EDBT 2026 Demo / reviewers in the wild / expert
Marinho P. Barcellos
dblp:b/MarinhoPBarcellos · also Antônio Marinho Pilla Barcellos, Marinho Barcellos
· DBLP profile ↗
67ranked-venue papers
7as first author
11since 2021 · last 2025
0000-0002-1505-6408ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 48 · 4 first-author · 6 since 2021Security and privacy · 6 · 1 first-author · 4 since 2021Systems, architecture and hardware · 2 · 2 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A First Look at the Adoption of BGP-based DDoS Scrubbing Services: A 5-year Longitudinal AnalysisabstractBesides being the de facto routing protocol of the Internet, the Border Gateway Protocol (BGP) has also been used for mitigating Distributed Denial of Service (DDoS) attacks for many years. In such situations, victims of DDoS attacks use BGP to redirect attack traffic to a “scrubber” outside their network, which separates clean traffic from DDoS traffic and forwards the former to the victim’s network. While there exist many BGP-based DDoS scrubbing providers, their adoption on the global Internet remains unstudied. This paper aims to fill this gap by identifying and characterizing Autonomous Systems (ASes) and prefixes protected by five of the leading scrubbing providers, using AS path patterns in public BGP routing data. Our study focuses on scrubbers that allow their protected ASes to originate their prefixes themselves. We find that the percentage of ASes using this kind of protection has increased almost three times (from 0.7% to 2% and from 464 ASes to 1,730 ASes) between 2020 and 2024. Similarly, the percentage of protected prefixes has also increased three times in the same period, from 0.3% to 0.9% and from 3,154 to 12,362 prefixes, across both IPv4 and IPv6. Globally, we observe a higher adoption rate among financial institutions, while adoption remains low among educational institutions. We believe our insights will be useful for individual AS operators to find the transit providers or peers that are DDoS-protected. It might also be useful for (national) policy-makers to incentivize the adoption of DDoS protection services and for researchers studying the phenomenon of DDoS scrubbing. Shyam Krishna Khadka, Suzan Bayhan, Ralph Holz, Saeedeh Shokoohi, Marinho P. Barcellos, Cristian Hesselman |
CNSM | 5 |
| 2025 | Guest Editorial: Special Issue on Advances in Internet Routing and Addressing
Jon Crowcroft, Jörg Ott, Miguel Rio, Noa Zilberman, Marinho P. Barcellos, Marwan Fayed |
IEEE J. Sel. Areas Commun. | 5 |
| 2024 | The Age of DDoScovery: An Empirical Comparison of Industry and Academic DDoS AssessmentsabstractMotivated by the impressive but diffuse scope of DDoS research and reporting, we undertake a multistakeholder (joint industry-academic) analysis to seek convergence across the best available macroscopic views of the relative trends in two dominant classes of attacks - direct-path attacks and reflection-amplification attacks. We first analyze 24 industry reports to extract trends and (in)consistencies across observations by commercial stakeholders in 2022. We then analyze ten data sets spanning industry and academic sources, across four years (2019-2023), to find and explain discrepancies based on data sources, vantage points, methods, and parameters. Our method includes a new approach: we share an aggregated list of DDoS targets with industry players who return the results of joining this list with their proprietary data sources to reveal gaps in visibility of the academic data sources. We use academic data sources to explore an industry-reported relative drop in spoofed reflection-amplification attacks in 2021-2022. Our study illustrates the value, but also the challenge, in independent validation of security-related properties of Internet infrastructure. Finally, we reflect on opportunities to facilitate greater common understanding of the DDoS landscape. We hope our results inform not only future academic and industry pursuits but also emerging policy efforts to reduce systemic Internet security vulnerabilities. Raphael Hiesgen, Marcin Nawrocki, Marinho P. Barcellos, Daniel Kopp, Oliver Hohlfeld, Echo Chan, Roland Dobbins, Christian Doerr, Christian Rossow, Daniel R. Thomas, Mattijs Jonker, Ricky K. P. Mok, Xiapu Luo, John Kristoff, Thomas C. Schmidt, Matthias Wählisch, K. C. Claffy |
IMC | 3 |
| 2024 | Quantifying Privacy in Cooperative Awareness Services Through Trajectory ReconstructionabstractCooperatively creating awareness of the vehicle and its surroundings can improve the safety of the transportation system. Creating such awareness involves frequently sharing the vehicle's location and kinematics information with its surroundings, which can be achieved by broadcasting Cooperative Awareness Messages (CAMs) or Basic Safety Messages (BSMs). The receivers of these messages know the current location and kinematics of the sender and can estimate the possibility of collision. However, continuously receiving CAMs/BSMs allows the receiver to reconstruct the sender's trajectory, in which the full trajectory may reveal information about the users, such as, house and workplace location. Hence, the user's privacy is violated. Prior works focused only on location-based trajectory reconstruction and ignored the other kinematics, such as heading and speed. Ignoring such information could lead to underestimating the adversary who seeks to misuse the communication. This work analyses the privacy loss which arises from additional information in BSMs/CAMs. We propose a trajectory reconstruction model that leverages all kinematics (AKs), including location, heading, and speed. The trajectory reconstruction model is composed of two sub-models, namely, inference and data association models. The first sub-model estimates the probability from the estimated value of a vehicle's kinematics, and the second sub-model performs linking between pseudonyms. We quantify the privacy loss regarding the precision, recall, and F1-score of the ability to identify the correct link between pseudonyms with AK s-based trajectory reconstruction and compare the proposed model with the location-based approach. We also quantify the users' privacy through the uncertainty in the trajectory reconstruction process. We show that, in some scenarios, the AK s-based trajectory reconstruction gains higher precision, recall, F1-score, and certainty in trajectory reconstruction compared to the location-based approach. Atthapan Daramas, Vimal Kumar 0001, Marinho P. Barcellos |
PST | 3 |
| 2024 | PoT-PolKA: Let the Edge Control the Proof-of-Transit in Path-Aware NetworksabstractThis paper presents a scalable and efficient solution for secure network design that involves the selection and verification of network paths. The proposal addresses the challenges related to compliance policies by introducing a Proof-of-Transit (PoT) feasible implementation for path-aware programmable networks. Our approach relies on i) a source routing mechanism based on a fixed routeID representing a unique identifier per path, which serves as a key for PoT lookup tables; ii) the "in situ" that allows to collect telemetry information in the packet while the packet traverses a path. The former enables path selection with policy at the edge, while the later allows to perform path verification without extra probe-traffic. A P4 programmable language prototype demonstrates the effectiveness of this approach to protect against deviation attacks with low overhead. The results show its scalability considering the protocol overhead as the path length increases; a significant reduction in network’s forwarding state for fat-tree topologies depending on the workload per path (flows/path). Finally, experimental results show a RTT comparison evaluation, the impact of PoT computation, protection to path deviation and seamless path migration keeping flow protection. Everson Scherrer Borges, Magnos Martinello, Vitor Berger Bonella, Abraão Jesus dos Santos, Roberta Lima-Gomes, Cristina K. Dominicini, Rafael S. Guimarães, Gabriel Tetzner Menegueti, Marinho P. Barcellos, Marco Ruffini |
IEEE Trans. Netw. Serv. Manag. | 9 |
