EDBT 2026 Demo / reviewers in the wild / expert
Muhammad Shuaib Siddiqui
dblp:187/6966 · also Shuaib Siddiqui
· DBLP profile ↗
32ranked-venue papers
3as first author
20since 2021 · last 2026
0000-0002-8257-4969ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 16 · 3 first-author · 8 since 2021Software engineering, systems software and programming languages · 5 · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards Secure Knowledge Distillation in Edge and Federated AI Systems: A System-Level Perspective
Nil Ortiz Rabella, Vladimir Estivill-Castro, Muhammad Shuaib Siddiqui, Hatim Chergui |
NetSoft | 3 |
| 2026 | Robust AI-based intrusion detection for IoMT: A data-efficient approach via optimized feature selection and hybrid data balancingabstractThe growing integration of the Internet of Medical Things (IoMT) in critical infrastructure demands efficient and accurate Intrusion Detection Systems (IDS) tailored to their resource-constrained environments. In this work, we propose the Optimized Preprocessing Framework (OPF): A novel pre-processing methodology to develop a computationally optimized and robust against extreme class imbalance Artificial Intelligence-based IDS. Our methodology operates in two stages: First, a fully balanced dataset is created using Random Undersampling of the majority classes, and a Gini feature-based prioritization method is employed to efficiently reduce the feature space. Then, a Random Forest model is trained on a nearly balanced version of the dataset, generated using a hybrid resampling technique via logarithmic interpolation that employs SMOTE-based oversampling of minority classes and Random Undersampling of majority classes. This process preserves relative class order while compressing extreme disparities. Moreover, it significantly reduces the feature space and computational overhead. We validate the proposed approach on multiple real-world datasets, including CICIoMT2024, IoMT-TrafficData, and CICIoT2023. Results show that our method improves the F1-score metric, while reducing model complexity by 31.11%, 31.39%, and 78.16% in each dataset respectively, thereby making it suitable for deployment in practical IoMT environments. Jordi Doménech, Saber Mhiri, Olga León 0001, Muhammad Shuaib Siddiqui, Josep Pegueroles 0001 |
Comput. Networks | 4 |
| 2026 | A knowledge-based multi-agent framework for security control recommendationabstractHardening IT on-premises environments can be a daunting task for teams without access to adequate cybersecurity expertise. In this regard, Decision Support Systems (DSS) with embedded expert knowledge can assist users by guiding them with security recommendations to meet their objectives. This work proposes a Security DSS that recommends security control sub-families given minimal user requirements indicating coverage of different security dimensions. It leverages a curated, unified dataset from both well-known Information Security (InfoSec) and academic sources. This DSS is defined as a non-zero-sum, simultaneous game that is grounded in a Multi-Agent Influence Diagram (MAID) model and explores the decision space over 7 security dimensions or agents, using no-regret online learning to ultimately find the security control sub-families that best fit the requirements while incurring minimal under- and over-provisioning of security resources. This work was validated in terms of performance and accuracy, among others, for varying dataset sizes. It shows exceptional satisfaction coverage results of 99% when using as little as ∼ 65% of the SW-implementable security controls, running in 1.2–35.7 seconds; and more moderate coverage results of 73%–77% when using ∼ 29% of the controls, resolving in 0.8–13.8 seconds. Carolina Fernandez 0001, Muhammad Shuaib Siddiqui, Vanesa Daza |
Knowl. Based Syst. | 2 |
| 2025 | Taming Bandwidth Bottlenecks in Federated Learning via ECN-based Gradient Compression
Javier Palomares, Chiara Camerota, Estefanía Coronado, Cristina Cervello-Pastor, Muhammad Shuaib Siddiqui, Flavio Esposito |
CNSM | 5 |
