EDBT 2026 Demo / reviewers in the wild / expert
Filippo Cugini
dblp:93/3671
· DBLP profile ↗
32ranked-venue papers
2as first author
18since 2021 · last 2026
0000-0002-9840-0365ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 24 · 2 first-author · 13 since 2021Systems, architecture and hardware · 2 · 2 since 2021Security and privacy · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Multi-Partner Project: Enhancing Resilience, Efficiency, and Trustworthiness of Edge AI in Safety-Critical Systems (GuardAI)abstractAI at the network edge promises real-time perception and decision-making in safety-critical domains such as aerial robotics, autonomous vehicles, and 5G-enabled infrastructures. Yet, operating under resource constraints, dynamic, and adversarial conditions exposes edge AI systems to fragility, inefficiency, and security risks that threaten their safe operation. GuardAI, a Horizon Europe project, introduces a framework for resilient and trustworthy edge AI that unites three pillars: adversarial robustness, context-enhanced inference, and security-by-design. Initial project results include a diffusion-based adversarial purification framework optimized for real-time operation, lightweight deep unrolling architectures for LiDAR super-resolution with built-in outlier removal, and robust uncertainty quantification modules to improve confidence calibration. It further develops a context-enhanced inference engine that integrates visual, spatial, and operational context across multi-agent systems, and a risk-aware defense recommender that autonomously selects mitigation strategies based on evolving threat landscapes. Through representative Use Cases, covering monitoring with Unmanned Aerial Vehicle, decentralized 5G network analytics, and secure perception in connected autonomous vehicles, GuardAI demonstrates how robust and adaptive AI can be achieved within stringent edge constraints. Together, these technologies lay the groundwork for a new generation of secure, context-aware, and certifiable AI systems that can be trusted to operate autonomously in the physical world. Antonis D. Savva, Mehmet Demirel, Yeshwanth Kumar Adimoolam, Rafaella Elia, Alexandros Gkillas, Erion-Vasilis M. Pikoulis, Amalia Damianou, Charmaine Barker, Daniel Bethell, Ahmed Salah Tawfik Ibrahim, Filippo Cugini, Francesco Paolucci, Kyriakos Vlachos, Simos Gerasimou, Antonios Lalas, Konstantinos Votis, Aris S. Lalos, Christos Kyrkou, Theocharis Theocharides |
DATE | 12 |
| 2026 | P4 Semantic Steering for Serverless Environments
Layal Ismail, István Pelle, Francesco Paolucci, Balázs Sonkoly, Filippo Cugini |
ICC | 5 |
| 2026 | PQKE-hCPABE: A Hybrid CP-ABE Scheme with Post‑Quantum Key Exchange for Secure Multicast
Matteo Sandrucci, Rana Abubakar, Abraham Cano Aguilera, Francesco Fumagalli, Francesco Paolucci, Juan Jose Vegas Olmos, Piero Castoldi, Filippo Cugini |
SECRYPT (1) | 8 |
| 2026 | From packets to predictions on GPU: Accelerated graph-based intrusion detection systemabstract• From Packets to Predictions On GPU: accelerated Graph-based Intrusion Detection System Ahmed Salah Tawfik Ibrahim, Emilio Paolini, Filippo Cugini, Francesco Paolucci This manuscript presents an In-GPU GNN-based intrusion detection system. Below, we summarize the novel contributions introduced in this work: • End-to-End In-GPU Pipeline - Problem: CPU-side graph construction and host-device memory transfers dominate prediction latency in GNN-based IDS pipelines, hindering real-time deployment. - New contribution: We redesign node aggregation and adjacency generation as CUDA kernels and execute both graph construction and GNN inference entirely on the GPU. This eliminates copy overheads and exploits thread-level parallelism to reduce end-to-end latency while preserving detection accuracy. • Reduced Memory Requirements - Problem: Previous GNN-based intrusion detection systems are memory-hungry. - New contribution: In this version, this problem is mitigated by exploiting the sparse properties of the input graph to reduce the memory size required for the system to run. • Optimized Memory Access Pattern - Problem: GPU memory accesses patterns are typically not considered. - New contribution: Accesses to GPU global memory are optimized achieving better performance and lower execution time especially after reducing the memory requirements. Graph Neural Networks (GNNs) are effective in detecting cyberattacks thanks to their ability to model network traffic, capturing structural relationships within the network. However, the high latency of the graph construction phase directly translates into higher overall prediction time, posing a challenge to real-time deployment. Therefore, an optimized GPU-accelerated framework that leverages the structural properties of the traffic graph is proposed in this work. It builds upon the notion of a precomputed adjacency matrix that gets modified by each graph instance. GPU threads are further used to construct the nodes, achieving an end-to-end graph generation and inference fully within the GPU. The sparsity of the graph and the coalesced memory access pattern within the GPU threads are further exploited to optimize the process. This allows the GPU to build large graphs much faster than the CPU without affecting the classification accuracy. This speedup is prominent for large graphs of 700 packets with the GPU being almost 4.3 times faster, highlighting the effectiveness of the proposed approach in real-time deployments. Ahmed Salah Tawfik Ibrahim, Emilio Paolini, Filippo Cugini, Francesco Paolucci |
