Luciano Paschoal Gaspary

dblp:g/LPGaspary · DBLP profile ↗
← Back
100ranked-venue papers
10as first author
16since 2021 · last 2025
0000-0002-7561-5582ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 56 · 7 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-authorSystems, architecture and hardware · 2Software engineering, systems software and programming languages · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2025 Towards an ML Assisted DASH-based Architecture: Leveraging Predictive Network Analyses with Interpretability
Eduardo R. Peretto, Manoel Narciso Reis Soares Filho, Débora Cristina Santos Sousa, Luciano Paschoal Gaspary, Bruno Grisci
CNSM4
2025 Towards Programmable Low-End Networking: Research Challenges and Lessons Learned
abstract
The research agenda on programmable data planes has been primarily focused on high-end networking devices, driven by technical requirements derived from operations & management needs of large scale datacenters and cloud providers. In this paper, we argue in favor of a yet incipient but equally paramount and challenging topic in this agenda: research on programmable low-end devices, like Low-power wide-area network (LPWAN). One main motivation is “unlocking” LPWAN, enabling one to freely redefine how they parse and process packets by means of Domain-specific languages such as P4. In addition to reducing capital expenditure by allowing interoperability between devices from multiple vendors, programmability would open LPWAN to an entire novel class of use cases, like providing inclusive internet access to technologically marginalized populations (such as rural communities). To contribute to this emerging research agenda, we propose a conceptual architecture and demonstrate the technical feasibility of a Programmable LPWAN by means of a proof-of-concept prototype, built using off-the-shelf hardware. More importantly, we present and discuss valuable lessons towards the design of such devices, maintaining their popular characteristics (like low power, low cost, long rage) yet freely (re)programmable for a broader class of novel use cases.
Vinícius Boff Alves, Marcelo Basso, Laura Becker Ramos, Julien Guillemot, Andre Riker, Antônio J. G. Abelém, Luciano Paschoal Gaspary, Mohamed Faten Zhani, Jaime Galán-Jiménez, Juliano Araújo Wickboldt, Weverton Luis da Costa Cordeiro
NOMS7
2025 Bringing Programmable Low-End Networks to Life: A Field Study with an Off-the-Shelf Prototype
abstract
We present a prototype that could open the doors to mitigate digital exclusion in technologically underserved pop-ulations. By converging software-defined networks (SDN) with programmable data planes (PDP), our approach enables one to customize low-cost hardware to fit the network behavior. We integrate low-power wide-area networks (LPWANs), known for their scalability and efficiency, with PDPs to propose a flexible solution for changing requirements, such as distance and terrain configurations, validated through real-world test scenarios.
Marcelo Basso, Vinícius B. Alves, Laura B. Ramos, Julien Guillemot, Andre Riker, Antônio J. G. Abelém, Luciano Paschoal Gaspary, Mohamed Faten Zhani, Jaime Galán-Jiménez, Juliano Araújo Wickboldt, Weverton Luis da Costa Cordeiro
NOMS7
2025 RNA: Automating IDS/IPS Event Detection Offload into Programmable Forwarding Devices
abstract
Intrusion Detection and Prevention Systems (IDS/IPSs) are essential for identifying and preventing the increasingly complex and growing number of cyber-attacks. These systems analyze streams of network packets, providing ways to identify attack patterns and notify operators about possible threats. Nonetheless, server-only approaches are inefficient, overwhelming server resources since servers typically operate at a Mbps scale, which is drastically slower than the Tbps scale of high-speed networks. In this paper, we propose RNA, a system that offloads to programmable forwarding devices the identification of critical events (per-packet) that are “consumed” by IDS/IPSs, thereby reducing the resource overhead of a server-only solution. At its core, RNA provides a mechanism for distilling events of interest from security signature specifications and an approach for automatically generating code to offload IDS/IPS event processing to programmable switches. The proposed system “envelops” this functionality into interfaces that allow for transparent communication between forwarding devices and IDS/IPS systems transparently. We implement a proof-of-concept of RNA on top of Zeek. Our evaluations with real datasets show that RNA can identify attacks while releasing resources from the server-only solution. We also show that RNA minimizes the effort by operators to code P4 software.
Lucas Sonntag Hagen, Alexandre da Silveira Ilha, Ricardo Parizotto, Luciano Paschoal Gaspary
NOMS4
2025 Distributed Graph Neural Networks in Programmable Data Planes
abstract
The ability to redefine the data plane behavior with programmable network devices provides a plethora of novel possibilities for in-network computing. One of these possibilities is embedding Artificial Intelligence (AI) and Machine Learning (ML) techniques directly in the data plane. Motivations include reducing decision latency and closing the control loop-i.e., performing measurements, learning, decisions, and actions directly in the data plane. However, running entire AI/ML algorithms in a single device might be infeasible due to memory and computing constraints. This work addresses the research challenges of running a Graph Neural Network (GNN) in a set of devices of a programmable data plane. Our hypothesis is that by distributing the GNN processing across the devices, the GNN uses instantaneous snapshots of the global network state and can act more quickly. As a proof of concept, we trained and evaluated a distributed GNN to perform explicit congestion notifications based on Data Center Transmission Control Protocol (DCTCP). We verified the feasibility of GNN classification in the data plane through simulations and both software and hardware switch experiments with bmv2 and Intel Tofino.
Ivan Peter Lamb, Pedro Arthur Pinheiro Rosa Duarte, Jonatas Adilson Marques, Marcelo Caggiani Luizelli, Luciano Paschoal Gaspary, Anderson Tavares, Ronaldo A. Ferreira, Ítalo S. Cunha, José Rodrigo Azambuja, Weverton Luis da Costa Cordeiro
NOMS5
2025 In-Network Inference with Neuralp4: Auto-Generating Full-Fledged NN Models for PDPs
abstract
The emergence of data plane programmability motivated the offloading of inference based on Neural Networks (NNs) into network devices. Although performing inference in the data plane can provide faster results by doing computation at the line rate, the constraints of these devices make the offloading challenging. Existing solutions predominantly involve NN binarization or other simplifications to circumvent these constraints, and little emphasis is given to offloading standard NNs. In this paper, we present NeuralP4, an automated approach for generating full-fledged NN models to perform inference on packet forwarding devices. Because manually coding and configuring the NN would be laborious and error-prone, NeuralP4 automatically generates all necessary switch code and configuration files, supporting the offloading for diverse use cases. To execute all NN operations within the device's constraints, we distribute the NN layers across multiple network switches (labor division) and devise customized algorithms employing numerical conversion techniques and algebraic transformations. We implemented a proof-of-concept and conducted experiments considering five use cases. Our results show that NeuralP4 is as accurate as a traditional, server-only NN and that its incurred memory footprint is compatible with existing data plane devices. Furthermore, the system minimizes the manual effort required to write the NN code.
João Vicente Fatur Lessa, Jonatas Adilson Marques, Ricardo Parizotto, Luciano Paschoal Gaspary
NOMS4
2024 Multi-Tenant Programmable Switch Virtualization Leveraging Explicit Resource Sharing
abstract
With the migration of traditional computer networks to the Software-defined Networking paradigm, flexibility is a core feature that novel technologies must provide. In this context, virtualization is gaining traction in Programmable Data Planes (PDPs) as a means of achieving greater flexibility, with several solutions in the literature for instantiating virtual programmable switches on the same host device. Virtualization brings numerous advantages, enabling multi-tenancy in programmable data/research center networks and greater device resource utilization. Nevertheless, enabling a complete multitenant solution, in which the tenants have disjoint sets of virtual devices, requires management and security considerations not yet approached in previous investigations. Previous works focus mainly on the core underlying technology necessary to deploy multiple devices in the same physical host. This paper presents a PDP virtualization architecture based on program composition and access control for securely managing virtual switches from different tenants. Additionally, we define extensions to PDP programmability, allowing tenants to specify shared elements, such as tables, between their virtual devices. Our experiments highlight the ability to transparently manage multiple virtual switches hosted in the same physical device in networking scenarios with multiple tenants.
Ivan Peter Lamb, Pedro Arthur Pinheiro Rosa Duarte, Marcelo Caggiani Luizelli, Luciano Paschoal Gaspary, José Rodrigo Azambuja, Weverton Luis sa Costa Cordeiro
CNSM4
2023 Advancing Network Monitoring and Operation with In-band Network Telemetry and Data Plane Programmability
abstract
Modern communication networks operate under high expectations on performance and resilience (e.g., latency, bandwidth, availability) mainly due to the continuous proliferation of non-elastic highly-distributed applications. In this context, closely monitoring the state, behavior, and performance of networking devices and their traffic as well as quickly troubleshooting problems as they arise is essential for the operation of network infrastructures. Data Plane Programmability (DPP) along with In-band Network Telemetry (INT), backed by the recent advances in Software-Defined Networking, emerge in this context as promising platforms to meet these monitoring demands. In this thesis we make several contributions that advance the discipline of network monitoring and operation. We introduce and formalize the In-band Network Telemetry Orchestration (INTO) problem, which consists in assigning subsets of traffic to carry out INT and provide full monitoring coverage while minimizing the overhead. We prove this problem to be NP-Complete and propose polynomial computing time heuristic to solve it. In our evaluation using real wide-area network topologies, we observe that the heuristics produce solutions close to optimal to any network in under one second. Continuing our work, we investigate DPP capabilities further and design IntSight, a system for highly accurate and fine-grained detection and diagnosis of SLO violations. Our evaluation using real networks also shows that IntSight generates up to two orders of magnitude less monitoring traffic than state-of-the-art approaches. As a final step in this thesis, we shift our focus to quick reaction and propose Felix, a system for failure recovery that reroutes around failures at data-plane timescales while still using the shortest available paths. Our evaluation shows that our approach can recover from failures up to four orders of magnitude faster than existing SDN approaches while making sensible use of data-plane resources.
Jonatas Adilson Marques, Luciano Paschoal Gaspary
NOMS2
2023 Responding to Network Failures at Data-plane Speeds with Network Programmability
abstract
Measurement studies show that equipment failures happen quite frequently and pose a challenge to reliable network operation. Quickly recovering from failures is critical to meeting service guarantees. Traditional routing protocols, due to being executed in a distributed fashion and involving multiple devices in a network, require non-negligible time to recompute routes upon failures. SDN with OpenFlow simplifies route recomputation, but the time to compute and install alternative forwarding entries can still result in significant packet loss. Existing fast failover mechanisms cannot handle all types of failure and do not guarantee the use of the best paths. In this paper, we present FELIX, an approach for failure recovery that reroutes around failures at data plane timescales. Felix works by efficiently pre-computing tactics to handle failure scenarios that can be quickly activated in the data plane in response to failures. Our evaluation shows that our approach can recover from failures up to three orders of magnitude faster than existing SDN approaches.
