EDBT 2026 Demo / reviewers in the wild / expert
Marco Savi
dblp:146/8141
· DBLP profile ↗
32ranked-venue papers
3as first author
19since 2021 · last 2025
0000-0002-8193-0597ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17 · 1 first-author · 11 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Software engineering, systems software and programming languages · 3 · 1 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Security and privacy · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A Federated Approach to Enhance Calibration of Distributed ML-Based Intrusion Detection SystemsabstractNetwork intrusion detection systems (IDSs) are a major component for network security, aimed at protecting network-accessible endpoints, such as IoT devices, from malicious activities that compromise confidentiality, integrity, or availability within the network infrastructure. Machine Learning models are becoming a popular choice for developing an IDS, as they can handle large volumes of network traffic and identify increasingly sophisticated patterns. However, traditional ML methods often require a centralized large dataset thus raising privacy and scalability concerns. Federated Learning (FL) offers a promising solution by enabling a collaborative training of an IDS, without sharing raw data among clients. However, existing research on FL-based IDSs primarily focuses on improving accuracy and detection rates, while little or no attention is given to a proper estimation of the model’s uncertainty in making predictions. This is however fundamental to increase the model’s reliability, especially in safety-critical applications, and can be addressed by an appropriate model’s calibration. This paper introduces a federated calibration approach that ensures the efficient distributed training of a calibrator while safeguarding privacy, as no calibration data has to be shared by clients with external entities. Our experimental results confirm that the proposed approach not only preserves model’s performance, but also significantly enhances confidence estimation, making it ideal to be adopted by IDSs. Jacopo Talpini, Nicoló Civiero, Fabio Sartori, Marco Savi |
ICAART (2) | 4 |
| 2025 | In-Kernel Traffic Sketching for Volumetric DDoS Detection
Mingyuan Zang, Federico De Iaco, Jie Wu 0001, Marco Savi |
ICC | 4 |
| 2025 | FedBEns: One-Shot Federated Learning based on Bayesian EnsembleabstractOne-Shot Federated Learning (FL) is a recent paradigm that enables multiple clients to cooperatively learn a global model in a single round of communication with a central server. In this paper, we analyze the One-Shot FL problem through the lens of Bayesian inference and propose FedBEns, an algorithm that leverages the inherent multimodality of local loss functions to find better global models.Our algorithm leverages a mixture of Laplace approximations for the clients' local posteriors, which the server then aggregates to infer the global model. We conduct extensive experiments on various datasets, demonstrating that the proposed method outperforms competing baselines that typically rely on unimodal approximations of the local losses. Jacopo Talpini, Marco Savi, Giovanni Neglia |
ICML | 2 |
| 2025 | Decentralized Edge Workload Forecasting With Gossip LearningabstractEdge computing has emerged as a crucial paradigm for addressing the growing demands of interconnected devices and large-scale mobile applications by relocating computation and storage services closer to end-users. Edge workloads are inherently volatile and challenging to forecast due to their dependence on factors such as human mobility patterns and geographically-distributed infrastructure, combined with the dynamic nature of edge nodes. Traditional centralized approaches to workload forecasting are inadequate in the context of decentralized and failure-prone edge environments. To address this challenge, this paper investigates workload forecasting using Gossip Learning (GL), an asynchronous peer-to-peer learning protocol. GL allows for the training of forecasting models in a fully-decentralized manner, thereby mitigating single point of failure risks and enhancing overall system robustness. We extended the original protocol across multiple dimensions to improve convergence, reduce communication overhead, and enhance resilience to failures. We evaluated the proposed approach through extensive simulations; the obtained results demonstrate its effectiveness with respect to classical methods, rendering it a promising solution to enhance load balancing and task offloading strategies at the edge, thereby ensuring Quality-of-Service (QoS) and reducing Service Level Agreement (SLA) violations. Alessandro Tundo, Federica Filippini, Francesco Regonesi, Michele Ciavotta, Marco Savi |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2024 | Hierarchical Multiclass Continual Learning for Network Intrusion DetectionabstractThe evolution of Internet and its related communication technologies have consistently increased