| 2024 | Analyzing Remote Peering Deployment and Its Implications for Internet RoutingabstractInternet eXchange Points (IXPs) have significantly transformed the structure and economics of the Internet by allowing many nearby networks to connect directly, avoiding the need for service providers. These large IXPs are so beneficial that they are not just used by nearby networks, but also by far away Autonomous Systems (AS). This is made possible by Remote Peering (RP), which typically involves the use of RP resellers to access remote IXPs. In this paper, we evaluate the effects of RP on four different routing aspects, using a representative group of IXPs located on three continents: (a) growth of RP deployment over one and a half years; (b) presence of route announcement mispractices (when networks prioritize the remote IXP over the local IXP), which are associated to routing anomalies; (c) reliability of RP interfaces and (d) adoption of RP-related BGP communities, i.e. to perform traffic engineering to remote peers. We make our data and results available to the community via a web portal. Fabrício M. Mazzola, Augusto Setti, Pedro de B. Marcos, Marinho P. Barcellos |
IEEE/ACM Trans. Netw. | 4 |
| 2023 | Provable Non-Frameability for 5G Lawful InterceptionabstractMobile networks have grown in size and relevance, with novel applications in areas including transportation, finance, and health. The wide use of mobile networks generates rich data about users, raising interest in using such data for law enforcement and antiterrorism through Lawful Interception (LI). Countries worldwide have established legal frameworks to conduct LI, and technical standards have been created for its implementation and deployment, but without sufficient (and rigorous) security controls. While LI originated for benign purposes, we show in this paper that malicious entities could exploit it to frame users into suspicion of criminal activity. Further, we propose a solution for non-frameability, which we formally prove uphold desired properties even in scenarios where attackers completely infiltrate the operator networks. To perform the formal verification, we extend prior work with a more complete model of the fifth generation (5G) of mobile networks in the Tamarin prover. Felipe Boeira, Mikael Asplund, Marinho P. Barcellos |
WISEC | 3 |
| 2022 | Light, camera, actions: characterizing the usage of IXPs' action BGP communitiesabstractBorder Gateway Protocol (BGP) communities, an optional message attribute, allow network operators to tag BGP announcements and act on routing decisions. Although widely used, it is so far unclear how prevalent the different types of communities are and the degree to which the different traffic engineering actions have been used. There are two major reasons for this gap: few community values have been standardised and the limited visibility at route collectors. Fabrício M. Mazzola, Pedro de B. Marcos, Marinho P. Barcellos |
CoNEXT | 3 |
| 2022 | On the Latency Impact of Remote Peering
Fabrício M. Mazzola, Pedro de B. Marcos, Ignacio Castro, Matthew J. Luckie, Marinho P. Barcellos |
PAM | 5 |
| 2022 | No Doppelgänger: Advancing Mobile Networks Against Impersonation in Adversarial ScenariosabstractThe expansion of mobile network capabilities throughout the decades has increased people's exposure to the digital world, and the next generations of communication networks are expected to achieve ubiquitous connectivity and immersive use cases. Security and privacy concerns have arisen and are continuously taken into account in the design of mobile networks. However, a relevant limitation currently lies in the use of shared secrets for providing security and privacy to users. Ideally, we believe that users' identities should be immune to impersonation as long as their own devices remain secure, notwithstanding the network operators and other entities potentially being compromised. In this paper, we develop this idea with the objective of providing the non-repudiation property, which represents a mitigation to its dual, impersonation. Felipe Boeira, Mikael Asplund, Marinho P. Barcellos |
WISEC | 3 |
| 2021 | Dynamic Property Enforcement in Programmable Data PlanesabstractNetwork programmers can currently deploy an arbitrary set of protocols in forwarding devices through data plane programming languages such as P4. However, as any other type of software, P4 programs are subject to bugs and misconfigurations. Network verification tools have been proposed as a means of ensuring that the network behaves as expected, but these tools frequently face severe scalability issues. In this paper, we argue for a novel approach to this problem. Rather than statically inspecting a network configuration looking for bugs, we propose to enforce networking properties at runtime. To this end, we developed P4box, a system for deploying runtime monitors in programmable data planes. P4box allows programmers to easily express a broad range of properties (both program-specific and network-wide). Moreover, we provide an automated framework based on assertions and symbolic execution for ensuring monitor correctness. Our experiments on a SmartNIC show that P4box monitors represent a small overhead to network devices in terms of latency, throughput and power consumption. Miguel C. Neves, Bradley Huffaker, Kirill Levchenko, Marinho P. Barcellos |
IEEE/ACM Trans. Netw. | 4 |
| 2020 | AS-Path Prepending: there is no rose without a thornabstractInbound traffic engineering (ITE)---the process of announcing routes to, e.g., maximize revenue or minimize congestion---is an essential task for Autonomous Systems (ASes). AS Path Prepending (ASPP) is an easy to use and well-known ITE technique that routing manuals show as one of the first alternatives to influence other ASes' routing decisions. We observe that origin ASes currently prepend more than 25% of all IPv4 prefixes. Pedro de B. Marcos, Lars Prehn, Lucas Leal, Alberto Dainotti, Anja Feldmann, Marinho P. Barcellos |
Internet Measurement Conference | 6 |
| 2020 | Spoofed traffic inference at IXPs: Challenges, methods and analysis
Lucas F. Müller, Matthew J. Luckie, Bradley Huffaker, K. C. Claffy, Marinho P. Barcellos |
Comput. Networks | 5 |
| 2019 | Challenges in inferring spoofed traffic at IXPsabstractAscertaining that a network will forward spoofed traffic usually requires an active probing vantage point in that network, effectively preventing a comprehensive view of this global Internet vulnerability. Recently, researchers have proposed using Internet Exchange Points (IXPs) as observatories to detect spoofed packets, by leveraging Autonomous System (AS) topology knowledge extracted from Border Gateway Protocol (BGP) data to infer which source addresses should legitimately appear across parts of the IXP switch fabric. We demonstrate that the existing literature does not capture several fundamental challenges to this approach, including noise in BGP data sources, heuristic AS relationship inference, and idiosyncrasies in IXP interconnectivity fabrics. We propose a novel method to navigate these challenges, leveraging customer cone semantics of AS relationships to guide precise classification of inter-domain traffic as in-cone, out-of-cone (spoofed), unverifiable, bogon, and unassigned. We apply our method to a mid-size IXP with approximately 200 members, and find an upper bound volume of out-of-cone traffic to be more than an order of magnitude less than the previous method inferred on the same data. Our work illustrates the subtleties of scientific assessments of operational Internet infrastructure, and the need for a community focus on reproducing and repeating previous methods. Lucas F. Müller, Matthew J. Luckie, Bradley Huffaker, K. C. Claffy, Marinho P. Barcellos |
CoNEXT | 5 |
| 2019 | Dynamic Property Enforcement in Programmable Data PlanesabstractNetwork programmers can currently deploy an arbitrary set of protocols in forwarding devices through data plane programming languages such as P4. However, as any other type of software, P4 programs are subject to bugs and misconfigurations. Network verification tools have been proposed as a means of ensuring that the network behaves as expected, but these tools typically require programmers to manually model P4 programs, are limited in terms of the properties they can guarantee and frequently face severe scalability issues. In this paper, we argue for a novel approach to this problem. Rather than statically inspecting a network configuration looking for bugs, we propose to enforce networking properties at runtime. To this end, we developed P4box, a system for deploying runtime monitors in programmable data planes. Our results show that P4box allows programmers to easily express a broad range of properties. Moreover, we demonstrate that runtime monitors represent a small overhead to network devices in terms of latency and resource consumption. Miguel C. Neves, Bradley Huffaker, Kirill Levchenko, Marinho P. Barcellos |