Jonatas Adilson Marques, Kirill Levchenko, Luciano Paschoal Gaspary
NOMS3
2023 VERMONT: Towards an In-band Telemetry-Based Approach for Live Network Property Verification
abstract
The verification of network properties is often an exhaustive and time-consuming effort. The number of configurations needed to be analyzed by static verification increases as the networks grow larger, and the processing time consumed becomes prohibitive. Equally important, existing approaches fall short of detecting violations in dynamic environments. While the field of static verification has received significant attention in the last few years, few research efforts have been made to verify networks in production time. Capitalizing on the emergence of programmable data planes, in this paper, we propose VERMONT, an In-Band Network Telemetry-Based verification approach that continuously verifies properties as the state of the network changes. The key contribution of our work is an in-network system capable of continuously collecting the metadata from the network to verify properties in real-time. By efficiently retrieving only the necessary information from the network, VERMONT can accurately and quickly reason whether a set of properties is being held or not at a given time within the network. We implemented VERMONT, evaluated its performance using realistic settings, and compared it with a state-of-the-art approach. The results show that the proposed solution is technically feasible and performs at least one order of magnitude faster than a static verification counterpart. We also provide evidence that VERMONT incurs a very low resource usage footprint considering its application in several real-world networks.
Gabriel Vassoler, Jonatas Adilson Marques, Luciano Paschoal Gaspary
NOMS3
2021 Using Quadratic Discriminant Analysis by Intrusion Detection Systems for Port Scan and Slowloris Attack Classification
Vinícius M. Deolindo, Bruno Lopes Dalmazo, Marcus Vinicius Brito da Silva, Luiz Ricardo Bertoldi de Oliveira, Allan de B. Silva, Lisandro Z. Granville, Luciano Paschoal Gaspary, Jéferson Campos Nobre
ICCSA (3)7
2021 Harnessing Cloud Computing to Power Up HPC Applications: The BRICS CloudHPC Project
Jonatas Adilson Marques, Zhongke Wu, Xingce Wang, Ruslan Kuchumov, Vladimir Korkhov, Weverton Luis da Costa Cordeiro, Philippe Olivier Alexandre Navaux, Luciano Paschoal Gaspary
ICCSA (8)8
2021 BUNGEE: An Adaptive Pushback Mechanism for DDoS Detection and Mitigation in P4 Data Planes
Libardo Andrey Quintero González, Lucas Castanheira, Jonatas Adilson Marques, Alberto E. Schaeffer Filho, Luciano Paschoal Gaspary
IM5
2021 ORACLE: An Architecture for Collaboration of Data and Control Planes to Detect DDoS Attacks
Sebastián Gómez Macías, Luciano Paschoal Gaspary, Juan Felipe Botero
IM2
2021 Programmable Low-End Networks: Powering Internet Connectivity for the Other Three Billion
André Scheibe, Willian Reichert, Luciano Paschoal Gaspary, Weverton Luis da Costa Cordeiro
IM3
2021 Revisiting the coupon collector's problem to unveil users' online sessions in networked systems
Weverton Luis da Costa Cordeiro, Luciano Paschoal Gaspary, Rafael Duarte Beltran, Kayuã Oleques Paim, Rodrigo B. Mansilha
Peer-to-Peer Netw. Appl.2
2020 IntSight: diagnosing SLO violations with in-band network telemetry
abstract
Performance requirements for many of today's high-perfor-mance networks are expressed as service-level objectives (SLOs), i.e., precise guarantees, typically on latency and bandwidth, that a user can expect from the network. For network operators, monitoring their own SLO compliance, and quickly diagnosing any violations, is a critical element for effective operations. Unfortunately, existing network architectures are not engineered for this purpose; there is no mechanism, for example, for the operator to monitor the 95th per-centile latency experienced by a customer. Data plane programmability has made per-packet measurements possible but brings the challenge of keeping the monitoring overhead low and practical. In this paper, we present IntSight, a system for highly accurate and fine-grained detection and diagnosis of SLO violations. The main contribution of IntSight is, building upon in-band telemetry, introducing path-wise computation of network metrics and selective generation of reports. We show the effectiveness of IntSight by way of two use cases. Our evaluation using real networks also shows that IntSight generates up to two orders of magnitude less monitoring traffic than state-of-the-art approaches. Furthermore, its processing and memory requirements are low and therefore compatible with currently existing programmable platforms.
Jonatas Adilson Marques, Kirill Levchenko, Luciano Paschoal Gaspary
CoNEXT3
2020 Performance Impact of IEEE 802.3ad in Container-Based Clouds for HPC Applications
Anderson M. Maliszewski, Eduardo Roloff, Dalvan Griebler, Luciano Paschoal Gaspary, Philippe Olivier Alexandre Navaux
ICCSA (6)4
2020 Performance and Cost-aware HPC in Clouds: A Network Interconnection Assessment
abstract
The availability of computing resources has significantly changed due to the growing adoption of the cloud computing paradigm. Aiming at potential advantages such as cost savings through the pay-per-use method and resource allocation in a scalable/elastic way, we witnessed consistent efforts to execute high-performance computing (HPC) applications in the cloud. Performance in this environment depends heavily upon two main system components: processing power and network interconnection. If, on the one hand, allocating more powerful hardware theoretically boosts performance, on the other hand, it increases the allocation cost. In this paper, we evaluated how the network interconnection impacts on performance and cost efficiency. Our experiments were carried out using NAS Parallel Benchmarks and Alya HPC application on Microsoft Azure public cloud provider, with three different cloud instances/network interconnections. The results revealed that through the use of the accelerated networking approach, which allows the instance to have a high-performance interconnect without additional charges, the performance of HPC applications can be significantly improved with a better cost efficiency.
Anderson M. Maliszewski, Eduardo Roloff, Emmanuell D. Carreño, Dalvan Griebler, Luciano Paschoal Gaspary, Philippe Olivier Alexandre Navaux
ISCC5
2020 From 2D to Next Generation VR/AR Videos: Enabling Efficient Streaming via QoE-aware Mobile Networks
abstract
Ranging from traditional video streaming to Virtual Reality (VR) videos, the demand for video applications to mobile devices is booming. In the context of mobile operators a challenging problem is how to handle the increasing video traffic while managing the interplay between infrastructure optimization and QoE. Solving this issue is remarkably difficult, and recent investigations do not consider large-scale networks. In this dissertation paper we explore the solution space of efficient video streaming over mobile networks. First, we propose a model to predict video streaming quality based on the observation of performance indicators of the underlying IP network. Second, we introduce a novel QoE-aware path deployment heuristic for large-scale SDN-based mobile networks. Third, based on the lessons learned with QoE prediction for traditional video streaming, we finally explore the VR video domain by proposing PERCEIVE and VR-EXP. PERCEIVE is a two-stage method for predicting the perceived quality of adaptive VR videos when streamed through mobile networks. In turn, VR-EXP consists of an experimentation platform that allows in-depth evaluation of state-of-the-art VR video optimization techniques. Obtained results show that the combination of the proposed methods for QoE-aware path selection outperformed state-of-the-art approaches.
Roberto Irajá Tavares da Costa Filho, Filip De Turck, Luciano Paschoal Gaspary
NOMS3
2020 Reality shock in virtual network embedding: Flexibilizing demands for dealing with multiple operational requirements in SDNs
Leonardo Richter Bays, Luciano Paschoal Gaspary
J. Netw. Comput. Appl.2
2020 CAPEST: Offloading Network Capacity and Available Bandwidth Estimation to Programmable Data Planes
abstract
Measuring available bandwidth and capacity represents an essential requirement for a multitude of network applications spanning from traffic engineering and admission control to network security. Measurement techniques frequently presume to know capacity a priori, but this constitutes a weak premise in a number of modern scenarios due to conditions such as abstractions in infrastructure virtualization, dynamic demands in resource sharing and fluctuations in interference, all of which can affect capacity in short time spans. Despite consistent efforts, currently employed techniques struggle to balance accuracy, intrusion and freshness, depending on either substantial intrusion, onerous processing or unfeasible deployment. Recent developments on data plane programmability have breathed new life into this undertaking, allowing observation points to be more efficiently distributed and programmable packet methods to be executed in-situ. This paper proposes CAPEST, a passive capacity and available bandwidth measurement method for the data plane, employing packet dispersion and autocorrelation. The method is evaluated regarding its parametrization sensitivity, its intrusion and freshness in comparison to state-of-the-art techniques and its performance in the real-world application of video routing. CAPEST was found to incur substantially (80%) less intrusion and achieve 10% better accuracy, all the while providing an order of magnitude improvement in freshness.
Nicolas Kagami, Roberto Irajá Tavares da Costa Filho, Luciano Paschoal Gaspary
IEEE Trans. Netw. Serv. Manag.3
2020 Dissecting the Performance of VR Video Streaming through the VR-EXP Experimentation Platform
abstract
To cope with the massive bandwidth demands of Virtual Reality (VR) video streaming, both the scientific community and the industry have been proposing optimization techniques such as viewport-aware streaming and tile-based adaptive bitrate heuristics. As most of the VR video traffic is expected to be delivered through mobile networks, a major problem arises: both the network performance and VR video optimization techniques have the potential to influence the video playout performance and the Quality of Experience (QoE). However, the interplay between them is neither trivial nor has it been properly investigated. To bridge this gap, in this article, we introduce VR-EXP, an open-source platform for carrying out VR video streaming performance evaluation. Furthermore, we consolidate a set of relevant VR video streaming techniques and evaluate them under variable network conditions, contributing to an in-depth understanding of what to expect when different combinations are employed. To the best of our knowledge, this is the first work to propose a systematic approach, accompanied by a software toolkit, which allows one to compare different optimization techniques under the same circumstances. Extensive evaluations carried out using realistic datasets demonstrate that VR-EXP is instrumental in providing valuable insights regarding the interplay between network performance and VR video streaming optimization techniques.