the risk of cyber-attacks. In this context, a crucial role is played by Intrusion Detection Systems (IDSs), which are security devices designed to identify and mitigate attacks to modern networks. In the last decade, data-driven approaches based on Machine Learning (ML) have gained more and more popularity for executing the classification tasks required by signature-based IDSs. However, typical ML models adopted for this purpose are trained in static settings while new attacks – and variants of known attacks – dynamically emerge over time. As a consequence, there is the need of keeping the IDS capability constantly updated, which poses peculiar challenges especially in resourced-constrained scenarios. To this end, we propose a novel hierarchical model based on a binary classification of benign and malicious traffic performed by a Bayesian Neural Network that is trained continuously and efficiently by exploiting Continual Learning. A generative multiclass classifier is then adopted to incrementally classify new kinds of attacks with respect to the malicious traffic. We prove the effectiveness of our approach showing that it removes the need of storing network traffic data samples related to historical data, representative of all the kinds of attacks, while ensuring good detection capabilities. Jacopo Talpini, Fabio Sartori, Marco Savi |
NetSoft | 3 |
| 2024 | Towards a Knowledge Diversity Notion to Identify Intrusions in Industrial ContextsabstractKnowledge diversity is becoming an important research topic in many fields, and assessing it can be useful for many purposes in many domains. In this paper, we present a first attempt to model knowledge diversity in intrusion detection field. IT attacks can be modelled through different techniques; in this way they can be evaluated for their risk and then it is also possible to implement some mitigation tools. The approach followed in our work aims at combining the formalism of Petri nets and Machine Learning techniques in order to detect intrusions and suspicious behaviours. Thanks to Petri nets, it is possible to highlight the critical points where a further analysis is needed. Basically, a normal behavior can be represented by a Petri Net capable to run correctly from the starting place to the ending one; an anomalous one by a Petri Net where some critical transition are activated that are not considered in the normal one, or, if considered, that can be further investigated thanks to the adoption of complimentary methods, like Machine Learning. In this paper tree-based classifiers have been applied to classify the instances of the data set and distinguish them between normal behaviour and attacks. A case study from Mississippi State University has been adopted to validate our research. Fabio Sartori, Marco Savi, Gaia Tarrini, Jacopo Talpini |
WETICE | 2 |
| 2024 | Introducing packet-level analysis in programmable data planes to advance Network Intrusion Detection
Roberto Doriguzzi Corin, Luis Augusto Dias Knob, Luca Mendozzi, Domenico Siracusa, Marco Savi |
Comput. Networks | 5 |
| 2024 | Unleashing Dynamic Pipeline Reconfiguration of P4 Switches for Efficient Network MonitoringabstractAs it is happening in many fields that need efficient and effective classification of data, Machine Learning (ML) is becoming increasingly popular in network management and monitoring. In general we can say that ML algorithms are complex, therefore better suited for execution in the centralized control plane of modern networks, but are also heavily reliant on data, that are necessarily collected in the data plane. The inevitable consequence is that may arise the need to transfer lots of data from the data plane to the control plane, with the risk to cause congestion on the control communication channel. This may turn into a major drawback, since congestion on the control channel may have a significant impact on network operations. Therefore it is of paramount importance to design systems capable of minimizing the interaction between data and control planes while ensuring good monitoring performance. The most recent generation of data plane programmable switches supporting the P4 language can help mitigate this problem by preprocessing traffic data at line rate. In this manuscript we follow this approach and propose P4RTHENON: an architecture to distill in the data plane the relevant information to be mirrored to the control plane, where complex analysis can be performed. P4RTHENON leverages the P4-native support for runtime data plane pipeline reconfiguration to minimize the interaction between data and control planes while ensuring good monitoring performance. We tested our scheme on the volumetric DDoS detection use case: P4RTHENON reduces the volume of exchanged data by almost 75% compared to a pure control-plane-based solution, guarantees low memory consumption in the data plane, and does not degrade the overall DDoS detection capabilities. Amir Al Sadi, Marco Savi, Andrea Melis 0001, Marco Prandini, Franco