VLDB 2026 Research / reviewers in the wild / expert
Iberia Medeiros
dblp:139/8915 · also Ibéria Medeiros
· DBLP profile ↗
25ranked-venue papers
9as first author
13since 2021 · last 2026
0000-0003-4478-8680ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 11 · 1 first-author · 8 since 2021Security and privacy · 9 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 4 first-author · 1 since 2021Systems, architecture and hardware · 3 · 3 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Multimodal NLP Framework for Detecting and Explaining Code Vulnerabilities
Jorge Guerreiro, Iberia Medeiros |
ENASE (2) | 2 |
| 2026 | Detecting Vulnerabilities in Encrypted Software Code While Ensuring Code PrivacyabstractSoftware vulnerabilities continue to be the primary cause of cyberattacks. It is crucial to identify vulnerabilities in applications' source code before attackers gain access to them and exploit any vulnerability they may contain. Developers have used static analysis tools (SATs) to find vulnerabilities in unprotected application code, and software testing companies have started offering software code analysis as a service to assist developers in these findings. Such services require access to unprotected code, which raises concerns about its privacy and intellectual property theft. Attackers can also perform this analysis using similar tools, if they gain access to the code. It is, therefore, beneficial to have a system that can maintain code privacy by protecting it with cryptographic techniques, while still allowing authorised people to detect vulnerabilities in the encrypted code. This paper presents such a solution, a novel approach to Software Quality and Privacy that allows source code to be analysed in a protected manner, preserving its privacy. The proposed solution combines Static Analysis with Searchable Symmetric Encryption (SSE) for confidential vulnerability detection, enabling data and dependency tracking for data flow analysis over encrypted source code. The solution represents the code's data and control flows as an Encrypted Inverted Index, in a connected way that enables SSE's queries for vulnerability discovery. The solution was implemented as the CoCoA tool and evaluated with synthetic and real PHP web applications. Results show that CoCoA has similar precision as (non-confidential) SATs - 93% - with real applications, requiring only 209 ms to process 4k LoC - a modest overhead of 42.7% compared to a non-confidential baseline. This paper also defines a new research field - Confidential Code Analysis -, from which other types of code analysis tasks can be derived. David Dantas, Rafael Ramires, Bernardo Ferreira, Iberia Medeiros |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | CCE: A Cloud-Based SIEM Correlation Engine Built on Serverless FunctionsabstractCybersecurity has been one of the most critical aspects for enterprises in the digital era. Security Information and Event Management (SIEM) systems have been essential in cybersecurity, helping security teams analyse and correlate millions of security events and discover indicators of compromise within an organisation's assets. Deploying and maintaining SIEMs on-premise is expensive, making it difficult for companies with limited budgets to acquire them. Cloud-based SIEMs have emerged as a more cost-effective and viable alternative for such companies. However, they do not fully use the pay-per-use model, requiring additional resources and service subscriptions, which makes them more expensive than initially promised. We present CCE, a Cloud-based SIEM Correlation Engine for processing and correlating events in a Function-as-a-service (FaaS) cloud infrastructure. The core of CCE is a novel method for translating SIEM rules into a set of cost-efficient functions to be deployed in a FaaS infrastructure. We evaluated CCE experimentally in various scenarios, considering different configurations of the FaaS cloud and quality-of-service levels, to study the monetary cost of operating CCE for monitoring different infrastructures. The results show that CCE is significantly cheaper than existing cloud-based SIEMs, costing as little as 272 monthly for processing the generated events by a medium-sized real infrastructure. Adriano Serckumecka, Iberia Medeiros, Alysson Neves Bessani |
SRDS | 2 |
| 2024 | Towards a Web Application Attack Detection System Based on Network Traffic and Log Classification
Rodrigo Branco, Vinicius Vielmo Cogo, Iberia Medeiros |
ENASE | 3 |
| 2024 | On the Path to Buffer Overflow Detection by Model Checking the Stack of Binary Programs
Luís Ferreirinha, Iberia Medeiros |
ENASE | 2 |
| 2024 | Towards a SQL Injection Vulnerability Detector Based on Session Types
António Silvestre, Iberia Medeiros, Andreia Mordido |
ENASE | 2 |
