VLDB 2026 Research / reviewers in the wild / expert
Ramin Sadre
dblp:90/2103
· DBLP profile ↗
40ranked-venue papers
1as first author
8since 2021 · last 2026
0000-0001-7362-359XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 16 · 3 since 2021Security and privacy · 6 · 2 since 2021Systems, architecture and hardware · 5 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Scylla: Scheduling Multiple Latency-Sensitive Applications in the Edge-Cloud Continuum
Yinan Cao, Etienne Rivière, Ramin Sadre |
IWQoS | 3 |
| 2025 | LASSY: A Latency-Aware SLOs-Sufficing Scheduling System for the Cloud/Edge ContinuumabstractDespite the advancements in cloud computing, cloud-hosted applications face significant network latency challenges, particularly for users distant from data centers. Edge computing has emerged as a solution to mitigate these issues by decentralizing processing, thereby reducing latency and enhancing user experience. However, the limited resources of edge data centers require careful scheduling of application instances to preserve the benefits of edge computing. This paper presents the Latency-Aware SLO-Sufficing Scheduling System (LASSY), a novel approach that considers network and queueing latencies in scheduling decisions for cloud/edge continuum environments. LASSY utilizes queueing theory to predict the tail latency experienced by users of latency-sensitive services such as Edge AI and optimizes service deployment across cloud and edge nodes to meet Service Level Objectives (SLOs). Our contributions include detailed latency modeling, an optimization algorithm that minimizes resource costs while ensuring SLO compliance, comprehensive experiments conducted on a testbed under realistic network emulation, and comparison with a state-of-the-art scheduling model. We evaluated LASSY under real-world latency conditions using two applications: a picture thumbnailing service and an Edge AI OCR service. We demonstrate LASSY's ability to achieve the desired service quality by effectively managing latency and resource allocation. Yinan Cao, Etienne Rivière, Ramin Sadre |
CCGrid | 3 |
| 2025 | The Forest Behind the Tree: Revealing Hidden Smart Home Communication PatternsabstractThe widespread use of Smart Home devices has attracted significant research interest in understanding their behavior within home networks. Unlike general-purpose computers, these devices exhibit relatively simple and predictable network activity patterns. However, previous studies have primarily focused on normal network conditions, overlooking potential hidden patterns that emerge under challenging conditions. Discovering the latter is crucial for assessing device robustness.This paper addresses this gap by presenting a framework that systematically and automatically reveals these hidden communication patterns. By actively disturbing communication and blocking observed traffic, the framework generates comprehensive profiles structured as behavior trees, uncovering traffic flows that are missed by more shallow methods. This approach was applied to ten real-world devices, identifying 254 unique flows, with over 27% only discovered through this new method. These insights enhance our understanding of device robustness, and the thus obtained profiles provide a more complete description of the network behavior of devices, as needed, for example, for the configuration of security solutions. François De Keersmaeker, Rémi Van Boxem, Cristel Pelsser, Ramin Sadre |
ICNP | 4 |
| 2025 | PANDAS: Peer-to-peer, Adaptive Networking Allowing Data Availability Sampling within Ethereum Consensus TimeboundsabstractLayer-2 protocols such as rollups can help address Ethereum's throughput limits. An efficient data availability layer is key for layer-2 support in Ethereum, but broadcast methods do not scale. A promising approach is the selective distribution of layer-2 data and its verification by data availability sampling (DAS). Integrating DAS with Ethereum consensus is, however, a challenge, as data must be shared and sampled within 4 seconds of each consensus slot. Matthieu Pigaglio, Onur Ascigil, Michal Król, Kaleem Peeroo, Sergi Rene, Ramin Sadre, Vladimir Stankovic 0002, Etienne Rivière |
Middleware | 7 |
| 2024 | DISC-NG: Robust Service Discovery in the Ethereum Global NetworkabstractThe Ethereum Global Network (EGN) hosts a complete ecosystem of decentralized services, including blockchains such as Ethereum mainnet but also exchange markets, content delivery networks, and many more. Service discovery is a fundamental mechanism in the EGN, allowing new nodes to look up and connect to other nodes already participating in one of these services. The current service discovery of the EGN, DISCv5, is not scalable and efficient enough to support the current and future needs of the ecosystem. We present DISC-NG, a novel service discovery protocol for the EGN that is scalable, efficient, and secure. DISC-NG leverages the EGN-wide DHT to allow service participation advertisements to meet service discovery requests. DISC-NG compensates the unbalance in service popularity and minimizes the potential for abuse by malicious nodes. We implement DISC-NG in devp2p, the network stack used by the majority of clients connecting to the EGN, as well as in a large-scale simulator. DISC-NG can discover services in the EGN faster than DISCv5 while being more robust to malicious nodes. DISC-NG is now in a staging phase and scheduled for deployment as an improvement to DISCv5. Michal Król, Onur Ascigil, Sergi Rene, Alberto Sonnino, Matthieu Pigaglio, Ramin Sadre, Etienne Rivière |