Roberto Irajá Tavares da Costa Filho, Marcelo Caggiani Luizelli, Stefano Petrangeli, Maria Torres Vega, Jeroen van der Hooft, Tim Wauters, Filip De Turck, Luciano Paschoal Gaspary
ACM Trans. Multim. Comput. Commun. Appl.8
2019 Exploring Instance Heterogeneity in Public Cloud Providers for HPC Applications
Eduardo Roloff, Matthias Diener, Luciano Paschoal Gaspary, Philippe Olivier Alexandre Navaux
CLOSER3
2019 Boosting HPC Applications in the Cloud Through JIT Traffic-Aware Path Provisioning
Guilherme R. Pretto, Bruno Lopes Dalmazo, Jonatas Adilson Marques, Zhongke Wu, Xingce Wang, Vladimir Korkhov, Philippe Olivier Alexandre Navaux, Luciano Paschoal Gaspary
ICCSA (4)8
2019 Offloading Real-time DDoS Attack Detection to Programmable Data Planes
Ângelo C. Lapolli, Jonatas Adilson Marques, Luciano Paschoal Gaspary
IM3
2018 Exploiting Load Imbalance Patterns for Heterogeneous Cloud Computing Platforms
Eduardo Roloff, Matthias Diener, Luciano Paschoal Gaspary, Philippe Olivier Alexandre Navaux
CLOSER3
2018 Scalable QoE-aware Path Selection in SDN-based Mobile Networks
abstract
To deal with the massive traffic produced by video applications, mobile operators rely on offloading technologies such as Small Cells, Content Delivery Networks and, shortly, Cloud Edge and 5G Device to Device communications. Although these techniques are fundamental for improving network efficiency, they produce a multitude of paths onto which the user traffic can be forwarded. Thus, a critical problem arises about how to handle the increasing video traffic while managing the interplay between infrastructure optimization and the user's Quality of Experience (QoE). Solving this problem is remarkably difficult, and recent investigations do not consider the large-scale context of mobile operator networks. To address this issue, we present a novel QoE-aware path deployment scheme for large-scale SDN-based mobile networks. The scheme relies on both a polynomial-time algorithm for composing multiple QoS metrics and a scalable QoS to QoE translation strategy. Considering real mobile operator network and video traffic traces, we show that the proposed algorithm outperformed state-of-the-art approaches by reducing impaired videos in aggregate MOS by at least 37% and lowering accumulated video stall length four times.
Roberto Irajá Tavares da Costa Filho, William Lautenschlager, Nicolas Kagami, Marcelo Caggiani Luizelli, Valter Roesler, Luciano Paschoal Gaspary
INFOCOM6
2018 Predicting the performance of virtual reality video streaming in mobile networks
abstract
The demand of Virtual Reality (VR) video streaming to mobile devices is booming, as VR becomes accessible to the general public. However, the variability of conditions of mobile networks affects the perception of this type of high-bandwidth-demanding services in unexpected ways. In this situation, there is a need for novel performance assessment models fit to the new VR applications. In this paper, we present PERCEIVE, a two-stage method for predicting the perceived quality of adaptive VR videos when streamed through mobile networks. By means of machine learning techniques, our approach is able to first predict adaptive VR video playout performance, using network Quality of Service (QoS) indicators as predictors. In a second stage, it employs the predicted VR video playout performance metrics to model and estimate end-user perceived quality. The evaluation of PERCEIVE has been performed considering a real-world environment, in which VR videos are streamed while subjected to LTE/4G network condition. The accuracy of PERCEIVE has been assessed by means of the residual error between predicted and measured values. Our approach predicts the different performance metrics of the VR playout with an average prediction error lower than 3.7% and estimates the perceived quality with a prediction error lower than 4% for over 90% of all the tested cases. Moreover, it allows us to pinpoint the QoS conditions that affect adaptive VR streaming services the most.
Roberto Irajá Tavares da Costa Filho, Marcelo Caggiani Luizelli, Maria Torres Vega, Jeroen van der Hooft, Stefano Petrangeli, Tim Wauters, Filip De Turck, Luciano Paschoal Gaspary
MMSys8
2018 A branch-and-price algorithm for the single-path virtual network embedding problem
abstract
Network virtualization is a growing trend in the implementation of Internet infrastructures. The Virtual Network Embedding problem is one of the challenges in the virtualization of physical networks. This work shows that finding a feasible solution to this problem is NP‐Hard. However, in practice, it can be solved to optimality by exploiting the problem structure. We propose a new branch‐and‐price algorithm applied to a flow‐based formulation of the problem, and present an extensive computational study performed for instances of distinct topologies and sizes. The results presented attest the efficiency of the branch‐and‐price algorithm in solving the problem.
Leonardo F. S. Moura, Luciano Paschoal Gaspary, Luciana S. Buriol
Networks2
2018 Enhancing Mobile Military Surveillance Based on Video Streaming by Employing Software Defined Networks
abstract
Situation awareness in surveillance systems benefits from high‐quality video streaming service. This is even more important considering military systems, in which delays in image transmission may have a significant impact on the decision‐making process. However, in order to deliver high‐quality video streaming service, the required network infrastructure may be prohibitively complex, or even completely impossible to deploy, if mobile data providers are considered. Moreover, the demand for high network throughput poses extra requirements on the network. Considering this context, this paper addresses the problem of highly mobile networks composed of unmanned aerial vehicles (UAVs) as data providers of a military surveillance system. The proposed approach to tackle the problem is based on a Software Defined Networking (SDN) approach aiming at providing the best routes to deliver the data, enhancing the end‐user quality of experience. An extensive experimental campaign was performed by means of simulations and the acquired results provide solid evidence of the usefulness of this proposal.
Iulisloi Zacarias, Janaina Schwarzrock, Luciano Paschoal Gaspary, Andersonn Kohl, Ricardo Queiroz de Araujo Fernandes, Jorgito Matiuzzi Stocchero, Edison Pignaton de Freitas
Wirel. Commun. Mob. Comput.3
2017 Leveraging Cloud Heterogeneity for Cost-Efficient Execution of Parallel Applications
Eduardo Roloff, Matthias Diener, Emmanuell D. Carreño, Luciano Paschoal Gaspary, Philippe Olivier Alexandre Navaux
Euro-Par4
2017 A scalable approach for managing access control in Information Centric Networks
abstract
One of the main challenges in Information Centric Networks (ICN) is providing access control to content publication and retrieval. Most of the existing approaches often consider a single user acting as publisher within a group. When dealing with multiple publishers, they may lead to a combinatorial explosion of cryptographic keys. Approaches that focus on multiple publishers, on the other hand, rely on specific network architectures and/or changes to operate. In this paper we propose a novel solution, supported by attribute-based encryption, for managing content access control. In our solution, we introduce secure content distribution groups, in which any member user can publish to and retrieve from. Unlike previous work, our solution keeps the number of cryptographic keys proportional to the number of group members, and may even be adopted gradually in any ICN architecture. The proposed solution is evaluated with respect to the overhead it imposes, number of required keys, and efficiency of content dissemination. In contrast to existing approaches, it offers higher access control flexibility, while reducing key management process complexity (in some scenarios, resulting in 97% less keys and objects in the network).
Rafael Hansen da Silva, Weverton Luis da Costa Cordeiro, Luciano Paschoal Gaspary
IM3
2017 Employing SDN to control video streaming applications in military mobile networks
abstract
Video streaming is an important service provided by surveillance systems to enhance situation awareness. However, in military systems, data acquisition heavily depends on the network infrastructure. In this application domain, units are spread and the distance between the sources of data and the decision makers may be very large. In the case of video streaming, the demand for high network throughput poses some extra requirements on the network. Considering the mobility patterns of the military units and the diversity of the new generations of sensors, especially those used by Unmanned Aerial Vehicles (UAV), the configuration and the management of the network must be so dynamic and so sensitive to data flow parameters that manual configuration is not acceptable. For this reason, the capability of the network to configure itself to offer the necessary Quality of Service is a must. Using principles of Software Defined Networks (SDN), this paper presents an analysis of video streaming for military surveillance in which multiple UAVs are employed as data providers through an SDN-enabled network, with promising results.
Iulisloi Zacarias, Janaina Schwarzrock, Luciano Paschoal Gaspary, Andersonn Kohl, Ricardo Queiroz de Araujo Fernandes, Jorgito Matiuzzi Stocchero, Edison Pignaton de Freitas
NCA3
2017 HPC Application Performance and Cost Efficiency in the Cloud
abstract
Unlike traditional cluster systems, the Cloud Computing paradigm provides access to an execution environment without upfront investments in hardware and facilities. Due to the elasticity and the pay-per-use billing model, it is possible to configure experimental environments with minimal idle costs. In this paper, we perform an extensive evaluation of the major commercial public clouds. Our results show that performance degradation due to virtualization and other cloud overheads is insignificant. However, the network interconnection in the cloud still remains a large bottleneck for HPC application performance.
Eduardo Roloff, Matthias Diener, Luciano Paschoal Gaspary, Philippe Olivier Alexandre Navaux
PDP3
2017 A fix-and-optimize approach for efficient and large scale virtual network function placement and chaining
Marcelo Caggiani Luizelli, Weverton Luis da Costa Cordeiro, Luciana S. Buriol, Luciano Paschoal Gaspary
Comput. Commun.4
2017 NDNrel: A mechanism based on relations among objects to improve the performance of NDN
Rodolfo Stoffel Antunes, Matheus B. Lehmann, Rodrigo B. Mansilha, Luciano Paschoal Gaspary, Marinho P. Barcellos
J. Netw. Comput. Appl.4
2016 Network Fortune Cookie: Using Network Measurements to Predict Video Streaming Performance and QoE
abstract
Due to the fact that video streaming is the current "killer" application and for competitiveness, telecommunication service providers need to be able to answer a fundamental question: to which extent is the available network infrastructure able to successfully provide users with a satisfactory experience when running video streaming applications? Answering this question is far from trivial because existing techniques are neither scalable nor accurate enough. To address this issue, we propose a model to predict video streaming quality based on the observation of performance indicators of the underlying IP network. To accomplish this objective, the proposed model - created using LTE networks as case study - leverages low network consumption active measurements and machine learning techniques. Obtained results show that the proposed solution produces accurate estimates (average error of less than 10%) while keeping intrusiveness around twenty times lower than traditional techniques.
