VLDB 2026 Research / reviewers in the wild / expert
Paulo Simões 0001
dblp:00/4225
· DBLP profile ↗
49ranked-venue papers
1as first author
8since 2021 · last 2025
0000-0002-5079-8327ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17 · 1 since 2021Security and privacy · 9 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4Systems, architecture and hardware · 3 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Audit Compliance and Forensics Frameworks for Complex, Large-Scale ICT SystemsabstractCurrent Information and Communication Technology (ICT) systems are rapidly increasing in scale and complexity, driven by the need to support sophisticated processes and the growing volume of heterogeneous data from interconnected services and devices. At the same time, rising concerns over cybersecurity and legal obligations demand greater attention to security, governance, and regulatory compliance. In this context, compliance management and cybersecurity forensics have become critical priorities, requiring innovative strategies and more effective tools, frameworks, and methodologies for audit and forensic analysis.This paper presents an integrated Forensics and Compliance Auditing framework, designed to support the identification and analysis of past security incidents and non-compliance events across both generic and domain-specific ICT systems, which stems from a PhD dissertation carried out in a mixed industrial/academic environment. Filipe Caldeira, Tiago Cruz 0001, Paulo Simões 0001 |
CNSM | 4 |
| 2024 | Enhancing 5G Core security with eBPF/XDPabstract5G technology brings several improvements to mobile communication systems. The ability to provide much faster connections, lower latency and greater scalability enables 5G to be employed in scenarios where previous generations failed to succeed. However, the growing number of connected devices, with a high proportion of Internet of Things (IoT) devices, expands the cyberattack surface and creates new vulnerabilities, including the heightened risk of Distributed Denial of Service (DDoS) attacks. This research explores the feasibility of using extended Berkeley Packet Filter/eXpress Data Path (eBPF/XDP) technology to enhance the security and robustness of 5G SA Core Network services against DDoS attacks. We evaluate the effectiveness of this approach through several SYN flooding attacks to the 5G Network Repository Function (NRF). In scenarios without eBPF/XDP, DDoS attacks caused significant disruptions, highlighting its impact in the 5G Core Network. With the eBPF/XDP framework in place, the NRF service demonstrated considerable resilience against the SYN Flooding attacks. Thus, we conclude eBPF/XDP effectively helped detecting and mitigating potential DDoS threats, ensuring uninterrupted service for legitimate traffic. Luís Loureiro, Vasco Pereira, Tiago Cruz 0001, Paulo Simões 0001 |
NOMS | 4 |
| 2024 | Data-Centric Federated Learning for Anomaly Detection in Smart Grids and Other Industrial Control SystemsabstractEnergy smart grids and other modern industrial control systems networks impose considerable security management challenges due to several factors: their broad geographic dispersion and capillarity, the constrained nature of many of the devices and network links that integrate them, and the fact that they are often fragmented across multiple domains, owned and managed by different entities which often have nonaligned or even competing interests. Due to this scenario, we propose to improve federated learning-based anomaly detection for smart grids and other industrial control networks, using a federated data-centric methodology that attends to the balance and causality of the data, improving the representation of the different classes of anomalies of the ingested data, which directly impact the classifier's performance. The proposed approach shows up to 33% performance improvements in terms of F1-score for attack classification, compared to the baseline federated approach (not attending to class imbalance and causality) on a broad range of industrial control systems traffic datasets. Dylan Perdigão, Tiago Cruz 0001, Paulo Simões 0001, Pedro H. Abreu |
NOMS | 3 |
| 2023 | Intrusion and Anomaly Detection in Industrial Automation and Control SystemsabstractIn the domain of Industrial Automation and Control Systems (IACS), security was traditionally downplayed to a certain extent, as it was originally deemed an exclusive concern of Information and Communications Technology (ICT) systems. The myth of the air-gap, as well as other preconceived notions about implicit IACS security, constituted dangerous fallacies that were debunked once successful attacks become known. Ultimately, the industry started shifting away from this dangerous mindset, discussing how to properly secure those systems. In many ways, IACS security should not be treated differently from modern ICT security. For sure, IACS have distinct characteristics, assets, protocols and even priorities that should be considered – but security should never be an optional concern.In this publication, we present the main results of a PhD dissertation that proposes a holistic and data-driven framework capable of leveraging distinct techniques to increase situational awareness and provide continuous and near real-time monitoring of IACS. For such purposes, it proposes an evolution of the Security Information and Event Management (SIEM) concept, geared towards providing a unified security data monitoring solution by leveraging recent advances in the field of real-time Big Data analytics. In the same way, the most recent machine-learning-based anomaly-detection techniques (which are becoming increasingly prominent in the cybersecurity field) are also analyzed and studied to understand their benefits for developing and advancing IACS cyber-intrusion detection processes. Luís Rosa 0001, Tiago Cruz 0001, Paulo Simões 0001, Edmundo Monteiro |
NOMS | 3 |