Networking | 4 |
| 2019 | Decentralized proof of location in vehicular Ad Hoc networks
Felipe Boeira, Mikael Asplund, Marinho P. Barcellos |
Comput. Commun. | 3 |
| 2018 | Dynam-IX: a dynamic interconnection eXchangeabstractAutonomous Systems (ASes) can reach hundreds of networks via Internet eXchange Points (IXPs), allowing improvements in traffic delivery performance and competitiveness. Despite the benefits, any pair of ASes needs first to agree on exchanging traffic. By surveying 100+ network operators, we discovered that most interconnection agreements are established through ad-hoc and lengthy processes heavily influenced by personal relationships and brand image. As such, ASes prefer long-term agreements at the expense of a potential mismatch between actual delivery performance and current traffic dynamics. ASes also miss interconnection opportunities due to trust reasons. To improve wide-area traffic delivery performance, we propose Dynam-IX, a framework that allows operators to build trust cooperatively and implement traffic engineering policies to exploit the rich interconnection opportunities at IXPs quickly. Dynam-IX offers a protocol to automate the interconnection process, an intent abstraction to express interconnection policies, a legal framework to digitally handle contracts, and a distributed tamper-proof ledger to create trust among ASes. We build and evaluate a Dynam-IX prototype and show that an AS can establish tens of agreements per minute with negligible overhead for ASes and IXPs. Pedro de B. Marcos, Marco Chiesa, Lucas F. Müller, Pradeeban Kathiravelu, Christoph Dietzel, Marco Canini, Marinho P. Barcellos |
CoNEXT | 7 |
| 2018 | Verification of P4 programs in feasible time using assertionsabstractRecent trends in software-defined networking have extended network programmability to the data plane. Unfortunately, the chance of introducing bugs increases significantly. Verification can help prevent bugs by assuring that the program does not violate its requirements. Although research on the verification of P4 programs is very active, we still need tools to make easier for programmers to express properties and to rapidly verify complex invariants. In this paper, we leverage assertions and symbolic execution to propose a more general P4 verification approach. Developers annotate P4 programs with assertions expressing general network correctness properties; the result is transformed into C models and all possible paths symbolically executed. We implement a prototype, and use it to show the feasibility of the verification approach. Because symbolic execution does not scale well, we investigate a set of techniques to speed up the process for the specific case of P4 programs. We use the prototype implemented to show the gains provided by three speed up techniques (use of constraints, program slicing, parallelization), and experiment with different compiler optimization choices. We show our tool can uncover a broad range of bugs, and can do it in less than a minute considering various P4 applications. Miguel C. Neves, Lucas Freire, Alberto E. Schaeffer Filho, Marinho P. Barcellos |
CoNEXT | 4 |
| 2018 | Vouch: A Secure Proof-of-Location Scheme for VANETsabstractIn Vehicular Ad Hoc Networks (VANETs), nodes periodically share beacons in order to convey information about identity, velocity, acceleration, and position. Truthful positioning of nodes is essential for the proper behavior of applications, including the formation of vehicular platoons. Incorrect position information can cause problems such as increased fuel consumption, reduced passenger comfort, and in some cases even accidents. In this paper, we design and evaluate Vouch: a secure proof-of-location scheme tailored for VANETs. The scheme leverages the node positioning capability of fifth generation (5G) wireless network roadside units. The key idea of Vouch is to disseminate periodic proofs of location, combined with plausibility checking of movement between proofs. We show that Vouch can detect position falsification attacks in high-speed scenarios without incurring a large overhead. Felipe Boeira, Mikael Asplund, Marinho P. Barcellos |
MSWiM | 3 |
| 2017 | POSTER: Finding Vulnerabilities in P4 Programs with Assertion-based VerificationabstractCurrent trends in SDN extend network programmability to the data plane through the use of programming languages such as P4. In this context, the chance of introducing errors and consequently software vulnerabilities in the network increases significantly. Existing data plane verification mechanisms are unable to model P4 programs or present severe restrictions in the set of modeled properties. To overcome these limitations and make programmable data planes more secure, we present a P4 program verification technique based on assertion checking and symbolic execution. First, P4 programs are annotated with assertions expressing general correctness and security properties. Then, the annotated programs are transformed into C code and all their possible paths are symbolically executed. Results show that it is possible to prove properties in just a few seconds using the proposed technique. Moreover, we were able to uncover two potential vulnerabilities in a large scale P4 production application. Lucas Freire, Miguel C. Neves, Alberto E. Schaeffer Filho, Marinho P. Barcellos |
CCS | 4 |
| 2017 | Exploiting parallelism in hierarchical content stores for high-speed ICN routers
Rodrigo B. Mansilha, Marinho P. Barcellos, Emilio Leonardi, Dario Rossi 0001 |
Comput. Networks | 2 |
| 2017 | Achieving minimum bandwidth guarantees and work-conservation in large-scale, SDN-based datacenter networks
Daniel S. Marcon, Fabrício M. Mazzola, Marinho P. Barcellos |
Comput. Networks | 3 |
| 2017 | NDNrel: A mechanism based on relations among objects to improve the performance of NDN
Rodolfo Stoffel Antunes, Matheus B. Lehmann, Rodrigo B. Mansilha, Luciano Paschoal Gaspary, Marinho P. Barcellos |
J. Netw. Comput. Appl. | 5 |
| 2016 | Providing producer mobility support in NDN through proactive data replicationabstractNamed Data Networking (NDN) is a novel architecture expected to overcome limitations of the current Internet. User mobility is one of the most relevant limitations to be addressed. NDN supports consumer mobility by design but fails to offer the same level of support for producer mobility. Existing approaches to extend NDN are host-centric, which conflicts with NDN principles, and provide limited support for producer mobility. This paper proposes a content-centric strategy that replicates and pushes objects proactively, and unlike previous approaches, takes full advantage of NDN routing and caching features. We compare the proposed strategy with default NDN mechanisms regarding content availability, consumer performance, and network overhead. The evaluation results indicate that our strategy can increase the hit rate of objects by at least 46% and reduce their retrieval time by over 60%, while not adding significant overhead. Matheus B. Lehmann, Marinho P. Barcellos, Andreas Mauthe |
NOMS | 2 |