| 2024 | KAVE: A Knowledge-Based Multi-Agent System for Web Vulnerability DetectionabstractThe growing use of the web has led to a rise in cyber attacks exploiting software vulnerabilities, thereby causing significant damage to companies and individuals. Static analysis tools can assist programmers in identifying vulnerabilities within their code. However, these tools are prone to producing false positives and lack precision, which relegates them to a somewhat marginalised role in software development. This paper proposes a new and more effective static analysis approach for assessing and evaluating web applications against vulnerabilities by using a knowledge-based multi-agent system web vulnerability detector called KAVE. The multi-agent system performs static taint analysis over a specially designed multi-layer knowledge graph, whereas this graph aggregates diverse interconnected representations of the lexical and semantic features of the application’s source code, their data and control flows, and function calls. Additionally, this graph integrates security properties associated with vulnerabilities. The evaluation results of KAVE and comparison with existing tools showed that KAVE employs an effective and efficient method to detect vulnerabilities in web applications, finding 235 vulnerabilities with a precision of 95.9% over 12 open-source PHP web applications. Rafael Ramires, Ana Respício, Iberia Medeiros |
ICWS | 3 |
| 2023 | Code Privacy in Detection of Web VulnerabilitiesabstractWe propose a solution combining source code static analysis with searchable symmetric encryption to detect input validation vulnerabilities of web applications in encrypted PHP code, allowing developers to protect their codebase from malicious third parties while simultaneously discovering vulnerabilities in it. Results show that our solution is capable of identifying vulnerabilities with precision similar to traditional static code, non-privacy-preserving analysers and exhibits a maximum overhead increase of around 16,55%. Iberia Medeiros, Bernardo Ferreira |
EASE | 2 |
| 2023 | CorCA: An Automatic Program Repair Tool for Checking and Removing Effectively C FlawsabstractEmbedded systems are present in many devices, such as the Internet of Things, drones, and cyber-physical systems. The software security of these devices can be critical, depending on the context they are integrated and the role they play (e.g., water plants, vehicles). C is the core language used to develop the software for these devices and is known for missing the bounds of its data types, which leads to vulnerabilities such as buffer overflows. These vulnerabilities, when exploited, can cause severe damage and put human life in danger. One of the concerns with vulnerable C programs is to correct the code automatically and adequately, employing secure code that can remove the existing vulnerabilities and avoid attacks. However, such a task faces some challenges, namely determining what code is needed to remove them and, at the same time, ensuring the correct behaviour of the program, where to insert it, and verifying that the correction applied is secure and effectively removes the vulnerabilities. Another challenge is to accomplish all these elements in an automated manner. This paper presents an approach that automatically, after discovering and confirming potential vulnerabilities of an application, applies code correction to fix the vulnerable code of those confirmed vulnerabilities and validates the new code. We implemented the approach, resulting in the CorCA [1] tool, and evaluated it with a set of tests and real applications. The experimental results showed that the tool was capable of detecting vulnerabilities and fixing them correctly. João Inácio, Iberia Medeiros |
ICST | 2 |
| 2022 | Generating Quality Threat Intelligence Leveraging OSINT and a Cyber Threat Unified TaxonomyabstractToday’s threats use multiple means of propagation, such as social engineering, email, and application vulnerabilities, and often operate in different phases, such as single device compromise, lateral network movement, and data exfiltration. These complex threats rely on advanced persistent threats supported by well-advanced tactics for appearing unknown to traditional security defenses. As organizations realize that attacks are increasing in size and complexity, cyber threat intelligence (TI) is growing in popularity and use. This trend followed the evolution of advanced persistent threats, as they require a different level of response that is more specific to the organization. TI can be obtained via many formats, with open-source intelligence one of the most common, and using threat intelligence platforms (TIPs) that aid organizations to consume, produce, and share TI. TIPs have multiple advantages that enable organizations to quickly bootstrap the core processes of collecting, analyzing, and sharing threat-related information. However, current TIPs have some limitations that prevent their mass adoption. This article proposes AECCP, a platform that addresses some of the TIPs limitations. AECCP improves quality TI by classifying it accordingly a single unified taxonomy , removing the information with low value, enriching it with valuable information from open-source intelligence sources, and aggregating it for complementing information associated with the same threat. AECCP was validated and evaluated with three datasets of events and compared with two other platforms, showing that it can generate quality TI automatically and help security analysts analyze security incidents in less time. Cláudio Martins, Iberia Medeiros |
