EDBT 2026 Demo / reviewers in the wild / expert
Ali Mazloum
dblp:348/3059
· DBLP profile ↗
18ranked-venue papers
6as first author
18since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 12 · 5 first-author · 12 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Accelerating Anomaly Detection in Industrial Control Systems Using SmartNICs and DPDKabstractIndustrial Control Systems (ICS) are critical infrastructures that integrate physical processes with programmable logic controllers (PLCs), human–machine interfaces (HMIs), and network communication. Given their dual exposure to cyber and physical threats, continuous monitoring is essential to ensure reliability and safety. A key requirement of ICS is maintaining low latency, as delays can desynchronize control loops and compromise system stability.This paper presents a hybrid detection framework that combines sensor-level time-series fault analysis with flow-based network anomaly detection for Modbus/TCP-based ICS. The framework leverages an NVIDIA BlueField-3 SmartNIC to offload machine-learning inference and sequential signal processing directly to the network interface using DPDK. The proposed system employs cumulative sum (CUSUM) and exponentially weighted moving average (EWMA) techniques to extract features for a multilayer perceptron (MLP) classifier, which identifies normal and faulty sensor behavior with high per-device accuracy. Network flow statistics are also analyzed to detect cyberattacks targeting the ICS infrastructure. Experimental results show sub–1 μs average inference latency for binary classification and an average of 5 μs per 32-packet burst on the BlueField-3 SmartNIC. Sergio Elizalde, Samia Choueiri, Ali Mazloum, Elie F. Kfoury, Jorge Crichigno |
CCNC | 3 |
| 2026 | A Testbed to Evaluate Next-Generation Security Solutions in Cyber-Physical Systems using Hardware AccelerationabstractAt the core of modern manufacturing systems lie Cyber-Physical Systems (CPS) that prioritize operational continuity over security, resulting in a rising number of cyberattacks targeting critical infrastructures. This paper presents a work-in-progress testbed that modernizes Smart Manufacturing Systems (SMS) by integrating Domain-Specific Accelerators (DSAs)—Data Processing Units (DPUs) and Programmable Data Plane (PDP) switches—to strengthen Operational Technology (OT) security without compromising availability or reliability. These accelerators provide fine-grained visibility, real-time anomaly detection, and efficient policy enforcement at line rate. Preliminary results show that accelerator-based applications outperform CPU-based implementations by several orders of magnitude. Demonstrated use cases include a DPU that performs memory inspection via Direct Memory Access (DMA) to detect injected anomalies and a PDP that implements inline detection using pre-trained Machine Learning (ML) models. With low processing overhead, the system also enables continuous telemetry collection for digital-twin generation without disrupting critical operations. The testbed, deployed on the South Carolina Cloud (SC Cloud), offers remote access for developing and evaluating next-generation CPS and OT security applications. Ali AlSabeh, Ali Mazloum, Elie F. Kfoury, Ramy F. Harik, Thorsten Wuest, Jorge Crichigno |
CCNC | 3 |
| 2026 | Design and Deployment of a Testbed for SmartNIC and Programmable Data Plane ExperimentationabstractThis paper presents the design and deployment of a virtualized testbed that facilitates experimentation and instruction in programmable network systems. The platform integrates Smart Network Interface Cards (SmartNICs), Programmable Data Plane (PDP) switches, and the Data Plane Development Kit (DPDK), within a cloud-based orchestration framework to reproduce high-performance, real-world networking scenarios. It supports line-rate processing, enabling real-time applications such as telemetry, encrypted traffic inspection, and malware detection. Through a series of use cases, we demonstrate how the testbed enables advanced experimentation by offloading infrastructure functions to the data plane, achieving low latency, high throughput, and high scalability. The system also provides users with guided labs for learners and is accessible via NETLAB+ for remote use. Future work includes federation with national-scale infrastructures such as FABRIC to broaden access and support multi-institutional collaboration. Samia Choueiri, Ali Mazloum, Sergio Elizalde, Amith GSPN, Ali AlSabeh, Elie F. Kfoury, Jorge Crichigno |
CCNC | 3 |
| 2026 | Real-Time Encrypted Traffic Classification with P4-DPDK
Amith Gorthi Srinivasa Prabhakara Narasimha, Ali Mazloum, Samia Choueiri, Sergio Elizalde, Elie F. Kfoury, Jorge Crichigno |
ICC | 2 |