Comput. Networks | 3 |
| 2025 | 6GUPF: A DPU-based Programmable User Plane Function for Enhanced Flow-based QoSabstractTraditional 5G user plane function (UPF) architectures are software-based implementations that struggle to maintain performance. To meet the stringent quality of service (QoS) and scalability requirements of 5G under high session and data plane loads, a highly efficient next-generation UPF is required. In this paper, we present a next-generation 6GUPF that fully leverages the hardware acceleration of SmartNICs/DPUs. The 6GUPF is developed using DOCA Flow API, which enables fast, programmable packet processing directly in the data path, specifically for the N3 gNB network and N6 interfaces of datanet. The architecture integrates flow-based acceleration for stateful flow tracking and symmetric Receive Side Scaling (RSS) to utilize cores and manage non-blocking states efficiently. This will help minimize latency and avoid contention in multi-core environments. Our experiments show that hardware-offloaded UPF achieves an aggregate line rate of 400 Gbit/s, supports 1 million concurrent data streams, and scales up to 500,000 active User Equipment (UE) instances while maintaining QoS and session isolation. It also enables 40% lower latency compared to traditional software UPFs. Unlike Tofino-based P4 switch UPF designs, which are limited by SRAM and TCAM constraints when storing large-scale data streams, our DPU-based solution is ideal for high-density Protocol Data Unit (PDU) deployments without sacrificing programmability and performance. It creates a path for cloud-native, 6G UPF deployments that can scale to a wide range of workloads, from ultra-low-latency applications to large-scale IoT backhaul. Rana Abubakar, Ahmed Salah Tawfik Ibrahim, Francesco Paolucci, Andrea Sgambelluri, Piero Castoldi, Filippo Cugini, Juan Jose Vegas Olmos |
GLOBECOM | 6 |
| 2025 | IDS-NGNN: A SmartNIC-based Intrusion Detection System Based on Reduce and Merge Nested Graph Neural NetworksabstractThe growing complexity of network attacks has outpaced the capabilities of traditional intrusion detection systems (IDS), which often rely on flat data structures that fail to capture complex relationships within networks. To address this limitation, we propose IDS-NGNN, a novel IDS that integrates hardware-offload SmartNIC preprocessing with a nested graph neural network (NGNN) architecture. Unlike standard Graph Neural Networks (GNN), IDS-NGNN jointly captures local and global dependencies using a three-layer design: an internal GNN for host-level activity, a nested graph module for hierarchical aggregation, and an external GNN for inter-host communication. SmartNIC acceleration enables efficient real-time processing of large-scale graph-structured network data at the edge. We evaluate IDS-NGNN on six public IDS datasets, including CIC-IDS-2017, CSE-CIC-IDS-2018, and ToN-IoT. Experimental results demonstrate that IDS-NGNN achieves up to 95% accuracy and 92% F1-score, while maintaining efficiency suitable for real-time 100 Gbps deployments. Rana Abubakar, Francesco Paolucci, Filippo Cugini, Juan Jose Vegas Olmos, Lorenzo De Marinis |
GLOBECOM | 3 |
| 2024 | 5GDAD: A Deep Learning Approach for DDoS Attack Detection in 5G P4-based UPFabstractThe fast-paced growth of 5G networks, along with the emergence of 6G technology, has emphasized the crucial importance of strong security measures to safeguard communication infrastructures. A key security issue in 5G data networks is Distributed Denial-of-Service (DDoS) at tacks, which specifically target the GTP-based protocol which is a significant threat. However, network telemetry data provides a rich source of information about the nature of network traffic, which can be used to detect and predict DDoS attacks. We propose a novel framework for collecting and processing large amounts of telemetry data in 5G networks leveraging state-of-the-art technologies, including data-plane programmability in P4-based User-Plane Function (UPF) and Data Processing Unit (DPU). Furthermore, we propose an anomaly-detection method for performing live deep learning analysis on network traffic using a Convolutional Neural Network (CNN) to detect DDoS attacks. Our results demonstrate the effectiveness of our framework, achieving an impressive 98.6% accuracy and 98% F1-score. Rana Abubakar, Faris Alhamed, Piero Castoldi, Andrea Sgambelluri, Juan Jose Vegas Olmos, Filippo Cugini, Francesco Paolucci |
HPSR | 6 |
