EDBT 2026 Demo / reviewers in the wild / expert
Leonardo Maccari
dblp:58/5643
· DBLP profile ↗
42ranked-venue papers
21as first author
13since 2021 · last 2026
0000-0002-5780-5008ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 26 · 12 first-author · 7 since 2021Security and privacy · 4 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-authorTheory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Preventing data loss in multinational companies: Two case studies on phishing simulation techniques and drive encryption
Martina Bonora, Andrea Ceccon, Leonardo Maccari |
J. Inf. Secur. Appl. | 3 |
| 2025 | Age-Based CoDel and His Friends. Improving the Linux Scheduler with 2-Level AQM DisciplinesabstractWe study the combination of Active Queue Management (AQM) techniques and age-based scheduling disciplines to improve network performance in the Linux packet scheduler. While AQM algorithms like CoDel, FQ-CoDel, and PIE manage queue lengths and ensure fair bandwidth sharing, age-based scheduling (e.g., Least Attained Service, Two-Level Processor Sharing) reduces mean flow completion time by prioritizing short flows. While their individual benefits are known, the integration of these orthogonal features had not been analysed so far. We propose a hybrid queuing solution using standard Linux utilities (tc, nftables) tested with state-of-the art open source traffic generators to generate realistic Pareto-distributed traffic. Our experiments on $1 \mathrm{~Gb} / \mathrm{s}$ and $10 \mathrm{~Gb} / \mathrm{s}$ links demonstrate that implementing age-based scheduling policies on top of AQM strategies significantly reduces flow completion time, with gains ranging from 3% to 20%. These improvements are achieved without increasing CPU load and while preserving or improving fairness among flows. The solution is easily implementable on any recent Linux kernel, and we provide all the code we realized to replicate and improve our results. Giovanni Moschini, Andrea Marin, Leonardo Maccari |
CNSM | 3 |
| 2025 | Next-Generation Wireless Backhaul Design for Rural AreasabstractRural areas often face significant challenges in accessing reliable broadband Internet due to high infrastructure costs and low population density. To address this issue, we propose a model for evaluating the performance and the cost of a mesh-based, last-and middle-mile replacement for broadband connection in these underserved regions. We use open data from ten underserved municipalities to assess the demand, plan the mesh network, and estimate the allocated capacity per user. We consider two designs: a low-cost network using the classical 5 unlicensed band, and a high-performance one using mmWave frequency. For both designs, we estimate the Operating Expenditure and the amortized Capital Expenditure using realistic device prices and operating cost estimations. We compare the price of the mesh-based solution with alternatives based on xDSL and satellite connectivity and show that it has competitive prices compared to existing offers, covering a larger portion of households than DSL. We open-source both the code and the elaborated data to reproduce, extend, and improve our results in different settings. Gabriele Gemmi, Llorenç Cerdà-Alabern, Leonardo Maccari |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2024 | Optimizing and Managing Wireless Backhaul for Resilient Next-Generation Cellular NetworksabstractNext-generation wireless networks target high network availability, ubiquitous coverage, and extremely high data rates for mobile users. This requires exploring new frequency bands, e.g., mmWaves, moving toward ultra-dense deployments in urban locations, and providing ad hoc, resilient connectivity in rural scenarios. The design of the backhaul network plays a key role in advancing how the access part of the wireless system supports next-generation use cases. Wireless backhauling, such as the newly introduced Integrated Access and Backhaul (IAB) concept in 5G, provides a promising solution, also leveraging the mmWave technology and steerable beams to mitigate interference and scalability issues. At the same time, however, managing and optimizing a complex wireless backhaul introduces additional challenges for the operation of cellular systems. This paper presents a strategy for the optimal creation of the backhaul network considering various constraints related to network topology, robustness, and flow management. We evaluate its feasibility and efficiency using synthetic and realistic network scenarios based on 3D modeling of buildings and ray tracing. We implement and prototype our solution as a dynamic IAB control framework based on the Open Radio Access Network (RAN) architecture, and demonstrate its functionality in Colosseum, a large-scale wireless network emulator with hardware in the loop. Gabriele Gemmi, Michele Polese, Tommaso Melodia, Leonardo Maccari |
CNSM | 4 |
