EDBT 2026 Demo / reviewers in the wild / expert
Muriel Figueredo Franco
dblp:180/3022
· DBLP profile ↗
36ranked-venue papers
9as first author
20since 2021 · last 2026
0000-0002-0208-0521ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 20 · 3 first-author · 12 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Knowing millions of students too well: High-entropy scores as deterministic quasi-identifiers for re-identification and data leakage in the Brazilian high school examabstractPublic microdata sit at the intersection of transparency mandates, data-protection law, and the technical realities of cybersecurity, while regulatory and judicial decisions often rely on threat models that underestimate modern re-identification capabilities. We study this tension in Brazil’s National High School Exam (ENEM), where a court first mandated utility-preserving anonymization, then recognized substantial compliance through a separated architecture that forgoes core analytical utility. We show that precise candidate-level performance scores are high-entropy quasi-identifiers that adversaries can use to link identities across complementary public releases. Across 57.7 million records from fifteen editions (2009–2023), edition-level singleton rates average 99.9985%. On commodity hardware, an exact join of files downloadable from official portals uniquely matches 26.59 million of 26.61 million candidate-year records in the federal admission system (99.91%). Cross-year canonicalization estimates 14.69 million distinct individuals with linked records. These links associate civil identities with socioeconomic data such as family income and household assets, and a smaller channel conditionally exposes accessibility-related proxies for disability. Moreover, no tested score generalization removed record individualization without degrading ranking and group-gap estimates. Multidimensional performance measures should be treated as quasi-identifiers, not just analytical attributes. Henrique Lindemann, Eder J. Scheid, Lisandro Z. Granville, Muriel Figueredo Franco |
Comput. Secur. | 4 |
| 2025 | Employing PDDL Plan to Recommend Security Controls Against Cyberattacks
Afaq Inayat, Matheus Saueressig, Muriel Figueredo Franco, Eder J. Scheid, Lisandro Z. Granville |
AINA (4) | 3 |
| 2025 | Assessing SSL/TLS Certificate Centralization: Implications for Digital SovereigntyabstractSSL/TLS is a fundamental technology in the network protocol stack that enables encrypted data transmission and authentication of web domains. However, the current model relies on a small number of Certificate Authorities (CAs) to provide and validate certificates, thus creating a highly centralized ecosystem. In this paper, we analyze the degree of centralization of certificate provisioning from CAs in two major political groups: Brazil, Russia, India, China, and South Africa (BRICS) and the European Union (EU). We have found that over 75% of certificates for both BRICS and EU domains originate from CAs based in the United States, indicating possible risks to their digital sovereignty due to the high level of external dependency. This indicates the need for nations within those groups to research alternatives to reduce the high level of dependency on foreign CAs and increase their digital autonomy. Andrei C. Azevedo, Eder J. Scheid, Muriel Figueredo Franco, Lisandro Z. Granville |
GLOBECOM | 3 |
| 2025 | Dhana: An Economic-Oriented Approach for Traffic Management using Software-Defined NetworkingabstractSoftware-Defined Networking (SDN) offers a flexible, programmable approach to network management by decoupling the control and data planes. While SDN technical advantages, such as improved network performance and security, are well-documented, its economic implications remain underexplored, particularly in prioritizing services based on business value. This paper introduces Dhana, a novel SDNbased traffic management approach that integrates economic considerations. Dhana dynamically prioritizes high-value services by analyzing network components using metrics like downtime costs and service-level agreement (SLA) compliance. The goal is to minimize economic loss during network congestion or failures, even if technical global optimization is partially sacrificed. Tests show that Dhana can take many paths according to its needs and has not significant overhead. Matheus Saueressig, Muriel Figueredo Franco, Eder J. Scheid, João Davi M. Nunes, Jéferson Campos Nobre, Lisandro Z. Granville |
ISCC | 2 |
| 2024 | FEVER: Intelligent Behavioral Fingerprinting for Anomaly Detection in P4-Based Programmable Networks
Matheus Saueressig, Muriel Figueredo Franco, Eder J. Scheid, Alberto Huertas Celdrán, Gérôme Bovet, Burkhard Stiller, Lisandro Z. Granville |
AINA (3) | 2 |
| 2024 | PerfResolv: A Geo-Distributed Approach for Performance Analysis of Public DNS Resolvers Based on Domain Popularity
Marcelo Almeida Silva, Muriel Figueredo Franco, Eder J. Scheid, Luciano Zembruzki, Lisandro Z. Granville |
AINA (2) | 2 |
