EDBT 2026 Demo / reviewers in the wild / expert
Lisandro Z. Granville
dblp:52/4475 · also Lisandro Zambenedetti Granville
· DBLP profile ↗
189ranked-venue papers
3as first author
33since 2021 · last 2026
0000-0001-8956-8660ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 116 · 1 first-author · 19 since 2021Software engineering, systems software and programming languages · 9 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 7 · 2 first-author · 1 since 2021Security and privacy · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Knowing millions of students too well: High-entropy scores as deterministic quasi-identifiers for re-identification and data leakage in the Brazilian high school examabstractPublic microdata sit at the intersection of transparency mandates, data-protection law, and the technical realities of cybersecurity, while regulatory and judicial decisions often rely on threat models that underestimate modern re-identification capabilities. We study this tension in Brazil’s National High School Exam (ENEM), where a court first mandated utility-preserving anonymization, then recognized substantial compliance through a separated architecture that forgoes core analytical utility. We show that precise candidate-level performance scores are high-entropy quasi-identifiers that adversaries can use to link identities across complementary public releases. Across 57.7 million records from fifteen editions (2009–2023), edition-level singleton rates average 99.9985%. On commodity hardware, an exact join of files downloadable from official portals uniquely matches 26.59 million of 26.61 million candidate-year records in the federal admission system (99.91%). Cross-year canonicalization estimates 14.69 million distinct individuals with linked records. These links associate civil identities with socioeconomic data such as family income and household assets, and a smaller channel conditionally exposes accessibility-related proxies for disability. Moreover, no tested score generalization removed record individualization without degrading ranking and group-gap estimates. Multidimensional performance measures should be treated as quasi-identifiers, not just analytical attributes. Henrique Lindemann, Eder J. Scheid, Lisandro Z. Granville, Muriel Figueredo Franco |
Comput. Secur. | 3 |
| 2025 | Employing PDDL Plan to Recommend Security Controls Against Cyberattacks
Afaq Inayat, Matheus Saueressig, Muriel Figueredo Franco, Eder J. Scheid, Lisandro Z. Granville |
AINA (4) | 5 |
| 2025 | Assessing SSL/TLS Certificate Centralization: Implications for Digital SovereigntyabstractSSL/TLS is a fundamental technology in the network protocol stack that enables encrypted data transmission and authentication of web domains. However, the current model relies on a small number of Certificate Authorities (CAs) to provide and validate certificates, thus creating a highly centralized ecosystem. In this paper, we analyze the degree of centralization of certificate provisioning from CAs in two major political groups: Brazil, Russia, India, China, and South Africa (BRICS) and the European Union (EU). We have found that over 75% of certificates for both BRICS and EU domains originate from CAs based in the United States, indicating possible risks to their digital sovereignty due to the high level of external dependency. This indicates the need for nations within those groups to research alternatives to reduce the high level of dependency on foreign CAs and increase their digital autonomy. Andrei C. Azevedo, Eder J. Scheid, Muriel Figueredo Franco, Lisandro Z. Granville |
GLOBECOM | 4 |
| 2025 | The Role of Legacy Mobile Networks in Infrastructure Resilience: Evidence from the Southern Brazil FloodabstractThis paper investigates the resilience of mobile communication networks during the extreme flooding that affected Rio Grande do Sul, Brazil, in May 2024. Based on regulatory data and technical insights from operators, the study identifies the leading causes of network disruptions, primarily related to flooding and prolonged power outages. The results reveal the significant vulnerability of modern networks (4G/5G) during the event and the essential role played by legacy technologies (2G/3G) in sustaining basic connectivity under adverse conditions. The findings underscore the necessity of disaster-aware infrastructure planning, taking into account the ongoing significance of legacy systems, diversified power supply strategies, and resilient network designs to enhance service continuity during future crises. Daniel Meyer, Lisandro Z. Granville, Leandro Marcio Bertholdo |
GLOBECOM | 2 |
| 2025 | Dhana: An Economic-Oriented Approach for Traffic Management using Software-Defined NetworkingabstractSoftware-Defined Networking (SDN) offers a flexible, programmable approach to network management by decoupling the control and data planes. While SDN technical advantages, such as improved network performance and security, are well-documented, its economic implications remain underexplored, particularly in prioritizing services based on business value. This paper introduces Dhana, a novel SDNbased traffic management approach that integrates economic considerations. Dhana dynamically prioritizes high-value services by analyzing network components using metrics like downtime costs and service-level agreement (SLA) compliance. The goal is to minimize economic loss during network congestion or failures, even if technical global optimization is partially sacrificed. Tests show that Dhana can take many paths according to its needs and has not significant overhead. Matheus Saueressig, Muriel Figueredo Franco, Eder J. Scheid, João Davi M. Nunes, Jéferson Campos Nobre, Lisandro Z. Granville |
ISCC | 6 |
| 2025 | Advancing Open RAN Deployment and Management on the OpenRAN@Brasil TestbedabstractThe OpenRAN@Brasil project has been advancing the evolution of Open RAN technology by enabling private SG networks in various fields, such as education, government, and industry. With this, there has been progress in techniques and de-velopments to improve the adoption of the technology and spread the use of Open RAN. This demonstration addresses the chal-lenges of fragmentation and complexity inherent in transitioning to open and disaggregated networks, leveraging an intent-based strategy to simplify the deployment and management of network services. The results demonstrate the feasibility of the solution by successfully provisioning 5G core network functions (Open5GS) and edge functions (SRS- RAN) in different Kubernetes clusters, allowing UE registration and access to Internet services. The integration of technologies such as OpenSGS, SRS-RAN, and Nephio highlights the potential for automation, scalability, and operational efficiency in distributed environments. Lucas B. De Oliveira, Murilo C. Da Silva, Daniel De A. L. Marques, Gustavo H. de Araújo, Marcos F. Schwarz, Fernando N. N. Farias, Lucas Bondan, Lisandro Z. Granville, Antônio J. G. Abelém |
NOMS | 8 |
| 2025 | Establishing Trust for Using Natural Language for Intent-Based NetworkingabstractTodays enterprise networks wrestle with accommodating an ever-growing number of devices of different types, supporting increasingly demanding applications and ever more complex services, and protecting their users from sophisticated and disrupting cyber threats. In response, a proposed architectural approach for improving network management, referred to as Intent-Based Networking (IBN), has attracted significant attention. It is built on the premise that network operators specify network policies in natural language and the network correctly translates these spoken intents (e.g., policies) into proper device-specific configurations that are then deployed across the network to reliably act on the operators expressed intents. Unfortunately, IBN has not yet fully delivered on its promise of automated, fast, and reliable policy deployment, mainly due to the significant challenges that the reliance on methods from Natural Language Processing (NLP) or more recent techniques from Machine Learning (ML) and Artificial Intelligence (AI) poses for unambiguously and accurately translating the myriad of intents that operators can express in natural language into “trustworthy” device configurations. This paper uses LUMI, a recently designed end-to-end prototype of a system that allows operators “to manage their network by talking to the network”, as an illustrative case study. In particular, we use it to elaborate on the different functionalities such systems should have to realize IBNs vision of automating the fast deployment of policies. At the same time, we leverage LUMI to highlight the extra efforts that are required to ensure that the deployed policies can be entrusted to accurately express and execute the operators original intents. Arthur Selle Jacobs, Ricardo J. Pfitscher, Rafael Hengen Ribeiro, Lisandro Z. Granville, Ronaldo A. Ferreira, Walter Willinger, Sanjay G. Rao |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2024 | Container-Level Auditing in Container Orchestrators with eBPF
Fabio Junior Bertinatto, Daniel Arioza, Jéferson Campos Nobre, Lisandro Z. Granville |
AINA (4) | 4 |
| 2024 | FEVER: Intelligent Behavioral Fingerprinting for Anomaly Detection in P4-Based Programmable Networks
Matheus Saueressig, Muriel Figueredo Franco, Eder J. Scheid, Alberto Huertas Celdrán, Gérôme Bovet, Burkhard Stiller, Lisandro Z. Granville |
AINA (3) | 7 |
| 2024 | PerfResolv: A Geo-Distributed Approach for Performance Analysis of Public DNS Resolvers Based on Domain Popularity
Marcelo Almeida Silva, Muriel Figueredo Franco, Eder J. Scheid, Luciano Zembruzki, Lisandro Z. Granville |
AINA (2) | 5 |
| 2024 | eBPF-Based Approach to Tracing System Calls and Predicting Privilege Escalation AttacksabstractThe extensive adoption of containerized applications significantly raises the criticality of managing potential vulnerabilities, including privilege escalation within these environments. While the Bag of System Calls (BoSC) is a common technique to detect such attacks, tracing system calls in containerized applications is often inefficient for real-world scenarios. This paper proposes an eBPF-based solution to trace system calls in containerized applications and apply the BoSC technique to identify privilege escalation attempts within containers. We analyzed the cost of different system call hooking methods and found that raw tracepoint programs have the least overhead. Furthermore, we observed a slight increase in overhead when tracing all executed operations within a containerized application. Finally, we confirmed that our solution successfully identifies user efforts to escape containers, concluding that eBPF can be a powerful tool for containerized system security. Fabio Junior Bertinatto, Daniel Arioza, Jéferson Campos Nobre, Lisandro Z. Granville |
GLOBECOM | 4 |
| 2024 | Securing Blockchain Wallet Files Using eBPFabstractBlockchain (BC) and Distributed Ledger Technologies (DLT) have been widely used in various applications in different areas, from finance to healthcare. For such applications to participate and interact with BCs and DLTs, they must rely on specific software, called nodes, when providing tools and functions for BC synchronization, and called wallets when providing tools for address generation, transaction creation, and fund management. In this sense, wallets are crucial components to be secured within BC-based applications, as they hold sensitive files (e.g., keystore files storing private keys used to generate addresses and sign transactions), which can be a target for attackers. Thus, we propose Scylla, a solution to protect wallet-related files using the extended Berkeley Filter (eBPF) that continuously monitors, at the kernel level, the system calls of processes and actively terminates unauthorized and malicious processes when accessing such files. To demonstrate the feasibility and performance of Scylla, a prototype was implemented and evaluated in terms of access time overhead and resource use. Such experiments show that Scylla is feasible and does not add significant overhead, compared to a native Linux tool dedicated to monitoring files (i.e., inotify) while being able to terminate processes before they can read protected files. Jeison C. Caroly, Eder J. Scheid, Muriel Figueredo Franco, Lisandro Z. Granville |
GLOBECOM | 4 |
| 2024 | Eeny, Meeny, Miny, Moe: Analyzing and Comparing the Selection of DNS Lookup ToolsabstractThe performance of Domain Name System (DNS) resolvers is crucial, as most of the communication on the Internet starts with a DNS lookup to resolve a domain of an IP address to reach the desired content. In this sense, academia has been devoted to measuring and analyzing the performance of DNS resolvers using different tools, either tailored for each work or generic. However, such tools might present different results due to their implementation and affect the measurements. Therefore, this paper reviews the literature on DNS performance research to gather the tools and DNS resolvers most used and, based on this, provides an analysis and comparison of the different DNS lookup tools employed in the literature and discusses the impact of tool selection on measurement results. Research showed that tool selection has an impact on results but not on the lookup success rate. Jose C. C. Pinto, Eder J. Scheid, Muriel Figueredo Franco, Lisandro Z. Granville |
ISCC | 4 |
| 2024 | Traffic Centralization and Digital Sovereignty: An Analysis Under the Lens of DNS ServersabstractThe Domain Name System (DNS) service is one of the pillars of the Internet. This service allows users to access websites on the Internet through easy-to-remember domain names rather than complex numeric IP addresses. However, the concentration of DNS service providers on the Internet affects user security, privacy, and network accessibility as the reliance on a small number of large DNS providers can lead to (a) risks of data breaches and disruption of service in the event of failures and (b) concerns about the digital sovereignty of countries regarding DNS hosting. This work approaches the issue of DNS concentration on the Internet by presenting a solution to measure DNS hosting centralization and digital sovereignty in different countries, such as Brazil, India, China, Russia, and South Africa. With the data obtained through these measurements, relevant questions are answered, such as which are the top-10 DNS providers, if there is DNS centralization, and how dependent countries are on such providers to manage domains using their country code Top-Level Domains (ccTLD). Demétrio Francisco Freitas Boeira, Eder J. Scheid, Muriel Figueredo Franco, Luciano Zembruzki, Lisandro Z. Granville |
NOMS | 5 |
| 2023 | Examining the Centralization of Email Industry: A Landscape Analysis for IPv4 and IPv6abstractCentralization of key Internet services, including email, can result in privacy and security concerns and increase the number of single points of failure. This paper measures and analyzes a large-scale dataset of email providers gathered from MX records of top-level domains. The findings reveal the concentration of email infrastructure providers for each TLD and identify the most significant providers in the market. The paper also demonstrates that the IPv6 adoption increased the centralization of email servers. The research contributes to the state-of-the-art by thoroughly examining email infrastructure centralization and identifying potential areas for future research. Luciano Zembruzki, Arthur Selle Jacobs, Lisandro Z. Granville, Ricardo J. Pfitscher |
ISCC | 3 |
| 2023 | CyberTEA: a Technical and Economic Approach for Cybersecurity Planning and InvestmentabstractIt is essential to look at cybersecurity not only as a technical problem but also from economic, societal, and legal perspectives. Companies need to pay more attention to planning and investments in cybersecurity due to different factors, such as budget constraints and complexities involved in the planning and decision-making processes. Also, companies wrongly do not see themselves as the target of a potential cyberattack. Therefore, there is still a need for approaches that support companies, especially Small and Medium-sized Enterprises (SME), during the cybersecurity planning and investment decisions. This PhD thesis addressed cybersecurity planning and investment gaps by proposing the CyberTEA approach. This approach is composed of a five-phase methodology, a framework, and a set of solutions for cybersecurity planning and investment, considering the technical requirements of cybersecurity and its economic dimensions, such as the potential economic impacts of cyberattacks and the cost-benefit of protections available on the market to protect against specific threats. The evaluations and scientific advances of CyberTEA approach was proven valid to support SMEs while also showing the benefits and opportunities for cybersecurity economic approaches. Muriel Figueredo Franco, Lisandro Z. Granville, Burkhard Stiller |
NOMS | 2 |
| 2023 | Enabling Self-Driving Networks with Machine LearningabstractThis work aims to enable self-driving networks by tackling the lack of trust that network operators have in Machine Learning (ML) models. We assess and scrutinize the decision-making process of ML-based classifiers used to compose a self-driving network. First, we investigate and evaluate the accuracy and credibility of classifications made by ML models used to process high-level management intents. We propose a novel conversational interface (LUMI) that allows operators to use natural language to describe how the network should behave. Second, we analyze and assess the accuracy and credibility of existing ML models’ for network security and performance. We also uncover the need to reinvent how researchers apply ML to networking problems, so we propose a new ML pipeline that introduces steps to scrutinize models using techniques from the emerging field of eXplainable Artificial Intelligence (XAI). Finally, we investigate whether there is a viable method to improve the trust of operators in the decisions made by ML models that enable self-driving networks. Our investigation led us to propose a new XAI method to extract explanations from any given black-box ML model in the form of decision trees while maintaining a manageable size, which we called TRUSTEE. Our results show that ML models widely applied to solve networking problems have not been put under proper scrutiny and can easily break when put under real-world traffic. Such models, therefore, need to be corrected to fulfill their given tasks properly. Arthur Selle Jacobs, Ronaldo A. Ferreira, Lisandro Z. Granville |
NOMS | 3 |
| 2022 | AI/ML for Network Security: The Emperor has no ClothesabstractSeveral recent research efforts have proposed Machine Learning (ML)-based solutions that can detect complex patterns in network traffic for a wide range of network security problems. However, without understanding how these black-box models are making their decisions, network operators are reluctant to trust and deploy them in their production settings. One key reason for this reluctance is that these models are prone to the problem of underspecification, defined here as the failure to specify a model in adequate detail. Not unique to the network security domain, this problem manifests itself in ML models that exhibit unexpectedly poor behavior when deployed in real-world settings and has prompted growing interest in developing interpretable ML solutions (e.g., decision trees) for "explaining'' to humans how a given black-box model makes its decisions. However, synthesizing such explainable models that capture a given black-box model's decisions with high fidelity while also being practical (i.e., small enough in size for humans to comprehend) is challenging. Arthur Selle Jacobs, Roman Beltiukov, Walter Willinger, Ronaldo A. Ferreira, Arpit Gupta, Lisandro Z. Granville |
CCS | 6 |
| 2022 | On the Asymmetry of Internet eXchange Points -Why Should IXPs and CDNs Care?abstractInternet eXchange Points (IXPs) provide an infrastructure where content providers and consumers can freely exchange network traffic. The main incentive for connecting to an IXP is to decrease costs and improve the user experience by having content closer to consumers. Despite these benefits, several small Content Delivery Networks (CDNs) avoid exchanging traffic on IXPs due to the poor routing quality via IXP paths. In this paper, we investigate how traffic asymmetry affects the quality of paths. IXP asymmetry occurs when traffic is sent (or received) via a direct IXP peering but received (or sent) on an alternative path outside the IXP. We employ a new method to quantify a symmetry rate for an IXP, which we evaluate on five IXPs. Our method covers three times more ASes than alternatives, such as using RIPE ATLAS. Our results show that IXPs have 15% asymmetric paths at a distance of one AS hop, i.e., when sending traffic to a given peer on the IXP, 15% of this traffic will be responded via a transit AS that does not use the IXP path. We also identify deaf neighbors, i.e., ASes that never return traffic to the IXP. We identify egress-only paths as a major cause of asymmetries and show that this occurs only for a small number of ASes. We also quantify the impact of traffic asymmetry at IXPs in terms of latency and show that traditional traffic engineering on IXP prefixes can actually make route quality worse. Leandro Marcio Bertholdo, Sandro L. A. Ferreira, João M. Ceron, Lisandro Z. Granville, Ralph Holz, Roland van Rijswijk-Deij |
CNSM | 4 |
| 2022 | IEEE GLOBECOM 2022 General Chair Welcome MessageabstractOn behalf of the Organizing Committee, we have been delighted to welcome you to the IEEE Global Telecommunications Conference (GLOBECOM 2022). The conference was held in Rio de Janeiro, Brazil from 4 to 8 December 2022. IEEE GLOBECOM is one of the two flagship conferences of the IEEE Communications Society (IEEE ComSoc). It is a premium event that brings together the best researchers and professionals from academic, industry and government to exchange novel ideas that will shape future generations of communication technologies. IEEE Globecom 2022 featured striking advances in communications research and industry development, which will certainly lead to new systems and networks and bring humanity to a new World, still unimaginable. The theme of Globecom 2022 “Accelerating the Digital Transformation through Smart Communications” reflects the fundamental role of intelligent communications in enabling dynamically adaptive societal systems. Nelson L. S. da Fonseca, José Roberto B. da Marca, Stefano Bregni, Lisandro Z. Granville |
GLOBECOM | 4 |
| 2022 | DWT in P4: Periodicity Detection in the Data PlaneabstractThis paper presents a P4 implementation of the (1-D) Discrete Wavelet Transform (DWT) method. As a mathe-matical tool for analyzing signals such as packet-level traces, the DWT divides a given signal into different frequency components and analyzes each component with a resolution matched to its scale. We develop an efficient online algorithm that circumvents various limitations of existing P4-programmable data plane devices and performs the DWT decomposition entirely in the data plane. Our evaluation of a hardware implementation (i.e., Netronome NFP-4000 SmartNIC) of the algorithm shows that it results in only minimal throughput overhead (less than 1% for average-sized packets) and operates within constraints imposed by the limited available data plane resources. As an application, we use our lightweight P4 implementation of the DWT and describe a novel threshold-based approach for detecting periodic behavior in a signal in real-time, at line rate in the data plane (40 Gbps). We illustrate our approach with different examples of synthetic and real-world packet-level traffic traces that exhibit periodic patterns of either benign or malicious origins. Briggette Olenka Roman Huaytalla, Arthur Selle Jacobs, Marcus V. B. Silva, Fabrício B. Carvalho, Ronaldo A. Ferreira, Walter Willinger, Lisandro Z. Granville |
GLOBECOM | 7 |
