VLDB 2026 Research / reviewers in the wild / expert
Michele Colajanni
dblp:c/MicheleColajanni
· DBLP profile ↗
93ranked-venue papers
12as first author
16since 2021 · last 2025
0000-0002-9499-1559ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 31 · 8 first-author · 2 since 2021Computer networks · 19 · 2 first-author · 5 since 2021Security and privacy · 11 · 1 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 1 since 2021Databases, data management, data science and information retrieval · 5 · 1 first-authorSoftware engineering, systems software and programming languages · 4Theory of computation · 2Artificial intelligence and machine learning · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Building Network Digital Twin Architectures from Architectural RepresentationabstractNetwork Digital Twins (NDTs) is emerging as a powerful approach to building and manipulating a digital representation of network services and architectures including different communication protocols, data flows, and interactions. These virtual counterparts enable comprehensive analysis of complex network environments, such as telecommunication networks, enterprise IT infrastructures, and cloud ecosystems, and can play an important role in network management by facilitating realtime monitoring, performance tuning, and proactive fault and attack detection. By continuously synchronizing with the real network, they can predict potential problems, model the impact of configuration changes, and assess scalability under varying loads without risking live operations. The difficulty of building NDTs is the counterpart of all these possible advantages. We introduce a novel approach to simplify and accelerate the creation of NDTs through graphical schemes and/or structured XML code. We incorporate machine learning models for image recognition that can ensure accuracy and efficiency in handling diverse input data formats. We evaluate the proposed approach by analyzing the accuracy of models trained on a custom dataset of visual infrastructures and by evaluating the performance for different workloads. Silvio Russo, Isabella Marasco, Michele Colajanni |
ISCC | 3 |
| 2025 | Continual Learning for Handling Maritime Data Shifts in Vessel Trajectory PredictionabstractThe highly dynamic characteristics of the maritime environment present significant challenges for vessel trajectory prediction. Traditional statistical and machine learning models often struggle to adapt to changing conditions and new data streams, leading to performance degradation. To address these well known issues, we propose the use of Continual Learning that enables the system to learn incrementally from sequential data streams. Our proposal avoids catastrophic forgetting of previously acquired knowledge through a replay-based approach. This strategy ensures that the prediction model can track and adapt to shifting environmental factors and variations in vessel behavior. We test the Continual Learning-based model using high-frequency trajectory data recorded by a cruise vessel Voyage Data Recorder. Experimental results indicate that our approach achieves a lower error compared to conventional static learning models. It mitigates catastrophic forgetting, ensuring the retention of critical information from past vessel movements, and demonstrates a strong capacity to adapt to data shifts inherent in real-world maritime operations. These findings highlight the potential of Continual Learning to enhance the reliability and robustness of vessel trajectory prediction systems in an ever-changing maritime landscape. Isabella Marasco, Alessandro Cantelli-Forti, Michele Colajanni |
LCN | 3 |
| 2024 | Cybersecurity Domains: A design pattern for creating Zero Trust Architectures through microsegmentationabstractPerimeter defense strategies are inadequate to ensure cybersecurity of infrastructures consisting of heterogeneous and dynamic resources. The Zero Trust security model emerges as the most promising solution to mitigate risks and protect assets, but significant organizational and implementation challenges hinder its adoption. Microsegmentation of networked systems composed by dynamic IT components and mobile devices cause several technological and management concerns. We present a comprehensive analysis of microsegmentation with the goal of identifying the key aspects that distinguish it from traditional perimeter defenses. We then propose a modular architectural design pattern that ensures adherence to the Zero Trust principles and satisfies its security constraints. This design is based on the concept of Security Domain, which represents the fundamental unit of network segmentation. By combining multiple Security Domains and following precise rules that provably preserve network security, it becomes possible to create complex infrastructures from elementary building blocks. We provide also a formal specification of the proposed design by means of the TLA+ modeling language. We leverage this model to verify its correctness and security properties even in the presence of insider threats. Claudio Zanasi, Mirco Marchetti, Michele Colajanni |
DASC | 3 |
| 2024 | Evaluating Technical Countermeasures for Telecom Spam and Scams in the AI EraabstractThis paper addresses the enduring issue of spam, scams, and robocalls within the telecommunications sector. The diffusion of generative AI technologies has escalated these challenges, as advancements in natural language processing and related tools enhance the sophistication of scams, facilitating the implementation of convincing social engineering attacks. The economic impact of these nefarious activities is significant, as evidenced by the vast number of spam calls and robocalls generated every day that lead to significant financial losses. Although technologies such as blocklists, STIR/SHAKEN, and Caller ID Verification methods are being implemented, the adoption of these solutions by phone companies remains slow due to industry barriers and varied regulatory frameworks. This paper evaluates the effectiveness of current anti-spam countermeasures and highlights the practical limits of these solutions, underscoring the need for improved decision-making tools. Marcello Pietri, Marco Mamei, Michele Colajanni |
NCA | 3 |
| 2024 | Flexible zero trust architecture for the cybersecurity of industrial IoT infrastructuresabstractThe growing digitalization of industrial systems and the increasing adoption of cloud technologies pose significant challenges to the secure management of modern industrial infrastructures integrating different Industrial Internet of Things (IIoT). Existing cybersecurity solutions can manage uniform and centralized software systems but are not designed to accommodate the requirements of heterogeneous IIoT devices, such as hard real-time operations, high reliability, and decentralization for distributed decision-making. We present a novel security architecture that is specifically designed to address the stringent requirements of IIoT systems. It is based on a network micro-segmentation that can be seamlessly integrated into existing environments, and two main components: a software-defined network (SDN) ensuring a unified abstraction layer for policy enforcement across diverse environments; and a centralized security management layer that simplifies the policy execution of any architectural design. We demonstrate the feasibility and effects of this original combination through a prototype. It experimentally demonstrates that our peer-to-peer SDN coupled with an asynchronous policy distribution process guarantees resiliency to individual failures, and enables fully decentralized operations while still ensuring a central flexible management of network topology and security policies. Claudio Zanasi, Silvio Russo, Michele Colajanni |
Ad Hoc Networks | 3 |
| 2023 | Penetrating the Silence: Data Exfiltration in Maritime and Underwater ScenariosabstractThe risk of data exfiltration remains a concern, even when the connectivity of the victim system is limited or the domain is physically isolated. This paper delves into the unique challenges associated with data exfiltration in surface and submarine naval scenarios in the absence of persistent data connections. It explores contexts where attacks through the supply chain can pose a serious risk even if the compromised hardware or software is not connected to any network or even (apparently) switched off. The attacks exploiting vulnerabilities in some components of the supply chain can serve as a conduit for data exfiltration. This study aims to enhance the overall security posture of maritime systems by identifying possible exposures and mitigating the risk of data exfiltration and covered channel attacks. Alessandro Cantelli-Forti, Michele Colajanni, Silvio Russo |
LCN | 2 |
| 2023 | A multidisciplinary detection system for cyber attacks on Powertrain Cyber Physical Systems
Dario Stabili, Raffaele Romagnoli, Mirco Marchetti, Bruno Sinopoli, Michele Colajanni |
Future Gener. Comput. Syst. | 5 |