| 2024 | Securing Blockchain Wallet Files Using eBPFabstractBlockchain (BC) and Distributed Ledger Technologies (DLT) have been widely used in various applications in different areas, from finance to healthcare. For such applications to participate and interact with BCs and DLTs, they must rely on specific software, called nodes, when providing tools and functions for BC synchronization, and called wallets when providing tools for address generation, transaction creation, and fund management. In this sense, wallets are crucial components to be secured within BC-based applications, as they hold sensitive files (e.g., keystore files storing private keys used to generate addresses and sign transactions), which can be a target for attackers. Thus, we propose Scylla, a solution to protect wallet-related files using the extended Berkeley Filter (eBPF) that continuously monitors, at the kernel level, the system calls of processes and actively terminates unauthorized and malicious processes when accessing such files. To demonstrate the feasibility and performance of Scylla, a prototype was implemented and evaluated in terms of access time overhead and resource use. Such experiments show that Scylla is feasible and does not add significant overhead, compared to a native Linux tool dedicated to monitoring files (i.e., inotify) while being able to terminate processes before they can read protected files. Jeison C. Caroly, Eder J. Scheid, Muriel Figueredo Franco, Lisandro Z. Granville |
GLOBECOM | 3 |
| 2024 | Eeny, Meeny, Miny, Moe: Analyzing and Comparing the Selection of DNS Lookup ToolsabstractThe performance of Domain Name System (DNS) resolvers is crucial, as most of the communication on the Internet starts with a DNS lookup to resolve a domain of an IP address to reach the desired content. In this sense, academia has been devoted to measuring and analyzing the performance of DNS resolvers using different tools, either tailored for each work or generic. However, such tools might present different results due to their implementation and affect the measurements. Therefore, this paper reviews the literature on DNS performance research to gather the tools and DNS resolvers most used and, based on this, provides an analysis and comparison of the different DNS lookup tools employed in the literature and discusses the impact of tool selection on measurement results. Research showed that tool selection has an impact on results but not on the lookup success rate. Jose C. C. Pinto, Eder J. Scheid, Muriel Figueredo Franco, Lisandro Z. Granville |
ISCC | 3 |
| 2024 | Traffic Centralization and Digital Sovereignty: An Analysis Under the Lens of DNS ServersabstractThe Domain Name System (DNS) service is one of the pillars of the Internet. This service allows users to access websites on the Internet through easy-to-remember domain names rather than complex numeric IP addresses. However, the concentration of DNS service providers on the Internet affects user security, privacy, and network accessibility as the reliance on a small number of large DNS providers can lead to (a) risks of data breaches and disruption of service in the event of failures and (b) concerns about the digital sovereignty of countries regarding DNS hosting. This work approaches the issue of DNS concentration on the Internet by presenting a solution to measure DNS hosting centralization and digital sovereignty in different countries, such as Brazil, India, China, Russia, and South Africa. With the data obtained through these measurements, relevant questions are answered, such as which are the top-10 DNS providers, if there is DNS centralization, and how dependent countries are on such providers to manage domains using their country code Top-Level Domains (ccTLD). Demétrio Francisco Freitas Boeira, Eder J. Scheid, Muriel Figueredo Franco, Luciano Zembruzki, Lisandro Z. Granville |
NOMS | 3 |
| 2024 | RCVaR: An economic approach to estimate cyberattacks costs using data from industry reportsabstractDigitization increases business opportunities and the risk of companies being victims of devastating cyberattacks. Therefore, managing risk exposure and cybersecurity strategies is essential for digitized companies that aim to survive in competitive markets. However, understanding company-specific risks and quantifying their associated costs is not trivial. Current approaches fail to approximate the individualized financial impact of cyber incidents with a monetary estimation. Additionally, due to limited resources and technical expertise, SMEs, but also large companies, struggle to quantify their cyberattack exposure. Therefore, novel approaches must be built to contribute to a better understanding of the financial loss associated with cyberattacks. This article introduces the Real Cyber Value at Risk (RCVaR), an economical approach for estimating cybersecurity costs using real-world information from public cybersecurity reports. RCVaR identifies the most significant cyber risk factors from various sources and combines their quantitative results to estimate specific cyberattack costs for companies. Furthermore, RCVaR extends current methods to achieve cost and risk estimations based on historical real-world data instead of only probability-based simulations. The evaluation of the approach on unseen data shows the high accuracy and efficiency of the RCVaR in predicting and managing cyber risks. Thus, we argue that the RCVaR is a valuable addition to cybersecurity planning and risk management processes. Muriel Figueredo Franco, Fabian Künzler, Jan von der Assen, Chao Feng 0001, Burkhard Stiller |
Comput. Secur. | 1 |
