Giorgio Ventre

dblp:04/1480 · DBLP profile ↗
← Back
69ranked-venue papers
0as first author
13since 2021 · last 2025
0009-0007-3612-9075ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 39 · 4 since 2021Security and privacy · 6 · 3 since 2021Systems, architecture and hardware · 5Software engineering, systems software and programming languages · 4Artificial intelligence and machine learning · 3Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1Theory of computation · 1
YearPublicationVenuePosition
2025 ADAPTO: Scaling and Offloading Cloud-Native Network Functions in Future Mobile Networks
Alessio Botta, Roberto Canonico, Annalisa Navarro, Giovanni Stanco, Giorgio Ventre, Antonio Buonocunto, Antonio Fresa, Vincenzo Gentile, Leonardo Scommegna, Enrico Vicario, Enzo Mingozzi, Antonio Virdis, Marcello Cucurachi
AINA (6)5
2025 Novel Datasets and Traffic Generation Tools for Intrusion Detection in IoT Communications
abstract
Datasets constitute the foundation for the training of a robust Intrusion Detection System (IDS). In particular, IDSs could be useful in IoT scenarios, in which resource-constrained devices can not run traditional security software and require a monitoring entity within their network. In this research, we move along two main directions: on one hand, the analysis and description of significant datasets regarding the security of IoT communications; on the other, the exploration of tools that enable their generation. Following this division, we first depict IoT datasets available in the literature and compare them with respect to their most important characteristics according to the literature. We also compare them according to the most popular features that are typically collected in such scenarios, including network and transport layer information, temporal parameters, payload characteristics, and statistical indicators. We then move our attention to the software tools and frameworks which enable the generation of benign or malicious network traffic in various experimental environments and are used in the construction of datasets. We believe this work could serve as a useful starting point to develop novel approaches and techniques in the field.
Giovanni Stanco, Stefania Zinno, Pietro Violante, Alessio Botta, Giorgio Ventre
CNSM5
2025 A Lightweight Deep Learning Approach for Latency Prediction in 5G and Beyond
Stefania Zinno, Annalisa Navarro, Sayna Rotbei, Nicola Pasquino, Alessio Botta, Giorgio Ventre
CNSM6
2025 Exploring Depression Severity During Lockdown Through Explainable AI
abstract
Depression and anxiety are among the most common responses to large-scale traumatic episodes (e.g. pandemics or armed conflicts), particularly when these involve prolonged restriction measures for the population. The goal of this study is to predict the extent of depressive symptoms, evaluated using the Beck Depression Inventory-II (BDI-II) scale, during the COVID-19 lockdown, starting from scores of multiple psychological scales collected prior to the lockdown. More importantly, we aim to identify the most influential features driving these predictions through eXplainable AI (XAI) techniques. To this end, we selected Gradient Boosting as our predictive model and applied SHapley Additive exPlanations (SHAP) to assess feature importance. We then generated Partial Dependence Plots (PDPs) on the topranking features identified by SHAP to further explore their impact on the model's output. Scores from Item 9, Item 3, and Item 1 of the BDI-II scales, regarding Suicidal Thoughts, Sadness and Failure emerged as key predictors in the model.
Stefania Zinno, Sayna Rotbei, Giovanni Stanco, Giorgio Ventre, Giordano D'Urso, Alessio Botta
WiMob4
2024 Edge to Cloud Network Function Offloading in the ADAPTO Framework
Alessio Botta, Roberto Canonico, Annalisa Navarro, Giovanni Stanco, Giorgio Ventre, Antonio Buonocunto, Antonio Fresa, Vincenzo Gentile, Leonardo Scommegna, Enrico Vicario
AINA (5)5
2024 QoE for Interactive Services in 5G Networks: Data-driven Analysis and ML-based Prediction
abstract
Nowadays, the focus in 5G networks has shifted from Quality of Service (QoS) to Quality of Experience (QoE) characterisation and prediction. As a matter of fact, mobile operators are increasingly interested in measuring and/or predicting QoE Key Performance Indicators (KPIs) on their 5G networks. In this context, a recent methodology by the International Telecommunication Union Telecommunication Standardization Sector (ITU-T) allows to characterize the level of interactivity achievable by real-time services on 5G networks, by computing a synthetic QoE KPI referred to as interactivity score (i-score). The i-score, defined as the measurable latency, continuity, and reliability of a given service, is computed by using a model that takes into account three QoS KPIs, i.e., packet trip time, jitter, and loss rate. In this paper, aiming at assessing the effectiveness of the ITU-T methodology in characterizing 5G network performance, we analyze a large-scale measurement campaign executed over two commercial 5G Non-Standalone (NSA) deployments in the city of Rome, Italy. During this campaign, traces related to radio coverage and service performance (i.e., the i-score and corresponding KPIs needed to compute it) were collected in parallel. Therefore, we use the dataset to characterize the observed i-score performance, and demonstrate that it is possible to successfully predict this KPI with machine learning techniques, using radio layer parameters and power measurements. Mobile operators could take advantage of our findings, minimizing the need for time/resource-consuming QoE tests. Ensemble methods in fact achieve an accuracy spanning from 0.79 to 0.83, with Random Forest as one of the best algorithm to predict the i-score from radio layer parameters.