| 2025 | AI-Driven NFV Service Chaining Across the Edge-to-Cloud Continuum: Placement, Fairness, and CoordinationabstractAI-driven Network Function Virtualization (NFV) service chaining is emerging as a key enabler for automation in edge-to-cloud infrastructures. However, existing standards and orchestration frameworks lack mechanisms for fairness, coordination, and dynamic resource sharing across distributed AI agents. This paper proposes a hierarchical architecture that integrates adaptive agent placement and fairness-aware scheduling for AI-based NFV coordination. At its core, the Multi-Agent Dynamic Bandwidth Environment (MADBE) framework leverages deep reinforcement learning to enable agents to collaboratively allocate shared bandwidth while meeting latency and throughput constraints. Experimental results demonstrate that MADBE significantly improves convergence speed, reduces conflict rates, and maintains bandwidth utilization near the 90% threshold, outperforming state-of-the-art baselines. Moreover, MADBE sustains near-zero violation rates for service-level constraints, even under dynamic and heterogeneous workloads. These results highlight the potential of fairness-aware, multi-agent coordination in next-generation 5G/6G networks and industrial automation environments. Javier Palomares, Estefanía Coronado, Cristina Cervello-Pastor, Muhammad Shuaib Siddiqui |
ICCCN | 4 |
| 2025 | Identity management for frameworks managing northbound APIs of future networksabstractFuture networks will deliver unprecedented performance, versatility, and efficiency, driven by advancements in automated monitoring and control. As networks evolve into interconnected platforms capable of enabling advanced features, allocating assets, and configuring them via northbound Application Programming Interfaces (APIs), dynamic control over multiple actors and stakeholders becomes essential. At this point, identity management plays a crucial role in overseeing onboarding, administering access, and registering activity to log and account for all operations. This paper compares the Open Common API Framework (CAPIF), based on the European Telecommunications Standards Institute (ETSI) standard, with a novel distributed identity-based approach using Distributed Ledger Technology (DLT). To assess the viability of these solutions, various tests are conducted to evaluate the frameworks’ latency and processing workloads. Emma O'Brien, Breno Da Costa Paulo, Angel Martin, Muhammad Shuaib Siddiqui, Sergio Giménez Antón |
ISNCC | 4 |
| 2025 | A Bayesian Network Approach for Enhancing Security-Focused Decision Support SystemsabstractThe adoption and integration of heterogeneous stacks in most of today’s open-source based networks brings clear benefits like interoperability and availability of advanced features. Yet, on the other hand the increasing number of interconnecting components and moving parts requires maintaining an ever increasing base of interdisciplinary knowledge of different tools in different domains to ensure proper operation. To alleviate such efforts, this work proposes a Decision Support System (DSS) to guide infrastructure operators through the selection of security approaches (e.g. tools) to adopt in their environments. This framework easily captures the end-user high-level requirements on the security triad for different domains and runs inference on the designated models to provide the identified tools (security mechanisms) that better serve such needs. The presented DSS aims at delivering an understandable and extensible framework to accommodate varying requirements and Bayesian Network (BN) models. The architecture and modelling of the system are proposed, aligned with its theoretical framework. Its performance is evaluated in terms of time and prediction accuracy. Carolina Fernandez 0001, Muhammad Shuaib Siddiqui, Vanesa Daza |
LCN | 2 |
| 2025 | Preventive and Reactive Cybersecurity Techniques on IoT Devices in Healthcare EnvironmentsabstractIn the rapidly evolving landscape of the Internet of Medical Things (IoMT), ensuring the security and reliability of interconnected medical devices is paramount. Traditional cybersecurity methods, while extensively discussed, often fall short in detecting and responding to evolving threats. Anomaly-based Intrusion Detection Systems (IDS) leveraging Artificial Intelligence (AI) techniques are increasingly favored for their ability to detect zero-day attacks and adapt to new threat landscapes. Accordingly, this doctoral thesis aims to develop and validate AI-based IDS for identifying and mitigating cybersecurity threats within IoMT environments. By utilizing publicly available datasets and generating a novel dataset from real-world IoMT devices and simulated cyberattacks, this study enhances detection system performance and investigates the generalizability of the proposed IDS across diverse environments using innovative AI techniques. Additionally, it explores and designs effective automated prevention techniques to enhance patient-centric cybersecurity against potential threats. The findings of this research are expected to significantly contribute to IoMT security, offering practical solutions for protecting critical healthcare infrastructure and ensuring patient safety. Jordi Doménech, Saber Mhiri, Muhammad Shuaib Siddiqui, Josep Pegueroles 0001 |