| 2023 | Using KNX-Based Building Automation and Control Systems for Data ExfiltrationabstractWhen it comes to protecting confidential and/or sensitive information, organizations have a plethora of recommendations, standards, policies and security controls at their disposal, conceived to deal with a wide variety of threats. However, most of them share the same fundamental premise: that weaknesses are inline by nature, as a consequence of infrastructure, social and/or technological gaps that can be detected, controlled, mitigated or constrained. Side channel threats are a different matter, though. Stemming from unconventional intrusion or attack vectors whose existence was inconceivable, unexpected or deemed unfeasible, their successful exploitation may provide attackers with the means to bypass and render most security controls ineffective or even useless. In this paper we address one such case: the use of a KNX-based building automation and control system to exfiltrate data from an air-gapped infrastructure. The introduction of a small device provides connectivity to the existing KNX fieldbus and enables sending data through it or even control other devices, with no interference in the operation of the building automation and control network. We validated the feasibility of this approach by means of an experimental setup, which was used to successfully evaluate two different techniques: inline bus exfiltration and optical transmission, via dimmer control. Finally, some measures for detecting and mitigating this type of attacks are proposed. Vitor Graveto, Tiago Cruz 0001, Paulo Simões 0001 |
IEEE Internet Things J. | 3 |
| 2022 | Security of Building Automation and Control Systems: Survey and future research directionsabstractBuilding Automation and Control Systems (BACS) designate the mechanisms that are used to automate buildings’ operations such as climate control, lightning and access control. As such, traditional BACS encompass extensively automated buildings managed in an integrated manner, with the support of Supervisory Control and Data Acquisition (SCADA) systems and specialized industry standards such as BACnet and KNX. More recently, the increasing adoption of IP-connected, IoT-like devices for automating single tasks led to a substantial increase in the number of automated building functions (especially for the smart home domain), although rarely with extensive or integrated automation levels. The interconnection with the building local area network (LAN) and even the Internet, comes with the cost of a wider exposition to attacks, that can either begin inside of the building or be initiated from anywhere outside of it. In contrast with other domains that recently received substantial attention (e.g. industrial control and automation systems), the security of BACS has been addressed in a somehow more superficial and less structured manner. Nevertheless, recent security incidents, combined with the fact that these systems are becoming more interconnected with the building networks and the Internet, are raising security concerns. This paper provides a systematic survey of recent research and industry developments related with the security and safety of building automation and control systems. It also presents an overview of the existing threats and known attacks against BACS, as well as open issues and future research directions. Vitor Graveto, Tiago Cruz 0001, Paulo Simões 0001 |
Comput. Secur. | 3 |
| 2022 | An automated closed-loop framework to enforce security policies from anomaly detectionabstractDue to the growing complexity and scale of IT systems, there is an increasing need to automate and streamline routine maintenance and security management procedures, to reduce costs and improve productivity. In the case of security incidents, the implementation and application of response actions require significant efforts from operators and developers in translating policies to code. Even if Machine Learning (ML) models are used to find anomalies, they need to be regularly trained/updated to avoid becoming outdated. In an evolving environment, a ML model with outdated training might put at risk the organization it was supposed to defend. To overcome those issues, in this paper we propose an automated closed-loop process with three stages. The first stage focuses on obtaining the Decision Trees (DT) that classify anomalies. In the second stage, DTs are translated into security Policies as Code based on languages recognized by the Policy Engine (PE). In the last stage, the translated security policies feed the Policy Engines that enforce them by converting them into specific instruction sets. We also demonstrate the feasibility of the proposed framework, by presenting an example that encompasses the three stages of the closed-loop process. The proposed framework may integrate a broad spectrum of domains and use cases, being able for instance to support the decide and the act stages of the ETSI Zero-touch Network & Service Management (ZSM) framework. Filipe Caldeira, Tiago Cruz 0001, Paulo Simões 0001 |
Comput. Secur. | 4 |
| 2021 | Intrusion and anomaly detection for the next-generation of industrial automation and control systems
Luís Rosa 0001, Tiago Cruz 0001, Miguel Borges de Freitas, Pedro Quitério, Filipe Caldeira, Edmundo Monteiro, Paulo Simões 0001 |
Future Gener. Comput. Syst. | 8 |
| 2020 | SDN-assisted containerized security and monitoring componentsabstractQuite often, the deployment of components for network monitoring or security purposes constitutes a burden, due to the need for IT teams to perform on-site setup procedures, and/or to manually configure diversified equipment or services. While this approach may still be somehow manageable for contained infrastructures such as LANs, it cannot cope with the scale of certain telecommunications service provider or industrial IoT environments.This paper proposes a solution for flexible virtualized component deployment, which takes advantage of containerized probes, together with SDN-assisted network traffic steering mechanisms. In this scope, the integration of SDN and Docker containers constitutes a relevant development, enabling the creation of probe deployment mechanisms which dismiss the need for physical appliance configuration and/or deployment. Miguel Borges de Freitas, Pedro Quitério, Luís Rosa 0001, Tiago Cruz 0001, Paulo Simões 0001 |