ACM Trans. Priv. Secur. | 2 |
| 2022 | Statically Detecting Vulnerabilities by Processing Programming Languages as Natural LanguagesabstractWeb applications continue to be a favorite target for hackers due to a combination of wide adoption and rapid deployment cycles, which often lead to the introduction of high-impact vulnerabilities. Static analysis tools are important to search for vulnerabilities automatically in the program source code, supporting developers on their removal. However, building these tools requires programming the knowledge on how to discover the vulnerabilities. This article presents an alternative approach in which toolslearnto detect flaws automatically by resorting to artificial intelligence concepts, more concretely to natural language processing. The approach employs a sequence model to learn to characterize vulnerabilities based on an annotated corpus. Afterwards, the model is utilized to discover and identify vulnerabilities in the source code. It was implemented in the DEKANT tool and evaluated experimentally with a large set of PHP applications and WordPress plugins. Overall, we found several thousand vulnerabilities belonging to 15 classes of input validation vulnerabilities, where 4143 of them were zero-day. Iberia Medeiros, Nuno Neves 0001, Miguel Correia 0001 |
IEEE Trans. Reliab. | 1 |
| 2021 | Improving Web Application Vulnerability Detection Leveraging Ensemble Fuzzing
João Caseirito, Iberia Medeiros |
ENASE | 2 |
| 2021 | ETIP: An Enriched Threat Intelligence Platform for improving OSINT correlation, analysis, visualization and sharing capabilities
Gustavo Gonzalez Granadillo, Mario Faiella, Iberia Medeiros, Rui Azevedo, Susana Gonzalez Zarzosa |
J. Inf. Secur. Appl. | 3 |
| 2020 | Towards Web Application Security by Automated Code Correction
Ricardo Morgado, Iberia Medeiros, Nuno Neves 0001 |
ENASE | 2 |
| 2019 | SLICER: Safe Long-Term Cloud Event ArchivalabstractSecurity Information and Event Management (SIEM) systems have been adopted by organizations to enable holistic monitoring of malicious activities in their IT infrastructures. SIEMs receive events from several devices of the organization's IT infrastructure (e.g., servers, firewalls, IDS), correlate these events, and present reports for security analysts. Given the large number of events collected by SIEMs, it is costly to store such data for long periods. Besides, since organizations store a relatively limited time-frame of events, the forensic analysis capabilities severely become reduced. We present SL I CER an archival system for long-term storage that makes use of multi-cloud storage to guarantee data security, low cost and high scalability, and ensures cost-effectiveness by grouping events in blocks and using indexing techniques to recover them. The system was evaluated using a real dataset, and the results show that it is significantly more cost-efficient than competing alternatives. Adriano Serckumecka, Iberia Medeiros, Bernardo Ferreira, Alysson Neves Bessani |
PRDC | 2 |
| 2019 | Low-Cost Serverless SIEM in the CloudabstractSecurity systems such as the Security Information and Event Management (SIEMs) have been used to monitor logs and correlate data to quickly detect and respond to incidents. Despite their advantages, SIEMs are expensive to deploy and maintain, requiring extra budget and specialized staff. Another concern is the event retention period, which events are stored for a short period of time, missing important information about how threats may have affected the company infrastructure in the past. This thesis aims to improve these issues by using low-cost cloud services to correlate and store security events. We will investigate techniques to index, compress and store events in the cloud in a cost-efficient and safe way for a long time. We will create a cloud correlation engine using a serverless platform, such as Amazon Lambda. This approach can minimize the complexity of managing SIEMs in place, charging the customer only for the time actually spent processing events. Finally, we will integrate the storage and correlation engine into a cloud SIEM, providing also a monitoring tool, building a complete and innovative low-cost cloud-based security monitoring solution. Adriano Serckumecka, Iberia Medeiros, Alysson Neves Bessani |
SRDS | 2 |
