutions for deriving high-level representations from bottom-up configuration analysis do not provide results as intents or have a very limited scope, missing essential details that enhance the representation. In the solution to these shortcomings, a deterministic bottom-up approach was developed to extract intents from network configuration files, which translates them into a high-level intent-defined language. By parsing security configurations from various network devices and translating them into an extended version of the Nile (Jacobs et al. 2018) language, an intent-defined language, the prototype demonstrates the concept of this approach. While three case studies illustrate the effectiveness of the approach proposed in real-world scenarios, additional evaluations exploit dumps of real-world firewall and Network Address Translator (NAT) configurations consisting of rules from different servers and institutions. These evaluations demonstrate that the proposed solution can represent configurations at an intent-level language, maintaining high accuracy while representing key details of low-level configurations.
Rafael Hengen Ribeiro, Arthur Selle Jacobs, Luciano Zembruzki, Ricardo Parizotto, Eder J. Scheid, Alberto E. Schaeffer Filho, Lisandro Z. Granville, Burkhard Stiller
Comput. Networks6
2021 Mobility and Community Detection Based on Topics of Interest
abstract
Human mobility datasets have been used to characterize mobility and social aspects. These datasets range from cellular operator logs to tracking apps in scenarios such as university campuses, vehicles, and conferences. In this paper, we present and characterize the mobility dataset of participants of an academic conference, gathered through a gamification system. To achieve this goal, we mapped the social network formed by attendees in each technical session of the conference into a temporal graph. Furthermore, we discuss a community detection scheme based on topics of interest and analyze the performance of device-to-device (D2D) opportunistic forwarding algorithms. Results show that, although each participant has a high number of contacts, contact time is low.
Iran Ribeiro, Lucas Castanheira, Alberto E. Schaeffer Filho, Weverton Luis da Costa Cordeiro, Vinícius F. S. Mota
CCNC3
2021 BUNGEE: An Adaptive Pushback Mechanism for DDoS Detection and Mitigation in P4 Data Planes
Libardo Andrey Quintero González, Lucas Castanheira, Jonatas Adilson Marques, Alberto E. Schaeffer Filho, Luciano Paschoal Gaspary
IM4
2021 VNFAccel: An FPGA-based Platform for Modular VNF Components Acceleration
Filipe Bachini Lopes, Gabriel L. Nazar, Alberto E. Schaeffer Filho
IM3
2021 NFV Resource Allocation: a Systematic Review and Taxonomy of VNF Forwarding Graph Embedding
Frederico Schardong, Ingrid Nunes, Alberto E. Schaeffer Filho
Comput. Networks3
2020 A Bottom-Up Approach for Extracting Network Intents
Rafael Hengen Ribeiro, Arthur Selle Jacobs, Ricardo Parizotto, Luciano Zembruzki, Alberto E. Schaeffer Filho, Lisandro Z. Granville
AINA5
2020 An Empirical Study of Tightest Network Calculus Analyses for Networks with Multicast Flows
Bruno Cattelan, Steffen Bondorf, Alberto E. Schaeffer Filho
COMPSAC3
2020 ShadowFS: Speeding-up Data Plane Monitoring and Telemetry using P4
abstract
Programmable Data Planes (PDPs) provide software abstractions for network operators to dynamically modify the data plane behavior. This behavior can be described in specification languages, such as P4, and deployed into programmable switches our routers. The degree of innovation enabled by PDPs allowed network operators to create new protocols and applications. Despite the high degree of innovation brought to data plane packet processing, this programmability may have a negative effect on the forwarding delay and update times of flow tables. Previous works have attempted to overcome these limitations, e.g., through caching mechanisms, however they do not provide efficient replacement primitives and incur large overhead for monitored traffic. In this paper we present the design and evaluation of ShadowFS, a system to speed-up monitoring and telemetry on the data plane. ShadowFS manages the replacement of table entries using smaller caches without requiring the programmer to specify the behavior of these tables or how to steer traffic through them. Different from previous work, ShadowFS builds a new data plane program that monitors flows and replaces rules between tables automatically. Evaluation results demonstrate that ShadowFS can increase the throughput of frequently monitored flows.
Ricardo Parizotto, Lucas Castanheira, Rafael Hengen Ribeiro, Luciano Zembruzki, Arthur Selle Jacobs, Lisandro Z. Granville, Alberto E. Schaeffer Filho
ICC7
2020 PRIME: Programming In-Network Modular Extensions
abstract
Programmable Data Planes (PDP) enable more flexibility for the operation of networks. The various benefits of programmability have led the community to develop new software on both academic and industrial capacities. To fully reap the benefits of programmability, it should be feasible to compose and operate multiple PDP programs into a single target switch as needed. However, existing techniques are not suitable in the sense that they: (1) use an excessive number of parser states and tables; and (2) lack abstractions for the steering of packets through the control flows of programs. As such, they do not support modular composition of PDP programs. This paper proposes a composition mechanism that also addresses the fundamental needs of packet steering between PDP program modules. PRIME (Programming In-Network Modular Extensions) enables network operators to specify compositions of P4 programs and how traffic traverses these programs. The composition employs a verification phase to identify ambiguities between applications and avoid loops inside the switch pipeline. An additional table and a control plane management framework enforce the steering of packets through control flows. We present a prototype of PRIME, along with a proof of the steering correctness. The prototype shows that it is possible to achieve module-wide compositions at little additional cost in terms of delay and throughput.
Ricardo Parizotto, Lucas Castanheira, Fernanda Bonetti, Anderson Santos da Silva, Alberto E. Schaeffer Filho
NOMS5
2019 An NSH-Enabled Architecture for Virtualized Network Function Platforms
Vinicius Fulber-Garcia, Leonardo da Cruz Marcuzzo, Giovanni Venâncio de Souza, Lucas Bondan, Jéferson Campos Nobre, Alberto E. Schaeffer Filho, Carlos Raniery Paula dos Santos, Lisandro Z. Granville, Elias P. Duarte Jr.