Stefania Zinno, Giuseppe Caso, Nicola Pasquino, Alessio Botta, Anna Brunström, Giorgio Ventre
CNSM6
2024 Adaptive overlay selection at the SD-WAN edges: A reinforcement learning approach with networked agents
abstract
Software-Defined Wide Area Networks (SD-WANs) have emerged as a promising solution to address the connectivity demands of modern distributed enterprises. However, the effective application of the Software Defined Networking (SDN) paradigm in such broad and dynamic environments remains a significant challenge. In this paper, we present two novel contributions. First, we design a decentralized control plane for SD-WANs that leverages edge-based network monitoring and overlays’ configuration. Then we present a Reinforcement Learning-based orchestration plane that leverages local information for the enforcement of SD-WAN policies. Since traditional approaches suffer either a lack of scalability due to the problem’s complexity or suboptimal performance due to isolated decision-making, the proposed approach leverages a cooperative Multi-Agent Reinforcement Learning framework. Our novel cooperative approach is based on per-site agents that exchange a small amount of information to enhance performance while preserving scalability. To validate the efficacy of our proposed approach, we conducted an extensive experimental evaluation considering diverse SD-WAN scenarios. Results show that our framework is able to satisfy global network policies for a multi-site SD-WAN with different QoS requirements and cost constraints.
Alessio Botta, Roberto Canonico, Annalisa Navarro, Giovanni Stanco, Giorgio Ventre
Comput. Networks5
2024 The human factor in phishing: Collecting and analyzing user behavior when reading emails
abstract
Phishing emails are constantly increasing their sophistication, and typical countermeasures struggle at addressing them. Attackers target our cognitive vulnerabilities with a varied set of techniques, and each of us, not trained enough or simply in the wrong moment, can be deceived and put an entire organization in trouble. To date, no study has evaluated the behavior of users when confronted with phishing emails characterized by a diverse set of features and attack strategies. We created a system called Spamley from these observations, which has the main aim of collecting and sharing data regarding such user behavior. Spamley is also meant to disseminate awareness among users. To reach these goals, we firstly analyzed the wide scientific literature on phishing. Our analysis shows that the focus of studies on phishing has more and more shifted from technical to human-oriented aspects. Building on this analysis we designed, implemented, and deployed a system comprising a web application to test user awareness about phishing, featuring a survey to identify the most interesting characteristics of users, and fueled by a large and varied set of test emails engineered to solicit the several possible cognitive vulnerabilities we all have. We describe in details the design and implementation choices, the lessons we learned, and the way we filled the gap in the available related work. Finally, we use real data from our first 500 users to show how data collected can be used for several important analyses, including which characteristics of the emails are more relevant for which cognitive vulnerability of specific groups of users. Results obtained can guide the development of novel email clients as well as tailored training programmes. Data collected is available to the scientific community for conducting further studies on the important and still unsolved issue of email phishing.
Danilo Gentile, Saverio Ruggiero, Alessio Botta, Giorgio Ventre
Comput. Secur.5
2023 Prediction of RTT Through Radio-Layer Parameters in 4G/5G Dual-Connectivity Mobile Networks
abstract
With E-UTRA-NR Dual Connectivity, terminals can connect to 4G Long-Term Evolution and 5G New Radio networks at the same time. This technology allows using multiple bandwidths belonging to the two radio layers, enhancing the overall system performance. The system also adopts Multiple Input Multiple Output on top of the dual radio layer access. Authors predict application-layer Round-Trip Time with Machine Learning algorithms leveraging radio layer parameters such as received power and signal quality. Binary classification techniques are adopted to predict if Round-Trip Time values are above or below a threshold. The prediction is tested with real data collected in two measurement campaigns. Results show that Random Forest and Decision Tree Classifiers are the best algorithms with a precision score of respectively 0.84 and 0.92 in both measurement setups. They also evidence the radio- and physical-layer information having more importance for predicting application-layer RTT.
Stefania Zinno, Antonia Affinito, Nicola Pasquino, Giorgio Ventre, Alessio Botta
ISCC4
2023 The evolution of Mirai botnet scans over a six-year period
abstract
The proliferation of Internet of Things devices has resulted in an increase in security vulnerabilities and network attacks. The Mirai botnet is a well-known example of a network used for malicious activities, detected for the first time by the white-hat research group in August 2016. Since then, Mirai initiated massive DDoS attacks by scanning for and exploiting vulnerabilities in network devices. In this paper, we investigate the evolution of the Mirai botnet over a six-year period, analyzing the TCP SYN packets using Mirai signature, i.e. with TCP sequence number equal to the destination IP address. Our analysis stands out as we extensively investigate the evolution of Mirai scans over a prolonged six-year period (2016–2022). Our findings reveal that the Mirai signature is still implemented by malicious actors today, in contrast with previous works. Moreover, we observe that the number of hijacked devices and TCP SYN packets involved in the scanning phase have increased over time. We also confirm that cybercriminals generally target Telnet port 23, followed by fewer requests on Telnet port 2323. Conversely, the number of probes on the SSH ports decreases over time, followed by a subsequent increase in 2022. Lastly, we identify several ports that had not been contacted until 2018 but have since received a large number of TCP SYN packets that verify the Mirai’s signature. These ports are linked with the emergence of new variants of the Mirai botnet.
Antonia Affinito, Stefania Zinno, Giovanni Stanco, Alessio Botta, Giorgio Ventre
J. Inf. Secur. Appl.5
2022 On the performance of IoT LPWAN technologies: the case of Sigfox, LoRaWAN and NB-IoT
abstract
Internet of Things is a widespread technology that comprises several networking solutions for connecting things to the rest of the Internet. Understanding the characteristics of such solutions is fundamental in order to satisfy the diverse requirements of all the possible applications. The goal of this paper is to empirically evaluate and compare the performance of the most spread technologies for IoT low-power long-range communications. The parameters considered are the energy efficiency, the message losses, and the latency of a message. Obtained results show that up to 2% of messages can be lost when using LoRaWAN, but the latency is always smaller than 7 seconds. NB-IoT shows slightly larger latency values and more delivered messages than LoRaWAN. The messages sent using Sigfox are always correctly delivered, but the communication introduces delays up to 100 seconds. These results are of great importance for all the players in the IoT scenario interested in LPWAN technologies. The results of this study show how different communication technologies provide significantly different performance.