| 2019 | SEPTIC: Detecting Injection Attacks and Vulnerabilities Inside the DBMSabstractDatabases continue to be the most commonly used backend storage in enterprises, but they are often integrated with vulnerable applications, such as web frontends, which allow injection attacks to be performed. The effectiveness of such attacks stems from a semantic mismatch between how SQL queries are believed to be executed and the actual way in which databases process them. This leads to subtle vulnerabilities in the way input validation is done in applications. In this paper, we propose SEPTIC, a mechanism for DBMS attack prevention, which can also assist on the identification of the vulnerabilities in the applications. The mechanism was implemented in MySQL and evaluated experimentally with various applications and alternative protection approaches. Our results show no false negatives and no false positives with SEPTIC, on the contrary to other solutions. They also show that SEPTIC introduces a low performance overhead, in the order of 2.2%. Iberia Medeiros, Miguel Beatriz, Nuno Neves 0001, Miguel Correia 0001 |
IEEE Trans. Reliab. | 1 |
| 2018 | Benchmarking Static Analysis Tools for Web SecurityabstractStatic analysis tools are recurrently used by developers to search for vulnerabilities in the source code of web applications. However, distinct tools provide different results depending on factors such as the complexity of the code under analysis and the application scenario; thus, missing some of the vulnerabilities while reporting false problems. Benchmarks can be used to assess and compare different systems or components, however, existing benchmarks have strong representativeness limitations, disregarding the specificities of the environment, where the tools under benchmarking will be used. In this paper, we propose a benchmark for assessing and comparing static analysis tools in terms of their capability to detect security vulnerabilities. The benchmark considers four real-world development scenarios, including workloads composed of real web applications with different goals and constraints, ranging from low budget to high-end applications. Our benchmark was implemented and assessed experimentally using a set of 134 WordPress plugins, which served as the basis for the evaluation of five free PHP static analysis tools. Results clearly show that the best solution depends on the deployment scenario and class of vulnerability being detected; therefore, highlighting the importance of these aspects in the design of the benchmark and of future static analysis tools. Paulo Jorge Costa Nunes, Iberia Medeiros, José Fonseca 0002, Nuno Neves 0001, Miguel Correia 0001, Marco Vieira |
IEEE Trans. Reliab. | 2 |
| 2017 | Demonstrating a Tool for Injection Attack Prevention in MySQLabstractDespite the significant efforts put in building more secure web applications, cases of high impact breaches continue to appear. Vulnerabilities in web applications are often created due to inconsistencies in the way SQL queries are believed to be run and the way they are actually executed by a Database Management System (DBMS). This paper presents a demonstration of SEPTIC, a mechanism that detects and blocks injection attacks inside the DBMS. The demonstration considers a scenario of a non-trivial PHP web application, backed by a MySQL DBMS, which was modified to include SEPTIC. It presents how SEPTIC blocks injection attacks without compromising the application correctness and performance. In addition, SEPTIC is compared to alternative approaches, such as sanitizations carried out with standard functions provided language and a web application firewall. Iberia Medeiros, Miguel Beatriz, Nuno Neves 0001, Miguel Correia 0001 |
DSN | 1 |
| 2016 | Hacking the DBMS to Prevent Injection Attacks
Iberia Medeiros, Miguel Beatriz, Nuno Neves 0001, Miguel Correia 0001 |
CODASPY | 1 |
| 2016 | Equipping WAP with WEAPONS to Detect Vulnerabilities: Practical Experience ReportabstractAlthough security starts to be taken into account during software development, the tendency for source code to contain vulnerabilities persists. Open source static analysis tools provide a sensible approach to mitigate this problem. However, these tools are programmed to detect a specific set of vulnerabilities and they are often difficult to extend to detect new ones. WAP is a recent popular open source tool that detects vulnerabilities in the source code of web applications written in PHP. The paper addresses the difficulty of extending these tools by proposing a modular and extensible version of the WAP tool, equipping it with "weapons" to detect (and correct) new vulnerability classes. The new version of the tool was evaluated with seven new vulnerability classes using web applications and plugins of the widely-adopted WordPress content management system. The experimental results show that this extensibility allows WAP to find many new (zero-day) vulnerabilities. Iberia Medeiros, Nuno Neves 0001, Miguel Correia 0001 |
DSN | 1 |