AINA6
2019 On the Design of a Flexible Architecture for Virtualized Network Function Platforms
abstract
The proper execution and management of heterogeneous Virtualized Network Functions (VNFs) relies on the employment of efficient and comprehensive VNF platforms. However, current systems are developed without following any standardized reference architecture, thus leading to proprietary and monolithic solutions. Furthermore, those platforms lack support for recent NFV developements, such as VNF Components (VNFC) and the Network Service Header (NSH). In this work, we present an architecture for VNF platforms that is fully compliant with the European Telecommunications Standards Institute (ETSI) NFV architecture, while also enabling the execution of both VNFC and NSH. Through the development of a system prototype called COmprehensive VirtualizEd NF (COVEN) platform, we were able to evaluate the effectiveness of our proposed architecture and to demonstrate the benefits of supporting VNFC and NSH, such as flexibility and efficiency.
Vinicius Fulber-Garcia, Leonardo da Cruz Marcuzzo, Alexandre Huff, Lucas Bondan, Jéferson Campos Nobre, Alberto E. Schaeffer Filho, Carlos Raniery Paula dos Santos, Lisandro Z. Granville, Elias P. Duarte Jr.
GLOBECOM6
2019 FlowStalker: Comprehensive Traffic Flow Monitoring on the Data Plane using P4
abstract
Programmability has been extensively investigated to enable a more flexible operation of computer networks, and in this context the P4 language was designed entirely for programming the data plane. With programmable data planes comes the possibility of revisiting many inefficient approaches to networking problems, for example how we use the data plane to create an understanding of the network state. Traditional switches expose only a bare minimum of what happens in their forwarding plane, forcing us to resort to inefficient methods, such as snapshotting, to acquire the state of the network. We advocate that by combining the programmable hardware on switches with every switch specific view over its traffic, we are able to accomplish the same tasks in a more efficient and comprehensive manner. In this paper we present an efficient monitoring mechanism using programmable data planes. Our mechanism capitalizes on data plane programmability to perform tasks that are usually performed solely by the control plane (e.g. traffic monitoring and information gathering). Firstly, we present a monitoring system based on a two-phase monitoring scheme that runs directly on the data plane. Secondly, we introduce a flexible method for network data gathering, enabling “control-plane-free” consolidation of data from switches. Finally, we show techniques for using both the monitor and the gathering system to create constant, snapshot-free analysis of network traffic.
Lucas Castanheira, Ricardo Parizotto, Alberto E. Schaeffer Filho
ICC3
2019 Safeguarding from abuse by IoT vendors: Edge messages verification of cloud-assisted equipment
Vitor A. Cunha, Eduardo da Silva, Marcio Barbosa de Carvalho, Daniel Corujo, João Paulo Barraca, Diogo Gomes 0001, Alberto E. Schaeffer Filho, Carlos Raniery Paula dos Santos, Lisandro Z. Granville, Rui L. Aguiar
IM7
2019 Adaptive Multipath Routing based on Hybrid Data and Control Plane Operation
abstract
Control plane programmability, primarily enabled by SDN/OpenFlow, has brought new impetus to already consolidated management and planning practices in the area of computer networks. However, applications that require high responsiveness and demand more dynamic mechanisms executing beyond the control plane can only be effectively exploited through interactions with the data plane, where decisions and reactive responses can be made at line rate. P4 achieves this goal by providing directives that allow a certain level of control over the hardware that performs packet forwarding tasks, bringing programmability to the data plane. In this paper, we present a multipath routing strategy that takes full advantage of a hybrid SDN/OpenFlow and P4 architecture. In the data plane, P4 and the Flowlet abstraction are used to actively perform load balancing and routing over multiple asymmetric paths, in addition to monitor active links. In the logically centralized control plane, the overall view of the network is leveraged to perform more elaborate passive tasks, which include mapping paths, configuring devices and updating routes asynchronously. Experimental evaluations are conducted in which we analyze different strategies for choosing the routes that provide the best results based on RTT values received from the switches.
Marcelo Pizzutti, Alberto E. Schaeffer Filho
INFOCOM2
2019 A Network Service for Preventing Data Leakage from IoT Cloud-assisted Equipment
abstract
The fact that most IoT solutions are provided by third parties, along with the pervasiveness of the collected data, raises privacy and security concerns. There is a need to verify which data is being sent to the third party, as well as preventing those channels from becoming an exploitation avenue. We propose to use existing API definition languages to create contracts which define the data that can be transmitted, their format and constraints. To verify the compliance with these contracts, we propose a Network Service architecture which validates REST-like API requests/responses against a Swagger schema. We deal with encrypted traffic using an Service Function Chaining (SFC)-enabled Man-in-the-Middle (MITM), allowing verifications in “real-time.” We devised a Proof of Concept and showed that we were able to detect (and stop) contract violations.
Vitor A. Cunha, Rui L. Aguiar, Eduardo da Silva, Marcio Barbosa de Carvalho, Daniel Corujo, João Paulo Barraca, Diogo Gomes 0001, Alberto E. Schaeffer Filho, Carlos Raniery Paula dos Santos, Lisandro Z. Granville
ISCC8
2019 Improved Network Traffic Classification Using Ensemble Learning
abstract
Despite the large number of research efforts that applied specific machine learning algorithms for network traffic classification, recent work has highlighted limitations and particularities of individual algorithms that make them more suitable to specific types of traffic and scenarios. As such, an important topic in this area is how to combine individual algorithms using meta-learning techniques in order to obtain more robust traffic classification metrics. This paper presents a comparative analysis among meta-learning approaches and individual classifiers to classify network traffic. We investigate and evaluate a range of meta-learning techniques, including Voting, Stacking, Bagging and Boosting. We then propose a new experimental analysis of different meta-learning techniques - also known as ensemble learners- and compare them with their own base classifiers when used individually. Finally, considering the emerging popularity of Neural Networks, we analyze this scenario using the Multi-layer Perceptron classifier. The experiments were performed with data provided by the UCI Machine Learning Repository. The best performance was obtained by an ensemble technique (Bagging), which obtained accuracy of 99.972% and false positive rate of 0.00018%.
Isadora P. Possebon, Anderson Santos da Silva, Lisandro Z. Granville, Alberto E. Schaeffer Filho, Angelos K. Marnerides
ISCC4
2019 ARMOR: An Architecture for Diagnosis and Remediation of Network Misconfigurations
abstract
SDN and NFV propose the use of software-based solutions to perform functions that historically have been implemented by physical devices. The use of software-based solutions can introduce misconfiguration in critical network services, such as routing inconsistencies. This paper proposes and evaluates ARMOR, an architecture for handling network misconfigurations when different types of software-based components are inserted or removed from the network. ARMOR is capable of monitoring software-based solutions using network information gathering mechanisms, such as SNMP, SFlow and REST API. Additionally, it is capable of identifying and addressing configuration issues using historical remediation schemes and machine learning techniques. As a result, the ARMOR architecture is a flexible mechanism to monitor and remediate network misconfigurations.