NetSoft | 3 |
| 2025 | A Vpn-As-A-Service Tailored Enabler for Computing-Constrained EnvironmentsabstractIndustry has embraced Zero Trust (ZT) architectural tenets and implementations for cloud-native environments, following stricter security requirements to both internal and external tenants. Among others, these approaches combine finegrained identity management and monitoring for both inventorying and better analysing the devices' security posture for overall protection, along with strict separation of concerns and isolation to enforce minimal privilege. Networking-wise, ZT approaches rely as well on isolation and least privilege; enacted by separate, secure tunnels per tenant connecting to a given infrastructure. Such implementations can also be applied to the connectivity within and towards experimental infrastructures. In this sense, this work contributes the design and evaluation of a cloud-native VPN-as-a-Service (VPNaaS) that can be (i) easily orchestrated to deploy on-the-fly, separate tunnels per each tenant remotely connecting to the infrastructure; (ii) integrated with common Identity and Access Management (IAM) tools, key to ZT deployments; and (iii) adapt to computing- or entropyconstrained environments. This solution is customisable and allows, among others, to select from RSA or Elliptic Curves (EC) as key generation algorithm and their parameters to achieve more secure keys and adapt to resource-constrained environments. Carolina Fernandez 0001, César Cajas Parra, Muhammad Shuaib Siddiqui |
NetSoft | 3 |
| 2025 | Enhanced Multi-Task Scheduling in MEC-Enabled Industrial Systems: Integrating Deep Reinforcement Learning with Optimizer ExperiencesabstractIn industrial multi-access edge computing (MEC), novel collaborative systems involving multiple automated guided vehicles (AGVs) require the execution of both critical tasks and computational tasks, such as AI-based collision avoidance. However, previous research focused mainly on scheduling process-related tasks and overlooked computational tasks. Moreover, scheduling tasks between AGVs in collaborative systems poses an integer problem, which is challenging to solve in polynomial time, highlighting the need for computationally efficient algorithms. This paper proposes a deep reinforcement learning (DRL)-based approach to multi-task scheduling (DRL-MTS) in multi-AGV systems. It involves dynamically applying a catalog of DRL models, each tailored to different numbers of AGVs. Evaluation results demonstrate that the proposed inter-AGV DRL-MTS strategy closely approaches the optimal solution, reaching up to 96% task completion compared to a 98% of the optimal solution, while significantly reducing decision times. Moreover, the training time for these models has been reduced threefold using datasets from existing optimization solvers, and transfer learning has further cut training times by up to 51%. Javier Palomares, Estela Carmona Cejudo, Cristina Cervello-Pastor, Estefanía Coronado, Muhammad Shuaib Siddiqui |
WCNC | 5 |
| 2025 | Minimizing active nodes in MEC environments: A distributed learning-driven framework for application placement
Claudia Torres-Pérez, Estefanía Coronado, Cristina Cervello-Pastor, Javier Palomares, Estela Carmona Cejudo, Muhammad Shuaib Siddiqui |
Comput. Networks | 6 |
| 2024 | 5GaaS: DLT and Smart Contract-Based Network Slice Management in a Decentralized MarketplaceabstractThe proper orchestration of end-to-end network slices demands dynamic and meticulous resource management while addressing the complexities of multi-tenancy and multiservice scenarios. In this context, integrating network orchestrators with distributed ledger technologies has gained significant attention for its potential to implement decentralized finance marketplaces and service-level agreements using smart contracts. This approach can support the evolution of business models beyond traditional network-sharing agreements, such as crowdfunding. To this end, we propose the 5G-as-a-Service (5GaaS) system architecture, which leverages distributed ledger technologies and smart contracts to orchestrate and optimize network slicing, enabling ubiquitous computing and connectivity in 5G networks. We evaluated the feasibility of this system across various Ethereum testnets, demonstrating the cost-effectiveness, scalability, and minimal latency of the 5GaaS system, making it suitable for seamless integration into existing telecommunications frameworks. Kurdman Rasol, Alfonso Egio, Miguel Catalan-Cid, Leonardo Lossi, Helio Simeão, Muhammad Shuaib Siddiqui |