Roberto Irajá Tavares da Costa Filho, William Lautenschlager, Nicolas Kagami, Valter Roesler, Luciano Paschoal Gaspary
GLOBECOM5
2016 Virtual network embedding in software-defined networks
abstract
Research on network virtualization has been active for a number of years, during which a number of virtual network embedding (VNE) approaches have been proposed. These approaches, however, neglect important operational requirements imposed by the underlying virtualization platforms. In the case of SDN/OpenFlow-based virtualization, a crucial example of an operational requirement is the availability of enough memory space for storing flow rules in OpenFlow devices. In this paper, we advocate that VNE must be performed with some knowledge of the underlying physical networks, otherwise the deployment may suffer from unpredictable or even unsatisfactory performance. Considering SDN/OpenFlow-based physical networks as an important virtualization scenario, we propose an approach based on VNE and OpenFlow coordination for proper deployment of virtual networks (VNs). The proposed approach unfolds in the following main contributions: (i) a virtual infrastructure abstraction that allows a service provider to represent the details of his/her VN requirements in a comprehensive manner; (ii) a privacy-aware compiler that is able to preprocess this detailed VN request in order to obfuscate sensitive information and derive computable operational requirements; and (iii) a model for embedding requested VNs ensuring their feasibility at the physical level. The results obtained through our evaluation demonstrate that taking such operational requirements into account, as well as accurately assessing them, is of paramount importance to ensure the correct behavior of VNs hosted on top of the virtualization platform.
Leonardo Richter Bays, Luciano Paschoal Gaspary, Reaz Ahmed, Raouf Boutaba
NOMS2
2016 ASTORIA: A framework for attack simulation and evaluation in smart grids
abstract
Electric power grids are undergoing a modernization process. By relying on the ICT infrastructure and on Internet connectivity, these so-called Smart Grids are now able to provide new functionalities and to become more efficient. However, despite the existence of a few standards that aim to specify the secure operation of Smart Grids, utility companies do not have a comprehensive set of metrics and evaluation tools for assessing security properties in these infrastructures. Thus, it is necessary to develop new toolsets to provide support for vulnerability analysis in Smart Grids. This paper proposes ASTORIA, a framework developed to allow the simulation of attacks and the evaluation of their impact on Smart Grid infrastructures, using closely-related real devices and real topologies comprising both power grid elements as well as ICT and networking equipment. We anticipate that ASTORIA can be used by Smart Grid operators not only to analyze the impact of malicious attacks and other security threats in different components, but also to permit the development and evaluation of anomaly detection techniques in a simulation environment. Further, we present evaluation scenarios illustrating customizable Smart Grid topologies, comprising sensors, master and remote stations, and using an extensible set of attack profiles.
Alexandre Gustavo Wermann, Marcelo Cardoso Bortolozzo, Eduardo Germano da Silva, Alberto E. Schaeffer Filho, Luciano Paschoal Gaspary, Marinho P. Barcellos
NOMS5
2016 Making puzzles green and useful for adaptive identity management in large-scale distributed systems
Weverton Luis da Costa Cordeiro, Flavio Santos, Marinho P. Barcellos, Luciano Paschoal Gaspary, Hanna Kavalionak, Alessio Guerrieri, Alberto Montresor
Comput. Networks4
2016 A toolset for efficient privacy-oriented virtual network embedding and its instantiation on SDN/OpenFlow-based substrates
Leonardo Richter Bays, Rodrigo Ruas Oliveira, Luciana S. Buriol, Marinho P. Barcellos, Luciano Paschoal Gaspary
Comput. Commun.5
2016 PredCloud: Providing predictable network performance in large-scale OpenFlow-enabled cloud platforms through trust-based allocation of resources
Daniel S. Marcon, Miguel C. Neves, Rodrigo Ruas Oliveira, Luciano Paschoal Gaspary, Marinho P. Barcellos
Comput. Commun.4
2016 How physical network topologies affect virtual network embedding quality: A characterization study based on ISP and datacenter networks
Marcelo Caggiani Luizelli, Leonardo Richter Bays, Luciana S. Buriol, Marinho P. Barcellos, Luciano Paschoal Gaspary
J. Netw. Comput. Appl.5
2015 IoNCloud: Exploring application affinity to improve utilization and predictability in datacenters
abstract
The intra-cloud network is typically shared in a best-effort manner, which causes tenant applications to have no actual bandwidth guarantees. Recent proposals address this issue either by statically reserving a slice of the physical infrastructure for each application or by providing proportional sharing among flows. The former approach results in overprovisioned network resources, while the latter requires substantial management overhead. In this paper, we introduce a resource allocation strategy that aims at providing an efficient way to predictably share bandwidth among applications and at minimizing resource underutilization while maintaining low management overhead. To demonstrate the benefits of the strategy, we develop IoNCloud, a system that implements the proposed allocation scheme. IoNCloud employs the abstraction of attraction/repulsion among applications according to their temporal bandwidth demands in order to group them in virtual networks. In doing so, we explore the trade-off between high resource utilization (which is desired by providers to achieve economies of scale) and strict network guarantees (necessary for tenants to run jobs predictably). Evaluation results show that IoNCloud can (a) provide predictable network sharing; and (b) reduce allocated bandwidth, resource underutilization and management overhead when compared against state-of-the-art proposals.
Daniel S. Marcon, Miguel C. Neves, Rodrigo Ruas Oliveira, Leonardo Richter Bays, Raouf Boutaba, Luciano Paschoal Gaspary, Marinho P. Barcellos
ICC6
2015 CCNrel: Leveraging relations among objects to improve the performance of CCN
abstract
Content-Centric Networking (CCN) is a promising architectural approach that focuses on the efficient distribution of uniquely named data objects. A piece of content is represented by a single object in the network and is divided into multiple chunks which can be uniquely named and cached by network nodes. However, in its current form, the potential of CCN is not fully exploited due to the lack of common means to express and take advantage from possible relations that may exist among different objects. Our work explores the simple yet effective idea of supporting and exploiting such relations in CCN. In this paper, we present CCNrel as a backward-compatible mechanism for CCN that enables publishers to distribute contents as related objects. Differently from existing relation mechanisms, which focus on one type of content and are application-specific, CCNrel is generic and enables the use of relations in both current and novel application domains. First, we discuss CCNrel fundamental concepts and main design aspects. Next, we use CCNrel as foundation for a case study of data redundancy elimination in multimedia content distribution. Through extensive simulation work we evaluate the potential benefits of leveraging relations measured by the clients experience and overall network efficiency. Results of the presented use case show that, on average and when compared to default CCN operations, content download times are improved in 34%, publishers load in 56%, and the network bandwidth usage in 43%.
Rodolfo Stoffel Antunes, Matheus B. Lehmann, Rodrigo B. Mansilha, Christian Esteve Rothenberg, Luciano Paschoal Gaspary, Marinho P. Barcellos
IM5
2015 Limiting fake accounts in large-scale distributed systems through adaptive identity management
abstract
Various online, networked systems offer a lightweight process for obtaining identities (e.g., confirming a valid e-mail address), so that users can easily join them. Such convenience comes with a price, however: with minimum effort, an attacker can subvert the identity management scheme in place, obtain a multitude of fake accounts, and use them for malicious purposes. In this work, we approach the issue of fake accounts in large-scale, distributed systems, by proposing a framework for adaptive identity management. Instead of relying on users' personal information as a requirement for granting identities (unlike existing proposals), our key idea is to estimate a trust score for identity requests, and price them accordingly using a proof of work strategy. The research agenda that guided the development of this framework comprised three main items: (i) investigation of a candidate trust score function, based on an analysis of users' identity request patterns, (ii) combination of trust scores and proof of work strategies (e.g. cryptograhic puzzles) for adaptively pricing identity requests, and (iii) reshaping of traditional proof of work strategies, in order to make them more resource-efficient, without compromising their effectiveness (in stopping attackers).
Weverton Luis da Costa Cordeiro, Luciano Paschoal Gaspary
IM2
2015 Piecing together the NFV provisioning puzzle: Efficient placement and chaining of virtual network functions
abstract
Network Function Virtualization (NFV) is a promising network architecture concept, in which virtualization technologies are employed to manage networking functions via software as opposed to having to rely on hardware to handle these functions. By shifting dedicated, hardware-based network function processing to software running on commoditized hardware, NFV has the potential to make the provisioning of network functions more flexible and cost-effective, to mention just a few anticipated benefits. Despite consistent initial efforts to make NFV a reality, little has been done towards efficiently placing virtual network functions and deploying service function chains (SFC). With respect to this particular research problem, it is important to make sure resource allocation is carefully performed and orchestrated, preventing over- or under-provisioning of resources and keeping end-to-end delays comparable to those observed in traditional middlebox-based networks. In this paper, we formalize the network function placement and chaining problem and propose an Integer Linear Programming (ILP) model to solve it. Additionally, in order to cope with large infrastructures, we propose a heuristic procedure for efficiently guiding the ILP solver towards feasible, near-optimal solutions. Results show that the proposed model leads to a reduction of up to 25% in end-to-end delays (in comparison to chainings observed in traditional infrastructures) and an acceptable resource over-provisioning limited to 4%. Further, we demonstrate that our heuristic approach is able to find solutions that are very close to optimality while delivering results in a timely manner.
Marcelo Caggiani Luizelli, Leonardo Richter Bays, Luciana S. Buriol, Marinho P. Barcellos, Luciano Paschoal Gaspary
IM5
2015 Capitalizing on SDN-based SCADA systems: An anti-eavesdropping case-study
abstract
Power grids are responsible for the transmission and distribution of electricity to end-users. These systems are undergoing a modernization process through the use of Information and Communication Technology (ICT), transforming the electric system into Smart Grids. In this context, Supervisory Control and Data Acquisition (SCADA) systems are responsible for the management and monitoring of substations and field devices. In this paper, we investigate the use of SDN as an approach to assist in the modernization of SCADA systems. We discuss its possible benefits, such as simplified management of power system resources. Moreover, SDN can facilitate the creation of new network applications that previously, with traditional networks, were more complex to be implemented. To illustrate the benefits of the use of SDN in SCADA, we designed a mechanism that aims to prevent a possible eavesdropper from fully capturing communication flows between SCADA components. The mechanism was implemented as an SDN-based application for SCADA systems that uses multipath routing, which relies on SDN features to frequently modify communication routes between SCADA devices. Further, we performed an experimental evaluation to verify the impact and performance of the mechanism in the SCADA network.