| 2016 | ASTORIA: A framework for attack simulation and evaluation in smart gridsabstractElectric power grids are undergoing a modernization process. By relying on the ICT infrastructure and on Internet connectivity, these so-called Smart Grids are now able to provide new functionalities and to become more efficient. However, despite the existence of a few standards that aim to specify the secure operation of Smart Grids, utility companies do not have a comprehensive set of metrics and evaluation tools for assessing security properties in these infrastructures. Thus, it is necessary to develop new toolsets to provide support for vulnerability analysis in Smart Grids. This paper proposes ASTORIA, a framework developed to allow the simulation of attacks and the evaluation of their impact on Smart Grid infrastructures, using closely-related real devices and real topologies comprising both power grid elements as well as ICT and networking equipment. We anticipate that ASTORIA can be used by Smart Grid operators not only to analyze the impact of malicious attacks and other security threats in different components, but also to permit the development and evaluation of anomaly detection techniques in a simulation environment. Further, we present evaluation scenarios illustrating customizable Smart Grid topologies, comprising sensors, master and remote stations, and using an extensible set of attack profiles. Alexandre Gustavo Wermann, Marcelo Cardoso Bortolozzo, Eduardo Germano da Silva, Alberto E. Schaeffer Filho, Luciano Paschoal Gaspary, Marinho P. Barcellos |
NOMS | 6 |
| 2016 | Making puzzles green and useful for adaptive identity management in large-scale distributed systems
Weverton Luis da Costa Cordeiro, Flavio Santos, Marinho P. Barcellos, Luciano Paschoal Gaspary, Hanna Kavalionak, Alessio Guerrieri, Alberto Montresor |
Comput. Networks | 3 |
| 2016 | A toolset for efficient privacy-oriented virtual network embedding and its instantiation on SDN/OpenFlow-based substrates
Leonardo Richter Bays, Rodrigo Ruas Oliveira, Luciana S. Buriol, Marinho P. Barcellos, Luciano Paschoal Gaspary |
Comput. Commun. | 4 |
| 2016 | PredCloud: Providing predictable network performance in large-scale OpenFlow-enabled cloud platforms through trust-based allocation of resources
Daniel S. Marcon, Miguel C. Neves, Rodrigo Ruas Oliveira, Luciano Paschoal Gaspary, Marinho P. Barcellos |
Comput. Commun. | 5 |
| 2016 | How physical network topologies affect virtual network embedding quality: A characterization study based on ISP and datacenter networks
Marcelo Caggiani Luizelli, Leonardo Richter Bays, Luciana S. Buriol, Marinho P. Barcellos, Luciano Paschoal Gaspary |
J. Netw. Comput. Appl. | 4 |
| 2015 | IoNCloud: Exploring application affinity to improve utilization and predictability in datacentersabstractThe intra-cloud network is typically shared in a best-effort manner, which causes tenant applications to have no actual bandwidth guarantees. Recent proposals address this issue either by statically reserving a slice of the physical infrastructure for each application or by providing proportional sharing among flows. The former approach results in overprovisioned network resources, while the latter requires substantial management overhead. In this paper, we introduce a resource allocation strategy that aims at providing an efficient way to predictably share bandwidth among applications and at minimizing resource underutilization while maintaining low management overhead. To demonstrate the benefits of the strategy, we develop IoNCloud, a system that implements the proposed allocation scheme. IoNCloud employs the abstraction of attraction/repulsion among applications according to their temporal bandwidth demands in order to group them in virtual networks. In doing so, we explore the trade-off between high resource utilization (which is desired by providers to achieve economies of scale) and strict network guarantees (necessary for tenants to run jobs predictably). Evaluation results show that IoNCloud can (a) provide predictable network sharing; and (b) reduce allocated bandwidth, resource underutilization and management overhead when compared against state-of-the-art proposals. Daniel S. Marcon, Miguel C. Neves, Rodrigo Ruas Oliveira, Leonardo Richter Bays, Raouf Boutaba, Luciano Paschoal Gaspary, Marinho P. Barcellos |
ICC | 7 |
| 2015 | Off the wire control: Improving the control plane resilience through cellular networksabstractSoftware Defined Networks simplify network programmability by detaching the control plane from forwarding devices and deploying it into a logically centralized controller. While this allows a clearer separation of concerns, it also creates a dependency between them. Failures in the control plane break the controller view of the network state and could render the network unusable if forwarding devices cannot be reached. The relevance of this problem has led to a range of proposals, including physical distribution of controller instances and delegation of concerns to forwarding devices. In this paper, we propose and evaluate an architecture that leverages cellular data networks (4G) as control plane backup links. No previous work has explored this idea, despite the recent research intersecting SDN and wireless networks. Our experiments answer three research questions: (i) How is the behavior of control plane traffic affected by the characteristics of cellular links, (ii) how quickly is the control plane handed over to the backup link when a failure occurs and (iii) how well do network functions that rely on a snapshot of the network state behave on such an architecture. Our evaluation shows that, despite the expected higher latency of cellular links, this architecture maintains partial functionality of tasks that depend on global network awareness when failures occur in primary links in a simple, affordable fashion. Tobias Petry, Rafael da Fonte Lopes da Silva, Marinho P. Barcellos |
ICC | 3 |
| 2015 | CCNrel: Leveraging relations among objects to improve the performance of CCNabstractContent-Centric Networking (CCN) is a promising architectural approach that focuses on the efficient distribution of uniquely named data objects. A piece of content is represented by a single object in the network and is divided into multiple chunks which can be uniquely named and cached by network nodes. However, in its current form, the potential of CCN is not fully exploited due to the lack of common means to express and take advantage from possible relations that may exist among different objects. Our work explores the simple yet effective idea of supporting and exploiting such relations in CCN. In this paper, we present CCNrel as a backward-compatible mechanism for CCN that enables publishers to distribute contents as related objects. Differently from existing relation mechanisms, which focus on one type of content and are application-specific, CCNrel is generic and enables the use of relations in both current and novel application domains. First, we discuss CCNrel fundamental concepts and main design aspects. Next, we use CCNrel as foundation for a case study of data redundancy elimination in multimedia content distribution. Through extensive simulation work we evaluate the potential benefits of leveraging relations measured by the clients experience and overall network efficiency. Results of the presented use case show that, on average and when compared to default CCN operations, content download times are improved in 34%, publishers load in 56%, and the network bandwidth usage in 43%. Rodolfo Stoffel Antunes, Matheus B. Lehmann, Rodrigo B. Mansilha, Christian Esteve Rothenberg, Luciano Paschoal Gaspary, Marinho P. Barcellos |
IM | 6 |
| 2015 | Piecing together the NFV provisioning puzzle: Efficient placement and chaining of virtual network functionsabstractNetwork Function Virtualization (NFV) is a promising network architecture concept, in which virtualization technologies are employed to manage networking functions via software as opposed to having to rely on hardware to handle these functions. By shifting dedicated, hardware-based network function processing to software running on commoditized hardware, NFV has the potential to make the provisioning of network functions more flexible and cost-effective, to mention just a few anticipated benefits. Despite consistent initial efforts to make NFV a reality, little has been done towards efficiently placing virtual network functions and deploying service function chains (SFC). With respect to this particular research problem, it is important to make sure resource allocation is carefully performed and orchestrated, preventing over- or under-provisioning of resources and keeping end-to-end delays comparable to those observed in traditional middlebox-based networks. In this paper, we formalize the network function placement and chaining problem and propose an Integer Linear Programming (ILP) model to solve it. Additionally, in order to cope with large infrastructures, we propose a heuristic procedure for efficiently guiding the ILP solver towards feasible, near-optimal solutions. Results show that the proposed model leads to a reduction of up to 25% in end-to-end delays (in comparison to chainings observed in traditional infrastructures) and an acceptable resource over-provisioning limited to 4%. Further, we demonstrate that our heuristic approach is able to find solutions that are very close to optimality while delivering results in a timely manner. Marcelo Caggiani Luizelli, Leonardo Richter Bays, Luciana S. Buriol, Marinho P. Barcellos, Luciano Paschoal Gaspary |