| 2022 | HashCuckoo: Predicting Elephant Flows using Meta-Heuristics in Programmable Data PlanesabstractSoftware-Defined Networking and programmable networks have lead to the development of novel solutions to identify and even predict critical network flows (i.e., flows that can more heavily impact network resources), so they can be properly handled. However, existing approaches found in the state-of-the-art typically incur delays because of the switch-controller communication or depend on thresholds being exceeded to identify flows of interest (e.g., elephant flows). In this paper, we present HashCuckoo, an approach to predict elephant flows that includes: (i) a hash-based mechanism to start the prediction process at line rate in P4 switches, based on the Cuckoo Search meta-heuristic; and (ii) a local prediction mechanism to infer the new flows' traffic behavior, confirming the classification, and handling elephant flows on-line before exceeding traditionally considered thresholds. We evaluate the trade-offs between HashCuckoo and state-of-the-art solutions, and show that HashCuckoo reduces elephant flow identification delay by 57%, from 102 ms to 43 ms, being the first solution to combine meta-heuristic optimization and prediction that can operate at line rate in programmable data planes. Marcus Vinicius Brito da Silva, Alberto E. Schaeffer Filho, Lisandro Z. Granville |
GLOBECOM | 3 |
| 2022 | On the Consolidation of the Internet Domain Name SystemabstractSeveral parts of society have expressed rising alarm about the Internet's consolidation in recent years. One of the critical concerns raised by this trend toward consolidation of infrastructure, traffic, users, and services is the concentration of many essential Internet resources among a small number of providers. Some consequences of such consolidation (single points of failure) were exposed in 2016 and 2019 in large-scale Distributed Denial of Service (DDoS) attacks on two DNS providers. In this paper, we study the Domain Name System (DNS) industry's consolidation in light of multiple country-code Top-Level Domains (ccTLDs) and generic top-level domains (gTLDs) by resolving and evaluating the authoritative name-servers (NS) for all domains in each TLD during five years. We show that, the Top 5 DNS providers account for more than 20% of all domains and, more shockingly, the Top 100 providers account for about 80% of the entire examined IPv4 domain namespace. We also reveal that domains in certain TLDs are highly concentrated in the hands of a few providers. For example, Estonia's (.ee) Top 5 providers will hold around 78% of the total TLD namespace in 2021. Additionally, we examine the domain concentration per TLD in terms of provider location origin. We notice a strong presence of local companies in Europe's top-level domains, emphasizing the Russian Federation. Luciano Zembruzki, Arthur Selle Jacobs, Lisandro Z. Granville |
GLOBECOM | 3 |
| 2022 | Hosting Industry Centralization and ConsolidationabstractThere have been growing concerns about the concentration and centralization of Internet infrastructure. In this work, we scrutinize the hosting industry on the Internet by using active measurements, covering 19 Top-Level Domains (TLDs). We show how the market is heavily concentrated: 1/3 of the domains are hosted by only 5 hosting providers, all US-based companies. For the country-code TLDs (ccTLDs), however, hosting is primarily done by local, national hosting providers and not by the large American cloud and content providers. We show how shared languages (and borders) shape the hosting market — German hosting companies have a notable presence in Austrian and Swiss markets, given they all share German as official language. While hosting concentration has been relatively high and stable over the past four years, we see that American hosting companies have been continuously increasing their presence in the market related to high traffic, popular domains within ccTLDs — except for Russia, notably. Luciano Zembruzki, Raffaele Sommese, Lisandro Z. Granville, Arthur Selle Jacobs, Mattijs Jonker, Giovane Cesar Moreira Moura |
NOMS | 3 |
| 2022 | JurisNN: Judging traffic differentiations as network neutrality violations according to the regulation
Marcio Barbosa de Carvalho, Lisandro Z. Granville |
Comput. Networks | 2 |
| 2022 | A deterministic approach for extracting network security intentsabstractIntents brought significant improvements in network management by the use of intent-level languages. Despite these improvements, intents are not yet fully integrated and deployed in most large-scale networks. As a result, network operators may still experience problems when deploying new intents, for instance, learning a vendor-specific language to understand previously deployed configurations of a network device. Additionally, traditional configurations are distributed across multiple devices, each configured using low-level, vendor-specific languages. As a result, inferring intents from these low-level configurations is a time-consuming process. Furthermore, current solutions for deriving high-level representations from bottom-up configuration analysis do not provide results as intents or have a very limited scope, missing essential details that enhance the representation. In the solution to these shortcomings, a deterministic bottom-up approach was developed to extract intents from network configuration files, which translates them into a high-level intent-defined language. By parsing security configurations from various network devices and translating them into an extended version of the Nile (Jacobs et al. 2018) language, an intent-defined language, the prototype demonstrates the concept of this approach. While three case studies illustrate the effectiveness of the approach proposed in real-world scenarios, additional evaluations exploit dumps of real-world firewall and Network Address Translator (NAT) configurations consisting of rules from different servers and institutions. These evaluations demonstrate that the proposed solution can represent configurations at an intent-level language, maintaining high accuracy while representing key details of low-level configurations. Rafael Hengen Ribeiro, Arthur Selle Jacobs, Luciano Zembruzki, Ricardo Parizotto, Eder J. Scheid, Alberto E. Schaeffer Filho, Lisandro Z. Granville, Burkhard Stiller |
Comput. Networks | 7 |
| 2021 | Using Quadratic Discriminant Analysis by Intrusion Detection Systems for Port Scan and Slowloris Attack Classification
Vinícius M. Deolindo, Bruno Lopes Dalmazo, Marcus Vinicius Brito da Silva, Luiz Ricardo Bertoldi de Oliveira, Allan de B. Silva, Lisandro Z. Granville, Luciano Paschoal Gaspary, Jéferson Campos Nobre |
ICCSA (3) | 6 |
| 2021 | TANGLED: A Cooperative Anycast Testbed
Leandro Marcio Bertholdo, João M. Ceron, Wouter B. de Vries, Ricardo de Oliveira Schmidt, Lisandro Z. Granville, Roland van Rijswijk-Deij, Aiko Pras |
IM | 5 |
| 2021 | Delay-aware Slicing and MAC Management using MCDA in IEEE 802.11 SD-RANs
Pedro Heleno Isolani, Daniel J. Kulenkamp, Johann Marquez-Barja, Lisandro Z. Granville, Steven Latré, Violet R. Syrotiuk |
IM | 4 |
| 2021 | On the Transition of Legacy Networks to SDN - An Analysis on the Impact of Deployment Time, Number, and Location of Controllers
Diogo Ferreira Thé Pontes, Marcos F. Caetano, Geraldo P. R. Filho, Lisandro Z. Granville, Marcelo Antonio Marotta |
IM | 4 |
| 2021 | SecGrid: a Visual System for the Analysis and ML-based Classification of Cyberattack TrafficabstractDue to the increasing number of cyberattacks and respective predictions for the upcoming years with even larger numbers of occurrences, companies are becoming aware not only that the digitization of their businesses is essential, but also that the adoption of efficient cybersecurity strategies is crucial. Therefore, approaches for a better understanding and analysis of cybersecurity are essential.Thus, SecGrid, a Machine Learning (ML) empowered platform for analyzing, classification, and visualization of cyberattacks is introduced. SecGrid implements an extensible set of miners to analyze information from network traces to provide insightful visualizations of malicious traffic given and to classify automatically different types of cyberattacks by using supervised ML. Experiments conducted show high overall usability, scalability in terms of the capacity of the platform to extract information from large files, and high performance and accuracy during the classification of cyberattacks. Muriel Figueredo Franco, Jan von der Assen, Luc Boillat, Christian Killer, Bruno Rodrigues 0001, Eder J. Scheid, Lisandro Z. Granville, Burkhard Stiller |
LCN | 7 |
| 2021 | Poster: DDoSGrid: a Platform for the Post-mortem Analysis and Visualization of DDoS AttacksabstractDistributed Denial-of-Service (DDoS) attacks remain one of the top reasons for business disruption and financial losses. Although mitigation solutions are available on the market, there is still a need for approaches that help network operators understand attack characteristics and behaviors, resulting in better planning of companies' cybersecurity strategies. This paper introduces DDoSGrid, a platform for the analysis and visualization of DDoS attacks. DDoSGrid implements an extensible set of miners to extract, process, and analyze information from network traces (i.e., PCAP files) to provide insightful visualizations for a better understanding and in-depth analysis of DDoS attacks in different scenarios. A case study was performed using an HTTP flood attack scenario to evaluate the feasibility of the approach. DDoSGrid enables real-world DDoS scenarios' analysis, providing an intuitive interface integrated with extensible insightful visualizations and data miners. Muriel Figueredo Franco, Jan von der Assen, Luc Boillat, Christian Killer, Bruno Rodrigues 0001, Eder J. Scheid, Lisandro Z. Granville, Burkhard Stiller |
Networking | 7 |
| 2021 | Hey, Lumi! Using Natural Language for Intent-Based Network Management
Arthur Selle Jacobs, Ricardo J. Pfitscher, Rafael Hengen Ribeiro, Ronaldo A. Ferreira, Lisandro Z. Granville, Walter Willinger, Sanjay G. Rao |
USENIX ATC | 5 |
| 2020 | Micro-service Based Network Management for Distributed Applications
Rafael de Jesus Martins, Rodolfo B. Hecht, Ederson Ribas Machado, Jéferson Campos Nobre, Juliano Araújo Wickboldt, Lisandro Z. Granville |
AINA | 6 |
| 2020 | A Bottom-Up Approach for Extracting Network Intents
Rafael Hengen Ribeiro, Arthur Selle Jacobs, Ricardo Parizotto, Luciano Zembruzki, Alberto E. Schaeffer Filho, Lisandro Z. Granville |
AINA | 6 |
| 2020 | Sample Selection Search to Predict Elephant Flows in IXP Programmable Networks
Marcus Vinicius Brito da Silva, André Augusto Pacheco de Carvalho, Arthur Selle Jacobs, Ricardo J. Pfitscher, Lisandro Z. Granville |
AINA | 5 |
| 2020 | dnstracker: Measuring Centralization of DNS Infrastructure in the Wild
Luciano Zembruzki, Arthur Selle Jacobs, Gustavo Spier Landtreter, Lisandro Z. Granville, Giovane Cesar Moreira Moura |
AINA | 4 |
| 2020 | BGP Anycast Tuner: Intuitive Route Management for Anycast ServicesabstractIP anycast has become a vital technology for DNS and CDN operators alike. Yet, while big operators have their tools to monitor and configure anycast routing, most of anycast networks are still configured manually. In this paper, we introduce a new approach to anycast management. Our solution is based on active measurements combined with traffic engineering. We propose the concept of a "BGP Cookbook" that allows operators to forecast the effects of routing policy changes over their services. We also introduce a web-based interface, called "BGP Anycast Tuner", that allows operators to gain insight into their service's performance and provides easy management through automation. We evaluate our approach by implementing a prototype running in a testbed composed of 12 anycast sites covering 5 continents. We demonstrate our tool in two different use cases: discovering and fixing a sub-optimal anycast routing issue, and shifting traffic between continents, which is useful during service disruptions. Leandro Marcio Bertholdo, João M. Ceron, Lisandro Z. Granville, Giovane Cesar Moreira Moura, Cristian Hesselman, Roland van Rijswijk-Deij |
CNSM | 3 |
| 2020 | SecBot: a Business-Driven Conversational Agent for Cybersecurity Planning and ManagementabstractBusinesses were moving during the past decades to-ward full digital models, which made companies face new threats and cyberattacks affecting their services and, consequently, their profits. To avoid negative impacts, companies' investments in cybersecurity are increasing considerably. However, Small and Medium-sized Enterprises (SMEs) operate on small budgets, minimal technical expertise, and few personnel to address cybersecurity threats. In order to address such challenges, it is essential to promote novel approaches that can intuitively present cybersecurity-related technical information.This paper introduces SecBot, a cybersecurity-driven conversational agent (i.e., chatbot) for the support of cybersecurity planning and management. SecBot applies concepts of neural networks and Natural Language Processing (NLP), to interact and extract information from a conversation. SecBot can (a) identify cyberattacks based on related symptoms, (b) indicate solutions and configurations according to business demands, and (c) provide insightful information for the decision on cybersecurity investments and risks. A formal description had been developed to describe states, transitions, a language, and a Proof-of-Concept (PoC) implementation. A case study and a performance evaluation were conducted to provide evidence of the proposed solution's feasibility and accuracy. Muriel Figueredo Franco, Bruno Rodrigues 0001, Eder J. Scheid, Arthur Selle Jacobs, Christian Killer, Lisandro Z. Granville, Burkhard Stiller |
CNSM | 6 |
| 2020 | SWEETEN: Automated Network Management Provisioning for 5G Microservices-Based Virtual Network FunctionsabstractForthcoming 5G systems promise a myriad of new and improved applications, relying on Network Functions Virtualization (NFV) to realize some of 5G's stringent requirements. To guarantee that these requirements are met, network monitoring and management must be deployed and fine-tuned according each application's specificity. As Virtual Network Functions (VNFs) adhere to the microservice paradigm, picking and configuring the right tools is not a trivial task for users. In this paper, we present SWEETEN, a system that assists user to operate a 5G network with the appropriate management tools for the job, in a transparent manner to the user. By enriching their function stack with high-level annotation of the management features they desire, users can easily deploy an augmented stack with both network and management functions. A prototype is presented and evaluated in a dynamic Cloud Radio Access Network (C-RAN) split case study. The evaluation confirms that SWEETEN can assist users in effortlessly deploying complex management solutions, while incurring in acceptable deployment time overhead and negligible computational overhead for throughout the functions life-cycle. Rafael de Jesus Martins, Ariel Galante Dalla-Costa, Juliano Araújo Wickboldt, Lisandro Z. Granville |
CNSM | 4 |
| 2020 | ShadowFS: Speeding-up Data Plane Monitoring and Telemetry using P4abstractProgrammable Data Planes (PDPs) provide software abstractions for network operators to dynamically modify the data plane behavior. This behavior can be described in specification languages, such as P4, and deployed into programmable switches our routers. The degree of innovation enabled by PDPs allowed network operators to create new protocols and applications. Despite the high degree of innovation brought to data plane packet processing, this programmability may have a negative effect on the forwarding delay and update times of flow tables. Previous works have attempted to overcome these limitations, e.g., through caching mechanisms, however they do not provide efficient replacement primitives and incur large overhead for monitored traffic. In this paper we present the design and evaluation of ShadowFS, a system to speed-up monitoring and telemetry on the data plane. ShadowFS manages the replacement of table entries using smaller caches without requiring the programmer to specify the behavior of these tables or how to steer traffic through them. Different from previous work, ShadowFS builds a new data plane program that monitors flows and replaces rules between tables automatically. Evaluation results demonstrate that ShadowFS can increase the throughput of frequently monitored flows. Ricardo Parizotto, Lucas Castanheira, Rafael Hengen Ribeiro, Luciano Zembruzki, Arthur Selle Jacobs, Lisandro Z. Granville, Alberto E. Schaeffer Filho |
ICC | 6 |
| 2020 | An SDN-based Framework for Slice Orchestration using In-Band Network Telemetry in IEEE 802.11abstractThe fifth generation of mobile networks (5G) and the Software- Defined Radio Access Networks (SD- RAN) architecture envision to support lower latency, enhanced reliability, massive connectivity, and improved energy efficiency. In this context, low latency is considered crucial and Ultra-Reliable Low Latency Communication (URLLC) as one of the key enablers. Currently, IEEE 802.11 networks cannot be programmed fine-grained enough nor manage multiple networks at runtime. Besides, in such scenarios, the coarse-grained level of monitoring information has been hindering troubleshooting and management. In this paper, we present an SDN-based framework where fine-grained End-to-End (E2E) network statistics can be gathered using Inband Network Telemetry (INT) and used for network control and management. With such fine-grained network information, we show how our system can enhance the Quality of Service (QoS) delivery through slice orchestration in IEEE 802.11 Radio Access Networks (RANs). Pedro Heleno Isolani, Jetmir Haxhibeqiri, Ingrid Moerman, Jeroen Hoebeke, Johann Marquez-Barja, Lisandro Z. Granville, Steven Latré |
NetSoft | 6 |
| 2020 | Quantifying the Influence of Regulatory Instructions over the Detection of Network Neutrality Violations
Marcio Barbosa de Carvalho, Vitor A. Cunha, Eduardo da Silva, Daniel Corujo, João Paulo Barraca, Rui L. Aguiar, Lisandro Z. Granville |
Networking | 7 |
| 2020 | IPro: An approach for intelligent SDN monitoring
Edwin Ferney Castillo, Oscar M. Caicedo, Armando Ordóñez 0001, Lisandro Z. Granville |
Comput. Networks | 4 |
| 2020 | FT-Aurora: A highly available IaaS cloud manager based on replication
Gustavo B. Heimovski, Rogério C. Turchetti, Juliano Araújo Wickboldt, Lisandro Z. Granville, Elias P. Duarte Jr. |
Comput. Networks | 4 |
| 2020 | Virtual Network Functions Migration Cost: from Identification to Prediction
Rafael de Jesus Martins, Cristiano Bonato Both, Juliano Araújo Wickboldt, Lisandro Z. Granville |
Comput. Networks | 4 |
| 2019 | An NSH-Enabled Architecture for Virtualized Network Function Platforms
Vinicius Fulber-Garcia, Leonardo da Cruz Marcuzzo, Giovanni Venâncio de Souza, Lucas Bondan, Jéferson Campos Nobre, Alberto E. Schaeffer Filho, Carlos Raniery Paula dos Santos, Lisandro Z. Granville, Elias P. Duarte Jr. |
AINA | 8 |
| 2019 | Predicting Elephant Flows in Internet Exchange Point Programmable Networks
Marcus Vinicius Brito da Silva, Arthur Selle Jacobs, Ricardo J. Pfitscher, Lisandro Z. Granville |
AINA | 4 |
| 2019 | On the Design of a Flexible Architecture for Virtualized Network Function PlatformsabstractThe proper execution and management of heterogeneous Virtualized Network Functions (VNFs) relies on the employment of efficient and comprehensive VNF platforms. However, current systems are developed without following any standardized reference architecture, thus leading to proprietary and monolithic solutions. Furthermore, those platforms lack support for recent NFV developements, such as VNF Components (VNFC) and the Network Service Header (NSH). In this work, we present an architecture for VNF platforms that is fully compliant with the European Telecommunications Standards Institute (ETSI) NFV architecture, while also enabling the execution of both VNFC and NSH. Through the development of a system prototype called COmprehensive VirtualizEd NF (COVEN) platform, we were able to evaluate the effectiveness of our proposed architecture and to demonstrate the benefits of supporting VNFC and NSH, such as flexibility and efficiency. Vinicius Fulber-Garcia, Leonardo da Cruz Marcuzzo, Alexandre Huff, Lucas Bondan, Jéferson Campos Nobre, Alberto E. Schaeffer Filho, Carlos Raniery Paula dos Santos, Lisandro Z. Granville, Elias P. Duarte Jr. |
GLOBECOM | 8 |
| 2019 | Safeguarding from abuse by IoT vendors: Edge messages verification of cloud-assisted equipment
Vitor A. Cunha, Eduardo da Silva, Marcio Barbosa de Carvalho, Daniel Corujo, João Paulo Barraca, Diogo Gomes 0001, Alberto E. Schaeffer Filho, Carlos Raniery Paula dos Santos, Lisandro Z. Granville, Rui L. Aguiar |
IM | 9 |
| 2019 | Enabling Dynamic SLA Compensation Using Blockchain-based Smart Contracts
Eder J. Scheid, Bruno Rodrigues 0001, Lisandro Z. Granville, Burkhard Stiller |
IM | 3 |
| 2019 | A Network Service for Preventing Data Leakage from IoT Cloud-assisted EquipmentabstractThe fact that most IoT solutions are provided by third parties, along with the pervasiveness of the collected data, raises privacy and security concerns. There is a need to verify which data is being sent to the third party, as well as preventing those channels from becoming an exploitation avenue. We propose to use existing API definition languages to create contracts which define the data that can be transmitted, their format and constraints. To verify the compliance with these contracts, we propose a Network Service architecture which validates REST-like API requests/responses against a Swagger schema. We deal with encrypted traffic using an Service Function Chaining (SFC)-enabled Man-in-the-Middle (MITM), allowing verifications in “real-time.” We devised a Proof of Concept and showed that we were able to detect (and stop) contract violations. Vitor A. Cunha, Rui L. Aguiar, Eduardo da Silva, Marcio Barbosa de Carvalho, Daniel Corujo, João Paulo Barraca, Diogo Gomes 0001, Alberto E. Schaeffer Filho, Carlos Raniery Paula dos Santos, Lisandro Z. Granville |
ISCC | 10 |
| 2019 | Improved Network Traffic Classification Using Ensemble LearningabstractDespite the large number of research efforts that applied specific machine learning algorithms for network traffic classification, recent work has highlighted limitations and particularities of individual algorithms that make them more suitable to specific types of traffic and scenarios. As such, an important topic in this area is how to combine individual algorithms using meta-learning techniques in order to obtain more robust traffic classification metrics. This paper presents a comparative analysis among meta-learning approaches and individual classifiers to classify network traffic. We investigate and evaluate a range of meta-learning techniques, including Voting, Stacking, Bagging and Boosting. We then propose a new experimental analysis of different meta-learning techniques - also known as ensemble learners- and compare them with their own base classifiers when used individually. Finally, considering the emerging popularity of Neural Networks, we analyze this scenario using the Multi-layer Perceptron classifier. The experiments were performed with data provided by the UCI Machine Learning Repository. The best performance was obtained by an ensemble technique (Bagging), which obtained accuracy of 99.972% and false positive rate of 0.00018%. Isadora P. Possebon, Anderson Santos da Silva, Lisandro Z. Granville, Alberto E. Schaeffer Filho, Angelos K. Marnerides |
ISCC | 3 |
| 2019 | BRAIN: Blockchain-based Reverse Auction for Infrastructure Supply in Virtual Network Functions-as-a -ServiceabstractNetwork Functions Virtualization (NFV) is transforming the way in which network operators acquire and manage network services. By using virtualization technologies to move packet processing from dedicated hardware to software, NFV has introduced a new market focused on the offer and distribution of Virtual Network Functions (VNF). Infrastructure Providers (InP) can benefit from an NFV market by providing their infrastructures to fulfill demands of end-users that, in turn, acquire VNFs-as-a-Service (VNFaaS). In this context, solutions that promote the competition between InPs can lead to lower prices, while increasing VNF performance to accommodate specific demands of end-users. In this paper, BRAIN, a blockchain-based reverse auction is presented to introduce an auditable solution in which InPs can compete to host VNFs taking into account the demands of each particular end-user. Such a solution helps reduce costs involved in VNF's commercialization and also monetize NFV-enabled infrastructures. BRAIN is supported by a case study that provides evidence of the solution's feasibility and effectiveness. A discussion regarding blockchain advantages and drawbacks in this use-case (e.g., additional costs and time) concludes this paper. Muriel Figueredo Franco, Eder J. Scheid, Lisandro Z. Granville, Burkhard Stiller |
