Michel S. Bonfim

dblp:118/0753 · also Michel Sales Bonfim · DBLP profile ↗
← Back
9ranked-venue papers
3as first author
4since 2021 · last 2024
0000-0001-8665-3675ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 1 first-author · 1 since 2021Security and privacy · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
YearPublicationVenuePosition
2024 Smart Anonymity: a mechanism for recommending data anonymization algorithms based on data profiles for IoT environments
Flávio Neves, Rafael Roque de Souza, Wesley Lima, Wellison Raul, Michel S. Bonfim, Vinicius Cardoso Garcia
J. Supercomput.5
2023 Data privacy in the Internet of Things based on anonymization: A review
abstract
The Internet of Things (IoT) has shown rapid growth in recent years. However, it presents challenges related to the lack of standardization of communication produced by different types of devices. Another problem area is the security and privacy of data generated by IoT devices. Thus, with the focus on grouping, analyzing, and classifying existing data security and privacy methods in IoT, based on data anonymization, we have conducted a Systematic Literature Review (SLR). We have therefore reviewed the history of works developing solutions for security and privacy in the IoT, particularly data anonymization and the leading technologies used by researchers in their work. We also discussed the challenges and future directions for research. The objective of the work is to give order to the main approaches that promise to provide or facilitate data privacy using anonymization in the IoT area. The study’s results can help us understand the best anonymization techniques to provide data security and privacy in IoT environments. In addition, the findings can also help us understand the limitations of existing approaches and identify areas for improvement. The results found in most of the studies analyzed indicate a lack of consensus in the following areas: (i) with regard to a solution with a standardized methodology to be applied in all scenarios that encompass IoT; (ii) the use of different techniques to anonymize the data; and (iii), the resolution of privacy issues. On the other hand, results made available by the k-anonymity technique proved efficient in combination with other techniques. In this context, data privacy presents one of the main challenges for broadening secure domains in applying privacy with anonymity.
Flávio Neves, Rafael Roque de Souza, Juliana Sousa, Michel S. Bonfim, Vinicius Cardoso Garcia
J. Comput. Secur.4
2022 Beholder - A CEP-based intrusion detection and prevention systems for IoT environments
Milton V. M. Lima, Ricardo Massa Ferreira Lima, Fernando Aires 0001, Michel S. Bonfim
Comput. Secur.4
2022 KDN-Based Fault-Tolerant Scheduling for VNFs in Data Centers
abstract
Network Functions Virtualization (NFV) aims to decouple network functionality from dedicated physical devices, thereby allowing Virtual Machines (VMs) to host services such as firewalls and load balancers. Hosting these services on VMs will provide new business opportunities for data centers. Currently, the available physical resources are limited, thus making efficient resource scheduling the most challenging issue towards the successful adoption of NFV. Therefore, optimizing resource allocation is crucial. This paper proposes an integrated, intelligent framework for VNF (Virtual Network Function) scheduling. In particular, the proposed solution is based on Knowledge Defined Networking (KDN) with Long Short-Term Memory (LSTM) to operate and optimize VNF scheduling. For this reason, our solution considers VNF affinity rules in a data center with LSTM- based multi-step ahead time forecast. Experimental analysis through benchmark data shows that the proposed fault-tolerant aware scheduling framework based on LSTM and affinity techniques achieves promising results.
Rafael Roque de Souza, Michel S. Bonfim, Kelvin Lopes Dias, Stenio F. L. Fernandes
IEEE Trans. Netw. Serv. Manag.3
2020 A real-time attack defense framework for 5G network slicing
abstract
Summary Network Slicing (NS) is a key enabler to support 5G network services on‐demand. However, since NS is a result of the recent advancement in Software‐Defined Networking and Network Function Virtualization, it introduces new security issues which include attacks against an NS instance within an operator network and interslice security threats. In this scenario, identifying and mitigating attacks in real‐time is of paramount importance to improve security aspects. However, it is far from being straightforward. Therefore, this work proposes the FrameRTP4, a P4‐based framework that aims to deliver real‐time attack detection and mitigation mechanisms in 5G NS scenarios. For this, it provides a P4‐based switch that implements an Service Function Chaining protocol layer, an efficient and scalable Access Control List for the detection and mitigation of known attacks, and a monitoring system aiming to reduce the overhead induced on the control channel. Furthermore, it delivers an orchestrator that aims to control all switches in order to enable lifecycle management of NS instances and P4 table rules. Besides, it also performs some autonomous tasks such as the wildcard rules generation and the detection of new threats by using machine learning algorithms. Preliminary results point to the potential benefits of FrameRTP4 to be part of a 5G NS infrastructure.