NOMS | 5 |
| 2018 | Denial of Service Attacks: Detecting the Frailties of Machine Learning Algorithms in the Classification Process
Ivo Frazão, Pedro H. Abreu, Tiago Cruz 0001, Helder Araújo, Paulo Simões 0001 |
CRITIS | 5 |
| 2017 | Building an NFV-based vRGW: Lessons learnedabstractThe residential gateway (RGW) is a widely deployed device in the context of telecommunication services such as triple play and internet access. Designed to make the connection between the customer home and the operator infrastructure, it provides wired and/or wireless connectivity capabilities, also handling services such as Domain Name Service (DNS) proxying, routing, Network Address Translation (NAT) or firewalling, among others. Its increased complexity, together with other factors - such as device-related costs, or the increased reliance on RGWs for providing critical services - has prompted an interest in its virtualization, also motivated by the evolution of network and service-centric virtualization concepts. This paper presents an approach for the virtualization of the residential gateway (vRGW). It starts by giving an overview of the concept, explaining it and pointing out its benefits. It also explains the virtualization techniques and paradigms that have pushed this movement, namely software defined networking (SDN), network function virtualization (NFV), and service function chaining (SFC). Additionally, it describes the implementation of the vRGW architecture, including a description of its components and their integration. Jorge Proença, Tiago Cruz 0001, Paulo Simões 0001, Gonçalo Gaspar, Bruno Parreira, Alexandre Laranjeira, Fernando Bastos |
CCNC | 3 |
| 2017 | Fuzzy System-Based Suspicious Pattern Detection in Mobile Forensic Evidence
Konstantia Barmpatsalou, Tiago Cruz 0001, Edmundo Monteiro, Paulo Simões 0001 |
ICDF2C | 4 |
| 2017 | Towards a Hybrid Intrusion Detection System for Android-based PPDR terminalsabstractMobile devices are used for communication and for tasks that are sensitive and subject to tampering. Indeed, attacks can be performed on the users' devices without user awareness, this represents additional risk in mission critical scenarios, such as Public Protection and Disaster Relief (PPDR). Intrusion Detection Systems are important for scenarios where information leakage is of crucial importance, since they allow to detect possible attacks to information assets (e.g., installation of malware), or can even compromise the security of PPDR personnel. HyIDS is an Hybrid IDS for Android and supporting the stringent security requirements of PPDR, by comprising agents that continuously monitor mobile device and periodically transmit the data to an analysis framework at the Command Control Center (CCC). The data collection retrieves resource usage metrics for each installed application such as CPU, memory usage, and incoming and outgoing network traffic. At the CCC, the HyIDS employs Machine Learning techniques to identify patterns that are consistent with malware signatures based on the data collected from the applications. The HyIDS's evaluation results demonstrate that the proposed solution has low impact on the mobile device in terms of battery consumption and CPU/memory usage. Pedro Borges, Bruno Sousa, Firooz B. Saghezchi, Georgios Mantas, José Carlos Ribeiro, Jonathan Rodriguez 0001, Luís Cordeiro, Paulo Simões 0001 |
IM | 9 |
| 2017 | Welcome from the ChairsabstractIt is our great pleasure to welcome you to the 15th IFIP/IEEE International Symposium on Integrated Network Management (IM 2017), sponsored by the IEEE Communications Society and IFIP Working Group 6.6. Held in odd-numbered years since 1989, IM 2017 will follow the 28-year tradition of IM as the primary IEEE Communications Society's forum for technical exchange on management of information and communication technology focusing on research, development, integration, standards, services, and user communities. IM 2017 focuses on the theme “Integrated Management in the Cloud and 5G Era”, that aims at capturing the emerging approaches and technical solutions for dealing with 5G and cloud infrastructures, as well as associated services and applications. Prosper Chemouil, Edmundo Monteiro, Marinos Charalambides, Edmundo Roberto Mauro Madeira, Paulo Simões 0001 |
IM | 5 |
| 2017 | Attacking SCADA systems: A practical perspectiveabstractAs Supervisory Control and Data Acquisition (SCADA) and Industrial and Automation Control System (IACS) architectures became more open and interconnected, some of their remotely controlled processes also became more exposed to cyber threats. Aspects such as the use of mature technologies and legacy equipment or even the unforeseen consequences of bridging IACS with external networks have contributed to this situation. This situation prompted the involvement of governmental, industrial and research organizations, as well as standardization entities, in order to create and promote a series of recommendations and standards for IACS cyber-security. Despite those efforts, which are mostly focused on prevention and mitigation, existing literature still lacks attack descriptions that can be reused to reproduce and further research specific use cases and scenarios of security incidents, useful for improving and developing new security detection strategies. In this paper, we describe the implementation of a set of attacks targeting a SCADA hybrid testbed that reproduces an electrical grid for energy distribution (medium and high voltage). This environment makes use of real SCADA equipment to faithfully reproduce a real operational deployment, providing a better insight into less evident SCADA- and device-specificities. Luís Rosa 0001, Tiago Cruz 0001, Paulo Simões 0001, Edmundo Monteiro, Leonid Lev |