Callegati |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2023 | A Clustering Strategy for Enhanced FL-Based Intrusion Detection in IoT NetworksabstractThe Internet of Things (IoT) is growing rapidly and so the need of ensuring protection against cybersecurity attacks to IoT devices. In this scenario, Intrusion Detection Systems (IDSs) play a crucial role and data-driven IDSs based on machine learning (ML) have recently attracted more and more interest by the research community. While conventional ML-based IDSs are based on a centralized architecture where IoT devices share their data with a central server for model training, we propose a novel approach that is based on federated learning (FL). However, conventional FL is ineffective in the considered scenario, due to the high statistical heterogeneity of data collected by IoT devices. To overcome this limitation, we propose a three-tier FL-based architecture where IoT devices are clustered together based on their statistical properties. Clustering decisions are taken by means of a novel entropy-based strategy, which helps improve model training performance. We tested our solution on the CIC-ToN-IoT dataset: our clustering strategy increases intrusion detection performance with respect to a conventional FL approach up to +17% in terms of F1-score, along with a significant reduction of the number of training rounds. Jacopo Talpini, Fabio Sartori, Marco Savi |
ICAART (3) | 3 |
| 2023 | Uncertainty-Aware QoT Forecasting in Optical Networks with Bayesian Recurrent Neural NetworksabstractWe consider the problem of forecasting the Quality-of-Transmission (QoT) of deployed lightpaths in a Wavelength Division Multiplexing (WDM) optical network. QoT forecasting plays a determinant role in network management and planning, as it allows network operators to proactively plan maintenance or detect anomalies in a lightpath. To this end, we leverage Bayesian Recurrent Neural Networks for learning uncertainty-aware probabilistic QoT forecasts, i.e., for modelling a probability distribution of the QoT over a time horizon. We evaluate our proposed approach on the open-source Microsoft Wide Area Network (WAN) optical backbone dataset. Our illustrative numerical results show that our approach not only outperforms state-of-the-art models from literature, but also predicts intervals providing near-optimal empirical coverage. As such, we demonstrate that uncertainty-aware probabilistic modelling enables the application of QoT forecasting in risk-sensitive application scenarios. Nicola Di Cicco, Jacopo Talpini, Memedhe Ibrahimi, Marco Savi, Massimo Tornatore |
ICC | 4 |
| 2023 | Performance characterization and profiling of chained CPU-bound Virtual Network FunctionsabstractThe increased demand for high-quality Internet connectivity resulting from the growing number of connected devices and advanced services has put significant strain on telecommunication networks. In response, cutting-edge technologies such as Network Function Virtualization (NFV) and Software Defined Networking (SDN) have been introduced to transform network infrastructure. These innovative solutions offer dynamic, efficient, and easily manageable networks that surpass traditional approaches. To fully realize the benefits of NFV and maintain the performance level of specialized equipment, it is critical to assess the behavior of Virtual Network Functions (VNFs) and the impact of virtualization overhead. This paper delves into understanding how various factors such as resource allocation, consumption, and traffic load impact the performance of VNFs. We aim to provide a detailed analysis of these factors and develop analytical functions to accurately describe their impact. By testing VNFs on different testbeds, we identify the key parameters and trends, and develop models to generalize VNF behavior. Our results highlight the negative impact of resource saturation on performance and identify the CPU as the main bottleneck. We also propose a VNF profiling procedure as a solution to model the observed trends and test more complex VNFs deployment scenarios to evaluate the impact of interconnection, co-location, and NFV infrastructure on performance. Sebastian Troia, Marco Savi, Giulia Nava, Ligia M. M. Zorello, Guido Maier |
Comput. Networks | 2 |
| 2023 | Locality-aware deployment of application microservices for multi-domain fog computing
Francescomaria Faticanti, Marco Savi, Francesco De Pellegrini, Domenico Siracusa |
Comput. Commun. | 2 |