Giovanni Stanco, Alessio Botta, Flavio Frattini, Ugo Giordano, Giorgio Ventre
ICC5
2021 A Machine Learning approach for dynamic selection of available bandwidth measurement tools
abstract
Available bandwidth is a vital parameter for understanding network status. A huge number of tools have been proposed in literature, including general ones as well as tools specialized for specific network scenarios. In this plethora of possibilities, an expert user is currently required to select the best one according to the specific operating settings, in order to achieve accurate results without disturbing the existing traffic.In this paper we propose the use of automatic decision systems based on machine learning to substitute the expert user and choose the right tool for the current scenario. To verify if this is a viable solution, we created a custom dataset and tested different decision systems including a simple, threshold-based one and four algorithms based on machine learning: k-nearest Neighbors, Random Forest, Support Vector Machine, and Long Short-Term Memory networks. We used different features including CPU, memory, and bandwidth and verified that the decision systems based on machine learning achieve very good performance and can be considered as a promising solution for this important problem.
Alessio Botta, Gennaro Esposito Mocerino, Stefano Cilio, Giorgio Ventre
ICC4
2021 2 Years in the anti-phishing group of a large company
Alessandro Maiello, Alessio Botta, Giorgio Ventre
Comput. Secur.4
2018 A user-oriented performance comparison of video hosting services
Alessio Botta, Aniello Avallone, Mauro Garofalo, Giorgio Ventre
Comput. Commun.4
2018 On a fair coexistence of LTE and Wi-Fi in the unlicensed spectrum: A Survey
Stefania Zinno, Giovanni Di Stasi, Stefano Avallone, Giorgio Ventre
Comput. Commun.4
2016 Dynamic Routing and Virtual Machine Consolidation in Green Clouds
abstract
In the last few years, there has been a remarkable growth in the number of data centers, which represent one of the leading sources of increased business data traffic on the Internet. An effect of the growing scale and the wide use of data centers is the dramatic increase of power consumption, with significant consequences both in terms of environmental and operational costs. Hence, energy awareness has become one of the major design constraints for Cloud infrastructures. In order to face these challenges, a new generation of energy-efficient and ecosustainable network infrastructures is needed. In this work, a novel energy-aware resource orchestration framework for distributed Cloud infrastructures is introduced, in order to manage both network and IT resources in a typical optical backbone. A high-level overview of the system architecture is provided by focusing on the definition of the different layers of the whole infrastructure, and introducing the Path Computation Element, which is the key component of the proposed architecture. The aim is to explain how both network and IT resources can be managed while, at the same time, the overall power consumption is being minimized and QoS requirements are satisfied. Finally, a green migration plan that is obtained by applying Virtual Machine relocation algorithms is discussed, in order to dynamically react to the fluctuating resource requirements of the VMs.
Giovanni B. Fioccola, Pasquale Donadio, Roberto Canonico, Giorgio Ventre
CloudCom4
2016 Internet Streaming and Network Neutrality: Comparing the Performance of Video Hosting Services
Alessio Botta, Aniello Avallone, Mauro Garofalo, Giorgio Ventre
ICISSP4
2016 A PCE-based architecture for green management of virtual infrastructures
Giovanni B. Fioccola, Pasquale Donadio, Roberto Canonico, Giorgio Ventre
Comput. Commun.4
2013 O-Gene: Towards an open green network control plane
abstract
Recent contributions on energy-aware management, aimed at improving the energy efficiency of network infrastructures are based on a combined use of two levers: power consumption optimization obtained by (wholly or partially) switching off a single network device and traffic engineering strategies (with related algorithms) that, given the traffic model on a daily time period, minimize the global energy consumption avoiding traffic congestion. Switches, routers and links of the actual Internet are often represented by simple power consumption models, based on just a few states (typically, on and off). Time for off-to-on switching is often ignored. We claim that complex large-scale network infrastructures need an energy-conscious control plane, which is able of quickly configuring the network by taking into account both energy efficiency goals and QoS constraints. In this paper we present a green extension to the GMPLS network control plane, that is able of minimizing the global power consumption under QoS constraints. Time for fully activating components that were initially in stand-by or off is considered as a QoS requirement.
Pasquale Donadio, Silvia Russo, Roberto Canonico, Giorgio Ventre
ISCC4
2012 Energy efficient online routing of flows with additive constraints
Stefano Avallone, Giorgio Ventre
Comput. Networks2
2011 Transparent migration of virtual infrastructures in large datacenters for Cloud computing
abstract
Cloud-enabled datacenters need advanced support for an integrated management of platform virtualization technologies. The networking infrastructure of large-scale datacenters is implemented according to redundant multi-tiered architectures whose layers operate at Layer 3 of the networking stack. Splitting the network infrastructure of a datacenter in a number of IP subnets, however, creates limits to the migration of Virtual Machines, reducing the possibility for administrators to efficiently balance the load and reduce the energy consumption of the whole infrastructure. In this paper we propose an innovative solution that allows transparent migration of Virtual Machines across the whole datacenter, based on the coordinated use of NAT rules that need to be consistently managed across the layers of the datacenter networking infrastructure. We describe in details how our approach can be easily implemented with current network devices without any modification to their hardware and present an experimental evaluation of an early prototype of our solution.