Anderson Santos da Silva, Alberto E. Schaeffer Filho
ISCC2
2019 Guiltiness: A practical approach for quantifying virtual network functions performance
Ricardo J. Pfitscher, Arthur Selle Jacobs, Luciano Zembruzki, Ricardo Luis dos Santos, Eder J. Scheid, Muriel Figueredo Franco, Alberto E. Schaeffer Filho, Lisandro Z. Granville
Comput. Networks7
2019 Self-Organization and Resilience for Networked Systems: Design Principles and Open Research Issues
abstract
Networked systems form the backbone of modern society, underpinning critical infrastructures such as electricity, water, transport and commerce, and other essential services (e.g., information, entertainment, and social networks). It is almost inconceivable to contemplate a future without even more dependence on them. Indeed, any unavailability of such critical systems is - even for short periods - a rather bleak prospect. However, due to their increasing size and complexity, they also require some means of autonomic formation and self-organization. This paper identifies the design principles and open research issues in the twin fields of self-organization and resilience for networked systems. In combination, they offer the prospect of combating threats and allowing essential services that run on networked systems to continue operating satisfactorily. This will be achieved, on the one hand, through the (self-)adaptation of networked systems and, on the other hand, through structural and operational resilience techniques to ensure that they can detect, defend against, and ultimately withstand challenges.
Simon A. Dobson, David Hutchison 0001, Andreas Mauthe, Alberto E. Schaeffer Filho, Paul Smith 0001, James P. G. Sterbenz
Proc. IEEE4
2018 NIEP: NFV Infrastructure Emulation Platform
abstract
Network Functions Virtualization (NFV) presents several advantages over traditional network architectures, such as flexibility, security, and reduced CAPEX/OPEX. However, virtualizing network functions usually executed on specialized hardware (e.g., firewall, DPI, load balancer) and employing innovative technologies (e.g., OpenFlow, P4) increases the challenges of designing, testing, and deploying network infrastructures and services. Although platforms for prototyping NFV environments have emerged in recent years, they still present limitations that hinder the evaluation of specific NFV scenarios, such as fog computing and heterogeneous networks. In this paper, we present NIEP: a platform for designing and testing NFV-based infrastructures and Virtualized Network Functions (VNFs) through the integration of a well-known network emulator (Mininet) and a novel platform for Click-based VNFs development (Click-on- OSv). NIEP provides a complete NFV emulation environment, allowing network operators to test their solutions in a controlled scenario prior to deployment in production networks. As main advantages, NIEP allows the emulation of heterogeneous scenarios, which can be easily migrated to production environments. An experimental scenario is defined to analyze NIEP's performance in terms of VNFs boot time and throughput. Further, NIEP's advantages and shortcomings are discussed and compared to existing emulation platforms.
Thales Nicolai Tavares, Leonardo da Cruz Marcuzzo, Vinicius Fulber-Garcia, Giovanni Venâncio de Souza, Muriel Figueredo Franco, Lucas Bondan, Filip De Turck, Lisandro Z. Granville, Elias P. Duarte Jr., Carlos Raniery Paula dos Santos, Alberto E. Schaeffer Filho
AINA11
2018 Verification of P4 programs in feasible time using assertions
abstract
Recent trends in software-defined networking have extended network programmability to the data plane. Unfortunately, the chance of introducing bugs increases significantly. Verification can help prevent bugs by assuring that the program does not violate its requirements. Although research on the verification of P4 programs is very active, we still need tools to make easier for programmers to express properties and to rapidly verify complex invariants. In this paper, we leverage assertions and symbolic execution to propose a more general P4 verification approach. Developers annotate P4 programs with assertions expressing general network correctness properties; the result is transformed into C models and all possible paths symbolically executed. We implement a prototype, and use it to show the feasibility of the verification approach. Because symbolic execution does not scale well, we investigate a set of techniques to speed up the process for the specific case of P4 programs. We use the prototype implemented to show the gains provided by three speed up techniques (use of constraints, program slicing, parallelization), and experiment with different compiler optimization choices. We show our tool can uncover a broad range of bugs, and can do it in less than a minute considering various P4 applications.
Miguel C. Neves, Lucas Freire, Alberto E. Schaeffer Filho, Marinho P. Barcellos
CoNEXT3
2018 An Efficient Multipath Mechanism Based on the Flowlet Abstraction and P4
abstract
The use of network infrastructure resources in an efficient manner is a necessity that requires the employment of a range of sophisticated techniques. Multipath is already designed as good practice to achieve load balancing and some level of resiliency. However, in order to achieve high efficiency, strategies need great responsiveness to network events. In this paper we present an approach that relies on the Flowlet abstraction to manage the division and monitoring of network flows. Through a simple idea, we add a function that dynamically monitors and acts in the data plane to find the minimum possible interval that allows the alternation of a flow between routes without causing adverse effects. We performed the evaluation using P4 as an engine that acts on the data plane.
Marcelo Pizzutti, Alberto E. Schaeffer Filho
GLOBECOM2
2018 An SFC-enabled approach for processing SSL/TLS encrypted traffic in Future Enterprise Networks
abstract
In this paper, we propose an architecture based on NFV and SDN which allows to balance traffic analysis techniques using a Classifier. It steers flows to the appropriate Service Function Chaining (to open traffic or not) according to network requirements (such as, effectiveness, flexibility, scalability, performance, and privacy). The SSL/TLS traffic processing is carried-out by the centerpiece of this work, the SFC-enabled MITM. A Proof-of-Concept was conducted (focusing on our SFC-enabled MITM) which showed that functionalities lost due to encryption (Content Optimization, Caching, Network Anti-virus, and Content Filter) were recovered when processing opened traffic within its Service Function Chains. We also evaluated its impact on performance. The results show that cipher suite overhead plays a role but can be mitigated, the Classifier can alleviate the performance overhead of different traffic analysis techniques, network functions have lower impact to performance, and Service Function Chaining length influences page load time.