| 2022 | Design and Development of Network Monitoring Strategies in P4-enabled Programmable SwitchesabstractNetwork monitoring is of paramount importance for effective network management: it allows to constantly observe a network’s behavior to ensure it is working as intended, and can trigger both automated and manual remediation procedures in case of failures and anomalies. Software-Defined Networking (SDN) decouples the control plane of network infrastructure from its data plane to perform centralized control on the multiple switches in a network. In this context, the responsibility of switches is only to forward packets according to the instructions provided by a controller. The lack of programmability in the data plane of SDNs prompted the advent of data-plane programmable switches, which allow developers to customize the data-plane pipeline (e.g. match-action tables) by using a domain specific language named P4, and implement novel programs and protocols operating at wire speed directly in the switches. This unlocks the possibility to offload some monitoring tasks to the programmable data plane, and to perform fine-grained monitoring at very high packet processing speeds. Given the central importance of this topic, the principal goal of this thesis is to enable a wide range of monitoring tasks in data-plane programmable switches, with a focus on the ones equipped with programmable Application-Specific Integrated Circuits (ASICs). To achieve this goal, this thesis makes three main contributions: (i.) We enhance P4-supported data plane programmability for network monitoring; (ii.) We design and develop several network monitoring tasks in programmable data planes; (iii.) We combine multiple tasks in a single commodity switch to collect various metrics for different monitoring purposes. Our evaluations show that our solutions can be exploited by network administrators, operators and security engineers to better track and understand the current network status, and thus prevent infrastructure and service failures. Damu Ding, Marco Savi, Federico Pederzolli, Domenico Siracusa |
NOMS | 2 |
| 2022 | Tracking Normalized Network Traffic Entropy to Detect DDoS Attacks in P4abstractDistributed Denial-of-Service (DDoS) attacks represent a persistent threat to modern telecommunications networks: detecting and counteracting them is still a crucial unresolved challenge for network operators. DDoS attack detection is usually carried out in one or more central nodes that collect significant amounts of monitoring data from networking devices, potentially creating issues related to network overload or delay in detection. The dawn of programmable data planes in Software-Defined Networks can help mitigate this issue, opening the door to the detection of DDoS attacks directly in the data plane of the switches. However, the most widely-adopted data plane programming language, namely P4, lacks supporting many arithmetic operations, therefore, some of the advanced network monitoring functionalities needed for DDoS detection cannot be straightforwardly implemented in P4. This work overcomes such a limitation and presents two novel strategies for flow cardinality and for normalized network traffic entropy estimation that only use P4-supported operations and guarantee a low relative error. Additionally, based on these contributions, we propose a DDoS detection strategy relying on variations of the normalized network traffic entropy. Results show that it has comparable or higher detection accuracy than state-of-the-art solutions, yet being simpler and entirely executed in the data plane. Damu Ding, Marco Savi, Domenico Siracusa |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Resilience of Delay-Sensitive Services With Transport-Layer Monitoring in SD-WANabstractToday, more and more enterprises are embarking on a digital transformation where most of their applications are hosted in the Cloud. As a result, a reliable Wide Area Network (WAN) has become a primary need to interconnect their distributed branch offices and data centers that accommodate those applications. Software-Defined Wide Area Network (SD-WAN) represents the most promising technology solution for next-generation enterprise networks, being able to increase network agility and reduce costs. In this paper, we present an experimental SD-WAN solution capable of running and optimizing delay-sensitive high-priority services, such as real-time video streaming, while minimizing downtime caused by network failures. This solution comprises a monitoring and a traffic engineering system for SD-WAN. The first consists of a Transport-layer Passive Monitoring (TPM) system based on extended Berkeley Packet Filter (eBPF) technology with the goal of monitoring TCP flows; the second consists of an application, running inside the SD-WAN controller, with the goal of orchestrating the network traffic in consideration of the monitoring measurements by ensuring rapid recovery and resilience in case of unexpected congestion events. We validate our solution over two SD-WAN testbeds: the first is hosted in our laboratory at Politecnico di Milano, while the second is deployed in a municipal network of an Italian city. Results show that our SD-WAN solution can increase the overall service availability while meeting the stringent QoS requirements of delay-sensitive services.s Sebastian Troia, Marco Mazzara, Marco Savi, Ligia M. M. Zorello, Guido Maier |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2021 | INVEST: Flow-based