| 2025 | Detection and Mitigation of Volumetric DDoS Attacks using Adaptive Rate-Limiting in P4-DPDKabstractDistributed Denial of Service (DDoS) attacks are increasingly targeting network environments. This paper presents a high-performance, adaptive system for detecting and mitigating volumetric DDoS attacks using P4-DPDK. The proposed system operates entirely in the user space, leveraging multicore CPUs and SmartNICs to process traffic at line rate while enabling flexible and efficient control plane operations. DDoS detection is implemented in a linear prediction model that forecasts traffic based on historical observations and dynamically adjusts ratelimiting thresholds. The hyperparameters for the model are tuned using an optimization algorithm. The system is evaluated on the FABRIC testbed and tested using real traffic traces. Experimental results demonstrate robust mitigation against diverse attack types, effective adaptation to real-world traffic, and reduced packet loss under high-throughput conditions approaching 100 Gbps, compared to Suricata-DPDK implementations. Samia Choueiri, Ali Mazloum, Sergio Elizalde, Elie F. Kfoury, Jorge Crichigno |
GLOBECOM | 2 |
| 2025 | Toward Fingerprinting Encrypted C2 Traffic in the Data Planeabstract• Transport Layer Security (TLS) is the dominant protocol that enables users to securely interact with the Internet. • Threat actors are using TLS to bypass traditional cybersecurity defenses like firewalls and intrusion detection systems. • Modern malware attacks are hiding behind TLS secure channels. • Many malware families that infect users receive malicious instructions from the command and control (C2) server. • As the communication between malware and the C2 server is encrypted, it can easily bypass modern security appliances that rely on deep packet inspection (DPI). • In response to this threat, this project aims at utilizing ML to identify encrypted C2 communication. • The project implements a distributed ML model over two hardware accelerators. • The system achieves 99.3% detection accuracy with a microsecond-level processing latency. Ali Mazloum, Elie F. Kfoury, Ali AlSabeh, Jorge Crichigno |
GLOBECOM | 1 |
| 2025 | Real-Time Flow Statistics Collection Using RDMA and P4 Programmable Data PlanesabstractMeasuring network traffic in real time is essential for applications such as traffic profiling, anomaly detection, resource allocation, and network performance improvement. As network speeds and traffic volumes increase, traditional solutions (e.g., NetFlow, sFlow, Zeek) face challenges in processing and summarizing traffic efficiently, often leading to incomplete measurements. This paper introduces a system that summarizes network traffic and provides per-flow measurements in real time by leveraging P4 Programmable Data Planes (PDPs). The system computes per-flow traffic statistics directly in the data plane at line rate. The statistics are then transmitted to a server using the low-latency, high-throughput RDMA over Converged Ethernet (RoCEv2) protocol. On the server, worker threads process the received reports and update a global data structure that maintain the flows. The system was implemented and tested using an Intel Tofino-based PDP and an RDMA-capable SmartNIC (NVIDIA BlueField-2). Experiments on real packet traces show that the system is capable of analyzing traffic at scale without compromising the accuracy of the measurements, outperforming traditional Network Security Monitors (NSMs). Elie F. Kfoury, Ali Mazloum, Ali AlSabeh, Jorge Crichigno |
ICC | 2 |
| 2025 | Domain Name Security Inspection at Line Rate: Tls Sni Extraction in the Data Plane Using P4 and DpdkabstractA widely adopted approach to monitor HTTPS traffic leverages the Server Name Identification (SNI) extension of TLS. Generally, the hostname is transferred in plain text over the SNI field and Deep Packet Inspection (DPI) is used to parse the TLS header and extract the hostname. However, DPI is often performed on general-purpose processors and utilizes the kernel of the operating system, which results in an overhead to the network, especially under high traffic loads. To this end, this paper proposes offloading the identification of SNI hostnames to the data plane using P4 and the Data Plane Development Kit (DPDK). In the proposed system, a P4 Programmable Data Plane (PDP) switch is the first line of defense where most of the TLS traffic is processed. DPDK is the second line of defense which processes all TLS packets that require processing capabilities beyond what the P4 PDP switch provides. To support line rate pattern matching on the hostname, the DPDK application is offloaded to a SmartNIC, leveraging its Regex engine. Experiments on various recent and public datasets from different regions and platforms reveal that the P4 switch is capable of parsing 85%99 % of hostnames. Furthermore, performance analysis shows that the P4 switch and the DPDK application, respectively, inspect a hostname in around 1 microsecond ($\mu \mathrm{s}$) and$7 \mu ~\mathrm{s}$, achieving an order of magnitude improvement over solution running on general-purpose processors. Ali Mazloum, Ali AlSabeh, Elie F. Kfoury, Jorge Crichigno |
ICC | 1 |