| 2023 | FRAMH: A Federated Learning Risk-Based Authorization Middleware for HealthcareabstractModern healthcare systems operate in highly dynamic environments requiring adaptable access control mechanisms. Access to sensitive data and medical equipment should be granted or denied according to the current health situation of the patient. To handle the need for adaptable access control of healthcare scenarios, we propose a novel model that allows dynamic access control decisions based on the context characterizing the source, type of access request, patient, and estimated risk corresponding to the conditions of the patient. Estimating patient status risk requires analyzing vital physiological data whose availability is growing, thanks to the widespread diffusion of the Internet of Medical Things (IoMT) devices. Inferring the patient health status risk through machine learning (ML) techniques is possible, but to achieve better accuracy, the training phase requires the aggregation of vast amounts of data from different sources. This aggregation could be difficult or even impossible due to organization regulations and privacy laws. To address these issues, this article proposes a novel federated learning risk-based authorization middleware for healthcare (FRAMH) that supports risk-based access control to deal with changing and unforeseen medical situations. Our solution infers the risk of health status through a federated learning (FL) approach enriched with blockchain to avoid the weaknesses of centralized servers. The implemented prototype and a large set of experimental results demonstrate the advantages of FL in estimating the risk in healthcare scenarios. Through this approach, even a medical institution with a limited dataset can achieve a satisfying risk estimation and efficient access control enforcement. Carlo Mazzocca, Nicolò Romandini, Michele Colajanni, Rebecca Montanari |
IEEE Trans. Comput. Soc. Syst. | 3 |
| 2023 | DOLOS: A Novel Architecture for Moving Target DefenseabstractMoving Target Defense and Cyber Deception emerged in recent years as two key proactive cyber defense approaches, contrasting with the static nature of the traditional reactive cyber defense. The key insight behind these approaches is to impose an asymmetric disadvantage for the attacker by using deception and randomization techniques to create a dynamic attack surface. Moving Target Defense (MTD) typically relies on system randomization and diversification, while Cyber Deception is based on decoy nodes and fake systems to deceive attackers. However, current Moving Target Defense techniques are complex to manage and can introduce high overheads, while Cyber Deception nodes are easily recognized and avoided by adversaries. This paper presents DOLOS, a novel architecture that unifies Cyber Deception and Moving Target Defense approaches. DOLOS is motivated by the insight that deceptive techniques are much more powerful when integrated into production systems rather than deployed alongside them. DOLOS combines typical Moving Target Defense techniques, such as randomization, diversity, and redundancy, with cyber deception and seamlessly integrates them into production systems through multiple layers of isolation. We extensively evaluate DOLOS against a wide range of attackers, ranging from automated malware to professional penetration testers, and show that DOLOS is effective in slowing down attacks and protecting the integrity of production systems. We also provide valuable insights and considerations for the future development of MTD techniques based on our findings. Giulio Pagnotta, Fabio De Gaspari, Dorjan Hitaj, Mauro Andreolini, Michele Colajanni, Luigi V. Mancini |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2022 | A Fully Decentralized Architecture for Access Control Verification in Serverless EnvironmentsabstractServerless computing is a novel paradigm that has been widely adopted, in recent years, across many sectors due to its fine-grained scalability and fast time-to-market. This paradigm aims at offloading users from heavy burden tasks including those related to authentication and authorization. However, existing security mechanisms provided by cloud providers do not seem to be adequate to completely secure serverless platforms. In particular, typical access control solutions rely either on centralized authorization services or implement access control verification within the business logic. These approaches respectively degrade system performance and lead to security issues derived from the tight coupling among code and authorization verification. In this paper, we present a solution to address these problems with a fully decentralized architecture integrating access control verification in serverless environments. We implemented a prototype of the proposed architecture and evaluated its performance under different load conditions. Experiments show that our proposal outperforms other approaches. Andrea Sabbioni, Carlo Mazzocca, Michele Colajanni, Rebecca Montanari, Antonio Corradi |
ISCC | 3 |
| 2022 | Robustness Evaluation of Network Intrusion Detection Systems based on Sequential Machine LearningabstractThe rise of sequential Machine Learning (ML) methods has paved the way for a new generation of Network Intrusion Detection Systems (NIDS) which base their classification on the temporal patterns exhibited by malicious traffic. Previous work presents successful algorithms in this field, but just a few attempts try to assess their robustness in real-world contexts. In this paper, we aim to fill this gap by presenting a novel evaluation methodology. In particular, we propose a new time-based adversarial attack in which we simulate a delay in the malicious communications that changes the arrangement of the samples in the test set. Moreover, we design an innovative evaluation technique simulating a worst-case training scenario in which the last portion of the training set does not include any malicious flow. Through them, we can evaluate how much sequential ML-based NIDS are sensible to modifications that an adaptive attacker might apply at temporal level, and we can verify their robustness to the unpredictable traffic produced by modern networks. Our experimental campaign validates our proposal against a recent NIDS trained on a public dataset for botnet detection. The results demonstrate its high resistance to temporal adversarial attacks, but also a drastic performance drop when even just 1% of benign flows are injected at the end of the training set. Our findings raise questions about the reliable deployment of sequential ML-NIDS in practice, and at the same time can guide researchers to develop more robust defensive tools in the future. Andrea Venturi, Claudio Zanasi, Mirco Marchetti, Michele Colajanni |
NCA | 4 |
| 2022 | A Zero Trust approach for the cybersecurity of Industrial Control SystemsabstractIndustrial plants are adopting an increasing number of digital interconnected technologies that are enriched by several software applications. The IT/OT convergence offers several benefits in terms of efficiency and flexibility but it opens as many issues in terms of cyber vulnerabilities because industrial plants were not designed to be open to Internet. The frequency of successful cyber attacks shows that typical security solutions are inadequate to the novel complexity of industrial contexts. This novel scenario requires original approaches differing from traditional multi-layer networking solutions that are applicable just to rigid and stable infrastructures. We explore the applicability of Zero Trust Architecture (ZTA) principles to the industrial context by designing, implementing and testing an integrated defensive solution. The results obtained through a working prototype show that it is possible to implement a Zero Trust identity-centric approach in an industrial context to increase the security and flexibility of the system while providing complete visibility over the entire network. The proposed approach can be used to strengthen legacy industrial systems that were designed for offline use, and to allow the adoption of innovative technologies that minimize the cyber risk for the overall infrastructure. Claudio Zanasi, Federico Magnanini, Silvio Russo, Michele Colajanni |
NCA | 4 |
| 2022 | Scalable, Confidential and Survivable Software UpdatesabstractSoftware update systems must guarantee high availability, integrity and security even in presence of cyber attacks. We propose the first survivable software update framework for the secure distribution of confidential updates that is based on a distributed infrastructure with no single points of failure. Previous works guarantee either survivability or confidentiality of software updates but do not ensure both properties. Our proposal is based on an original application of a multi-authority attribute-based encryption scheme in the context of decentralized access control management that avoids single-point-of-vulnerability. We describe the original framework, propose the protocols to implement it, and demonstrate its feasibility through a security and performance evaluation. Federico Magnanini, Luca Ferretti, Michele Colajanni |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2021 | Survivable zero trust for cloud computing environments
Luca Ferretti, Federico Magnanini, Mauro Andreolini, Michele Colajanni |
Comput. Secur. | 4 |
| 2021 | Verifiable and auditable authorizations for smart industries and industrial Internet-of-Things
Luca Ferretti, Francesco Longo 0001, Giovanni Merlino, Michele Colajanni, Antonio Puliafito, Nachiket Tapas |
J. Inf. Secur. Appl. | 4 |
| 2021 | Glyph: Efficient ML-Based Detection of Heap Spraying AttacksabstractHeap spraying is probably the most simple and effective memory corruption attack, which fills the memory with malicious payloads and then jumps at a random location in hopes of starting the attacker's routines. To counter this threat, GRAFFITI has been recently proposed as the first OS-agnostic framework for monitoring memory allocations of arbitrary applications at runtime; however, the main contributions of GRAFFITI are on the monitoring system, and its detection engine only considers simple heuristics which are tailored to certain attack vectors and are easily evaded. In this article, we aim to overcome this limitation and propose GLYPH as the first ML-based heap spraying detection system, which is designed to be effective, efficient, and resilient to evasive attackers. GLYPH relies on the information monitored by GRAFFITI, and we investigate the effectiveness of different feature spaces based on information entropy and memory n-grams, and discuss the several engineering challenges we have faced to make GLYPH efficient with an overhead compatible with that of GRAFFITI. To evaluate GLYPH, we build a representative dataset with several variants of heap spraying attacks, and assess GLYPH's resilience against evasive attackers through selective hold-out experiments. Results show that GLYPH achieves high accuracy in detecting spraying and is able to generalize well, outperforming the state-of-the-art approach for heap spraying detection, NOZZLE. Finally, we thoroughly discuss the trade-offs between detection performance and runtime overhead of GLYPH's different configurations. Fabio Pierazzi, Stefano Cristalli, Danilo Bruschi, Michele Colajanni, Mirco Marchetti, Andrea Lanzi |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2020 | A Framework for the Evaluation of Trainee Performance in Cyber Range Exercises