| 2024 | FTG-Net-E: A hierarchical ensemble graph neural network for DDoS attack detectionabstractDistributed Denial-of-Service (DDoS) attacks are a major threat to computer networks. These attacks can be carried out by flooding a network with malicious traffic, overwhelming its resources, and/or making it unavailable to legitimate users. Existing machine learning methods for DDoS attack detection typically use statistical features of network traffic, such as packet sizes and inter-arrival times. However, these methods often fail to capture the complex relationships between different traffic flows. This paper proposes a new DDoS attack detection approach that uses Graph Neural Networks (GNN) ensemble learning. GNN ensemble learning is a type of machine learning that combines multiple GNN models to improve the detection accuracy. We evaluated our approach on the Canadian Institute for Cybersecurity Intrusion Detection Evaluation Dataset (CICIDS2018) and CICIDS2017 datasets, a benchmark dataset for DDoS attack detection. Our work provides two main contributions. First, we extend our DDoS attack detection approach using GNN ensemble learning. Second, we explore the evaluation and fine-tuning of hyperparameter metrics through ensemble learning, significantly enhancing accuracy compared to a single GNN model and achieving an average 3.2% higher F1-score. Additionally, our approach effectively reduces overfitting by incorporating regularization techniques, such as dropout and early stopping. Specifically, we use a hierarchical ensemble of GNN, where each GNN learns the relationships between traffic flows at a different granularity level. We then use bagging and boosting to combine the predictions of the individual GNN, further improving detection accuracy. Results show that our system can achieve 99.67% accuracy, with a F1-score of 99.29%, which is better than state-of-the-art methods, even using single traffic architecture. Rana Abubakar, Lorenzo De Marinis, Filippo Cugini, Francesco Paolucci |
Comput. Networks | 3 |
| 2023 | Cascaded Look Up Table Distillation of P4 Deep Neural Network SwitchesabstractIn-network function offloading represents a key enabler of the SDN-based data plane programmability to enhance network operation and awareness while speeding up applications and reducing the energy footprint. The offload of network functions exploiting machine learning and artificial intelligence has been recently considered with intermediate solutions such as feature extraction acceleration and mixed architectures including AI-specific platforms (e.g., GPU, FPGA). Indeed, the P4 language enables the programmability of deep neural networks inside the pipelines of both software and hardware switches and NICs. However, programmable hardware pipeline chipsets suffer from significant computing capability limitations (e.g., missing arithmetic logic units, limited and slow stateful registers) preventing the plain programmability of a deep neural network (DNN) operating at wirespeed. This paper proposes an innovative knowledge distillation technique that maps a DNN into a cascade of lookup tables (i.e., flow tables) with limited entry size. The proposed mapping avoids stateful elements and maths operators, whose requirement prevented the deployment of DNNs within hardware switches up to now. The evaluation is carried out considering a cyber security use case targeting a DDoS mitigator network function, showing negligible impact due to the lossless mapping reduction and feature quantization. Lorenzo De Marinis, Emilio Paolini, Rana Abubakar, Filippo Cugini, Francesco Paolucci |
GLOBECOM | 4 |
| 2023 | FTG-Net: Hierarchical Flow-to-Traffic Graph Neural Network for DDoS Attack DetectionabstractDistributed Denial of Service (DDoS) is one of the most common cyber-attacks and caused several damages in recent years. Such attacks can be executed either through the orchestration of multiple devices that synchronously send requests or through specific patterns followed by a single device to force the victim to keep resources overrun. It becomes crucial to develop robust techniques to promptly detect those two kinds of DDoS attacks and mitigate their consequences. Most of the existing Machine Learning (ML) methods are based on flow and traffic information aggregations expressed in the form of independent vectors of statistical data, ignoring topological connections. Few recent solutions try to exploit the structural information of the network to improve the classification results. In particular, Graph Neural Network (GNN) based models can process traffic-level or flow-level relationships, represented as graphs, to detect malicious patterns.The objective of this paper is to combine the relationships at both the traffic-level and the flow-level by developing a two-level hierarchical graph representation and a GNN model able to process it, maximizing the information brought by the traffic structure and removing the necessity of stateful features. Experiments on the CIC-IDS2017 dataset show that the performances are comparable to the state-of-the-art solutions even using only the traffic structure. Luca Barsellotti, Lorenzo De Marinis, Filippo Cugini, Francesco Paolucci |
HPSR | 3 |
| 2023 | Failure Prediction in Software Defined Flying Ad-hoc NetworkabstractThis research aims to propose an approach to address the unpredictability topology state issue of FANET. The mobility of the network can lead to frequent link disruptions, causing communication unavailability. To mitigate this, our goal is to implement an AI algorithm that can identify patterns in UAV mobility, predict potential disconnections, and trigger rerouting/forwarding algorithms in advance. This paper presents an example of an SD-FANET able to provide wireless in-band telemetry to the AI-equipped edge node placed at the ground station, discusses the design of subsystems hosting the AI process, and demonstrates how a machine learning model can recognize critical network situations without relying on complex neural networks. Domenico Uomo, Andrea Sgambelluri, Piero Castoldi, Emiliano De Paoli, Francesco Paolucci, Filippo Cugini |