IM | 3 |
| 2017 | Evaluation of scalable, on-demand DNS-as-a-ServiceabstractThe Domain Name Service (DNS) is a vital service in the Internet. Much more than a simple translation mechanism, it also allows higher profile functionalities such as load balancing and enhanced content distribution. In the scope of cloud computing, DNS is foreseen as an elastic and robust service, supporting failover mechanisms, decentralised configuration and multi-tenant isolation. This paper presents and validates a cloud-based architecture for DNS as Service, considering the expected principles of security, scalability and elasticity. The obtained results reveal that the proposed architecture is capable of accommodating a high-load of DNS queries per second by dynamically managing the amount of used resources, enforcing a constraint of reduced query latency (<; 1s). Additionally, it also incorporates failover monitoring mechanisms to ensure the stability of the system. The performed assessment in Fed4FIRE testbeds shows that this approach allows for reduction of operational costs, managing used resources according to the service's load introduced by the simultaneous clients and by appropriately scaling in or out DNS servers independently of the underlying cloud infrastructure platform (e.g. OpenStack, Amazon Web Services). Bruno Sousa, Vitor Fonseca, Paulo Simões 0001, Luís Cordeiro |
IM | 3 |
| 2017 | Edge caching with mobility prediction in virtualized LTE mobile networks
Andre S. Gomes, Bruno Sousa, David Palma 0001, Vitor Fonseca, Zhongliang Zhao, Edmundo Monteiro, Torsten Braun, Paulo Simões 0001, Luís Cordeiro |
Future Gener. Comput. Syst. | 8 |
| 2016 | Enabling a Mobility Prediction-Aware Follow-Me Cloud ModelabstractThe location of data centres is crucial when mobile network operators are moving towards cloudified mobile networks to optimize resource utilization and to improve performance of services. Quality of Experience (QoE) can be enhanced in terms of content access latency, by placing user content at locations where they will be present in the future. The Follow-Me Cloud (FMC) concept aims at optimising operations of moving Mobile Network Operators Services towards cloudified environments, where Information Centric Networking (ICN) and the appropriate content migration policies are of paramount importance. However, several factors need to be considered, including user movements and mobility prediction (MP), content popularity, and migration. This paper addresses all these aspects by implementing a fully integrated multi-criteria FMC and mobility prediction mechanisms (MP-FMC) on a cloud infrastructure. Experimental evaluation shows that MP-FMC can be orchestrated on-demand within a reasonable time frame, and it could deliver ≈ 33% improvement of content retrieval time. Bruno Sousa, Zhongliang Zhao, Morteza Karimzadeh, David Palma 0001, Vitor Fonseca, Paulo Simões 0001, Torsten Braun, Hans van den Berg, Aiko Pras, Luís Cordeiro |
LCN | 6 |
| 2016 | Expedite feature extraction for enhanced cloud anomaly detectionabstractCloud computing is the latest trend in business for providing software, platforms and services over the Internet. However, a widespread adoption of this paradigm has been hampered by the lack of security mechanisms. In view of this, the aim of this work is to propose a new approach for detecting anomalies in cloud network traffic. The anomaly detection mechanism works on the basis of a Support Vector Machine (SVM). The key requirement for improving the accuracy of the SVM model, in the context of cloud, is to reduce the total amount of data. In light of this, we put forward the Poisson Moving Average predictor which is the core of the feature extraction approach and is able to handle the vast amount of information generated over time. In addition, two case studies are employed to validate the effectiveness of the mechanism on the basis of real datasets. Compared with other approaches, our solution exhibits the best performance in terms of detection and false alarm rates. Bruno Lopes Dalmazo, João P. Vilela, Paulo Simões 0001, Marília Curado |
NOMS | 3 |
| 2016 | A mobile follow-me cloud content caching modelabstractWith the increasing usage of mobile devices for traffic-heavy applications, mobile operators struggle for delivering good performance while, at the same time, optimizing resource consumption. By resorting to Information-Centric Networking and mobile cloud computing paradigms, mobile operators are able to tackle this challenge, simultaneously supporting more users and reducing operational costs. In this paper we propose a Mobile Follow-Me Cloud (M-FMC) model for enhancing the migration of content caches located at the edge of cloudified mobile networks, leveraging the benefits of such paradigms. This is achieved by accounting for content popularity and user mobility, optimizing systems' caches according to user interests and improving resource management. Evaluation results demonstrate that M-FMC model achieves more than 90% accuracy in real-time selection of content objects to be migrated between caches. This performance is reflected in higher cache-hit rates, therefore representing an improvement in content-access latency and overall bandwidth savings. Andre S. Gomes, Vitor Fonseca, Bruno Sousa, David Palma 0001, Paulo Simões 0001, Edmundo Monteiro, Luís Cordeiro |
NOMS | 5 |