CNSM | 6 |
| 2024 | MEO: An Enhanced MEC Orchestrator for Federated and Distributed MEC SystemsabstractResource distribution among diverse administrative domains, network operators, and geographical locations across the edge-to-cloud continuum requires suitable communication and management and orchestration (MANO) mechanisms among orchestration domains. In multi-access edge computing (MEC) environments, efficient application lifecycle management and system federation are essential for scalability, optimal resource utilization, and ensuring service continuity and reliability. Existing orchestration solutions, typically designed for centralized cloud architectures, often fall short in accommodating application delay requirements and in managing the dynamic and distributed nature of MEC resources effectively. This paper introduces a cloud-native, platform-agnostic MEC Orchestrator (MEO) with enhancements over the ETSI MEC architecture, albeit aligned with GSMA and ETSI MEC federation standards, that supports cross-platform MANO and resource controllability. Federation is supported through a new MEO-to-MEO interface that enables application migration across MEC systems. Experimental results demonstrate a 95% instantiation success rate for instantiation, overperforming the baseline Kubernetes scheduler, and 93.3% for migration requests within federated MEC systems in high request volume scenarios. Javier Palomares, Estefanía Coronado, Cristina Cervello-Pastor, Estela Carmona Cejudo, Muhammad Shuaib Siddiqui |
GLOBECOM | 5 |
| 2023 | Design and Evaluation of a K8s-based System for Distributed Open-Source Cellular NetworksabstractVirtualization in cellular networks is one of the key areas of research where technologies, infrastructure and challenges are rapidly changing as 5G system architecture demands a paradigm shift. This paper aims to study the viability and the performance of cloud-native infrastructures for hosting network functions. The selected frameworks implement both the 4G and the 5G stacks and their network functions. This work considers a variety of scenarios for enabling the deployment of a distributed and open-source cellular network: a baremetal setup, an all-docker-based setup and the proposed Kubernetes setup. Moreover, an analysis of the impact that the Radio Access Network (RAN) and the Core Network (CN) have on computational resource utilization is presented as the network conditions vary. The design proposed in this work has been validated and analyzed using the proposed prototype and testbed. This paper proposes a design to increase resource usage flexibility and performance and reduction of deployment time. The analysis of the gathered data reveals that the deployments of containerized cellular networks display better performance in terms of flexibility, low startup times, and ease of deployment while consuming the same resources as the non-containerized. Javier Palomares, Estefanía Coronado, David Rincón Rivera, Muhammad Shuaib Siddiqui |
IWCMC | 4 |
| 2023 | Enabling Intelligence Inclusiveness in Edge to Cloud Continuum: Challenges and OpportunitiesabstractEdge to Cloud Continuum is a concept that integrates cloud computing and cellular networks that has been gaining popularity due to its potential to provide a seamless user experience and address the challenges of managing complex multi-domain networks involving massive IoT devices. Enabling intelligence in the Edge to Cloud Continuum can further enhance its capabilities, offering benefits such as reduced latency, improved scalability, enhanced resource utilization, and increased context awareness. This paper provides insights into the opportunities and challenges of enabling intelligence in Edge to Cloud Continuum, highlighting the potential of this technology. This study presents a comprehensive review of the existing literature on enabling intelligence in Edge to Cloud Continuum, to reach the research questions that will construct the PhD. Various tools and technologies that can be used to integrate intelligence into the Edge to Cloud Continuum system were explored and analyzed. In addition, this study provides a detailed work plan for the upcoming months of the project. Javier Palomares, Estefanía Coronado, Cristina Cervello-Pastor, Muhammad Shuaib Siddiqui |