Roberto Bifulco, Roberto Canonico, Giorgio Ventre, Vittorio Manetti
ISCC3
2010 Performance footprints of heavy-users in 3G networks via empirical measurement
Alessio Botta, Antonio Pescapè, Giorgio Ventre, Ernst W. Biersack, Stefan Rugel
WiOpt3
2010 Integration of 3G Connectivity in PlanetLab Europe
Alessio Botta, Roberto Canonico, Giovanni Di Stasi, Antonio Pescapè, Giorgio Ventre, Serge Fdida
Mob. Networks Appl.5
2009 Traffic analysis of peer-to-peer IPTV communities
Thomas Silverston, Olivier Fourmaux, Alessio Botta, Alberto Dainotti, Antonio Pescapè, Giorgio Ventre, Kavé Salamatian
Comput. Networks6
2009 A cascade architecture for DoS attacks detection based on the wavelet transform
abstract
In this paper we propose an automated system able to detect volume-based anomalies in network traffic caused by Denial of Service (DoS) attacks. We designed a system with a two-stage architecture that combines more traditional change point detection approaches (Adaptive Threshold and Cumulative Sum ) with a novel one based on the Continuous Wavelet Transform. The presented anomaly detection system is able to achieve good results in terms of the trade-off between correct detections and false alarms, estimation of anomaly duration, and ability to distinguish between subsequent anomalies. We test our system using a set of publicly available attack-free traffic traces to which we superimpose anomaly profiles obtained both as time series of known common behaviors and by generating traffic with real tools for DoS attacks. Extensive test results show how the proposed system accurately detects a wide range of DoS anomalies and how the performance indicators are affected by anomalies characteristics (i.e. amplitude and duration). Moreover, we separately consider and evaluate some special test-cases.
Alberto Dainotti, Antonio Pescapè, Giorgio Ventre
J. Comput. Secur.3
2009 A channel and rate assignment algorithm and a layer-2.5 forwarding paradigm for multi-radio wireless mesh networks
Stefano Avallone, Ian F. Akyildiz, Giorgio Ventre
IEEE/ACM Trans. Netw.3
2008 Providing UMTS connectivity to PlanetLab nodes
abstract
Planetlab is widely recognized as being one of the most important Internet-scale testbeds. However, while allowing experimentations involving hundreds of hosts spread all over the world, PlanetLab still suffers of a few significant limitations. One of these limitations is the lack of heterogeneity, in particular in terms of access technologies. In this paper we describe the efforts we made, in the context of the OneLab European project, in order to mitigate this problem. In particular, we describe how we managed to integrate UMTS connectivity into a PlanetLab-based testbed. We illustrate the technical challenges we had to face, the final result we obtained, and present a case study meant to show the utility of having UMTS connectivity available in Planetlab.
Alessio Botta, Roberto Canonico, Giovanni Di Stasi, Antonio Pescapè, Giorgio Ventre
CoNEXT5
2008 Networked Embedded Systems: A Quantitative Performance Comparison
abstract
Networked embedded systems are gaining more and more attention and their use in current network scenarios is of indisputable importance. Research community and industry are proposing novel embedded solutions, often based on network processors, for network connectivity, data processing and service delivery. Despite this, quantitative performance comparisons of such systems seem to be very hard to find. In this paper, we describe an experimental analysis of different boards for networked embedded systems using both general-purpose and network processors, and running both commercial and open source operating systems. The results show that network-processor based boards are able to attain very high performance when compared to boards based on x86 processors, especially when running commercial operating systems. The analysis provides a reference for the design, development, and testing of novel networked embedded systems.
Alessio Botta, Walter de Donato, Antonio Pescapè, Giorgio Ventre
GLOBECOM4
2008 An approach to the identification of network elements composing heterogeneous end-to-end paths
Alessio Botta, Antonio Pescapè, Giorgio Ventre
Comput. Networks3
2008 Internet traffic modeling by means of Hidden Markov Models
Alberto Dainotti, Antonio Pescapè, Pierluigi Salvo Rossi, Francesco Palmieri 0001, Giorgio Ventre
Comput. Networks5
2008 Performance measurement of IEEE 802.11b-based networks affected by narrowband interference through cross-layer measurements
abstract
Researches and development efforts in wireless networking and systems are progressing at an incredible rate. Among them, measurement and analysis of performance achieved at network layer and perceived by end users is an important task. In particular, recent advances concerning IEEE 802.11b-based networks seem to be focused on the measurement of key parameters at different protocol levels in a cross-layered fashion, because of their inherent vulnerability to in-channel interference. By adopting a cross-layer approach on a real network set-up operating in a suitable experimental testbed, packet loss against signal-to-interference ratio in IEEE 802.11b-based networks is hereinafter assessed. Results of several measurements aimed at establishing the sensitivity of IEEE 802.11b carrier sensing mechanisms to continuous interfering signals and evaluating the effects of triggered interference on packet transmission.
Leopoldo Angrisani, Antonio Pescapè, Giorgio Ventre, Michele Vadursi
IET Commun.3
2007 High-speed wireless backbones: measurements from MagNets
abstract
The long-standing vision of ubiquitous Internet access requires high-speed wireless networks that sustain 100 Mbps or more. While existing hardware already supports these speeds and they are available at single access points, measurement studies of existing mesh or multi-hop WiFi networks that cover and span larger areas report effective throughputs that are one or two orders of magnitude lower. We ask the question whether we can not already build high-speed wireless network that sustain high rates. To answer this question, we have built the MagNets high-speed WiFi backbone in the heart of Berlin. This paper presents an experimental evaluation of the single and multi-hop performance in terms of throughput, jitter, delay, packet loss, and assesses the impact of environmental factors on these parameters. Our results indicate, e.g. that some links achieve a sustained UDP throughput of up to 62 Mbps using off-the-shelf hardware supporting Super-AG modes, whereas others are limited to 4–5 Mbps due to interfering networks. In contrast, we show that the link performance is largely unaffected by environmental factors, such as day/night or social events (i.e. 2006 FIFA World Cup semi-final and final matches).