Traffic Volume Estimation in Data-plane Programmable NetworksabstractThe emergence of programmable data planes in Software-Defined Networks enables the execution of various monitoring tasks directly in network devices, overcoming the need to deliver huge amounts of information to a controller that must then process it at scale. In this paper, we aim to solve a fundamental problem arising when exploiting programmable data planes for network-wide monitoring: how to estimate the overall number of packets in the network (i.e., the traffic volume), and the related number and size of flows, while avoiding packet double counting. Most existing works solve this problem by ensuring that each packet is counted only once on its path, which limits routing or requires coordination among devices. We propose a different approach, INVEST, a flow-based traffic volume estimator for P4-based switches, that relies on and can reuse commonly employed data structures while naturally solving the double-counting problem. We theoretically analyze and experimentally evaluate our solution, which we implemented in a real P4 carrier-grade switch, finding that it is accurate, memory-efficient, and can process packets at line rate. Damu Ding, Marco Savi, Federico Pederzolli, Domenico Siracusa |
Networking | 2 |
| 2021 | Challenges and Solutions for hybrid SDN
Elisa Rojas, Rashid Amin, Carmen Guerrero, Marco Savi, Adib Rastegarnia |
Comput. Networks | 4 |
| 2021 | Impact of Processing-Resource Sharing on the Placement of Chained Virtual Network FunctionsabstractNetwork Function Virtualization (NFV) provides higher flexibility for network operators and reduces the complexity in network service deployment. Using NFV, Virtual Network Functions (VNF) can be located in various network nodes and chained together in a Service Function Chain (SFC) to provide a specific service. Consolidating multiple VNFs in a smaller number of locations would allow decreasing capital expenditures. However, excessive consolidation of VNFs might cause additional latency penalties due to processing-resource sharing, and this is undesirable, as SFCs are bounded by service-specific latency requirements. In this paper, we identify two different types of penalties (referred as “costs”) related to the processing-resource sharing among multiple VNFs: thecontext switching costsand theupscaling costs. Context switching costs arise when multiple CPU processes (e.g., supporting different VNFs) share the same CPU and thus repeated loading/saving of their context is required. Upscaling costs are incurred by VNFs requiring multi-core implementations, since they suffer a penalty due to the load-balancing needs among CPU cores. These costs affect how the chained VNFs are placed in the network to meet the performance requirement of the SFCs. We evaluate their impact while considering SFCs with different bandwidth and latency requirements in a scenario of VNF consolidation. Marco Savi, Massimo Tornatore, Giacomo Verticale |
IEEE Trans. Cloud Comput. | 1 |
| 2021 | In-Network Volumetric DDoS Victim Identification Using Programmable Commodity SwitchesabstractVolumetric distributed Denial-of-Service (DDoS) attacks have become one of the most significant threats to modern telecommunication networks. However, most existing defense systems require that detection software operates from a centralized monitoring collector, leading to increased traffic load and delayed response. The recent advent of Data Plane Programmability (DPP) enables an alternative solution: threshold-based volumetric DDoS detection can be performed directly in programmable switches to skim only potentially hazardous traffic, to be analyzed in depth at the controller. In this paper, we first introduce the BACON data structure based on sketches, to estimate per-destination flow cardinality, and theoretically analyze it. Then we employ it in a simple in-network DDoS victim identification strategy, INDDoS, to detect the destination IPs for which the number of incoming connections exceeds a pre-defined threshold. We describe its hardware implementation on a Tofino-based programmable switch using the domain-specific P4 language, proving that some limitations imposed by real hardware to safeguard processing speed can be overcome to implement relatively complex packet manipulations. Finally, we present some experimental performance measurements, showing that our programmable switch is able to keep processing packets at line-rate while performing volumetric DDoS detection, and also achieves a high F1 score on DDoS victim identification. Damu Ding, Marco Savi, Federico Pederzolli, Mauro Campanella, Domenico Siracusa |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2020 | Estimating Logarithmic and Exponential Functions to Track Network Traffic Entropy in P4abstractThe evaluation of network traffic entropy is very useful for management purposes, since it helps to keep track of changes in network flow distribution. Nowadays, network traffic entropy is usually