IM | 4 |
| 2015 | Predictor: Providing fine-grained management and predictability in multi-tenant datacenter networksabstractSoftware-Defined Networking (SDN) can simplify traffic management in large-scale datacenter networks (DCNs). On one hand, it provides a robust method to address the challenge of performance interference (bandwidth sharing unfairness) in DCNs. On the other, its pragmatic implementation based on OpenFlow introduces scalability challenges, as it (a) adds latency for new flows (the controller must process hundreds of thousands of requests per second and install appropriate rules in switches); and (b) requires large flow tables in devices (DCNs can have more than 16 million distinct flows per second with different requirements and duration). To employ OpenFlow-based SDN in DCNs, recent work has proposed techniques that require hardware customization to keep up with the high dynamic traffic patterns of these networks. We make two key observations: providers do not need to control each flow individually (e.g., VM-to-VM), since they charge tenants based on the amount of resources consumed by applications; and congestion control in the intra-cloud network is expected to be proportional to the tenant's payment. Based on these insights, we introduce Predictor, a novel system for DCNs that enables fine-grained network management for providers, minimizes flow table size by controlling flows at application-layer and reduces flow setup time by proactively installing rules in switches. It also enables tenants to request and receive predictable network performance for both intra- and inter-application communication, with work-conserving bandwidth sharing. Evaluation results show that Predictor provides significant improvements against DevoFlow (reducing flow table size up to 87%) and offers predictable and guaranteed network performance for tenants. Daniel S. Marcon, Marinho P. Barcellos |
IM | 2 |
| 2015 | Opportunistic resilience embedding (ORE): Toward cost-efficient resilient virtual networksabstractNetwork Virtualization promotes the development of new architectures and protocols by enabling the creation of multiple virtual networks on top of the same physical substrate. One of its main advantages is the use of isolation to limit the scope of attacks – that is, avoiding traffic from one virtual network to interfere with the others. However, virtual networks are still vulnerable to disruptions on the underlying network. Particularly, high capacity physical links constitute good targets since they may be important for a large number of virtual networks. Previous work protects virtual networks by setting aside backup resources. Although effective, this kind of solution tends to be expensive, as backup resources increase the cost to infrastructure providers and usually remain idle. This paper presents ORE (opportunistic resilience embedding), a novel embedding approach for protecting virtual links against substrate network disruptions. ORE’s design is two-fold: while a proactive strategy embeds each virtual link into multiple substrate paths in order to mitigate the initial impact of a disruption, a reactive one attempts to recover any capacity affected by an underlying disruption. Both strategies are modeled as optimization problems . Additionally, since the embedding problem is NP -Hard, ORE uses a simulated annealing-based meta-heuristic to solve it efficiently. Numerical results show that ORE can provide resilience to disruptions at a lower cost. Rodrigo Ruas Oliveira, Daniel S. Marcon, Leonardo Richter Bays, Miguel C. Neves, Luciano Paschoal Gaspary, Deep Medhi, Marinho P. Barcellos |
Comput. Networks | 7 |
| 2014 | Survivor: An enhanced controller placement strategy for improving SDN survivabilityabstractIn SDN, forwarding devices can only operate correctly while connected to a logically centralized controller. To avoid single-point-of-failure, controller architectures are usually implemented as distributed systems. In this context, recent literature identified fundamental issues, such as device isolation and controller overload, and proposed controller placement strategies to tackle them. However, current proposals have crucial limitations: (i) device-controller connectivity is modeled using single paths, yet in practice multiple concurrent connections may occur; (ii) peaks in the arrival of new flows are only handled on-demand, assuming that the network itself can sustain high request rates; and (iii) failover mechanisms require predefined information, which, in turn, has been overlooked. This paper proposes Survivor, a controller placement strategy that addresses these challenges. The strategy explicitly considers path diversity, capacity, and failover mechanisms at network design. Comparisons to the state-of-the-art on survivable controller placement show that Survivor is superior because (a) path diversity increases the survivability significantly; and (b) capacity-awareness is essential to handle overload during both normal and failover states. Lucas F. Müller, Rodrigo Ruas Oliveira, Marcelo Caggiani Luizelli, Luciano Paschoal Gaspary, Marinho P. Barcellos |
GLOBECOM | 5 |
| 2014 | A heuristic-based algorithm for privacy-oriented virtual network embeddingabstractNetwork virtualization has become increasingly popular in recent years. It has the potential to allow timely handling of network infrastructure requests and, after instantiated, their lifecycle. In addition, it enables improved physical resource utilization. However, the use of network virtualization in large-scale, real environments depends on the ability to adequately map virtual routers and links to physical resources, as well as to protect virtual networks against security threats. With respect to security, confidentiality and privacy mechanisms have become essential in light of recent discoveries related to pervasive electronic surveillance. In this paper we propose a heuristic method for virtual network embedding with security support. The method features precise modeling of overhead costs of security mechanisms and handles incoming requests in an online manner. Additionally, we present a detailed performance comparison between the proposed heuristic and an optimization model based on the same problem. The obtained results demonstrate that the heuristic method is able to find feasible mappings in the order of seconds even when dealing with large network infrastructures, while the optimization model is limited to smaller networks. Leonardo Richter Bays, Rodrigo Ruas Oliveira, Luciana S. Buriol, Marinho P. Barcellos, Luciano Paschoal Gaspary |
NOMS | 4 |
| 2014 | Slowing down to speed up: Protecting users against massive attacks in content distribution systemsabstractThe Internet has become a large platform where users can interact and share contents. In this context, content distribution systems (CDS) have been designed to satisfy users needs. Peer-to-Peer (P2P) systems have emerged as a prominent solution to speed up CDS. In this kind of distributed system, a particular interesting challenge refers to mechanisms employed to match user's interests and published contents. The efficacy of CDS depends on the expertise of publishers to properly describe contents, which comprises an important task to guarantee good quality of experience (QoE) to users. Massive attacks may harm CDS if countermeasure mechanisms are not considered to fight content pollution. The main objective of the thesis is to devise a mechanism to provide users a good QoE and reduce the effect of malicious interference. To achieve that, three main steps guided the research work presented in the thesis and summarized in this paper: (i) we proposed a novel strategy that operates conservatively to avoid wide pollution dissemination, (ii) we extended our previous solution to cope with the subjectivity regarding content descriptions, and last, (iii) we proposed a generic model to investigate massive attacks (including content pollution) and conservative approaches. Flavio Santos, Marinho P. Barcellos, Luciano Paschoal Gaspary |