NetSoft | 4 |
| 2022 | Design of AI-based Resource Forecasting Methods for Network SlicingabstractWith the forthcoming of 5G networks, the underlying infrastructure needs to support a higher number of heterogeneous services with different QoS needs than ever. For that reason, 5G inherently provides a way to allocate these services over the same infrastructure through the concept of Network Slicing. However, to maximize revenue and reduce operational costs, a method to proactively adapt the resources assigned to each slice becomes imperative. For that reason, this work presents two Machine Learning (ML) models, leveraging Long-Short Term Memory (LSTM) and Random Forest algorithms, to forecast the throughput of each slice and adapt accordingly the amount of resources needed. The models are evaluated using NS-3, which has been integrated with the ML models through a shared memory framework. This enables a closed loop in which the predictions of the models can be used at run time to introduce changes in the network. Consequently, it makes it able to cope with the forecasted requirements, eliminating the need for off-line training and resembling better a real-life scenario. The evaluation performed shows the ability of the models to predict the slices' throughput under various settings and proves that Random Forest provides up to 26% better results than LSTM. Juan Sebastian Camargo, Estefanía Coronado, Blas Gómez, David Rincón Rivera, Muhammad Shuaib Siddiqui |
IWCMC | 5 |
| 2022 | Roadrunner: O-RAN-based Cell Selection in Beyond 5G NetworksabstractO-RAN is currently emerging as the way to build a virtualized 5G and beyond Radio Access Network (RAN) that is based on open interfaces and off-the-shelf hardware. O-RAN consolidates the intelligence of several gNodeBs at the Near-realtime RAN Intelligent Controller (RIC) making it more programmable and aware of the mobile users’ surroundings. In this paper we present Roadrunner, an O-RAN-based solution designed to improve cell selection in 5G and beyond networks. Our work has been motivated by the fact that the legacy cell selection procedure in both 4G and 5G networks tends to prefer radio quality and seamless connectivity to high data rates. The reason for this can be traced back to the older releases of the mobile network architecture that were optimized for the circuit-switched communication paradigm and for sparse network deployments. However, with an O-RAN-based approach we can leverage the global network view built and maintained by the Near-realtime RIC to jointly optimize mobility management for channel quality and bitrate. We have designed Roadrunner following the O-RAN Alliance design principles and without requiring any change to the existing 3GPP signaling. No changes to the mobile devices are required either. Performance measurements carried out on a small scale testbed show how Roadrunner can almost double the median throughput in some specific traffic scenarios while also achieving better network fairness. Estefanía Coronado, Muhammad Shuaib Siddiqui, Roberto Riggio |
NOMS | 2 |
| 2022 | Optimal Offloading of Kubernetes Pods in Three-Tier NetworksabstractBy pushing resources to far-edge servers located in the proximity of users, edge computing can greatly reduce end-to-end transmission delays. Task offloading in multi-tier networks refers to the optimization of which tasks should be offloaded from the far-edge to the edge and the cloud. Moreover, the containerization of applications can further reduce resource and time consumption and, in turn, the latency of such applications. Even though Kubernetes has become the de facto container orchestrator, not many works have considered the offloading of containerized applications in Kubernetes clusters spanning from cloud to far-edge. In this work, the problem of offloading Kubernetes tasks (or pods) in three-tier networks is formulated and optimized. First, a utility function is presented in terms of the cumulative