EuroS&P | 6 |
| 2024 | Avoiding "Hot Potato" Problems in Internet Service ProvidersabstractInternet service providers (ISPs) strive to provide the best possible services to their customers. Service outages, or incidents, due to technical failures are inevitable, so the aim of ISPs must be to respond as quickly as possible to error notifications. However, services may rely on thousands of devices and components that are interconnected and managed by different teams (network administrators, technicians, etc.). Identifying the team to which an incident ticket should be assigned becomes a tedious task that slows down recovery time.In this paper we focus on the problem of finding the right team when an incident occurs. We group teams into logical team groups and use machine learning models that we train on previous resolved incidents to predict the most appropriate team group from a failure description. Using a large dataset from a national ISP and telecommunication company, we demonstrate that, even with a small amount of information available at the beginning of the incident, machine learning models can achieve an accuracy of 88.52% and an F1 score of 90.17%. With more complete information about the incident, the accuracy and F1 score increase to 90.52% and 91.7%. Khanh-Huu-The Dam, Gorby Kabasele Ndonda, Axel Legay, Ramin Sadre |
NOMS | 4 |
| 2021 | Synthetic and Private Smart Health Care Data Generation using GANsabstractWith the rapid advancements in machine learning, the health care paradigm is shifting from treatment towards prevention. The smart health care industry relies on the availability of large-scale health datasets in order to benefit from machine learning-based services. As a consequence, preserving the individuals’ privacy becomes vital for sharing sensitive personal information. Synthetic datasets with generative models are considered to be one of the most promising solutions for privacy-preserving data sharing. Among the generative models, generative adversarial networks (GANs) have emerged as the most impressive models for synthetic data generation in recent times. However, smart health care data is attributed with unique challenges such as volume, velocity, and various data types and distributions. We propose a GAN coupled with differential privacy mechanisms for generating a realistic and private smart health care dataset. The proposed approach is not only able to generate realistic synthetic data samples but also the differentially private data samples under different settings: learning from a noisy distribution or noising the learned distribution. We tested and evaluated our proposed approach using a real-world Fitbit dataset. Our results indicate that our proposed approach is able to generate quality synthetic and differentially private dataset that preserves the statistical properties of the original dataset. Sana Imtiaz, Vladimir Vlassov, Ramin Sadre |
ICCCN | 4 |
| 2021 | Chaos Duck: A Tool for Automatic IoT Software Fault-Tolerance AnalysisabstractInternet of Things (IoT) device software frequently handles sensitive data. This software has to be resistant to faults to prevent leakage and ensure data privacy and security. Source code hardening is a common way to make software fault-tolerant. However, the effectiveness and performance impact of a chosen hardening technique are not always obvious. Moreover, it becomes increasingly difficult to predict potential attack vectors and implement proper countermeasures. To assist in this task, we developed Chaos Duck, an automatic tool for IoT software fault-tolerance analysis. Chaos Duck emulates various fault types and provides statistics on their impact on software security and stability. We present a case study in which we use Chaos Duck to compare five software hardening techniques applied to the PRESENT block cipher implementation. We show that some simple hardening techniques may improve fault-tolerance, while others can instead reduce overall security and introduce new vulnerabilities. Our contributions are twofold: we offer a software fault-tolerance analysis tool to IoT developers seeking to make their software secure and robust, and we shed light on the efficiency of various hardening techniques. Igor Zavalyshyn, Thomas Given-Wilson, Axel Legay, Ramin Sadre, Etienne Rivière |
SRDS | 4 |