| 2016 | A Cybersecurity Detection Framework for Supervisory Control and Data Acquisition SystemsabstractThis paper presents a distributed intrusion detection system (DIDS) for supervisory control and data acquisition (SCADA) industrial control systems, which was developed for the CockpitCI project. Its architecture was designed to address the specific characteristics and requirements for SCADA cybersecurity that cannot be adequately fulfilled by techniques from the information technology world, thus requiring a domain-specific approach. DIDS components are described in terms of their functionality, operation, integration, and management. Moreover, system evaluation and validation are undertaken within an especially designed hybrid testbed emulating the SCADA system for an electrical distribution grid. Tiago Cruz 0001, Luís Rosa 0001, Jorge Proença, Leandros Maglaras, Matthieu Aubigny, Leonid Lev, Jianmin Jiang, Paulo Simões 0001 |
IEEE Trans. Ind. Informatics | 8 |
| 2016 | Toward a Fully Cloudified Mobile Network InfrastructureabstractCloud computing enables the on-demand delivery of resources for a multitude of services and gives the opportunity for small agile companies to compete with large industries. In the telco world, cloud computing is currently mostly used by mobile network operators (MNO) for hosting non-critical support services and selling cloud services such as applications and data storage. MNOs are investigating the use of cloud computing to deliver key telecommunication services in the access and core networks. Without this, MNOs lose the opportunities of both combining this with over-the-top (OTT) and value-added services to their fundamental service offerings and leveraging cost-effective commodity hardware. Being able to leverage cloud computing technology effectively for the telco world is the focus of mobile cloud networking (MCN). This paper presents the key results of MCN integrated project that includes its architecture advancements, prototype implementation, and evaluation. Results show the efficiency and the simplicity that a MNO can deploy and manage the complete service lifecycle of fully cloudified, composed services that combine OTT/IT- and mobile-network-based services running on commodity hardware. The extensive performance evaluation of MCN using two key proof-of-concept scenarios that compose together many services to deliver novel converged elastic, on-demand mobile-based but innovative OTT services proves the feasibility of such fully virtualized deployments. Results show that it is beneficial to extend cloud computing to telco usage and run fully cloudified mobile-network-based systems with clear advantages and new service opportunities for MNOs and end-users. Bruno Sousa, Luís Cordeiro, Paulo Simões 0001, Andy Edmonds 0001, Santiago Ruiz, Giuseppe Carella, Marius Iulian Corici, Navid Nikaein, Andre S. Gomes, Eryk Schiller, Torsten Braun, Thomas Michael Bohnert |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2015 | Improving network security monitoring for industrial control systemsabstractProgrammable Logic Controller (PLC) technology plays an important role in the automation architectures of several critical infrastructures such as Industrial Control Systems (ICS), controlling equipment in contexts such as chemical processes, factory lines, power production plants or power distribution grids, just to mention a few examples. Despite their importance, PLCs constitute one of the weakest links in ICS security, frequently due to reasons such as the absence of secure communication mechanisms, authenticated access or system integrity checks. While events such as the Stuxnet worm have raised awareness for this problem, industry has slowly reacted, either due to reliability or cost concerns. This paper introduces the Shadow Security Unit, a low-cost device deployed in parallel with a PLC or Remote Terminal Unit (RTU), being capable of transparently intercepting its communications control channels and physical process I/O lines to continuously assess its security and operational status. The proposed device does not require significant changes to the existing control network, being able to work in standalone or integrated within an ICS protection framework. Tiago Cruz 0001, Jorge Barrigas, Jorge Proença, Antonio Graziano, Stefano Panzieri, Leonid Lev, Paulo Simões 0001 |
IM | 7 |
| 2015 | Provisioning of Inter-Domain QoS-Aware Services
Fernando Matos 0001, Alexandre Matos, Paulo Simões 0001, Edmundo Monteiro |
J. Comput. Sci. Technol. | 3 |
| 2015 | Cooperative security management for broadband network environmentsabstractAbstract From an internet service provider's (ISP) perspective, modern broadband access networks pose significant and ever increasing challenges in terms of security management. The growing number of permanently connected home networks, with a myriad of poorly managed devices, imposes significant security risks not only to the domestic customers, unable to defend themselves from security attacks, but also to the ISP and third‐parties potentially targeted by large‐scale distributed botnet attacks fed by swarms of zombie domestic personal computers. In this context, the traditional delimitation of customer and ISP perimeters is no longer effective. Home networks became too complex and vulnerable to be autonomously managed by the average customer, and the scale and sophistication of distributed security attacks make it more and more difficult for the ISP to properly manage security without intervening outside the boundaries of its own network. Considering this state of affairs, we propose an alternative architecture for security management. This architecture increases the level of integration and cooperation between the domains of the ISP infrastructure and the home network. At the same time, it potentially improves the scalability and granularity of traditional intrusion detection and prevention mechanisms. Copyright © 2015 John Wiley & Sons, Ltd. Tiago Cruz 0001, Paulo Simões 0001, Edmundo Monteiro, Fernando Bastos, Alexandre Laranjeira |
Secur. Commun. Networks | 2 |
