EDBT 2026 Demo / reviewers in the wild / expert
Sebastiano Miano
dblp:191/3336
· DBLP profile ↗
14ranked-venue papers
6as first author
12since 2021 · last 2026
0000-0002-1247-9640ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 4 first-author · 7 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Defending against Traffic Analysis Attacks with Flexible In-Network Obfuscation
Guorui Xie, Qing Li 0006, Zhenning Shi, Gianni Antichi, Yijia Zhu, Changxing Weng, Sebastiano Miano, Yong Jiang 0001, Mingwei Xu 0001 |
NSDI | 8 |
| 2025 | An Investigation on Packet Sampling between Kernel and User Space for NIDSabstractExtended Berkeley Packet Filter technology has been successfully used to accelerate several data-plane algorithms. An application area of growing interest is Intrusion Detection, where timely packet processing at high speed is critical. In this paper, we focus on anomaly detection, which uses machine learning to identify packets belonging to a malicious flow with the intervention of a packet sampling policy to keep up with the traffic network pace in a kernel-to-user-space pipeline, to investigate the deployment feasibility of the designed anomaly-based kernel-enhanced intrusion detection system. The performance tests related to the packet sampling policy have been carried out taking into account the same dataset used to test the inference algorithm, establishing a packet sampling rate threshold maintaining a high accuracy. The throughput measurements have been tried out on our testbed composed by two back-to-back connected programmable middlebox leveraging on the iperf3 tool to employ the stress test, validating that our designed network intrusion detection system is suitable for deployment.1 Luca Giacometti, Dario Crippa, Sebastiano Miano, Giacomo Verticale |
ISNCC | 3 |
| 2025 | State-Compute Replication: Parallelizing High-Speed Stateful Packet Processing
Qiongwen Xu, Sebastiano Miano, Tao Wang 0088, Adithya Murugadass, Songyuan Zhang, Anirudh Sivaraman, Gianni Antichi, Srinivas Narayana |
NSDI | 2 |
| 2025 | Switch bypass: End-host cloud networking revisited
Antonio Le Caldare, Luigi Leonardi, Sebastiano Miano, Gregorio Procissi, Gianni Antichi, Giuseppe Lettieri |
Comput. Networks | 3 |
| 2024 | Rethinking Cloud Network Stacks with Switch BypassabstractVirtual switches are one of the most important building blocks in public cloud network stacks as they apply high-level policies to traffic enabling communication between virtual machines (VMs) and the rest of the world. The problem is that virtual switches need CPU cores to process packets and the more cores assigned to them, the less are available to VMs that are rented to customers and hence generate revenue. With this paper, we show that it is potentially possible to find a sweet-spot between performance and costs. The insight is that applications running on VMs are not always using 100% of their CPU processing power: we use this to design switch bypass, a new technique that allow virtual switches to opportunistically offload part of their processing to the virtual NIC drivers associated with guest VMs. Using packet classification as use-case, we show that with switch bypass we obtain a performance boost up to 40% without the need of additional core processing power. Antonio Le Caldare, Luigi Leonardi, Sebastiano Miano, Gregorio Procissi, Gianni Antichi, Giuseppe Lettieri |
HPSR | 3 |
| 2024 | Accelerating network analytics with an on-NIC streaming engine
Sebastiano Miano, Giuseppe Lettieri, Gianni Antichi, Gregorio Procissi |
Comput. Networks | 1 |
| 2024 | Morpheus: A Run Time Compiler and Optimizer for Software Data PlanesabstractState-of-the-art approaches to design, develop and optimize software packet-processing programs are based on static compilation: the compiler’s input is a description of the forwarding plane semantics and the output is a binary that can accommodate any control plane configuration or input traffic. In this paper, we demonstrate that tracking control plane actions and packet-level traffic dynamics at run time opens up new opportunities for code specialization. We present Morpheus, a system working alongside static compilers that continuously optimizes the targeted networking code. We introduce a number of new techniques, from static code analysis to adaptive code instrumentation, and we implement a toolbox of domain specific optimizations that are not restricted to a specific data plane framework or programming language. We apply Morpheus to several systems, from eBPF and DPDK programs including Katran, Meta’s production-grade load balancer to container orchestration solutions such a Kubernets. We compare Morpheus to state-of-the-art optimization frameworks and show that it can bring up to 2x throughput improvement, while halving the 99th percentile latency. Sebastiano Miano, Alireza Sanaee, Fulvio Risso, Gábor Rétvári, Gianni Antichi |
IEEE/ACM Trans. Netw. | 1 |
| 2023 | Automatic Kernel Offload Using BPFabstractBPF support in Linux has made kernel extensions easier. Recent efforts have shown that using BPF to offload portions of server applications, e.g., memcached and service proxies, can improve application performance and efficiency. However, thus far, the community has not looked at the question of what parts of an application should be offloaded? This paper first shows that blindly offloading application functionality to the kernel is neither beneficial nor desirable, and care must be taken when deciding what to offload. Furthermore, when deciding what to offload, developers must consider not just the application, but also the workload being handled, and the kernel being targetted, Therefore, we advocate automating this decision process in a compiler, that can analyze application code, and produce two executables, a kernel offload and a userspace program, that jointly implement the application's functionality. This paper discusses the challenges that must be addressed to build such a compiler, and why they can be feasibly addressed. Farbod Shahinfar, Sebastiano Miano, Giuseppe Siracusano, Roberto Bifulco, Aurojit Panda, Gianni Antichi |