| 2016 | DEKANT: a static analysis tool that learns to detect web application vulnerabilitiesabstractThe state of web security remains troubling as web applications continue to be favorite targets of hackers. Static analysis tools are important mechanisms for programmers to deal with this problem as they search for vulnerabilities automatically in the application source code, allowing programmers to remove them. However, developing these tools requires explicitly coding knowledge about how to discover each kind of vulnerability. This paper presents a new approach in which static analysis tools learn to detect vulnerabilities automatically using machine learning. The approach uses a sequence model to learn to characterize vulnerabilities based on a set of annotated source code slices. This model takes into consideration the order in which the code elements appear and are executed in the slices. The model created can then be used as a static analysis tool to discover and identify vulnerabilities in source code. The approach was implemented in the DEKANT tool and evaluated experimentally with a set of open source PHP applications and WordPress plugins, finding 16 zero-day vulnerabilities. Iberia Medeiros, Nuno Neves 0001, Miguel Correia 0001 |
ISSTA | 1 |
| 2016 | Detecting and Removing Web Application Vulnerabilities with Static Analysis and Data MiningabstractAlthough a large research effort on web application security has been going on for more than a decade, the security of web applications continues to be a challenging problem. An important part of that problem derives from vulnerable source code, often written in unsafe languages like PHP. Source code static analysis tools are a solution to find vulnerabilities, but they tend to generate false positives, and require considerable effort for programmers to manually fix the code. We explore the use of a combination of methods to discover vulnerabilities in source code with fewer false positives. We combine taint analysis, which finds candidate vulnerabilities, with data mining, to predict the existence of false positives. This approach brings together two approaches that are apparently orthogonal: humans coding the knowledge about vulnerabilities (for taint analysis), joined with the seemingly orthogonal approach of automatically obtaining that knowledge (with machine learning, for data mining). Given this enhanced form of detection, we propose doing automatic code correction by inserting fixes in the source code. Our approach was implemented in the WAP tool, and an experimental evaluation was performed with a large set of PHP applications. Our tool found 388 vulnerabilities in 1.4 million lines of code. Its accuracy and precision were approximately 5% better than PhpMinerII's and 45% better than Pixy's. Iberia Medeiros, Nuno Neves 0001, Miguel Correia 0001 |
IEEE Trans. Reliab. | 1 |
| 2014 | Automatic detection and correction of web application vulnerabilities using data mining to predict false positivesabstractWeb application security is an important problem in today's internet. A major cause of this status is that many programmers do not have adequate knowledge about secure coding, so they leave applications with vulnerabilities. An approach to solve this problem is to use source code static analysis to find these bugs, but these tools are known to report many false positives that make hard the task of correcting the application. This paper explores the use of a hybrid of methods to detect vulnerabilities with less false positives. After an initial step that uses taint analysis to flag candidate vulnerabilities, our approach uses data mining to predict the existence of false positives. This approach reaches a trade-off between two apparently opposite approaches: humans coding the knowledge about vulnerabilities (for taint analysis) versus automatically obtaining that knowledge (with machine learning, for data mining). Given this more precise form of detection, we do automatic code correction by inserting fixes in the source code. The approach was implemented in the WAP tool and an experimental evaluation was performed with a large set of open source PHP applications. Iberia Medeiros, Nuno Neves 0001, Miguel Correia 0001 |
WWW | 1 |
| 2013 | Securing energy metering software with automatic source code correctionabstractIndustry is using power meters to monitor the consumption of energy and achieving cost savings. This monitoring often involves energy metering software with a web interface. However, web applications often have vulnerabilities that can be exploited by cyber-attacks. We present an approach and a tool to solve this problem by analyzing the application source code and automatically inserting fixes to remove the discovered vulnerabilities. We demonstrate the use of the tool with two open source energy metering applications in which it found and corrected 17 vulnerabilities. By looking in more detail into some of these vulnerabilities, we argue that they are very serious, leading to the following impacts: violation of user privacy, counter the benefits of energy metering, and serve as entering points for attacks on other user software. Iberia Medeiros, Nuno Neves 0001, Miguel Correia 0001 |
INDIN | 1 |