| 2020 | GateSelect: A novel Internet gateway selection algorithm for client nodesabstractThe Internet gateway selection problem is becoming very important as the number of Internet-connected devices increases and stresses the limited number of Internet gateway nodes. The gateway nodes often experience frequent performance fluctuations, and the best gateway selection candidate changes frequently with growing network dynamics. We propose GateSelect, a customized selection algorithm for each client node that not only provides the best-effort selection candidate but also ensures the global, balanced distribution of the gateway nodes. We utilize over the counter, lightweight calculations to optimize the client-side selection algorithm by combining classification, short term performance prediction, and randomized selection. We compare our algorithm with several baseline algorithms, and the experiment results show that our proposal provides better performance and balanced distribution of gateway nodes. Khulan Batbayar, Roc Meseguer, Ramin Sadre, Suresh Subramaniam 0001 |
CNSM | 3 |
| 2020 | My House, My Rules: A Private-by-Design Smart Home PlatformabstractSmart home technology has gained widespread adoption. However, several instances of massive corporate surveillance and episodes of sensor data breaches have raised many privacy concerns amongst potential consumers. This paper presents PatrIoT, a private-by-design IoT platform for smart home environments. PatrIoT revisits the typical architecture of existing IoT platforms, and provides an alternative design where the home owner retains full ownership and control of smart device generated data. It leverages Intel SGX to prevent unauthorized access to the data by untrusted IoT cloud providers, and offers homeowners an intuitive security abstraction named flowwall which allows them to specify easy-to-use policies for controlling sensitive sensor data flows within their smart homes. We have built and evaluated a PatrIoT prototype. Most of the participants in a field study considered PatrIoT to be easy to use, and the supported policies to be useful in protecting their privacy. Igor Zavalyshyn, Nuno Santos 0001, Ramin Sadre, Axel Legay |
MobiQuitous | 3 |
| 2020 | Brief Announcement: Effectiveness of Code Hardening for Fault-Tolerant IoT Software
Igor Zavalyshyn, Thomas Given-Wilson, Axel Legay, Ramin Sadre |
SSS | 4 |
| 2019 | Sense-Share: A Framework for Resilient Collaborative Service Performance MonitoringabstractModern large-scale networked services, such as video streaming, are typically deployed at multiple locations in the network to provide redundancy and load balancing. Different techniques are used to provide performance monitoring information so that client nodes can select the best service instance. One of them is collaborative sensing, where clients share measurement results on the observed service performance to build a common ground of knowledge with low overhead. Clients can then use this common ground to select the most suitable service provider. However, collaborative algorithms are susceptible to false measurements sent by malfunctioning or malicious nodes, which decreases the accuracy of the performance sensing process. We propose Sense-Share, a simple light-weight and resilient collaborative sensing framework based on the similarity of the client nodes' perception of service performance. Our experimental evaluation in different topologies shows that service performance sensing using Sense-Share achieves, on average, 94% similarity to non-collaborative brute force performance sensing, tolerating faulty nodes. Furthermore, our approach effectively distributes the service monitoring requests over the service nodes and exploits direct inter-node communication to share measurements, resulting in reduced monitoring overhead. Khulan Batbayar, Emmanouil Dimogerontakis, Roc Meseguer, Leandro Navarro-Moldes, Ramin Sadre |
CNSM | 5 |
| 2019 | Distributed Middlebox Architecture for IoT ProtectionabstractThe Internet of Things (IoT) is not one single entity, but a collection of different devices, communication technologies, protocols and services. IoT systems can span a large number of individually managed networks that are interconnected through the Internet and host the different components of an IoT application, such as sensor devices, storage servers and data processing services. Protecting such a complex multiparty system from abuse becomes a very challenging task. New difficulties arise everyday when policies are updated or new collaborations and federations appear between entities. Moreover, hacked IoT devices can also become the source of powerful attacks, as the Mirai malware has demonstrated, and therefore a danger for the other involved parties. In this paper, we propose an approach to improve the management and protection of collaborating IoT systems using distributed intrusion detection and permission-based access control. Our approach is based on interconnected middleboxes that monitor the communication between the various IoT networks and are able to stop incoming as well as outgoing attacks. We evaluate our approach through experiments with different types of attacks. Lionel Metongnon, Ramin Sadre, Eugène C. Ezin |
CNSM | 2 |
| 2019 | Collaborative informed gateway selection in large-scale and heterogeneous networks
Khulan Batbayar, Roc Meseguer, Emmanouil Dimogerontakis, Leandro Navarro-Moldes, Ramin Sadre |