Networking | 3 |
| 2019 | Flexible fine-grained baseband processing with network functions virtualization: Benefits and impacts
Maicon Kist, Juliano Araújo Wickboldt, Lisandro Z. Granville, Juergen Rochol, Luiz A. DaSilva, Cristiano Bonato Both |
Comput. Networks | 3 |
| 2019 | Guiltiness: A practical approach for quantifying virtual network functions performance
Ricardo J. Pfitscher, Arthur Selle Jacobs, Luciano Zembruzki, Ricardo Luis dos Santos, Eder J. Scheid, Muriel Figueredo Franco, Alberto E. Schaeffer Filho, Lisandro Z. Granville |
Comput. Networks | 8 |
| 2018 | ISPANN: A Policy-Based ISP Auditor for Network Neutrality Violation DetectionabstractNetwork Neutrality is a controversial and full of ambiguity topic. Several works measure network features in the end-user vantage point to detect traffic differentiations, which are judged as Network Neutrality violations. However, these works neglected that each country has their own Network Neutrality rules. Some countries consider specific cases of traffic differentiations as Network Neutrality violations, and are not as general as previous works believed. In this work we consider violations directly from governments legislators Network Neutrality rules. In this sense, we propose ISPANN, a system which takes as input countries' Network Neutrality rules and audits an ISP network, identifying Network Neutrality violations. No other work proposes Network Neutrality violation detection in the ISP operator vantage point, to the best of our knowledge. We conducted an evaluation that assumes an SDN based ISP network to verify Network Neutrality violations based on OpenFlow switches flow tables and network's informations. Vinicius Garcez Schaurich, Marcio Barbosa de Carvalho, Lisandro Z. Granville |
AINA | 3 |
| 2018 | NIEP: NFV Infrastructure Emulation PlatformabstractNetwork Functions Virtualization (NFV) presents several advantages over traditional network architectures, such as flexibility, security, and reduced CAPEX/OPEX. However, virtualizing network functions usually executed on specialized hardware (e.g., firewall, DPI, load balancer) and employing innovative technologies (e.g., OpenFlow, P4) increases the challenges of designing, testing, and deploying network infrastructures and services. Although platforms for prototyping NFV environments have emerged in recent years, they still present limitations that hinder the evaluation of specific NFV scenarios, such as fog computing and heterogeneous networks. In this paper, we present NIEP: a platform for designing and testing NFV-based infrastructures and Virtualized Network Functions (VNFs) through the integration of a well-known network emulator (Mininet) and a novel platform for Click-based VNFs development (Click-on- OSv). NIEP provides a complete NFV emulation environment, allowing network operators to test their solutions in a controlled scenario prior to deployment in production networks. As main advantages, NIEP allows the emulation of heterogeneous scenarios, which can be easily migrated to production environments. An experimental scenario is defined to analyze NIEP's performance in terms of VNFs boot time and throughput. Further, NIEP's advantages and shortcomings are discussed and compared to existing emulation platforms. Thales Nicolai Tavares, Leonardo da Cruz Marcuzzo, Vinicius Fulber-Garcia, Giovanni Venâncio de Souza, Muriel Figueredo Franco, Lucas Bondan, Filip De Turck, Lisandro Z. Granville, Elias P. Duarte Jr., Carlos Raniery Paula dos Santos, Alberto E. Schaeffer Filho |
AINA | 8 |
| 2018 | IDEAFIX: Identifying Elephant Flows in P4-Based IXP NetworksabstractInternet Exchange Points (IXPs) are high-performance networks that allow multiple autonomous systems to exchange traffic, with benefits ranging from cost reductions to performance improvements. In addition, performance requirements and a number of players involved in such networks bring out several issues to management tasks, such as elephant flows identification. This kind of flows, with high size and substantial duration, can severely impact the performance of smaller flows. In this paper, we present IDEAFIX, a mechanism to identify elephant flows in P4-based IXP networks. Our approach consists in analyzing flows features for each ingress packet immediately in the edge switch. These features are then stored in P4 registers, indexed by hash keys, and compared to predefined thresholds for flow classification. Experimental evaluations show that IDEAFIX is significantly more efficient than the state-of-the-art approaches implemented with sFlow and traditional Software-Defined Networking (SDN) tools (e.g., OpenFlow). While state-of-the-art mechanisms add up to 17MB of monitoring data, our solution causes an overhead of only 25KB. Also, the implemented prototype takes less than 0.40ms to identify elephant flows with a 95% accuracy in scenarios with scarce memory resources. Marcus Vinicius Brito da Silva, Arthur Selle Jacobs, Ricardo J. Pfitscher, Lisandro Z. Granville |
GLOBECOM | 4 |
| 2018 | An SFC-enabled approach for processing SSL/TLS encrypted traffic in Future Enterprise NetworksabstractIn this paper, we propose an architecture based on NFV and SDN which allows to balance traffic analysis techniques using a Classifier. It steers flows to the appropriate Service Function Chaining (to open traffic or not) according to network requirements (such as, effectiveness, flexibility, scalability, performance, and privacy). The SSL/TLS traffic processing is carried-out by the centerpiece of this work, the SFC-enabled MITM. A Proof-of-Concept was conducted (focusing on our SFC-enabled MITM) which showed that functionalities lost due to encryption (Content Optimization, Caching, Network Anti-virus, and Content Filter) were recovered when processing opened traffic within its Service Function Chains. We also evaluated its impact on performance. The results show that cipher suite overhead plays a role but can be mitigated, the Classifier can alleviate the performance overhead of different traffic analysis techniques, network functions have lower impact to performance, and Service Function Chaining length influences page load time. Vitor A. Cunha, Marcio Barbosa de Carvalho, Daniel Corujo, João Paulo Barraca, Diogo Gomes 0001, Alberto E. Schaeffer Filho, Carlos Raniery Paula dos Santos, Lisandro Z. Granville, Rui L. Aguiar |
ISCC | 8 |
| 2018 | On the Use of a Measurement Correlation Service for Measurement FederationsabstractThe diversity of services that operate in the Internet has increased significantly in the last years. Performance problems in these services cause important financial losses. To ensure that these problems do not occur, service levels need to be monitored. One of the main techniques for such monitoring involves the use of active measurement mechanisms. However, these mechanisms are expensive in terms of resources consumption due to the activation of measurement sessions. Measurement sessions usually cover only a fraction of what could be measured, which leads to service level problems being missed. Measurement federations can help network administrators in different tasks, such as controlling the activation of active measurement sessions. In this context, measurement correlation can be deployed in order to improve this control in such federations. The main contribution of the present work is the proposal of a data transformation service that provides measurement correlation. This service is used to enable cooperation features in measurement federations, while decreasing resource consumption. Besides that, statistical tests that can be used to compose such correlation are presented. The proposed solution is evaluated using an active measurement dataset from the Brazilian National Research and Education Network (Rede Nacional de Ensino e Pesquisa - RNP). Our results provide insights regarding measurement correlation from federated measurement points and can be used for the design of better application to control active measurement sessions. Jéferson Campos Nobre, Leandro Lisboa Penz, Muriel Figueredo Franco, Lisandro Z. Granville |
ISCC | 4 |
| 2018 | Unfolding the Mutual Relation Between Timeliness and Scalability in Cloud MonitoringabstractCloud computing is a suitable solution for professionals, companies, and institutions that need to have access to computational resources on demand. Clouds rely on proper management to provide such computational resources with adequate quality of service, which is established by Service Level Agreements (SLAs), to customers. In this context, cloud monitoring is a critical function to achieve such proper management. Cloud monitoring systems have to accomplish requirements to perform its functions properly, and currently, there are plenty of requirements which includes: timeliness, adaptability, comprehensiveness, and scalability. However, such requirements usually have mutual influence, which is positive or negative, among themselves, and it has prevented the development of complete cloud monitoring solutions. This paper presents a mathematical model to predict the mutual influence between timeliness and scalability, which is a step forward in cloud monitoring because it paves the way for the development of complete monitoring solutions. It complements our previous work that identified the monitoring parameters (e.g., frequency sampling, amount of monitoring data) that influence timeliness and scalability. Evaluations present the effectiveness of the mathematical model based on a comparison of the results provided by the mathematical model and the results obtained via simulation. Guilherme da Cunha Rodrigues, Rodrigo N. Calheiros, Glederson Lessa dos Santos, Vinicius Tavares Guimaraes, Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco, Rajkumar Buyya |
ISCC | 5 |
| 2018 | Using NFV and Reinforcement Learning for Anomalies Detection and Mitigation in SDNabstractComputer networks are subject to several anomalies, which leads to the necessity of techniques to coordinate detection and mitigation to keep the network operational. In this paper we propose the use of reinforcement learning to promote resilience in Software Defined Networking (SDN). In particular, it is proposed collecting network metrics and grouping them into profiles, each one having a set of actions that handles problems using reinforcement learning, Network Functions Virtualization (NFV), and an SDN controller. Policies for dealing with anomalies are defined based on rewards for each action. Results show that the system obtains mostly positive rewards, but a small increment in the topology size leads to more than four times the number of entries in the state-action table. Lauren S. R. Sampaio, Pedro Faustini, Anderson Santos da Silva, Lisandro Z. Granville, Alberto E. Schaeffer Filho |
ISCC | 4 |
| 2018 | Artificial neural network model to predict affinity for virtual network functionsabstractNetwork Functions Virtualization (NFV) was proposed to migrate middleboxes that compose network services, such as firewalls and Network Address Translation (NAT) servers, from hardware to software running on Virtual Machines (VMs), commonly known as Virtualized Network Functions (VNFs). In NFV-enabled networks, VNFs can be chained in Forwarding Graphs (FGs) to provide services. These FGs establish the logical order in which network packets must traverse until reaching the end-service. In this scenario, network operators establish affinity and anti-affinity rules, which determine restrictions on the placement and chaining of VNFs according to how well or poorly VNFs operate together. To address the subject of identifying affinity relations in NFV-enabled networks, we previously proposed a mathematical model to measure the affinity between pairs of VNFs. However, that affinity model falls short for identifying affinity of VNFs not yet deployed, as they have no resource usage data to take into account. In this paper, we use artificial neural networks to predict affinity estimation for newly introduced VNFs, which still do not have usage data to be analyzed. This affinity neural network is trained using past affinity measurements, containing the data from VNFs, Physical Machines (PMs), and FGs of each measurement as features. We evaluate our solution by analyzing it over real usage data from a Cloud dataset, and conclude that neural networks can be used to provide affinity values for network operators, or NFV orchestrators, to plan the deployment of new VNFs. Arthur Selle Jacobs, Ricardo J. Pfitscher, Ricardo Luis dos Santos, Muriel Figueredo Franco, Eder J. Scheid, Lisandro Z. Granville |
NOMS | 6 |
| 2018 | A model for quantifying performance degradation in virtual network function service chainsabstractVirtual Network Functions (VNFs) can be chained and provisioned on demand, providing elasticity and dynamicity to the network. Due to the interdependencies between VNFs, resulting service chains may not work as expected, and because of that, it is crucial to determine which VNFs are having a negative impact on the service quality. In this paper, we introduce a model to quantify the guiltiness of a VNF on being a bottleneck in a service chain, which provides a metric that estimates the impact on processing delay. In addition, we propose an adaptive algorithm, based on linear regression and neural networks, to adjust the model parameters according to the environment particularities, such as the type and number of VNFs. We show through an experimental evaluation that the guiltiness metric faithfully characterizes end-service performance, by identifying up to 94% of the bottleneck VNFs in the analyzed scenarios. Also, we provide artifacts for researchers to reproduce our results in other scenarios. Ricardo J. Pfitscher, Arthur Selle Jacobs, Eder J. Scheid, Muriel Figueredo Franco, Ricardo Luis dos Santos, Alberto E. Schaeffer Filho, Lisandro Z. Granville |
NOMS | 7 |
| 2018 | A Smart Meter and Smart House Integrated to an IdM and Key-based Scheme for Providing Integral Security for a Smart Grid ICT
Vilmar Abreu, Altair Olivo Santin, Alex Xavier, Alison Lando, Adriano Witkovski, Rafael Ribeiro, Maicon Stihler, Lisandro Z. Granville, Ivan Chueiri |
Mob. Networks Appl. | 8 |
| 2017 | Maestro: An NFV Orchestrator for Wireless Environments Aware of VNF Internal CompositionsabstractDynamic Cloud Radio Access Network (Dynamic C-RAN) is an emerging wireless architecture that aims for flexibility, business agility, adaptability, among other benefits. In a Dynamic C-RAN, wireless functionalities can be split into smaller components and distributed along a hierarchical cloud infrastructure. Network Functions Virtualization (NFV) concepts have been recently investigated to facilitate management-related operations of these wireless functionalities. Despite the many advocated advantages of the function's splitting and the effectiveness of NFV orchestration solutions, both academia and industry are considering Virtualized Network Functions (VNF)s as atomic elements, disregarding the potential advantages of splitting VNFs into several different components. Aiming to improve VNF orchestration in Dynamic C-RAN scenarios, in this paper we propose Maestro: an NFV orchestrator for wireless environments that is able to decide among several possible VNF compositions which are more suitable for each situation. Maestro is designed to operate using different decision mechanisms that can be defined based on network operators' needs. We evaluate the effectiveness of our proposal by modeling the orchestrator's decision mechanism as a linear programming problem. Thus, we show how fronthaul bandwidth consumption can be reduced threefold considering different VNF compositions against atomic VNF placement. Ariel Galante Dalla-Costa, Lucas Bondan, Juliano Araújo Wickboldt, Cristiano Bonato Both, Lisandro Z. Granville |
AINA | 5 |
| 2017 | Interactive Visualizations for Planning and Strategic Business Decisions in NFV-Enabled NetworksabstractNetwork Functions Virtualization (NFV) is driving a paradigm shift in telecommunications networks, fostering new business models and creating innovation opportunities. In NFV-enabled networks, Service Providers (SPs) have the opportunity to build a business model where tenants can purchase Virtual Network Functions (VNFs) that provide distinct network services and functions. However, the chance to negotiate VNFs requires a change in traditional network planning strategies to accommodate tenants demands. In this context, the planning tasks perform a critical role in the introducing of business strategies that encompass both profit and health of services, which requires operators to have a broad understanding of the environment. In this paper, we propose the usage of two interactive visualization techniques to help NFV network operators in planning and strategic decisions. We advocate that our visualizations can aid in NFV planning tasks, such as infrastructure investment, resources allocation, and service pricing. We present three case studies to provide evidence of the feasibility and effectiveness of our visualizations. Muriel Figueredo Franco, Ricardo Luis dos Santos, Ricardo Andrade Cava, Eder J. Scheid, Ricardo J. Pfitscher, Carla M. D. S. Freitas, Lisandro Z. Granville |
AINA | 7 |
| 2017 | A Reuse-Based Approach to Promote the Adoption of Visualizations for Network Management TasksabstractInformation Visualization (InfoVis) is a powerful tool to assist network administrators in daily tasks, and several authors report investigations about visualization techniques for network management. However, we have observed a fundamental issue that has not been addressed yet: how to promote the adoption of visualizations by network administrators, focusing on improving productivity and reducing costs? We claim that, in general, administrators do not have expertise in the InfoVis domain. Thus, the adoption of visualizations tends to be expensive and decrease the productivity of administrators, in special, because they lose focus on their core tasks. To overcome the raised issue, in this paper, we introduce a reuse-based approach (named as VisNSM) that aims to promote and encourage the adoption of visualizations for network management. To analyze and evaluate the feasibility of VisNSM, we have conducted a case study, and the obtained results show that our approach can significantly reduce costs and improve productivity. Vinicius Tavares Guimaraes, Oscar M. Caicedo, Glederson Lessa dos Santos, Guilherme da Cunha Rodrigues, Carla M. D. S. Freitas, Liane Margarida Rockenbach Tarouco, Lisandro Z. Granville |
AINA | 7 |
| 2017 | iMPROVE: Enhancing the Introduction of Services on Programmable Virtual NetworksabstractProgrammable Virtual Networks (PVNs) make the network more flexible and allow the fast introduction of new services. However, several shortcomings hamper their wider adoption, including: (i) the extensive knowledge required to configure and manage the NetApps; (ii) the lack of descriptors to detail all nuances of the NetApps; and (iii) there is no solution that enables to distribute and configure NetApps over distinct technologies. Therefore, we propose iMPROVE to simplify the introduction of services in PVNs, enhancing the distribution of NetApps. We also extend the ETSI network service descriptor to support distinct technologies as well as to represent conflict issues. We demonstrate evidence of iMPROVE's feasibility in a case study and compare it with the main solutions for distributing and deploying applications over multiple platforms. Ricardo Luis dos Santos, Muriel Figueredo Franco, Eder J. Scheid, Ricardo J. Pfitscher, Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco |
AINA | 5 |
| 2017 | Affinity measurement for NFV-enabled networks: A criteria-based approachabstractNetwork Functions Virtualization (NFV) offers several benefits for Service Providers (SPs), such as mitigating equipment cost and increasing business agility. In NFV-enabled networks, inadequate placement of Virtualized Network Functions (VNFs) creates bottlenecks, impacting negatively on performance. Therefore, network operators must establish affinity and anti-affinity rules to avoid network and processing bottlenecks, and thus comply with Service Level Agreement (SLA) requirements of tenants. Affinity and anti-affinity rules in NFV must be broad and carefully elaborated to maintain service performance. Network operators must consider further than simply resource allocation when identifying affinity among VNFs. The criteria for VNFs affinity varies for different forwarding graphs. Geolocation, latency, packet loss, and bandwidth usage are some examples of criteria that can be considered as indicators of bottlenecks in high traffic networks. In this paper, we propose a solution to measure affinity between pairs of VNFs, based on a weighted set of affinity criteria considered relevant by a network operator. To evaluate the feasibility of our affinity model, we analyze three case studies over an experimental NFV scenario. We conclude that our affinity model can help network operators identify the cause of issues in NFV-enabled networks, as well as it may be used by NFV orchestrators to aid on VNFs migration and embedding. Arthur Selle Jacobs, Ricardo Luis dos Santos, Muriel Figueredo Franco, Eder J. Scheid, Ricardo J. Pfitscher, Lisandro Z. Granville |
IM | 6 |
| 2017 | AMNESiA: Affinity measurement platform for NFV-enabled networksabstractAMNESiA is an affinity measurement platform for NFV-enabled networks, designed to consolidate and interpret existing monitoring data into an affinity metric, aiding operators to identify affinity and anti-affinity relations in the network. AMNESiA uses the latest snapshot of usage data, collected through a generic monitoring solution, from the database to measure affinity between VNFs. Arthur Selle Jacobs, Ricardo Luis dos Santos, Muriel Figueredo Franco, Eder J. Scheid, Ricardo J. Pfitscher, Lisandro Z. Granville |
IM | 6 |
| 2017 | Click-on-OSv: A platform for running Click-based middleboxesabstractIn this paper, we present a modern platform for running Virtualized Network Functions based on the Click Modular Router. The proposed platform leverages of current technologies - such as DPDK, OSv, and REST Web Services - to fulfill the ETSI requirements for Network Functions Virtualization. The obtained results show the feasibility of the platform to consolidate disparate network functions, while demonstrating flexibility from a management point-of-view. Leonardo da Cruz Marcuzzo, Vinicius Fulber-Garcia, Vitor A. Cunha, Daniel Corujo, João Paulo Barraca, Rui L. Aguiar, Alberto E. Schaeffer Filho, Lisandro Z. Granville, Carlos Raniery Paula dos Santos |
IM | 8 |
| 2017 | Decentralized detection of violations of Service Level Agreements using Peer-to-Peer technologyabstractCritical networked services established between service providers and customers are expected to operate respecting Service Level Agreements (SLAs). An interesting possibility to monitor such SLAs is using active measurement mechanisms. However, these mechanisms are expensive in terms of network devices resource consumption and also increase the network load because of the injected traffic. In addition, if the number of SLA violations in a given time is higher than the number of available measurement sessions (common place in large and complex network infrastructures), certainly some violations will be missed. The current best practice, the observation of just a subset of network destinations driven by human administrators expertise, is error prone, does not scale well, and is ineffective on dynamic network conditions. This practice can lead to SLA violations being missed, which invariably affects the performance of several applications. In the present thesis, we advocate the use of Peer-to-Peer (P2P) technology to improve the detection of SLA violations. Such use is described using principles to control active measurement mechanisms. These principles are accomplished through strategies to activate measurement sessions. In this context, the thesis contains several contributions towards SLA monitoring, conceptually as well pragmatically. The findings show properties which improve the detection of SLA violations in terms of the number of detected violations and the adaptivity to network dynamics. We expect that such findings can lead to better SLA monitoring tools and methods. Jéferson Campos Nobre, Lisandro Z. Granville |
IM | 2 |