MobiHoc | 6 |
| 2023 | P4 Telemetry collector
Faris Alhamed, Davide Scano, Piero Castoldi, Juan Jose Vegas Olmos, Ilya Vershkov, Francesco Paolucci, Filippo Cugini |
Comput. Networks | 7 |
| 2023 | P4-assisted seamless migration of serverless applications towards the edge continuumabstractServerless computing has recently been presented as an effective technology for handling short-lived compute tasks in the cloud. It has the potential of becoming an attractive option also in the context of edge computing where resource-aware deployment, constrained by both limited edge computing resources and experienced latency, plays a vital role. In this paper, we present and experimentally validate a framework that oversees serverless applications in an edge computing scenario. It completely automates serverless application deployment and provides hitless dynamic migration of application compute tasks between a pair of edge nodes, paving the way for handling significantly more complex cases. The framework relies on an integrated deployment, monitoring and offloading infrastructure that enhances AWS IoT Greengrass features and performance. Our implementation provides two separate options for relocating compute tasks by steering application traffic towards the most suitable node. One builds on an on-the-fly application component reconfiguration, while the other selects the suitable node through P4 in-network processing of resource metrics emitted by the nodes. Our experimental demonstration evaluates the migration performance using a latency-sensitive application decomposed to serverless functions. Results reveal extremely fast dynamic reconfiguration and traffic rerouting operations. The used methods avoid congestion peaks at the edge and show no end-to-end latency increase upon migration between the nodes. István Pelle, Francesco Paolucci, Balázs Sonkoly, Filippo Cugini |
Future Gener. Comput. Syst. | 4 |
| 2023 | Experimental Demonstration of Partially Disaggregated Optical Network Control Using the Physical Layer Digital TwinabstractOptical communications and networking are fast becoming the solution to support ever-increasing data traffic across all segments of the network, expanding from core/metro networks to 5G/6G front-hauling. Therefore, optical networks need to evolve towards an efficient exploitation of the infrastructure by overcoming the closed and aggregated paradigm, to enable apparatus sharing together with the slicing and separation of the optical data plane from the optical control. In addition to the advantages in terms of efficiency and cost reduction, this evolution will increase network reliability, also allowing for a fine trade-off between robustness and maximum capacity exploitation. In this work, an optical network architecture is presented based on the physical layer digital twin of the optical transport used within a multi-layer hierarchical control operated by an intent-based network operating system. An experimental proof of concept is performed on a three-node network including up to 1000 km optical transmission, open re-configurable optical add & drop multiplexers (ROADMs) and whitebox transponders hosting pluggable multirate transceivers. The proposed solution is based on GNPy as the optical physical layer digital twin and ONOS as intent-based network operating system. The reliability of the optical control decoupled by the data plane functioning is experimentally demonstrated exploiting GNPy as open lightpath computation engine and software optical amplifier models derived from the component characterization. Besides the lightpath deployment exploiting the modulation format evaluation given a generic traffic request, the architecture reliability is tested mimicking the use case of an automatic failure recovery from a fiber cut. Giacomo Borraccini, Stefano Straullu, Alessio Giorgetti, Renato Ambrosone, Emanuele Virgillito, Andrea D'Amico, Rocco D'Ingillo, Francesco Aquilino, Antonino Nespola, Nicola Sambo, Filippo Cugini, Vittorio Curri |
IEEE Trans. Netw. Serv. Manag. | 11 |
| 2022 | Introducing Data Processing Units (DPU) at the Edge [Invited]abstractThe recent availability of smart network interface cards (smart NICs) and Data Processing units (DPUs) providing hardware-accelerated networking and computing functionalities is opening the way towards new applications and use cases beyond the traditional data center scenarios. In this paper, three different use cases for edge scenarios that leverage on the innovative programmability enabled by DPUs are presented and discussed. The first use case focuses on a pervasive monitoring infrastructure to support accurate and decentralized network awareness for low-latency 5G services. The second one focuses on the implementation of power-efficient edge-to-cloud continuum. The third use case refers to effective network security functions at the DPU. Luca Barsellotti, Faris Alhamed, Juan Jose Vegas Olmos, Francesco Paolucci, Piero Castoldi, Filippo Cugini |
ICCCN | 6 |