NOMS | 2 |
| 2013 | Characterizing the impact of network substrate topologies on virtual network embeddingabstractNetwork virtualization is a mechanism that allows the coexistence of multiple virtual networks on top of a single physical substrate. One of the research challenges addressed recently in the literature is the efficient mapping of virtual resources on physical infrastructures. Although this challenge has received considerable attention, state-of-the-art approaches present, in general, a high rejection rate, i.e., the ratio between the number of denied virtual network requests and the total amount of requests is considerably high. In this work, we investigate the relationship between the quality of virtual network mappings and the topological structures of the underlying substrates. Exact solutions of an online embedding model are evaluated under different classes of network topologies. The obtained results demonstrate that the employment of physical topologies that contain regions with high connectivity significantly contributes to the reduction of rejection rates and, therefore, to improved resource usage. Marcelo Caggiani Luizelli, Leonardo Richter Bays, Luciana S. Buriol, Marinho P. Barcellos, Luciano Paschoal Gaspary |
CNSM | 4 |
| 2013 | No more backups: Toward efficient embedding of survivable virtual networksabstractAlthough network virtualization can improve security by isolating traffic from different networks, routers and links are still vulnerable to attacks on the underlying network. High capacity physical links, in particular, constitute good targets since they may be important for a large number of virtual networks. Previous work protects virtual networks by setting aside backup resources. Although effective, this solution increases the cost to infrastructure providers. In this paper, we present a virtual network embedding approach which enables resilience to attacks and efficiency in resource utilization. Our approach is two-folded: while a preventive strategy embeds virtual links into multiple substrate paths, a reactive strategy attempts to reallocate any capacity affected by an underlying DoS attack. Since the embedding problem is NP-Hard, we devise a Simulated Annealing meta-heuristic to solve it efficiently. Results show our solution can provide resilience to attacks at a lower cost. Rodrigo Ruas Oliveira, Daniel S. Marcon, Leonardo Richter Bays, Miguel C. Neves, Luciana S. Buriol, Luciano Paschoal Gaspary, Marinho P. Barcellos |
ICC | 7 |
| 2013 | Make it green and useful: Reshaping puzzles for identity management in large-scale distributed systems
Weverton Luis da Costa Cordeiro, Flavio Santos, Marinho P. Barcellos, Luciano Paschoal Gaspary |
IM | 3 |
| 2013 | Slowing down to speed up: Mitigating collusion attacks in Content Distribution Systems
Flavio Santos, Weverton Luis da Costa Cordeiro, Marinho P. Barcellos, Luciano Paschoal Gaspary, Fabio Victora Hecht, Burkhard Stiller |
IM | 3 |
| 2013 | Trust-based grouping for cloud datacenters: Improving security in shared infrastructures
Daniel S. Marcon, Rodrigo Ruas Oliveira, Miguel C. Neves, Luciana S. Buriol, Luciano Paschoal Gaspary, Marinho P. Barcellos |
Networking | 6 |
| 2013 | Exploring your neighborhood: Comparing connection strategies in swarming networks through evolving graphsabstractThe swarm-based P2P networks research area evolved to a mature state due to studies related to algorithms for efficient data exchange. However, comparatively less attention has been given to the overlay network topological characteristics, which result from connections between peers. In swarm-based networks, there are three known connection management strategies: inactive, preemptive and pro-active. So far, there has been no previous work comparing these three strategies under the same scenarios. This paper presents a model based on evolving graphs to describe the resulting system topology according to network configuration and connection management strategies. Base on this model, we analyze the robustness and performance potential of topologies under different peer arrival patterns and network reachability ratios in two distinct moments: at the end of the arrival period and in the steady-state period. Our findings show that, in all scenarios, the preemptive and pro-active strategies generate topologies with higher robustness, because they distribute more uniformly connections among all peers, and better performance due to greater centralization of the content source in the overlay topology. Matheus B. Lehmann, Rodolfo Stoffel Antunes, Marinho P. Barcellos |
P2P | 3 |
| 2013 | Beyond pollution and taste: A tag-based strategy to increase download quality in P2P file sharing systems
Flavio Santos, Weverton Luis da Costa Cordeiro, Luciano Paschoal Gaspary, Marinho P. Barcellos |
Comput. Commun. | 4 |
| 2012 | Security-aware optimal resource allocation for virtual network embedding
Leonardo Richter Bays, Rodrigo Ruas Oliveira, Luciana S. Buriol, Marinho P. Barcellos, Luciano Paschoal Gaspary |
CNSM | 4 |
| 2012 | Characterizing dissemination of illegal copies of content through monitoring of BitTorrent networksabstractBitTorrent networks are nowadays the most employed method of Peer-to-Peer (P2P) file sharing in the Internet. Recent monitoring reports reveal that content copies being shared are mostly illegal and movies are the most popular media type. Research efforts carried out to understand the dynamics of content production and sharing in BT networks have been unable to provide precise information regarding the dissemination of illegal copies. In this paper we perform an extensive experimental study in order to characterize the behavior of producers, publishers and providers of copyright-infringing files. The study is based on four months of traces obtained by monitoring swarms sharing movies via one of the most popular BT public communities. Traces were obtained with an extension of a BitTorrent “universe” observation architecture, which allowed the collection of a database with information about more than 40,000 torrents, 900 trackers and 1.3 million IPs. Our analysis not only shows that a small group of active users is responsible for the majority of disseminated illegal copies, as well as unravels existing relationships among these actors. Adler Hoff Schmidt, Rodolfo Stoffel Antunes, Marinho P. Barcellos, Luciano Paschoal Gaspary |
NOMS | 3 |
| 2012 | Disconnecting to connect: Understanding optimistic disconnection in BitTorrentabstractThe significance of BitTorrent motivated various studies focused on modeling and evaluating the protocol characteristics and its current implementations in the Internet. So far, however, no work has investigated Optimistic Disconnect (OD), an ad hoc connection management mechanism widely employed in BitTorrent agents. OD allows a peer to search for “better” neighbors in the swarm by disconnecting peers from the current neighborhood and connecting to others. This paper presents an extensive experimental evaluation to study and quantify potential benefits of OD, such as average download time and topology robustness. We evaluate different scenarios and the impact of factors such as average peer reachability and arrival pattern. We found that OD generally improves the overall performance of the swarm (in up to 30% in the evaluated scenarios), while improving the robustness of its topology. Matheus B. Lehmann, Lucas F. Müller, Rodolfo Stoffel Antunes, Marinho P. Barcellos |
P2P | 4 |
| 2012 | Identity management based on adaptive puzzles to protect P2P systems from Sybil attacks
Weverton Luis da Costa Cordeiro, Flavio Santos, Gustavo Huff Mauch, Marinho P. Barcellos, Luciano Paschoal Gaspary |
Comput. Networks | 4 |