| 2023 | CyberTEA: a Technical and Economic Approach for Cybersecurity Planning and InvestmentabstractIt is essential to look at cybersecurity not only as a technical problem but also from economic, societal, and legal perspectives. Companies need to pay more attention to planning and investments in cybersecurity due to different factors, such as budget constraints and complexities involved in the planning and decision-making processes. Also, companies wrongly do not see themselves as the target of a potential cyberattack. Therefore, there is still a need for approaches that support companies, especially Small and Medium-sized Enterprises (SME), during the cybersecurity planning and investment decisions. This PhD thesis addressed cybersecurity planning and investment gaps by proposing the CyberTEA approach. This approach is composed of a five-phase methodology, a framework, and a set of solutions for cybersecurity planning and investment, considering the technical requirements of cybersecurity and its economic dimensions, such as the potential economic impacts of cyberattacks and the cost-benefit of protections available on the market to protect against specific threats. The evaluations and scientific advances of CyberTEA approach was proven valid to support SMEs while also showing the benefits and opportunities for cybersecurity economic approaches. Muriel Figueredo Franco, Lisandro Z. Granville, Burkhard Stiller |
NOMS | 1 |
| 2022 | RITUAL: a Platform Quantifying the Trustworthiness of Supervised Machine LearningabstractThis demo presents RITUAL, a platform composed of a novel algorithm and a Web application quantifying the trustworthiness level of supervised Machine and Deep Learning (ML/DL) models according to their fairness, explainability, robustness, and accountability. The algorithm is deployed on a Web application to allow users to quantify and compare the trustworthiness of their ML/DL models. Finally, a scenario with ML/DL models classifying network cyberattacks demonstrates the platform applicability. Alberto Huertas Celdrán, Melike Demirci, Joel Leupp, Muriel Figueredo Franco, Pedro Miguel Sánchez Sánchez, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller |
CNSM | 5 |
| 2022 | VeNiCE: Enabling Automatic VNF Management based on Smart Contract EventsabstractNetwork Functions Virtualization (NFV) has been a key part of evolving communication systems in the last few years. However, the life-cycle management of Virtual Network Functions (VNF) is still a not trivial task. Blockchains (BC), due to their decentralization and immutability characteristics, together with the automation provided by Smart Contracts (SC), can be employed to enable such automated and trustworthy VNF management.Thus, this paper proposes VeNiCE to automate the deployment and life-cycle management of VNFs using events emitted on SCs. VeNiCE provides automation and auditability by relying on a BC to provide a decentralized approach for VNF management, which performs management actions, such as VNF deployment and deletion, and based on events and communicates with an SC to provide immutable logging of the VNF life-cycle. VeNiCE provides (i) a frontend for user interaction, (ii) a backend implementing the communication with the NFV framework, and (iii) an SC that emits events, stores VNF allocations, and authenticates users. A prototype of VeNiCE was developed and deployed in the Ethereum BC using OpenStack Tacker as an NFV platform. Experiments were conducted in a real-world deployment of such a prototype to analyze the economic costs of using SCs and the time required to process requests by each component of VeNiCE and the BC. Those results obtained show VeNiCE’s feasibility, highlight its benefits achieved with the automation and provide insights on reducing costs by exploring additional BC platforms and different deployment types, which introduce centralization and management concerns. Eder J. Scheid, Muriel Figueredo Franco, Fabian Küffer, Niels Kübler, Pascal Kiechl, Burkhard Stiller |
LCN | 2 |
| 2022 | Blockchain-Based Voting Considered Harmful?abstractBlockchains (BC) and Distributed Ledgers (DL) offer favorable properties, especially immutability and decentralization, which are suitable for voting systems’ Bulletin Boards (BB). In recent years, an influx of BC-based voting systems have been observed. Distributing trust among multiple trustees is a crucial reason to adopt BCs and DLs in voting systems. The practical deployment must be decentralized, too, and not just done through virtualizing interconnected systems. As discussed widely, adopting a BC or DL can incur threats to a system that assumed a trusted and centralized Public Bulletin Board (PBB). Therefore, the exploitation of BCs or DLs requires careful consideration of cryptographic mechanisms and the overall system design, as well as the adversary model. Besides these operational necessities, the long-term privacy of ballots is essential. Thus, the key question investigated in this article is: Can BC, and DL-based voting systems be considered harmful? Hence, first (i) requirements of BC-based voting systems are provided, followed by (ii) terminology definitions, and (iii) complemented by the design and implementation of a fully decentralized voting system: Æternum, which achieves Unconditional Privacy (UP) and neither relies on computational hardness assumptions nor on a trusted Trusted Third Party (TTP). Achieving UP is crucial because future adversaries may be able to break hardness assumptions. Æternum does not present a Single-Point-of-Failure (SPoF) either, since (i) the PBB in use is based on a permissioned DL, and (ii) the final tally and proofs can be verified by anyone, without requiring trust in any