| 2017 | Measurement correlation for improving cooperation in measurement federationsabstractThe diversity of services that operate in the Internet has increased significantly in the last years. Performance problems in these services cause important financial losses. In order to ensure that these problems do not occur, service levels need to be monitored. One of the main techniques for this monitoring involves the utilization of active measurement mechanisms. However, such mechanisms are expensive in terms of resources consumption due to the activation of measurement sessions. Thus, such sessions usually can cover only a fraction of what could be measured, which can lead to service level problems being missed. Measurement federations can help network administrators in different tasks, such as the control of the activation of active measurement sessions. In this context, measurement correlation can be deployed in order to improve this control in such federations. The main contribution of the present work is the proposal of a data transformation service which provides measurement correlation. This service can be used to enable cooperation features in measurement federations, while decreasing resource consumption. Besides that, statistical tests that can be used to compose such correlation are presented. The proposed solution provides valuable insights regarding measurement correlation from federated measurement points and can be used for the design of better application for the control of active measurement sessions. Jéferson Campos Nobre, Leandro Lisboa Penz, Lisandro Z. Granville |
IM | 3 |
| 2017 | INSpIRE: Integrated NFV-based Intent Refinement EnvironmentabstractMany aspects of the management of computer networks, such as quality of service and security, must be taken into consideration to ensure that the network meets the users and clients demands. Fortunately, management solutions were developed to address these aspects, such as Intent-Based Networking (IBN). IBN is a novel networking paradigm that abstracts network configurations by allowing administrators to specify how the network should behave and not what it should do. In this paper, we introduce an IBN solution called INSpIRE (Integrated NFV-based Intent Refinement Environment). INSpIRE implements a refinement technique to translate intents into a set of configurations to perform a desired service chain in both homogeneous environments (VNFs only) and heterogeneous environments (VNFs and physical middleboxes). Our solution is capable of (i) determining the specific VNFs required to fulfill an intent, (ii) chaining these VNFs according to their dependencies, and (iii) presenting enough low-level information to network devices for posterior traffic steering. Finally, to assess the feasibility of our solution we detail a case study that reflects real-world management situations and evaluate the scalability of the refinement process. Eder J. Scheid, Cristian Cleder Machado, Muriel Figueredo Franco, Ricardo Luis dos Santos, Ricardo J. Pfitscher, Alberto E. Schaeffer Filho, Lisandro Z. Granville |
IM | 7 |
| 2017 | Mitigating elephant flows in SDN-based IXP networksabstractInternet Exchange Points (IXPs) play a key role in the Internet architecture, enabling cost-effective connections among multiple autonomous systems (ASes). The management of IXP networks includes the activity of taking care of elephant flows; they represent a small number of the total flows of an IXP, but have high impact on the overall network traffic. Managing elephant flows involves adequate identification and eventually rerouting of such flows to more appropriate locations, to minimize the possible negative impact on the other (mice) flows. Elephant flow management becomes even more important in SDN-based IXPs that require controllers to have a consistent view of the underlying network to allow fine-grained adjustment. In this paper, we propose, develop, and evaluate a recommendation system to suggest alternative configurations to previously identified elephant flows in an SDN-based IXP network. In our solution, the IXP operator can define templates that ultimately define how elephant flows can be rerouted to achieve a specific objective. We demonstrate that our system can help IXP operators to mitigate the impact of elephant flows on the IXP network. Luis Augusto Dias Knob, Rafael Pereira Esteves, Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco |
ISCC | 3 |
| 2017 | Anomaly detection framework for SFC integrity in NFV environmentsabstractWith the increasing deployments of Network Functions Virtualization (NFV) in both industry and academia, it becomes necessary to design mechanisms for keeping the integrity of Service Function Chains (SFC) responsible for NFV services delivering. Despite the advances in the development of management and orchestration for NFV, solutions to keep SFCs resilient to well-known and zero-day threats are still much needed. In this paper, we introduce a framework for deploying anomaly detection techniques for SFC in NFV environments. Our framework consists of a set of functional blocks with well-defined functions, composing an additional SFC Integrity Module (SIM) for the standard NFV architecture. The proposed SIM enables NFV orchestrators to analyze NFV elements and perform suggested actions with the goal of keeping service integrity in the network. The results obtained through the evaluation of a Proof-of-Concept implementation show that the proposed framework is able to properly detect different types of anomalies using entropy-based detection techniques. Lucas Bondan, Tim Wauters, Bruno Volckaert, Filip De Turck, Lisandro Z. Granville |
NetSoft | 5 |
| 2017 | MARS: From traffic containment to network reconfiguration in malware-analysis systemsabstractMalware analysis systems are essential to characterize malware behavior and to improve defense mechanisms. In dynamic malware analysis, the actions performed by malware in a sandbox are highly dependent on the interactions with other hosts and services. However, the current solutions superficially deal with the network environment that surrounds the sandbox, exposing limitations to traffic containment and network resources reconfiguration. We have already shown how Software-Defined Networking (SDN) could enable network access policies changes and thus exposing distinct malware actions. In this paper, we investigate the malware analysis process by considering the entire analysis environment, including a sandbox and other components that comprise it. We developed a fully-automated malware analysis solution that uses network layer as a tool to reconfigure the analysis environment. In that way, it is possible to implement per-flow containment rules, dynamic resources configuration, and to manipulate network traffic to impersonate services. Our experiments show that it is feasible to identify behavioral deviations in different analysis scenarios and reveal many more malware behaviors than those revealed by the state-of-the-art analysis systems. João M. Ceron, Cíntia B. Margi, Lisandro Z. Granville |
Comput. Networks | 3 |
| 2017 | A framework for SDN integrated management based on a CIM model and a vertical management plane
Felipe Estrada Solano, Armando Ordóñez 0001, Lisandro Z. Granville, Oscar M. Caicedo |
Comput. Commun. | 3 |
| 2017 | ARKHAM: An Advanced Refinement toolkit for Handling Service Level Agreements in Software-Defined Networking
Cristian Cleder Machado, Juliano Araújo Wickboldt, Lisandro Z. Granville, Alberto E. Schaeffer Filho |
J. Netw. Comput. Appl. | 3 |
| 2016 | VISION - Interactive and Selective Visualization for Management of NFV-Enabled NetworksabstractNetwork Functions Virtualization (NFV) enhances the flexibility of network service provisioning and reduces the time to services deployment. NFV and SDN promises transform the carrier networks, introducing innovation in the network core. NFV moves packet processing from dedicated hardware middleboxes to Virtualized Network Functions (VNFs), which run on virtual machines hosted on commercial off-the-shelf servers. However, in NFV-enabled networks, the amount of data managed grows in a fast way. Based on this, the network operator must understand and manipulate a lot of information to effectively manage the network. In this paper, we introduce the VISION, a platform to help the network operator to determine the cause of problems based on visualizations techniques. Our platform implements a set of interactive and selective visualizations to assist in the NFV management. Finally, we conducted three cases studies to provide evidences of the feasibility of our platform. Muriel Figueredo Franco, Ricardo Luis dos Santos, Alberto E. Schaeffer Filho, Lisandro Z. Granville |
AINA | 4 |
| 2016 | Performance Analysis of 6LoWPAN and CoAP for Secure Communications in Smart HomesabstractSmart grids and smart homes improve energy management by coupling communication capabilities to their devices. Due to computational constraints of these devices, employment of simplified communication protocols is necessary. In this paper, we investigate the use of communication protocols based on CoAP and 6LoWPAN in smart home environments. Specifically, we analyze the vulnerabilities a smart home employing CoAP and 6LoWPAN may be susceptible to. We also present a performance analysis of the use of these protocols for ensuring secure communicationsin smart homes. Rafael de Jesus Martins, Vinicius Garcez Schaurich, Luis Augusto Dias Knob, Juliano Araújo Wickboldt, Alberto E. Schaeffer Filho, Lisandro Z. Granville, Marcelo Pias |
AINA | 6 |
| 2016 | Hierarchy-based monitoring of Vehicular Delay-Tolerant NetworksabstractVehicular Ad Hoc Networks (VANETs) are mobile networks that extend over vast areas and have intense node mobility. These characteristics lead to frequent delays and disruptions. A solution is to employ the Delay Tolerant Network (DTN) paradigm. However, the frequent disruptions as well as the delay and reliability constraints of certain VANET applications hinder the employment of both conventional and DTN-based management architectures. This paper tackles monitoring, one of the tasks of network management. We describe a hierarchical architecture that copes with near real-time as well as non real-time monitoring tasks. The proposed solution is evaluated using simulations, where we measure the delay and delivery rates of the monitoring data. The results show that the proposed solution reduces the delivery delay and increases the chances that a notification will be delivered on time to its destination. Ewerton Monteiro Salvador, Daniel F. Macedo, José Marcos S. Nogueira, Virgil Del Duca Almeida, Lisandro Z. Granville |
CCNC | 5 |
| 2016 | Booter blacklist: Unveiling DDoS-for-hire websitesabstractThe expansion of Distributed Denial of Service (DDoS) for hire websites, known as Booters, has radically modified both the scope and stakes of DDoS attacks. Until recently, however, Booters have only received little attention from the research community. Given their impact, addressing the challenges associated with this phenomenon is crucial. In this paper, we present a rigorous methodology to identify a comprehensive set of existing Booters in the Internet. The methodology relies on well-defined mechanisms to generate a Booter blacklist, from crawling suspect URLs to characterizing and classifying the collected URLs. The list obtained using the methodology presented in this paper has a classification accuracy of 95.5%, which is 10.5% better compared to previous work. We also demonstrate the usage of our methodology applied by the Dutch NREN, SURFNet, which started using our blacklist to extend their Booters' activities monitoring. José Jair Santanna, Ricardo de Oliveira Schmidt, Daphné Tuncer, Joey de Vries, Lisandro Z. Granville, Aiko Pras |
CNSM | 5 |
| 2016 | A One-Class NIDS for SDN-Based SCADA SystemsabstractPower systems are undergoing an intense process of modernization, and becoming highly dependent on networked systems used to monitor and manage system components. These so-called Smart Grids comprise energy generation, transmission, and distribution subsystems, which are monitored and managed by Supervisory Control and Data Acquisition (SCADA) systems. In this paper, we discuss the benefits of using Software-Defined Networking (SDN) to assist in the deployment of next generation SCADA systems. We also present a specific Network-Based Intrusion Detection System (NIDS) for SDN-based SCADA systems, which uses SDN to capture network information and is responsible for monitoring the communication between power grid components. Our approach relies on SDN to periodically gather statistics from network devices, which are then processed by One-Class Classification (OCC) algorithms. Given that attack traces in SCADA networks are scarce and not publicly disclosed by utility companies, the main advantage of using OCC algorithms is that they do not depend on known attack signatures to detect possible malicious traffic. Our results indicate that OCC algorithms achieve an approximate accuracy of 98% and can be effectively used to detect cyber-attacks targeted against SCADA systems. Eduardo Germano da Silva, Anderson Santos da Silva, Juliano Araújo Wickboldt, Paul Smith 0001, Lisandro Z. Granville, Alberto E. Schaeffer Filho |
COMPSAC | 5 |
| 2016 | Comparing virtualization solutions for NFV deployment: A network management perspectiveabstractNetwork Functions Virtualization (NFV) is a paradigm designed to promote service agility and able to quickly generate revenue, thus encouraging competition among companies in the computer network industry. Besides the advocated benefits of NFV, management requirements should be properly taken into account. The choice of a particular NFV-based technology must consider its management requirements. However, there is still no evaluation of virtualization solutions providing an in-depth analysis from the management point-of-view. This paper presents a performance analysis of three prominent virtualization solutions: ClickOS, CoreOS, and OSv. Our results place ClickOS and CoreOS as the best solutions regarding boot time, response time, and memory consumption. Moreover, based on the results obtained for each performance metric, we provide a broad discussion about the effectiveness of each virtualization solution in fulfilling qualitative management requirements. Lucas Bondan, Carlos Raniery Paula dos Santos, Lisandro Z. Granville |
ISCC | 3 |
| 2016 | MARS: An SDN-based malware analysis solutionabstractMechanisms to detect and analyze malicious software are essential to improve security systems. Current security mechanisms have limited success in detecting sophisticated malicious software. More than to evade analysis system, many malwares require specific conditions to activate their actions in the target system. The flexibility of Software-Defined Networking (SDN) provides an opportunity to develop a malware analysis architecture integrating different systems and networks profile configuration. In this paper we design an architecture specialized in malware analysis using SDN to dynamically reconfigure the network environment based on malware actions. As result, we demonstrate that our solution can trigger more malware's events than traditional solutions that do not consider sandbox surround environment as an important component in malware analysis. João M. Ceron, Cíntia B. Margi, Lisandro Z. Granville |
ISCC | 3 |
| 2016 | Improving productivity and reducing cost through the use of visualizations for SDN managementabstractVisualization means the use of Information Visualization (InfoVis) techniques to augment human cognitive capacity to support users tasks more efficiently. According to the current literature, visualization is a relevant requirement to support the management of Software-Defined Networking (SDN). For example, visualization can help network administrators in everyday tasks such as in the identification of traffic patterns, or in the implementation and test of new networking services. However, in most cases, network administrators are unskilled on InfoVis, which makes them naturally reluctant in the use of visualizations. Also, building up visualizations from scratch can spend a significant amount of effort, which directly impacts on the increase of cost and the decrease of administrators' productivity. Thus, in this paper, we introduce a reuse-based approach to facilitating the employment of visualizations in the SDN context with the focus on improving productivity and reduce costs. We developed a prototype to evaluate and demonstrate the feasibility of our approach. The obtained results to one of the usage scenarios show, for example, that our solution can decrease in 264 hours the administrators' workload (i.e., around U$ 9,976.56) when employing visualizations in daily tasks. Vinicius Tavares Guimaraes, Oscar M. Caicedo, Glederson Lessa dos Santos, Guilherme da Cunha Rodrigues, Carla M. D. S. Freitas, Liane Margarida Rockenbach Tarouco, Lisandro Z. Granville |
ISCC | 7 |
| 2016 | ANSwer: Combining NFV and SDN features for network resilience strategiesabstractSoftware-Defined Networking (SDN) relies on open programmability of network devices, which is achieved by defining new communication interfaces, network operating systems, and changing the traditional decision-making logic of regular TCP/IP networks. Network Functions Virtualization (NFV), in turn, permits virtualizing network functions that are traditionally performed by physical middleboxes (e.g., firewalling and intrusion detection/prevention). Although SDN and NFV improve the flexibility of the management of computer networks, SDN remains vulnerable to major network security problems, such as Distributed Denial of Service (DDoS) attacks. These attacks typically result in the disruption of network services and resources. In this paper, we introduce ANSwer, an architecture that combines NFV and SDN features to create sophisticated network resilience strategies. ANSwer relies on a feedback control-loop which explores SDN features to monitor and analyze the behavior of the network infrastructure, indicating whether parts of an existing resilience strategy can be reconfigured to achieve more satisfactory results, or if an entire resilience strategy needs to be added or replaced. Our experiments demonstrate that ANSwer can rapidly identify and handle distinct anomalies in different scenarios, indicating that the reconfiguration and deployment of resilience strategies can be performed in real-time. Cristian Cleder Machado, Lisandro Z. Granville, Alberto E. Schaeffer Filho |
ISCC | 2 |
| 2016 | DReAM - a distributed result-aware monitor for Network Functions VirtualizationabstractNetwork Functions Virtualization (NFV) is a key technology to reduce management costs as well as to improve scalability and elasticity of computer networks. Still, recent research efforts have been exposing additional management challenges. Concerning monitoring in particular, new types of entities and requirements are underexploited. To address these issues, we propose DReAM, a resource management architecture based on management by delegation and distributed monitoring, where each agent runs a diagnostic model to compute the network service state. In this paper, we describe DReAM's proposed architecture and its major components. We also discuss the feasibility of DReAM through experimental and analytical evaluations, where we observed application throughput, CPU utilization, communication overhead, scalability, and diagnosis complexity. We provide a trade-off analysis on the monitoring strategies in NFV scenarios. Our results indicate that a result-aware strategy is a better option when the monitored environment has more than 256 agents or when the diagnosis module induces at least 10% of CPU utilization. Ricardo J. Pfitscher, Eder J. Scheid, Ricardo Luis dos Santos, Rafael R. Obelheiro, Maurício Aronne Pillon, Alberto E. Schaeffer Filho, Lisandro Z. Granville |
ISCC | 7 |
| 2016 | Policy-based dynamic service chaining in Network Functions VirtualizationabstractNetwork Functions Virtualization (NFV) enables the rapid development, flexible management, and the dynamic placement of new, innovative Virtualized Network Functions (VNFs), such as load balancers, firewalls, and Intrusion Detection Systems (IDSes). Furthermore, NFV along with Software-Defined Networking (SDN) allows VNFs and physical middleboxes to be dynamically composed into service chaining graphs. Despite these benefits, service chaining graphs can be further improved through the use of techniques that have not been satisfactorily explored yet, such as Policy-Based Network Management (PBNM). In PBNM, policies can be written and triggered during runtime, thus supporting the dynamic (re)configuration of service graphs with minimal disruption. In this paper, we propose an approach to automatically design NFV service chaining graphs based on policies. These policies rule the forwarding of traffic and the construction of service chaining graphs. In our approach, service chaining graphs are enforced dynamically in the network during runtime. Finally, to assess its feasibility and generality, we create two different scenarios to demonstrate and discuss how our solution can be employed and its expected results. Eder J. Scheid, Cristian Cleder Machado, Ricardo Luis dos Santos, Alberto E. Schaeffer Filho, Lisandro Z. Granville |
ISCC | 5 |
| 2016 | SDEFIX - Identifying elephant flows in SDN-based IXP networksabstractInternet Exchange Points (IXPs) are fundamental blocks of the Internet ecosystem by providing cost-effective connections among multiple autonomous systems (ASes). One of the main management challenges in IXP networks is the management of the so-called elephant flows. Elephant flows, characterized by high throughput and long duration, represent a small fraction of the total flows of an IXP network but have high impact on the overall traffic. A first step in the management of elephant flows is their identification, which becomes more important in SDN-based IXPs that require controllers to have a consistent view of the underlying network to allow fine-grained adjustment. In this paper, we propose, develop, and evaluate a monitoring system to identify elephant flows in an SDN-based IXP network. We demonstrate that our system can assist IXP operators to properly identify elephant flows in an efficient, scalable, and timely manner. Luis Augusto Dias Knob, Rafael Pereira Esteves, Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco |
NOMS | 3 |
| 2016 | ATLANTIC: A framework for anomaly traffic detection, classification, and mitigation in SDNabstractAnomaly traffic detection and classification mechanisms need to be flexible and easy to manage in order to detect the ever growing spectrum of anomalies. Detection and classification are difficult tasks because of several reasons, including the need to obtain an accurate and comprehensive view of the network, the ability to detect the occurrence of new attack types, and the need to deal with misclassification. In this paper, we argue that Software-Defined Networking (SDN) form propitious environments for the design and implementation of more robust and extensible anomaly classification schemes. Different than other approaches from the literature, which individually tackle either anomaly detection or classification or mitigation, we present a management framework to perform these tasks jointly. Our proposed framework is called ATLANTIC and it combines the use of information theory to calculate deviations in the entropy of flow tables and a range of machine learning algorithms to classify traffic flows. As a result, ATLANTIC is a flexible framework capable of categorizing traffic anomalies and using the information collected to handle each traffic profile in a specific manner, e.g., blocking malicious flows. Anderson Santos da Silva, Juliano Araújo Wickboldt, Lisandro Z. Granville, Alberto E. Schaeffer Filho |
NOMS | 3 |
| 2016 | ChiMaS: A spectrum sensing-based channels classification system for cognitive radio networksabstractCognitive radio devices are able to sense the spectrum of frequencies and share access to vacant channels. These devices usually have a candidate channels list that must be sensed to find a vacant channel. In this paper, we propose a novel system called ChiMaS, which is able to manage the candidate channels list implementing three tasks: Analysis, Creation, and Sort. Analysis applies reinforcement learning algorithms to evaluate the channels quality based on their historical occupancy and their conditions; Creation is responsible for creating the Candidate Channels List; and Sort ranks the channels to obtain an Ordered Channels List in terms of quality. Results show that ChiMaS manages the candidate channels list following the IEEE 802.22 definition, while it finds the best channel in terms of availability and quality faster than Q-Noise+ algorithm, which was implemented for comparison purpose. Lucas Bondan, Marcelo Antonio Marotta, Leonardo Roveda Faganello, Juergen Rochol, Lisandro Z. Granville |