Alessio Botta, Antonio Pescapè, Giorgio Ventre, Roger P. Karrer
BROADNETS3
2007 Discovering Topologies at Router Level: Part II
abstract
Measurement and monitoring of network topologies are essential tasks in current network scenarios. Indeed, due to their utility in planning, management, security, and reliability of network infrastructures, effective and efficient approaches and tools for discovering large topologies are gaining more and more attention from both Application Service Providers and network administrators. In this paper we propose a hybrid methodology and its implementation in a software platform we calledHynetd. We present the architecture, some novel algorithms and methods adopted in the discovery chain, and a performance evaluation over two network scenarios: a small scale test-bed and a large scale MAN in the heart of Napoli (Italy). We provide experimental results confirming and improving those previously obtained by a prototype ofHynetd. In addition a comparison with a commercial tool is presented. Achieved results, in terms of accuracy, discovery time, and traffic injected, are very encouraging in both considered scenarios.
Alessio Botta, Walter de Donato, Antonio Pescapè, Giorgio Ventre
GLOBECOM4
2007 Reducing Network Traffic Data Sets
abstract
In the study of network traffic, the collection and the processing of measurement data sets play a fundamental role. Due to the large size of typical traffic traces, their analysis is often heavy in terms of computational time and resources. In addition, even when the data sets are small, due to the intrinsic redundancy of the data, there is no need to consider the entire data sets in the processing stages. To cope with these issues, we use anentropy-based methodology to reduce network traffic data sets obtained by measurements over real networks. The off-line approach we used is based on themarginalutilityconcept, and reveals encouraging results when applied to real data captured over real networks, especially when dealing with large amounts of data. To show the applicability of our approach, we present and discuss results obtained in the analysis and characterization, at packet-level, of traffic traces from two popular network games:Counter-StrikeandAgeofMythology. Thanks to the differences between the two considered on-line games and their traffic traces we can draw pros and cons in realistic scenarios.
Alessio Botta, Alberto Dainotti, Antonio Pescapè, Giorgio Ventre
ICC4
2007 Worm Traffic Analysis and Characterization
abstract
Internet worms are gaining ever more attention by the research community, representing one of the hot research topics in the field of network security. Our knowledge of phenomena related to Internet worms (from their intrinsic characteristics to their impact and to possible countermeasures) is still in its infancy. This is one of the main reasons for the existence of different kinds of research approaches. In this paper we focus on worm traffic analysis. We propose a general methodology, we discuss issues involved, and we present a software platform which can be used for this kind of study. Moreover, we show some interesting preliminary results from our traffic analysis of two of the most relevant worms that spread over the Internet: Witty and Slammer. Our results provide interesting evidences of (spatial and temporal) invariance and give some hints on worm traffic fingerprinting.
Alberto Dainotti, Antonio Pescapè, Giorgio Ventre
ICC3
2007 SCTP performance evaluation over heterogeneous networks
abstract
Abstract Since its definition in 2000, the Stream Control Transmission Protocol (SCTP) has attracted increasing interest. Several research works, often validated through analytical and simulative analysis, have attempted to evaluate the benefits of substituting TCP with SCTP, both for signaling and data transfer. In this work, we present a traffic generation and performance analysis tool to test SCTP on real networks. We study the performance of SCTP on real heterogeneous (wired/wireless) scenarios, providing results in terms of throughput and jitter, and comparing its performance against TCP and UDP over the same conditions. Our experimental analysis shows that the current performance of SCTP (operating on a Linux platform) does not justify the use of SCTP as a simple substitute for TCP. Copyright © 2007 John Wiley & Sons, Ltd.
Alberto Dainotti, Salvatore Loreto, Antonio Pescapè, Giorgio Ventre
Concurr. Comput. Pract. Exp.4
2006 Measuring SCTP Throughput and Jitter over Heterogeneous Networks
abstract
Stream control transmission protocol (SCTP) is gaining ever more attention. Several proposals, based on simulation results, aiming to replace TCP with SCTP are present. To the best of our knowledge there are no available tools supporting SCTP traffic generation. In this work, to study the performance of SCTP in real heterogeneous (wired/wireless) scenarios, we provide some preliminary results in terms of throughput and jitter that we obtained using a tool we developed to support SCTP traffic generation in real networks. A comparison with TCP and UDP over the same scenarios is also present.
Donato Emma, Salvatore Loreto, Antonio Pescapè, Giorgio Ventre
AINA (2)4
2006 Searching for invariants in network games traffic
abstract
Even if Internet traffic analysis and characterization is a fertile research area, a lot of work still must be done to study and understand the traffic characteristics of new emerging multimedia applications. Among them, an interesting category is that of multiplayer network games. This paper aims at demonstrating that, at packet level, spatial and temporal invariants exist in the traffic of such applications. For this purpose, we study Counter-Strike, a popular client/server network game, comparing results from two different networks. The effectiveness of the proposed approach is evaluated by studying statistics of both packet size and inter-packet time. Results provide a view on packet-level game traffic and they confirm that the main traffic dynamics present properties that can be generalized, independently of the observation point and time.