| 2024 | Finite Capacity Multi-Server Job Systems: A Simulation StudyabstractCloud computing has revolutionized how computational resources are accessed and utilized. However, the dynamic nature of the cloud computing environment, which is characterized by a variety of resource types and capabilities presents challenges for managing the workload and ensuring the quality of service. The selection and implementation of queueing policies can have a major impact on the efficiency of the cloud environment, and thus on the quality of service experienced by the end users. Understanding the performance metrics of different queueing policies in cloud computing environments with scalable resource management is essential for both cloud service providers and consumers. In response to this, our work aims to evaluate the effectiveness of some queueing policies in cloud environments characterized by dynamic resource allocation with a particular emphasis on their dropping probabilities. We proposed a simulation approach that combines the development of an accurate simulation model of a cloud computing environment with adaptable resource management, along with a comprehensive performance analysis of different queueing policies including First-Come-First-Serve and Priority queueing. The result revealed that assigning priority to jobs with longer service times and larger resource demands has a positive impact on small jobs as well. Muhammad Waqas 0004, Leonardo Maccari, Andrea Marin |
ECMS | 2 |
| 2024 | Estimating coverage and capacity of high frequency mobile networks in ultradense urban areas
Gabriele Gemmi, Michele Segata, Leonardo Maccari |
Comput. Commun. | 3 |
| 2024 | Optimizing MRAI on large scale BGP networks: An emulation-based approach
Mattia Milani, Michele Segata, Luca Baldesi, Marco Nesler, Renato Lo Cigno, Leonardo Maccari |
Comput. Commun. | 6 |
| 2023 | Joint Routing and Energy Optimization for Integrated Access and Backhaul with Open RANabstractEnergy consumption represents a major part of the operating expenses of mobile network operators. With the densification foreseen with 5G and beyond, energy optimization has become a problem of crucial importance. While energy optimization is widely studied in the literature, there are limited insights and algorithms for energy-saving techniques for Integrated Access and Backhaul (IAB), a self-backhauling architecture that ease deployment of dense cellular networks reducing the number of fiber drops. This paper proposes a novel optimization model for dynamic joint routing and energy optimization in IAB networks. We leverage the closed-loop control framework introduced by the Open Radio Access Network (O-RAN) architecture to minimize the number of active IAB nodes while maintaining a minimum capacity per User Equipment (UE). The proposed approach formulates the problem as a binary nonlinear program, which is transformed into an equivalent binary linear program and solved using the Gurobi solver. The approach is evaluated on a scenario built upon open data of two months of traffic collected by network operators in the city of Milan, Italy. Results show that the proposed optimization model reduces the RAN energy consumption by 47%, while guaranteeing a minimum capacity for each UE. Gabriele Gemmi, Maxime Elkael, Michele Polese, Leonardo Maccari, Hind Castel-Taleb, Tommaso Melodia |
GLOBECOM | 4 |
| 2023 | On the Performance and Effectiveness of Digital Contact Tracing in the Second Wave of COVID-19 in ItalyabstractContact-tracing smartphone applications have been developed and used as a complement to manual contact tracing in the COVID-19 pandemic. The goal of these apps is to trace contacts between people and notify the mobile phone owners when one of their contacts tested positive. People who receive a notification should behave as exposed people, take a test, and possibly isolate themselves until they receive the result. Unfortunately, identifying contacts based on distance is technically a daunting task: apps can be configured conservatively (a very small number of people are notified, limiting the effectiveness of the app) or they may be more tolerant and produce a high number of notifications but also of false positives. We review the data available from Immuni, the Italian app, which provides detailed figures on the notifications sent and the positive users, and we show that Immuni was configured to generate a very large amount of notifications. We estimate the testing resources that the health system would have needed if the app was downloaded by 100% of the adult population, and every notified person would require a test. In such conditions, Immuni would have generated a number of tests orders of magnitude higher than what was available. We compare the performance of Immuni with the currently available literature on other apps and observe that contact-tracing apps had a limited impact on the second wave of the COVID-19 pandemic. As contact tracing exposes citizens to privacy risks, we discuss some ways to reshape the goal of the apps to achieve a better tradeoff between social benefit and risk. Leonardo Maccari |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2022 | A Realistic Open-Data-based Cost Model for Wireless Backhaul Networks in Rural AreasabstractBroadband Internet provision is an increasing demand in many rural areas and wireless internet service providers have emerged as an opportunity to fill this need. However, this type of operator typically consists of a small business with little resources, and difficulty to plan and assess a reliable and economically sustainable infrastructure. In this paper, we try to bring some aid to this challenging problem by describing a reliable mesh-based backhaul design, together with a detailed CapEx/OpEx economic assessment. We apply our model using real data from ten Italian rural municipalities. Our numerical results show that having clusters of 200 subscribers, a reliable backhaul could be deployed with a monthly subscription and price per Mb/s extremely competitive compared to existing market offers. Gabriele Gemmi, Llorenç Cerdà-Alabern, Leonardo Maccari |