| 2014 | Efficient and secure M2M communications for smart meteringabstractMachine-to-Machine technology supports several application scenarios, such as smart metering, automotive, healthcare and city monitoring. Smart metering applications have attracted the interest of companies and governments since these applications bring many benefits (e.g. costs reduction and increased reliability) for production, monitoring and distribution of utilities, such as gas, water and electricity. Multi-hop wireless communication is a cost-effective technology for smart metering applications because it extends the wireless range and enables fast deployment. Smart metering data communicated via wireless multi-hop approaches needs mechanisms that makes the communication less vulnerable to security threats and saves the device resources. Data encryption and data aggregation mechanisms emerge as potential solutions to fulfill these requirements. However, the simultaneous execution of data encryption and data aggregation mechanisms is not a trivial task. This is because the data encryption prevents the data aggregation mechanism to summarize the data along the path. Another challenge is to manage both mechanisms according to the concurrent Machine-to-Machine (M2M) applications interests. In this context, we present sMeter, which is a framework that deals with multiple applications interests, avoiding interest conflicts of concurrent users and supporting the management of data aggregation and data encryption. sMeter is implemented using low-cost hardware in an indoor environment. The communication is performed via a wireless multi-hop technology, and the performance of this communication is evaluated in terms of delay, data reception ratio and received signal strength indication. Andre Riker, Tiago Cruz 0001, Bruno F. Marques, Marília Curado, Paulo Simões 0001, Edmundo Monteiro |
ETFA | 5 |
| 2014 | Keeping an Eye on Your Security Through Assurance IndicatorsabstractDespite the incommensurable effort made from across computer sciences disciplines to provide more secure systems, compromising the security of a system has now become a very common and stark reality for organizations of all sizes and from a variety of sectors. The lax in the technology has often been cited as the salient cause of systems insecurity. In this paper we advocate the need for a Security Assurance (SA) system to be embedded within current IT systems. Such a system has the potential to address one facet of cyber insecurity, which is the exploit of lax within the deployed security and its underlining policy. We discuss the challenges associated to such an SA assessment and present the flavor of its evaluation and monitoring through an initial prototype. By providing indicators on the status of a security matter that is more and more devolved to the provider as it is the case in the cloud, the SA tool can be used as a means of fostering better security transparency between a cloud provider and client. Moussa Ouedraogo, Chien-Ting Kuo, Simon Tjoa, David Preston 0001, Eric Dubois 0001, Paulo Simões 0001, Tiago Cruz 0001 |
SECRYPT | 6 |
| 2014 | A Survey of Cloud Computing Migration Issues and Frameworks
Abílio Cardoso, Fernando Moreira, Paulo Simões 0001 |
WorldCIST (1) | 3 |
| 2013 | A management framework for residential broadband environments
Tiago Cruz 0001, Paulo Simões 0001 |
IM | 2 |
| 2013 | Managed hybrid storage for home and SOHO environments
Tiago Cruz 0001, Paulo Simões 0001, Edmundo Monteiro, Fernando Bastos |
IM | 2 |
| 2013 | An architecture for virtualized home gateways
Tiago Cruz 0001, Paulo Simões 0001, Nuno Reis, Edmundo Monteiro, Fernando Bastos |
IM | 2 |
| 2013 | On the use of thin-client Set-Top Boxes for IPTV servicesabstractTogether with the developments in terms of broadband connectivity and IP-based service consolidation, the introduction of cloud technologies is opening a whole new window of opportunity for service and telecommunications operators alike, to improve and expand their service portfolio. In this line of thought, this paper presents an innovative proposal to improve the delivery of IPTV services for residential users. It departs from the existing model, based on fat Set-Top Box (STB) appliances designed for specific IPTV frameworks, going instead for a solution that turns STBs into stateless devices, with the whole service interface being moved to the provider infrastructure. This thin-client STB-based service delivery model for IPTV, also includes the necessary management mechanisms to provision and configure the involved components. Overall, this approach is designed to enable providers to improve and simplify their IPTV delivery infrastructure, while maintaining backwards-compatibility with their existing Operations Support Systems. Tiago Cruz 0001, Paulo Simões 0001, Pedro Cabaco, Edmundo Monteiro, Fernando Bastos |
LCN | 2 |
| 2012 | Using UPnP-CWMP integration for operator-assisted management of domestic LANsabstractThe Universal Plug and Play (UPnP) protocol framework was conceived to allow seamless device discovery, control and configuration on domestic LANs, with minimum user intervention. It supports a wide range of devices, from printers to network equipment, having become an important mechanism for automatic configuration of devices within domestic LANs. Tiago Cruz 0001, Paulo Simões 0001, Edmundo Monteiro, Fernando Bastos, Alexandre Laranjeira |
CCNC | 2 |
| 2012 | Peer Selection in P2P Service Overlays Using Geographical Location Criteria
Adriano Fiorese, Paulo Simões 0001, Fernando Boavida |
ICCSA (2) | 2 |
| 2011 | Outsourced management of home and SOHO Windows desktops
Tiago Cruz 0001, Paulo Simões 0001, Edmundo Monteiro, Fernando Bastos |
CNSM | 2 |
| 2011 | An approach to peer selection in service overlays
Adriano Fiorese, Paulo Simões 0001, Fernando Boavida |
CNSM | 2 |