Mauro Andreolini, Vincenzo Giuseppe Colacino, Michele Colajanni, Mirco Marchetti |
Mob. Networks Appl. | 3 |
| 2020 | Deep Reinforcement Adversarial Learning Against Botnet Evasion AttacksabstractAs cybersecurity detectors increasingly rely on machine learning mechanisms, attacks to these defenses escalate as well. Supervised classifiers are prone to adversarial evasion, and existing countermeasures suffer from many limitations. Most solutions degrade performance in the absence of adversarial perturbations; they are unable to face novel attack variants; they are applicable only to specific machine learning algorithms. We propose the first framework that can protect botnet detectors from adversarial attacks through deep reinforcement learning mechanisms. It automatically generates realistic attack samples that can evade detection, and it uses these samples to produce an augmented training set for producing hardened detectors. In such a way, we obtain more resilient detectors that can work even against unforeseen evasion attacks with the great merit of not penalizing their performance in the absence of specific attacks. We validate our proposal through an extensive experimental campaign that considers multiple machine learning algorithms and public datasets. The results highlight the improvements of the proposed solution over the state-of-the-art. Our method paves the way to novel and more robust cybersecurity detectors based on machine learning applied to network traffic analytics. Giovanni Apruzzese, Mauro Andreolini, Mirco Marchetti, Andrea Venturi, Michele Colajanni |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2019 | Evaluating the effectiveness of Adversarial Attacks against Botnet DetectorsabstractClassifiers based on Machine Learning are vulnerable to adversarial attacks, which involve the creation of malicious samples that are not classified correctly. While this phenomenon has been extensively studied within the image processing domain, comprehensive analyses are scarce in the cybersecurity field. This is a critical problem because cyber-detectors are being increasingly integrated with machine learning methods, making them suitable targets for skilled attackers leveraging adversarial samples to evade detection. In this paper, we propose a thorough analysis of realistic adversarial attacks performed against network intrusion detection systems that focus on identifying botnet traffic through machine learning classifiers. Our large campaign of experiments involves the most recent public datasets, representing multiple realistic network scenarios. Moreover, we evaluate the impact of these attacks against state-of-the-art detectors relying on different machine learning algorithms, providing a clear overview of this problem. The results outline the fragility of these methods. Our study represent a stepping stone for devising suitable countermeasures to the menace of adversarial attacks against cyber-detectors. Giovanni Apruzzese, Michele Colajanni, Mirco Marchetti |
NCA | 2 |
| 2019 | Efficient License Management Based on Smart Contracts Between Software Vendors and Service ProvidersabstractIn a fully interconnected world where even network-related services are becoming more dependent on software, the management of license agreements is critical for the business of any software vendor and communication provider. Building, managing and protecting the infrastructure to handle software license validation and scalability for the provider and, on the other hand, assessing the correct use of the software licenses for the vendor can become an expensive part of the relationship costs. We propose a novel approach for decentralized software licensing that leverages blockchain and smart contracts as fundamental enabling technologies. Our proposal guarantees a secure and inexpensive system with no central point of failure that can regulate the relations among untrusted parties. We describe the main design choices and present a prototype experimentation that demonstrates the benefits of the proposal in the context of virtualized network infrastructures. Federico Magnanini, Luca Ferretti, Michele Colajanni |
NCA | 3 |
| 2019 | Fog-based Secure Communications for Low-power IoT DevicesabstractDesigning secure, scalable, and resilient IoT networks is a challenging task because of resource-constrained devices and no guarantees of reliable network connectivity. Fog computing improves the resiliency of IoT, but its security model assumes that fog nodes are fully trusted. We relax this latter constraint by proposing a solution that guarantees confidentiality of messages exchanged through semi-honest fog nodes thanks to a lightweight proxy re-encryption scheme. We demonstrate the feasibility of the solution by applying it to IoT networks of low-power devices through experiments on microcontrollers and ARM-based architectures. Luca Ferretti, Mirco Marchetti, Michele Colajanni |
ACM Trans. Internet Techn. | 3 |
| 2018 | Evading Botnet Detectors Based on Flows and Random Forest with Adversarial SamplesabstractMachine learning is increasingly adopted for a wide array of applications, due to its promising results and autonomous capabilities. However, recent research efforts have shown that, especially within the image processing field, these novel techniques are susceptible to adversarial perturbations. In this paper, we present an analysis that highlights and evaluates experimentally the fragility of network intrusion detection systems based on machine learning algorithms against adversarial attacks. In particular, our study involves a random forest classifier that utilizes network flows to distinguish between botnet and benign samples. Our results, derived from experiments performed on a public real dataset of labelled network flows, show that attackers can easily evade such defensive mechanisms by applying slight and targeted modifications to the network activity generated by their controlled bots. These findings pave the way for future techniques that aim to strengthen the performance of machine learning-based network intrusion detection systems. Giovanni Apruzzese, Michele Colajanni |
NCA | 2 |
| 2018 | A symmetric cryptographic scheme for data integrity verification in cloud databases
Luca Ferretti, Mirco Marchetti, Mauro Andreolini, Michele Colajanni |
Inf. Sci. | 4 |
| 2017 | Verifiable Delegated Authorization for User-Centric Architectures and an OAuth2 ImplementationabstractDelegated authorization protocols have become wide-spread to implement Web applications and services, where some popular providers managing people identity information and personal data allow their users to delegate third party Web services to access their data. In this paper, we analyze the risks related to untrusted providers not behaving correctly, and we solve this problem by proposing the first verifiable delegated authorization protocol that allows third party services to verify the correctness of users data returned by the provider. The contribution of the paper is twofold: we show how delegated authorization can be cryptographically enforced through authenticated data structures protocols, we extend the standard OAuth2 protocol by supporting efficient and verifiable delegated authorization including database updates and privileges revocation. Luca Ferretti, Mirco Marchetti, Michele Colajanni |
COMPSAC (2) | 3 |
| 2017 | Identifying malicious hosts involved in periodic communicationsabstractAfter many research efforts, Network Intrusion Detection Systems still have much room for improvement. This paper proposes a novel method for automatic and timely analysis of traffic generated by large networks, which is able to identify malicious external hosts even if their activities do not raise any alert by existing defensive systems. Our proposal focuses on periodic communications, since our experimental evaluation shows that they are more related to malicious activities, and it can be easily integrated with other detection systems. We highlight that periodic network activities can occur at very different intervals ranging from seconds to hours, hence a timely analysis of long time-windows of the traffic generated by large organizations is a challenging task in itself. Existing work is primarily focused on identifying botnets, whereas the method proposed in this paper has a broader target and aims to detect external hosts that are likely involved in any malicious operation. Since malware-related network activities can be considered as rare events in the overall traffic, the output of the proposed method is a manageable graylist of external hosts that are characterized by a considerably higher likelihood of being malicious compared to the entire set of external hosts contacted by the monitored large network. A thorough evaluation on a real large network traffic demonstrates the effectiveness of our proposal, which is capable of automatically selecting only dozens of suspicious hosts from hundreds of thousands, thus allowing security operators to focus their analyses on few likely malicious targets. Giovanni Apruzzese, Mirco Marchetti, Michele Colajanni, Gabriele Gambigliani Zoccoli, Alessandro Guido |
NCA | 3 |
| 2016 | Implementation of Verified Set Operation Protocols Based on Bilinear Accumulators