CNSM | 3 |
| 2022 | On Cost-Effective, Reliable Coverage for LoS Communications in Urban AreasabstractThe use of ultra high frequencies in 5G and future networks to improve transmission speeds and capacity requires that users’ equipment remain in Line of Sight with the access antennas most of the service time. This requirement implies a change in perspective to plan the coverage: Antennas cannot be placed on roofs or remote antenna sites, and a robust coverage is based on multi-antenna visibility from any point. This paper tackles the problem of public street coverage in urban areas with a data-driven methodology. Starting from 3D digital maps, we formalize the problem of antenna placement as a set coverage problem and leverage powerful heuristics to implement a general algorithm that allows the exploration of different policies, returning the detailed coverage, the antenna placement, and the cost of the coverage. Results on 15 areas in 3 Italian cities show the properties of different policies and confirm for the first time on large scale real data the feasibility of Line of Sight communications with a sustainable number of antennas per km2. Gabriele Gemmi, Renato Lo Cigno, Leonardo Maccari |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2021 | WIP: Analysis of Feasible Topologies for Backhaul Mesh NetworksabstractMesh backhauls are getting attention for 5G networks, but not only. A backhaul mesh is attractive due to its multiple potential paths that grants redundancy and robustness. The real topology and its properties, however, is heavily influenced by the characteristics of the place where it is deployed, a fact that is rarely taken into account by scientific literature, mainly due to the lack of detailed topographic data. This WIP analyzes the impact of true topography on small backhaul meshes in nine different locations in Italy. Initial results stress how true data influence results and can help designing better networks and better services. Gabriele Gemmi, Renato Lo Cigno, Leonardo Maccari |
WOWMOM | 3 |
| 2021 | Do we need a contact tracing app?
Leonardo Maccari, Valeria Cagno |
Comput. Commun. | 1 |
| 2020 | Poster: TrueNets, a Topology Generator for Realistic Network Analysis
Gabriele Gemmi, Renato Lo Cigno, Leonardo Maccari |
Networking | 3 |
| 2020 | Infective flooding in low-duty-cycle networks, properties and bounds
Luca Baldesi, Leonardo Maccari, Renato Lo Cigno |
Comput. Commun. | 2 |
| 2020 | Exact Distributed Load Centrality Computation: Algorithms, Convergence, and Applications to Distance Vector RoutingabstractMany optimization techniques for networking protocols take advantage of topological information to improve performance. Often, the topological information at the core of these techniques is a centrality metric such as the Betweenness Centrality (BC) index. BC is, in fact, a centrality metric with many well-known successful applications documented in the literature, from resource allocation to routing. To compute BC, however, each node must run a centralized algorithm and needs to have the global topological knowledge; such requirements limit the feasibility of optimization procedures based on BC. To overcome restrictions of this kind, we present a novel distributed algorithm that requires only local information to compute an alternative similar metric, called Load Centrality (LC). We present the new algorithm together with a proof of its convergence and the analysis of its time complexity. The proposed algorithm is general enough to be integrated with any distance vector (DV) routing protocol. In support of this claim, we provide an implementation on top of Babel, a real-world DV protocol. We use this implementation in an emulation framework to show how LC can be exploited to reduce Babel's convergence time upon node failure, without increasing control overhead. As a key step towards the adoption of centrality-based optimization for routing, we study how the algorithm can be incrementally introduced in a network running a DV routing protocol. We show that even when only a small fraction of nodes participate in the protocol, the algorithm accurately ranks nodes according to their centrality. Leonardo Maccari, Lorenzo Ghiro, Alessio Guerrieri, Alberto Montresor, Renato Lo Cigno |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2019 | Towards scalable Community Networks topologies
Leonardo Maccari, Gabriele Gemmi, Renato Lo Cigno, Merkourios Karaliopoulos, Leandro Navarro-Moldes |
Ad Hoc Networks | 1 |