| 2011 | Trust based interdependency weighting for on-line risk monitoring in interdependent critical infrastructuresabstractCritical infrastructure (CI) services are constantly consumed by the society and are expected to be available 24 hours a day. A common definition states that CIs are so vital to our society that a disruption or destruction would have a severe impact on the social well-being and the economy nationally and internationally. CI sectors include, amongst others, the electricity, telecommunication, air traffic and transport sectors. CIs can be mutually dependent on each other and a failure in one CI can cascade to another dependent or interdependent CI to cause service disruptions. Methods to better assess and monitor CIs and their dependencies in order to predict possible risks have to be developed. Information about the current risk in a service provided by a CI can contribute not only to increase CI security, but also to increase the confidence of consumers and CIs that depend on this service. In this paper, a previous work on CI security modelling is extended. A trust based component is added to the security model as a means to improve its accuracy and its resilience to inconsistent information provided by dependent CIs allowing to evaluate the correctness of information received from those dependencies. Filipe Caldeira, Thomas Schaberreiter, Edmundo Monteiro, Jocelyn Aubert, Paulo Simões 0001, Djamel Khadraoui |
CRiSIS | 5 |
| 2011 | Assurance and Trust Indicators to Evaluate Accuracy of On-line Risk in Critical Infrastructures
Thomas Schaberreiter, Filipe Caldeira, Jocelyn Aubert, Edmundo Monteiro, Djamel Khadraoui, Paulo Simões 0001 |
CRITIS | 6 |
| 2011 | Performance evaluation of service searching using aggregation in peer-to-peer Service Overlay NetworksabstractThis paper presents a performance evaluation in the context of the Aggregation Service (AgS). The AgS is a P2P overlay-tier whose purpose is to aggregate the services and service components maintained by service providers in a P2P Service Overlay Network (SON). The performance evaluation takes into account two metrics: (1) the average path length, and (2) the response time. Both of them are used in the comparison of two environments: (1) AgS and (2) a P2P SON without AgS. Additionally, the searching performance in the environment with AgS is compared with a P2P SON that uses Gnutella as the searching mechanism. The simulation results clearly show an improvement in the performance of the search operations when the AgS is used to the detriment of the searches performed without it. The results also show AgS is better suited for use in small overlays. Adriano Fiorese, Paulo Simões 0001, Fernando Boavida |
Integrated Network Management | 2 |
| 2011 | QoS adaptation in inter-domain servicesabstractQoS adaptation is an important process in inter-domain service management, since it can guarantee the correct service provisioning when unexpected events occur. However, in inter-domain environments, the human interference and the manual-based operations hamper the deployment of expeditious mechanisms to adapt the QoS of the services. This paper presents an approach based on SOA principles to perform QoS adaptation in these environments. This approach allows providers to determine the new QoS parameters, renegotiate these parameters with other providers along the provisioning path, update their contracts and enforce the changes in the equipment configuration in an automatic and on-demand fashion. The QoS adaptation process can be caused by technical (QoS violations, infrastructure malfunctions) or business (financial problems) issues. In addition, if a provider configuration in the provisioning path already supports the new requirements, this provider is not affected by the adaptation, thus decreasing the processing time. Fernando Matos 0001, Alexandre Matos, Paulo Simões 0001, Edmundo Monteiro |
Integrated Network Management | 3 |
| 2011 | How to provision and manage off-the-shelf SIP phones in domestic and SOHO environmentsabstractIntegrated services delivered over broadband connections are becoming the norm in domestic households, as it is the case with triple-play bundles which offer combined Voice, Television and Data services delivered using IP-based technologies and protocols. As a result, the usage of SIP-based (Session Initiation Protocol) VoIP devices has known a significant growth in domestic environments, either in the form of standalone (e.g. SIP telephones) or embedded devices (as it happens with some domestic gateways, which embed analog-to-SIP adaptors). For Internet Service Providers (ISPs), the provisioning and management of those devices is a challenge — especially standalone SIP phones, since most of them were exclusively designed for corporate LAN usage, not supporting adequate mechanisms for remote management over broadband access networks. In this paper we propose a framework which allows the integration of off-the-shelf SIP phones with the CWMP protocol suite, the prevailing standard for remote management of Customer Premises Devices (CPEs) in broadband access networks. This integration framework supports the vast majority of commercially available SIP phones whilst maintaining full compatibility with the original CWMP specification — thus allowing ISPs to reuse their CWMP management infrastructure to configure and provision off-the-shelf SIP telephones. Tiago Cruz 0001, Paulo Simões 0001, Edmundo Monteiro, Fernando Bastos, Alexandre Laranjeira |
LCN | 2 |
| 2010 | Integration of PXE-based desktop solutions into broadband access networksabstractPresently there is a lack of remote desktop management solutions for domestic and SOHO users connected to broadband access networks. This contrasts with the enterprise LAN environment, where there are several standards, resources and frameworks for PC or thin-client management. Among these, one specific remote boot technology the Preboot execution Environment (PXE) is now the basis for a wide array of LAN-wide desktop management applications. In this context, integrating PXE-based solutions into broadband access networks would allow novel management paradigms, targeting not just domestic end-users but also telecommuters working from their homes and small businesses which are too small for local deployment of full-fledged enterprise desktop management platforms. In this paper we propose a solution that brings the benefits of managed desktop computing to home users, telecommuters and small businesses by integrating PXE technologies into broadband access network environments. In addition, we also propose a desktop services delivery model capable of efficiently providing a secure and quality managed desktop experience to domestic and SOHO end-users, using a PXE-based thin-client platform for broadband environments that can replace a full-fledged PC whilst maintaining most of its benefits. Tiago Cruz 0001, Paulo Simões 0001, Fernando Bastos, Edmundo Monteiro |