Vitor A. Cunha, Marcio Barbosa de Carvalho, Daniel Corujo, João Paulo Barraca, Diogo Gomes 0001, Alberto E. Schaeffer Filho, Carlos Raniery Paula dos Santos, Lisandro Z. Granville, Rui L. Aguiar
ISCC6
2018 Using NFV and Reinforcement Learning for Anomalies Detection and Mitigation in SDN
abstract
Computer networks are subject to several anomalies, which leads to the necessity of techniques to coordinate detection and mitigation to keep the network operational. In this paper we propose the use of reinforcement learning to promote resilience in Software Defined Networking (SDN). In particular, it is proposed collecting network metrics and grouping them into profiles, each one having a set of actions that handles problems using reinforcement learning, Network Functions Virtualization (NFV), and an SDN controller. Policies for dealing with anomalies are defined based on rewards for each action. Results show that the system obtains mostly positive rewards, but a small increment in the topology size leads to more than four times the number of entries in the state-action table.
Lauren S. R. Sampaio, Pedro Faustini, Anderson Santos da Silva, Lisandro Z. Granville, Alberto E. Schaeffer Filho
ISCC5
2018 A model for quantifying performance degradation in virtual network function service chains
abstract
Virtual Network Functions (VNFs) can be chained and provisioned on demand, providing elasticity and dynamicity to the network. Due to the interdependencies between VNFs, resulting service chains may not work as expected, and because of that, it is crucial to determine which VNFs are having a negative impact on the service quality. In this paper, we introduce a model to quantify the guiltiness of a VNF on being a bottleneck in a service chain, which provides a metric that estimates the impact on processing delay. In addition, we propose an adaptive algorithm, based on linear regression and neural networks, to adjust the model parameters according to the environment particularities, such as the type and number of VNFs. We show through an experimental evaluation that the guiltiness metric faithfully characterizes end-service performance, by identifying up to 94% of the bottleneck VNFs in the analyzed scenarios. Also, we provide artifacts for researchers to reproduce our results in other scenarios.
Ricardo J. Pfitscher, Arthur Selle Jacobs, Eder J. Scheid, Muriel Figueredo Franco, Ricardo Luis dos Santos, Alberto E. Schaeffer Filho, Lisandro Z. Granville
NOMS6
2018 Providing cognitive components with a bidding heuristic for emergent NFV orchestration
abstract
Network function virtualisation (NFV) decouples network functions from the underlying hardware by means of virtualisation, thus enabling the replacement of proprietary middleboxes by software components that can be dynamically deployed and configured on demand. The selection of the most appropriate virtual network functions (VNFs) to achieve a particular objective, and the decision on where to deploy these VNFs and through which paths they will communicate, are the responsibilities of an NFV orchestrator. In this paper, we propose to orchestrate VNFs using interacting cognitive components structured with the BDI architecture, leading to emergent solutions to address network challenges. More specifically, we extend a previously proposed reverse auction protocol and propose a novel bidding heuristic that can be used to make decisions regarding the orchestration tasks. We validate our model in a DDoS attack case study, in which we demonstrate that our components can successfully mitigate the attack.
Frederico Schardong, Ingrid Nunes, Alberto E. Schaeffer Filho
NOMS3
2017 POSTER: Finding Vulnerabilities in P4 Programs with Assertion-based Verification
abstract
Current trends in SDN extend network programmability to the data plane through the use of programming languages such as P4. In this context, the chance of introducing errors and consequently software vulnerabilities in the network increases significantly. Existing data plane verification mechanisms are unable to model P4 programs or present severe restrictions in the set of modeled properties. To overcome these limitations and make programmable data planes more secure, we present a P4 program verification technique based on assertion checking and symbolic execution. First, P4 programs are annotated with assertions expressing general correctness and security properties. Then, the annotated programs are transformed into C code and all their possible paths are symbolically executed. Results show that it is possible to prove properties in just a few seconds using the proposed technique. Moreover, we were able to uncover two potential vulnerabilities in a large scale P4 production application.
Lucas Freire, Miguel C. Neves, Alberto E. Schaeffer Filho, Marinho P. Barcellos
CCS3
2017 Click-on-OSv: A platform for running Click-based middleboxes
abstract
In this paper, we present a modern platform for running Virtualized Network Functions based on the Click Modular Router. The proposed platform leverages of current technologies - such as DPDK, OSv, and REST Web Services - to fulfill the ETSI requirements for Network Functions Virtualization. The obtained results show the feasibility of the platform to consolidate disparate network functions, while demonstrating flexibility from a management point-of-view.
Leonardo da Cruz Marcuzzo, Vinicius Fulber-Garcia, Vitor A. Cunha, Daniel Corujo, João Paulo Barraca, Rui L. Aguiar, Alberto E. Schaeffer Filho, Lisandro Z. Granville, Carlos Raniery Paula dos Santos
IM7
2017 A distributed NFV orchestrator based on BDI reasoning
abstract
Network function virtualisation (NFV) decouples network functions from physical devices, simplifying the deployment of new services. As opposed to traditional middleboxes, VNFs can be dynamically deployed and reconfigured on demand, posing strict management challenges to networked systems. Selecting VNFs from a repository, defining where they will be placed in the virtualised network as well as chaining them to achieve the desired behaviour are problems that have to be tackled by an orchestrator. In this paper, we propose a distributed approach to NFV orchestration using belief-desire-intention (BDI) reasoning, addressing the selection, placement and chaining problems through the interaction among autonomous software agents, which collectively work in a distributed and decentralised manner. Agents are capable of bidding on the allocation of resources for new VNFs, as well as managing the chaining of VNFs. Further, we validate our theoretical model through a DDoS attack case study, in which we analyse the emergent behaviour of the autonomous agents.
Frederico Schardong, Ingrid Nunes, Alberto E. Schaeffer Filho
IM3
2017 INSpIRE: Integrated NFV-based Intent Refinement Environment
abstract
Many aspects of the management of computer networks, such as quality of service and security, must be taken into consideration to ensure that the network meets the users and clients demands. Fortunately, management solutions were developed to address these aspects, such as Intent-Based Networking (IBN). IBN is a novel networking paradigm that abstracts network configurations by allowing administrators to specify how the network should behave and not what it should do. In this paper, we introduce an IBN solution called INSpIRE (Integrated NFV-based Intent Refinement Environment). INSpIRE implements a refinement technique to translate intents into a set of configurations to perform a desired service chain in both homogeneous environments (VNFs only) and heterogeneous environments (VNFs and physical middleboxes). Our solution is capable of (i) determining the specific VNFs required to fulfill an intent, (ii) chaining these VNFs according to their dependencies, and (iii) presenting enough low-level information to network devices for posterior traffic steering. Finally, to assess the feasibility of our solution we detail a case study that reflects real-world management situations and evaluate the scalability of the refinement process.