Luca Ferretti, Michele Colajanni, Mirco Marchetti |
CANS | 2 |
| 2016 | Guaranteeing Correctness of Bulk Operations in Outsourced Databases
Luca Ferretti, Michele Colajanni, Mirco Marchetti |
DBSec | 2 |
| 2016 | Analysis of high volumes of network traffic for Advanced Persistent Threat detection
Mirco Marchetti, Fabio Pierazzi, Michele Colajanni, Alessandro Guido |
Comput. Networks | 3 |
| 2016 | Exploratory security analytics for anomaly detection
Fabio Pierazzi, Sara Casolari, Michele Colajanni, Mirco Marchetti |
Comput. Secur. | 3 |
| 2015 | Enforcing Correct Behavior without Trust in Cloud Key-Value DatabasesabstractTraditional computation outsourcing and modern cloud computing are affected by a common risk of distrust between service requestor and service provider. We propose a novel protocol, named Probus, that offers guarantees of correct behavior to both parts without assuming any trust relationship between them in the context of cloud-based key-value databases. Probus allows a service requestor to have evidence of cloud provider misbehavior on its data, and a cloud provider to defend itself from false accusations by demonstrating the correctness of its operations. Accusation and defense proofs are based on cryptographic mechanisms that can be verified by a third party. Probus improves the state-of-the-art by introducing novel solutions that allow for efficient verification of data security properties and by limiting the overhead required to provide its security guarantees. Thanks to Probus it is possible to check the correctness of all the results generated by a cloud service, thus improving weaker integrity assurance based on probabilistic verifications that are adopted by related work. Andrea Andreoli, Luca Ferretti, Mirco Marchetti, Michele Colajanni |
CSCloud | 4 |
| 2015 | A collaborative framework for intrusion detection in mobile networks
Mauro Andreolini, Michele Colajanni, Mirco Marchetti |
Inf. Sci. | 2 |
| 2015 | Adaptive, scalable and reliable monitoring of big data on clouds
Mauro Andreolini, Michele Colajanni, Marcello Pietri, Stefania Tosi |
J. Parallel Distributed Comput. | 2 |
| 2014 | Efficient detection of unauthorized data modification in cloud databasesabstractCloud services represent an unprecedented opportunity, but their adoption is hindered by confidentiality and integrity issues related to the risks of outsourcing private data to cloud providers. This paper focuses on integrity and proposes an innovative solution that allows cloud tenants to detect unauthorized modifications to outsourced data while minimizing storage and network overheads. Our approach is based on encrypted Bloom filters, and is designed to allow efficient integrity verification for databases stored in the cloud. We assess the effectiveness of the proposal as well as its performance improvements with respect to existing solutions by evaluating storage and network costs. Luca Ferretti, Fabio Pierazzi, Michele Colajanni, Mirco Marchetti, Marcello Missiroli |
ISCC | 3 |
| 2014 | Detecting correlation between server resources for system management
Stefania Tosi, Sara Casolari, Michele Colajanni |
J. Comput. Syst. Sci. | 3 |
| 2014 | Performance and Cost Evaluation of an Adaptive Encryption Architecture for Cloud DatabasesabstractThe cloud database as a service is a novel paradigm that can support several Internet-based applications, but its adoption requires the solution of information confidentiality problems. We propose a novel architecture for adaptive encryption of public cloud databases that offers an interesting alternative to the tradeoff between the required data confidentiality level and the flexibility of the cloud database structures at design time. We demonstrate the feasibility and performance of the proposed solution through a software prototype. Moreover, we propose an original cost model that is oriented to the evaluation of cloud database services in plain and encrypted instances and that takes into account the variability of cloud prices and tenant workloads during a medium-term period. Luca Ferretti, Fabio Pierazzi, Michele Colajanni, Mirco Marchetti |
IEEE Trans. Cloud Comput. | 3 |
| 2014 | Scalable Architecture for Multi-User Encrypted SQL Operations on Cloud Database ServicesabstractThe success of the cloud database paradigm is strictly related to strong guarantees in terms of service availability, scalability and security, but also of data confidentiality. Any cloud provider assures the security and availability of its platform, while the implementation of scalable solutions to guarantee confidentiality of the information stored in cloud databases is an open problem left to the tenant. Existing solutions address some preliminary issues through SQL operations on encrypted data. We propose the first complete architecture that combines data encryption, key management, authentication and authorization solutions, and that addresses the issues related to typical threat scenarios for cloud database services. Formal models describe the proposed solutions for enforcing access control and for guaranteeing confidentiality of data and metadata. Experimental evaluations based on standard benchmarks and real Internet scenarios show that the proposed architecture satisfies also scalability and performance requirements. Luca Ferretti, Fabio Pierazzi, Michele Colajanni, Mirco Marchetti |
IEEE Trans. Cloud Comput. | 3 |
| 2014 | Distributed, Concurrent, and Independent Access to Encrypted Cloud DatabasesabstractPlacing critical data in the hands of a cloud provider should come with the guarantee of security and availability for data at rest, in motion, and in use. Several alternatives exist for storage services, while data confidentiality solutions for the database as a service paradigm are still immature. We propose a novel architecture that integrates cloud database services with data confidentiality and the possibility of executing concurrent operations on encrypted data. This is the first solution supporting geographically distributed clients to connect directly to an encrypted cloud database, and to execute concurrent and independent operations including those modifying the database structure. The proposed architecture has the further advantage of eliminating intermediate proxies that limit the elasticity, availability, and scalability properties that are intrinsic in cloud-based solutions. The efficacy of the proposed architecture is evaluated through theoretical analyses and extensive experimental results based on a prototype implementation subject to the TPC-C standard benchmark for different numbers of clients and network latencies. Luca Ferretti, Michele Colajanni, Mirco Marchetti |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2013 | Access Control Enforcement on Query-Aware Encrypted Cloud DatabasesabstractThe diffusion of cloud database services requires a lot of efforts to improve confidentiality of data stored in external infrastructures. We propose a novel scheme that integrates data encryption with users access control mechanisms. It can be used to guarantee confidentiality of data with respect to a public cloud infrastructure, and to minimize the risks of internal data leakage even in the worst case of a legitimate user colluding with some cloud provider personnel. The correctness and feasibility of the proposal is demonstrated through formal models, while the integration in a cloud-based architecture is left to future work. Luca Ferretti, Michele Colajanni, Mirco Marchetti |
CloudCom (2) | 2 |
| 2013 | Real-time adaptive algorithm for resource monitoringabstractIn large scale systems, real-time monitoring of hardware and software resources is a crucial means for any management purpose. In architectures consisting of thousands of servers and hundreds of thousands of component resources, the amount of data monitored at high sampling frequencies represents an overhead on system performance and communication, while reducing sampling may cause quality degradation. We present a real-time adaptive algorithm for scalable data monitoring that is able to adapt the frequency of sampling and data updating for a twofold goal: to minimize computational and communication costs, to guarantee that reduced samples do not affect the accuracy of information about resources. Experiments carried out on heterogeneous data traces referring to synthetic and real environments confirm that the proposed adaptive approach reduces utilization and communication overhead without penalizing the quality of data with respect to existing monitoring algorithms. Mauro Andreolini, Michele Colajanni, Marcello Pietri, Stefania Tosi |
CNSM | 2 |
| 2013 | Data clustering based on correlation analysis applied to highly variable domains
Stefania Tosi, Sara Casolari, Michele Colajanni |
Comput. Networks | 3 |
| 2013 | Algorithms for Web service selection with static and dynamic requirements
Claudia Canali, Michele Colajanni, Riccardo Lancellotti |
Serv. Oriented Comput. Appl. | 2 |
| 2012 | A Novel Intermediary Framework for Dynamic Edge Service Composition
Claudia Canali, Michele Colajanni, Delfina Malandrino, Vittorio Scarano, Raffaele Spinelli |
J. Comput. Sci. Technol. | 2 |
| 2012 | Dual time-scale distributed capacity allocation and load redirect algorithms for cloud systems
Danilo Ardagna, Sara Casolari, Michele Colajanni, Barbara Panicucci |
J. Parallel Distributed Comput. | 3 |