Alberto Dainotti, Alessio Botta, Antonio Pescapè, Giorgio Ventre
CoNEXT4
2006 An HMM Approach to Internet Traffic Modeling
abstract
Traffic modeling is a fertile research area. This paper proposes a packet-level traffic model of traffic sources based on hidden Markov model. It has been developed by using real network traffic and estimating in a combined fashion packet size and inter packet time. The effectiveness of the proposed model is evaluated by studying several traffic types with strong differences in terms of both applications/users and protocol behavior. Indeed, we applied our model to real traffic traces of Age of Mythology (a Multi Player Network Game), SMTP, and HTTP. An analytical basis and the mathematical details regarding the model are given. Results show how the proposed model captures first-order statistics, as well as temporal dynamics via auto- and cross-correlation. Also, the capability to accurately replicate the considered traffic sources is shown. Finally, preliminary results for model-based traffic prediction reveal encouraging.
Alberto Dainotti, Antonio Pescapè, Pierluigi Salvo Rossi, Giulio Iannello, Francesco Palmieri 0001, Giorgio Ventre
GLOBECOM6
2006 Wavelet-based Detection of DoS Attacks
abstract
Automated detection of anomalies in network traffic is an important and challenging task. In this work we propose an automated system to detect volume-based anomalies in network traffic caused by denial of service (DoS) attacks. The system has a two-stage architecture that combines more traditional approaches (adaptive threshold and cumulative sum) with a novel one based on the continuous wavelet transform. Thanks to the proposed architecture, we obtain good results in terms of tradeoff between correct detections and false alarms, estimation of anomaly duration, and ability to distinguish between subsequent anomalies. We test our system using a set of publicly available traffic traces to which we superimpose anomalies related to real DoS attacks tools. Extensive test results show how the proposed system accurately detects a wide range of anomalies and how the performance indicators are affected by anomalies characteristics (i.e. amplitude and duration).
Alberto Dainotti, Antonio Pescapè, Giorgio Ventre
GLOBECOM3
2006 Identification of Network Bricks in Heterogeneous Scenarios
abstract
Accurate identification of network elements (network bricks) composing end-to-end paths represents a novel and interesting research topic. In heterogeneous scenarios, automatic network bricks identification can improve the performance of adaptive and network-aware applications. This work proposes an approach, based on Bayesian classifiers, for the identification of network bricks belonging to a large number of real heterogeneous end-to-end paths. The identification is performed by means of measurement and off-line observation of delay, jitter, and packet loss. We introduce the term "blind identification" meaning the capability to identify network bricks, by looking at quality of service (QoS) parameters observed on the end-to-end path. We propose first insights and preliminary results regarding the identification stage, based on both concise and detailed QoS parameters statistics. Moreover, we show some results of the identification performed using a reduced set of QoS parameters
Alessio Botta, Antonio Pescapè, Giorgio Ventre
LCN3
2006 Research challenges in QoS routing
Xavier Masip-Bruin, Marcelo Yannuzzi, Jordi Domingo-Pascual, Alexandre Fonte, Marília Curado, Edmundo Monteiro, Fernando A. Kuipers, Piet Van Mieghem, Stefano Avallone, Giorgio Ventre, Pedro A. Aranda-Gutiérrez, Matthias Hollick, Ralf Steinmetz, Luigi Iannone, Kavé Salamatian
Comput. Commun.10
2006 Design principles and algorithms for effective high-speed IP flow monitoring
Maurizio Molina, Agostino Chiosi, Salvatore D'Antonio, Giorgio Ventre
Comput. Commun.4
2006 Systematic performance modeling and characterization of heterogeneous IP networks
Alessio Botta, Donato Emma, Antonio Pescapè, Giorgio Ventre
J. Comput. Syst. Sci.4
2006 High Performance Internet Traffic Generators
Stefano Avallone, Donato Emma, Antonio Pescapè, Giorgio Ventre
J. Supercomput.4
2005 Would Self-organized or Self-managed Networks Lead to Improved QoS?
David Hutchison 0001, Gísli Hjálmtýsson, James P. G. Sterbenz, Giorgio Ventre, John B. Vicente
IWQoS4
2005 Time-aware admission control on top of time-unaware network infrastructures
Salvatore D'Antonio, Marcello Esposito, Simon Pietro Romano, Giorgio Ventre
Comput. Commun.4
2005 Experimental analysis of attacks against intradomain routing protocols
abstract
Nowadays attacks against the routing infrastructure are gaining an impressive importance. Therefore, approaches to network security and reliability must take into account effects of routing protocols attacks and consequently must consider techniques to protect the network infrastructure. However, i n spite of an increasing attention by scientists and practitioners to this issue, there is still a lack of experimental quantitative studies on the effects of routing attacks. To cope with these deficiencies, in this work we present a framework to conduct experimental analysis of routing attacks, and to prove its usefulness we study three attacks against routing protocols: route flapping on RIP, Denial of Service on OSPF by means of the Max Age attack and, finally, route forcing on RIP. We present a qualitative analysis and a performance analysis that aims to quantify the effects of routing protocol attacks with respect to routers resources and network traffic over controlled test beds.
Antonio Pescapè, Giorgio Ventre
J. Comput. Secur.2
2005 Performance evaluation of an open distributed platform for realistic traffic generation
Stefano Avallone, Donato Emma, Antonio Pescapè, Giorgio Ventre
Perform. Evaluation4
2004 Experimental analysis of attacks against routing network infrastructures
abstract
At the present time, attacks against routing infrastructure are gaining an impressive importance. Currently an approach to network security and reliability must take into account the effects of routing protocols attacks and techniques for network infrastructure protection. This work presents an experimental analysis of three well know attacks against routing protocols: route flapping on RIP, denial of service on OSPF (max age attack) and finally route forcing on RIP. We also present this last attack in a rudimental traffic engineering mechanism.