Eder J. Scheid, Cristian Cleder Machado, Muriel Figueredo Franco, Ricardo Luis dos Santos, Ricardo J. Pfitscher, Alberto E. Schaeffer Filho, Lisandro Z. Granville
IM6
2017 ARKHAM: An Advanced Refinement toolkit for Handling Service Level Agreements in Software-Defined Networking
Cristian Cleder Machado, Juliano Araújo Wickboldt, Lisandro Z. Granville, Alberto E. Schaeffer Filho
J. Netw. Comput. Appl.4
2017 BDI2DoS: An application using collaborating BDI agents to combat DDoS attacks
Ingrid Nunes, Frederico Schardong, Alberto E. Schaeffer Filho
J. Netw. Comput. Appl.3
2016 VISION - Interactive and Selective Visualization for Management of NFV-Enabled Networks
abstract
Network Functions Virtualization (NFV) enhances the flexibility of network service provisioning and reduces the time to services deployment. NFV and SDN promises transform the carrier networks, introducing innovation in the network core. NFV moves packet processing from dedicated hardware middleboxes to Virtualized Network Functions (VNFs), which run on virtual machines hosted on commercial off-the-shelf servers. However, in NFV-enabled networks, the amount of data managed grows in a fast way. Based on this, the network operator must understand and manipulate a lot of information to effectively manage the network. In this paper, we introduce the VISION, a platform to help the network operator to determine the cause of problems based on visualizations techniques. Our platform implements a set of interactive and selective visualizations to assist in the NFV management. Finally, we conducted three cases studies to provide evidences of the feasibility of our platform.
Muriel Figueredo Franco, Ricardo Luis dos Santos, Alberto E. Schaeffer Filho, Lisandro Z. Granville
AINA3
2016 Performance Analysis of 6LoWPAN and CoAP for Secure Communications in Smart Homes
abstract
Smart grids and smart homes improve energy management by coupling communication capabilities to their devices. Due to computational constraints of these devices, employment of simplified communication protocols is necessary. In this paper, we investigate the use of communication protocols based on CoAP and 6LoWPAN in smart home environments. Specifically, we analyze the vulnerabilities a smart home employing CoAP and 6LoWPAN may be susceptible to. We also present a performance analysis of the use of these protocols for ensuring secure communicationsin smart homes.
Rafael de Jesus Martins, Vinicius Garcez Schaurich, Luis Augusto Dias Knob, Juliano Araújo Wickboldt, Alberto E. Schaeffer Filho, Lisandro Z. Granville, Marcelo Pias
AINA5
2016 A One-Class NIDS for SDN-Based SCADA Systems
abstract
Power systems are undergoing an intense process of modernization, and becoming highly dependent on networked systems used to monitor and manage system components. These so-called Smart Grids comprise energy generation, transmission, and distribution subsystems, which are monitored and managed by Supervisory Control and Data Acquisition (SCADA) systems. In this paper, we discuss the benefits of using Software-Defined Networking (SDN) to assist in the deployment of next generation SCADA systems. We also present a specific Network-Based Intrusion Detection System (NIDS) for SDN-based SCADA systems, which uses SDN to capture network information and is responsible for monitoring the communication between power grid components. Our approach relies on SDN to periodically gather statistics from network devices, which are then processed by One-Class Classification (OCC) algorithms. Given that attack traces in SCADA networks are scarce and not publicly disclosed by utility companies, the main advantage of using OCC algorithms is that they do not depend on known attack signatures to detect possible malicious traffic. Our results indicate that OCC algorithms achieve an approximate accuracy of 98% and can be effectively used to detect cyber-attacks targeted against SCADA systems.
Eduardo Germano da Silva, Anderson Santos da Silva, Juliano Araújo Wickboldt, Paul Smith 0001, Lisandro Z. Granville, Alberto E. Schaeffer Filho
COMPSAC6
2016 ANSwer: Combining NFV and SDN features for network resilience strategies
abstract
Software-Defined Networking (SDN) relies on open programmability of network devices, which is achieved by defining new communication interfaces, network operating systems, and changing the traditional decision-making logic of regular TCP/IP networks. Network Functions Virtualization (NFV), in turn, permits virtualizing network functions that are traditionally performed by physical middleboxes (e.g., firewalling and intrusion detection/prevention). Although SDN and NFV improve the flexibility of the management of computer networks, SDN remains vulnerable to major network security problems, such as Distributed Denial of Service (DDoS) attacks. These attacks typically result in the disruption of network services and resources. In this paper, we introduce ANSwer, an architecture that combines NFV and SDN features to create sophisticated network resilience strategies. ANSwer relies on a feedback control-loop which explores SDN features to monitor and analyze the behavior of the network infrastructure, indicating whether parts of an existing resilience strategy can be reconfigured to achieve more satisfactory results, or if an entire resilience strategy needs to be added or replaced. Our experiments demonstrate that ANSwer can rapidly identify and handle distinct anomalies in different scenarios, indicating that the reconfiguration and deployment of resilience strategies can be performed in real-time.
Cristian Cleder Machado, Lisandro Z. Granville, Alberto E. Schaeffer Filho
ISCC3
2016 DReAM - a distributed result-aware monitor for Network Functions Virtualization
abstract
Network Functions Virtualization (NFV) is a key technology to reduce management costs as well as to improve scalability and elasticity of computer networks. Still, recent research efforts have been exposing additional management challenges. Concerning monitoring in particular, new types of entities and requirements are underexploited. To address these issues, we propose DReAM, a resource management architecture based on management by delegation and distributed monitoring, where each agent runs a diagnostic model to compute the network service state. In this paper, we describe DReAM's proposed architecture and its major components. We also discuss the feasibility of DReAM through experimental and analytical evaluations, where we observed application throughput, CPU utilization, communication overhead, scalability, and diagnosis complexity. We provide a trade-off analysis on the monitoring strategies in NFV scenarios. Our results indicate that a result-aware strategy is a better option when the monitored environment has more than 256 agents or when the diagnosis module induces at least 10% of CPU utilization.