Eduardo Germano da Silva, Luis Augusto Dias Knob, Juliano Araújo Wickboldt, Luciano Paschoal Gaspary, Lisandro Z. Granville, Alberto E. Schaeffer Filho
IM4
2015 Opportunistic resilience embedding (ORE): Toward cost-efficient resilient virtual networks
abstract
Network Virtualization promotes the development of new architectures and protocols by enabling the creation of multiple virtual networks on top of the same physical substrate. One of its main advantages is the use of isolation to limit the scope of attacks – that is, avoiding traffic from one virtual network to interfere with the others. However, virtual networks are still vulnerable to disruptions on the underlying network. Particularly, high capacity physical links constitute good targets since they may be important for a large number of virtual networks. Previous work protects virtual networks by setting aside backup resources. Although effective, this kind of solution tends to be expensive, as backup resources increase the cost to infrastructure providers and usually remain idle. This paper presents ORE (opportunistic resilience embedding), a novel embedding approach for protecting virtual links against substrate network disruptions. ORE’s design is two-fold: while a proactive strategy embeds each virtual link into multiple substrate paths in order to mitigate the initial impact of a disruption, a reactive one attempts to recover any capacity affected by an underlying disruption. Both strategies are modeled as optimization problems . Additionally, since the embedding problem is NP -Hard, ORE uses a simulated annealing-based meta-heuristic to solve it efficiently. Numerical results show that ORE can provide resilience to disruptions at a lower cost.
Rodrigo Ruas Oliveira, Daniel S. Marcon, Leonardo Richter Bays, Miguel C. Neves, Luciano Paschoal Gaspary, Deep Medhi, Marinho P. Barcellos
Comput. Networks5
2014 Survivor: An enhanced controller placement strategy for improving SDN survivability
abstract
In SDN, forwarding devices can only operate correctly while connected to a logically centralized controller. To avoid single-point-of-failure, controller architectures are usually implemented as distributed systems. In this context, recent literature identified fundamental issues, such as device isolation and controller overload, and proposed controller placement strategies to tackle them. However, current proposals have crucial limitations: (i) device-controller connectivity is modeled using single paths, yet in practice multiple concurrent connections may occur; (ii) peaks in the arrival of new flows are only handled on-demand, assuming that the network itself can sustain high request rates; and (iii) failover mechanisms require predefined information, which, in turn, has been overlooked. This paper proposes Survivor, a controller placement strategy that addresses these challenges. The strategy explicitly considers path diversity, capacity, and failover mechanisms at network design. Comparisons to the state-of-the-art on survivable controller placement show that Survivor is superior because (a) path diversity increases the survivability significantly; and (b) capacity-awareness is essential to handle overload during both normal and failover states.
Lucas F. Müller, Rodrigo Ruas Oliveira, Marcelo Caggiani Luizelli, Luciano Paschoal Gaspary, Marinho P. Barcellos
GLOBECOM4
2014 A heuristic-based algorithm for privacy-oriented virtual network embedding
abstract
Network virtualization has become increasingly popular in recent years. It has the potential to allow timely handling of network infrastructure requests and, after instantiated, their lifecycle. In addition, it enables improved physical resource utilization. However, the use of network virtualization in large-scale, real environments depends on the ability to adequately map virtual routers and links to physical resources, as well as to protect virtual networks against security threats. With respect to security, confidentiality and privacy mechanisms have become essential in light of recent discoveries related to pervasive electronic surveillance. In this paper we propose a heuristic method for virtual network embedding with security support. The method features precise modeling of overhead costs of security mechanisms and handles incoming requests in an online manner. Additionally, we present a detailed performance comparison between the proposed heuristic and an optimization model based on the same problem. The obtained results demonstrate that the heuristic method is able to find feasible mappings in the order of seconds even when dealing with large network infrastructures, while the optimization model is limited to smaller networks.
Leonardo Richter Bays, Rodrigo Ruas Oliveira, Luciana S. Buriol, Marinho P. Barcellos, Luciano Paschoal Gaspary
NOMS5
2014 Slowing down to speed up: Protecting users against massive attacks in content distribution systems
abstract
The Internet has become a large platform where users can interact and share contents. In this context, content distribution systems (CDS) have been designed to satisfy users needs. Peer-to-Peer (P2P) systems have emerged as a prominent solution to speed up CDS. In this kind of distributed system, a particular interesting challenge refers to mechanisms employed to match user's interests and published contents. The efficacy of CDS depends on the expertise of publishers to properly describe contents, which comprises an important task to guarantee good quality of experience (QoE) to users. Massive attacks may harm CDS if countermeasure mechanisms are not considered to fight content pollution. The main objective of the thesis is to devise a mechanism to provide users a good QoE and reduce the effect of malicious interference. To achieve that, three main steps guided the research work presented in the thesis and summarized in this paper: (i) we proposed a novel strategy that operates conservatively to avoid wide pollution dissemination, (ii) we extended our previous solution to cope with the subjectivity regarding content descriptions, and last, (iii) we proposed a generic model to investigate massive attacks (including content pollution) and conservative approaches.
Flavio Santos, Marinho P. Barcellos, Luciano Paschoal Gaspary
NOMS3
2014 Efficient Model Checking of IT Change Operations
abstract
The success of businesses in modern organizations heavily depends on the high availability of information technology (IT) infrastructures. To prevent business disruption, IT operators have worked hard to ensure that any changes to this infrastructure are properly and efficiently deployed. Change management - a discipline of the Information Technology Infrastructure Library (ITIL) - provides important guidance to help achieve this end. As IT infrastructures grow larger, however, ensuring that changes are harmless to business continuity becomes increasingly complex. In fact, previous research has shown that existing approaches for verifying changes suffer from severe scalability issues. This problem can become a serious threat to most organizations, as it can lead for example to customer dissatisfaction due to missed deadlines in service change deployment. To bridge this gap, we propose a partial-order reduction model checking paradigm and algorithm for efficiently detecting harmful change operations. Our model improves the complexity of verifying a set of concurrent change activities against safety constraints by reducing - without losing effectiveness - the verification scope. To prove concept and technical feasibility, we carried out an extensive performance evaluation of our algorithm considering a variety of change activities, safety constraints, and configuration scenarios. The results obtained from 32 benchmarks have shown that our algorithm significantly outperformed state-of-the-art, general purpose model checkers, improving the runtime complexity from polynomial/exponential to linear. In summary, the results evidenced that change verification finally became feasible and efficient for larger IT infrastructures.
Sebastian Hagen, Weverton Luis da Costa Cordeiro, Luciano Paschoal Gaspary, Lisandro Z. Granville, Alfons Kemper
IEEE Trans. Netw. Serv. Manag.3
2013 Characterizing the impact of network substrate topologies on virtual network embedding
abstract
Network virtualization is a mechanism that allows the coexistence of multiple virtual networks on top of a single physical substrate. One of the research challenges addressed recently in the literature is the efficient mapping of virtual resources on physical infrastructures. Although this challenge has received considerable attention, state-of-the-art approaches present, in general, a high rejection rate, i.e., the ratio between the number of denied virtual network requests and the total amount of requests is considerably high. In this work, we investigate the relationship between the quality of virtual network mappings and the topological structures of the underlying substrates. Exact solutions of an online embedding model are evaluated under different classes of network topologies. The obtained results demonstrate that the employment of physical topologies that contain regions with high connectivity significantly contributes to the reduction of rejection rates and, therefore, to improved resource usage.
Marcelo Caggiani Luizelli, Leonardo Richter Bays, Luciana S. Buriol, Marinho P. Barcellos, Luciano Paschoal Gaspary
CNSM5
2013 No more backups: Toward efficient embedding of survivable virtual networks
abstract
Although network virtualization can improve security by isolating traffic from different networks, routers and links are still vulnerable to attacks on the underlying network. High capacity physical links, in particular, constitute good targets since they may be important for a large number of virtual networks. Previous work protects virtual networks by setting aside backup resources. Although effective, this solution increases the cost to infrastructure providers. In this paper, we present a virtual network embedding approach which enables resilience to attacks and efficiency in resource utilization. Our approach is two-folded: while a preventive strategy embeds virtual links into multiple substrate paths, a reactive strategy attempts to reallocate any capacity affected by an underlying DoS attack. Since the embedding problem is NP-Hard, we devise a Simulated Annealing meta-heuristic to solve it efficiently. Results show our solution can provide resilience to attacks at a lower cost.
Rodrigo Ruas Oliveira, Daniel S. Marcon, Leonardo Richter Bays, Miguel C. Neves, Luciana S. Buriol, Luciano Paschoal Gaspary, Marinho P. Barcellos
ICC6
2013 Make it green and useful: Reshaping puzzles for identity management in large-scale distributed systems
Weverton Luis da Costa Cordeiro, Flavio Santos, Marinho P. Barcellos, Luciano Paschoal Gaspary
IM4
2013 Slowing down to speed up: Mitigating collusion attacks in Content Distribution Systems
Flavio Santos, Weverton Luis da Costa Cordeiro, Marinho P. Barcellos, Luciano Paschoal Gaspary, Fabio Victora Hecht, Burkhard Stiller
IM4
2013 Identifying the root cause of failures in IT changes: Novel strategies and trade-offs
Ricardo Luis dos Santos, Juliano Araújo Wickboldt, Bruno Lopes Dalmazo, Lisandro Z. Granville, Luciano Paschoal Gaspary, Roben Castagna Lunardi
IM5
2013 Trust-based grouping for cloud datacenters: Improving security in shared infrastructures
Daniel S. Marcon, Rodrigo Ruas Oliveira, Miguel C. Neves, Luciana S. Buriol, Luciano Paschoal Gaspary, Marinho P. Barcellos
Networking5
2013 Beyond pollution and taste: A tag-based strategy to increase download quality in P2P file sharing systems
Flavio Santos, Weverton Luis da Costa Cordeiro, Luciano Paschoal Gaspary, Marinho P. Barcellos
Comput. Commun.3
2012 Security-aware optimal resource allocation for virtual network embedding
Leonardo Richter Bays, Rodrigo Ruas Oliveira, Luciana S. Buriol, Marinho P. Barcellos, Luciano Paschoal Gaspary
CNSM5
2012 Planning in the large: Efficient generation of IT change plans on large infrastructures
Sebastian Hagen, Weverton Luis da Costa Cordeiro, Luciano Paschoal Gaspary, Lisandro Z. Granville, Michael Seibold, Alfons Kemper
CNSM3
2012 Characterizing dissemination of illegal copies of content through monitoring of BitTorrent networks
abstract
BitTorrent networks are nowadays the most employed method of Peer-to-Peer (P2P) file sharing in the Internet. Recent monitoring reports reveal that content copies being shared are mostly illegal and movies are the most popular media type. Research efforts carried out to understand the dynamics of content production and sharing in BT networks have been unable to provide precise information regarding the dissemination of illegal copies. In this paper we perform an extensive experimental study in order to characterize the behavior of producers, publishers and providers of copyright-infringing files. The study is based on four months of traces obtained by monitoring swarms sharing movies via one of the most popular BT public communities. Traces were obtained with an extension of a BitTorrent “universe” observation architecture, which allowed the collection of a database with information about more than 40,000 torrents, 900 trackers and 1.3 million IPs. Our analysis not only shows that a small group of active users is responsible for the majority of disseminated illegal copies, as well as unravels existing relationships among these actors.