| 2021 | P4 Programmability at the Network Edge: the BRAINE Approach [Invited]abstractNetwork programmability based on the P4 language is gaining consensus in multiple scenarios, including edge computing. In this work, we present the P4-based edge networking solutions adopted in the framework of the EU-funded BRAINE Project. The project targets the design and development of a powerful edge micro data center (EMDC) aiming at boosting artificial intelligence (AI) at the network edge. The EMDC will encompass an embedded programmable P4 ASIC supporting unprecedented intra- and inter-edge/fog interconnection. In this paper, a selection of the solutions to be supported by the P4 switch embedded within the BRAINE EMDC is presented. They include decentralized traffic engineering solutions driven in-band telemetry (INT), quality of service enforcement and verification, 5G network function virtualization, and decentralized cyber-security at the edge. Filippo Cugini, Davide Scano, Alessio Giorgetti, Andrea Sgambelluri, Piero Castoldi, Francesco Paolucci |
ICCCN | 1 |
| 2021 | Latency-Sensitive Edge/Cloud Serverless Dynamic Deployment Over Telemetry-Based Packet-Optical NetworkabstractThe serverless technology, introduced for data center operation, represents an attractive technology for latency-sensitive applications operated at the edge, enabling a resource-aware deployment accounting for limited edge computing resources or end-to-end network congestion to the cloud. This paper presents and validates a framework for automated deployment and dynamic reconfiguration of serverless functions at either the edge or cloud. The framework relies on extensive telemetry data retrieved from both the computing and packet-optical network infrastructure and operates on diverse Amazon Web Services technologies, including Greengrass on the edge. Experimental demonstration with a latency-sensitive serverless application is then provided, showing fast dynamic reconfiguration capabilities, e.g., enabling even zero outage time under certain conditions. István Pelle, Francesco Paolucci, Balázs Sonkoly, Filippo Cugini |
IEEE J. Sel. Areas Commun. | 4 |
| 2021 | Soft-Failure Detection, Localization, Identification, and Severity Prediction by Estimating QoT Model Input ParametersabstractThe performance of optical devices can degrade because of aging and external causes like, for example, temperature variations. Such degradation might start with a low impact on the Quality of Transmission (QoT) of the supported lightpaths (soft-failure). However, it can degenerate into a hard-failure if the device itself is not repaired or replaced, or if an external cause responsible for the degradation is not properly addressed. In this work, we propose comparing the QoT measured in the transponders with the one estimated using a QoT tool. Those deviations can be explained by changes in the value of input parameters of the QoT model representing the optical devices, like noise figure in optical amplifiers and reduced Optical Signal to Noise Ratio in the Wavelength Selective Switches. By applying reverse engineering, the value of those modeling parameters can be estimated as a function of the observed QoT of the lightpaths. Experiments reveal high accuracy estimation of modeling parameters, and results obtained by simulation show large anticipation of soft-failure detection and localization, as well as accurate identification of degradations before they have a major impact on the network. Sima Barzegar, Marc Ruiz 0001, Andrea Sgambelluri, Filippo Cugini, Antonio Napoli, Luis Velasco 0001 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2020 | Machine-learning-assisted DDoS attack detection with P4 languageabstractWhile Software Defined Networking (SDN) provides well-known advantages in terms of network automation, flexibility and resources utilization, it has been observed that SDN controllers may represent critical points of failure for the entire network infrastructure, especially when they are targeted by malicious cyber attacks such as Distributed Denial of Service (DDoS). To address this issue, in this paper we exploit stateful data planes, as enabled by P4 programming language, where switches maintain persistent memory of handled packets to perform attack detection directly at the data plane, with only marginal involvement of the SDN controllers. As machine learning (ML) is recognized as primary anomaly detection methodology, we perform DDoS attack detection using a MLbased classification and compare different ML algorithms in terms of classification accuracy and train/test duration. Moreover, we combine ML and P4-enab1ed stateful data planes to design a real-time DDoS attack detection module, which we evaluate in terms of latency required for the detection. Three real-time scenarios are considered, where P4-enab1ed switches elaborate the received packets in different ways, namely, packet mirroring, header mirroring, and P4-metadata extraction. Numerical results show significant latency reduction when P4 is adopted. Francesco Musumeci 0001, Valentina Ionata, Francesco Paolucci, Filippo Cugini, Massimo Tornatore |
ICC | 4 |
| 2017 | Traffic engineering in segment routing networks
Eduardo Moreno 0001, Alejandra Beghelli, Filippo Cugini |
Comput. Networks | 3 |