Ricardo J. Pfitscher, Eder J. Scheid, Ricardo Luis dos Santos, Rafael R. Obelheiro, Maurício Aronne Pillon, Alberto E. Schaeffer Filho, Lisandro Z. Granville
ISCC6
2016 Policy-based dynamic service chaining in Network Functions Virtualization
abstract
Network Functions Virtualization (NFV) enables the rapid development, flexible management, and the dynamic placement of new, innovative Virtualized Network Functions (VNFs), such as load balancers, firewalls, and Intrusion Detection Systems (IDSes). Furthermore, NFV along with Software-Defined Networking (SDN) allows VNFs and physical middleboxes to be dynamically composed into service chaining graphs. Despite these benefits, service chaining graphs can be further improved through the use of techniques that have not been satisfactorily explored yet, such as Policy-Based Network Management (PBNM). In PBNM, policies can be written and triggered during runtime, thus supporting the dynamic (re)configuration of service graphs with minimal disruption. In this paper, we propose an approach to automatically design NFV service chaining graphs based on policies. These policies rule the forwarding of traffic and the construction of service chaining graphs. In our approach, service chaining graphs are enforced dynamically in the network during runtime. Finally, to assess its feasibility and generality, we create two different scenarios to demonstrate and discuss how our solution can be employed and its expected results.
Eder J. Scheid, Cristian Cleder Machado, Ricardo Luis dos Santos, Alberto E. Schaeffer Filho, Lisandro Z. Granville
ISCC4
2016 ATLANTIC: A framework for anomaly traffic detection, classification, and mitigation in SDN
abstract
Anomaly traffic detection and classification mechanisms need to be flexible and easy to manage in order to detect the ever growing spectrum of anomalies. Detection and classification are difficult tasks because of several reasons, including the need to obtain an accurate and comprehensive view of the network, the ability to detect the occurrence of new attack types, and the need to deal with misclassification. In this paper, we argue that Software-Defined Networking (SDN) form propitious environments for the design and implementation of more robust and extensible anomaly classification schemes. Different than other approaches from the literature, which individually tackle either anomaly detection or classification or mitigation, we present a management framework to perform these tasks jointly. Our proposed framework is called ATLANTIC and it combines the use of information theory to calculate deviations in the entropy of flow tables and a range of machine learning algorithms to classify traffic flows. As a result, ATLANTIC is a flexible framework capable of categorizing traffic anomalies and using the information collected to handle each traffic profile in a specific manner, e.g., blocking malicious flows.
Anderson Santos da Silva, Juliano Araújo Wickboldt, Lisandro Z. Granville, Alberto E. Schaeffer Filho
NOMS4
2016 ASTORIA: A framework for attack simulation and evaluation in smart grids
abstract
Electric power grids are undergoing a modernization process. By relying on the ICT infrastructure and on Internet connectivity, these so-called Smart Grids are now able to provide new functionalities and to become more efficient. However, despite the existence of a few standards that aim to specify the secure operation of Smart Grids, utility companies do not have a comprehensive set of metrics and evaluation tools for assessing security properties in these infrastructures. Thus, it is necessary to develop new toolsets to provide support for vulnerability analysis in Smart Grids. This paper proposes ASTORIA, a framework developed to allow the simulation of attacks and the evaluation of their impact on Smart Grid infrastructures, using closely-related real devices and real topologies comprising both power grid elements as well as ICT and networking equipment. We anticipate that ASTORIA can be used by Smart Grid operators not only to analyze the impact of malicious attacks and other security threats in different components, but also to permit the development and evaluation of anomaly detection techniques in a simulation environment. Further, we present evaluation scenarios illustrating customizable Smart Grid topologies, comprising sensors, master and remote stations, and using an extensible set of attack profiles.
Alexandre Gustavo Wermann, Marcelo Cardoso Bortolozzo, Eduardo Germano da Silva, Alberto E. Schaeffer Filho, Luciano Paschoal Gaspary, Marinho P. Barcellos
NOMS4
2015 Policy authoring for software-defined networking management
abstract
Software-Defined Networking (SDN) permits centralizing part of the decision-logic in controller devices. Thus, controllers can have an overall view of the network, assisting network programmers to configure network-wide services. Despite this, the behavior of network devices and their configurations are often written for specific situations directly in the controller. As an alternative, techniques such as Policy-Based Network Management (PBNM) can be used by business-level operators to write Service Level Agreements (SLAs) in a user-friendly interface without the need to change the code implemented in the controllers. In this paper, we introduce a framework for Policy Authoring to (i) facilitate the specification of business-level goals and (ii) automate the translation of these goals into the configuration of system-level components in an SDN. We use information from the network infrastructure obtained through SDN features and logic reasoning for analyzing policy objectives. As a result, experiments demonstrate that the framework performs well even when increasing the number of expressions in an SLA or increasing the size of the repository.
Cristian Cleder Machado, Juliano Araújo Wickboldt, Lisandro Z. Granville, Alberto E. Schaeffer Filho
IM4
2015 Capitalizing on SDN-based SCADA systems: An anti-eavesdropping case-study
abstract
Power grids are responsible for the transmission and distribution of electricity to end-users. These systems are undergoing a modernization process through the use of Information and Communication Technology (ICT), transforming the electric system into Smart Grids. In this context, Supervisory Control and Data Acquisition (SCADA) systems are responsible for the management and monitoring of substations and field devices. In this paper, we investigate the use of SDN as an approach to assist in the modernization of SCADA systems. We discuss its possible benefits, such as simplified management of power system resources. Moreover, SDN can facilitate the creation of new network applications that previously, with traditional networks, were more complex to be implemented. To illustrate the benefits of the use of SDN in SCADA, we designed a mechanism that aims to prevent a possible eavesdropper from fully capturing communication flows between SCADA components. The mechanism was implemented as an SDN-based application for SCADA systems that uses multipath routing, which relies on SDN features to frequently modify communication routes between SCADA devices. Further, we performed an experimental evaluation to verify the impact and performance of the mechanism in the SCADA network.