IM | 5 |
| 2019 | Improving Performance of QUIC in WiFiabstractQUIC is a new transport protocol under standardization since 2016. Initially developed by Google as an experiment, the protocol is already deployed in large-scale, thanks to its support in Chromium and Google's servers. In this paper we experimentally analyze the performance of QUIC in WiFi networks. We perform experiments using both a controlled WiFi testbed and a production WiFi mesh network. In particular, we study how QUIC interplays with MAC layer features such as IEEE 802.11 frame aggregation. We show that the current implementation of QUIC in Chromium achieves sub-optimal throughput in wireless networks. Indeed, burstiness in modern WiFi standards may improve network performance, and we show that a Bursty QUIC (BQUIC), i.e., a customized version of QUIC that is targeted to increase its burstiness, can achieve better performance in WiFi. BQUIC outperforms the current version of QUIC in WiFi, with throughput gains ranging between 20% to 30%. Jawad Manzoor, Llorenç Cerdà-Alabern, Ramin Sadre, Idilio Drago |
WCNC | 3 |
| 2017 | Efficient probing of heterogeneous IoT networksabstractThe Internet of Things leads to the inter-connectivity of a wide range of devices. This heterogeneity of hardware and software poses significant challenges to security. Constrained IoT devices often do not have enough resources to carry the overhead of an intrusion protection system or complex security protocols. A typical initial step in network security is a network scan in order to find vulnerable nodes. In the context of IoT, the initiator of the scan can be particularly interested in finding constrained devices, assuming that they are easier targets. In IoT networks hosting devices of various types, performing a scan with a high discovery rate can be a challenging task, since low-power networks such as IEEE 802.15.4 are easily overloaded. In this paper, we propose an approach to increase the efficiency of network scans by combining them with active network measurements. The measurements allow the scanner to differentiate IoT nodes by the used network technology. We show that the knowledge gained from this differentiation can be used to control the scan strategy in order to reduce probe losses. Lionel Metongnon, Eugène C. Ezin, Ramin Sadre |
IM | 3 |
| 2016 | The curious case of parallel connections in HTTP/2abstractWeb pages and web-based services are becoming more and more complex. The average page size for the Alexa top 1000 websites in 2016 has reached 2.1 MB and fetching a page requires requests for 128 different objects. Although the bandwidth has been increasing exponentially in the last few years, the web experience is not improving at the same pace because of latency issues in HTTP/1. The HTTP/2 protocol aims to solve these issues by allowing clients and servers to multiplex HTTP requests and responses on a single TCP connection. If HTTP/2 is widely adopted, it can have enormous benefits not only for the user experience, but also for the servers and the network. Since clients do not have to open multiple parallel connections to avoid the problem of head-of-line blocking in HTTP/1.1, the number of concurrent TCP sessions can be significantly reduced. However, although multiplexing is one of the main features of HTTP/2, nothing actually prevents a client from opening multiple HTTP/2 connections to a server. In this paper we investigate the behavior of HTTP/2 traffic in the wild. We perform experiments to examine if web browsers use a single connection per domain over HTTP/2 in practice. Contrary to popular belief, our experiments on the traffic of a large university campus network and a residential network show that a significant number of HTTP/2 accesses are performed using parallel connections to a single domain on a server. We present two possible hypotheses for this behavior and discuss its implications for the future of the web. Jawad Manzoor, Idilio Drago, Ramin Sadre |
CNSM | 3 |
| 2016 | Measuring the Adoption of DDoS Protection Services
Mattijs Jonker, Anna Sperotto, Roland van Rijswijk-Deij, Ramin Sadre, Aiko Pras |
Internet Measurement Conference | 4 |
| 2016 | Observing real Multipath TCP traffic
Hoang Tran-Viet, Quentin De Coninck, Benjamin Hesmans, Ramin Sadre, Olivier Bonaventure |
Comput. Commun. | 4 |