| 2015 | Path Encoding in Segment RoutingabstractSegment Routing (SR) is emerging as an innovative traffic engineering technique compatible with traditional MPLS data plane. SR relies on label stacking, without requiring a signaling protocol. This greatly simplifies network operations in transit nodes. However, it may introduce scalability issues at the ingress node and packet overhead. Therefore, specific algorithms are required to efficiently compute the label stack for a given path. This study proposes two algorithms for SR label stack computation of strict routes that guarantee minimum label stack depth. Then, SR scalability performance is investigated. Results show that, in most of the cases, SR uses label stacks composed of few labels and introduces a limited packet overhead. However, relevant scalability issues may arise in specific cases, e.g., large planar topologies. Alessio Giorgetti, Piero Castoldi, Filippo Cugini, Jeroen Nijhof, Francesco Lazzeri, Gianmarco Bruno |
GLOBECOM | 3 |
| 2015 | Hierarchical OAM Infrastructure for Proactive Control of SDN-Based Elastic Optical NetworksabstractElastic Optical Networks will drive a high degree of flexibility enabling dynamic configurable lightpaths provisioning and re- optimization due to next generation bandwidth variable transponders and switches. In order to guarantee quality of transmission (QoT), novel Operation Administration and Maintenance (OAM) solutions are necessary with respect to existing standard management protocols. For optical networks, scalable mechanisms providing fast and effective QoT alarm information, including localization and, possibly, forecasting critical events, are needed. The introduction of the Application Based Network Operation (ABNO) architecture is pushing towards a dedicated OAM Handler, in charge of collecting OAM information from the network, performing correlations and triggering control plane reaction. However, serious scalability issues may arise since a centralized element would have to elaborate a potentially huge amount of data. In this paper, a novel hierarchical OAM architecture is proposed, that enables multi- level OAM entities to provide OAM Handler with effective information, obtained by filtering several OAM messages at each layer, so that the overload of OAM Handler is avoided. Moreover, the NETCONF protocol, typically used for SDN- based node configuration purposes, is proposed and utilized as OAM protocol, in order to achieve high degree of convergence and limit the number of utilized protocols. The proposed OAM architecture is implemented and experimentally evaluated in a QoT degradation use case, showing that multi-level localization and local correlation of events allow aggregated, fast and scalable OAM information set provided to the OAM Handler. Francesco Paolucci, Andrea Sgambelluri, Nicola Sambo, Filippo Cugini, Piero Castoldi |
GLOBECOM | 4 |
| 2013 | Performance Analysis of Media Redundancy Protocol (MRP)abstractThe International Electrotechnical Commission (IEC) recently standardized several Industrial Ethernet solutions that introduce the fieldbus concepts within Ethernet based networks. In addition, the IEC 62439 standardized a set of redundancy management protocols, including the Media Redundancy Protocol (MRP). In this way, IEC standards provide a variety of Ethernet-based solutions for satisfying both temporal and redundancy management requirements of Industrial Area Networks (IANs). In this paper, after a detailed study and implementation of MRP, two factors are identified that have an important impact on the protocol performance: the offset time and the physical detection time. A method is then provided to calculate a threshold to the network recovery time. Finally, extensive simulations and experimental measurements are performed to accurately evaluate the effect of the aforementioned factors on the protocol performance. Alessio Giorgetti, Filippo Cugini, Francesco Paolucci, Luca Valcarenghi, Alessia Pistone, Piero Castoldi |
IEEE Trans. Ind. Informatics | 2 |
| 2012 | Experimenting push-pull defragmentation in flexible optical networks with direct detectionabstractIn flexi-grid optical networks, effective defragmentation (i.e., re-optimization) solutions are required to efficiently exploit network spectrum resources. However, current defragmentation solutions can only be implemented thanks to the presence of additional resources, such as spare extensive transponders. In this study, focusing on optically-amplified direct-detection systems, we experimentally demonstrate the feasibility of a novel defragmentation technique, called push-pull, based on dynamic lightpath frequency retuning upon proper reconfiguration of allocated spectrum resources. The technique does not require additional transponders and does not determine traffic disruption. All the relevant technological limitations that may affect the push-pull applicability are discussed. A simple yet effective closed-form expression is also proposed and experimentally validated to assess the maximum retuning range in a single push-pull operation, such that the quality of transmission during defragmentation is safely guaranteed. The technique is then successfully demonstrated in a flexi-grid network testbed. In particular the reoptimization of one lightpath is safely completed in few seconds (mainly due just to node configuration latencies) without experiencing any traffic disruption. Filippo Cugini, Francesco Paolucci, Gianluca Berrettini, Marco Secondini, Francesco Fresi, Gianluca Meloni, Nicola Sambo, Luca Potì, Piero Castoldi |
GLOBECOM | 1 |