| 2011 | Dynamic Request Management Algorithms for Web-Based Services in Cloud ComputingabstractProviders of Web-based services can take advantage of many convenient features of cloud computing infrastructures, but they still have to implement request management algorithms that are able to face sudden peaks of requests. We consider distributed algorithms implemented by front-end servers to dispatch and redirect requests among application servers. Current solutions based on load-blind algorithms, or considering just server load and thresholds are inadequate to cope with the demand patterns reaching modern Internet application servers. In this paper, we propose and evaluate a request management algorithm, namely Performance Gain Prediction, that combines several pieces of information (server load, computational cost of a request, user session migration and redirection delay) to predict whether the redirection of a request to another server may result in a shorter response time. To the best of our knowledge, no other study combines information about infrastructure status, user request characteristics and redirection overhead for dynamic request management in cloud computing. Our results show that the proposed algorithm is able to reduce the response time with respect to existing request management algorithms operating on the basis of thresholds. Riccardo Lancellotti, Mauro Andreolini, Claudia Canali, Michele Colajanni |
COMPSAC | 4 |
| 2011 | Defeating NIDS evasion in Mobile IPv6 networksabstractThe diffusion of mobile devices and technologies supporting transparent network mobility can have detrimental effects on network security. We describe how an attacker can lever-age mobility in IPv6 networks to perpetrate known attacks while evading detection by state-of-the-art Network Intrusion Detection Systems (NIDSs). We then propose a new defense strategy based on the exchange of state information among distributed NIDSs. We demonstrate the effectiveness of the proposed solution through a prototype implementation, evaluated experimentally in a Mobile IPv6 network. Michele Colajanni, Luca Dal Zotto, Mirco Marchetti, Michele Messori |
WOWMOM | 1 |
| 2010 | Real-time models supporting resource management decisions in highly variable systemsabstractData centers providing modern interactive applications are enriched by autonomous management decision systems that are able to clone and migrate virtual machines, to re-distribute resources or to re-map services in real-time. At the basis of all these decisions, there is the need of a continuous evaluation of the state of system resources and of detecting when some relevant changes are occurring. Unfortunately, the load of interactive applications reaching the system is intrinsically heterogeneous with consequent highly variable effects on the resource behavior emerging from system monitors. Hence, existing algorithms for online detection of state changes are affected by low precision and scarce robustness when they are applied to modern contexts. We propose a novel model for online detection of relevant state changes that combines a filtered representation of the raw measures with adaptive detection rules. Experiments carried out on real and emulated data sets confirm that the proposed model is able to timely signal all relevant state changes, to limit false detections and, even more important, its results are robust in highly variable contexts. Sara Casolari, Michele Colajanni, Stefania Tosi, Francesco Lo Presti |
IPCCC | 2 |
| 2010 | Characteristics and evolution of content popularity and user relations in social networksabstractSocial networks have changed the characteristics of the traditional Web and these changes are still ongoing. Nowadays, it is impossible to design valid strategies for content management, information dissemination and marketing in the context of a social network system without considering the popularity of its content and the characteristics of the relations among its users. By analyzing two popular social networks and comparing current results with studies dating back to 2007, we confirm some previous results and we identify novel trends that can be utilized as a basis for designing appropriate content and system management strategies. Our analyses confirm the growth of the two social networks in terms of quantity of contents and numbers of social links among the users. The social navigation is having an increasing influence on the content popularity because the social links are representing a primary method through which the users search and find contents. An interesting novel trend emerging from our study is that subsets of users have major impact on the content popularity with respect to previous analyses, with evident consequences on the possibility of implementing content dissemination strategies, such as viral marketing1. Claudia Canali, Michele Colajanni, Riccardo Lancellotti |
ISCC | 2 |
| 2010 | Resource Management Strategies for the Mobile Web
Claudia Canali, Michele Colajanni, Riccardo Lancellotti |
Mob. Networks Appl. | 2 |
| 2010 | MIMOSA: context-aware adaptation for ubiquitous web access
Delfina Malandrino, Francesca Mazzoni, Daniele Riboni, Claudio Bettini, Michele Colajanni, Vittorio Scarano |
Pers. Ubiquitous Comput. | 5 |
| 2009 | Peer-to-Peer Architecture for Collaborative Intrusion and Malware Detection on a Large Scale
Mirco Marchetti, Michele Messori, Michele Colajanni |
ISC | 3 |
| 2009 | Runtime state change detector of computer system resources under non stationary conditionsabstractAll runtime management decisions in computer and information systems require immediate detection of relevant changes in the state of their resources. This is accomplished by continuously monitoring the performance/utilization of key system resources and by using appropriate statistical tests to detect the occurance of significant state changes. Unfortunately, the complexity of today systems and applications and the unpredictability of user request patterns result in highly variable and non stationary time series which are difficult to analyze. As a consequence, present solutions for detecting state changes at runtime are affected by excessive time delays or false positives. We propose a novel ¿agile¿ runtime detector that solves the delay vs. false positive tradeoff: it is able to detect the relevant state changes as fast as the best reactive models with the lowest percentages of false positives. All evaluations carried out for a large set of scenarios confirm the efficacy and robustness of the proposed model. Sara Casolari, Michele Colajanni, Francesco Lo Presti |
MASCOTS | 2 |
| 2009 | Short-term prediction models for server management in Internet-based contexts
Sara Casolari, Michele Colajanni |
Decis. Support Syst. | 2 |
| 2008 | Runtime Prediction Models for Internet-based Systems
Sara Casolari, Mauro Andreolini, Michele Colajanni |
MASCOTS | 3 |
| 2008 | Collaborative architecture for malware detection and analysis
Michele Colajanni, Daniele Gozzi, Mirco Marchetti |
SEC | 1 |
| 2008 | Resource Management Strategies for Mobile Web-Based ServicesabstractThe great diffusion of Mobile Web-enabled devices allows the implementation of novel personalization, location and adaptation services that will place unprecedented strains on the server infrastructure of the content provider. This paper has a twofold contribution. First, we analyze the five-years trend of Mobile Web-based applications in terms of workload characteristics of the most popular services and their impact on the server infrastructures. As the technological improvements at the server level in the same period of time are insufficient to face the computational requirements of the future Mobile Web-based services, we propose and evaluate adequate resource management strategies. We demonstrate that pre-adaptating a small fraction of the most popular resources can reduce the response time up to one third thus facing the increased computational impact of the future Mobile Web-based services. Claudia Canali, Michele Colajanni, Riccardo Lancellotti |
WiMob | 2 |
| 2008 | Models and framework for supporting runtime decisions in Web-based systemsabstractEfficient management of distributed Web-based systems requires several mechanisms that decide on request dispatching, load balance, admission control, request redirection. The algorithms behind these mechanisms typically make fast decisions on the basis of the load conditions of the system resources. The architecture complexity and workloads characterizing most Web-based services make it extremely difficult to deduce a representative view of a resource load from collected measures that show extreme variability even at different time scales. Hence, any decision based on instantaneous or average views of the system load may lead to useless or even wrong actions. As an alternative, we propose a two-phase strategy that first aims to obtain a representative view of the load trend from measured system values and then applies this representation to support runtime decision systems. We consider two classical problems behind decisions: how to detect significant and nontransient load changes of a system resource and how to predict its future load behavior. The two-phase strategy is based on stochastic functions that are characterized by a computational complexity that is compatible with runtime decisions. We describe, test, and tune the two-phase strategy by considering as a first example a multitier Web-based system that is subject to different classes of realistic and synthetic workloads. Also, we integrate the proposed strategy into a framework that we validate by applying it to support runtime decisions in a cluster Web system and in a locally distributed Network Intrusion Detection System. Mauro Andreolini, Sara Casolari, Michele Colajanni |
ACM Trans. Web | 3 |
| 2007 | Enhancing interoperability and stateful analysis of cooperative network intrusion detection systemsabstractA traditional Network Intrusion Detection System (NIDS) is based on a centralized architecture that does not satisfy the needs of most modern network infrastructures characterized by high traffic volumes and complex topologies. The of decentralized NIDS based on multiple sensors is that each of them gets just a partial view of the network traffic and this prevents a stateful and fully reliable traffic analysis. We propose a novel cooperation mechanism that the previous issues through an innovative state management and state migration framework. It allows multiple decentralized sensors to share their internal state, thus accomplishing innovative and powerful traffic analysis. The advanced functionalities and performance of the proposed cooperative framework for network intrusion detection systems are demonstrated through a fully operative prototype. Michele Colajanni, Daniele Gozzi, Mirco Marchetti |