| 2019 | Detecting and Mitigating Points of Failure in Community Networks: A Graph-Based ApproachabstractA community network (CN) is a bottom-up network created by a community of people with the goal of gaining control of their communications and overcoming digital divide. CNs are blooming, they range from small ones (tens of nodes) to gigantic ones (tens of thousands of nodes). They are made primarily of wireless links but in some cases, they mix wired and wireless technologies. CNs are generally unplanned and nonlayered, and the community tries to mirror the same approach in its governance, avoiding unnecessary management structures and relying on self-organization and spontaneous interactions. CNs are peer production platforms, a community of people that pools resources and contributes to build a shared value. While this value is generally immaterial (as in WikiPedia) CNs instead realize a distributed, peer-to-peer physical communication network. This paper analyses ninux.org, the largest CN in Italy, and one of the eldest in Europe. The goal of this paper is to understand if the spontaneous growth of the network and the community leads to a technically robust network and a socially robust community, or it hides the presence of (potentially interdependent) points of failure. We will show that, in spite of the original motivations of the ninux community, the network is fragile under several aspects, and we suggest ways to improve it. Leonardo Maccari |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2018 | Centrality-Based Route Recovery in Wireless Mesh NetworksabstractWireless Mesh Networks are subject to frequent node and link failures, and routing protocols currently used, such as Optimized Link State Routing (OLSR) or Babel, suffer from relatively long recovery times characterized by broken and looped routes due to long management timeouts that can not be shortened to keep the overhead at an acceptable level. This paper experiments a novel timer management technique named Pop-Routing on top of OLSR. Pop-Routing exploits the notion of betweenness centrality to tune timers depending on the node position in the network, so that failures that lead to larger traffic losses can be recovered faster. Pop-Routing maintains the overhead constant, but favors the most central nodes, whose failure is devastating from the performance point of view, and penalizes peripheral ones, whose failure has a very little impact on the entire network. Pop-Routing has been implemented as a plug-in in the OLSR daemon, coupled with an external process, named Prince, that computes centrality and timer values without interfering with the routing daemon. Experiments are run on the WiSHFUL showing the benefit of Pop-tuning OLSR Hello and Traffic Control timers. Michele Segata, Nicolò Facchi, Leonardo Maccari, Gabriele Gemmi, Renato Lo Cigno |
ICC | 3 |
| 2018 | On the Distributed Computation of Load Centrality and its Application to DV RoutingabstractCentrality metrics are a key instrument for graph analysis and play a central role in many problems related to networking such as service placement, robustness analysis and network optimization. Betweenness centrality is one of the most popular and well-studied metric. While distributed algorithms to compute this metric exist, they are either approximated or limited to certain topologies (directed acyclic graphs or trees). Exact distributed algorithms for betweenness centrality are computationally complex, because its calculation requires the knowledge of all possible shortest paths within the graph. In this paper we consider load centrality, a metric that usually converges to betweenness, and we present the first distributed and exact algorithm to compute it. We prove its convergence, we estimate its complexity and we show it is directly applicable-with minimal modifications-to any distance-vector routing protocol based on Bellman-Ford. We finally implement it on top of the Babel routing protocol and we show that, exploiting centrality, we can significantly reduce Babel's convergence time upon node failure without increasing signalling overhead. Our contribution is relevant in the realm of wireless distributed networks, but the algorithm can be adopted in any distributed system where it is not possible, or computationally impractical, to reconstruct the whole network graph at each node and compute betweenness centrality with the classical approach based on Dijkstra's algorithm. Leonardo Maccari, Lorenzo Ghiro, Alessio Guerrieri, Alberto Montresor, Renato Lo Cigno |
INFOCOM | 1 |
| 2018 | Where have all the MPRs gone? On the optimal selection of Multi-Point Relays
Leonardo Maccari, Mirko Maischberger, Renato Lo Cigno |
Ad Hoc Networks | 1 |
| 2018 | Improving Routing Convergence With Centrality: Theory and Implementation of Pop-Routing
Leonardo Maccari, Renato Lo Cigno |
IEEE/ACM Trans. Netw. | 1 |
| 2017 | Optimized P2P streaming for wireless distributed networks
Leonardo Maccari, Nicolò Facchi, Luca Baldesi, Renato Lo Cigno |
Pervasive Mob. Comput. | 1 |