weighted pod response time, and a utility minimization problem with central processing unit (CPU) constraints is presented. Based on the optimal theoretical solution to this problem, a three-tier offloading decision algorithm (TTODA) is developed. Horizontal scaling is considered, and specific hardware capabilities of each node are taken into account by setting specific SLAs that are fed back to the algorithm. Numerical results show that TTODA outperforms a typical Kubernetes QoS model based on first-in, first-served algorithm (FIFSA) in terms of utility, average pod response time, and usage of far-edge CPU. Further, TTODA achieves an excellent trade-off between performance and computational complexity, and thus it can help achieve the requirements of latency-sensitive applications. Moreover, TTODA can easily be extended to scenarios with joint memory and CPU constraints. Estela Carmona Cejudo, Francesco Iadanza, Muhammad Shuaib Siddiqui |
WCNC | 3 |
| 2021 | Delay-Sensitive Wireless Content Delivery: An Interpretable Artificial Intelligence ApproachabstractThe COVID-19 emergency has made the consumption of multimedia content skyrocket in all contexts, including education. Many universities leverage hybrid learning models, in which students join a real-time video session via Wi-Fi from several classrooms to ensure safety and social distancing. This is creating a significant strain on the wireless access network, which is required to deliver an unusually high level of traffic. Artificial Intelligence (AI) and Machine Learning (ML) solutions have emerged as a way to make networks easier to control and to manage. However, their black box nature and in general their fire and forget approach has generated considerable skepticism over the entire value chain, from vendors to network administrators. This situation has led to a new interest in interpretable AI solutions, which aim at making the decisions taken by AI/ML models intelligible to a domain expert. In this article, we review the concept of interpretable AI and analyze the challenges, requirements, and benefits it can bring to delay-sensitive content delivery in 802.11 Wi-Fi networks. Furthermore, we apply these requirements to a use case in which we focus on advanced Quality of Service (QoS) provision, and we propose an interpretable and low-complexity ML model that addresses those requirements. The results demonstrate performance gains up to 60% in the sensitive traffic and up to 20% at network-wide level. Estefanía Coronado, Blas Gómez, José Miguel Villalón Millán, Antonio Jose Garrido del Solo, Muhammad Shuaib Siddiqui, Roberto Riggio |
CNSM | 5 |
| 2021 | Validation and Benchmarking of CNFs in OSM for pure Cloud Native applications in 5G and beyondabstractCloud Native (CN) in 5G systems has been identified as a pivotal candidate for operational and capital expenditure savings as well as for improvements in system agility and services role-out. CN telco is a step forward with respect to Network Function Virtualisation (NFV) aiming at embracing a microservice-based architecture. With this in mind, the European Telecommunications Standards Institute (ETSI) has evolved the ETSI NFV reference architecture to adapt to CN and fill the gap with the NFV framework, including containers and ZeroTouch, among other capabilities. Open-source Management & Orchestration (MANO) initiatives, such as Open Source MANO (OSM), are promoting this adoption giving support to CN solutions based on containers. However, at this early stage deployments are currently non-standalone and embedded in VNF-based solutions such as OpenStack. In this context, this paper presents a proof of concept of a full container technology deployment -via Kubernetes- in a NFV architecture. First, a full CN NFV environment is set with the help of OSM MANO, for which we describe the implementation to enable native kubernetes-based Container Network Functions (CNFs) and analyse their performance, limits, advantages and drawbacks. Finally, our solution for CNFs is benchmarked against a typical OSMOpenStack setup where VNFs are deployed. The results obtained in this work can help to further encourage users and operators to use CNFs and get the most out of containerisation in NFV. Adrián Pino, Pouria Sayyad Khodashenas, Xavier Hesselbach, Estefanía Coronado, Muhammad Shuaib Siddiqui |
ICCCN | 5 |
| 2020 | On 5G network slice modelling: Service-, resource-, or deployment-driven?