ANCS | 1 |
| 2007 | Trend-based Load Balancer for a Multi-tier Distributed SystemabstractThe unexpected and continuous changes of the workload reaching any Internet-based service make really difficult to guarantee a balanced utilization of the server resources. In this paper, we propose a novel class of state-aware dispatching algorithms that take into account not only the present resource load but also the behavioral trend of the server load, that is, whether it is increasing, decreasing or oscillating. We apply one algorithm of this class to a multitier Web-based system and demonstrate that it is able to improve load balancing of the most critical server resources. Mauro Andreolini, Sara Casolari, Michele Colajanni |
MASCOTS | 3 |
| 2007 | Dynamic load balancing for network intrusion detection systems based on distributed architecturesabstractIncreasing traffic and the necessity of stateful analyses impose strong computational requirements on network intrusion detection systems (NIDS), and motivate the need of distributed architectures with multiple sensors. In a context of high traffic with heavy tailed characteristics, static rules for dispatching traffic slices among distributed sensors cause severe imbalance. Hence, the distributed NIDS architecture must be combined with adequate mechanisms for dynamic load redistribution. In this paper, we propose and compare different policies for the activation/deactivation of the dynamic load balancer. In particular, we consider and compare single vs. double threshold schemes, and load representations based on resource measures vs. load aggregation models. Our experimental results show that the best combination of a double threshold scheme with a linear aggregation of resource measures is able to achieve a really satisfactory balance of the sensor loads together with a sensible reduction of the number of load balancer activations. Mauro Andreolini, Sara Casolari, Michele Colajanni, Mirco Marchetti |
NCA | 3 |
| 2007 | A Distributed Infrastructure Supporting Personalized Services for the Mobile Web
Claudia Canali, Michele Colajanni, Riccardo Lancellotti, Philip S. Yu |
WiMob | 2 |
| 2006 | Distribution of Adaptation Services for Ubiquitous Web AccesDriven by User ProfilesabstractThe popularity of ubiquitous Web access requires runtime adaptations of the Web contents. A significant trend in these content adaptation services is the growing amount of personalization required by users. Personalized services are and will be a key feature for the success of the ubiquitous Web, but they open two critical issues: performance and profile management. Issues related to the performance of adaptation services are typically addressed by highly distributed architectures with a large number of nodes located closer to user. On the other hand, the management of user profile must take into account the nature of these data that may contain sensitive information, such as geographic position, navigation history and personal preferences that should be kept private. In this paper, we investigate the impact that a correct profile management has on distributed infrastructures that provide content adaptation services for ubiquitous Web access. In particular, we propose and compare two scalable solutions of adaptation services deployed on the nodes of a two-level topology. We study, through real prototypes, the performance and the constraints that characterize the proposed architectures. Claudia Canali, Michele Colajanni, Riccardo Lancellotti |
ISCC | 2 |
| 2006 | A Distributed Architecture for Gracefully Degradable Web-Based ServicesabstractModern Web sites provide multiple services that are often deployed through distributed architectures. The importance and the economic impact of Web-based services introduces significant requirements in terms of performance and quality of service. In this paper, we propose an access control mechanism for dynamic, Web-based systems. The proposed architecture takes into account two goals: the service of all requests pertaining to an admitted session until system saturation, and a graceful, controlled degradation of performance in case of overwhelming user request loads. The session-oriented behavior is obtained through an admission control mechanism that denies access to requests starting new sessions if the system is judged as overloaded. Graceful degradation is achieved through the refusal of single requests with increasing priority. Static priorities, determined for example, by the user category (guest, member, gold) are taken into account first. If the system is still in overload, the access control mechanism evaluates dynamically the popularity of single requests, and drops the least popular requests Mauro Andreolini, Sara Casolari, Michele Colajanni |
NCA | 3 |
| 2005 | A Scalable Framework for the Support of Advanced Edge Services
Michele Colajanni, Raffaella Grieco, Delfina Malandrino, Francesca Mazzoni, Vittorio Scarano |
HPCC | 1 |
| 2005 | Hybrid cooperative schemes for scalable and stable performance of Web content delivery
Riccardo Lancellotti, Francesca Mazzoni, Michele Colajanni |
Comput. Networks | 3 |
| 2004 | Topic 18: Peer-to-Peer and Web Computing
Seif Haridi, Karl Aberer, Peter Van Roy, Michele Colajanni |
Euro-Par | 4 |
| 2003 | Kernel-based Web switches providing content-aware routingabstractLocally distributed Web server systems represent a cost-effective solution to the performance problems due to high traffic volumes reaching popular Web sites. In this paper we focus on architectures based on layer-7 Web switches because they allow a much richer set of possibilities for the Web site architecture, at the price of a scalability much lower than that provided by a layer-4 switch. In this paper we compare the performance of three solutions for layer-7 Web switch: a two-way application-layer architecture, a two-way kernel-based architecture, and a one-way kernel-based architecture. We show quantitatively how much better the one-way architecture performs with respect to a two-way scheme, even if implemented at the kernel level. We conclude that an accurate implementation of a layer-7 Web switch may become a viable solution to the performance requirements of the majority of cluster-based information systems. Mauro Andreolini, Michele Colajanni, Marcello Nuccio |
NCA | 2 |
| 2003 | Distributed Cooperation Schemes for Document Lookup in Multiple Cache ServersabstractArchitectures consisting of multiple cache servers are a popular solution to deal with performance and network resource utilization issues related to the growth of the Web request. Cache cooperation is often carried out through purely hierarchical and flat schemes that suffer from scalability problems when the number of servers increases. We propose, implement and compare the performance of three novel distributed cooperation models based on a two-tier organization of the cache servers. The experimental results show that the proposed architectures are effective in supporting cooperative document lookup and download They guarantee cache hit rates comparable to those of the most performing protocols with a significant reduction of the cooperation overhead Moreover in case of congested network, they reduce the 90-percentile of the system response time up to nearly 30% with respect to the best pure cooperation mechanisms. Riccardo Lancellotti, Bruno Ciciani, Michele Colajanni |
NCA | 3 |
| 2003 | Request Redirection Algorithms for Distributed Web SystemsabstractReplication of information among multiple servers is necessary to support high request rates to popular Web sites. We consider systems that maintain one interface to users, even it they consist of multiple nodes with visible IP addresses that are distributed among different networks. In these systems, first-level dispatching is achieved through the Domain Name System (DNS) during the address lookup phase. Distributed Web systems can use a request redirection mechanism as second-level dispatching because the DNS routing scheme has limited control on offered load. Redirection is always executed by the servers, but there are many alternatives that are worth investigating. We explore the combination of DNS dispatching with redirection schemes that use centralized or distributed control on the basis of global or local state information. In fully distributed schemes, DNS dispatching is carried out by simple algorithms because load sharing is taken by some redirection mechanisms that each server activates autonomously. On the other hand, in fully centralized schemes, redirection is used as a tool to enforce decisions taken by the same centralized entity that provides the first-level dispatching. We also investigate hybrid strategies. We conclude that distributed algorithms are preferable over their centralized counterpart because they provide stable performance, take content-aware dispatching decisions, limit the percentage of redirected requests, and their implementation is much simpler than that required by centralized schemes. Valeria Cardellini, Michele Colajanni, Philip S. Yu |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2002 | Performance analysis of adaptive wormhole routing in a two-dimensional torus
Francesco Quaglia, Bruno Ciciani, Michele Colajanni |
Parallel Comput. | 3 |