| 2016 | On the Computation of Centrality Metrics for Network Security in Mesh NetworksabstractBetweenness centrality is a popular metric in social science, and recently it was adopted also in computer science. Betweenness identifies the node, or the nodes, that are most suitable to perform critical network functions, such as firewalling and intrusion detection. However, computing centrality is resource-demanding, we can not give for granted that it can be computed in real time at every change in the network topology. This is especially true in mesh networks that generally use devices with few computation resources. This paper shows that using the fastest state-of-the-art heuristic algorithm it is indeed possible to compute network centrality even in real, low-power networking hardware in a network made of up to 1000 nodes. Not only, observing the behavior of a real mesh network it shows that centrality does not need to be updated at every topology change, but it can be safely re-computed with an interval in the order of the tens of minutes. Our findings confirms that centrality can be effectively and successfully used as a building block for security functions in mesh networks. Leonardo Maccari, Renato Lo Cigno |
GLOBECOM | 1 |
| 2016 | Pop-routing: Centrality-based tuning of control messages for faster route convergenceabstractFast and efficient recovery from node failure, with minimal disruption of routes and the consequent traffic loss is of the utmost importance for any routing protocol. Link-state protocols, albeit preferred to distance vector ones because of faster convergence, still suffer from a trade-off between control message overhead and performance. This work formalizes the routes' disruption following a node failure as an optimization problem depending on the nodes' centrality in the topology, constrained to a constant signaling overhead. Next, it shows that the solution can be found using Lagrange Multipliers. The solution complexity is low enough to be computed on-line on the network routers, thus obtaining the optimal setting of control message timers that minimize the traffic loss following a node failure. The gain obtained is quantified in power-law synthetic topologies, and it is also tested on real network topologies extending the OLSR protocol to use the modified timers, showing that the inevitable approximations introduced in the analysis do not hamper the very good results achievable through this novel approach. The technique can be applied to any link state protocol, including OSPF, and improves route convergence not only upon failures but on every topology modification. Leonardo Maccari, Renato Lo Cigno |
INFOCOM | 1 |
| 2015 | A week in the life of three large Wireless Community Networks
Leonardo Maccari, Renato Lo Cigno |
Ad Hoc Networks | 1 |
| 2015 | Improving P2P streaming in Wireless Community Networks
Luca Baldesi, Leonardo Maccari, Renato Lo Cigno |
Comput. Networks | 2 |
| 2014 | Improving P2P streaming in community-lab through local strategiesabstractDistributing live streaming in Wireless Community Networks (WCNs) is a service with a high added value; however, cloud-based streaming, as commonly used in the Internet, does not fit well the architecture of WCNs, which often have restricted access to the Internet. Modern WCNs, instead, can have a good internal connectivity with high bandwidth. A P2P approach is thus well matched for streaming in WCNs. This paper presents experimental results obtained with PeerStreamer running on top of Community-Lab, a test-bed realized by the CONFINE EU Project for the experimentation of novel protocols in community networks. The experiments highlight relevant differences between a WCN and the Internet, and we propose strategies that can be implemented on all the peers or even only locally on the source to improve the streaming quality. These strategies are based on simple heuristics and can be activated dynamically when the streaming quality degrades below a given threshold. Luca Baldesi, Leonardo Maccari, Renato Lo Cigno |
WiMob | 2 |
| 2014 | Betweenness estimation in OLSR-based multi-hop networks for distributed filtering
Leonardo Maccari, Renato Lo Cigno |
J. Comput. Syst. Sci. | 1 |
| 2014 | Protecting mobile agents communications in pervasive networks with a trusted distributed mediator for ID-based RSAabstractABSTRACT This paper proposes a new method of data authentication and encryption for distributed networks supporting mobile software agents. Software agents are a valuable instrument in wireless distributed monitoring networks, because they can be used to concentrate monitoring efforts in certain areas where an event is taking place. In this way, events can be tracked in a dynamic and efficient way. Mobile agents have to send messages to each other in order to coordinate their actions, and those messages need to be secured by crypto credentials. However, when agents are moved over wireless networks, how can credentials be protected from sniffing by an attacker, besides layer II encryption? Moreover, if a rogue agent is injected in the network, is it possible to limit the damages it can produce? The proposed approach bridges mediated RSA with the trusted platform modules, in order to provide an efficient and secure communication between agents. The communication is secured using indeed Identity based cryptography, while maintaing the compatibility with standard RSA and eliminating the mediator introduced by mediated RSA. We will show that this approach is convenient in terms of traffic overhead, perfectly applicable to existing trusted platform modules specifications and able to limit damages that both external and internal attackers can produce to the network. Copyright © 2013 John Wiley & Sons, Ltd. Leonardo Maccari, Romano Fantacci, Tommaso Pecorella, G. Ghettini, Francesco Chiti |