estimated in centralized monitoring collectors, which require a significant amount of information to be retrieved from switches. The advent of programmable data planes in Software-Defined Networks helps mitigate this issue, opening the door to the possibility of estimating entropy directly in the switches’ data plane. Unfortunately, the most widely-adopted programming language used to program the data plane, called P4, lacks supporting many arithmetic operations such as logarithm and exponential function computation, which are necessary for entropy estimation. In this paper we propose two new algorithms, called P4Log and P4Exp, to fill this gap: these algorithms can estimate logarithms and exponential functions with a given precision by only using P4-supported arithmetic operations. Additionally, we leverage them to propose a novel strategy, called P4Entropy, to estimate traffic entropy entirely in the switch data plane. Results show that P4Entropy has comparable accuracy as an existing solution but without (i) constraining the number of packets in an observation interval and (ii) requiring the usage of TCAM, which is a scarce resource. Damu Ding, Marco Savi, Domenico Siracusa |
NOMS | 2 |
| 2020 | Rethinking the Design of Wearable Expert Systems: The Role of Network InfrastructuresabstractThe recent COVID-19 emergency has pointed out the importance of effective and efficient tools to support users in their day-by-day activities, ranging from health-related ones to studying, remote working and recreation. Indeed, wearables and modern network technologies, such as network slicing and SDWAN, play a key role in this scenario, but existing applications should be rethought to be really useful in critical situations like the current pandemic. In this paper, we reflect about this topic, trying to design an innovative architectural framework where Wearable Expert Systems, IoT and network infrastructures are integrated to obtain the best level of performance. Marco Savi, Fabio Sartori, Riccardo Melen |
WiMob | 1 |
| 2020 | Smart Contracts for Service-Level Agreements in Edge-to-Cloud Computing
Petar Kochovski, Vlado Stankovski, Sandi Gec, Francescomaria Faticanti, Marco Savi, Domenico Siracusa |
J. Grid Comput. | 5 |
| 2020 | Dynamic and Application-Aware Provisioning of Chained Virtual Security Network FunctionsabstractA promising area of application for Network Function Virtualization (NFV) is in network security, where chains of Virtual Security Network Functions (VSNFs), i.e., security-specific virtual functions such as firewalls or Intrusion Prevention Systems, can be dynamically created and configured to inspect, filter or monitor the network traffic. However, the traffic handled by VSNFs could be sensitive to specific network requirements, such as minimum bandwidth or maximum end-to-end latency. Therefore, the decision on which VSNFs should apply for a given application, where to place them and how to connect them, should take such requirements into consideration. Otherwise, security services could affect the quality of service experienced by customers. In this paper, we propose PESS (Progressive Embedding of Security Services), a solution to efficiently deploy chains of virtualised security functions based on the security requirements of individual applications and operators' policies, while optimizing resource utilization. We provide the PESS mathematical model and heuristic solution. Simulation results show that, compared to state-of-the-art application-agnostic VSNF provisioning models, PESS reduces computational resource utilization by up to 50%, in different network scenarios. This result ultimately leads to a higher number of provisioned security services and to up to a 40% reduction in end-to-end latency of application traffic. Roberto Doriguzzi Corin, Sandra Scott-Hayward, Domenico Siracusa, Marco Savi, Elio Salvadori |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2020 | An Incrementally-Deployable P4-Enabled Architecture for Network-Wide Heavy-Hitter DetectionabstractThe advent of Software-Defined Networking with OpenFlow first, and subsequently the emergence of programmable data planes, has boosted lots of research around many networking aspects: monitoring, security, traffic engineering. In the context of monitoring, most of the proposed solutions show the benefits of data plane programmability by simplifying the network complexity with a one big-switch abstraction. Only few papers look at network-wide solutions, but consider the network only composed by programmable devices. In this paper, we argue that the primary challenge for a successful adoption of those solutions is the deployment problem: how to compose and monitor a network consisting of both legacy and programmable switches? We propose an approach for incrementally deploy programmable devices in an ISP network with the goal of monitoring as many distinct network flows as possible. While assessing the benefits of our solution, we realized that proposed network-wide