Eduardo Germano da Silva, Luis Augusto Dias Knob, Juliano Araújo Wickboldt, Luciano Paschoal Gaspary, Lisandro Z. Granville, Alberto E. Schaeffer Filho
IM6
2015 An EC-based formalism for policy refinement in software-defined networking
abstract
Software-Defined Networking (SDN) provides a sophisticated and accurate solution for managing network traffic. SDN logically centralizes, in devices called controllers, part of the decision-making logic of flow processing and packet routing. The whole network is controlled according to rules written and deployed in the controller device. However, the large amount of network devices, links, and services also gives rise to a large number of rules to be managed in the controller. Policy-Based Network Management (PBNM) can be used to manage complex network infrastructures through policies rather than specifying device-by-device configurations. Particularly, policy refinement techniques can be used to automatically translate high-level policies into a set of low-level ones. In this paper, we define a formal representation of high-level SLA policies using Event Calculus (EC) and apply logical reasoning to model both the system behavior and the policy refinement process for SDN management. We also describe the implementation of this formal model in Prolog, which enables the automatic inference of low-level policies from high-level ones, and present evaluation results.
Cristian Cleder Machado, Juliano Araújo Wickboldt, Lisandro Z. Granville, Alberto E. Schaeffer Filho
ISCC4
2015 Change data capture in NoSQL databases: A functional and performance comparison
abstract
Requirements for data storage and processing have reached new levels, with applications relying on the analysis of large amounts of data in order to support everyday life services to end users. Since the costs of maintaining and managing databases are significant, change data capture (CDC) techniques can be used to determine which parts of a data source have changed, and thus assist in the management of large volumes of data in data warehouses. In this paper we investigate a number of CDC techniques suitable for NoSQL databases. CDC techniques can be used to track modifications in a source database, which later can be made available to a target database. Our base system and testbed are based on Apache Cassandra, which is a NoSQL database that offers high performance and scalability. Cassandra is combined with a MapReduce framework, which is used to implement the logic of each CDC technique and is suitable for highly distributed and parallel computing. This paper also presents both a functional comparison of the different CDC techniques, as well as a performance evaluation in a real testbed.
Felipe Mathias Schmidt, Cláudio Fernando Resin Geyer, Alberto E. Schaeffer Filho, Stefan Deßloch, Yong Hu 0001
ISCC3
2015 Tool support for the evaluation of anomaly traffic classification for network resilience
abstract
Resilience is the ability of the network to maintain an acceptable level of operation in the face of anomalies, such as malicious attacks, operational overload or misconfigurations. Techniques for anomaly traffic classification are often used to characterize suspicious network traffic, thus supporting anomaly detection schemes in network resilience strategies. In this paper, we extend the PReSET toolset to allow the investigation, comparison and analysis of algorithms for anomaly traffic classification based on machine learning. PReSET was designed to allow the simulation-based evaluation of resilience strategies, thus enabling the comparison of optimal configurations and policies for combating different types of attacks (e.g., DDoS attacks, worms) and other anomalies. In such resilience strategies, policies written in the Ponder2 language can be used to activate/reconfigure traffic classification modules and other mechanisms (e.g., traffic shaping), depending on monitored results in the simulation environment. Our results show that PReSET can be a valuable tool for network operators to evaluate anomaly traffic classification techniques in terms of standard performance metrics.
Anderson Santos da Silva, Juliano Araújo Wickboldt, Alberto E. Schaeffer Filho, Angelos K. Marnerides, Andreas Mauthe
ISCC3
2015 Identification and Selection of Flow Features for Accurate Traffic Classification in SDN
abstract
Software-Defined Networking (SDN) aims to alleviate the limitations imposed by traditional IP networks by decoupling network tasks performed on each device in particular planes. This approach offers several benefits, such as standard communication protocols, centralized network functions, and specific network elements, for example, controller devices. Despite these benefits, there is still a lack of adequate support for performing tasks related to traffic classification, because (i) there are traffic profiles that are very similar, which makes their classification difficult (e.g., Both HTTP and DNS flows are characterized by packet bursts), (ii) Open Flow, the key SDN implementation today, only offers native flow features, such as packet and byte count, that do not describe intrinsic traffic profiles, and (iii) there is a lack of support to determine what is the optimal set of flow features to characterize different types of traffic profiles. In this paper, we introduce an architecture to collect, extend, and select flow features for traffic classification in Open Flow-based networks. The main goal of our solution is to offer an extensive set of flow features that can be analyzed and refined and to be capable of finding the optimal subset of features to classify different types of traffic flows. The experimental evaluation of our proposal shows that some features emerge as meaningful, occupying the top positions for the classification of distinct flows in different experimental scenarios.
Anderson Santos da Silva, Cristian Cleder Machado, Rodolfo Vebber Bisol, Lisandro Z. Granville, Alberto E. Schaeffer Filho
NCA5
2015 Resilience support in software-defined networking: A survey
Anderson Santos da Silva, Paul Smith 0001, Andreas Mauthe, Alberto E. Schaeffer Filho
Comput. Networks4
2014 Towards SLA Policy Refinement for QoS Management in Software-Defined Networking
abstract
Software-Defined Networking (SDN) is a dynamic, adaptable, controllable and flexible network architecture. It provides an extensible platform for delivery of network services, capable of responding quickly to service requirement changes. As a result, SDN has become a suitable scenario for the application of techniques and approaches for improved infrastructure management, such as Policy-Based Management (PBM). In PBM, using techniques such as refinement, a high-level policy-e.g., specified as a Service Level Agreement (SLA) - can be translated into a set of corresponding low-level rules, enforceable in various elements of a system. However, when using SLAs, their translation to low-level policies, e.g., for controller configuration, is not straightforward. If this translation is not done properly, the controller may not be able to meet the implicit requirements of the SLA, failing to satisfy the goals described in the high-level policy. This paper proposes a novel approach towards SLA policy refinement for Quality of Service (QoS) management (based on routing) in Software-Defined Networking. It consists of an initial manual process performed by an administrator, followed by an automatic policy refinement process executed by an OpenFlow controller. As a result, our approach is capable of identifying the requirements and resources that need to be configured in accordance with SLA refinement, and can successfully configure and execute reactive dynamic actions for supporting dynamic infrastructure reconfiguration.