Apostolos Papageorgiou, Adriana Fernández-Fernández, Muhammad Shuaib Siddiqui, Gino Carrozzo |
Comput. Commun. | 3 |
| 2018 | Identity and Access Control for micro-services based 5G NFV platformsabstractThe intrinsic use of SDN/NFV technologies in 5G infrastructures promise to enable the flexibility and programmability of networks to ensure lower cost of network and service provisioning and operation, however it brings new challenges and requirements due to new architectural changes. In terms of security, authentication and authorization functions need to evolve towards the new and emerging 5G virtualization platforms in order to meet the requirements of service providers and infrastructure operators. Over the years, a lot of authentication techniques have been used. Now, a wide range of options arise allowing to extend existing authentication and authorization mechanisms. Daniel Guija, Muhammad Shuaib Siddiqui |
ARES | 2 |
| 2018 | Insights from SONATA: Implementing and integrating a microservice-based NFV service platform with a DevOps methodologyabstractIn pursuit of a flexible, resource efficient and high- performant 5G infrastructure, many operators, vendors and research consortia are currently developing, testing and integrating their NFV platform with associated management and orchestration (MANO) functionality. The SONATA NFV platform follows a micro-service design, which involves a tight coupling between an SDK, monitoring and MANO functionality, targeting a secure and stable software foundation. This experience paper gives a thorough overview on the encountered challenges, insights and resulting learnings when implementing and integrating the SONATA Service Platform using a continuous integration and delivery DevOps methodology. This is the result of a strong cooperation between prominent equipment vendors, network operators, software companies and universities, providing a set of constructive recommendations in hope of catalysing the development and deployment of NFV platforms. Thomas Soenen, Steven van Rossem, Wouter Tavernier, Felipe Vicens, Dario Valocchi, Panagiotis Trakadas, Panagiotis Karkazis, Georgios Xilouris, Philip Eardley, Stavros Kolometsos, Michail-Alexandros Kourtis, Daniel Guija, Muhammad Shuaib Siddiqui, Peer Hasselmeyer, José Bonnet, Diego R. López |
NOMS | 13 |
| 2017 | Devops based service orchestration in 5G virtualised networks - SONATA project demoabstractResearch in 5G architectures is focused on exploring ways to leverage the use of virtualisation offered by cloud infrastructures and network programmability to provide flexibility and agility in the development and deployment of Network Services and virtual network functions. In this context, this paper presents the description of SONATA project demonstrator. SONATA supports agile development and orchestration of network services in 5G networks. Georgios Xilouris, Stavros Kolometsos, Christos Xilouris, Javier Fernandez Hidalgo, Muhammad Shuaib Siddiqui, Alberto Rocha, Sonia Castro, Felipe Vicens, Josep Martrat |
NetSoft | 5 |
| 2017 | Leading innovations towards 5G: Europe's perspective in 5G infrastructure public-private partnership (5G-PPP)abstractThe paper elaborates on the technological and architectural innovations researched and developed by 5G-PPP Phase 1 projects and covering innovation areas such as 5G system design and evaluation, novel air interfaces, network management and security as well as virtualization and service deployment aspects. José M. Alcaraz Calero, Ioannis-Prodromos Belikaidis, Carlos J. Bernardos, Pascal Bisson, Didier Bourse, Michael Bredel, Daniel Camps-Mur, Tao Chen 0011, Xavier Pérez Costa, Panagiotis Demestichas, Mark Doll, Salah-Eddine Elayoubi, Andreas Georgakopoulos, Aarne Mämmelä, Hans-Peter Mayer, Miquel Payaró, Bessem Sayadi, Muhammad Shuaib Siddiqui, Miurel Tercero, Qi Wang 0001 |
PIMRC | 18 |
| 2015 | A survey on the recent efforts of the Internet Standardization Body for securing inter-domain routing
Muhammad Shuaib Siddiqui, Diego Montero, René Serral-Gracià, Xavier Masip-Bruin, Marcelo Yannuzzi |
Comput. Networks | 1 |
| 2015 | Self-reliant detection of route leaks in inter-domain routing
Muhammad Shuaib Siddiqui, Diego Montero, René Serral-Gracià, Marcelo Yannuzzi |
Comput. Networks | 1 |