Adler Hoff Schmidt, Rodolfo Stoffel Antunes, Marinho P. Barcellos, Luciano Paschoal Gaspary
NOMS4
2012 Identity management based on adaptive puzzles to protect P2P systems from Sybil attacks
Weverton Luis da Costa Cordeiro, Flavio Santos, Gustavo Huff Mauch, Marinho P. Barcellos, Luciano Paschoal Gaspary
Comput. Networks5
2012 Denial-of-service attacks and countermeasures on BitTorrent
Matheus B. Lehmann, Flavio Santos, Luciano Paschoal Gaspary, Marinho P. Barcellos
Comput. Networks3
2011 Securing P2P systems from Sybil attacks through adaptive identity management
Weverton Luis da Costa Cordeiro, Flavio Santos, Gustavo Huff Mauch, Marinho P. Barcellos, Luciano Paschoal Gaspary
CNSM5
2011 Leveraging IT project lifecycle data to predict support costs
abstract
There is an intuitive notion that the costs associated with project support actions, currently deemed too high and increasing, are directly related to the effort spent during their development and test phases. Despite the importance of systematically characterizing and understanding this relationship, little has been done in this realm mainly due to the lack of proper tooling for both sharing information between IT project phases and learning from past experiences. To tackle this issue, in this paper we propose a solution that, leveraging existing IT project lifecycle data, is able to predict support costs. The solution has been evaluated through a case study based on the ISBSG dataset, producing correct estimates for more than 80% of the assessed scenarios.
Bruno Lopes Dalmazo, Weverton Luis da Costa Cordeiro, Abraham Lincoln Rabelo de Sousa, Juliano Araújo Wickboldt, Roben Castagna Lunardi, Ricardo Luis dos Santos, Luciano Paschoal Gaspary, Lisandro Z. Granville, Claudio Bartolini, Marianne Hickey
Integrated Network Management7
2011 Observing the BitTorrent universe through Telescopes
abstract
Recent analysis of the latest peer-to-peer trends worldwide indicates that BitTorrent is the most popular file sharing protocol, taking more than half of the P2P traffic in some geographical locations. Despite several studies about the dynamics of the “BitTorrent universe”, there exists no methodology to systematically observe it. This is mainly due to the challenges that need to be faced in order to observe the BitTorrent universe, the specificity of existing studies, and the ad hoc nature of the monitoring methods employed so far. In this paper, we propose a novel monitoring architecture (called TorrentU) that allows the systematic observation of large numbers of BitTorrent networks. Complementary monitoring strategies are flexibly combined to allow varying degrees of network/geographic coverage, information accuracy and richness of detail. To show the concept and technical feasibility of TorrentU, we implemented a prototype with the key parts of the architecture, and evaluated it through a case study with a rich set of monitoring campaigns running on PlanetLab nodes.
Rodrigo B. Mansilha, Leonardo Richter Bays, Matheus B. Lehmann, Alan Mezzomo, Giovani Facchini, Luciano Paschoal Gaspary, Marinho P. Barcellos
Integrated Network Management6
2011 A solution for identifying the root cause of problems in IT change management
abstract
The reuse of knowledge acquired by operators to diagnose failures in Information Technology (IT) infrastructures has potential to decrease the recurrence of failures and, consequently, reduce possible losses and maintenance costs. Nevertheless, existing solutions to support failure diagnosis lack of flexibility to adapt to a constantly changing IT environment. As a result, diagnostic is performed in an ad hoc and static fashion, which hampers the reuse of knowledge to solve similar failures affecting different elements of an IT infrastructure. To bridge this gap, in this paper we propose an extension of Common Information Model (CIM), supported by a conceptual solution for the identification of the root causes of problems, adaptable to changes in the target infrastructure and applicable to similar failures. Experiments carried out considering typical failures during the deployment of IT changes provide evidence about the efficacy of the proposed solution.
Ricardo Luis dos Santos, Juliano Araújo Wickboldt, Roben Castagna Lunardi, Bruno Lopes Dalmazo, Lisandro Z. Granville, Luciano Paschoal Gaspary, Claudio Bartolini, Marianne Hickey
Integrated Network Management6
2011 A framework for risk assessment based on analysis of historical information of workflow execution in IT systems
Juliano Araújo Wickboldt, Luís Armando Bianchin, Roben Castagna Lunardi, Lisandro Z. Granville, Luciano Paschoal Gaspary, Claudio Bartolini
Comput. Networks5
2011 A conservative strategy to protect P2P file sharing systems from pollution attacks
abstract
Abstract Despite being currently one of the main Internet applications, P2P file sharing has been hampered by content pollution attacks. To tackle this problem, we introduce a novel pollution control strategy that consists in adjusting the rate in which content is disseminated, according to content version reputation. The proposed strategy is modeled and evaluated using simplifying assumptions. Then, inspired by classic distributed designs, we propose a pollution control mechanism that implements such a strategy. The mechanism is evaluated in terms of the delays imposed on non‐polluted version dissemination, the effectiveness of reducing dissemination when the version is polluted, and the negative impact that collusion attacks can impose on the reputation system upon which our mechanism is built. Simulation results looking at scenarios with several hundred peers indicate that the pollution control mechanism can effectively reduce pollution without substantially affecting the dissemination of non‐polluted content. Copyright © 2010 John Wiley & Sons, Ltd.
Marinho P. Barcellos, Luciano Paschoal Gaspary, Weverton Luis da Costa Cordeiro, Rodolfo Stoffel Antunes
Concurr. Comput. Pract. Exp.2
2011 Funnel: Choking Polluters in BitTorrent File Sharing Communities
abstract
BitTorrent-based file sharing communities are very popular nowadays. Anecdotal evidence hints that such communities are exposed to content pollution attacks (i.e., publication of "false" files, viruses, or other malware), requiring a moderation effort from their administrators. The size of such a cumbersome task increases with content publishing rate. To tackle this problem, we propose a generic pollution control strategy and instantiate it as a mechanism for BitTorrent communities. The strategy follows a conservative approach: it regards newly published content as polluted, and allows the dissemination rate to increase according to the proportion of positive feedback issued about the content. In contrast to related approaches, the strategy and mechanism avoid the problem of pollution dissemination at the initial stages of a swarm, when insufficient feedback is available to form a reputation about the content. To evaluate the proposed solution, we conducted a set of experiments using a popular BitTorrent agent and an implementation of our mechanism. Results indicate that the proposed approach mitigates the dissemination of polluted content in BitTorrent, imposing a low overhead in the distribution of non-polluted ones.
Flavio Santos, Weverton Luis da Costa Cordeiro, Luciano Paschoal Gaspary, Marinho P. Barcellos
IEEE Trans. Netw. Serv. Manag.3
2010 Similarity metric for risk assessment in IT change plans
abstract
The proper management of IT infrastructures is essential for organizations that aim to deliver high quality services. Given the dynamics of these infrastructures, changes become imminent. In some cases, these changes might raise failures, causing disruption to provided services and consequently affecting the business continuity. Therefore, it is strongly recommended to evaluate the risks associated with changes before their actual execution. Learning from information of past deployed changes it is possible to estimate the risks for recently planned ones. Thereby, in this paper, we propose a solution to weigh the information available from past executed plans by the similarity calculated in relation with the analyzed change plan. A prototype system has been developed in order to evaluate the effectiveness of the solution over an emulated IT infrastructure. The results obtained show that the solution is capable of capturing similarity among activities in change plans, improving the accuracy of risk assessment for IT change planning.
Luís Armando Bianchin, Juliano Araújo Wickboldt, Lisandro Z. Granville, Luciano Paschoal Gaspary, Claudio Bartolini, Maher Rahmouni
CNSM4
2010 On strategies for planning the assignment of human resources to IT change activities
abstract
Planning is a fundamental sub-process of the overarching Information Technology (IT) change management process, proposed by the Information Technology Infrastructure Library to help organizations to deploy and maintain IT services in an effective and efficient way. A major issue behind IT change planning and of special importance for the alignment of changes with business objectives/constraints - the adequate projection of which human resources to assign to change activities - has not been properly addressed in previous investigations. To fill this gap, in this paper we propose and analyze novel strategies for planning the assignment of human resources to change activities. These strategies explore different ways to prioritize humans to activities (i.e., from the most to the less efficient or proficient humans), and to rank/cluster the activities that should be analyzed first. The novel strategies have been experimentally evaluated through ChangeAdvisor, a prototypical implementation of a decision support system that helps IT administrators in the task of understanding the trade-offs between alternative change designs.