monitoring algorithms might not be optimized for a partial deployment scenario. We then also developed and implemented in P4 a novel strategy capable of detecting network-wide heavy flows: results show that it can achieve better accuracy than state-of-the-art solutions while relying on less information from the data plane and leading to only marginal additional packet processing time. Damu Ding, Marco Savi, Gianni Antichi, Domenico Siracusa |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2019 | Incremental Deployment of Programmable Switches for Network-wide Heavy-hitter DetectionabstractThe advent of Software-Defined Networking with OpenFlow first, and subsequently the emergence of programmable data planes, has boosted lot of research around many networking aspects: monitoring, security, traffic engineering. In the context of network monitoring, most of the proposed solutions show the benefits of data plane programmability by simplifying the complexity of the network with a one big-switch abstraction. Only few papers look at network-wide solutions, but consider the network as non heterogeneous: only composed by programmable devices. In this paper, we argue that the primary challenge for a successful adoption of those solutions is the deployment problem: how to compose and monitor a network consisting of both legacy and programmable switches? We propose an approach for incrementally deploy programmable devices in an ISP network with the goal of monitoring as many distinct network flows as possible. While assessing the benefits of our solution, we realized that proposed network-wide monitoring algorithms might not be optimized for a partial deployment scenario. We then also developed a novel strategy capable of detecting network-wide heavy flows with the same accuracy of state-of-the-art solutions but by relying on less information from the data plane. Damu Ding, Marco Savi, Gianni Antichi, Domenico Siracusa |
NetSoft | 2 |
| 2017 | An interactive intent-based negotiation scheme for application-centric networksabstractThe demonstration presents the first implementation of a resource negotiation scheme between users and a network for the provisioning of application-aware connectivity services. This active interaction enables the users, who request connectivity services with multiple application requirements, to select an alternative solution when the network does not have enough resources to satisfy the original requests. Antonio Marsico, Michele Santuari, Marco Savi, Domenico Siracusa, Stéphane Junique, Pontus Sköldström |
NetSoft | 3 |
| 2017 | Protection strategies for virtual network functions placement and service chains provisioningabstractTelecom operators worldwide are witnessing squeezed profit margins mainly due to hyper‐competition. Hence, new business models/strategies are needed to help operators reduce Operational and Capital Expenditures. In this context, the Network Function Virtualization (NFV) paradigm, which consists of running Virtual Instances of Network Functions (NFs) in Commercial‐Off‐The‐Shelf (COTS) hardware, represents a solid alternative. Virtual Network Functions (VNFs) are then concatenated together in a sequential order to form service chains (SCs) that provide specific Internet services. In this article, we study different approaches to provision SCs with resiliency against single‐link and single‐node failures. We propose three Integer Linear Programming (ILP) models to jointly solve the problem of VNF placement and traffic routing, while guaranteeing resiliency against single‐link and/or single‐node failures. Specifically, we focus on the trade‐off between the conflicting objectives of meeting SCs latency requirements and consolidating as many as possible VNFs in NFV‐capable nodes. We show that providing resiliency against both single‐link and single‐node failures comes at twice the amount of resources in terms of NFV‐capable nodes, and that for latency‐critical services providing resiliency against single‐node failures comes at the same cost with respect to resiliency against single‐link and single‐node failures. Finally, we discuss important insights about the deployment of bandwidth‐intensive SCs. © 2017 Wiley Periodicals, Inc. NETWORKS, Vol. 70(4), 373–387 2017 Ali Hmaity, Marco Savi, Francesco Musumeci 0001, Massimo Tornatore, Achille Pattavina |
Networks | 2 |
| 2015 | ICN based shared caching in future converged fixed and mobile networkabstractThe explosion of mobile multimedia and Internet-of-things (IoT) services implies strong requirements for seamless switching among various types of networks. Thus, to offer true ubiquitous Internet connection, a Fixed and Mobile Converged (FMC) network architecture is essential for the future 5G network. Such a convergent network can not only improve the utilization of network resources, but also inspire new add-on services for FMC network operators. In this paper, we introduce a shared caching overlay based on Information Centric Networking (ICN). It is deployed on top of the FMC network and controlled by the FMC network operator to offer Caching as a Service (CaaS) to Over-The-Top (OTT) service providers and virtual network operators. Business analysis and performance evaluation will highlight the benefits of deploying such a controlled Shared Caching System (SCS) over an FMC network. Jean-Charles Point, Selami Çiftçi, Onur Eker, Giulia Mauri, Marco Savi, Giacomo Verticale |