| 2010 | Hierarchical Border Gateway Protocol (HBGP) for PCE-Based Multi-Domain Traffic EngineeringabstractIn multi-domain multi-carrier networks the effective use of network resources shall be achieved while guaranteeing an adequate level of confidentiality and scalability. A candidate solution to perform effective multi- domain Traffic Engineering (TE) is based on a combination of (i) hierarchical routing and (ii) path computation procedures. Hierarchical routing identifies the domain sequence to cross while path computation computes the strict end to end path. In this multi-domain study we first propose a hierarchical instance of BGP (HBGP) dedicated to TE information only. Then we propose and evaluate the integration of HBGP with path computation procedures based on IETF PCE architecture. Simulation results show that the hierarchical HBGP-PCE architecture, compared to current routing solutions based on BGP only, significantly improves the overall network resource utilization. In addition, this study identifies the network scenarios in which the aforementioned HBGP-PCE features provide significant advantages. Finally, the experimental implementation of the proposed HBGP-PCE architecture in a network testbed composed of commercially available routers shows the viability of the solution in real networks. Luca Buzzi, Matteo Conforto Bardellini, Domenico Siracusa, Guido Maier, Francesco Paolucci, Filippo Cugini, Luca Valcarenghi, Piero Castoldi |
ICC | 6 |
| 2010 | PCE-Based Dynamic Restoration in Wavelength Switched Optical NetworksabstractIn GMPLS-controlled wavelength switched optical networks (WSONs), the RSVP-TE signaling protocol is utilized to reserve resources during both lightpath provisioning and dynamic restoration. During restoration, a number of reservation instances are contemporarily triggered by the failure. In such dynamic conditions, resource contention is the main blocking source. Several distributed solutions to reduce the impact of resource contention have been proposed that utilize advanced signaling mechanisms extending the RSVP-TE protocol. Conversely, this paper proposes two centralized solutions based on the Path Computation Element (PCE) that is used to coordinate the dynamic restoration of disrupted lightpaths with the specific aim of reducing resource contentions. Simulation results show that the utilization of the PCE during restoration reduces the blocking at the expenses of an increased recovery time with respect to distributed solutions. In addition, if the PCE is utilized together with the aforementioned advanced signaling mechanisms, the blocking can be further reduced. Alessio Giorgetti, Luca Valcarenghi, Filippo Cugini, Piero Castoldi |
ICC | 3 |
| 2009 | Experimental Evaluation of PCE-Based Batch Provisioning of Grid Service InterconnectionsabstractIf dynamic bandwidth-guaranteed connections between distributed services (e.g., grid services) are provisioned through a centralized system, the policy to serve connection requests might heavily impact both the success in and the time required for setting up user services (e.g., grid-enabled applications). In this paper, the implementation of a batch queue in the centralized system is proposed. By implementing different service policies for the queued requests, connections and, in consequence, user services can be set up with different guarantees. In this study, a bulk-service policy is proposed and implemented to maximize connection set up success. The experimental evaluation results show that the utilization of the proposed policy brings advantages in terms of percentage of accepted connection requests as the number of requests served in one batch increases. Moreover, the achieved improvement does not impact the time required to set up the connections because of the specific LSP set up procedures implemented in the utilized commercial routers. Luca Valcarenghi, Pawel Korus, Francesco Paolucci, Filippo Cugini, Miroslaw Kantor, Krzysztof Wajda, Piero Castoldi |
GLOBECOM | 4 |
| 2009 | A Recursive Distributed Topology Discovery Service for Network-Aware Grid ClientsabstractDistributed application (e.g., grid-enabled application) performance is highly dependent on the information available when computational resources are chosen. A resource selection based on computational resource information complemented with network performance information has the potential to be optimal from the application performance viewpoint. This is particularly true for network-intensive distributed applications. This study proposes a recursive distributed topology discovery service (RD-TDS) that allows grid clients to retrieve network performance information (i.e., IP-level topology and link capacity) without the need of specific administrative privileges. The RD-TDS exploits a selected set of distributed beacons (i.e., measurement points) that recursively probe newly discovered nodes until no undiscovered nodes are found during an exploration step. The RD-TDS simulative and experimental evaluation confirms its expected qualities: a rapid and complete discovery of the network performance information with the utilization of a limited number of active beacons. In addition, the proposed method rationale can be easily applied to many current network exploration tools. Francesco Paolucci, Luca Valcarenghi, Piero Castoldi, Filippo Cugini |
ICC | 4 |