| 2002 | A Performance Study of Robust Load Sharing Strategies for Distributed Heterogeneous Web Server SystemsabstractReplication of information across multiple servers is becoming a common approach to support popular Web sites. A distributed architecture with some mechanisms to assign client requests to Web servers is more scalable than any centralized or mirrored architecture. In this paper, we consider distributed systems in which the Authoritative Domain Name Server (ADNS) of the Web site takes the request dispatcher role by mapping the URL hostname into the IP address of a visible node, that is, a Web server or a Web cluster interface. This architecture can support local and geographical distribution of the Web servers. However, the ADNS controls only a very small fraction of the requests reaching the Web site because the address mapping is not requested for each client access. Indeed, to reduce Internet traffic, address resolution is cached at various name servers for a time-to-live (TTL) period. This opens an entirely new set of problems that traditional centralized schedulers of parallel/distributed systems do not have to face. The heterogeneity assumption on Web node capacity, which is much more likely in practice, increases the order of complexity of the request assignment problem and severely affects the applicability and performance of the existing load sharing algorithms. We propose new assignment strategies, namely adaptive TTL schemes, which tailor the TTL value for each address mapping instead of using a fixed value for all mapping requests. The adaptive TTL schemes are able to address both the nonuniformity of client requests and the heterogeneous capacity of Web server nodes. Extensive simulations show that the proposed algorithms are very effective in avoiding node overload, even for high levels of heterogeneity and limited ADNS control. Michele Colajanni, Philip S. Yu |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2001 | Two-Tier Cooperation: A Scalable Protocol for Web Cache SharingabstractThe benefits of Web caching can be improved by systems of cooperative cache servers that share their cached documents. The increasing number of Web cache servers over the Internet makes the scalability of the cooperation protocol a major issue to be addressed. In this paper, we propose the Two-Tier Cooperation (2TC) protocol, which is specifically designed for systems of dozens or hundreds of cache servers with no centralized control. 2TC embeds two classical cooperation approaches for distributed Web caching systems, namely informed cooperation (IC) and query cooperation (QC), that are applied within different subsets of cache servers in the system. IC is applied within subsets of close servers and lets them cooperate through mutual exchange of state information related to their cache content. QC lets more distant cache servers cooperate through query/reply messages to locate documents within the global cache. Thanks to the use of IC among close cache servers, QC can explore the cache content of several cache servers through a single query message. High scalability arises as few queries explore the cache content of many cache servers and state information is exchanged within small groups of close cache servers. We report experimental results based on real traces that compare a prototype implementation of 2TC with classical protocols of the informed and query classes. The results point out a strong reduction (up to 50%) of the amount of transferred information to manage cooperation. This overhead reduction is achieved with no performance degradation in terms of latency and cache hit rate. Andrea Santoro, Bruno Ciciani, Francesco Quaglia, Michele Colajanni |
NCA | 4 |
| 2001 | A client-aware dispatching algorithm for web clusters providing multiple servicesabstractThe typical Web cluster architecture consists of replicated back-end and Web servers, and a network Web switch that routes client requests among the nodes. In this paper, we propose a new scheduling policy, namely client-awarepolicy (CAP), for Web switches operating at layer-7 of the OSI protocol stack. Its goal is to improve load sharing in Web clusters that provide multiple services such as static, dynamic and secure information. CAP classies the clientrequestson the basis of their expected impact on main server resources, that is, network interface, CPU, disk. At run-time, CAP schedules client requests reaching the Web cluster with the goal of sharing all classes of services among the server nodes. We demonstrate through a large set of simulations and some prototype experiments that dispatching policies aiming to improve locality in server caches give best results for Web publishing sites providing static information and some simple database searches. When we consider Web sites providing also dynamic and secure services, CAP is more eective than state-of-the-art layer-7 Web switch policies. The proposed client-aware algorithm is also more robust than server-aware policies whose performance depends on optimal tuning of system parameters, veryhardtoachieveina highly dynamic system suchasaWeb site. Categories and Subject Descriptors C.2.4 [######## ############# ########]: Distributed Systems; C.4 [########### ## #######]: Design studies; H.3.5 [########### ####### ### #########]: Online Information Services|Web-based services General Terms Algorithms, Design, Performance Keywords Load balancing, Dispatching algorithms, Clusters Copyright is held by the author/owner. WWW10, May 1-5, 2001, Hong Kong. Copyright 2001 ACM 1-58113-348-0/01/0005 ...$5.00. 1. Emiliano Casalicchio, Michele Colajanni |
WWW | 2 |
| 2001 | Mechanisms for quality of service in Web clusters
Valeria Cardellini, Emiliano Casalicchio, Michele Colajanni, Salvatore Tucci |
Comput. Networks | 3 |
| 2000 | Scalable Web Clusters with Static and Dynamic ContentsabstractCluster systems are leading architectures for building popular Web sites that have to guarantee scalable services when the number of accesses grows exponentially. The most common Web cluster systems consist of replicated back-end and Web servers and a Web switch that routes client requests among the nodes. We propose a new scheduling policy, namely Multi-Class Round Robin (MC-RR) for Web switches operating at layer 7 of the OSI protocol stack. Its goal is to improve load sharing in recent Web clusters that provide multiple services such as static and dynamic information. We demonstrate through a wide set of simulation experiments that other dispatching policies aiming to improve locality in server caches give best results for traditional Web publishing sites providing static information and some simple database searches. On the other hand, when we consider more recent Web sites providing highly dynamic services, MC-RR is much more effective than state-of-the-art Web switch policies. The proposed algorithm has the additional benefit of guaranteeing stable results because its performance does not depend on several parameters that are very hard to tune in highly variable Web systems. Emiliano Casalicchio, Michele Colajanni |
CLUSTER | 2 |
| 2000 | Geographic Load Balancing for Scalable Distributed Web SystemsabstractUsers of highly popular Web sites may experience long delays when accessing information. Upgrading content site infrastructure from a single node to a locally distributed Web cluster composed by multiple server nodes provides limited relief, because the cluster wide-area connectivity may become the bottleneck. A better solution is to distribute Web clusters over the Internet by placing content nodes in strategic locations. A geographically distributed architecture where the Domain Name System (DNS) servers evaluate network proximity and users are served from the closest cluster reduces network impact on response time. On the other hand, serving closest requests only may cause unbalanced servers and may increase system impact on response time. To achieve a scalable Web system, we propose to integrate DNS proximity scheduling with an HTTP request redirection mechanism that any Web server can activate. We demonstrate through simulation experiments that this further dispatching mechanism augments the percentage of requests with guaranteed response time, thereby enhancing the Quality of Service of geographically distributed Web sites. However, HTTP request redirection should be used selectively because the additional round-trip increases network impact on latency time experienced by users. As a further contribution, this paper proposes and compares various mechanisms to limit reassignments with no negative consequences on load balancing. Valeria Cardellini, Michele Colajanni, Philip S. Yu |
MASCOTS | 2 |
| 2000 | A hierarchical approach for bounding the completion time distribution of stochastic task graphs
Michele Colajanni, Francesco Lo Presti, Salvatore Tucci |
Perform. Evaluation | 1 |
| 2000 | PSBLAS: a library for parallel linear algebra computation on sparse matricesabstractMany computationally intensive problems in engineering and science give rise to the solution of large, sparse, linear systems of equations. Fast and efficient methods for their soltion are very important because these systems usually occur in the innermost loop of the computational scheme. Parallelization is often necessary to achieve an acceptable level of performance. This paper presents the design, implementation, and interface of a library of Basic Linear Algebra Subroutines for sparse matrices (PSBLAS) which is specifically tailored to distributed-memory computers. PSBLAS enables easy, efficient, and portable implementations of parallel iterative solvers for linear systems. The interface keeps in view a Single Program Multiple Data programming model on distributed-memory machines. However, the architecture of the library does not exclude an implementation in different paradigms, such as those based on the shared-memory model. Salvatore Filippone, Michele Colajanni |
ACM Trans. Math. Softw. | 2 |
| 1999 | Performance Analysis of Wormhole Switching with Adaptive Routing in a Two-Dimensional Torus
Michele Colajanni, Bruno Ciciani, Francesco Quaglia |
Euro-Par | 1 |
