EDBT 2026 Demo / reviewers in the wild / expert
Giuseppe Siracusano
dblp:144/7799
· DBLP profile ↗
20ranked-venue papers
4as first author
10since 2021 · last 2026
0000-0002-8960-4622ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 4 · 1 since 2021Systems, architecture and hardware · 3 · 3 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Clean up the mess: Addressing data pollution in cryptocurrency abuse reporting services
Gibran Gómez, Kevin van Liebergen, Davide Sanvito, Giuseppe Siracusano, Roberto Gonzalez, Juan Caballero |
Future Gener. Comput. Syst. | 4 |
| 2025 | What Did I Do Wrong? Quantifying LLMs' Sensitivity and Consistency to Prompt EngineeringabstractFederico Errica, Davide Sanvito, Giuseppe Siracusano, Roberto Bifulco. Proceedings of the 2025 Conference of the Nations of the Americas Chapter of the Association for Computational Linguistics: Human Language Technologies (Volume 1: Long Papers). 2025. Federico Errica, Davide Sanvito, Giuseppe Siracusano, Roberto Bifulco |
NAACL (Long Papers) | 3 |
| 2025 | Web of shadows: Investigating malware abuse of internet services
Mauro Allegretta, Giuseppe Siracusano, Roberto Gonzalez, Marco Gramaglia, Juan Caballero |
Comput. Secur. | 2 |
| 2023 | Automatic Kernel Offload Using BPFabstractBPF support in Linux has made kernel extensions easier. Recent efforts have shown that using BPF to offload portions of server applications, e.g., memcached and service proxies, can improve application performance and efficiency. However, thus far, the community has not looked at the question of what parts of an application should be offloaded? This paper first shows that blindly offloading application functionality to the kernel is neither beneficial nor desirable, and care must be taken when deciding what to offload. Furthermore, when deciding what to offload, developers must consider not just the application, but also the workload being handled, and the kernel being targetted, Therefore, we advocate automating this decision process in a compiler, that can analyze application code, and produce two executables, a kernel offload and a userspace program, that jointly implement the application's functionality. This paper discusses the challenges that must be addressed to build such a compiler, and why they can be feasibly addressed. Farbod Shahinfar, Sebastiano Miano, Giuseppe Siracusano, Roberto Bifulco, Aurojit Panda, Gianni Antichi |
HotOS | 3 |
| 2023 | Are crowd-sourced CTI datasets ready for supporting anti-cybercrime intelligence?abstractCyber crimes rapidly increased over the past years, with attackers performing large-scale activities, using sophisticated and complex tactics and techniques, that have targeted governments, companies, and even strategic infrastructures. To tackle these attacks, the cyber-security community usually shares Cyber Threat Intelligence (CTI) that includes the collected Indicators of Compromise (IoC) using several open or private sharing platforms. In this paper, we study the informativeness and relevance of the IoCs related to cyber crimes following a major real-world event such as the war in Ukraine, which started in February 2022. To this end, we analyze different kinds of attacks available in a crowd-sourced dataset of Cyber Threat Intelligence (CTI) reports. Our analysis shows that while this data is able to capture major trends such as the ones following major events, the degree of miscellaneous information inside the reports makes it difficult to discern the association of a specific trace unequivocally. Mauro Allegretta, Giuseppe Siracusano, Roberto Gonzalez, Marco Gramaglia |
Comput. Networks | 2 |
| 2022 | Poster: MUSTARD - Adaptive Behavioral Analysis for Ransomware DetectionabstractBehavioural analysis based on filesystem operations is one of the most promising approaches for the detection of ransomware. Nonetheless, tracking all the operations on all the files for all the processes can introduce a significant overhead on the monitored system. We present MUSTARD, a solution to dynamically adapt the degree of monitoring for each process based on their behaviour to achieve a reduction of monitoring resources for the benign processes. Davide Sanvito, Giuseppe Siracusano, Roberto Gonzalez, Roberto Bifulco |
CCS | 2 |
| 2022 | Re-architecting Traffic Analysis with Neural Network Interface Cards
Giuseppe Siracusano, Salvator Galea, Davide Sanvito, Mohammad Malekzadeh, Gianni Antichi, Paolo Costa, Hamed Haddadi 0001, Roberto Bifulco |
NSDI | 1 |
| 2022 | Faster Software Packet Processing on FPGA NICs with eBPF Program Warping
Marco Bonola, Giacomo Belocchi, Angelo Tulumello, M. Spaziani Brunella, Giuseppe Siracusano, Giuseppe Bianchi 0001, Roberto Bifulco |
USENIX ATC | 5 |
| 2021 | The case for network functions decompositionabstractThis paper makes a case for writing unrestricted eBPF network functions which then get automatically decomposed between kernel and user-space. Farbod Shahinfar, Sebastiano Miano, Alireza Sanaee, Giuseppe Siracusano, Roberto Bifulco, Gianni Antichi |