| 2012 | Denial-of-service attacks and countermeasures on BitTorrent
Matheus B. Lehmann, Flavio Santos, Luciano Paschoal Gaspary, Marinho P. Barcellos |
Comput. Networks | 4 |
| 2012 | Beyond network simulators: Fostering novel distributed applications and protocols through extendible design
Marinho P. Barcellos, Rodolfo Stoffel Antunes, Hisham H. Muhammad, Ruthiano S. Munaretti |
J. Netw. Comput. Appl. | 1 |
| 2011 | Securing P2P systems from Sybil attacks through adaptive identity management
Weverton Luis da Costa Cordeiro, Flavio Santos, Gustavo Huff Mauch, Marinho P. Barcellos, Luciano Paschoal Gaspary |
CNSM | 4 |
| 2011 | Observing the BitTorrent universe through TelescopesabstractRecent analysis of the latest peer-to-peer trends worldwide indicates that BitTorrent is the most popular file sharing protocol, taking more than half of the P2P traffic in some geographical locations. Despite several studies about the dynamics of the “BitTorrent universe”, there exists no methodology to systematically observe it. This is mainly due to the challenges that need to be faced in order to observe the BitTorrent universe, the specificity of existing studies, and the ad hoc nature of the monitoring methods employed so far. In this paper, we propose a novel monitoring architecture (called TorrentU) that allows the systematic observation of large numbers of BitTorrent networks. Complementary monitoring strategies are flexibly combined to allow varying degrees of network/geographic coverage, information accuracy and richness of detail. To show the concept and technical feasibility of TorrentU, we implemented a prototype with the key parts of the architecture, and evaluated it through a case study with a rich set of monitoring campaigns running on PlanetLab nodes. Rodrigo B. Mansilha, Leonardo Richter Bays, Matheus B. Lehmann, Alan Mezzomo, Giovani Facchini, Luciano Paschoal Gaspary, Marinho P. Barcellos |
Integrated Network Management | 7 |
| 2011 | A conservative strategy to protect P2P file sharing systems from pollution attacksabstractAbstract Despite being currently one of the main Internet applications, P2P file sharing has been hampered by content pollution attacks. To tackle this problem, we introduce a novel pollution control strategy that consists in adjusting the rate in which content is disseminated, according to content version reputation. The proposed strategy is modeled and evaluated using simplifying assumptions. Then, inspired by classic distributed designs, we propose a pollution control mechanism that implements such a strategy. The mechanism is evaluated in terms of the delays imposed on non‐polluted version dissemination, the effectiveness of reducing dissemination when the version is polluted, and the negative impact that collusion attacks can impose on the reputation system upon which our mechanism is built. Simulation results looking at scenarios with several hundred peers indicate that the pollution control mechanism can effectively reduce pollution without substantially affecting the dissemination of non‐polluted content. Copyright © 2010 John Wiley & Sons, Ltd. Marinho P. Barcellos, Luciano Paschoal Gaspary, Weverton Luis da Costa Cordeiro, Rodolfo Stoffel Antunes |
Concurr. Comput. Pract. Exp. | 1 |
| 2011 | Funnel: Choking Polluters in BitTorrent File Sharing CommunitiesabstractBitTorrent-based file sharing communities are very popular nowadays. Anecdotal evidence hints that such communities are exposed to content pollution attacks (i.e., publication of "false" files, viruses, or other malware), requiring a moderation effort from their administrators. The size of such a cumbersome task increases with content publishing rate. To tackle this problem, we propose a generic pollution control strategy and instantiate it as a mechanism for BitTorrent communities. The strategy follows a conservative approach: it regards newly published content as polluted, and allows the dissemination rate to increase according to the proportion of positive feedback issued about the content. In contrast to related approaches, the strategy and mechanism avoid the problem of pollution dissemination at the initial stages of a swarm, when insufficient feedback is available to form a reputation about the content. To evaluate the proposed solution, we conducted a set of experiments using a popular BitTorrent agent and an implementation of our mechanism. Results indicate that the proposed approach mitigates the dissemination of polluted content in BitTorrent, imposing a low overhead in the distribution of non-polluted ones. Flavio Santos, Weverton Luis da Costa Cordeiro, Luciano Paschoal Gaspary, Marinho P. Barcellos |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2010 | Choking polluters in BitTorrent file sharing communitiesabstractBitTorrent-based file sharing communities are very popular nowadays. Anedoctal evidence hints that such communities are exposed to content pollution attacks (i.e., publication of `false' files, viruses, or other malware), requiring a moderation effort from their administrators. The size of such a cumbersome task increases with content publishing rate. To tackle this problem, we propose a generic pollution control strategy and instantiate it as a mechanism for BitTorrent communities. The strategy follows a conservative approach: it regards newly published content as polluted, and allows the dissemination rate to increase according to the proportion of positive feedback issued about the content. In contrast to related approaches, the strategy and mechanism avoid the problem of pollution dissemination at the initial stages of a swarm, when insufficient feedback is available to form a reputation about the content. To evaluate the proposed solution, we conducted a set of experiments using a popular BitTorrent agent and an implementation of our mechanism. Results indicate that the proposed approach mitigates the dissemination of polluted content in BitTorrent, imposing a low overhead in the distribution of non-polluted ones. Flavio Santos, Weverton Luis da Costa Cordeiro, Luciano Paschoal Gaspary, Marinho P. Barcellos |
NOMS | 4 |
| 2010 | Flexible and secure service discovery in ubiquitous computing
Eduardo Moschetta, Rodolfo Stoffel Antunes, Marinho P. Barcellos |
J. Netw. Comput. Appl. | 3 |
| 2009 | AGRADC: An architecture for autonomous deployment and configuration of grid computing applicationsabstractDeployment and configuration of grid computing applications are exhaustive and error-prone tasks, and represent a weak link of the lifecycle of grid applications. To address the problem, this paper proposes AGRADC, an architecture to instantiate grid applications on demand, which incorporates features from the Autonomic Computing paradigm. This architecture improves the grid application development process, providing tools to define a deployment flow, configuration parameters, and actions to be executed when adverse situations like faults arise. Luciano Paschoal Gaspary, Weverton Luis da Costa Cordeiro, Sidnei Roberto Selzler Franco, Marinho P. Barcellos, Gerson G. H. Cavalheiro |
ISCC | 4 |
| 2008 | TorrentLab: investigating BitTorrent through simulation and live experimentsabstractBitTorrent is probably the most popular file sharing protocol nowadays. Since it is a complex protocol which was created mostly as an engineering effort, there have been attempts to evaluate and understand the behavior of BitTorrent, exposing drawbacks and identifying opportunities for improvement. Simulation(al) and experimental evaluation are two important methodologies for the investigation of BitTorrent implementations and protocol variations, but using them with BitTorrent and P2P in general represents a challenge. In this paper, we introduce TorrentLab, a testbed in which BitTorrent simulations as well as live experiments can be performed under both controlled and uncontrolled settings. For a given swarm, we compare results obtained by means of simulation and live experiments, and show that both are in line with the expected behavior. Marinho P. Barcellos, Rodrigo B. Mansilha, Francisco Vilar Brasileiro |
ISCC | 1 |