| 2025 | Enabling Line-Rate TLS SNI Inspection in P4 Programmable Data PlanesabstractWith the increasing adoption of the HyperText Transfer Protocol Secure (HTTPS), organizations face new challenges in monitoring traffic to defend against attacks and enforce security policies, such as filtering malicious websites. One widely used technique to monitor HTTPS is by scrutinizing the hostname in the Server Name Identification (SNI) extension during the Transport Layer Security (TLS) handshake. Parsing the SNI typically involves Deep Packet Inspection (DPI), often performed on general-purpose processors, which can create bottlenecks and significantly impact network throughput. In response, this paper introduces a novel framework for parsing and identifying SNI hostnames in the data plane at line-rate using P4. Evaluation results on recent publicly available datasets from various regions and platforms demonstrate that our framework can successfully parse 85%-99% of hostnames in P4. Furthermore, performance analysis reveals that the proposed data plane solution can inspect the hostname in approximately 1 microsecond (μ s), representing orders of magnitude improvement over solutions running on Central Processing Units (CPUs). Ali AlSabeh, Ali Mazloum, Elie F. Kfoury, Jorge Crichigno, Hala Strohmier Berry |
NOMS | 2 |
| 2025 | Performance Evaluation of Stateless Firewalling: Host-Based, SmartNIC, and P4 SwitchabstractIn modern data centers, traditional software-based firewalls often struggle to keep up with the growing demands for robust security. One adopted approach to improve the packet processing efficiency is through software acceleration techniques like the Data Plane Development Kit (DPDK), which significantly enhances the performance of software-based firewalls. Another approach is to offload the firewall functionalities to the hardware either using the new generation of Network Interface Cards (SmartNICs) or by using P4 Programmable Data Plane (PDP) switches. SmartNICs integrate dedicated processing units optimized to efficiently handle networking tasks, including security. P4 PDP switches enable custom packet processing in the data plane, allowing security applications to run at line rates within the network. This study compares the performance of stateless firewalls implemented using nftables (host-based), DPDK (host-based), DOCA Flow and OvS hardware (SmartNIC-based), and P4 (PDP-based). It evaluates the achievable throughput and processing latency for the five implementations under different testing scenarios. It also compares the CPU utilization of the host-based implementations. The results demonstrate that while the software acceleration technique significantly enhances host-side performance, SmartNIC-based and PDP-based firewalls provide a superior performance over all software-based implementations. Sergio Elizalde, Ali Mazloum, Samia Choueiri, Elie F. Kfoury, Jorge Crichigno |
NOMS | 2 |
| 2025 | Improving flow fairness in non-programmable networks using P4-programmable Data Planes
Elie F. Kfoury, Ali Mazloum, Jorge Crichigno |
Comput. Networks | 3 |
| 2025 | Security applications in P4: Implementation and lessons learned
Ali Mazloum, Ali AlSabeh, Elie F. Kfoury, Jorge Crichigno |
Comput. Networks | 1 |
| 2025 | A survey on security applications with SmartNICs: Taxonomy, implementations, challenges, and future trendsabstractOver the last decade, network applications have grown exponentially, demanding high-speed interconnects. Unfortunately, chip manufacturers are approaching the upper limits of silicon-based computing with slow improvements in computational performance and energy efficiency. This trend has forced the industry to shift paradigms, moving from monolithic architectures to heterogeneous, domain-specific designs. Moreover, the ever-evolving threats compromise digital services and demand more scalable and flexible solutions to ensure service continuity in production networks. Smart Network Interface Cards (SmartNICs) are a product of this new paradigm, integrating domain-specific engines and general-purpose cores to offload various network infrastructure tasks, including those related to security. This paper provides a comprehensive overview of SmartNICs, with a particular focus on their role in strengthening network defenses. It introduces SmartNIC technology and presents a taxonomy of security applications offloaded to SmartNICs, categorized into Intrusion Detection and Prevention Systems (IDS/IPS), defenses against volumetric attacks, and data confidentiality mechanisms. Additionally, the paper explores vulnerabilities associated with adopting SmartNICs in the cloud, examining the threat model and reviewing proposed remediations in the literature. Finally, it discusses challenges and future trends in SmartNIC security applications, highlighting current initiatives and open research areas. Sergio Elizalde, Ali AlSabeh, Ali Mazloum, Samia Choueiri, Elie F. Kfoury, Jorge Crichigno |
J. Netw. Comput. Appl. | 3 |
| 2025 | Enhancing visibility on a science DMZ with P4-perfSONARabstractThe Science Demilitarized Zone (Science DMZ) is a specialized network designed to facilitate the transfer of large-scale scientific data. One of the key elements of the Science DMZ is perfSONAR, an active performance measurement device that monitors end-to-end paths over multiple domains. Although versatile, perfSONAR faces limitations such as restricted visibility of events and coarse-grained measurements. This paper proposes a scheme that integrates P4 programmable data plane (PDP) switches with perfSONAR. P4 PDP switches are passively installed and operate on real-time traffic copies, providing flexibility to collect fine-grained custom measurements and report events in the data plane. This integration enables perfSONAR to collect per-flow granular statistics of actual traffic, identify a broader range of networking issues, and enhance visibility while reducing the overhead of active tests. Additionally, the scheme uses an adaptive linear prediction (LP) model that dynamically adjusts the rate of reports sent from the P4 PDP switch to perfSONAR, minimizing the storage and processing needed for the latter. Experimental results show that the system reduces the number of reports by a factor of five while maintaining a small and configurable relative mean error (RME). Ali Mazloum, Elie F. Kfoury, Ali AlSabeh, Jorge Crichigno |