Roben Castagna Lunardi, Fabrício Girardi Andreis, Weverton Luis da Costa Cordeiro, Juliano Araújo Wickboldt, Bruno Lopes Dalmazo, Ricardo Luis dos Santos, Luís Armando Bianchin, Luciano Paschoal Gaspary, Lisandro Z. Granville, Claudio Bartolini
NOMS8
2010 Choking polluters in BitTorrent file sharing communities
abstract
BitTorrent-based file sharing communities are very popular nowadays. Anedoctal evidence hints that such communities are exposed to content pollution attacks (i.e., publication of `false' files, viruses, or other malware), requiring a moderation effort from their administrators. The size of such a cumbersome task increases with content publishing rate. To tackle this problem, we propose a generic pollution control strategy and instantiate it as a mechanism for BitTorrent communities. The strategy follows a conservative approach: it regards newly published content as polluted, and allows the dissemination rate to increase according to the proportion of positive feedback issued about the content. In contrast to related approaches, the strategy and mechanism avoid the problem of pollution dissemination at the initial stages of a swarm, when insufficient feedback is available to form a reputation about the content. To evaluate the proposed solution, we conducted a set of experiments using a popular BitTorrent agent and an implementation of our mechanism. Results indicate that the proposed approach mitigates the dissemination of polluted content in BitTorrent, imposing a low overhead in the distribution of non-polluted ones.
Flavio Santos, Weverton Luis da Costa Cordeiro, Luciano Paschoal Gaspary, Marinho P. Barcellos
NOMS3
2010 Computer-generated comprehensive risk assessment for IT project management
abstract
Information Technology (IT) products and services provided by modern organizations are designed in projects that often involve large amount of resources (e.g., humans, hardware, and software). It is essential that organizations enforce rational practices for project management, in order to successfully conclude projects and avoid waste of substantial resources. In this context, Risk Management is fundamental to guarantee the accomplishment of project's objectives by dealing with adverse and favorable events. Although important, risk assessment in IT projects is usually performed by stakeholders in interviews and brainstorms which may be a very time/resource-consuming task. Therefore, in this paper, we introduce a solution to automate the risk assessment process, based on the history of previously conducted projects. Furthermore, comprehensive and interactive risk reports are proposed in order to ease the analysis of automatically generated reports. The results show that our solution is not only useful to speed the risk assessment process, but also to assist the decision making of project managers by organizing risk information according to the project structure.
Juliano Araújo Wickboldt, Luís Armando Bianchin, Roben Castagna Lunardi, Fabrício Girardi Andreis, Ricardo Luis dos Santos, Bruno Lopes Dalmazo, Weverton Luis da Costa Cordeiro, Abraham Lincoln Rabelo de Sousa, Lisandro Z. Granville, Luciano Paschoal Gaspary, Claudio Bartolini
NOMS10
2009 How much management is management enough? Providing monitoring processes with online adaptation and learning capability
abstract
Recent investigations of management traffic patterns in production networks suggest that just a small and static set of management data tends to be used, the flow of management data is relatively constant, and the operations in use for manager-agent communication are reduced to a few, sometimes obsolete set. This is an indication of lack of progress of monitoring processes, taking into account their strategic role and potential, for example, to anticipate and prevent faults, performance bottlenecks, and security problems. One of the main reasons for such limitation relies on the fact that operators, who still are a fundamental element of the monitoring control loop, can no longer handle the rapidly increasing size and heterogeneity of both hardware and software components that comprise modern networked computing systems. This form of human-in-the-loop management certainly hampers timely adaptation of monitoring processes. To tackle this issue, this paper presents a model, inspired by the reinforcement learning theory, for adaptive network, service and application monitoring. The model is instantiated through a prototypical implementation of an autonomic element, which, based on historical and even unexpected values retrieved for management objects, dynamically widens or restricts the set of management objects to be monitored.
Josiane Ortolan Coelho, Luciano Paschoal Gaspary, Liane Margarida Rockenbach Tarouco
Integrated Network Management2
2009 CHANGEMINER: A solution for discovering IT change templates from past execution traces
abstract
The main goal of change management is to ensure that standardized methods and procedures are used for the efficient and prompt handling of changes in IT systems, in order to minimize change-related incidents and service-delivery disruption. To meet this goal, it is of paramount importance reusing the experience acquired from previous changes in the design of subsequent ones. Two distinct approaches may be usefully combined to this end. In a top-down approach, IT operators may manually design change templates based on the knowledge owned/acquired in the past. Considering a reverse, bottom-up perspective, these templates could be discovered from past execution traces gathered from IT provisioning tools. While the former has been satisfactorily explored in previous investigations, the latter - despite its undeniable potential to result in accurate templates in a reduced time scale - has not been subject of research, as far as the authors are aware of, by the service operations and management community. To fill in this gap, this paper proposes a solution, inspired on process mining techniques, to discover change templates from past changes. The solution is analyzed through a prototypical implementation of a change template miner subsystem called CHANGEMINER, and a set of experiments based on a real-life scenario.
Weverton Luis da Costa Cordeiro, Guilherme Sperb Machado, Fabrício Girardi Andreis, Juliano Araújo Wickboldt, Roben Castagna Lunardi, Alan Diego dos Santos, Cristiano Bonato Both, Luciano Paschoal Gaspary, Lisandro Z. Granville, David Trastour, Claudio Bartolini
Integrated Network Management8
2009 Refined failure remediation for IT change management systems
abstract
In order to deal with failures in the deployment of IT changes and to always leave IT infrastructures into consistent states, we proposed in a previous work, a solution to automate the generation of rollback plans in IT change management systems. The solution was based on a mechanism that treats Requests for Change (RFC) (or parts of them) as a single atomic transaction. In this work, we extend our previous investigation and present more flexible and fine grained treatment of failures. The paper first presents extensions to our conceptual model in order (i) to give IT operators some flexibility in defining rollback actions, for example, by allowing the rollback plan to not only be a reversed change plan; and (ii) to execute different recovery activities depending on the cause and location of a problem. The paper then focuses on a refined manner to handle and treat failures in change deployments. We follow the ITIL version 3 best practises which suggest that, depending on the RFC context, the human operator can classify activities as reversible or irreversible. Such classification allows change management systems to automatically generate more accurate remediation plans. The proposal takes into account not only a precise way to define how rollback plans will be generated, but also an intuitive method enabling the operator to define compensation activities in order to complete the RFC successfully, even with the occurrence of failures. To prove the concept and technical feasibility, we have materialized our solution in the CHANGELEDGE prototype that, using elements of the Business Process Execution Language (BPEL), is able to generate correct remediation plans to handle and treat failures in IT change management systems.
Guilherme Sperb Machado, Weverton Luis da Costa Cordeiro, Alan Diego dos Santos, Juliano Araújo Wickboldt, Roben Castagna Lunardi, Fabrício Girardi Andreis, Cristiano Bonato Both, Luciano Paschoal Gaspary, Lisandro Z. Granville, David Trastour, Claudio Bartolini
Integrated Network Management8
2009 A solution to support risk analysis on IT Change Management
abstract
The growing necessity of organizations in using technologies to support to their operations implies that managing IT resources became a mission-critical issue for the health of the primary companies' businesses. Thus, in order to minimize problems in the IT infrastructure, possibly affecting the daily business operations, risks intrinsic to the change process have to be analyzed and assessed. Risk Management is a widely discussed subject in several areas, although for IT Change Management it is quite a new discipline. The Information Technology Infrastructure Library (ITIL) introduces a set of best practices to conduct the management of IT infrastructures. According to ITIL, risks should be investigated, measured, and mitigated before any change is approved. Even with these guidelines, there is no default automatic method for risk assessment in IT Change Management. In this paper we introduce a risk analysis method based on the execution history of past changes. In addition, we propose a failure representation model to capture the feedback of the execution of changes over IT infrastructures.
Juliano Araújo Wickboldt, Guilherme Sperb Machado, Weverton Luis da Costa Cordeiro, Roben Castagna Lunardi, Alan Diego dos Santos, Fabrício Girardi Andreis, Cristiano Bonato Both, Lisandro Z. Granville, Luciano Paschoal Gaspary, Claudio Bartolini, David Trastour
Integrated Network Management9
2009 Breaking the barriers between security mechanisms through the composition of Web Services: Towards a solution for the detection of multistage distributed attacks
abstract
In recent years, the number of planned and coordinated attacks, such as DDoS (Distributed Denial of Service), has increased significantly. These attacks, also known as multistage attacks, are composed of several stages and originated from multiple sources (hosts). Traditional Intrusion Detection Systems (IDSes) do not tackle adequately such attacks, mainly due to the lack of mechanisms for uniform communication with distinct security systems (e.g., other IDSes, firewalls, etc.) and for the correlation, in a timely manner, of the observed events. In a first attempt to address the aforementioned issues, in this paper we propose a solution for the detection of multistage, distributed attacks based on the creation of security oriented Web Services. The solution comprises two key components: (i) a novel language for the specification of the diverse stages that compose a multistage attack, and (ii) SECCOMPOSE, a service oriented architecture for multistage, distributed attack detection.
Leonardo Lemes Fagundes, Luciano Paschoal Gaspary
ISCC2
2009 AGRADC: An architecture for autonomous deployment and configuration of grid computing applications
abstract
Deployment and configuration of grid computing applications are exhaustive and error-prone tasks, and represent a weak link of the lifecycle of grid applications. To address the problem, this paper proposes AGRADC, an architecture to instantiate grid applications on demand, which incorporates features from the Autonomic Computing paradigm. This architecture improves the grid application development process, providing tools to define a deployment flow, configuration parameters, and actions to be executed when adverse situations like faults arise.
Luciano Paschoal Gaspary, Weverton Luis da Costa Cordeiro, Sidnei Roberto Selzler Franco, Marinho P. Barcellos, Gerson G. H. Cavalheiro
ISCC1
2009 ChangeLedge: Change design and planning in networked systems based on reuse of knowledge and automation
Weverton Luis da Costa Cordeiro, Guilherme Sperb Machado, Fabrício Girardi Andreis, Alan Diego dos Santos, Cristiano Bonato Both, Luciano Paschoal Gaspary, Lisandro Z. Granville, Claudio Bartolini, David Trastour
Comput. Networks6
2008 A template-based solution to support knowledge reuse in IT change design
abstract
Capturing and reusing the experience of operators in implementing IT changes is an important aspect of IT service management, as it may result in fewer incidents (upon change execution) and faster specification of change plans, to mention just a few potential advantages. Nevertheless, in practice, changes are usually described and documented in an ad hoc fashion, due to the lack of proper support to assist the design process. This hampers knowledge acquired when specifying, planning, and carrying out previous changes to be reused in subsequent requests. In order to address this issue, we propose the use of change templates as a mechanism to formalize, preserve, and reuse the experience accumulated within organizations in relation to IT changes. Our solution is analyzed through a prototypical implementation of a change management system and a case study based on a real-life scenario.