| 2015 | Impact of Packet Sampling on Link DimensioningabstractLink dimensioning is used by network operators to properly provision the capacity of their network links. Proposed methods for link dimensioning often require statistics, such as traffic variance, that need to be calculated from packet-level measurements. In practice, due to increasing traffic volume, operators deploy packet sampling techniques aiming to reduce the burden of traffic monitoring, but little is known about how link dimensioning is affected by such measurements. In this paper, we make use of a previously proposed and validated dimensioning formula that requires traffic variance to estimate required link capacity. We assess the impact of three packet sampling techniques on link dimensioning, namely, Bernoulli, n-in-N and sFlow sampling. To account for the additional variance introduced by the sampling algorithms, we propose approaches to better estimate traffic variance from sampled data according to the employed technique. Results show that, depending on sampling rate and link load, packet sampling does not negatively impact on link dimensioning accuracy even at very short timescales such as 10 ms. Moreover, we also show that the loss of inter-arrival time of sampled packets due to the exporting process in sFlow does not harm the estimations, given that an appropriate sampling rate is used. Our study is validated using a large dataset consisting of traffic packet traces captured at several locations around the globe. Ricardo de Oliveira Schmidt, Ramin Sadre, Anna Sperotto, Hans van den Berg, Aiko Pras |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2014 | Linking network usage patterns to traffic Gaussianity fitabstractGaussian traffic models are widely used in the domain of network traffic modeling. The central assumption is that traffic aggregates are Gaussian distributed. Due to its importance, the Gaussian character of network traffic has been extensively assessed by researchers in the past years. In 2001, researchers showed that the property of Gaussianity can be disturbed by traffic bursts. However, assumptions on network infrastructure and traffic composition made by the authors back in 2001 are not consistent with those of today's networks. The goal of this paper is to study the impact of traffic bursts on the degree of Gaussianity of network traffic. We identify traffic bursts, uncover applications and hosts that generate them and, ultimately, relate these findings to the Gaussianity degree of the traffic expressed by a goodness-of-fit factor. In our analysis we use recent traffic captures from 2011 and 2012. Our results show that Gaussianity can be directly linked to the presence or absence of extreme traffic bursts. In addition, we also show that even in a more homogeneous network, where hosts have similar access speeds to the Internet, we can identify extreme traffic bursts that might compromise Gaussianity fit. Ricardo de Oliveira Schmidt, Ramin Sadre, Nikolay Melnikov, Jürgen Schönwälder, Aiko Pras |
Networking | 2 |
| 2014 | Internet Bad Neighborhoods temporal behaviorabstractMalicious hosts tend to be concentrated in certain areas of the IP addressing space, forming the so-called Bad Neighborhoods. Knowledge about this concentration is valuable in predicting attacks from unseen IP addresses. This observation has been employed in previous works to filter out spam. In this paper, we focus on the temporal behavior of bad neighborhoods. The goal is to determine if bad neighborhoods strike multiple times over a certain period of time, and if so, when do the attacks occur. Among other findings, we show that even though bad neighborhoods do not exhibit a favorite combination of days to carry out attacks, 85% of the recurrent bad neighborhoods do carry out a second attack within the first 5 days from the first attack. These and the other findings here presented lead to several considerations on how attack prediction models can be more effective i.e., generating both predictive and short neighborhood blacklists. Giovane Cesar Moreira Moura, Ramin Sadre, Aiko Pras |
NOMS | 2 |
| 2014 | Taking on Internet Bad NeighborhoodsabstractIt's known fact that malicious IP addresses are not evenly distributed over the IP addressing space. In this paper, we frame networks concentrating malicious addresses as bad neighborhoods. We propose a formal definition and show this concentration can be used to predict future attacks (new spamming sources, in our case), and propose an algorithm to aggregate individual IP addresses can bigger neighborhoods. Moreover, we show how bad neighborhoods are specific according to the exploited application (e.g., spam, ssh) and how the performance of different blacklist sources impacts lightweight spam filtering algorithms. Giovane Cesar Moreira Moura, Ramin Sadre, Aiko Pras |
NOMS | 2 |
| 2014 | A hybrid procedure for efficient link dimensioning
Ricardo de Oliveira Schmidt, Ramin Sadre, Anna Sperotto, Hans van den Berg, Aiko Pras |
Comput. Networks | 2 |
| 2013 | Lightweight link dimensioning using sFlow samplingabstractOperators use link dimensioning to provision network links. In practice, traffic averages are obtained via SNMP are used to roughly estimate required capacity. More accurate solutions often require traffic statistics easily obtained from packet captures, e.g. variance. However, packet capturing may not be trivial in high-speed links. Aiming scalability, operators often deploy packet sampling on monitoring, but little is known how it affects link dimensioning. In this paper we assess the feasibility of lightweight link dimensioning using sFlow, which is a widely-deployed traffic monitoring tool. We implement sFlow sampling algorithm and use a previously proposed and validated dimensioning formula that needs traffic variance.We validate our approach using packet captures from real networks. Results show that the proposed procedure is successful for a range of sampling rates and that, due to randomness of sampling algorithm, the error introduced by scaling the traffic variance yields more conservative results that cope with short-term traffic fluctuations. Ricardo de Oliveira Schmidt, Ramin Sadre, Anna Sperotto, Aiko Pras |