authority. Christian Killer, Bruno Rodrigues 0001, Eder J. Scheid, Muriel Figueredo Franco, Burkhard Stiller |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2022 | On the Employment of Machine Learning in the Blockchain Selection ProcessabstractGiven the growing increase in the number of blockchain (BC) platforms, cryptocurrencies, and tokens, non-technical individuals face a complex question when selecting a BC that meets their requirements (e.g., performance or security). In addition, current approaches that aid such a selection process present drawbacks (e.g., require specific BC knowledge or are not automated and scalable), which hinders the decision process even further. Fortunately, techniques such as Machine Learning (ML) allow the creation of selection models without human interaction by identifying the BC features that match the requirements provided by the user in an automated and flexible manner. Thus, this work presents the design and implementation of an ML-based BC selection approach that employs five ML models to select the most suitable BC given user requirements (e.g., BC popularity, fast block inclusion, or Smart Contract - SC support). The approach follows an ML-specific data flow and defines a novel equation to quantify the popularity of a BC. Furthermore, it details the models’ accuracy and functionality in two distinct use cases, which shows their good accuracy (>85%). Finally, discussions on (a) the ML usefulness, (b) advantages over rule-based systems, and (c) the most relevant features for the BC selection are presented. Eder J. Scheid, Ratanak Hy, Muriel Figueredo Franco, Christian Killer, Burkhard Stiller |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2021 | BluePIL: a Bluetooth-based PassIve Localization Method
Bruno Rodrigues 0001, Cyrill Halter, Muriel Figueredo Franco, Eder J. Scheid, Christian Killer, Burkhard Stiller |
IM | 3 |
| 2021 | LaFlector: a Privacy-preserving LiDAR-based Approach for Accurate Indoor TrackingabstractLight Detection and Ranging (LiDAR) is used in various applications, from mapping the environment’s topography to self-driving vehicles. Among such applications, the use of LiDAR for indoor tracking and quantifying visitors’ interest (and ensuring safe distancing) is still not widely explored. Technologies based on wireless signals and video captures are typically used for indoor tracking, but they deficits concerning the lack of accuracy of captured signals or the lack of user privacy in the case of traditional surveillance cameras. Despite introducing tracking challenges inherent in the detection based on light reflection, LiDAR-based approaches represent a relatively low-cost solution for accurate indoor tracking. Thus, this paper presents LaFlector, a LiDAR-based indoor tracking system introducing tracking heuristics capable of detecting, classifying, and tracking several objects simultaneously, which are recorded and dynamically displayed in a 2D coordinate system. LaFlector was evaluated based on a low-cost 2D LiDAR hardware (Slamtec Mapper M1M1) and capable of detecting moving objects with high precision, showing in practice that a LiDAR-based can be used to track visitors’ interest and count the number of moving objects. Bruno Rodrigues 0001, Lukas Müller, Eder J. Scheid, Muriel Figueredo Franco, Christian Killer, Burkhard Stiller |
LCN | 4 |
| 2021 | SecGrid: a Visual System for the Analysis and ML-based Classification of Cyberattack TrafficabstractDue to the increasing number of cyberattacks and respective predictions for the upcoming years with even larger numbers of occurrences, companies are becoming aware not only that the digitization of their businesses is essential, but also that the adoption of efficient cybersecurity strategies is crucial. Therefore, approaches for a better understanding and analysis of cybersecurity are essential.Thus, SecGrid, a Machine Learning (ML) empowered platform for analyzing, classification, and visualization of cyberattacks is introduced. SecGrid implements an extensible set of miners to analyze information from network traces to provide insightful visualizations of malicious traffic given and to classify automatically different types of cyberattacks by using supervised ML. Experiments conducted show high overall usability, scalability in terms of the capacity of the platform to extract information from large files, and high performance and accuracy during the classification of cyberattacks. Muriel Figueredo Franco, Jan von der Assen, Luc Boillat, Christian Killer, Bruno Rodrigues 0001, Eder J. Scheid, Lisandro Z. Granville, Burkhard Stiller |
LCN | 1 |
| 2021 | Poster: DDoSGrid: a Platform for the Post-mortem Analysis and Visualization of DDoS AttacksabstractDistributed Denial-of-Service (DDoS) attacks remain one of the top reasons for business disruption and financial losses. Although mitigation solutions are available on the market, there is still a need for approaches that help network operators understand attack characteristics and behaviors, resulting in better planning of companies' cybersecurity strategies. This paper introduces DDoSGrid, a platform for the analysis and visualization of DDoS attacks. DDoSGrid implements an extensible set of miners to extract, process, and analyze information from network traces (i.e., PCAP files) to provide insightful visualizations for a better understanding and in-depth analysis of DDoS attacks in different scenarios. A case study was performed using an HTTP flood attack scenario to evaluate the feasibility of the approach. DDoSGrid enables real-world DDoS scenarios' analysis, providing an intuitive interface integrated with extensible insightful visualizations and data miners. Muriel Figueredo Franco, Jan von der Assen, Luc Boillat, Christian Killer, Bruno Rodrigues 0001, Eder J. Scheid, Lisandro Z. Granville, Burkhard Stiller |