Michel S. Bonfim, Marcelo Anderson Santos, Kelvin Lopes Dias, Stenio F. L. Fernandes
Softw. Pract. Exp.1
2019 A Semantic-Based Policy Analysis Solution for the Deployment of NFV Services
abstract
Policies in network function virtualization (NFV) systems may conflict when they have different restrictions on the shared resources. In this context, it is of paramount importance to identify such conflicts before sending network service (NS) request (NS-Req) to the embedding algorithm to avoid unexpected behavior in its execution. Since both NS-Req and NFV infrastructure (NFVI) may contain many policies, the process of conflict detection and diagnosis is an intricate work both for humans and computer systems. Besides, as conflicts may occur among a set of constraints, pairwise detection will not suffice. Therefore, this paper proposes NSChecker, a semantic verification system to detect and diagnose policy conflicts in NFV environments. To achieve its functionality, NSChecker uses an ontology, called Onto-NFV, to describe the NFVI, NS, and associated policies. With Onto-NFV, conflicts detection is carried out through description logic (DL) inconsistency verification. We develop a prototype of NSChecker in Java and validate its capabilities on a small scenario with three use cases, showing that it supports conflict detection concerning the following policies: network function precedence, resource usage, and location. Finally, we evaluate NSChecker performance using some real topologies. The results shows that our solution is efficient even in scenarios with 50 000 nodes.
Michel S. Bonfim, Fred Freitas, Stenio F. L. Fernandes
IEEE Trans. Netw. Serv. Manag.1
2018 Towards an Accurate Bandwidth Estimation Tool for 802.11n Wireless Networks
abstract
Available Bandwidth Estimation (ABE) has been the subject of several studies in recent years. ABE tools based on the PRM approach have been the primary choice for production environments since they are more suitable for applications that are far from users (e.g., Cloud applications). At the same time, the 802.11n wireless network standard has been increasingly used in companies and homes. However, the 802.11n introduced significant changes to improve efficiency such as Frame Aggregation (FA) and the Channel Bonding (CB), which directly influence the accuracy of ABE techniques. Therefore, this work aims to provide a solution that reduces the impact of the new 802.11n arrangements in ABE. For this, we initially performed experiments on a testbed to assess how much these 802.11n MAC layer factors influence the estimates of four ABE tools: ASSOLO, PTR, PathChirp, and YAZ. Results showed that YAZ achieved the best efficiency. Nevertheless, its accuracy is significantly affected in FA-enabled scenarios. Then, we performed an indepth analysis of YAZ aiming to identify the causes of that problem. Finally, we proposed and evaluated the YAZ++, a tool that implements a new technique to improve ABE accuracy in FA scenarios. Results showed an improvement in the estimated values.
Diego Azevedo, Michel S. Bonfim, Leonidas Lima, Stenio F. L. Fernandes
ISCC2
2018 Identifying performance bottlenecks in software data planes for cloud-based NFV services
abstract
Network Function Visualization (NFV) is transforming the market for computer networks. Most proposed NFV solutions have been implemented and tested in cloud computing environments. In this context, both hardware and software-based features have been used to improve the performance of Virtual Network Functions (VNFs) by speeding up packet processing. However, there are still essential research challenges that need to be tackled to provide better performance experiences for NFV Services, such as detecting and diagnosing performance bottlenecks. However, due to the characteristics inherited from both Cloud and NFV environments, the detection and diagnose of performance problems is a complex task. In this work, we proposed PerfChecker, a monitoring tool that aims at detecting and diagnosing performance bottlenecks in Cloud-based NFV environments. We implemented a PerfChecker prototype for OpenStack and performed some experiments demonstrating that it can assist the cloud infrastructure operator to improve the performance of NFV services.
Michel S. Bonfim, Rafael Roque Aschoff, Emanuel Ferreira Coutinho, Kelvin Lopes Dias, Stenio F. L. Fernandes
NOMS1
2015 An OpenFlow-Based Elastic Solution for Cloud-CDN Video Streaming Service
abstract
Media streaming services are responsible for the significant increase of Internet traffic. This fact generates the need for better computing resources management in order to maintain such services always available. Cloud computing offers an elastic infrastructure that provides computing resources on demand in order to maintain such services always available. Moreover, emerging network architectures, such as Software Defined Networks, provide mechanisms that simplify the implementation of advanced network functions. In this context, this paper proposes an elastic approach to manage a video streaming service. The solution includes an OpenFlow-based load balancer, and an elasticity management mechanism that increases or decreases the amount of active streaming servers, considering customer's demand. A prototype was developed using a private cloud infrastructure and experiments were performed to show the viability and effectiveness of our solution, in terms of load balancing and elasticity functionality.
Paulo A. L. Rego, Michel S. Bonfim, Marcos Dantas Ortiz, Jeandro M. Bezerra, Divanilson Campelo, José Neuman de Souza
GLOBECOM2