| 2008 | Protecting BitTorrent: Design and Evaluation of Effective Countermeasures against DoS AttacksabstractBitTorrent is a P2P file-sharing protocol that can be used to efficiently distribute files such as software updates and digital content to very large numbers of users. In a previous paper, we have shown that vulnerabilities can be exploited to launch Denial-of-Service attacks against BitTorrent swarms, which can substantially increase download times and network traffic. In this paper, we review the three most damaging attacks, and propose two algorithms as countermeasures to effectively tackle them. We implemented the attacks and countermeasures in a packet-level BitTorrent simulator. The results indicate that our proposed approach is effective when there is an ongoing attack while at the same time efficient when the countermeasure is active but there is no attack. To the best of our knowledge, this is the first proposal in the literature to make BitTorrent more robust against Denial-of-Service (DoS) attacks. Marinho P. Barcellos, Daniel Bauermann, Henrique Sant'anna, Matheus B. Lehmann, Rodrigo B. Mansilha |
SRDS | 1 |
| 2007 | Attacking a Swarm with a Band of Liars: evaluating the impact of attacks on BitTorrentabstractTit-for-tat is widely believed to be the most effective strategy to enforce collaboration among selfish users. However, it has been shown that its usefulness for decentralized and dynamic environments such as peer-to-peer networks is marginal, as peers can rapidly end up in a deadlock situation. Many proposed solutions to this problem are either less resilient to freeloading behavior or induce a computational overhead that cannot be sustained by regular peers. In contrast, we retain tit-for-tat, but enhance the system with a novel form of source coding and an effective scheme to prevent peers from freeloading from seeding peers. We show that our system performs well without the risk of peer starvation and without sacrificing fairness. The proposed solution has a reasonably low overhead, and may hence be suitable for fully distributed content distribution applications in real networks. Marlom A. Konrath, Marinho P. Barcellos, Rodrigo B. Mansilha |
Peer-to-Peer Computing | 2 |
| 2007 | Flexible security in peer-to-peer applications: Enabling new opportunities beyond file sharing
Luciano Paschoal Gaspary, Marinho P. Barcellos, André Detsch, Rodolfo Stoffel Antunes |
Comput. Networks | 2 |
| 2006 | Flexible Security Configuration & Deployment in Peer-to-Peer ApplicationsabstractThe widespread adoption of P2P applications in environments beyond ordinary file sharing demands the fulfillment of several security requirements. Important steps have been taken towards security in P2P systems, with relevant mechanisms being proposed in the past to address specific vulnerabilities. However, existing approaches lack flexibility, since they do not (include enough mechanisms to) tackle a wide range of requirements in an integrated fashion. In addition, they oblige the user/application to manipulate a complex programming interface, as well as going through a cumbersome configuration process. To address these issues, we present P2PSL (P2P security layer), which allows gradual and flexible integration of security functionality into P2P applications. To show concept and technical feasibility, we have implemented P2PSL, assessed the overhead it induces, and incorporated the layer into a P2P-based grid computing infrastructure André Detsch, Luciano Paschoal Gaspary, Marinho P. Barcellos, Ricardo Nabinger Sanchez |
NOMS | 3 |
| 2005 | Evaluating high-throughput reliable multicast for grid applications in production networksabstractGrid computing can be characterized as a distributed infrastructure that is a collection of computing resources within or across locations that are aggregated to act as a unified processing resource. In some of the anticipated future grid applications, the same data will be transmitted to multiple sites. It is widely accepted that this can be, in theory, best achieved using reliable multicast protocols. This paper addresses the use of reliable multicast in grid computing, identifying applications and requirements, and discussing how these requirements are met by the main protocols being standardized by the Internet engineering task force (IETF). The emphasis of the study is on high-performance computing and communication, and on I-N reliable multicast using the NACK oriented reliable multicast (NORM) protocol family. The two existing implementations are evaluated and compared with TCP, in scenarios that require I-N transmission of data with a deadline. Unlike other work, our conclusions are backed by experimental evaluation of existing protocols in production environments. Therefore, the results shown portray the range of performance and cost that will be obtained if grid applications are to embrace reliable multicast. The evaluation shows that NORM protocols can greatly reduce the network overhead incurred in I-N transfers using TCP, but currently fail to satisfy the high-throughput requirements of the grid. Marinho P. Barcellos, Maziar M. Nekovee, M. Koyabe, Michael Daw, J. Brooke |
CCGRID | 1 |
| 2005 | Hybrid reliable multicast with TCP-XMabstractIn recent years, much work has been done on attempting to scale multicast data transmission to hundreds or thousands of receivers. There are, however, many situations where an application might involve transmission to just ten or twenty sites. The European Space Agency, for example, carry out regular multi-gigabyte bulk data transfers to a handful of destinations.Using multicast for this type of application can provide significant benefits including reduced load on the transmitter, an overall reduction in network traffic, and consequently shorter data transfer times.In this paper we take a fresh look at the problem of deploying reliable multicast. So far, there has been no convincing solution to achieve this. We present a simple hybrid solution which has not been proposed before. The approach taken is to combine unicast with multicast by modifying TCP to support multicast transfers, and run this modified TCP engine over UDP as a userspace transport protocol.Our goal is clear: reliable bulk data delivery to a moderate number of sites. Unlike some other multicast protocols, our work is complete: we have designed, implemented, deployed and evaluated a protocol which meets this goal. Karl Jeacle, Jon Crowcroft, Marinho P. Barcellos, Stefano Pettini |
CoNEXT | 3 |
| 2005 | Congestion Control with ECN Support in Poll-Based Multicast ProtocolsabstractMost of the traffic in the Internet nowadays is transmitted using TCP, or transport control protocol. The stability of the Internet depends on the congestion control being performed by this protocol, as well as equivalent mechanisms employed by other protocols. The ECN technique (explicit congestion notification), in which packets forwarded by routers are marked whenever congestion is about to occur (or already occurring), allows a transmitter to reduce the sending rate accordingly without relying on packet drops. ECN has not been fully explored, particularly regarding multicast protocols. This paper presents models of poll-based reliable multicast protocols and extends them with a new single-rate congestion control mechanism that harnesses ECN. Simulation results show that it provides fairness between flows from multiple sources, and is TCP-friendly. Further, they demonstrate the substantial efficiency gain obtained with the use of ECN in multicast. Marinho P. Barcellos, André Detsch |
ISCC | 1 |
| 1998 | An End-to-End Reliable Multicast Protocol Using Polling for ScaleabilityabstractReliable sender-based one-to-many protocols do not scale well due mainly to implosion caused by the excessive rate of feedback packets arriving from receivers. We show that this problem can be circumvented by making the sender poll the receivers at carefully planned timing instants, so that the arrival rate of feedback packets is not large enough to cause implosion. We describe a generic end-to-end protocol which incorporates this polling scheme together with error and flow control mechanisms. We analyse the behaviour of our protocol using simulations which indicate that our scheme can be effective in minimising losses due to implosion, achieving high throughput with low network cost. Marinho P. Barcellos, Paul D. Ezhilchelvan |
INFOCOM | 1 |