WCNC | 5 |
| 2016 | A joint CPU-RAM energy efficient and SLA-compliant approach for cloud data centers
Pedro H. P. Castro, Vívian L. Barreto, Sand Correa, Lisandro Z. Granville, Kleber Vieira Cardoso |
Comput. Networks | 4 |
| 2016 | Rich dynamic mashments: An approach for network management based on mashups and situation management
Oscar M. Caicedo, Felipe Estrada Solano, Vinicius Tavares Guimaraes, Liane Margarida Rockenbach Tarouco, Lisandro Z. Granville |
Comput. Networks | 5 |
| 2016 | Using Empirical Estimates of Effective Bandwidth in Network-Aware Placement of Virtual Machines in DatacentersabstractDatacenter operators are increasingly deploying virtualization platforms to improve resource usage efficiency and to simplify the management of tenant applications. Although there are significant efficiency gains to be made, predicting performance becomes a major challenge, especially given the difficulty of allocating datacenter network bandwidth to multitier applications, which generate highly variable traffic flows between their constituent software components. Static bandwidth allocation based on peak traffic rates ensures SLA compliance at the cost of significant overprovisioning, while allocation based on mean traffic rates ensures efficient usage of bandwidth at the cost of QoS violations. We describe MAPLE, a network-aware VM ensemble placement system that uses empirical estimations of the effective bandwidth required between servers to ensure that QoS violations are within targets specified in the SLAs for tenant applications. Moreover, we describe an extended version of MAPLE, termed MAPLEx, which allows the specification of anticolocation constraints relating to the placement of application VMs. Experimental results, obtained using an emulated datacenter, show that, in contrast to the Oktopus network-aware VM placement system, MAPLE can allocate computing and network resources in a manner that balances efficiency of resource utilization with performance predictability. Runxin Wang, Juliano Araújo Wickboldt, Rafael Pereira Esteves, Lei Shi 0008, Brendan Jennings, Lisandro Z. Granville |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2015 | Application-Aware adaptive provisioning in virtualized networksabstractNetwork virtualization is a feasible solution to tackle the so-called Internet ossification by enabling multiple virtual networks (VNs) running simultaneously on top of a shared physical infrastructure. Network management with virtualization support, however, poses challenges that need to be addressed in order to fully achieve an effective and reliable networking environment. One of the main aspects related to the management of network virtualization environments is virtual network provisioning. Unfortunately, current provisioning solutions focus on a single or a limited set of objectives that may not simultaneously match the requirements of an increasing number of applications deployed in networks everyday. In this thesis, we formulate the Application-Aware Virtual Network Provisioning Problem (AVNP) and propose an adaptive provisioning framework for virtualized networks that takes into consideration the characteristics of multiple applications and their distinct performance objectives. The proposed framework is based on the concept of allocation paradigm, which is defined as a set of provisioning policies that guide the resource allocation process. A paradigm translates objectives from both Infrastructure Providers (InPs) and Service Providers (SPs) to individual allocation actions that actually provision VNs. To determine the efficiency of a particular paradigm, we propose a virtual network performance computation model to quantify the performance of allocated VNs and guide paradigm changing decisions. Simulation results show the feasibility of allocation paradigms in helping network providers to select the best provisioning strategy given a set of InP/SP objectives. Rafael Pereira Esteves, Lisandro Z. Granville |
IM | 2 |
| 2015 | Interactive monitoring, visualization, and configuration of OpenFlow-based SDNabstractSoftware-Defined Networking (SDN) is an emerging paradigm that arguably facilitates network innovation and simplifies network management. However, in the context of SDN, management activities, such as monitoring, visualization, and configuration can be considerably different from traditional networks. An SDN controller, for example, can be customized by network administrators according to their needs. Such customizations might pose an impact on resource consumption and traffic forwarding performance, which is difficult to assess without an SDN-devoted management system. In this paper, we initially present an analysis of control traffic in SDN aiming to better understand the impact of the communication between the controller and forwarding devices. Afterwards, we propose an interactive approach to SDN management through monitoring, visualization, and configuration that includes the administrator in the management loop. To show the feasibility of our approach a prototype has been developed. The results obtained with this prototype show that our approach can help the administrator to better understand the impact of configuring SDN-related parameters on the overall network performance. Pedro Heleno Isolani, Juliano Araújo Wickboldt, Cristiano Bonato Both, Juergen Rochol, Lisandro Z. Granville |
IM | 5 |
| 2015 | SDN interactive manager: An OpenFlow-based SDN managerabstractCurrently, many investigations addressed SDN management considering using monitoring information for different purposes. Zhang [1] used monitoring information to develop algorithms for anomaly detection and traffic engineering. Jose et al. [2] used the same monitoring information to propose mechanisms for online measurement of large traffic aggregates. Yu et al. [3] proposed FlowSense, which is aimed to keep the lowest control channel overhead and the highest information accuracy as possible in OpenFlow monitoring. Chowdhury et al. addressed SDN monitoring from a different perspective. The authors proposed Payless [4] framework that is able to deal with monitoring considering the polling frequency and data granularity. Payless relies on OpenTM [5] to select only important switches to be monitored, also aiming to reduce the overhead imposed in the control channel. Thus, this framework allows to adjust the polling frequency parameter to balance the control channel overhead, imposed by monitoring messages, and accuracy of monitored information. Pedro Heleno Isolani, Juliano Araújo Wickboldt, Cristiano Bonato Both, Juergen Rochol, Lisandro Z. Granville |
IM | 5 |
| 2015 | Policy authoring for software-defined networking managementabstractSoftware-Defined Networking (SDN) permits centralizing part of the decision-logic in controller devices. Thus, controllers can have an overall view of the network, assisting network programmers to configure network-wide services. Despite this, the behavior of network devices and their configurations are often written for specific situations directly in the controller. As an alternative, techniques such as Policy-Based Network Management (PBNM) can be used by business-level operators to write Service Level Agreements (SLAs) in a user-friendly interface without the need to change the code implemented in the controllers. In this paper, we introduce a framework for Policy Authoring to (i) facilitate the specification of business-level goals and (ii) automate the translation of these goals into the configuration of system-level components in an SDN. We use information from the network infrastructure obtained through SDN features and logic reasoning for analyzing policy objectives. As a result, experiments demonstrate that the framework performs well even when increasing the number of expressions in an SLA or increasing the size of the repository. Cristian Cleder Machado, Juliano Araújo Wickboldt, Lisandro Z. Granville, Alberto E. Schaeffer Filho |
IM | 3 |
| 2015 | Booters - An analysis of DDoS-as-a-service attacksabstractIn 2012, the Dutch National Research and Education Network, SURFnet, observed a multitude of Distributed Denial of Service (DDoS) attacks against educational institutions. These attacks were effective enough to cause the online exams of hundreds of students to be cancelled. Surprisingly, these attacks were purchased by students from Web sites, known as Booters. These sites provide DDoS attacks as a paid service (DDoS-as-a-Service) at costs starting from 1 USD. Since this problem was first identified by SURFnet, Booters have been used repeatedly to perform attacks on schools in SURFnet's constituency. Very little is known, however, about the characteristics of Booters, and particularly how their attacks are structure. This is vital information needed to mitigate these attacks. In this paper we analyse the characteristics of 14 distinct Booters based on more than 250 GB of network data from real attacks. Our findings show that Booters pose a real threat that should not be underestimated, especially since our analysis suggests that they can easily increase their firepower based on their current infrastructure. José Jair Santanna, Roland van Rijswijk-Deij, Rick Hofstede, Anna Sperotto, Mark Wierbosch, Lisandro Z. Granville, Aiko Pras |
IM | 6 |
| 2015 | Evaluating SNMP, NETCONF, and RESTful web services for router virtualization managementabstractIn network virtualization environments (NVEs), the physical infrastructure is shared among different users (or service providers) who create multiple virtual networks (VNs). As part of VN provisioning, virtual routers (VRs) are created inside physical routers supporting virtualization. Currently, the management of NVEs is mostly realized by proprietary solutions. Heterogeneous NVEs (i.e., with different equipment and technologies) are difficult to manage due to the lack of standardized management solutions. As a first step to achieve management interoperability, good performance, and high scalability, we implemented, evaluated, and compared four management interfaces for physical routers that host virtual ones. The interfaces are based on SNMP (v2c and v3), NETCONF, and RESTful Web Services, and are designed to perform three basic VR management operations: VR creation, VR retrieval, and VR removal. We evaluate these interfaces with regard to the following metrics: response time, CPU time, memory consumption, and network usage. Results show that the SNMPv2c interface is the most suitable one for small NVEs without strict security requirements and NETCONF is the best choice to compose a management interface to be deployed in more realistic scenarios, where security and scalability are major concerns. Paulo Roberto da Paz Ferraz Santos, Rafael Pereira Esteves, Lisandro Z. Granville |
IM | 3 |
| 2015 | Capitalizing on SDN-based SCADA systems: An anti-eavesdropping case-studyabstractPower grids are responsible for the transmission and distribution of electricity to end-users. These systems are undergoing a modernization process through the use of Information and Communication Technology (ICT), transforming the electric system into Smart Grids. In this context, Supervisory Control and Data Acquisition (SCADA) systems are responsible for the management and monitoring of substations and field devices. In this paper, we investigate the use of SDN as an approach to assist in the modernization of SCADA systems. We discuss its possible benefits, such as simplified management of power system resources. Moreover, SDN can facilitate the creation of new network applications that previously, with traditional networks, were more complex to be implemented. To illustrate the benefits of the use of SDN in SCADA, we designed a mechanism that aims to prevent a possible eavesdropper from fully capturing communication flows between SCADA components. The mechanism was implemented as an SDN-based application for SCADA systems that uses multipath routing, which relies on SDN features to frequently modify communication routes between SCADA devices. Further, we performed an experimental evaluation to verify the impact and performance of the mechanism in the SCADA network. Eduardo Germano da Silva, Luis Augusto Dias Knob, Juliano Araújo Wickboldt, Luciano Paschoal Gaspary, Lisandro Z. Granville, Alberto E. Schaeffer Filho |
IM | 5 |
| 2015 | An EC-based formalism for policy refinement in software-defined networkingabstractSoftware-Defined Networking (SDN) provides a sophisticated and accurate solution for managing network traffic. SDN logically centralizes, in devices called controllers, part of the decision-making logic of flow processing and packet routing. The whole network is controlled according to rules written and deployed in the controller device. However, the large amount of network devices, links, and services also gives rise to a large number of rules to be managed in the controller. Policy-Based Network Management (PBNM) can be used to manage complex network infrastructures through policies rather than specifying device-by-device configurations. Particularly, policy refinement techniques can be used to automatically translate high-level policies into a set of low-level ones. In this paper, we define a formal representation of high-level SLA policies using Event Calculus (EC) and apply logical reasoning to model both the system behavior and the policy refinement process for SDN management. We also describe the implementation of this formal model in Prolog, which enables the automatic inference of low-level policies from high-level ones, and present evaluation results. Cristian Cleder Machado, Juliano Araújo Wickboldt, Lisandro Z. Granville, Alberto E. Schaeffer Filho |
ISCC | 3 |
| 2015 | The interplay between timeliness and scalability in cloud monitoring systemsabstractCloud computing is a groundbreaking solution to acquire computational resources on demand. To deliver high quality cloud services and provide features such as reduced costs and availability to customers, a cloud, like any other computational system, needs to be properly managed in accordance with its characteristics (e.g., scalability, elasticity, timeliness). In this scenario, cloud monitoring is a key to achieve it. To properly work, cloud monitoring systems need to meet several requirements such as scalability, accuracy, and timeliness. This paper aims to unveil the trade-off between timeliness and scalability. Evaluations demonstrate the mutual influence between scalability and timeliness based on monitoring parameters (e.g., monitoring topologies, frequency sampling). Results show that non-deep monitoring topologies and decreasing the frequency sampling assist to reduce the mutual influence between timeliness and scalability. Guilherme da Cunha Rodrigues, Rodrigo N. Calheiros, Marcio Barbosa de Carvalho, Carlos Raniery Paula dos Santos, Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco, Rajkumar Buyya |
ISCC | 5 |
| 2015 | A DTLS-based security architecture for the Internet of ThingsabstractThe Internet of Things (IoT) is part of the Future Internet. IoT comprises a huge amount of devices (hereinafter called as constrained devices) able to interact with the environment and to communicate over the Internet. Among other challenges that prevents the growth of IoT, the IoT is challenged for security issues. In this work, we are mainly interested in secure communication concerns for constrained devices. In essence, constrained devices are devices operating under low-power, and with limited computational and network resources. For such characteristics, they do not support standard security protocols and, consequently, they become a potential target for traditional Internet attacks (e.g., Denial of Service and man-in-the-middle). Thus, we introduce an architecture to enable constrained devices to use Datagram Transport Layer Security (DTLS) with mutual authentication to communicate with Internet devices. Briefly, we propose a third part device called Internet of Things Security Support Provider (IoTSSP) and two main mechanisms: (i) the Optional Handshaking Delegation, and (ii) the Transfer of Session. Experimental results show the proposal feasibility and its additional benefits. Glederson Lessa dos Santos, Vinicius Tavares Guimaraes, Guilherme da Cunha Rodrigues, Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco |
ISCC | 4 |
| 2015 | App2net: A platform to transfer and configure applications on programmable virtual networksabstractIn programmable virtual networks, simple tasks, like installing software, can be extremely complex. This complexity occurs mainly because the code transfer and initial functional settings in network execution environments are not automated. In addition, the same tasks have different requirements in each service lifecycle stage. In this sense, we propose the App2net platform for enabling the transfer and configuration of network applications in programmable virtual networks that use heterogeneous execution environments. We also propose a taxonomy for grouping code transfer techniques and, based on such techniques, we develop models for code transfer. A prototype has been implemented and tested on realistic network topologies commonly found on the Internet. Results allow us to identify which models improve code transfer consuming fewer resources, regarding service lifecycle stages and network topologies. Ricardo Luis dos Santos, Oscar M. Caicedo, Juliano Araújo Wickboldt, Lisandro Z. Granville |
ISCC | 4 |
| 2015 | Identification and Selection of Flow Features for Accurate Traffic Classification in SDNabstractSoftware-Defined Networking (SDN) aims to alleviate the limitations imposed by traditional IP networks by decoupling network tasks performed on each device in particular planes. This approach offers several benefits, such as standard communication protocols, centralized network functions, and specific network elements, for example, controller devices. Despite these benefits, there is still a lack of adequate support for performing tasks related to traffic classification, because (i) there are traffic profiles that are very similar, which makes their classification difficult (e.g., Both HTTP and DNS flows are characterized by packet bursts), (ii) Open Flow, the key SDN implementation today, only offers native flow features, such as packet and byte count, that do not describe intrinsic traffic profiles, and (iii) there is a lack of support to determine what is the optimal set of flow features to characterize different types of traffic profiles. In this paper, we introduce an architecture to collect, extend, and select flow features for traffic classification in Open Flow-based networks. The main goal of our solution is to offer an extensive set of flow features that can be analyzed and refined and to be capable of finding the optimal subset of features to classify different types of traffic flows. The experimental evaluation of our proposal shows that some features emerge as meaningful, occupying the top positions for the classification of distinct flows in different experimental scenarios. Anderson Santos da Silva, Cristian Cleder Machado, Rodolfo Vebber Bisol, Lisandro Z. Granville, Alberto E. Schaeffer Filho |
NCA | 4 |
| 2015 | Adaptive threshold architecture for spectrum sensing in public safety radio channelsabstractCognitive radio make use of spectrum sensing techniques to detect licensed users transmissions and avoid causing interference. The major drawback in current spectrum sensing techniques is the use of static decision thresholds to detect such transmissions, which may be infeasible in public safety radio channels. More precisely, the cognitive radio may find different noise or interference levels when switching among these channels. This can lead to a wrong picture of the channel occupancy status, which in turn can increase the interference caused to licensed users. In this paper we propose an Adaptive Threshold Architecture, which uses machine learning algorithms to dynamically adapt the decision threshold, enabling the detection of licensed users transmissions in public safety radio channels. Results showed that the proposed architecture increased the sensing accuracy up to 2 times, providing results up to 6 times faster when compared to other solutions of the literature. Maicon Kist, Leonardo Roveda Faganello, Lucas Bondan, Marcelo Antonio Marotta, Lisandro Z. Granville, Juergen Rochol, Cristiano Bonato Both |
WCNC | 5 |
| 2015 | Managing mobile cloud computing considering objective and subjective perspectives
Marcelo Antonio Marotta, Leonardo Roveda Faganello, Matias A. K. Schimuneck, Lisandro Z. Granville, Juergen Rochol, Cristiano Bonato Both |
Comput. Networks | 4 |
| 2015 | Towards automated composition of convergent services: A survey
Armando Ordóñez 0001, Vidal Alcázar, Oscar M. Caicedo, Paolo Falcarin, Juan Carlos Corrales, Lisandro Z. Granville |
Comput. Commun. | 6 |
| 2014 | Towards SLA Policy Refinement for QoS Management in Software-Defined NetworkingabstractSoftware-Defined Networking (SDN) is a dynamic, adaptable, controllable and flexible network architecture. It provides an extensible platform for delivery of network services, capable of responding quickly to service requirement changes. As a result, SDN has become a suitable scenario for the application of techniques and approaches for improved infrastructure management, such as Policy-Based Management (PBM). In PBM, using techniques such as refinement, a high-level policy-e.g., specified as a Service Level Agreement (SLA) - can be translated into a set of corresponding low-level rules, enforceable in various elements of a system. However, when using SLAs, their translation to low-level policies, e.g., for controller configuration, is not straightforward. If this translation is not done properly, the controller may not be able to meet the implicit requirements of the SLA, failing to satisfy the goals described in the high-level policy. This paper proposes a novel approach towards SLA policy refinement for Quality of Service (QoS) management (based on routing) in Software-Defined Networking. It consists of an initial manual process performed by an administrator, followed by an automatic policy refinement process executed by an OpenFlow controller. As a result, our approach is capable of identifying the requirements and resources that need to be configured in accordance with SLA refinement, and can successfully configure and execute reactive dynamic actions for supporting dynamic infrastructure reconfiguration. Cristian Cleder Machado, Lisandro Z. Granville, Alberto E. Schaeffer Filho, Juliano Araújo Wickboldt |
AINA | 2 |
| 2014 | On the Use of Traffic Information to Improve the Coordinated P2P Detection of SLA ViolationsabstractCritical networked services are usually regulated by Service Level Agreements (SLAs). In order to ensure SLAs are being met, it is necessary to monitor Service Level Objectives (SLOs). Active measurement mechanisms are usually chosen to perform this monitoring task, which requires measurement probes to be activated in network devices. However, these probes are expensive in terms of computational resources consumption, thus, active measurement mechanisms usually can cover only a fraction of what could be measured, which can lead to SLA violations being missed. Besides that, highly dynamic networking patterns require the ongoing selection of the candidate network destinations for probing and their respective prioritization, a practice that is not well suited for human administrators because configuring the probes is labor-intensive and error-prone. A possibility to improve the detection of SLA violations is the employment of Peer-to-Peer (P2P) technology in order to steer tasks related to a distributed decision making process for probe activation. In this context, a P2P management overlay can be used to coordinate the probe activation and to share measurement results among the network devices. For a node to rely on measurement data from a peer to determine which probes to configure, it needs to know which of the peers are best correlated with itself, i.e., which nodes have the most significance in terms of being indicative of service level violations that might be observed by the node itself. We propose an autonomic P2P solution to coordinate the placement of active measurement probes in large-scale networks. The edge nodes of the network cooperate via a P2P management overlay to determine what destinations should be monitored. Each edge node determines autonomously what destinations to probe considering local measurements and measurement data from other edge nodes. The measurements considered are traffic information from passive measurement results and past service level measurement results from active measurement results. The proposed solution is evaluated using simulation and the results show its feasibility and interesting features. Jéferson Campos Nobre, Lisandro Z. Granville, Alexander Clemm, Alberto Gonzalez Prieto |