CNSM | 2 |
| 2013 | Evaluating third-party Bad Neighborhood blacklists for Spam detection
Giovane Cesar Moreira Moura, Anna Sperotto, Ramin Sadre, Aiko Pras |
IM | 3 |
| 2013 | Gaussian traffic revisited
Ricardo de Oliveira Schmidt, Ramin Sadre, Aiko Pras |
Networking | 2 |
| 2013 | Measurement Artifacts in NetFlow Data
Rick Hofstede, Idilio Drago, Anna Sperotto, Ramin Sadre, Aiko Pras |
PAM | 4 |
| 2012 | Towards periodicity based anomaly detection in SCADA networksabstractSupervisory Control and Data Acquisition (SCADA) networks are commonly deployed to aid the operation of large industrial facilities. The polling mechanism used to retrieve data from field devices causes the data transmission to be highly periodic. In this paper, we propose an approach that exploits traffic periodicity to detect traffic anomalies, which represent potential intrusion attempts. We present a proof of concept to show the feasibility of our approach. Rafael Ramos Regis Barbosa, Ramin Sadre, Aiko Pras |
ETFA | 2 |
| 2012 | Inside dropbox: understanding personal cloud storage servicesabstractPersonal cloud storage services are gaining popularity. With a rush of providers to enter the market and an increasing offer of cheap storage space, it is to be expected that cloud storage will soon generate a high amount of Internet traffic. Very little is known about the architecture and the performance of such systems, and the workload they have to face. This understanding is essential for designing efficient cloud storage systems and predicting their impact on the network. Idilio Drago, Marco Mellia, Maurizio M. Munafò, Anna Sperotto, Ramin Sadre, Aiko Pras |
Internet Measurement Conference | 5 |
| 2012 | A first look into SCADA network trafficabstractSupervisory Control and Data Acquisition (SCADA) networks are commonly deployed to aid the operation of critical infrastructures, such as water distribution facilities. These networks provide automated processes that ensure the correct functioning of these infrastructures, in a operation much similar to those of management operations found in traditional Internet Protocol (IP), in particular the Simple Network Management Protocol (SNMP). In this paper we provide a first look into characteristics of SCADA traffic, with the goal of building an empirical foundation for future research, and investigate to what extent the SCADA traffic patterns are similar to SNMP. Rafael Ramos Regis Barbosa, Ramin Sadre, Aiko Pras |
NOMS | 2 |
| 2012 | Internet bad neighborhoods aggregationabstractInternet Bad Neighborhoods have proven to be an innovative approach for fighting spam. They have also helped to understand how spammers are distributed on the Internet. In our previous works, the size of each bad neighborhood was fixed to a /24 subnetwork. In this paper, however, we investigate if it is feasible to aggregate Internet bad neighborhoods not only at /24, but to any network prefix. To do that, we propose two different aggregation strategies: fixed prefix and variable prefix. The motivation for doing that is to reduce the number of entries in the bad neighborhood list, thus reducing memory storage requirements for intrusion detection solutions. We also introduce two error measures that allow to quantify how much error was incurred by the aggregation process. An evaluation of both strategies was conducted by analyzing real world data in our aggregation prototype. Giovane Cesar Moreira Moura, Ramin Sadre, Anna Sperotto, Aiko Pras |
NOMS | 2 |
| 2012 | The effects of DDoS attacks on flow monitoring applicationsabstractFlow-based monitoring has become a popular approach in many areas of network management. However, flow monitoring is, by design, susceptible to anomalies that generate a large number of flows, such as Distributed Denial-Of-Service attacks. This paper aims at getting a better understanding on how a flow monitoring application reacts to the presence of massive attacks. We analyze the performance of a flow monitoring application from the perspective of the flow data it has to process. We first identify the changes in the flow data caused by a massive attack and propose a simple queueing model that describes the behavior of the flow monitoring application. Secondly, we present a case study based on a real attack trace collected at the University of Twente and we analyze the performance of the flow monitoring application by means of simulation experiments. We conclude that the observed changes in the flow data might cause unwanted effects in monitoring applications. Furthermore, our results show that our model can help to parametrize and dimension flow-based monitoring systems. Ramin Sadre, Anna Sperotto, Aiko Pras |
NOMS | 1 |
| 2012 | Difficulties in Modeling SCADA Traffic: A Comparative Analysis