CoNEXT | 4 |
| 2021 | On the Fly Orchestration of Unikernels: Tuning and Performance Evaluation of Virtual Infrastructure ManagersabstractNetwork operators are facing significant challenges meeting the demand for more bandwidth, agile infrastructures, innovative services, while keeping costs low. Network Functions Virtualization (NFV) and Cloud Computing are emerging as key trends of 5G network architectures, providing flexibility, fast instantiation times, support of Commercial Off The Shelf hardware and significant cost savings. NFV leverages Cloud Computing principles to move the data-plane network functions from expensive, closed and proprietary hardware to the so-called Virtual Network Functions (VNFs). In this paper we deal with the management of virtual computing resources (Unikernels) for the execution of VNFs. This functionality is performed by the Virtual Infrastructure Manager (VIM) in the NFV MANagement and Orchestration (MANO) reference architecture. We discuss the instantiation process of virtual resources and propose a generic reference model, starting from the analysis of three open source VIMs, namely OpenStack, Nomad and OpenVIM. We improve the aforementioned VIMs introducing the support for special-purpose Unikernels and aiming at reducing the duration of the instantiation process. We evaluate some performance aspects of the VIMs, considering both stock and tuned versions. The VIM extensions and performance evaluation tools are available under a liberal open source licence. Pier Luigi Ventre, Paolo Lungaroni, Giuseppe Siracusano, Claudio Pisa, Florian Schmidt 0002, Francesco Lombardo, Stefano Salsano |
IEEE Trans. Cloud Comput. | 3 |
| 2020 | hXDP: Efficient Software Packet Processing on FPGA NICs
M. Spaziani Brunella, Giacomo Belocchi, Marco Bonola, Salvatore Pontarelli, Giuseppe Siracusano, Giuseppe Bianchi 0001, Aniello Cammarano, Alessandro Palumbo, Luca Petrucci, Roberto Bifulco |
OSDI | 5 |
| 2019 | Poster: On the Application of NLP to Discover Relationships between Malicious Network EntitiesabstractThe increase in network traffic volumes challenges the scalability of security analysis tools. In this paper, we present NetLearn, a solution to identify potentially malicious network entities from large amounts of network traffic data. NetLearn applies recently developed natural language processing algorithms to discover security-relevant relationships between the observed network entities, e.g., domain names and IP addresses, without requiring external sources of information for its analysis. Giuseppe Siracusano, Martino Trevisan, Roberto Gonzalez, Roberto Bifulco |
CCS | 1 |
| 2019 | FlowBlaze: Stateful Packet Processing in Hardware
Salvatore Pontarelli, Roberto Bifulco, Marco Bonola, Carmelo Cascone, M. Spaziani Brunella, Valerio Bruschi, Davide Sanvito, Giuseppe Siracusano, Antonio Capone, Michio Honda, Felipe Huici |
NSDI | 8 |
| 2018 | A framework for experimenting ICN over SDN solutions using physical and virtual testbeds
Giuseppe Siracusano, Stefano Salsano, Pier Luigi Ventre, Andrea Detti, O. Rashed, Nicola Blefari-Melazzi |
Comput. Networks | 1 |
| 2017 | D-StreaMon: From middlebox to distributed NFV framework for network monitoringabstractMany reasons make NFV an attractive paradigm for IT security: lowers costs, agile operations and better isolation as well as fast security updates, improved incident responses and better level of automation. On the other side, the network threats tend to be increasingly complex and distributed, implying huge traffic scale to be monitored and increasingly strict mitigation delay requirements. Considering the current trend of the networking and the requirements to counteract to the evolution of cyber-threats, it is expected that also network monitoring will move towards NFV based solutions. In this paper, we present D-StreaMon an NFV-capable distributed framework for network monitoring realized to face the above described challenges. It relies on the StreaMon platform, a solution for network monitoring originally designed for traditional middleboxes. An evolution path which migrates StreaMon from middleboxes to Virtual Network Functions (VNFs) has been realized. Pier Luigi Ventre, Alberto Caponi, Giuseppe Siracusano, Davide Palmisano, Stefano Salsano, Marco Bonola, Giuseppe Bianchi 0001 |
LANMAN | 3 |
| 2017 | Implementation of virtual network function chaining through segment routing in a linux-based NFV infrastructureabstractThis paper presents an architecture to support Vir- tual Network Functions (VNFs) chaining using the IPv6 Segment Routing (SR) network programming model. Two classes of VNFs are considered: SR-aware and SR-unaware. The operations to support both SR-aware and SR-unaware VNFs are described at an architectural level and we propose a solution for SR-unaware VNFs hosted in a NFV node. An Open Source implementation of the proposed solution for a Linux based NFV host is available and a set of performance measurements have been carried out in a testbed. Ahmed Abdelsalam, François Clad, Clarence Filsfils, Stefano Salsano, Giuseppe Siracusano, Luca Veltri |