HPSR | 6 |
| 2015 | Performance evaluation of video server replication in metro/access networks
Marco Savi, Roberto Fratini, Giacomo Verticale, Massimo Tornatore |
Comput. Networks | 1 |
| 2015 | Mitigation of peer-to-peer overlay attacks in the automatic metering infrastructure of smart gridsabstractAbstract Measurements gathered by smart metres and collected through the automatic metering infrastructure of smart grids can be accessed by numerous external subjects for different purposes, ranging from billing to grid monitoring. Therefore, to prevent the disclosure of personal information through the analysis of energy consumption patterns, the metering data must be securely handled. Peer‐to‐peer networking is a promising approach for interconnecting communication nodes among the automatic metering infrastructure to efficiently perform data collection while ensuring privacy and confidentiality, but it is also prone to various security attacks. This paper discusses the impact of the most relevant peer‐to‐peer attack scenarios on the performance of a protocol for privacy preserving aggregation of metering data. The protocol relies on communication gateways located in the customers’ households and interconnected by means of a variant of the Chord overlay. We also propose some countermeasures to mitigate the effects of such attacks: we integrate a verifiable secret sharing scheme based on Pedersen commitments in the aggregation protocol, which ensures data integrity, with compliance checks aimed at identifying the injection of altered measurements. Moreover, we introduce Chord auxiliary routing tables to counteract the routing pollution performed by dishonest nodes. The paper evaluates the computational complexity and effectiveness of the proposed solutions through analytical and numerical results. Copyright © 2014 John Wiley & Sons, Ltd. Cristina Rottondi, Marco Savi, Giacomo Verticale, Christoph Krauß |
Secur. Commun. Networks | 2 |
| 2014 | Using replicated video servers for VoD traffic offloading in integrated metro/access networksabstractInternet traffic is increasingly becoming a mediastreaming traffic. Especially, Video-on-Demand (VoD) services are pushing the demand for broadband connectivity to the Internet, and optical fiber technology is being deployed in the access network to keep up with such increasing demand. To provide a more scalable network architecture for video/content delivery, network operators are currently considering novel integrated metro/access networks which accommodate replicated video servers directly in their infrastructure. In such way, servers for VoD delivery are placed nearer to the end users, the core segment of the network is partially traffic offloaded, and the end users experience better performance in terms of QoS. In our work, we will evaluate the performance improvement of an integrated metro/access architecture for VoD delivery with replicated video servers considering different configurations in terms of number of replicated servers, meshing degree and adopted network technologies. We develop a network simulator in which replicas of video servers (called Metro Servers, or MSs) are deployed to meet the demand of VoD traffic. In the result section we compare the performance of the various configurations and discuss which are the minimum requirements to minimize blocking of the VoD requests. Roberto Fratini, Marco Savi, Giacomo Verticale, Massimo Tornatore |
ICC | 2 |
| 2013 | A decisional attack to privacy-friendly data aggregation in Smart GridsabstractThe privacy-preserving management of energy consumption measurements gathered by Smart Meters plays a pivotal role in the Automatic Metering Infrastructure of Smart Grids. Grid users and standardization committees are requiring that utilities and third parties collecting aggregated metering data are prevented from accessing measurements at the household granularity, and data perturbation is a technique used to provide a trade-off between the privacy of individual users and the precision of the aggregated measurements. In this paper, we discuss a decisional attack to aggregation with data-perturbation, showing that a curious entity can exploit the temporal correlation of Smart Grid measurements to detect the presence or absence of individual data generated by a given user inside an aggregate. We also propose a countermeasure to such attack and show its effectiveness using both synthetic and real home energy consumption measurement traces. Cristina Rottondi, Marco Savi, Daniele Polenghi, Giacomo Verticale, Christoph Krauß |
GLOBECOM | 2 |