CNSM | 2 |
| 2010 | An aggregation scheme for the optimisation of service search in Peer-to-Peer overlaysabstractThis paper presents a mechanism to improve the efficiency of service searching in large-scale multi-domain environments composed of service providers organized in a P2P Service Overlay Network (SON). This mechanism relies on a P2P overlay-tier whose purpose is to aggregate the services and service components maintained by service providers in the P2P SON. We name this mechanism Aggregation Service (AgS). It comprises the service and service components publishing and allows the separation between the service providers and the search schema. The average search path length was used as metric for the AgS assessment through simulation. The simulation results clearly show an improvement in search operations when the proposed Aggregation Service is used, when compared to searches performed without it. Adriano Fiorese, Paulo Simões 0001, Fernando Boavida |
CNSM | 2 |
| 2010 | A service composition approach for inter-domain provisioningabstractInter-domain QoS-aware service provisioning is still a complex task due to the Internet heterogeneity. It is necessary to overcome several obstacles in order to achieve a scenario where providers fully interact to satisfy all customer service requirements. Some of these obstacles are service class specification and service composition. This paper presents an integrated approach for service class specification and service composition that supports the provisioning of QoS-aware services in inter-domain environments. This approach makes use of QoS performance parameters, service-specific parameters and business parameters to compose services that fulfill customer requirements and comply with providers' business expectations. Fernando Matos 0001, Alexandre Matos, Paulo Simões 0001, Edmundo Monteiro |
CNSM | 3 |
| 2010 | Trust and Reputation for Information Exchange in Critical Infrastructures
Filipe Caldeira, Edmundo Monteiro, Paulo Simões 0001 |
CRITIS | 3 |
| 2010 | CWMP extensions for enhanced management of domestic network servicesabstractBroadband Forum's CPE Wan Management Protocol (CWMP/TR-069) became, in the last few years, a key industry standard for the management of devices that, despite located in the local network of domestic broadband users, still need to be directly managed by operators due to their relevance to added value services such as VoIP, IPTV, VoD or femtocell applications. Despite its relevance, the adoption of CWMP is still slow, in part because current CWMP applications do not cope well (yet) with the dynamic environment of domestic LANs, where the nature of topologies and services to be managed quickly evolves. In this paper we propose an extensible CWMP agent framework that, whilst keeping full compatibility with the original specification, allows it to better adapt to the home network environment, by incorporating the notion of extensible CWMP agents and proxying mechanisms. Tiago Cruz 0001, Paulo Simões 0001, Patricio Batista, Edmundo Monteiro, Fernando Bastos |
LCN | 2 |
| 2008 | A Framework for the establishment of inter-domain, on-demand VPNsabstractVirtual private networks (VPNs) are a popular and cost-effective means to build wide-area corporate networks, since they provide bandwidth, privacy and security for a fraction of the cost of private networks. However, establishing VPNs across different domains (inter-domain VPNs) is still a cumbersome task, requiring human- based negotiation between involved carriers, manual configuration of network equipment and inefficient exploitation procedures during the whole VPN life cycle. For these reasons, inter-domain VPNs are usually contracted in a long-term basis and thus appropriate only for a limited set of usage scenarios. In this paper we propose a framework for efficient provisioning of inter-domain VPNs, comprising a business layer for inter-carrier negotiation and orchestration, policy-based mechanisms for intra-domain resource management, and RFC 4364-based mechanisms for configuration of VPNs. This framework will allow ISPs to provide much more elastic VPN services, able to support not only traditional VPNs (contracted for long periods, for interconnection of corporate networks) but also a new class of more granular, on-demand VPNs for support of shorter-term services such as videoconference sessions or internet banking transaction. Alexandre Matos, Fernando Matos 0001, Paulo Simões 0001, Edmundo Monteiro |
NOMS | 3 |
| 2003 | Enabling PreOS Desktop Management
Tiago Cruz 0001, Paulo Simões 0001 |
Integrated Network Management | 2 |
| 2002 | Distributed retrieval of management information: is it about mobility, locality or distribution?abstractIn this paper we present results from an experimental study addressing the use of mobile agents in the retrieval of management information. We compare several agent-based models for distributed collection and processing of management data, focusing on performance but also considering network traffic and setup costs. This study reveals that in many situations the performance of mobile agent systems is mainly determined by distribution, rather than locality. Furthermore, it shows that despite its importance in the flexibility and adaptability of the management system, agent mobility does not increase the system performance. Paulo Simões 0001, Luís Moura Silva, Fernando Boavida |
NOMS | 1 |