Secur. Commun. Networks | 1 |
| 2013 | An analysis of the Ninux wireless community networkabstractWireless community networks are wireless mesh networks created and managed by a local community with mainly two main goals: sharing Internet connection and supporting local services. They are an emerging trend in Europe and have received the attention of many researchers, since they are large accessible deployments of distributed wireless networks. This paper illustrates the features of the Rome-based Ninux community network, the largest in Italy, and studies some interesting features it offers related to routing metrics and centrality metrics. Leonardo Maccari |
WiMob | 1 |
| 2012 | A Collaborative Firewall for Wireless Ad-Hoc Social Networks
Leonardo Maccari |
SECRYPT | 1 |
| 2012 | How to reduce and stabilize MPR sets in OLSR networksabstractMPR selection is one of the most important and critical functions of OLSR. The OLSR standard specifies an algorithm that has good local properties in terms of number of MPR selected but does not use available information in order to reduce the global number of MPR nodes. MPR selection affects many network properties, from the actual logical topology, to the routing efficiency, to the protocol overhead and the broadcast/multicast delivery. This paper proposes and evaluates two simple modifications to the MPR selection strategy, which are oriented to global properties rather than local `optimality'. The results presented show that even marginal modifications of the heuristic lead to a performance improvement, with, for instance, a reduction of up to 15% in the number of control messages required to maintain the topology, a relevant gain specially when obtained without introducing any overhead in control messages. Leonardo Maccari, Renato Lo Cigno |
WiMob | 1 |
| 2010 | Analytical Model for Performance Analysis of IEEE 802.11 DCF Mechanism in Multi-Radio Wireless NetworksabstractWireless mesh networks suffer of scalability problems when the number of nodes grows. To solve this issue, wireless mesh networks with multi-interface nodes were introduced. In such networks it is possible to use multiple channels to implement spatial reuse of frequencies. These solutions offer a huge throughput performance improvement but they increase the complexity due to the need of implementing a selection interface policy. One of the most simple interface selection policy is random choice. In this paper we provide an analytical analysis of the Uniform Random Interface Selection strategy applied in a 802.11 DCF multi-radio network. Then we also present a set of performance results for the throughput and discard probability in function of the number of nodes and the number of interfaces. Luca Bencini, Romano Fantacci, Leonardo Maccari |
ICC | 3 |
| 2009 | A Novel Interface Selection Scheme for Multi-Interface Wireless Mesh NetworksabstractWireless mesh networks suffer of scalability problems when the number of nodes grows. To solve this issue, multi-interface wireless mesh networks were introduced. In such networks it is possible to use multiple channels to implement spatial reuse of frequencies. However, channel assignment schemes make this kind of networks complex to manage and limit their applicability in presence of mobile nodes. In this paper a novel technique is introduced for the optimization of resources allocation in a multi-interface wireless mesh network where channel assignment is fixed. With this technique the scalability of the network is improved and the support for mobility is easily granted. Andrea Barbieri, Romano Fantacci, Leonardo Maccari |
ICC | 3 |
| 2009 | Avoiding Eclipse Attacks on Kad/Kademlia: An Identity Based ApproachabstractKademlia is a Distributed hash table widely used in P2P networks that has been applied to commercial and non commercial distribution of files. In this paper the authors review some security issues connected with Kademlia and a technique to leverage its security using an external certification service. Romano Fantacci, Leonardo Maccari, Matteo Rosi, Luigi Chisci, Luca Maria Aiello, Marco Milanesio |
ICC | 2 |
| 2008 | Lightweight, Distributed Access Control for Wireless Sensor Networks Supporting MobilityabstractWireless sensor networks (WSN) are large scale networks of unattended devices, aimed at monitoring environmental parameters. Their extremely scarce hardware resources constitute a huge limitation to the use of standard security protocols to secure communications, so that custom ones must be designed. In this article we describe the development of a novel access control system for WSN based on a distributed threshold scheme. Our model gives support for mobility and limits the needed communication and consequent energy drain, which is a fundamental parameter for the lifetime of WSN. Leonardo Maccari, Lorenzo Mainardi, Maria Antonietta Marchitti, Neeli R. Prasad, Romano Fantacci |
ICC | 1 |