Antonio Pescapè, Giorgio Ventre
IPCCC2
2004 An efficient approach to the network division problem, VLANs configuration and WLANs hosts grouping
abstract
Nowadays, network design and management can be considered as well understood topics. A thorough view of a complete project of a network infrastructure is definitely more important than its single details. Among the many innovations introduced in the IP networks, an interesting issue is represented by enhanced architectures where services like telephony and video transmission are provided on the same infrastructure used for data traffic. At the same time, actual networks are heterogeneous in terms of access network technologies, end user's device and finally operating systems. In these new scenarios innovative and efficient management's approaches are needed. This paper describes a proposal to improve the management of different network scenarios. This work presents a "partitioning algorithm" and some of its possible practical applications in the field of shared LANs, full switched LANs, VLANs (virtual local area networks) configuration, and in WLANs (wireless local area networks) environments.
Marcello Esposito, Antonio Pescapè, Giorgio Ventre
LANMAN3
2004 An architecture for automatic configuration of integrated networks
abstract
Configuration and management activities are frequently performed both in local area and campus networks due to the intrinsic variability characterizing such networks and the innovative services provided through them. Indeed, in order to benefit from services like voice over IP and multimedia content distribution, corporate users need to configure and manage their network appropriately. Suitable strategies have to be undertaken to fulfill stringent requirements imposed by such services on the underlying "integrated" transport infrastructure. These activities are both time and money consuming since they are usually under the responsibility of network administrators and managers. We present an architecture that allows the configuration of network devices in an automatic fashion in order to facilitate traffic management and prioritization in LANs. On one hand, traffic management is optimized through the segmentation of a corporate network into multiple virtual LANs via SNMP. On the other, traffic prioritization is carried out by grouping LAN packets into separate classes associated with different priority levels in compliance with 802.1p. The segmentation process is carried out in two steps: in the first, the network segmentation into "multimedia hosts" (i.e., IP phone and multimedia PC) and "data hosts" is accomplished (as well as traffic prioritization); in the second, the segmentation task is optimized in both VLANs thanks to the utilization of a "partitioning algorithm".
Salvatore D'Antonio, Maurizio D'Arienzo, Antonio Pescapè, Giorgio Ventre
NOMS (1)4
2004 Managing service level agreements in Premium IP networks: a business-oriented approach
Salvatore D'Antonio, Maurizio D'Arienzo, Marcello Esposito, Simon Pietro Romano, Giorgio Ventre
Comput. Networks5
2003 An XML Description Language for Web-Based Network Simulation
abstract
Simulation of large scale network scenarios is a challenging task and requires a great amount of computational power. Hence, realizing Web-accessible simulation servers is a key step for the success of network simulation as a useful instrument in the context of network administration and capacity planning. This paper presents an XML-based description language for describing network simulation scenarios. For the proposed language, we also present an XSL translation process that can be used to automatically translate a simulation scenario into a simulation script for a well known network simulator. This work is part of a larger project, aimed at implementing a cluster-based network simulation server to be integrated in a distributed system for QoS monitoring, SLA validation and measurement-based modeling in an inter-domain environment.
Roberto Canonico, Donato Emma, Giorgio Ventre
DS-RT3
2003 Introducing QoS awareness in distributed programming: QTcl
abstract
Abstract A number of distributed applications require communication services with quality of service (QoS) guarantees. Building global‐scale distributed systems with predictable properties is one of the great challenges for computer systems engineering in the new century. Work undertaken within the Internet Engineering Task Force has led to the definition of novel architectural models for the Internet with QoS support. According to these models, the network has to be appropriately configured in order to provide applications with the required performance guarantees. In next‐generation networks, enabling applications to interact with the underlying QoS services is of primary importance. Hence, several special‐purpose application programming interfaces (APIs) have been defined to let applications negotiate QoS parameters across QoS‐capable networks. However, so far, none of these APIs are available in different operating environments. We believe that such features should be embedded in programming environments for distributed applications. In this work we present how we included QoS control features in Tcl, a programming language that has been widely adopted for the development of distributed multimedia applications. Our work has led to the implementation of QTcl, an extended Tcl interpreter that provides programmers with a new set of primitives, in full compliance with the standard SCRAPI programming interface for the RSVP protocol. QTcl in highly portable, in that it enables standard QoS negotiation to be performed in a seamless fashion on the most common operating systems. Copyright © 2003 John Wiley & Sons, Ltd.
Roberto Canonico, Maurizio D'Arienzo, Simon Pietro Romano, Giorgio Ventre
Softw. Pract. Exp.4
2002 An active security protocol against DoS attacks
abstract
Denial of service (DoS) attacks represent, in today's Internet, one of the most complex issues to address. A session is under a DoS attack if it cannot achieve its intended throughput due to the misbehavior of other sessions. Many research studies dealt with DoS, proposing models and/or architectures mostly based on an attack prevention approach. Prevention techniques lead to different models, each suitable for a single type of misbehavior, but do not guarantee the protection of a system from a more general DoS attack. We analyze the fundamental requirements to be satisfied in order to protect hosts and routers from any form of distributed DoS (DDoS). Then we propose a network signaling protocol, named active security protocol(ASP), which satisfies most of the defined requirements. ASP provides an active protection from a DDoS attack, being able to adapt its defense strategies to the current type of violation. Protocol specification and design are performed using an object oriented methodology: we used Unified Modeling Language (UML) as a software description language.