Networking | 1 |
| 2021 | ASIMOV: a Fully Passive WiFi Device TrackingabstractMobile devices expose information about their hardware and manufacturer while searching for available WiFi networks via a Media Access Control (MAC) protocol. Thus, to protect the users' privacy and prevent MAC address tracking, manufacturers typically provide anonymity through MAC randomization techniques by randomly and periodically modifying the MAC address. This paper presents the ASIMOV tracking approach, which shows through the correlation of randomized information concerning the displacement of devices in space-time dimensions that it is possible to gain insights into identifiable device information. The proposed system is entirely passive and uses a combined Received Signal Strength Indicator (RSSI) value-based localization and the Information Elements (IE) transmitted in every IEEE 802.11 probe request frame. Rafael Hengen Ribeiro, Bruno Rodrigues 0001, Christian Killer, Lenz Baumann, Muriel Figueredo Franco, Eder J. Scheid, Burkhard Stiller |
Networking | 5 |
| 2020 | SecBot: a Business-Driven Conversational Agent for Cybersecurity Planning and ManagementabstractBusinesses were moving during the past decades to-ward full digital models, which made companies face new threats and cyberattacks affecting their services and, consequently, their profits. To avoid negative impacts, companies' investments in cybersecurity are increasing considerably. However, Small and Medium-sized Enterprises (SMEs) operate on small budgets, minimal technical expertise, and few personnel to address cybersecurity threats. In order to address such challenges, it is essential to promote novel approaches that can intuitively present cybersecurity-related technical information.This paper introduces SecBot, a cybersecurity-driven conversational agent (i.e., chatbot) for the support of cybersecurity planning and management. SecBot applies concepts of neural networks and Natural Language Processing (NLP), to interact and extract information from a conversation. SecBot can (a) identify cyberattacks based on related symptoms, (b) indicate solutions and configurations according to business demands, and (c) provide insightful information for the decision on cybersecurity investments and risks. A formal description had been developed to describe states, transitions, a language, and a Proof-of-Concept (PoC) implementation. A case study and a performance evaluation were conducted to provide evidence of the proposed solution's feasibility and accuracy. Muriel Figueredo Franco, Bruno Rodrigues 0001, Eder J. Scheid, Arthur Selle Jacobs, Christian Killer, Lisandro Z. Granville, Burkhard Stiller |
CNSM | 1 |
| 2020 | Provotum: A Blockchain-based and End-to-end Verifiable Remote Electronic Voting SystemabstractWhile the existence of Public Bulletin Boards (PBB) is often formulated as an assumption in related work on Remote Electronic Voting (REV) systems, this work here on Provotum focuses on the practical design and architecture of such a PBB, including its distributed execution. Further, Provotum leverages a public permissioned Blockchain (BC) as a PBB, where only authorized entities can sign blocks, while the general public can verify all BC data. Therefore, Provotum defines a new and fully decentralized BC-based REV system, which deploys a permissioned BC as a PBB and allows for the explicit distribution of trust across different permissioned BC nodes. Provotum is operated in a fully distributed fashion by using Smart Contracts (SC), Distributed Key Generation (DKG), Homomorphic Encryption (HE), and Cooperative Decryption (CD), as well as employing client-side encryption, which enables ballot secrecy, while the BC forms an audit trail, enabling public and End-to-end Verifiability (E2E-V). Christian Killer, Bruno Rodrigues 0001, Eder J. Scheid, Muriel Figueredo Franco, Moritz Eck, Nik Zaugg, Alex Scheitlin, Burkhard Stiller |
LCN | 4 |
| 2020 | A Practical Analysis on Mirai Botnet Traffic
Getoar Gallopeni, Bruno Rodrigues 0001, Muriel Figueredo Franco, Burkhard Stiller |
Networking | 3 |
| 2019 | MENTOR: The Design and Evaluation of a Protection Services Recommender SystemabstractCyberattacks are the cause of several damages on governments and companies in the last years. Such damage includes not only leaks of sensitive information, but also economic loss due to downtime of services. The security market size worth billions of dollars, which represents investments to acquire protection services and training response teams to operate such services, determines a considerable part of the investment in technologies around the world. Although a vast number of protection services are available, it is neither trivial for network operators nor endusers to choose one of them in order to prevent or mitigate an imminent attack. As the next-generation cybersecurity solutions are on the horizon, systems that simplify their adoption are still required in support of security management tasks. Thus, this paper introduces MENTOR, a support tool for cybersecurity, focusing on the recommendation of protection services. MENTOR is able to (a) to deal with different demands from the user and (b) to recommend the adequate protection service in order to provide a proper level of cybersecurity in different scenarios. Four similarity measurements are implemented in order to prove the feasibility of the MENTOR's enngine. Aug evaluation determines the performance and accuracy of each measurement used during the recommendation process. Muriel Figueredo Franco, Bruno Rodrigues 0001, Burkhard Stiller |