Weverton Luis da Costa Cordeiro, Guilherme Sperb Machado, Fabio Fabian Daitx, Cristiano Bonato Both, Luciano Paschoal Gaspary, Lisandro Z. Granville, Akhil Sahai, Claudio Bartolini, David Trastour, Katia Barbosa Saikoski
NOMS5
2008 Enabling rollback support in IT change management systems
abstract
The current research on IT change management has been exploring several aspects of this new discipline, but it usually assumes that changes expressed in requests for change (RFC) documents will be successfully executed over the managed IT infrastructure. This assumption, however, is not realistic in actual IT systems because failures during the execution of changes do happen and cannot be ignored. In order to address this issue, we propose a solution where tightly-related change activities are grouped together forming atomic groups of activities. These groups are atomic in the sense that if one activity fails, all other already executed activities of the same group must rollback to move the system backwards to the previous state. The automation of change rollback is especially convenient because it relieves the IT human operator of manually undoing the activities of a change group that has failed. To prove concept and technical feasibility, we have materialized our solution in a prototype system that, using elements of the business process execution language (BPEL), is able to control how atomic groups of activities must be handled in IT change management systems.
Guilherme Sperb Machado, Fabio Fabian Daitx, Weverton Luis da Costa Cordeiro, Cristiano Bonato Both, Luciano Paschoal Gaspary, Lisandro Z. Granville, Claudio Bartolini, Akhil Sahai, David Trastour, Katia Barbosa Saikoski
NOMS5
2008 Applying a model of configuration complexity to measure security impact on IT procedures
abstract
IT security has become over the recent years a major concern for organizations. However, it doesn’t come without large investments on both the acquisition of tools to satisfy particular security requirements and complex procedures to deploy and maintain a protected infrastructure. The scientific community has proposed in the recent past models and techniques to measure the complexity of configuration procedures, aware that they represent a significant operational cost, often dominating total cost of ownership. However, despite the central role played by security within this context, it has not been subject to any investigation so far. To address this issue, we apply a model of configuration complexity proposed in the literature in order to be able to estimate security impact on the complexity of IT procedures. Our proposal has been materialized through a prototypical implementation of a complexity scorer system called Security Complexity Analyzer (SCA). To prove concept and technical feasibility of our proposal, we have used the SCA to evaluate real-life security scenarios.
Giovane Cesar Moreira Moura, Luciano Paschoal Gaspary
NOMS2
2008 Distinguished experts panel
abstract
In recent years we have been introduced to computing environments that integrate wireless and wired components, providing ubiquitous access to information services and applications in a seamless manner. The years to come are expected to be more exciting as we will witness a proliferation in the use of emerging wireless technologies (e.g., sensor networks, vehicular networks, etc.) and enhanced networked applications (e.g., biosensing networks for healthcare, terrestrial ecology observing systems, smart spaces, dynamic communities, etc.) Such increasingly pervasive environments will require new management strategies, which can cope with resource constraints, multi-federated operation, scalability, dependability, context awareness, security, mobility, to mention just a few challenges. The issue to be addressed in this Distinguished Experts Panel is whether we are reinventing the wheel or there are real new challenges ahead. If so, what are they, in which context, and how should we approach them? If not, how can existing management solutions be used/combined/modified/extended in order to address the management needs the emeging ubiquitous environments?
George Pavlou, Luciano Paschoal Gaspary
NOMS2
2007 On the Performance of Web Services Management Standards - An Evaluation of MUWS and WS-Management for Network Management
abstract
Important steps have been taken in the recent years towards evaluating the performance of Web services for network management. Due to the lack of specific standards for Web services-based management, previous evaluations have been carried out measuring only the performance of SOAP (the basic Web services protocol) running in network management environments. While the conclusions of the papers published so far indicate the feasibility of employing Web services for network management, there is no evidence that these conclusions also hold for solutions developed according to recent Web services management standards. In this paper we go a step further and present the results of a set of experiments carried out in order to compare the specifications OASIS management Using Web services (MUWS) and DMTF Web services for management (WS-management) against the de facto network management standard, i.e., the simple network management protocol (SNMP). The performance metrics investigated were network usage, response time, and CPU usage.
Giovane Cesar Moreira Moura, Giancarlo Silvestrin, Ricardo Nabinger Sanchez, Luciano Paschoal Gaspary, Lisandro Z. Granville
Integrated Network Management4
2007 Flexible security in peer-to-peer applications: Enabling new opportunities beyond file sharing
Luciano Paschoal Gaspary, Marinho P. Barcellos, André Detsch, Rodolfo Stoffel Antunes
Comput. Networks1
2006 Flexible Security Configuration & Deployment in Peer-to-Peer Applications
abstract
The widespread adoption of P2P applications in environments beyond ordinary file sharing demands the fulfillment of several security requirements. Important steps have been taken towards security in P2P systems, with relevant mechanisms being proposed in the past to address specific vulnerabilities. However, existing approaches lack flexibility, since they do not (include enough mechanisms to) tackle a wide range of requirements in an integrated fashion. In addition, they oblige the user/application to manipulate a complex programming interface, as well as going through a cumbersome configuration process. To address these issues, we present P2PSL (P2P security layer), which allows gradual and flexible integration of security functionality into P2P applications. To show concept and technical feasibility, we have implemented P2PSL, assessed the overhead it induces, and incorporated the layer into a P2P-based grid computing infrastructure
André Detsch, Luciano Paschoal Gaspary, Marinho P. Barcellos, Ricardo Nabinger Sanchez
NOMS2
2005 A SNMP-based platform for distributed stateful intrusion detection in enterprise networks
abstract
In recent years, intrusion detection systems (IDSs) use has increased into detect security breaches in both systems and networks. However, widespread IDS usage has been hindered by several challenges, including: 1) time-consuming configuration and analysis; 2) integration difficulties with existing network management infrastructure; and 3) the inability to add new attack signatures in a well-understood, yet expressive high-level notation. This paper presents the ID-Trace Management Platform, an extension of the simple network management protocol infrastructure based on the Internet Engineering Task Force (IETF) script management information base (Script MIB) to support distributed stateful intrusion detection in enterprise networks. It provides mechanisms allowing a management station to delegate security-related tasks to mid-level managers (MLMs) that, in turn, interact with monitoring and action agents to execute these tasks. Protocol trace specification language specifications are used by the MLMs to program monitoring agents that sniff packets on the network comparing their signatures to those of known attack signatures. With the information gathered from the monitoring process, the MLMs may execute procedures via the action agents (Java, Tcl, or Perl scripts), enabling the automation of several security tasks (including reactive and proactive tasks). The platform also provides notification mechanisms (traps) so that MLMs can report the occurrence of major events to the management station.
Luciano Paschoal Gaspary, Ricardo Nabinger Sanchez, D. W. Antunes, Edgar Meneghetti
IEEE J. Sel. Areas Commun.1
2004 Assessing transaction-based Internet applications performance through a passive network traffic monitoring approach
abstract
The paper proposes an approach to monitor the response time of transaction-based Internet applications and protocols that uses a passive network traffic monitoring technique and stores the resulting statistics in a management information base compatible with the SNMP architecture. The work is within the scope of the Trace platform, which provides support for high-layer protocols, services and networked applications management. The implementation of the proposed approach comprises the extension of the monitoring agent, a key component of the platform, so that it stores information related to response time and generates performance-related reports.
Luciano Paschoal Gaspary, Ederson Canterle
GLOBECOM1
2004 Identification of Intrustion Scenarios through Classification, Characterization and Analysis of Firewall Events
abstract
The content analysis of firewall logs is essential (i) to quantify and identify accesses to external and private networks, (ii) to follow the historical growth of accesses volume and applications used, (iii) to debug problems on the configuration of filtering rules and (iv) to recognize suspicious event sequences that indicate strategies used by intruders in attempts to obtain non-authorized access to stations and services. The paper presents an approach to classify, characterize and analyze events generated by firewalls. The proposed approach explores the case-based reasoning technique to identify possible intrusion scenarios. The paper also describes the validation of our approach carried out based on real logs generated during one week by the university firewall.
Luciano Paschoal Gaspary, Cristina Melchiors, Fábio Elias Locatelli, Fabiane Dillenburg
LCN1
2003 An SNMP Agent for Stateful Intrusion Inspection
Luciano Paschoal Gaspary, Edgar Meneghetti, Liane Margarida Rockenbach Tarouco
Integrated Network Management1
2002 High-layer protocol and service management based on passive network traffic monitoring: the trace management platform
abstract
A fast-growing number of high-layer protocols, services and networked applications has been run over computer networks and needs to be managed. A unified, decentralized framework should be used to scale for the current large and complex computing environments. Besides, the management environment should be quickly and easily adaptable to monitor dynamic scenarios. This paper presents the trace management platform, an extension of the SNMP infrastructure based on the IETF Script MIB to support integrated, distributed and flexible management of high-layer protocols, services and networked applications.
Luciano Paschoal Gaspary, Edgar Meneghetti, Fabricio Wendt, Lucio Braga, Roberto Storch, Liane Margarida Rockenbach Tarouco
ISCC1
2002 DÓRIS - Pedagogical Agent in Intelligent Tutoring Systems
Cássia Trojahn dos Santos, Rejane Frozza, Alessandra Dhamer, Luciano Paschoal Gaspary
Intelligent Tutoring Systems4
2002 Trace: an open platform for high-layer protocols, services and networked applications management
abstract
This paper presents the Trace management platform, an extension of the SNMP infrastructure based on the IETF Script MIB to support integrated, distributed and flexible management of high-layer protocols, services and networked applications. The platform is specifically geared towards running and analyzing protocol interactions, and triggering custom scripts when certain conditions are met.
Luciano Paschoal Gaspary, Edgar Meneghetti, Fabricio Wendt, Lucio Braga, Luis Felipe Balbinot, Roberto Storch, Liane Margarida Rockenbach Tarouco
NOMS1
1999 MUSE: An Environment for the Conception of Java Multimedia Applications
Luciano Paschoal Gaspary, Maria Janilce Bosquiroli Almeida, Roberto Willrich
Multim. Tools Appl.1
1998 MUSE - An Interactive Networked Multimedia Applications Specification Environment with E-LOTOS Translator
Luciano Paschoal Gaspary, Maria Janilce Bosquiroli Almeida
CAiSE1