| 2014 | A techno-economie study of network coding protection schemesabstractThe recent advances in optical technologies pave the way to the deployment of high-bandwidth services. As reliability becomes a mandatory requirement for some of these services, network providers must endow their networks with resilience capabilities. In recent years, network coding protection (NCP) has emerged as a tentative solution aiming at enabling network resilience in a proactive and efficient way. The goal of this paper is to conduct a techno-economic study to evaluate the protection cost required by NCP schemes deployed either at the IP/MPLS or at the Optical layer of a multi-layer network, as well as its impact on both the capital and operational expenditures (CAPEX, OPEX) of a network provider. Our evaluation results show that a significant reduction in both CAPEX and OPEX is obtained with NCP. Indeed, at least a 49% and 52% of CAPEX and OPEX reduction is achieved respectively in comparison with conventional proactive protection schemes. Wilson Ramírez, Xavier Masip-Bruin, Eva Marín-Tordera, Marcelo Yannuzzi, Anny Martínez, Sergio Sánchez-López, Muhammad Shuaib Siddiqui, Víctor López 0001 |
GLOBECOM | 7 |
| 2014 | Route leak detection using real-time analytics on local BGP informationabstractA route leak can be defined as a security gap that occurs due to the infringement of the routing policies that any two Autonomous Systems (ASes) have agreed upon. Route leaks are seemingly simple, but hard to resolve since the ASes keep their routing policies confidential. Indeed, the traditional palliatives, such as the utilization of route filters, are no longer used by a large number of ASes, given the high administrative burden that they entail. Other alternatives, like BGP monitoring tools, not only require third party information gathered at multiple vantage points, but also they become impotent in many cases, due to their limited view of the interdomain routing state. In this paper, we propose a different approach, which allows to autonomously detect the occurrence of route leaks by solely inspecting the BGP information available at the AS. Our main contributions can be summarized as follows. First, we propose a self-contained Route Leak Detection (RLD) technique, which is based on real-time analytics on the Route Information Bases (RIBs) of the border routers of an AS. Second, we introduce Benign Fool Back (BFB), "a harmless bluff" that can substantially improve the success rate of the RLD technique. Third, we show through exhaustive simulations that our technique can detect route leak incidents in various scenarios with high success rate. In addition, our solution has the following practical advantages: a) no reliance on third party information (e.g., on vantage points); b) no changes required to control-plane protocols (e.g., to BGP); and c) allows non-invasive integration (e.g., using SDN). Muhammad Shuaib Siddiqui, Diego Montero, Marcelo Yannuzzi, René Serral-Gracià, Xavier Masip-Bruin, Wilson Ramírez |
GLOBECOM | 1 |
| 2014 | A survey and taxonomy of ID/Locator Split Architectures
Wilson Ramírez, Xavier Masip-Bruin, Marcelo Yannuzzi, René Serral-Gracià, Anny Martínez, Muhammad Shuaib Siddiqui |
Comput. Networks | 6 |
| 2014 | TEFIS: A single access point for conducting multifaceted experiments on heterogeneous test facilities
Marcelo Yannuzzi, Muhammad Shuaib Siddiqui, Annika Sällström, John Brian Pickering, René Serral-Gracià, Anny Martínez, S. Taylor, Farid Benbadis, Jeremie Leguay, E. Borrelli, Itziar Ormaetxea, K. Campowsky, Gabriele Giammatteo, Georgios Aristomenopoulos, Symeon Papavassiliou, T. Kuczynski, S. Zielinski, Jean-Marc Seigneur, Carlos Ballester Lafuente, Jeaneth Johansson, Xavier Masip-Bruin, M. Caria, J. R. Ribeiro Junior, E. Salageanu, J. Latanicki |
Comput. Networks | 2 |
| 2013 | Securing the LISP map registration processabstractThe motivation behind the Locator/Identifier Separation Protocol (LISP) has shifted over time from routing scalability issues in the core Internet to a set of use cases for which LISP stands as a technology enabler. Among these are the mobility of physical and virtual appliances without breaking their TCP connections, seamless migration and fast deployments of IPv6, multihoming, and data-center applications. However, LISP was born without security, and therefore is susceptible to attacks in its control-plane. The IETF's LISP working group has recently started to work in this direction, but the protocol still lacks end-to-end mechanisms for securing the overall registration process on the mapping system. In this paper, we address this issue and propose a solution that counters the attacks. We have deployed LISP in a real testbed, and compared the performance of our proposal with current LISP implementations, in terms of both messaging and packet size overhead. Our preliminary results prove that our solution offers much higher security with minimum overhead. Diego Montero, Muhammad Shuaib Siddiqui, René Serral-Gracià, Xavier Masip-Bruin, Marcelo Yannuzzi |
GLOBECOM | 2 |