Domenico Cotroneo, L. Peluso, Simon Pietro Romano, Giorgio Ventre
ISCC4
2002 An active network approach to virtual private networks
abstract
Virtual private networks (VPN) represent, in today's Internet, one of the most interesting applications. This is due both to their usefulness in corporate network scenarios and to the high revenues they guarantee to network providers. We propose an innovative approach to VPN implementation, exploiting the capabilities of active networks. We present a model aiming at building and dynamically configuring VPNs in a modular way and with a high degree of flexibility. We claim that the proposed approach has substantial advantages over traditional techniques and clearly shows how active technologies may help network engineers realize a number of critical applications for next generation networks.
R. Maresca, Maurizio D'Arienzo, Marcello Esposito, Simon Pietro Romano, Giorgio Ventre
ISCC5
2002 A Framework for Policy-Based Management of QoS Aware IP Networks
Piergiorgio Cremonese, Marcello Esposito, Silvia Giordano, M. Mondini, Simon Pietro Romano, Giorgio Ventre
NETWORKING6
2002 On the introduction of quality of service awareness in legacy ditributed applications
abstract
A number of distributed applications require communication services with Quality of Service (QoS) guarantees. Work undertaken within the Internet Engineering Task Force (IETF) has led to the definition of novel architectural models for the Internet with QoS support. According to these models, the network has to be appropriately configured in order to provide applications with the needed performance guarantees. In a first proposal, called Integrated Services, applications need to explicitly interact with network routers by means of a signaling protocol (such as RSVP), in order to enforce QoS on a per-flow basis. The Differentiated Services architecture, on the other hand, looks after scalability, thus providing performance guarantees to aggregates of flows. In the case of real-time applications, a hybrid model capable of putting together micro-flow guarantees in the access network and aggregate management in the backbone seems to represent the ideal tradeoff between strict performance and scalability. In this scenario, giving applications a means to interact with the underlying QoS services is of primary importance. Hence, several special-purpose APIs have been defined to let applications negotiate QoS parameters across QoS-capable networks. However, so far, none of these APIs is available for the use of programmers in different operating environments. We believe that such features should be embedded in programming environments for distributed applications. In this work we present how we included QoS control features in a programming language that since years has been adopted for the development of network-based applications: Tcl. We present QTcl, an extension of Tcl, which provides program- mers with a new set of primitives fully compliant with the standard SCRAPI programming interface for the RSVP protocol. We gave QTcl a high portability, in that it enables standard QoS negotiation to be performed in a seamless fashion on the most common operating systems.
Roberto Canonico, Maurizio D'Arienzo, B. Fadini, Simon Pietro Romano, Giorgio Ventre
SEKE5
2002 Designing service negotiation entities for the electronic market-place
abstract
The emergence of service providers and brokers who are independent of network providers has opened the way to a spot market in free network resources: it is under everybody's eyes that market enabled service provision based on Service Level Agreements (SLAs) will be essential for the delivery of many services such as bandwidth on demand. In order for those services to be created, configured and delivered dynamically via automated SLAs, a market enabling mechanism is required that is sufficiently flexible to convey the varying information requirements of the various stakeholders involved in the service delivery chain, together with their internal processes. In this paper an innovative framework for the negotiation of services with quality assurances is presented. The study is conducted keeping an eye on the latest standard proposals coming from the electronic business research community, with respect to both the modeling methodology and the actual design for implementation.
Salvatore D'Antonio, B. Fadini, Simon Pietro Romano, Giorgio Ventre
SEKE4
2001 Panel Discussion: How Will Media Distribution Work in the Internet
Andrew T. Campbell, Carsten Griwodz, Jörg Liebeherr, Dwight J. Makaroff, Andreas Mauthe, Giorgio Ventre, Michael Zink
IWQoS6
2000 A Scheme for Time-Dependent Resource Reservation in QoS-Enabled IP Networks
Roberto Canonico, Simon Pietro Romano, Mauro Sellitto, Giorgio Ventre
NETWORKING4
1997 Distributed Advance Reservation of Real-Time Connections
Domenico Ferrari, Amit Gupta 0001, Giorgio Ventre
Multim. Syst.3
1995 Distributed Advance Reservation of Real-Time Connections
Domenico Ferrari, Amit Gupta 0001, Giorgio Ventre
NOSSDAV3
1994 Guaranteed quality of service for efficient multiparty communication
Clemens A. Szyperski, Giorgio Ventre
Comput. Commun.2
1994 A Petri net based methodology to integrate qualitative and quantitative analysis
Monika Heiner, Giorgio Ventre, Dietmar Wikarski
Inf. Softw. Technol.2
1993 Galileo: A tool for simulation and analysis of real-time networks
abstract
Galileo is a flexible tool for simulation of heterogeneous real-time communication networks and for development and validation of network protocols. Galileo provides several unique features that make it particularly suitable for the simulation and analysis of networks that provide quality-of-service guarantees. First, its object-oriented programming environment provides the means for a modular, hierarchical, heterogeneous description of networks. Second, its multimedia device interface provides the tools for a qualitative analysis of network protocols. Finally, Galileo's network interface provides interaction with actual networks to access real data and simulate realistic multimedia scenarios.>
Edward W. Knightly, Giorgio Ventre
ICNP2
1992 Using CSP languages to program parallel workstation systems
Antonino Mazzeo, Stefano Russo 0001, Giorgio Ventre
Future Gener. Comput. Syst.3
1990 Parallel software development in the DISC programming environment
Giulio Iannello, Antonino Mazzeo, Carlo Savy, Giorgio Ventre
Future Gener. Comput. Syst.4