HotOS | 2 |
| 2022 | Domain specific run time optimization for software data planesabstractState-of-the-art approaches to design, develop and optimize software packet-processing programs are based on static compilation: the compiler's input is a description of the forwarding plane semantics and the output is a binary that can accommodate any control plane configuration or input traffic. Sebastiano Miano, Alireza Sanaee, Fulvio Risso, Gábor Rétvári, Gianni Antichi |
ASPLOS | 1 |
| 2021 | The case for network functions decompositionabstractThis paper makes a case for writing unrestricted eBPF network functions which then get automatically decomposed between kernel and user-space. Farbod Shahinfar, Sebastiano Miano, Alireza Sanaee, Giuseppe Siracusano, Roberto Bifulco, Gianni Antichi |
CoNEXT | 2 |
| 2021 | Providing Telco-oriented Network Services with eBPF: the Case for a 5G Mobile GatewayabstractAlthough several technologies exist for high-speed data plane processing, such as DPDK, the above technologies require a rigid partitioning of the resources of the system, such as dedicated CPU cores and network interfaces. Unfortunately, this is not always possible when running at the edge of the network, in which a few servers are available in each cluster and a mixture of data and control plane services must coexist on the same hardware. In this respect, eBPF can become a better alternative thanks to its integration in the vanilla Linux kernel, which enables contemporary support for data and control plane services, hence enabling a more efficient usage of the (scarce) computing resources. This paper proposes the first proof-of-concept open-source implementation of a 5G Mobile Gateway based on eBPF/XDP, highlighting the possible challenges (e.g., to create traffic policers, as buffering is not available in eBPF) and the resulting architecture. The result is characterized in terms of performance and scalability and compared with alternative technologies, showing that it outperforms other in-kernel solutions (e.g., Open vSwitch) and is comparable with DPDK-based platforms. Federico Parola, Fulvio Risso, Sebastiano Miano |
NetSoft | 3 |
| 2021 | A Framework for eBPF-Based Network Functions in an Era of MicroservicesabstractBy moving network functionality from dedicated hardware to software running on end-hosts, Network Functions Virtualization (NFV) pledges the benefits of cloud computing to packet processing. While most of the NFV frameworks today rely on kernel-bypass approaches, no attention has been given to kernel packet processing, which has always proved hard to evolve and to program. In this article, we present Polycube, a software framework whose main goal is to bring the power of NFV to in-kernel packet processing applications, enabling a level of flexibility and customization that was unthinkable before. Polycube enables the creation of arbitrary and complex network function chains, where each function can include an efficient in-kernel data plane and a flexible user-space control plane with strong characteristics of isolation, persistence, and composability. Polycube network functions, called Cubes, can be dynamically generated and injected into the kernel networking stack, without requiring custom kernels or specific kernel modules, simplifying the debugging and introspection, which are two fundamental properties in recent cloud environments. We validate the framework by showing significant improvements over existing applications, and we prove the generality of the Polycube programming model through the implementation of complex use cases such as a network provider for Kubernetes. Sebastiano Miano, Fulvio Risso, Mauricio Vásquez Bernal, Matteo Bertrone, Yunsong Lu |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2019 | A Service-Agnostic Software Framework for Fast and Efficient in-Kernel Network ServicesabstractThis paper presents Polycube, an open-source software framework based on eBPF, that enables the creation of arbitrary and complex network function chains. Each function can include an efficient in-kernel data plane and a flexible user-space control plane with strong characteristics of isolation, persistence (e.g., across server reboots)and composability. In addition, a generic model for the control and management plane of each network function simplifies the manageability and accelerates the development of new network services. We validate the framework by creating different network services and benchmarking their performance in a complex scenario, namely a network provider for Kubernetes. Results show that Polycube programs are about 20x shorter than equivalent programs implemented with vanilla-eBPF. Sebastiano Miano, Matteo Bertrone, Fulvio Risso, Mauricio Vásquez Bernal, Yunsong Lu, Jianwen Pi, Aasif Shaikh |
ANCS | 1 |
| 2018 | Creating Complex Network Services with eBPF: Experience and Lessons LearnedabstractThe extended Berkeley Packet Filter (eBPF) is a recent technology available in the Linux kernel that enables flexible data processing. However, so far the eBPF was mainly used for monitoring tasks such as memory, CPU, page faults, traffic, and more, with a few examples of traditional network services, e.g., that modify the data in transit. In fact, the creation of complex network functions that go beyond simple proof-of-concept data plane applications has proven to be challenging due to the several limitations of this technology, but at the same time very promising due to some characteristics (e.g., dynamic recompilation of the source code) that are not available elsewhere. Based on our experience, this paper presents the most promising characteristics of this technology and the main encountered limitations, and we envision some solutions that can mitigate the latter. We also summarize the most important lessons learned while exploiting eBPF to create complex network functions and, finally, we provide a quantitative characterization of the most significant aspects of this technology. Sebastiano Miano, Matteo Bertrone, Fulvio Risso, Massimo Tumolo, Mauricio Vásquez Bernal |
HPSR | 1 |