| 2008 | Fast distributed bi-directional authentication for wireless sensor networksabstractAbstract In this paper, we present the comparison between a distributed and a centralized authentication protocol for wireless sensor networks (WSN). We outline the difference between authentication and key‐agreement schemes and we propose a novel approach based on the use of polynomial functions to produce a distributed bi‐directional authentication. The advantages of this approach are: speed of operation that can allow multiple subsequent authentications, thus support to mobility; balanced energy consumption if compared with the imbalanced centralized approach and the prevention of partition attacks. Copyright © 2008 John Wiley & Sons, Ltd. Romano Fantacci, Francesco Chiti, Leonardo Maccari |
Secur. Commun. Networks | 3 |
| 2007 | Mesh Network Firewalling with Bloom FiltersabstractThe nodes of a multi-hop wireless mesh network often share a single physical media for terminal traffic and for the backhaul network, so that the available resources are extremely scarce. Under these conditions it is important to avoid that unwanted traffic may traverse the network subtracting resources to authorized terminals. Packet filtering in wireless mesh networks is an extremely challenging task, since the number of possible connections is quadratic with respect to the number of the terminals of the network; for each connection a rule is needed and the time needed for filtering grows linearly with the number of rules. Moreover nodes can be in possession of end users and the administrator might want to keep the explicit ruleset as much secret as possible while giving the nodes enough data to behave as a firewall. In this article we present a solution for distributed firewalling in multi-hop mesh networks based on the use of Bloom Filters, a powerful but compact data structure allowing probabilistic membership queries. Leonardo Maccari, Romano Fantacci, Pablo Neira Ayuso, Rafael M. Gasca |
ICC | 1 |
| 2007 | Security Analysis of IEEE 802.16abstractThis paper analyzes some critical security issues in the family of IEEE 802.16 standard that has not been addressed so far. In particular two of the key features of the standard, the dynamic resources allocation and the mesh mode revealed to be vulnerable to attacks that represent serious threats to the robustness and privacy of the communications. In the first case the attacker is able to reduce bandwidth assigned to its neighbors, with the aim of obtaining more resources for himself; in the second case, we observed that there might be no real privacy in communications between two nodes of the mesh network. These vulnerabilities are still present even after the latest amendment to the standard, IEEE 802.16e that solved some previously addressed security flaws. Leonardo Maccari, Matteo Paoli, Romano Fantacci |
ICC | 1 |
| 2007 | S.T.R.E.S.S. : Stress Testing and Reverse Engineering for System SecurityabstractIn modern wireless networks the functions included into layer II have to deal with complex problems, such as security and access control, that were previously demanded to upper layers. This growing complexity led some vendors to implement layer II primitives directly in software, e.g. IEEE 802.111 has been largely distributed as a software patch to be used with legacy 802.11b/g hardware. In any extremely complex software the likelihood of committing errors during the implementation raises, and it is well known that software bugs can lead to instability of the system and possibly to security vulnerability. Software bugs are the most common cause of successful attacks against any kind of network and represent a real plague for system administrators. Stress test is a widely used methodology to find and eliminate software bugs. In this paper we present a platform to perform a stress test of generic network protocols implementations but especially optimized for Layer II stress tests, that present specific problems. With our approach a generic network protocol described with ABNF language can be tested transmitting arbitrary frame sequences and interpreting the responses to verify consistence with the communication standard used. Our platform can interact dynamically with the tested machine (an access point, a router etc.) to verify its robustness and its compliance with the standard. Experiments confirmed the validity of our approach both as a stress test technique for system under development and as a reverse engineering technique for interaction with closed source system. Matteo Rosi, Leonardo Maccari, Romano Fantacci |
ICC | 2 |
| 2006 | Secure, fast handhoff techniques for 802.1X based wireless networkabstractWireless networks that support client mobility have to face the challenge of providing a secure, performant handoff between different access points. IEEE 802.1X [1] model provides a secure mechanism used by many standard protocols to securely generate keying material between two peer hosts when one of the two is accessing the network for first time, but that is hardly usable for reauthentication during handoff procedures without loss of performance. This paper deals with the proposal of a novel scheme to transport authentication credentials during handoff that uses a two-way only exchange with the backend authentication server maintaining the security of the system. As a high-level method it can be applied to different types of network, such as IEEE 802.11i [2] infrastructure or ad-hoc mode networks in a mesh environment. Leonardo Maccari, Romano Fantacci, Tommaso Pecorella, Federico Frosali |
ICC | 1 |