Cristian Cleder Machado, Lisandro Z. Granville, Alberto E. Schaeffer Filho, Juliano Araújo Wickboldt
AINA3
2014 Management patterns: SDN-enabled network resilience management
abstract
Software-defined networking provides abstractions and a flexible architecture for the easy configuration of network devices, based on the decoupling of the data and control planes. This separation has the potential to considerably simplify the implementation of resilience functionality (e.g., traffic classification, anomaly detection, traffic shaping) in future networks. Although software-defined networking in general, and OpenFlow as its primary realisation, provide such abstractions, support is still needed for orchestrating a collection of OpenFlow-enabled services that must cooperate to implement network-wide resilience. In this paper, we describe a resilience management framework that can be readily applied to this problem. An important part of the framework are policy-controlled management patterns that describe how to orchestrate individual resilience services, implemented as OpenFlow applications.
Paul Smith 0001, Alberto E. Schaeffer Filho, David Hutchison 0001, Andreas Mauthe
NOMS2
2014 Traffic anomaly diagnosis in Internet backbone networks: A survey
Angelos K. Marnerides, Alberto E. Schaeffer Filho, Andreas Mauthe
Comput. Networks2
2013 PReSET: A toolset for the evaluation of network resilience strategies
Alberto E. Schaeffer Filho, Andreas Mauthe, David Hutchison 0001, Paul Smith 0001, Michael Fry 0001
IM1
2013 Simulation and evaluation of network resilience with PReSET
Alberto E. Schaeffer Filho, Andreas Mauthe, David Hutchison 0001, Paul Smith 0001, Michael Fry 0001
IM1
2012 A framework for the design and evaluation of network resilience management
abstract
Network resilience strategies aim to maintain acceptable levels of network operation in the face of challenges, such as malicious attacks, operational overload or equipment failures. Often the nature of these challenges requires resilience strategies comprising mechanisms across multiple protocol layers and in disparate locations of the network. In this paper, we address the problem of resilience management and advocate that a new approach is needed for the design and evaluation of resilience strategies. To support the realisation of this approach we propose a framework that enables (1) the offline evaluation of resilience strategies to combat several types of challenges, (2) the generalisation of successful solutions into reusable patterns of mechanisms, and (3) the rapid deployment of appropriate patterns when challenges are observed at run-time. The evaluation platform permits the simulation of a range of challenge scenarios and the resilience strategies used to combat these challenges. Strategies that can successfully address a particular type of challenge can be promoted to become resilience patterns. Patterns can thus be used to rapidly deploy resilience configurations of mechanisms when similar challenges are detected in the live network.
Alberto E. Schaeffer Filho, Paul Smith 0001, Andreas Mauthe, David Hutchison 0001, Michael Fry 0001
NOMS1
2012 Efficient message-passing and autonomic management architecture for NGNs
abstract
There is a gap between the increasing complexity of computer networks and the human operators ability to manage them. This gap, likely to become bigger in the coming years, needs to be addressed by more dynamic and autonomic management techniques. The ultimate aim is to provide the network with the functionality to manage itself. This paper outlines an architecture which provides support to facilitate self-organisation in a network's management/control plane. The central element of this research is a novel message-passing framework, facilitating de-composition and dynamic composition of services. The overall design of the autonomic network management architecture is first introduced but the focus is on the communication protocols and interactions between Atomic Functional Blocks, the basic auto-nomic management elements that provide a network management service.
Andreas Louca, Andreas Mauthe, Alberto E. Schaeffer Filho
NOMS3
2012 Resilience Strategies for Networked Malware Detection and Remediation
Michael Fry 0001, Bernhard Plattner, Paul Smith 0001, Alberto E. Schaeffer Filho
NSS5
2008 AMUSE: autonomic management of ubiquitous e-Health systems
abstract
Abstract Future e‐Health systems will consist of low‐power on‐body wireless sensors attached to mobile users that interact with an ubiquitous computing environment to monitor the health and well being of patients in hospitals or at home. Patients or health practitioners have very little technical computing expertise so these systems need to be self‐configuring and self‐managing with little or no user input. More importantly, they should adapt autonomously to changes resulting from user activity, device failure, and the addition or loss of services. We propose the Self‐Managed Cell (SMC) as an architectural pattern for all such types of ubiquitous computing applications and use an e‐Health application in which on‐body sensors are used to monitor a patient living in their home as an exemplar. We describe the services comprising the SMC and discuss cross‐SMC interactions as well as the composition of SMCs into larger structures. Copyright © 2007 John Wiley & Sons, Ltd.
Emil C. Lupu, Naranker Dulay, Morris Sloman, Joseph S. Sventek, Steven Heeps, Stephen D. Strowes, Kevin P. Twidle, Sye Loong Keoh, Alberto E. Schaeffer Filho
Concurr. Comput. Pract. Exp.9
2007 Self-Managed Cell: A Middleware for Managing Body-Sensor Networks
abstract
Body sensor networks consisting of low-power on- body wireless sensors attached to mobile users will be used in the future to monitor the health and well being of patients in hospitals or at home. Such systems need to adapt autonomously to changes in context, user activity, device failure, and the availability or loss of services. To this end, we propose a policy- based architecture that uses the concept of a Self-Managed Cell (SMC) to integrate services, managed resources and a policy interpreter by means of an event bus. Policies permit the declarative specification of adaptation strategy for self- configuration and self-management. We present the design and implementation of the SMC and describe its potential use in a scenario for management of heart monitoring. Preliminary performance measurements are also presented and discussed.
Sye Loong Keoh, Naranker Dulay, Emil C. Lupu, Kevin P. Twidle, Alberto E. Schaeffer Filho, Morris Sloman, Steven Heeps, Stephen D. Strowes, Joseph S. Sventek
MobiQuitous5
2005 A Scalable Dissemination Service for the ISAM Architecture
abstract
The ISAM architecture presents a platform to the development and to the execution of pervasive applications. DIMI (Disseminador Multicast de Informacoes - information multicast disseminator) is an information dissemination service designed for the ISAM architecture. DIMI seeks mainly to obtain scalability, avoiding bottlenecks formation while accepting new consumers on a channel. Besides the search for scalability, this service outfits other necessary characteristics of the computational environment proposed by the ISAM architecture, as planned disconnection support and user mobility support.
Mauricio Moraes, Luciano Cavalheiro da Silva, Alberto E. Schaeffer Filho, Cláudio Fernando Resin Geyer, Adenauer C. Yamin, Iara Augustin
SBAC-PAD3