CNSM | 1 |
| 2019 | BRAIN: Blockchain-based Reverse Auction for Infrastructure Supply in Virtual Network Functions-as-a -ServiceabstractNetwork Functions Virtualization (NFV) is transforming the way in which network operators acquire and manage network services. By using virtualization technologies to move packet processing from dedicated hardware to software, NFV has introduced a new market focused on the offer and distribution of Virtual Network Functions (VNF). Infrastructure Providers (InP) can benefit from an NFV market by providing their infrastructures to fulfill demands of end-users that, in turn, acquire VNFs-as-a-Service (VNFaaS). In this context, solutions that promote the competition between InPs can lead to lower prices, while increasing VNF performance to accommodate specific demands of end-users. In this paper, BRAIN, a blockchain-based reverse auction is presented to introduce an auditable solution in which InPs can compete to host VNFs taking into account the demands of each particular end-user. Such a solution helps reduce costs involved in VNF's commercialization and also monetize NFV-enabled infrastructures. BRAIN is supported by a case study that provides evidence of the solution's feasibility and effectiveness. A discussion regarding blockchain advantages and drawbacks in this use-case (e.g., additional costs and time) concludes this paper. Muriel Figueredo Franco, Eder J. Scheid, Lisandro Z. Granville, Burkhard Stiller |
Networking | 1 |
| 2019 | Guiltiness: A practical approach for quantifying virtual network functions performance
Ricardo J. Pfitscher, Arthur Selle Jacobs, Luciano Zembruzki, Ricardo Luis dos Santos, Eder J. Scheid, Muriel Figueredo Franco, Alberto E. Schaeffer Filho, Lisandro Z. Granville |
Comput. Networks | 6 |
| 2018 | NIEP: NFV Infrastructure Emulation PlatformabstractNetwork Functions Virtualization (NFV) presents several advantages over traditional network architectures, such as flexibility, security, and reduced CAPEX/OPEX. However, virtualizing network functions usually executed on specialized hardware (e.g., firewall, DPI, load balancer) and employing innovative technologies (e.g., OpenFlow, P4) increases the challenges of designing, testing, and deploying network infrastructures and services. Although platforms for prototyping NFV environments have emerged in recent years, they still present limitations that hinder the evaluation of specific NFV scenarios, such as fog computing and heterogeneous networks. In this paper, we present NIEP: a platform for designing and testing NFV-based infrastructures and Virtualized Network Functions (VNFs) through the integration of a well-known network emulator (Mininet) and a novel platform for Click-based VNFs development (Click-on- OSv). NIEP provides a complete NFV emulation environment, allowing network operators to test their solutions in a controlled scenario prior to deployment in production networks. As main advantages, NIEP allows the emulation of heterogeneous scenarios, which can be easily migrated to production environments. An experimental scenario is defined to analyze NIEP's performance in terms of VNFs boot time and throughput. Further, NIEP's advantages and shortcomings are discussed and compared to existing emulation platforms. Thales Nicolai Tavares, Leonardo da Cruz Marcuzzo, Vinicius Fulber-Garcia, Giovanni Venâncio de Souza, Muriel Figueredo Franco, Lucas Bondan, Filip De Turck, Lisandro Z. Granville, Elias P. Duarte Jr., Carlos Raniery Paula dos Santos, Alberto E. Schaeffer Filho |
AINA | 5 |
| 2018 | On the Use of a Measurement Correlation Service for Measurement FederationsabstractThe diversity of services that operate in the Internet has increased significantly in the last years. Performance problems in these services cause important financial losses. To ensure that these problems do not occur, service levels need to be monitored. One of the main techniques for such monitoring involves the use of active measurement mechanisms. However, these mechanisms are expensive in terms of resources consumption due to the activation of measurement sessions. Measurement sessions usually cover only a fraction of what could be measured, which leads to service level problems being missed. Measurement federations can help network administrators in different tasks, such as controlling the activation of active measurement sessions. In this context, measurement correlation can be deployed in order to improve this control in such federations. The main contribution of the present work is the proposal of a data transformation service that provides measurement correlation. This service is used to enable cooperation features in measurement federations, while decreasing resource consumption. Besides that, statistical tests that can be used to compose such correlation are presented. The proposed solution is evaluated using an active measurement dataset from the Brazilian National Research and Education Network (Rede Nacional de Ensino e Pesquisa - RNP). Our results provide insights regarding measurement correlation from federated measurement points and can be used for the design of better application to control active measurement sessions. Jéferson Campos Nobre, Leandro Lisboa Penz, Muriel Figueredo Franco, Lisandro Z. Granville |