AINA | 2 |
| 2014 | An Approach to Overcome the Complexity of Network Management Situations by MashmentsabstractThe work performed by network administrators to address sudden, dynamic, heterogeneous, and time specific situations that happen in the network management domain is complex. In this paper, we introduce an approach that allows network administrators to overcome the complexity of handling these network management situations (called NMSits). The approach is made up of Mashments that are special mashups used to cope with NMSits, the process to develop and execute Mashments, and the Mashment Maker that supports such model and process. We use IT Service Management metrics to evaluate our approach, measuring the complexity of facing, with and without the Maker, a specific NMS it that occurs in several networks based on the Software Defined Networking paradigm. The evaluation results demonstrate that the complexity decreases when network administrators use our approach to handle NMSits. Oscar M. Caicedo, Felipe Estrada Solano, Lisandro Z. Granville |
AINA | 3 |
| 2014 | On using P2P technology to enable opportunistic management in DTNs through statistical estimationabstractDisruption-Tolerant Networks (DTNs) are characterized by long delays and constant disconnections among nodes. These networks have management needs analogous to those of traditional computer networks, but, their intrinsic characteristics (e.g., intermittent connections) hinder the execution of network management tasks. The employment of P2P technology is an alternative for managing DTNs since this technology promotes the autonomy of management entities (i.e., management peers). This autonomy enables the use of local logic and data in order to perform opportunistic management tasks. We propose a solution to estimate the future contacts of nodes through distributed statistical analysis of past contacts. Besides that, nodes can share information about their contacts to improve contact estimation using a P2P management overlay. The proposed solution was implemented using an open source P2P-Based Network Management (P2PBNM) system, ManP2P-ng. Furthermore, the solution was evaluated through experiments performed using publicly available DTN traces. The results show that the proposed solution can improve the execution of management tasks in DTNs. Jéferson Campos Nobre, Pedro Arthur Pinheiro Rosa Duarte, Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco, Fabio Junior Bertinatto |
ICC | 3 |
| 2014 | Efficient configuration of monitoring slices for cloud platform administratorsabstractMonitoring is an important issue in cloud environments because it assures that acquired cloud slices attend the user's expectations. However, these environments are multitenant and dynamic, requiring automation techniques to offload cloud administrators. In a previous work, we proposed FlexACMS: a framework to automate monitoring configuration related to cloud slices using multiple monitoring solutions. In this work, we enhanced FlexACMS to allow dynamic and automatic attribution of monitoring configuration tasks to servers without administrator intervention, which was not available in previous version. FlexACMS also considers the monitoring server load when attributing configuration tasks, which allows load balancing between monitoring servers. The evaluation showed that enhancements reduced FlexACMS response time up to 60% in comparison to previous version. The scalability evaluation of enhanced version demonstrated the feasibility of our approach in large scale cloud environments. Marcio Barbosa de Carvalho, Rafael Pereira Esteves, Guilherme da Cunha Rodrigues, Clarissa Cassales Marquezan, Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco |
ISCC | 5 |
| 2014 | Kitsune: A management system for cognitive radio networks based on spectrum sensingabstractSoftware defined radio enables the improvement of the radio-frequency spectrum utilization through the design of cognitive radio devices. The implementation of these devices must be based on spectrum sensing function searching for vacant channels and, opportunistically, transmit over these channels in a cognitive radio network. Therefore, the configuration, monitoring and visualization of the spectrum sensing function are fundamentals to the continuous learning process of the network administrator. In this paper we propose Kitsune, a management system based on a hierarchical model allowing to manage summarized information about the spectrum sensing function in a cognitive radio networks. Moreover, a Kitsune prototype was developed and evaluated through a real IEEE 802.22 scenario using TV channels to Internet access. Results shown that Kitsune allows network administrator to achieve a higher knowledge about behavior of the users and improve the average throughput for each channel. Lucas Bondan, Marcelo Antonio Marotta, Maicon Kist, Leonardo Roveda Faganello, Cristiano Bonato Both, Juergen Rochol, Lisandro Z. Granville |
NOMS | 7 |
| 2014 | Evaluating allocation paradigms for multi-objective adaptive provisioning in virtualized networksabstractRecent advances in virtualization technology have made it possible to partition a network into multiple virtual networks managed by different users. Although virtual networks share the same physical infrastructure, they host diverse applications with different goals. Unfortunately, current virtual network provisioning solutions have only focused on achieving a single objective that may not be suited for all the applications deployed across the network. In this paper, we propose an adaptive provisioning framework for virtualized networks that takes into consideration the characteristics of multiple applications and their distinct performance objectives. The proposed framework is based on the concept of allocation paradigm, which is defined as a set of application-driven provisioning policies that guide the resource allocation process. To determine the efficiency of a particular paradigm, we propose a virtual network performance computation model based on data measured from existing benchmarks. Simulation results show that our model helps network providers to select the best allocation paradigms in terms of provisioning quality. Rafael Pereira Esteves, Lisandro Z. Granville, Mohamed Faten Zhani, Raouf Boutaba |
NOMS | 2 |
| 2014 | Monitoring Virtual Nodes using mashups
Oscar M. Caicedo, Carlos Raniery Paula dos Santos, Arthur Selle Jacobs, Lisandro Z. Granville |
Comput. Networks | 4 |
| 2014 | Resource management in IaaS cloud platforms made flexible through programmability
Juliano Araújo Wickboldt, Rafael Pereira Esteves, Marcio Barbosa de Carvalho, Lisandro Z. Granville |
Comput. Networks | 4 |
| 2014 | Efficient Model Checking of IT Change OperationsabstractThe success of businesses in modern organizations heavily depends on the high availability of information technology (IT) infrastructures. To prevent business disruption, IT operators have worked hard to ensure that any changes to this infrastructure are properly and efficiently deployed. Change management - a discipline of the Information Technology Infrastructure Library (ITIL) - provides important guidance to help achieve this end. As IT infrastructures grow larger, however, ensuring that changes are harmless to business continuity becomes increasingly complex. In fact, previous research has shown that existing approaches for verifying changes suffer from severe scalability issues. This problem can become a serious threat to most organizations, as it can lead for example to customer dissatisfaction due to missed deadlines in service change deployment. To bridge this gap, we propose a partial-order reduction model checking paradigm and algorithm for efficiently detecting harmful change operations. Our model improves the complexity of verifying a set of concurrent change activities against safety constraints by reducing - without losing effectiveness - the verification scope. To prove concept and technical feasibility, we carried out an extensive performance evaluation of our algorithm considering a variety of change activities, safety constraints, and configuration scenarios. The results obtained from 32 benchmarks have shown that our algorithm significantly outperformed state-of-the-art, general purpose model checkers, improving the runtime complexity from polynomial/exponential to linear. In summary, the results evidenced that change verification finally became feasible and efficient for larger IT infrastructures. Sebastian Hagen, Weverton Luis da Costa Cordeiro, Luciano Paschoal Gaspary, Lisandro Z. Granville, Alfons Kemper |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2013 | A cloud monitoring framework for self-configured monitoring slices based on multiple toolsabstractThe monitoring of cloud computing environments is a key point to assure the availability of the cloud slices offered to cloud users. However, there are not any monitoring systems that satisfy all the cloud administrator requirements which imposes that cloud slices need to be monitored by a set of monitoring systems. The set of monitoring system configuration necessary to monitor a cloud slice and the corresponding set of monitored metrics we define as a monitoring slice. Unfortunately, the monitoring slices need to be built using solutions that are not integrated with cloud platforms. This lack of integration imposes that cloud administrators manually configure the monitoring solutions or develop scripts to automate this task. In this paper we propose a framework to address the problem of creating monitoring slices automatically independent of the monitoring solutions employed. To evaluate our proposed framework in an IaaS scenario, we develop FlexACMS, flexible automate cloud monitoring slices, which relies on a modules that flexibly handles cloud platforms and monitoring solutions. Marcio Barbosa de Carvalho, Rafael Pereira Esteves, Guilherme da Cunha Rodrigues, Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco |
CNSM | 4 |
| 2013 | ProViNet - An Open Platform for Programmable Virtual Network ManagementabstractThe disheartening and thorny path followed while deploying new solutions in the core of current computer networks, culminates in a low rate of emergence of innovation. Several researches proposed applying Software Defined Networks (SDN) and the Network Virtualization (NV) concepts to reverse this rate. However, many gaps and open challenges were observed in the application of these concepts together. In this paper, we propose the ProViNet platform, which merge the SDN and NV concepts to provide a fast and safe deployment of innovations in the existing network infrastructure. ProViNet advance the state-of-art introducing the concept of Network Programming as a Service, in which applications are built simply by composing control plane services. Such approach encourages End-Users to develop and share novel network solutions, fostering innovation. To prove concept and technical feasibility, we evaluate ProViNet with a prototype that allowed demonstrating virtual network infrastructure provisioning and programming. Wanderson Paim de Jesus, Juliano Araújo Wickboldt, Lisandro Z. Granville |
COMPSAC | 3 |
| 2013 | A Mashup-Based Approach for Virtual SDN ManagementabstractThe Software Defined Networks paradigm aided by the Network Virtualization is a key driver to cope the Internet ossification. There are different proposals to deploy this paradigm, but there is not an integrated or standardized way for the management of networks built with such proposals. In this sense, the network management becomes too complex because multiple solutions must be used by Network Administrators to perform their tasks. In this paper, we introduce a mashup-based approach that allows Network Administrators to customize and combine management solutions, in order to they build composite applications (called SDN Mashups) aiming the integrated management of Virtual Software Defined Networks in heterogeneous environments. We evaluate our approach by building a SDN Mashup for the management of a network slice that uses three distinct Network Operating Systems and by running performance tests, corroborating that the mashup built has small response time. Oscar M. Caicedo, Felipe Estrada Solano, Lisandro Z. Granville |
COMPSAC | 3 |
| 2013 | A mashup ecosystem for network management situationsabstractCurrent network management approaches and their implementations are not intended to address dynamic situations that need rapid delivery of good-enough and comprehensive solutions. In this paper, we introduce a novel mashup ecosystem, called Mashment Ecosystem, that allows Network Administrators to conduct on a Mashment Maker the activities and interactions necessary to provide Mashments. Mashments are mashups aimed to tackle network management situations. We evaluate the Mashment Ecoystem by estimating with the Keystroke-Level Model and measuring in a test scenario the time that Network Administrators take to perform the activities of creating, launching, and publishing Mashments. Similarly, we evaluate the time for retrieving information about a network management situation by using or not Mashments. The evaluation results corroborated that Network Administrators, in our ecosystem, need short-time to deal with network management situations. Oscar M. Caicedo, Felipe Estrada Solano, Lisandro Z. Granville |
GLOBECOM | 3 |
| 2013 | Coordination in P2P management overlays to improve decentralized detection of SLA violationsabstractCritical networked services enable significant revenue for network operators and, in turn, are regulated by Service Level Agreements (SLAs). In order to ensure SLAs are being met, service levels need to be monitored. One technique for this involves active measurement mechanisms which employ measurement probes along the network to inject synthetic traffic and compute the network performance. However, these mechanisms are expensive in terms of resources consumption. Thus, active measurement mechanisms usually can cover only a fraction of what could be measured, which can lead to SLA violations being missed. Besides that, the definition of this fraction is a practice done by human administrators, which does not scale well and does not adapt to highly dynamic networking patterns. The contribution of the present work is the proposal of a solution to increase the potential number of detected SLA violations in which network devices autonomously and dynamically share service level measurement results. The sharing of these measurement results is based on the utilization of a Peer-to-Peer (P2P) management overlay built using past service level measurement results and a coordination strategy characterized by a high degree of decentralized decision making. The solution is evaluated using simulation and the results show its feasibility and interesting features. Jéferson Campos Nobre, Lisandro Z. Granville, Alexander Clemm, Alberto Gonzalez Prieto |
ICC | 2 |
| 2013 | Paradigm-based adaptive provisioning in virtualized data centers
Rafael Pereira Esteves, Lisandro Z. Granville, Hadi Bannazadeh, Raouf Boutaba |
IM | 2 |
| 2013 | Delay-tolerant management using self-∗ properties and P2P technology
Jéferson Campos Nobre, Pedro Arthur Pinheiro Rosa Duarte, Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco |
IM | 3 |
| 2013 | On tackling virtual data center embedding problem
Md. Golam Rabbani, Rafael Pereira Esteves, Maxim Podlesny, Gwendal Simon, Lisandro Z. Granville, Raouf Boutaba |
IM | 5 |
| 2013 | Quality improvement and quantitative modeling - Using mashups for human error prevention
Carlos Raniery Paula dos Santos, Lisandro Z. Granville, Larisa Shwartz, Nikos Anerousis, David Loewenstern |
IM | 2 |
| 2013 | Identifying the root cause of failures in IT changes: Novel strategies and trade-offs
Ricardo Luis dos Santos, Juliano Araújo Wickboldt, Bruno Lopes Dalmazo, Lisandro Z. Granville, Luciano Paschoal Gaspary, Roben Castagna Lunardi |
IM | 4 |
| 2013 | Rethinking cloud platforms: Network-aware flexible resource allocation in IaaS clouds
Juliano Araújo Wickboldt, Lisandro Z. Granville, Fabian Schneider 0001, Dominique Dudkowski, Marcus Brunner |
IM | 2 |
| 2013 | Self-* properties and P2P technology on disruption-tolerant managementabstractThe introduction of self-* properties has been proven to be a feasible approach for the management demands of Disruption-Tolerant Networks (DTNs). Among the properties of the self-* management vision, self-healing figures as a key property to improve the dependability of the managed infrastructures. An interesting possibility to materialize self-* support in disruption-tolerant management is through the employment of Peer-to-Peer (P2P) technology. In this paper, we introduce a P2P self-healing service tailored for disruption-tolerant management. We implemented the proposed service using ManP2P-ng, an open source P2P-based network management system. In addition, an experimental evaluation is performed considering as case study the disruption-tolerant management of a Host-based Intrusion Detection System (HIDS) deployed on a specific kind of DTN: Internet access networks for remote villages. The results show the feasibility of our proposal and its interesting features. Jéferson Campos Nobre, Pedro Arthur Pinheiro Rosa Duarte, Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco |
ISCC | 3 |
| 2013 | Improving reinforcement learning algorithms for dynamic spectrum allocation in cognitive sensor networksabstractCognitive Radio Networks enable a higher number of users to access the spectrum of frequency simultaneously. This access is possible due to the implementation of dynamic spectrum allocation algorithms. In this context, one of the main algorithms found in the literature is the reinforcement learning based approach called Q-Learning. Although been widely applied, this algorithm does not take into account accurate information about the behavior of users neither the channel propagation conditions. In this sense, we propose three improvements to the dynamic spectrum allocation algorithms based on reinforcement learning for cognitive sensor networks. Simulation results show that all the proposed algorithms allow allocating channels with up to 6dB better quality and 4% higher efficiency than Q-Learning. Leonardo Roveda Faganello, Rafael Kunst, Cristiano Bonato Both, Lisandro Z. Granville, Juergen Rochol |
WCNC | 4 |
| 2012 | Planning in the large: Efficient generation of IT change plans on large infrastructures
Sebastian Hagen, Weverton Luis da Costa Cordeiro, Luciano Paschoal Gaspary, Lisandro Z. Granville, Michael Seibold, Alfons Kemper |
CNSM | 4 |
| 2012 | Decentralized detection of SLA violations using P2P technology
Jéferson Campos Nobre, Lisandro Z. Granville, Alexander Clemm, Alberto Gonzalez Prieto |
CNSM | 2 |
| 2012 | A new approach to the design of flexible cloud management platforms
Juliano Araújo Wickboldt, Lisandro Z. Granville, Fabian Schneider 0001 |
CNSM | 2 |
| 2012 | Internet of Things in healthcare: Interoperatibility and security issuesabstractInternet of Things devices being used now expose limitations that prevent their proper use in healthcare systems. Interoperability and security are especially impacted by such limitations. In this paper, we discuss today's issues, including benefits and difficulties, as well as approaches to circumvent the problems of employing and integrating Internet of Things devices in healthcare systems. We present this discussion in the context of the REMOA project, which targets a solution for home care/telemonitoring for patients with chronic illnesses. Liane Margarida Rockenbach Tarouco, Leandro Marcio Bertholdo, Lisandro Z. Granville, Lucas Mendes Ribeiro Arbiza, Felipe Jose Carbone, Marcelo Antonio Marotta, José Jair Santanna |
ICC | 3 |
| 2012 | A BPM-based solution for inter-domain circuit managementabstractIn the last few years, network middleware solutions have been proposed to deal with Quality of Service (QoS) demands of end-user network applications. Usually, such solutions employ virtual circuits, with end-points often located in different administrative domains. However, these middleware solutions still do not support online human decisions. The human-centered support is specially important when pre-installed rules do not suffice to evaluate virtual circuit requests. In this paper, we present a middleware for dynamic circuit networks (DCNs) based on the Business Process Management (BPM) approach to support human administrator decisions in virtual circuits provisioning. A set of experiments have been conducted in the Brazilian National Education and Research Network (RNP) backbone, and the findings in performance and flexibility are presented. José Jair Santanna, Juliano Araújo Wickboldt, Lisandro Z. Granville |
NOMS | 3 |
| 2012 | A self-adapting connection admission control solution for mobile WiMAX: Enabling dynamic switching of admission control algorithms based on predominant network usage profiles
Cristiano Bonato Both, Clarissa Cassales Marquezan, Rafael Kunst, Lisandro Z. Granville, Juergen Rochol |
J. Netw. Comput. Appl. | 4 |
| 2011 | Performance management and quantitative modeling of IT service processes using mashup patterns
Carlos Raniery Paula dos Santos, Lisandro Z. Granville, Winnie Cheng, David Loewenstern, Larisa Shwartz, Nikos Anerousis |
CNSM | 2 |
| 2011 | Incorporating virtualization awareness in service monitoring systemsabstractTraditional service monitoring systems (e.g., Nagios and Cacti) have been conceived to monitor services hosted in physical computers. With the recent popularization of server virtualization platforms (e.g., Xen and VMware), monitored services can migrate from a physical computer to another, invalidating the original monitoring logic. In this paper, we investigate which strategies should be used to modify traditional service monitoring systems so that they can still provide accurate status information even for monitored services that are constantly moving on top of a set of servers with virtualization support. Marcio Barbosa de Carvalho, Lisandro Z. Granville |
Integrated Network Management | 2 |
| 2011 | On the use of SNMP as a management interface for virtual networksabstractVirtual networks emerged as an alternative for network infrastructure provision. However, the growth in users demand for shared resources over network elements increase allocation complexity. Thus, enabling effective management on each node is key to the global network operation. This work investigate the use of SNMP as a management interface for virtual routers in order to support automation and provide optimal use of physical assets. The solution was evaluated in two virtualization platforms (Xen and VMware) in order the verify the advantages and limitations of the proposed management interface. Fabio Fabian Daitx, Rafael Pereira Esteves, Lisandro Z. Granville |
Integrated Network Management | 3 |
| 2011 | Leveraging IT project lifecycle data to predict support costsabstractThere is an intuitive notion that the costs associated with project support actions, currently deemed too high and increasing, are directly related to the effort spent during their development and test phases. Despite the importance of systematically characterizing and understanding this relationship, little has been done in this realm mainly due to the lack of proper tooling for both sharing information between IT project phases and learning from past experiences. To tackle this issue, in this paper we propose a solution that, leveraging existing IT project lifecycle data, is able to predict support costs. The solution has been evaluated through a case study based on the ISBSG dataset, producing correct estimates for more than 80% of the assessed scenarios. Bruno Lopes Dalmazo, Weverton Luis da Costa Cordeiro, Abraham Lincoln Rabelo de Sousa, Juliano Araújo Wickboldt, Roben Castagna Lunardi, Ricardo Luis dos Santos, Luciano Paschoal Gaspary, Lisandro Z. Granville, Claudio Bartolini, Marianne Hickey |
Integrated Network Management | 8 |