| 2007 | Topology discovery and performance information services for optical gridsabstractGlobal Grid Computing goal is to connect heterogeneous computational resources belonging to the same Virtual Organization (VO) through the Internet to form a single, more powerful virtual computer. However, to fulfill this goal it is necessary to develop services that provide the virtual computer with the same functionalities of individual end systems, such as security, interprocess communication, and resource management. Luca Valcarenghi, Francesco Paolucci, Piero Castoldi, Filippo Cugini, Davide Adami, Domenico Ficara, Stefano Giordano |
BROADNETS | 4 |
| 2007 | The Beacon Number Problem in a Fully Distributed Topology Discovery ServiceabstractIn grid computing the need for collecting information about both distributed computational resources and network topology and performance is constantly growing. Several tools are currently under development to provide such information. They are based either on a centralized or a distributed architecture. Distributed tools are commonly based on IP-level application- oriented network metrology. The measurements are done by means of beacons running in some network nodes (e.g., grid hosts) and collecting the required information. However, the number of utilized beacons might heavily impact the final result, i.e. the discovered topology and the collected performance information. In this study a model is developed to estimate the percentage of discovered links provided that a specific number of beacons is placed in the network. The model is developed for Erdos-Renyi (ER) graph network models but it can be applied also to other networks. Numerical evaluation shows that the model closely approximate the percentage of discovered links obtained through simulation for ER networks. For other theoretical and real networks the model overestimates the percentage of discovered links. However experimental results show that for networks with realistic average nodal degree the overestimate is less than 20%. Domenico Ficara, Francesco Paolucci, Luca Valcarenghi, Filippo Cugini, Piero Castoldi, Stefano Giordano |
GLOBECOM | 4 |
| 2006 | Network Resource Management in High-Quality NetworksabstractThis paper presents the architecture, some specific supporting functions and an experimental validation of a new functional plane, namely the service plane, for realizing an added-value service provisioning (e.g., grid connectivity) for telecommunication operators. First, it is shown as the service plane can be a viable solution for decoupling service and transport development, by masking the transport-related implementation details from the abstract request of a service by a customer or by a qualified application. To this purpose, the service plane exports a high-level interface for supporting application-initiated invocation of QoS-enabled virtual private networks (VPN) or connection-less services. As a significant use case for a grid user, a VPN set-up through the service plane is experimentally demonstrated. Second, some of the main functions that the service plane should support are presented in detail and experimentally assessed, namely a centralized topology discovery service (C-TDS) and path computation service (PCS). As an example, from a grid user perspective, the C-TDS can provide up-to-date information on the grid topology according to various levels of abstraction (physical topology, MPLS topology, and logical topology). Several techniques for the grid topology discovery and various update policies are investigated. PCS elaborates upon the logical topology obtained by TDS and runs linear programming (LP) formulations to identify optimal traffic engineering solutions according to specific objective functions. The combination of C-TDS and PCS represents an an enhanced level of network- awareness in the (network) middleware supporting global grid computing (i.e., grid computing in wide area networks). Experiments performed on IP/MPLS metropolitan network based on commercial routers exhibit a topology delivery performance within a time span in the order of a few seconds and a PCS operation in the order of ten seconds. Piero Castoldi, Luca Valcarenghi, Francesco Paolucci, Valerio Martini, Fabio Baroncelli, Filippo Cugini, Barbara Martini |
BROADNETS | 6 |
| 2006 | GMPLS Signaling Feedback for Encompassing Physical Impairments in Transparent Optical NetworksabstractNext generation GMPLS networks will be characterized by domains of transparency, in which the end-to-end optical signal quality has to be guaranteed. Currently GMPLS does not take into account the evaluation of physical impairments. Thus just limited size domains of transparency, where physical impairments can be neglected, are practically achievable. This study utilizes GMPLS signaling protocol extensions to encompass the optical layer physical impairments. The proposed approach allows to detect during the signaling phase whether lightpaths cannot be set up because of unacceptable optical signal quality. In this case successive set up attempts are performed, selecting the alternative routes with three schemes which exploit the feedback information of the signaling messages. Numerical results show that the proposed extensions are able to significantly decrease the lightpath blocking probability due to physical impairments in both static and dynamic conditions. Nicola Sambo, Alessio Giorgetti, Nicola Andriolli, Filippo Cugini, Luca Valcarenghi, Piero Castoldi |
GLOBECOM | 4 |