J. Netw. Comput. Appl. | 1 |
| 2024 | Scalable Heavy Hitter Detection: A DPDK-based Software Approach with P4 IntegrationabstractIdentifying heavy hitters is vital for applications like Denial of Service (DoS) detection and traffic engineering. Current solutions fall into hardware or software categories. Hardware solutions (e.g., P4 programmable data plane switches) offer high performance but require adding hardware, which may not be ideal for virtualized environments (e.g., cloud). Software solutions are cost-effective and flexible but suffer from performance issues due to the packet processing overhead in the Operating System (OS) kernel. This paper presents a scalable heavy hitter detection algorithm in the software, bypassing the kernel using the Data Plane Development Kit (DPDK). The Count-min Sketch (CMS) data structure is used to estimate the frequency of packets per flow. The system is implemented in P4 and deployed on the P4-DPDK target running on CPU cores. The experiments analyzed the impact of various parameters such as the packet size distribution, the number of CPU cores, and the number of hash functions, on the performance and the accuracy of the detection. The system's performance is further evaluated through comparison with another DPDK-based approach for heavy hitter detection. The results show accurate identification of heavy hitters and improved performance, even at a high traffic rate approaching 100Gbps. Samia Choueiri, Ali Mazloum, Elie F. Kfoury, Jorge Crichigno |
GLOBECOM | 2 |
| 2024 | Enabling Fairness in Flow Allocation using P4-programmable Data PlanesabstractThis paper presents a system designed to enhance Transmission Control Protocol (TCP) fairness by rebalancing router queues and reducing the impact of Round-Trip Time (RTT) unfairness. The proposed system utilizes a P4-programmable Data Plane (PDP) to process a copy of the traffic from the link between two non-programmable routers. The PDP measures the throughput and calculates the RTT of competing flows in the data plane. Then, the control plane generates the rules to be implemented in a non-programmable router that will allocate flows in different queues to isolate their dynamics. The limits for each queue result from the Jenks optimization algorithm. This approach ensures that flows with similar characteristics share the same queue.The results demonstrate that the system efficiently identifies and segregates flows into multiple queues, thereby enforcing fairness among competing flows and enhancing the Flow Completion Time (FCT). The experiments were executed on traffic provided by Measurement and Analysis on the WIDE Internet (MAWI). The system effectively rebalances queues and dynamically redistributes underutilized bandwidth independently of the design principles of the transport protocol. Furthermore, the results show that the system effectively mitigates the effects of bufferbloat and successfully detects and reduces the impact of protocol abuses at the network layer. Elie F. Kfoury, Ali Mazloum, Jorge Crichigno |
GLOBECOM | 3 |
| 2024 | perfSONAR: Enhancing Data Collection through Adaptive SamplingabstractperfSONAR IS a tool used to monitor and troubleshoot problems in high-speed networks such as Science Demilitarized Zones (DMZs). It is essential to validate that data transfers are performing as expected. However, perfSONAR suffers from the trade-off between the measurement accuracy and the overhead induced by its active testsThis paper presents a scheme that offloads the traffic monitoring to a programmable data plane (PDP) switch. The scheme integrates a PDP switch with perfSONAR, where the switch continuously collects network measurements (e.g., latency, throughput, packet loss rate) and periodically reports the measurements to the perfSONAR archiver. This integration significantly enhances the granularity, visibility, and troubleshooting capabilities of perfSONAR. Additionally, the scheme automates the reporting period according to the variability of the monitored measurements, which eliminates the need of human intervention observed in today’s networks. In contrast to traditional schemes that report all measurements, the proposed approach uses the Linear Prediction (LP) method to only report the samples that reveal a variation on the measurements. Experimental results show that the system reduces the number of reports by five times under stable network conditions and sustains a relative mean error (RME) below 0.06. Ali Mazloum, Ali AlSabeh, Elie F. Kfoury, Jorge Crichigno |
NOMS | 1 |
| 2023 | A Survey on Rerouting Techniques with P4 Programmable Data Plane Switches
Ali Mazloum, Elie F. Kfoury, Jorge Crichigno |
Comput. Networks | 1 |