| 2011 | A P2P-Based self-healing service for network maintenanceabstractThe introduction of self-* properties over distributed network management infrastructures has been proving to be a feasible approach for the new demands of modern network management. Among the properties of the self-* management vision, self-healing figures as key property in improving the dependability of the managed infrastructures. An interesting possibility to materialize self-* support - and self-healing support as well - in network management is through the employment of peer-to-peer (P2P) management overlays. Considering this scenario, we introduce in this paper a self-healing service provided by a prototype P2P-Based Network Management (P2PBNM) system. Such a service is expected to be contracted by human administrators interested in monitoring and recovering their IT infrastructures. In addition, an experimental evaluation of the self-healing service is performed considering a case study where a Host-based Intrusion Detection System (HIDS) needs to be constantly observed and eventually healed to keep the underlying communication network protected. Pedro Arthur Pinheiro Rosa Duarte, Jéferson Campos Nobre, Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco |
Integrated Network Management | 3 |
| 2011 | On the investigation of the joint use of self-* properties and Peer-To-Peer for network managementabstractOver the years, the network management community has been face to the need of designing new alternative management approaches able to support heterogeneity, scalability, reliability, and minor human intervention. Currently, there are two major alternatives that have been employed on the design and development of network management solutions. The first one uses autonomic computing and self-* properties, while the second one employs Peer-To-Peer (P2P) concepts and technologies. In the case of autonomic and self-* properties, there is a lack of investigations approximating the high level models to the management infrastructure, while P2P investigations suffer from the opposite problem. This thesis aims at bringing knowledge to issues involving the joint use of self-* properties and P2P. The major contributions of this thesis are: (i) a survey relating autonomic computing and self-* properties, P2P, and network and service management; (ii) the combination of techniques to explore parallel and cooperative behavior of management peers running the management algorithms; (iii) algorithms that embed managers into the managed environment instead of using managers on the borders of such environment; (iv) the change on the angle of network management solution development from morphological aspects (such as APIs, protocols, architectures, and frameworks) to the design of management algorithms. Clarissa Cassales Marquezan, Lisandro Z. Granville |
Integrated Network Management | 2 |
| 2011 | A characterization study of SNMP usage patternsabstractThe Simple Network Management Protocol (SNMP), proposed almost 20 years ago, still remains as the de facto standard for TCP/IP networks managing. However, there are few studies that present the real usage of SNMP in production networks. This work aims at presenting a characterization study that was performed over a sample of the management traffic from the Brazilian Education and Research Network (RNP). The achieved results may help both academy and industry in the development of new technologies for managing networks, in order to better meet the needs of the production networks users and administrators. Ewerton Monteiro Salvador, Jussara M. Almeida, José Marcos S. Nogueira, Paulo Teles Barbosa, Lisandro Z. Granville |
Integrated Network Management | 5 |
| 2011 | A data confidentiality architecture for developing management mashupsabstractMashups are powerful applications created from accessing and composing multiple and distributed information sources. Their ease-of-use and modularity allow users at any skill level to construct, share and integrate their own applications. However, data security concerns remain a hindering factor in its widespread adoption, in particular, for network management. In this paper, we propose a novel development methodology and system architecture called Maestro that allows developers to express their data privacy concerns and enforce policies during mashup executions. We evaluated Maestro by building two mashup applications for managing live networks and by running performance tests that show that our runtime has negligible overhead. Carlos Raniery Paula dos Santos, Rafael Santos Bezerra, Lisandro Z. Granville, Leandro Marcio Bertholdo, Winnie Cheng, Nikos Anerousis |
Integrated Network Management | 3 |
| 2011 | A solution for identifying the root cause of problems in IT change managementabstractThe reuse of knowledge acquired by operators to diagnose failures in Information Technology (IT) infrastructures has potential to decrease the recurrence of failures and, consequently, reduce possible losses and maintenance costs. Nevertheless, existing solutions to support failure diagnosis lack of flexibility to adapt to a constantly changing IT environment. As a result, diagnostic is performed in an ad hoc and static fashion, which hampers the reuse of knowledge to solve similar failures affecting different elements of an IT infrastructure. To bridge this gap, in this paper we propose an extension of Common Information Model (CIM), supported by a conceptual solution for the identification of the root causes of problems, adaptable to changes in the target infrastructure and applicable to similar failures. Experiments carried out considering typical failures during the deployment of IT changes provide evidence about the efficacy of the proposed solution. Ricardo Luis dos Santos, Juliano Araújo Wickboldt, Roben Castagna Lunardi, Bruno Lopes Dalmazo, Lisandro Z. Granville, Luciano Paschoal Gaspary, Claudio Bartolini, Marianne Hickey |
Integrated Network Management | 5 |
| 2011 | On the impact of hybrid errors on mobile WiMAX networks
Rafael Kunst, Cristiano Bonato Both, Lisandro Z. Granville, Juergen Rochol |
Comput. Networks | 3 |
| 2011 | A framework for risk assessment based on analysis of historical information of workflow execution in IT systems
Juliano Araújo Wickboldt, Luís Armando Bianchin, Roben Castagna Lunardi, Lisandro Z. Granville, Luciano Paschoal Gaspary, Claudio Bartolini |
Comput. Networks | 4 |
| 2010 | Similarity metric for risk assessment in IT change plansabstractThe proper management of IT infrastructures is essential for organizations that aim to deliver high quality services. Given the dynamics of these infrastructures, changes become imminent. In some cases, these changes might raise failures, causing disruption to provided services and consequently affecting the business continuity. Therefore, it is strongly recommended to evaluate the risks associated with changes before their actual execution. Learning from information of past deployed changes it is possible to estimate the risks for recently planned ones. Thereby, in this paper, we propose a solution to weigh the information available from past executed plans by the similarity calculated in relation with the analyzed change plan. A prototype system has been developed in order to evaluate the effectiveness of the solution over an emulated IT infrastructure. The results obtained show that the solution is capable of capturing similarity among activities in change plans, improving the accuracy of risk assessment for IT change planning. Luís Armando Bianchin, Juliano Araújo Wickboldt, Lisandro Z. Granville, Luciano Paschoal Gaspary, Claudio Bartolini, Maher Rahmouni |
CNSM | 3 |
| 2010 | Botnet master detection using a mashup-based approachabstractBotnets are considered by specialists, in both industry and academy, as one of the greatest threats to security on the Internet. These networks are composed by a large number of malware-infected hosts acting under a central command. They are usually employed to perform DDoS attacks or phishing scams. The behaviour of these botnets evolves due the adoption of new and sophisticated infection methods, changing of network protocols, and the employment of different command and control mechanisms. The security community, thus, is always dealing with such constant change. However, most botnet mitigation methods address just specific infection types or C&C protocols. We, therefore, propose a botnet mitigation approach based on the dynamic integration of pre-existing tools that can be employed together to achieve a more efficiently detection solution. To such end, we base our approach on a novel Web 2.0 technology called mashups to perform the information correlation. The proposal is extensible enough to allow even non-security information such as online mapping APIs be integrated to create more sophisticated compositions, and displaying the results in a more meaningful way. Carlos Raniery Paula dos Santos, Rafael Santos Bezerra, João M. Ceron, Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco |
CNSM | 4 |
| 2010 | On the Impact of Using Presence Services in P2P-Based Network Management SystemsabstractThe use of notifications to inform the status of network devices and software to network administrators has a crucial function to guarantee the correct network operations and to prevent unnecessary costs. Presence services have been designed with the objective to provide ways to deliver presence information to interested parties, however they are used only in communications systems. In this paper we thus present a proposal that aims to using presence services in P2P-based network management systems. Carlos Raniery Paula dos Santos, Sérgio Luis Cechin, Lisandro Z. Granville, Maria Janilce Bosquiroli Almeida, Liane Margarida Rockenbach Tarouco |
GLOBECOM | 3 |
| 2010 | Interactive SNMP traffic analysis through information visualizationabstractThe network management area deals with large amounts of data. Some of its protocols and techniques are not completely understood when it comes to usage patterns and most used features. The understanding of such characteristics is a challenging process, due to the massive data amount involved. This process can be supported by information visualization techniques. These consist in visual representations of data that make use of the unique properties of the human visual system to make insights about it in a more intuitive and effective way. In this context, interactivity has proved itself to be one of the main factors involved in providing such intuitiveness and effectiveness, specially in analysis of large datasets. Nevertheless, few interaction possibilities are available in current network management traffic visualization systems. In this paper we present a set of interactive information visualization techniques adapted to visualize SNMP trace files. We used an insight-based evaluation to show how the presented techniques can aid on the insight achievement process. Paulo Teles Barbosa, Lisandro Z. Granville |
NOMS | 2 |
| 2010 | On the feasibility of Web 2.0 technologies for network management: A mashup-based approachabstractMashups are a new breed of Web applications, created through the integration of external resources available on the Web. Recently, they have been considered a hallmark of Web 2.0 technologies, placing the end user on a developer role and encouraging both collaboration and reuse. Following the increasing efforts in investigating new approaches to network management, mashups present themselves as a technology that can bring several advantages to the field. However, to this date, the usage of mashups in network management remains unexplored. Therefore, the present paper approaches this subject, proposing a Mashup Development Tool to network management. We discuss both the architecture of such system and a proof of concept prototype. We them employ our prototype to address the case study of integrating Autonomous System routing information. Rafael Santos Bezerra, Carlos Raniery Paula dos Santos, Leandro Marcio Bertholdo, Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco |
NOMS | 4 |
| 2010 | On strategies for planning the assignment of human resources to IT change activitiesabstractPlanning is a fundamental sub-process of the overarching Information Technology (IT) change management process, proposed by the Information Technology Infrastructure Library to help organizations to deploy and maintain IT services in an effective and efficient way. A major issue behind IT change planning and of special importance for the alignment of changes with business objectives/constraints - the adequate projection of which human resources to assign to change activities - has not been properly addressed in previous investigations. To fill this gap, in this paper we propose and analyze novel strategies for planning the assignment of human resources to change activities. These strategies explore different ways to prioritize humans to activities (i.e., from the most to the less efficient or proficient humans), and to rank/cluster the activities that should be analyzed first. The novel strategies have been experimentally evaluated through ChangeAdvisor, a prototypical implementation of a decision support system that helps IT administrators in the task of understanding the trade-offs between alternative change designs. Roben Castagna Lunardi, Fabrício Girardi Andreis, Weverton Luis da Costa Cordeiro, Juliano Araújo Wickboldt, Bruno Lopes Dalmazo, Ricardo Luis dos Santos, Luís Armando Bianchin, Luciano Paschoal Gaspary, Lisandro Z. Granville, Claudio Bartolini |
NOMS | 9 |
| 2010 | Distributed autonomic resource management for network virtualizationabstractNetwork virtualization is an emerging trend claimed to reduce the costs of future networks. The key strategy in network virtualization is of slicing physical resources (links, routers, servers, etc.) to create virtual networks composed of subsets of these slices. One important challenge on network virtualization is the resource management of the physical or substrate networks. Sophisticated management techniques should be used to accomplish such management. The sophisticated techniques offered by autonomic communications rise as an appropriated alternative to address the challenges of managing the efficient use of substrate resources on network virtualization. Thus, this paper proposes a distributed self-organizing model to manage the substrate network resources. An evaluation scenario is depicted and simulations show that approximately 36.8% of the network traffic load can be spared when the self-organizing model is enabled in the evaluated scenario. Clarissa Cassales Marquezan, Lisandro Z. Granville, Giorgio Nunzi, Marcus Brunner |
NOMS | 2 |
| 2010 | Consistency maintenance of policy states in decentralized autonomic network managementabstractAutonomic network management is a vision that brings autonomic computing principles to network management. In this vision, the use of policies is a key aspect. Besides, it is necessary to add some level of decentralization to enable broad autonomic capabilities. Thus, the elements that build decentralized autonomic network management systems (known as autonomic management elements) must be policy-enabled. However, the consistency of policy states among autonomic management elements is an important challenge. Traditional mechanisms to maintain consistency of these states are supported by some centralization which wastes some desirable properties of decentralization. In contrast to these mechanisms, we propose a distributed, scalable and robust mechanism to maintain the consistency of policy states. In this paper we introduce multi-agent truth maintenance features in decentralized autonomic network management as a mechanism to bring consistency maintenance of policy states. We developed a model of a decentralized autonomic network management system on Peersim to perform simulation experiments. Besides, the utilization of policies in P2P-based autonomic network management systems is presented as case study. Jéferson Campos Nobre, Lisandro Z. Granville |
NOMS | 2 |
| 2010 | Computer-generated comprehensive risk assessment for IT project managementabstractInformation Technology (IT) products and services provided by modern organizations are designed in projects that often involve large amount of resources (e.g., humans, hardware, and software). It is essential that organizations enforce rational practices for project management, in order to successfully conclude projects and avoid waste of substantial resources. In this context, Risk Management is fundamental to guarantee the accomplishment of project's objectives by dealing with adverse and favorable events. Although important, risk assessment in IT projects is usually performed by stakeholders in interviews and brainstorms which may be a very time/resource-consuming task. Therefore, in this paper, we introduce a solution to automate the risk assessment process, based on the history of previously conducted projects. Furthermore, comprehensive and interactive risk reports are proposed in order to ease the analysis of automatically generated reports. The results show that our solution is not only useful to speed the risk assessment process, but also to assist the decision making of project managers by organizing risk information according to the project structure. Juliano Araújo Wickboldt, Luís Armando Bianchin, Roben Castagna Lunardi, Fabrício Girardi Andreis, Ricardo Luis dos Santos, Bruno Lopes Dalmazo, Weverton Luis da Costa Cordeiro, Abraham Lincoln Rabelo de Sousa, Lisandro Z. Granville, Luciano Paschoal Gaspary, Claudio Bartolini |
NOMS | 9 |
| 2009 | Distributed Reallocation Scheme for Virtual Network ResourcesabstractNetwork visualization is an emerging technology for cost-effective sharing of network resources. The key strategy in network virtualization is of slicing physical resources (links, CPU, memory, and storage) to create virtual networks that are assigned to different operators. One important challenge on network virtualization is the efficient use of the physical resources. To accomplish such efficient use the management of the physical resources should be transparent to the applications running within the virtual networks, and should be executed at runtime in order to deal with the variation on the load requests of different virtual networks. Traditional resource allocation schemes use offline, centralized, and global view strategies to manage the use of physical resources. In contrast to these strategies, we propose a runtime, distributed, local view approach to manage physical resources. In this paper we introduce a virtual network architecture and an associated self-organizing algorithm to reallocate virtual network resources along different physical nodes in order to equalize the bandwidth, and storage consumption on the physical nodes. We developed a virtual network model based on Omnet++ to simulate the designed self- organizing algorithm. An IPTV testbed scenario is presented and initial experiments, about the interruption time of the application inside the IPTV virtual network, are described. Clarissa Cassales Marquezan, Jéferson Campos Nobre, Lisandro Z. Granville, Giorgio Nunzi, Dominique Dudkowski, Marcus Brunner |
ICC | 3 |
| 2009 | CHANGEMINER: A solution for discovering IT change templates from past execution tracesabstractThe main goal of change management is to ensure that standardized methods and procedures are used for the efficient and prompt handling of changes in IT systems, in order to minimize change-related incidents and service-delivery disruption. To meet this goal, it is of paramount importance reusing the experience acquired from previous changes in the design of subsequent ones. Two distinct approaches may be usefully combined to this end. In a top-down approach, IT operators may manually design change templates based on the knowledge owned/acquired in the past. Considering a reverse, bottom-up perspective, these templates could be discovered from past execution traces gathered from IT provisioning tools. While the former has been satisfactorily explored in previous investigations, the latter - despite its undeniable potential to result in accurate templates in a reduced time scale - has not been subject of research, as far as the authors are aware of, by the service operations and management community. To fill in this gap, this paper proposes a solution, inspired on process mining techniques, to discover change templates from past changes. The solution is analyzed through a prototypical implementation of a change template miner subsystem called CHANGEMINER, and a set of experiments based on a real-life scenario. Weverton Luis da Costa Cordeiro, Guilherme Sperb Machado, Fabrício Girardi Andreis, Juliano Araújo Wickboldt, Roben Castagna Lunardi, Alan Diego dos Santos, Cristiano Bonato Both, Luciano Paschoal Gaspary, Lisandro Z. Granville, David Trastour, Claudio Bartolini |
Integrated Network Management | 9 |
| 2009 | Self-management of hybrid networks: Can we trust netflow data?abstractNetwork measurement provides vital information on the health of managed networks. The collection of network information can be used for several reasons (e.g., accounting or security) depending on the purpose the collected data will be used for. At the University of Twente (UT), an automatic decision process for hybrid networks that relies on collected network information has been investigated. This approach, called self-management of hybrid networks requires information retrieved from measuring processes in order to automatically decide on establishing/releasing lambda-connections for IP flows that are long in duration and big in volume (known as elephant flows). Nonetheless, the employed measurement technique can break the self-management decisions if the reported information does not accurately describe the actual behavior and characteristics of the observed flows. Within this context, this paper presents an investigation on the trustfulness of measurements performed using the popular NetFlow monitoring solution when elephant flows are especially observed. We primarily focus on the use of NetFlow with sampling in order to collect network information and investigate how reliable such information is for the self-management processes. This is important because the self-management approach decides which flows should be off-loaded to the optical level based on the current state of the network and its running flows. We observe three specific flow metrics: octets, packets, and flow duration. Our analysis shows that NetFlow provides reliable information regarding octets and packets. On the other hand, the flow duration reported when sampling is employed tends to be shorter than the actual duration. Tiago Fioreze, Lisandro Z. Granville, Aiko Pras, Anna Sperotto, Ramin Sadre |
Integrated Network Management | 2 |
| 2009 | Refined failure remediation for IT change management systemsabstractIn order to deal with failures in the deployment of IT changes and to always leave IT infrastructures into consistent states, we proposed in a previous work, a solution to automate the generation of rollback plans in IT change management systems. The solution was based on a mechanism that treats Requests for Change (RFC) (or parts of them) as a single atomic transaction. In this work, we extend our previous investigation and present more flexible and fine grained treatment of failures. The paper first presents extensions to our conceptual model in order (i) to give IT operators some flexibility in defining rollback actions, for example, by allowing the rollback plan to not only be a reversed change plan; and (ii) to execute different recovery activities depending on the cause and location of a problem. The paper then focuses on a refined manner to handle and treat failures in change deployments. We follow the ITIL version 3 best practises which suggest that, depending on the RFC context, the human operator can classify activities as reversible or irreversible. Such classification allows change management systems to automatically generate more accurate remediation plans. The proposal takes into account not only a precise way to define how rollback plans will be generated, but also an intuitive method enabling the operator to define compensation activities in order to complete the RFC successfully, even with the occurrence of failures. To prove the concept and technical feasibility, we have materialized our solution in the CHANGELEDGE prototype that, using elements of the Business Process Execution Language (BPEL), is able to generate correct remediation plans to handle and treat failures in IT change management systems. Guilherme Sperb Machado, Weverton Luis da Costa Cordeiro, Alan Diego dos Santos, Juliano Araújo Wickboldt, Roben Castagna Lunardi, Fabrício Girardi Andreis, Cristiano Bonato Both, Luciano Paschoal Gaspary, Lisandro Z. Granville, David Trastour, Claudio Bartolini |