ISCC | 3 |
| 2018 | Artificial neural network model to predict affinity for virtual network functionsabstractNetwork Functions Virtualization (NFV) was proposed to migrate middleboxes that compose network services, such as firewalls and Network Address Translation (NAT) servers, from hardware to software running on Virtual Machines (VMs), commonly known as Virtualized Network Functions (VNFs). In NFV-enabled networks, VNFs can be chained in Forwarding Graphs (FGs) to provide services. These FGs establish the logical order in which network packets must traverse until reaching the end-service. In this scenario, network operators establish affinity and anti-affinity rules, which determine restrictions on the placement and chaining of VNFs according to how well or poorly VNFs operate together. To address the subject of identifying affinity relations in NFV-enabled networks, we previously proposed a mathematical model to measure the affinity between pairs of VNFs. However, that affinity model falls short for identifying affinity of VNFs not yet deployed, as they have no resource usage data to take into account. In this paper, we use artificial neural networks to predict affinity estimation for newly introduced VNFs, which still do not have usage data to be analyzed. This affinity neural network is trained using past affinity measurements, containing the data from VNFs, Physical Machines (PMs), and FGs of each measurement as features. We evaluate our solution by analyzing it over real usage data from a Cloud dataset, and conclude that neural networks can be used to provide affinity values for network operators, or NFV orchestrators, to plan the deployment of new VNFs. Arthur Selle Jacobs, Ricardo J. Pfitscher, Ricardo Luis dos Santos, Muriel Figueredo Franco, Eder J. Scheid, Lisandro Z. Granville |
NOMS | 4 |
| 2018 | A model for quantifying performance degradation in virtual network function service chainsabstractVirtual Network Functions (VNFs) can be chained and provisioned on demand, providing elasticity and dynamicity to the network. Due to the interdependencies between VNFs, resulting service chains may not work as expected, and because of that, it is crucial to determine which VNFs are having a negative impact on the service quality. In this paper, we introduce a model to quantify the guiltiness of a VNF on being a bottleneck in a service chain, which provides a metric that estimates the impact on processing delay. In addition, we propose an adaptive algorithm, based on linear regression and neural networks, to adjust the model parameters according to the environment particularities, such as the type and number of VNFs. We show through an experimental evaluation that the guiltiness metric faithfully characterizes end-service performance, by identifying up to 94% of the bottleneck VNFs in the analyzed scenarios. Also, we provide artifacts for researchers to reproduce our results in other scenarios. Ricardo J. Pfitscher, Arthur Selle Jacobs, Eder J. Scheid, Muriel Figueredo Franco, Ricardo Luis dos Santos, Alberto E. Schaeffer Filho, Lisandro Z. Granville |
NOMS | 4 |
| 2017 | Interactive Visualizations for Planning and Strategic Business Decisions in NFV-Enabled NetworksabstractNetwork Functions Virtualization (NFV) is driving a paradigm shift in telecommunications networks, fostering new business models and creating innovation opportunities. In NFV-enabled networks, Service Providers (SPs) have the opportunity to build a business model where tenants can purchase Virtual Network Functions (VNFs) that provide distinct network services and functions. However, the chance to negotiate VNFs requires a change in traditional network planning strategies to accommodate tenants demands. In this context, the planning tasks perform a critical role in the introducing of business strategies that encompass both profit and health of services, which requires operators to have a broad understanding of the environment. In this paper, we propose the usage of two interactive visualization techniques to help NFV network operators in planning and strategic decisions. We advocate that our visualizations can aid in NFV planning tasks, such as infrastructure investment, resources allocation, and service pricing. We present three case studies to provide evidence of the feasibility and effectiveness of our visualizations. Muriel Figueredo Franco, Ricardo Luis dos Santos, Ricardo Andrade Cava, Eder J. Scheid, Ricardo J. Pfitscher, Carla M. D. S. Freitas, Lisandro Z. Granville |
AINA | 1 |
| 2017 | iMPROVE: Enhancing the Introduction of Services on Programmable Virtual NetworksabstractProgrammable Virtual Networks (PVNs) make the network more flexible and allow the fast introduction of new services. However, several shortcomings hamper their wider adoption, including: (i) the extensive knowledge required to configure and manage the NetApps; (ii) the lack of descriptors to detail all nuances of the NetApps; and (iii) there is no solution that enables to distribute and configure NetApps over distinct technologies. Therefore, we propose iMPROVE to simplify the introduction of services in PVNs, enhancing the distribution of NetApps. We also extend the ETSI network service descriptor to support distinct technologies as well as to represent conflict issues. We demonstrate evidence of iMPROVE's feasibility in a case study and compare it with the main solutions for distributing and deploying applications over multiple platforms. Ricardo Luis dos Santos, Muriel Figueredo Franco, Eder J. Scheid, Ricardo J. Pfitscher, Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco |
AINA | 2 |
| 2017 | Affinity measurement for NFV-enabled networks: A criteria-based approachabstractNetwork Functions Virtualization (NFV) offers several benefits for Service Providers (SPs), such as mitigating equipment cost and increasing business agility. In NFV-enabled networks, inadequate placement of Virtualized Network Functions (VNFs) creates bottlenecks, impacting negatively on performance. Therefore, network operators must establish affinity and anti-affinity rules to avoid network and processing bottlenecks, and thus comply with Service Level Agreement (SLA) requirements of tenants. Affinity and anti-affinity rules in NFV must be broad and carefully elaborated to maintain service performance. Network operators must consider further than simply resource allocation when identifying affinity among VNFs. The criteria for VNFs affinity varies for different forwarding graphs. Geolocation, latency, packet loss, and bandwidth usage are some examples of criteria that can be considered as indicators of bottlenecks in high traffic networks. In this paper, we propose a solution to measure affinity between pairs of VNFs, based on a weighted set of affinity criteria considered relevant by a network operator. To evaluate the feasibility of our affinity model, we analyze three case studies over an experimental NFV scenario. We conclude that our affinity model can help network operators identify the cause of issues in NFV-enabled networks, as well as it may be used by NFV orchestrators to aid on VNFs migration and embedding. Arthur Selle Jacobs, Ricardo Luis dos Santos, Muriel Figueredo Franco, Eder J. Scheid, Ricardo J. Pfitscher, Lisandro Z. Granville |
IM | 3 |
| 2017 | AMNESiA: Affinity measurement platform for NFV-enabled networksabstractAMNESiA is an affinity measurement platform for NFV-enabled networks, designed to consolidate and interpret existing monitoring data into an affinity metric, aiding operators to identify affinity and anti-affinity relations in the network. AMNESiA uses the latest snapshot of usage data, collected through a generic monitoring solution, from the database to measure affinity between VNFs. Arthur Selle Jacobs, Ricardo Luis dos Santos, Muriel Figueredo Franco, Eder J. Scheid, Ricardo J. Pfitscher, Lisandro Z. Granville |
IM | 3 |
| 2017 | INSpIRE: Integrated NFV-based Intent Refinement EnvironmentabstractMany aspects of the management of computer networks, such as quality of service and security, must be taken into consideration to ensure that the network meets the users and clients demands. Fortunately, management solutions were developed to address these aspects, such as Intent-Based Networking (IBN). IBN is a novel networking paradigm that abstracts network configurations by allowing administrators to specify how the network should behave and not what it should do. In this paper, we introduce an IBN solution called INSpIRE (Integrated NFV-based Intent Refinement Environment). INSpIRE implements a refinement technique to translate intents into a set of configurations to perform a desired service chain in both homogeneous environments (VNFs only) and heterogeneous environments (VNFs and physical middleboxes). Our solution is capable of (i) determining the specific VNFs required to fulfill an intent, (ii) chaining these VNFs according to their dependencies, and (iii) presenting enough low-level information to network devices for posterior traffic steering. Finally, to assess the feasibility of our solution we detail a case study that reflects real-world management situations and evaluate the scalability of the refinement process. Eder J. Scheid, Cristian Cleder Machado, Muriel Figueredo Franco, Ricardo Luis dos Santos, Ricardo J. Pfitscher, Alberto E. Schaeffer Filho, Lisandro Z. Granville |
IM | 3 |
| 2016 | VISION - Interactive and Selective Visualization for Management of NFV-Enabled NetworksabstractNetwork Functions Virtualization (NFV) enhances the flexibility of network service provisioning and reduces the time to services deployment. NFV and SDN promises transform the carrier networks, introducing innovation in the network core. NFV moves packet processing from dedicated hardware middleboxes to Virtualized Network Functions (VNFs), which run on virtual machines hosted on commercial off-the-shelf servers. However, in NFV-enabled networks, the amount of data managed grows in a fast way. Based on this, the network operator must understand and manipulate a lot of information to effectively manage the network. In this paper, we introduce the VISION, a platform to help the network operator to determine the cause of problems based on visualizations techniques. Our platform implements a set of interactive and selective visualizations to assist in the NFV management. Finally, we conducted three cases studies to provide evidences of the feasibility of our platform. Muriel Figueredo Franco, Ricardo Luis dos Santos, Alberto E. Schaeffer Filho, Lisandro Z. Granville |
AINA | 1 |