NetSoft | 5 |
| 2017 | Re-Designing Dynamic Content Delivery in the Light of a Virtualized InfrastructureabstractWe explore the opportunities and design options enabled by novel SDN and NFV technologies, by re-designing a dynamic content delivery network (CDN) service. Our system, named MOSTO, provides performance levels comparable to that of a regular CDN, but does not require the deployment of a large distributed infrastructure. In the process of designing the system, we identify relevant functions that could be integrated in the future Internet infrastructure. Such functions greatly simplify the design and effectiveness of services, such as MOSTO. We demonstrate our system using a mixture of simulation, emulation, testbed experiments, and by realizing a proof-of-concept deployment in a planet-wide commercial cloud system. Giuseppe Siracusano, Roberto Bifulco, Martino Trevisan, Tobias Jacobs, Simon Kuenzer, Stefano Salsano, Nicola Blefari-Melazzi, Felipe Huici |
IEEE J. Sel. Areas Commun. | 1 |
| 2016 | PMSR - Poor Man's Segment Routing, a minimalistic approach to Segment Routing and a Traffic Engineering use caseabstractThe current specification of the Segment Routing (SR) architecture requires enhancements to the intradomain routing protocols (e.g. OSPF and IS-IS) so that the nodes can advertise the Segment Identifiers (SIDs). We propose a simpler solution called PMSR (Poor Man's Segment Routing), that does not require any enhancement to routing protocol. We compare the procedures of PMSR with traditional SR, showing that PMSR can reduce the operation and management complexity. We analyze the set of use cases in the current SR drafts and we claim that PMSR can support the large majority of them. Thanks to the drastic simplification of the control plane, we have been able to develop an open source prototype of PMSR. In the second part of the paper, we consider a Traffic Engineering use case, starting from a traditional flow assignment optimization problem, which allocates hop-by-hop paths to flows. We propose a SR path assignment algorithm and prove that it is optimal with respect to the number of segments allocated to a flow. Stefano Salsano, Luca Veltri, Luca Davoli, Pier Luigi Ventre, Giuseppe Siracusano |
NOMS | 5 |
| 2016 | Hybrid IP/SDN Networking: Open Implementation and Experiment Management ToolsabstractThe introduction of SDN in large-scale IP provider networks is still an open issue and different solutions have been suggested so far. In this paper, we propose a hybrid approach that allows the coexistence of traditional IP routing with SDN based forwarding within the same provider domain. The solution is called OSHI-Open Source Hybrid IP/SDN networking, as we have fully implemented it combining and extending open source software. We discuss the OSHI system architecture and the design and implementation of advanced services like pseudo wires and virtual switches. In addition, we describe a set of open source management tools for the emulation of the proposed solution using either the Mininet emulator or distributed physical testbeds. We refer to this suite of tools as Mantoo (management tools). Mantoo includes an extensible Web-based graphical topology designer, which provides different layered network “views” (e.g., from physical links to service relationships among nodes). The suite can validate an input topology, automatically deploy it over a Mininet emulator or a distributed SDN testbed and allows access to emulated nodes by opening consoles in the web GUI. Mantoo provides also tools to evaluate the performance of the deployed nodes. Stefano Salsano, Pier Luigi Ventre, Francesco Lombardo, Giuseppe Siracusano, Matteo Gerola, Elio Salvadori, Michele Santuari, Mauro Campanella, Luca Prete |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2015 | ICONA: Inter Cluster Onos Network applicationabstractSeveral Network Operating Systems have been proposed in the last few years for Software Defined Networks; however, only few of them are offering resiliency, scalability and high availability required for production environments. In our demonstration we present a geographically distributed SDN Control Plane, called ICONA, build on top of the Open Networking Operating System (ONOS) and designed to meet the aforementioned Service Providers requirements. During the demo, that runs inside the GEANT OpenFlow pan-european testbed, we show how a Service Provider engineer can easily manage and monitor the network, deploy some services and how ICONA can automatically recover from Control and Data planes failures. Matteo Gerola, Michele Santuari, Elio Salvadori, Stefano Salsano, Pier Luigi Ventre, Mauro Campanella, Francesco Lombardo, Giuseppe Siracusano |
NetSoft | 8 |