Integrated Network Management | 9 |
| 2009 | Evaluating WS-security and XACML in web services-based network managementabstractThe use of Web services in network management has became a reality after recent researches and industry standardization effort. Although performance is a critical issue, as well as security support, no investigation so far has observed how secure Web services communications perform when employed for network management. In this paper we present a first investigation in this subject by evaluating the performance of WS-security and XACML in a scenario where remote processes information is retrieved. Our evaluation shows that encryption and access control increase the response time more than other aspects like message signature or authentication. We also observe that messages carrying security information are 10 times larger than un-secure messages, which may prevent the retrieval of a large number of information and short periods of time. Estêvão M. Z. Rohr, Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco |
Integrated Network Management | 2 |
| 2009 | A solution to support risk analysis on IT Change ManagementabstractThe growing necessity of organizations in using technologies to support to their operations implies that managing IT resources became a mission-critical issue for the health of the primary companies' businesses. Thus, in order to minimize problems in the IT infrastructure, possibly affecting the daily business operations, risks intrinsic to the change process have to be analyzed and assessed. Risk Management is a widely discussed subject in several areas, although for IT Change Management it is quite a new discipline. The Information Technology Infrastructure Library (ITIL) introduces a set of best practices to conduct the management of IT infrastructures. According to ITIL, risks should be investigated, measured, and mitigated before any change is approved. Even with these guidelines, there is no default automatic method for risk assessment in IT Change Management. In this paper we introduce a risk analysis method based on the execution history of past changes. In addition, we propose a failure representation model to capture the feedback of the execution of changes over IT infrastructures. Juliano Araújo Wickboldt, Guilherme Sperb Machado, Weverton Luis da Costa Cordeiro, Roben Castagna Lunardi, Alan Diego dos Santos, Fabrício Girardi Andreis, Cristiano Bonato Both, Lisandro Z. Granville, Luciano Paschoal Gaspary, Claudio Bartolini, David Trastour |
Integrated Network Management | 8 |
| 2009 | ChangeLedge: Change design and planning in networked systems based on reuse of knowledge and automation
Weverton Luis da Costa Cordeiro, Guilherme Sperb Machado, Fabrício Girardi Andreis, Alan Diego dos Santos, Cristiano Bonato Both, Luciano Paschoal Gaspary, Lisandro Z. Granville, Claudio Bartolini, David Trastour |
Comput. Networks | 7 |
| 2008 | Using visualization techniques for SNMP traffic analysesabstractThe network management area is currently dealing with huge amounts of information, which are produced, for example, by large scale and high-speed networks, heterogeneous devices, and monitoring and notification systems. Researchers and network administrators are frequently supported by information visualization techniques in the task of analyzing these large data sets. The simple network management protocol (SNMP) is the de facto standard for TCP/IP networks management. Despite its importance, there are no specific visualizations defined for SNMP traffic traces. In this paper we present a study on techniques for visualizing SNMP trace files, motivated by the fact that general purpose network traffic visualizations available today are not suitable for SNMP observation. Our proposed techniques have been prototyped in a software tool called management traffic analyzer, which has been used to analyze and visualize SNMP traces. Ewerton Monteiro Salvador, Lisandro Z. Granville |
ISCC | 2 |
| 2008 | A template-based solution to support knowledge reuse in IT change designabstractCapturing and reusing the experience of operators in implementing IT changes is an important aspect of IT service management, as it may result in fewer incidents (upon change execution) and faster specification of change plans, to mention just a few potential advantages. Nevertheless, in practice, changes are usually described and documented in an ad hoc fashion, due to the lack of proper support to assist the design process. This hampers knowledge acquired when specifying, planning, and carrying out previous changes to be reused in subsequent requests. In order to address this issue, we propose the use of change templates as a mechanism to formalize, preserve, and reuse the experience accumulated within organizations in relation to IT changes. Our solution is analyzed through a prototypical implementation of a change management system and a case study based on a real-life scenario. Weverton Luis da Costa Cordeiro, Guilherme Sperb Machado, Fabio Fabian Daitx, Cristiano Bonato Both, Luciano Paschoal Gaspary, Lisandro Z. Granville, Akhil Sahai, Claudio Bartolini, David Trastour, Katia Barbosa Saikoski |
NOMS | 6 |
| 2008 | Enabling rollback support in IT change management systemsabstractThe current research on IT change management has been exploring several aspects of this new discipline, but it usually assumes that changes expressed in requests for change (RFC) documents will be successfully executed over the managed IT infrastructure. This assumption, however, is not realistic in actual IT systems because failures during the execution of changes do happen and cannot be ignored. In order to address this issue, we propose a solution where tightly-related change activities are grouped together forming atomic groups of activities. These groups are atomic in the sense that if one activity fails, all other already executed activities of the same group must rollback to move the system backwards to the previous state. The automation of change rollback is especially convenient because it relieves the IT human operator of manually undoing the activities of a change group that has failed. To prove concept and technical feasibility, we have materialized our solution in a prototype system that, using elements of the business process execution language (BPEL), is able to control how atomic groups of activities must be handled in IT change management systems. Guilherme Sperb Machado, Fabio Fabian Daitx, Weverton Luis da Costa Cordeiro, Cristiano Bonato Both, Luciano Paschoal Gaspary, Lisandro Z. Granville, Claudio Bartolini, Akhil Sahai, David Trastour, Katia Barbosa Saikoski |
NOMS | 6 |
| 2008 | An investigation of visualization techniques forSNMP traffic tracesabstractThe network management area is currently dealing with huge amounts of information. Researchers and network administrators are frequently supported by information visualization techniques in the task of analyzing these large data sets. The simple network management protocol (SNMP) is the de facto standard for TCP/IP networks management. Despite its importance, there are no specific visualizations defined for SNMP traffic traces. In this paper we present a study on techniques for visualizing SNMP trace files, motivated by the fact that general purpose network traffic visualizations available today are not suitable for SNMP observation. Our proposed techniques have been prototyped in a software tool called management traffic analyzer. Ewerton Monteiro Salvador, Lisandro Z. Granville |
NOMS | 2 |
| 2007 | Performance Evaluation of Notifications in a Web Services and P2P-Based Network Management OverlayabstractNotification service on network management is an essential tool that helps to save network resources, such as bandwidth. A management notification is basically an event message that reports a resource's internal state to an interested manager. A complete notification support is not accomplished via simple tasks anymore, for example, restricted to notifying managers from the same administrative domain of the managed devices. Due to huge changes on current network usage, this management topic needs to be reviewed in the light of modern technologies and requirements. In this paper we present a notification service integrated in a P2P-based network management solution called ManP2P. We also present an experimental evaluation regarding propagation delay and processing costs. We believe that with our solution it is possible to enhance P2P-based network management advantages without paying a great performance cost. Clarissa Cassales Marquezan, Carlos Raniery Paula dos Santos, Ewerton Monteiro Salvador, Maria Janilce Bosquiroli Almeida, Sérgio Luis Cechin, Lisandro Z. Granville |
COMPSAC (1) | 6 |
| 2007 | Evaluating the Performance of Web Services Composition for Network ManagementabstractThe composition of network management information is a feature widely required but not properly supported in traditional management technologies. Web services technology has been investigated to enable more sophisticated management solutions. In this paper, we show that Web services have more to offer to the network management discipline than just bridging established management protocols and Web-based applications. We explore the possibility of using Web services composition for network management considering two approaches: in the first one a single device needs to be contacted and its information composed; in the second one, many devices need to be contacted and the information retrieved from them need to be composed. We show that using proper tools one can not only really use Web services composition for network management, but also that such use can be integrated with traditional management technologies that are unlike to be abandoned in short and mid terms. Moreover, we investigate the performance of Web services compositions for network management considering response time and network traffic. Performance investigations are crucial because Web services protocols are based on plain text XML documents and impose a processing overhead, which may prevent their adoption depending on the requirements and limitations of the management environment. Ricardo Lemos Vianna, Maria Janilce Bosquiroli Almeida, Liane Margarida Rockenbach Tarouco, Lisandro Z. Granville |
ICC | 4 |
| 2007 | On the Performance of Web Services Management Standards - An Evaluation of MUWS and WS-Management for Network ManagementabstractImportant steps have been taken in the recent years towards evaluating the performance of Web services for network management. Due to the lack of specific standards for Web services-based management, previous evaluations have been carried out measuring only the performance of SOAP (the basic Web services protocol) running in network management environments. While the conclusions of the papers published so far indicate the feasibility of employing Web services for network management, there is no evidence that these conclusions also hold for solutions developed according to recent Web services management standards. In this paper we go a step further and present the results of a set of experiments carried out in order to compare the specifications OASIS management Using Web services (MUWS) and DMTF Web services for management (WS-management) against the de facto network management standard, i.e., the simple network management protocol (SNMP). The performance metrics investigated were network usage, response time, and CPU usage. Giovane Cesar Moreira Moura, Giancarlo Silvestrin, Ricardo Nabinger Sanchez, Luciano Paschoal Gaspary, Lisandro Z. Granville |
Integrated Network Management | 5 |
| 2007 | An Evaluation of Service Composition Technologies Applied to Network ManagementabstractService composition is a technique that may help the development of management systems by aggregating smaller services to produce more sophisticated ones. Service composition can be realized by using traditional management technologies, although these technologies have not been conceived taking composition support as one of their main aspects. Current service-oriented architecture (SOA)-related efforts, however, define specific standards for Web services composition, such as the Web services business process execution language (WS-BPEL). Web services for network management have been investigated by the management community at least in the last four years, but up to today no research evaluating Web services composition applied to network management has been carried out. In this paper we present such an evaluation where compositions based on the IETF Script MIB, ad-hoc Java Web services, and WS- BPEL are compared against one another in a managed network where BGP routers are investigated in order to identify route advertisement anomalies. Ricardo Lemos Vianna, Everton Rafael Polina, Clarissa Cassales Marquezan, Leandro Marcio Bertholdo, Liane Margarida Rockenbach Tarouco, Maria Janilce Bosquiroli Almeida, Lisandro Z. Granville |
Integrated Network Management | 7 |
| 2006 | Investigating Web Services Composition Applied to Network ManagementabstractThe composition of network management information is a feature widely required but poorly supported in traditional management technologies. Recently, Web services for network management has been enabling the investigation of more sophisticate management solutions, even though some concerns related to the Web services performance have been initially exposed, but quickly disappeared after the first research results. In this paper we show that Web services technologies have more to offer to the network management discipline than just bridging established network management protocols and Web services protocols. Particularly we explore the possibility of using Web services composition applied to network management. If successful, Web services composition can bring to network management the solution for some key problems yet to be solved, such as retrieving the information from several different devices and yet being able to use a simple and fast interface at the manager side. We present Web services composition for network management considering two approaches: in the first one a single network device needs to be contacted and its information composed; in the second one, many devices need to be contacted and the information retrieved from them need to be composed. We show that using proper tools we can not only really use Web services composition for network management, but also that such use can be integrated with traditional management technologies that are unlike to be abandoned in short and mid terms Ricardo Lemos Vianna, Maria Janilce Bosquiroli Almeida, Liane Margarida Rockenbach Tarouco, Lisandro Z. Granville |
ICWS | 4 |
| 2006 | Designing the Architecture of P2P-Based Network Management SystemsabstractP2P-based network management has been recently proposed. However, the entities involved in this new management model have not been detailed up to today. In this paper we introduce the internal architecture of management peers. According to the set of elements internally employed, a management peer may act in the role of a top level or mid level manager, or in the role of a hybrid entity with mixed duties. The presented architecture can then be used as basis for the development of P2P-based management systems, such as the system prototype we also present in the paper. André Panisson, Diego Moreira da Rosa, Cristina Melchiors, Lisandro Z. Granville, Maria Janilce Bosquiroli Almeida, Liane Margarida Rockenbach Tarouco |
ISCC | 4 |
| 2006 | A Policy-Based Hierarchical Approach for Management of Grids and NetworksabstractGrids are distributed infrastructures that have been used as an important and powerful resource for distributed computing. Since the nodes of a grid can potentially be located in different administrative domains, the underlying network infrastructure that supports grid communications has to be properly configured to provide efficient node-to-node message exchange. Currently, the management of grids and networks is performed by different and independent tools: there is no tool integration to provide, for example, an automatic network configuration. This forces grids administrators to request, in a non-automated fashion, the configuration of network devices to network administrators. In this paper we present a policy translation mechanism that generates network policies from grid requirements expressed in grid policies. The paper also presents a prototype tool that allows grid administrators to define grid policies, and network administrators to define corresponding translation rules. The proposed translation mechanism and its implementation in the associated tool show that the management of grids and networks can be executed in an integrated way Tiago Fioreze, Ricardo Neisse, Lisandro Z. Granville, Maria Janilce Bosquiroli Almeida, Aiko Pras |
NOMS | 3 |
| 2006 | Evaluating the Performance of SNMP and Web Services NotificationsabstractWeb Services against SNMP comparisons have been carried out by the network management community in order to understand the impact on adopting Web Services as a management tool. In these comparisons, however, notification messages have been neglected to a secondary plane in such a way that the current conclusions about the performance of Web Services may not apply for networks extensively managed via notifications. In this paper we first evaluate the performance of Web Services notifications encoded following the WS-Notification specification, and compare it with the performance of SNMP traps. Then, we introduce a configurable SNMP to Web Services gateway that reacts to SNMP traps on behalf of an SNMP manager, retrieves further information from the notifying entity, and builds up WS-Notification compliant messages which are sent to Web Services-based managers. We finally evaluate the performance of the proposed solution in order to redraw the current conclusions about Web Services against SNMP, now explicitly considering the also important notification support. Weldson Queiroz de Lima, Rodrigo Sanger Alves, Ricardo Lemos Vianna, Maria Janilce Bosquiroli Almeida, Liane Margarida Rockenbach Tarouco, Lisandro Z. Granville |
NOMS | 6 |
| 2005 | Comparing Web services with SNMP in a management by delegation environmentabstractThe traditional management by delegation model has lead the IETF, more recently, to define its Script MIB, which allows management entities to transfer, control and retrieve results generated by management scripts. These operations, however, can also be accomplished by Web services. Web services have been pointed out as an interesting approach for network management in general, but in this paper we present the use of Web services in the specific context of management by delegation. We also present a Web services-based system prototype that allows us to compare a Script MIB implementation against SNMP to Web service gateways for management by delegation. Tiago Fioreze, Lisandro Z. Granville, Maria Janilce Bosquiroli Almeida, Liane Margarida Rockenbach Tarouco |
Integrated Network Management | 2 |
| 2004 | Experiences in the implementation of an SNMP-based high performance cluster management systemabstractHigh performance clusters, like any network element, require management. Cluster management tools do not follow a standard operation method, making the interaction with other tools hard. To obtain interoperability, cluster management particularities should be adapted to the management architecture used in the network. This work presents the experiences obtained with SNMP-based cluster management. Moreover, a cluster management tool based on SNMP is proposed. Rodrigo Sanger Alves, Clarissa Cassales Marquezan, Lisandro Z. Granville |
ISCC | 3 |
| 2004 | Implementation and bandwidth consumption evaluation of SNMP to Web services gatewaysabstractWeb services gateways are needed to include SNMP devices into a Web services based management architecture. We propose in this paper two approaches for such gateways and evaluate these approaches in order to verify the feasibility of using Web services closer to the network devices interface. We primarily tested the bandwidth consumed by these gateways when using SOAP with HTTP, HTTPS, and a compression process. The evaluation shows that Web services gateways are especially interesting when the number of SNMP object instances retrieved is high. Ricardo Neisse, Ricardo Lemos Vianna, Lisandro Z. Granville, Maria Janilce Bosquiroli Almeida, Liane Margarida Rockenbach Tarouco |
NOMS (1) | 3 |
| 2003 | A Dynamic SNMP to XML Proxy Solution
Ricardo Neisse, Lisandro Z. Granville, Diego Osório Ballvé, Maria Janilce Bosquiroli Almeida, Liane Margarida Rockenbach Tarouco |
Integrated Network Management | 2 |
| 2002 | An architecture for automated replacement of QoS policiesabstractThis paper introduces the notion of PoP (policy of policies) used to define standard policy replacement strategies in a policy-based network. We also propose an architecture to support PoP within PDPs (policy decision points originally defined by the IETF). The notion of PoP, and the proposed architecture allow the automation of the policy replacement task currently manually executed by the network administrator based on the network business plan. Lisandro Z. Granville, Gustavo Augusto Faraco de Sá Coelho, Maria Janilce Bosquiroli Almeida, Liane Margarida Rockenbach Tarouco |
ISCC | 1 |
| 2001 | QAME - QoS-Aware Management EnvironmentabstractProviding QoS-guaranteed services in current installed networks is an important issue, only the deploying QoS services is not enough to guarantee their success: QoS management must also be provided. Nowadays, policy-based management addresses this need, but such management is not enough either network managers often deal with QoS tasks that cannot be performed using only policy-based management This paper describes six important QoS management-related tasks (QoS installation, operation maintenance, discovery, monitoring, analysis and visualization) and shows solutions that can help managers proceed with these tasks. However, these solutions are independent from each other, leading to a scenario where integration is difficult. To solve this lack of integration, QAME (QoS-aware management environment) has been developed, which provides support to allow the execution of the defined QoS tasks in an integrated fashion. Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco |
COMPSAC | 1 |
| 2000 | Electronic Commerce Solution for Small BusinessesabstractAs the Internet grew and evolved, it became more broadly used by everyone. What once was destined to military and academic purposes is now used as a marketing strategy, a means to sell products and perform electronic business. Electronic business exists in two distinct forms. One is between suppliers and consumers of goods or services. The other is between a seller (company) and a final consumer (home user). Nowadays, many companies see the Internet as a niche to be explored. For some of them, implementing an e-commerce Web site is not a financial challenge, whereas it is different for smaller businesses. This work defines the most appropriate structure for a given business, taking into account its own resources combined with those found on the Web, and presents an e-commerce site generating tool that solves small businesses' troubles. Cleber Machado Ortiz, Lisandro Z. Granville |
WISE (2) | 2 |
| 1998 | Specification of E-LOTOS Systems in the E-DART EnvironmentabstractPresents the E-DART (Enhancements to Diagrams for Architectural RepresenTation), a graphical environment for the specification of systems based on graphic constructions for the formal description technique E-LOTOS (Enhancements to LOTOS). The use of diagrams reduces the complexity of the specifications, making E-LOTOS accessible even to users who are not familiar with a formal description technique. A new graphic syntax was created, as well as a specification tool, the E-DART Editor, that supports the new syntax. A translating module, from graphic specifications to the E-LOTOS syntax, is also part of the environment. The main purpose is to provide a new way to allow the user to specify time-dependent systems in a graphical approach, abstracting the largest complexities of the E-LOTOS textual syntax. Lisandro Z. Granville, Maria Janilce Bosquiroli Almeida |
COMPSAC | 1 |