| 1999 | Redirection Algorithms for Load Sharing in Distributed Web-server SystemsabstractReplication of information among multiple World Wide Web servers is necessary to support high request rates to popular Web sites. A clustered Web server organization is preferable to multiple independent mirrored servers because it maintains a single interface to the users and has the potential to be more scalable, fault-tolerant and better load-balanced. In this paper, we propose a Web cluster architecture in which the Domain Name System (DNS) server, which dispatches the user requests among the servers through the URL name to the IP address mapping mechanism, is integrated with a redirection request mechanism based on HTTP. This should alleviate the side-effect of caching the IP address mapping at intermediate name servers. We compare many alternative mechanisms, including synchronous vs. asynchronous activation and centralized vs. distributed decisions on redirection. Moreover, we analyze the reassignment of entire domains or individual client requests, different types of status information and different server selection policies for redirecting requests. Our results show that the combination of centralized and distributed dispatching policies allows the Web server cluster to handle high load skews in the WWW environment. Valeria Cardellini, Michele Colajanni, Philip S. Yu |
ICDCS | 2 |
| 1999 | An Analytical Comparison of Cooperation Protocols for Web Proxy ServersabstractSharing cached documents among cooperative Web proxies is an effective solution to reduce Web traffic and alleviate network bottlenecks. This paper aims at comparing the performance of two cooperation protocols which follow opposite approaches: the Internet Cache Protocol (ICP) and the Full Informed Protocol (FIP). The former activates information exchange among proxies on client demand; the latter guarantees that any proxy is kept informed about the cache content of all the other cooperative proxies. The performance comparison is carried out through analytical models determining under which conditions one protocol outperforms the other. Our analysis shows that ICP is often preferable to FIP, thus pointing out that the client demand based approach is an effective solution for proxy cooperation. Francesco Quaglia, Bruno Ciciani, Michele Colajanni |
MASCOTS | 3 |
| 1999 | DNS Dispatching Algorithms with State Estimators for Scalable Web-Server Clusters
Valeria Cardellini, Michele Colajanni, Philip S. Yu |
World Wide Web | 2 |
| 1998 | Efficient State Estimators for Load Control Policies in Scalable Web Server ClustersabstractReplication of information across a server cluster provides a promising way to support popular Web sites. However a Web server cluster requires some mechanism for directing requests to the best server. One common approach is to use the Domain Name Server (DNS) as a centralized schedule. However address caching mechanisms and the non-uniformity of the load from different client domains complicate the load balancing issue and make existing scheduling algorithms for traditional distributed systems not applicable to Web server clusters. We consider the theoretical DNS policies that require some system state information. We extend them to realistic situations where state information needs to be estimated with low computation and communication overhead. We show that by incorporating these estimators into the DNS policies, load balancing improves substantially, even if the DNS control is limited to a small portion of client requests. Valeria Cardellini, Michele Colajanni, Philip S. Yu |
COMPSAC | 2 |
| 1998 | Dynamic Load Balancing in Geographically Distributed Heterogeneous Web ServersabstractWith ever increasing Web traffic, a distributed multi server Web site can provide scalability and flexibility to cope with growing client demands. Load balancing algorithms to spread the requests across multiple Web servers are crucial to achieve the scalability. Various domain name server (DNS) based schedulers have been proposed in the literature, mainly for multiple homogeneous servers. The presence of heterogeneous Web servers not only increases the complexity of the DNS scheduling problem, but also makes previously proposed algorithms for homogeneous distributed systems not directly applicable. This leads us to propose new policies, cabled adaptive TTL algorithms, that take into account both the uneven distribution of client request rates and heterogeneity of Web servers to adaptively set the time-to-live (TTL) value for each address mapping request. Extensive simulation results show that these strategies are robust and effective in balancing load among geographically distributed heterogeneous Web servers. Michele Colajanni, Philip S. Yu, Valeria Cardellini |
ICDCS | 1 |
| 1998 | Threshold-Based Reconfiguration Strategies for Gracefully Degradable Parallel Computations
Michele Colajanni, Vincenzo Grassi, Michele Angelaccio |
J. Parallel Distributed Comput. | 1 |
| 1998 | Performance evaluation of deterministic wormhole routing in k-ary n-cubes
Bruno Ciciani, Michele Colajanni, Claudio Paolucci |
Parallel Comput. | 2 |
| 1998 | Performance Analysis of Circuit-Switching Interconnection Networks with Deterministic and Adaptive Routing
Michele Colajanni, Bruno Ciciani, Salvatore Tucci |
Perform. Evaluation | 1 |
| 1998 | Analysis of Task Assignment Policies in Scalable Distributed Web-Server SystemsabstractA distributed multiserver Web site can provide the scalability necessary to keep up with growing client demand at popular sites. Load balancing of these distributed Web-server systems, consisting of multiple, homogeneous Web servers for document retrieval and a Domain Name Server (DNS) for address resolution, opens interesting new problems. In this paper, we investigate the effects of using a more active DNS which, as an atypical centralized scheduler, applies some scheduling strategy in routing the requests to the most suitable Web server. Unlike traditional parallel/distributed systems in which a centralized scheduler has full control of the system, the DNS controls only a very small fraction of the requests reaching the multiserver Web site. This peculiarity, especially in the presence of highly skewed load, makes it very difficult to achieve acceptable load balancing and avoid overloading some Web servers. This paper adapts traditional scheduling algorithms to the DNS, proposes new policies, and examines their impact under different scenarios. Extensive simulation results show the advantage of strategies that make scheduling decisions on the basis of the domain that originates the client requests and limited server state information (e.g., whether a server is overloaded or not). An initially unexpected result is that using detailed server information, especially based on history, does not seem useful in predicting the future load and can often lead to degraded performance. Michele Colajanni, Philip S. Yu, Daniel M. Dias |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 1997 | Scheduling Algorithms for Distributed Web ServersabstractA distributed Web system, consisting of multiple servers for data retrieval and a Domain Name Server (DNS) for address resolution, can provide the scalability necessary to keep up with growing client demand at popular sites. However, balancing the requests among these atypical distributed servers opens interesting new challenges. Unlike traditional distributed systems in which a centralized scheduler has full control of the system, the DNS controls only a small fraction of the requests reaching the Web site. This makes it very difficult to avoid overloading situations among the multiple Web servers. We adapt traditional scheduling algorithms to the DNS, propose new policies, and examine their impact. Extensive simulation results show the advantage of using strategies that schedule requests on the basis of the origin of the clients and very limited state information, such as whether a server is overloaded or not. Conversely, algorithms that use detailed state information often exhibit the worst performance. Michele Colajanni, Philip S. Yu, Daniel M. Dias |
ICDCS | 1 |
| 1997 | Dynamic data decomposition in a message-passing environment
Michele Angelaccio, Michele Colajanni |
J. Syst. Archit. | 2 |
| 1997 | Non-Uniform and Dynamic Domain Decompositions for Hypercomputing
Michele Cermele, Michele Colajanni |
Parallel Comput. | 2 |
| 1994 | The Row/Column Pivoting Strategy on Multicomputers
Michele Angelaccio, Michele Colajanni |
Parallel Comput. | 2 |
| 1994 | Subcube Matrix Decomposition: A Unifying View for LU Factorization on Multicomputers
Michele Angelaccio, Michele Colajanni |
Parallel Comput. | 2 |
| 1993 | Unifying and Optimizing Parallel Linear Algebra AlgorithmsabstractTwo issues in linear algebra algorithms for multicomputers are addressed. First, how to unify parallel implementations of the same algorithm in a decomposition-independent way. Second, how to optimize naive parallel programs maintaining the decomposition independence. Several matrix decompositions are viewed as instances of a more general allocation function called subcube matrix decomposition. By this meta-decomposition, a programming environment characterized by general primitives that allow one to design meta-algorithms independently of a particular decomposition. The authors apply such a framework to the parallel solution of dense matrices. This demonstrates that most of the existing algorithms can be derived by suitably setting the primitives used in the meta-algorithm. A further application of this programming style concerns the optimization of parallel algorithms. The idea to overlap communication and computation has been extended from 1-D decompositions to 2-D decompositions. Thus, a first attempt towards a decomposition-independent definition of such optimization strategies is provided.> Michele Angelaccio, Michele Colajanni |
IEEE Trans. Parallel Distributed Syst. | 2 |