Rafael Ramos Regis Barbosa, Ramin Sadre, Aiko Pras |
PAM | 2 |
| 2012 | Autonomic Parameter Tuning of Anomaly-Based IDSs: an SSH Case StudyabstractAnomaly-based intrusion detection systems classify network traffic instances by comparing them with a model of the normal network behavior. To be effective, such systems are expected to precisely detect intrusions (high true positive rate) while limiting the number of false alarms (low false positive rate). However, there exists a natural trade-off between detecting all anomalies (at the expense of raising alarms too often), and missing anomalies (but not issuing any false alarms). The parameters of a detection system play a central role in this trade-off, since they determine how responsive the system is to an intrusion attempt. Despite the importance of properly tuning the system parameters, the literature has put little emphasis on the topic, and the task of adjusting such parameters is usually left to the expertise of the system manager or expert IT personnel. In this paper, we present an autonomic approach for tuning the parameters of anomaly-based intrusion detection systems in case of SSH traffic. We propose a procedure that aims to automatically tune the system parameters and, by doing so, to optimize the system performance. We validate our approach by testing it on a flow-based probabilistic detection system for the detection of SSH attacks. Anna Sperotto, Michel Mandjes, Ramin Sadre, Pieter-Tjerk de Boer, Aiko Pras |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2011 | Internet Bad Neighborhoods: The spam case
Giovane Cesar Moreira Moura, Ramin Sadre, Aiko Pras |
CNSM | 2 |
| 2009 | Self-management of hybrid networks: Can we trust netflow data?abstractNetwork measurement provides vital information on the health of managed networks. The collection of network information can be used for several reasons (e.g., accounting or security) depending on the purpose the collected data will be used for. At the University of Twente (UT), an automatic decision process for hybrid networks that relies on collected network information has been investigated. This approach, called self-management of hybrid networks requires information retrieved from measuring processes in order to automatically decide on establishing/releasing lambda-connections for IP flows that are long in duration and big in volume (known as elephant flows). Nonetheless, the employed measurement technique can break the self-management decisions if the reported information does not accurately describe the actual behavior and characteristics of the observed flows. Within this context, this paper presents an investigation on the trustfulness of measurements performed using the popular NetFlow monitoring solution when elephant flows are especially observed. We primarily focus on the use of NetFlow with sampling in order to collect network information and investigate how reliable such information is for the self-management processes. This is important because the self-management approach decides which flows should be off-loaded to the optical level based on the current state of the network and its running flows. We observe three specific flow metrics: octets, packets, and flow duration. Our analysis shows that NetFlow provides reliable information regarding octets and packets. On the other hand, the flow duration reported when sampling is employed tends to be shorter than the actual duration. Tiago Fioreze, Lisandro Z. Granville, Aiko Pras, Anna Sperotto, Ramin Sadre |
Integrated Network Management | 5 |
| 2004 | The pseudo-self-similar traffic model: application and validation
Rachid El Abdouni Khayari, Ramin Sadre, Boudewijn R. Haverkort, Alexander Ost |
Perform. Evaluation | 2 |
| 2003 | Fitting world-wide web request traces with the EM-algorithm
Rachid El Abdouni Khayari, Ramin Sadre, Boudewijn R. Haverkort |
Perform. Evaluation | 2 |
| 2002 | A Validation of the Pseudo Self-Similar Traffic ModelabstractSince the early 1990s, a variety of studies has shown that network traffic, both for local- and wide-area networks, has self-similarity properties. This has led to new approaches in network traffic modelling. Instead of developing completely new traffic models, a number of researchers have proposed to adapt traditional traffic modelling approaches to incorporate aspects of self-similarity. The motivation for doing so is the hope to be able to reuse techniques and tools that have been developed in the past and with which experience has been gained. One such an approach for a traffic model that incorporates aspects of self-similarity is the so-called pseudo self-similar traffic model. This model is appealing, as it is easy, to understand and easily embedded in Markovian performance evaluation studies. In applying this model in a number of cases, we have perceived various problems which we initially, thought were particular to these specific cases. We briefly review the pseudo self-similar traffic model and discuss its fundamental shortcomings. Rachid El Abdouni Khayari, Ramin Sadre, Boudewijn R. Haverkort |
DSN | 2 |