VLDB 2026 Research / reviewers in the wild / expert
Diogo M. F. Mattos
dblp:144/8416 · also Diogo Menezes Ferrazani Mattos
· DBLP profile ↗
20ranked-venue papers
4as first author
9since 2021 · last 2026
0000-0002-1279-7366ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 12 · 4 first-author · 4 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An Efficient Shared-Memory Framework for TCP Vegas Congestion Control Using Clustering and Optimization
Marcos V. C. Madeira, Diogo M. F. Mattos |
NetSoft | 2 |
| 2025 | Linear, Fractional, and Expolinear: Fair and Efficient Congestion Control Algorithms for TCP in Lossy and Delay-Sensitive NetworksabstractAs the number of devices connected to the Internet increases, the response of applications to competition for network resources and, consequently, to congestion has become a critical issue that affects service quality and user experience. Next-generation networks, such as beyond 5G, 6G, and low Earth orbit (LEO) satellite networks, face additional challenges due to their high sensitivity to delays and packet losses. This paper proposes three TCP congestion control algorithms (CCA) models, named Expolinear, Fractional, and Linear, which leverage packet loss information to dynamically adjust the congestion window (CWND), improving efficiency and adaptability to varying network conditions. We have implemented the algorithms as Linux kernel modules and compared them to traditional algorithms. The proposed models demonstrated up to ten times greater transmission rate efficiency in high packet loss scenarios while maintaining fairness in bandwidth usage among competing flows. Marcos V. C. Madeira, Diogo M. F. Mattos |
NetSoft | 2 |
| 2024 | Optimizing feature selection in intrusion detection systems: Pareto dominance set approaches with mutual information and linear correlation
Guilherme N. N. Barbosa, Martin Andreoni, Diogo M. F. Mattos |
Ad Hoc Networks | 3 |
| 2024 | FedSBS: Federated-Learning participant-selection method for Intrusion Detection Systems
Hélio N. Cunha Neto, Jernej Hribar, Ivana Dusparic, Natalia Castro Fernandes, Diogo M. F. Mattos |
Comput. Networks | 5 |
| 2023 | Exploring Overlay Topology Cost-Termination Tradeoff in Blockchain Vicinity-Based ConsensusabstractPrivate blockchain platforms tend to apply deterministic consensus mechanisms as a more efficient alternative to the proof-based consensus. Deterministic mechanisms tolerate two types of failures, Byzantine, and Crash-Fault. Byzantine-Fault tolerant consensus assumes restrictive assumptions of time and number of failures to guarantee the validity, while the termination depends on node message broadcasting. Crash-Fault tolerant consensus mechanisms induce lower overhead and faster termination than Byzantine-Fault tolerant mechanisms at the cost of not tolerating malicious behaviors. This paper explores different overlay topologies to assess a lightweight consensus mechanism based on vicinity voting with reliable message broadcasting. The paper proposes different ways to compose the consensus quorum according to the vicinity models. Vicinity models applied in the overlay network allow for relaxing the trade-off between agreement and termination. Analytical and experimental results for different physical topologies show that certain vicinity models guarantee higher number of nodes reached at the time of reaching the consensus threshold (higher than 90% of all nodes) with a lower cost at the exchange of lower fault tolerance. Other models induce a lower agreement while increase fault tolerance (higher than 50%). Diogo M. F. Mattos, Gabriel R. Carrara, Célio Vinicius N. de Albuquerque, Daniel Mossé |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2022 | FedSA: Accelerating Intrusion Detection in Collaborative Environments with Federated Simulated AnnealingabstractFast identification of new network attack patterns is crucial for improving network security. Nevertheless, identifying an ongoing attack in a heterogeneous network is a non-trivial task. Federated learning emerges as a solution to collaborative training for an Intrusion Detection System (IDS). The federated learning-based IDS trains a global model using local machine learning models provided by federated participants without sharing local data. However, optimization challenges are intrinsic to federated learning. This paper proposes the Federated Simulated Annealing (FedSA) metaheuristic to select the hyperparameters and a subset of participants for each aggregation round in federated learning. FedSA optimizes hyperparameters linked to the global model convergence. The proposal reduces aggregation rounds and speeds up convergence. Thus, FedSA accelerates learning extraction from local models, requiring fewer IDS updates. The proposal assessment shows that the FedSA global model converges in less than ten communication rounds. The proposal requires up to 50% fewer aggregation rounds to achieve approximately 97% accuracy in attack detection than the conventional aggregation approach. Hélio N. Cunha Neto, Ivana Dusparic, Diogo M. F. Mattos, Natalia Castro Fernandes |
NetSoft | 3 |
| 2021 | Private Data Sharing in a Secure Cloud-based Application for Acute Stroke CareabstractAcute stroke care demands fast procedures and collaboration of different healthcare organisations and professionals. The development of cloud computing and the wide adoption of electronic health records (EHR) foster healthcare systems to improve data availability and potentially enhance acute-stroke care quality. However, the design of a secure and privacy-preserving EHR cloud-based application is challenging. This paper presents the leading security and privacy requirements for healthcare applications and contextualises each requirement in the acute stroke care use case. Moreover, we deploy the ASCLEPIOS eHealth Cloud-based framework to address each requirement in designing an EHR cloud-based application for data sharing during acute stroke care. Our initial prototype combines the ASCLEPIOS framework with a public cloud service infrastructure and a private signature scheme. The prototype meets the security and privacy requirements since it protects the EHR data against unauthorised access, data breaches, and data exposure on public cloud providers. Moreover, we present preliminary results and discussions about the usability and overhead of the ASCLEPIOS framework. Lúcio Henrik A. Reis, Marcela Tuler de Oliveira, Diogo M. F. Mattos, Sílvia Delgado Olabarriaga |
CBMS | 3 |
| 2021 | Vicinity-based Consensus: A Fast in-Neighborhood Convergence Consensus Mechanism for BlockchainabstractPrivate blockchains tend to apply deterministic con-sensus mechanisms as a more efficient alternative to the proof-based consensus. Deterministic mechanisms tolerate two types of failures, byzantine and crash-fault. Byzantine fault-tolerant consensus assumes restrictive assumptions of time and number of failures to guarantee validity, while the termination depends on message broadcasting among nodes. Crash-Fault tolerant consensus is less rigorous to ensure termination and higher throughput while sacrificing agreement. This paper proposes a lightweight consensus mechanism based on vicinity voting with confirmed message broadcasting. Formation rules in the neighborhoods of the peer-to-peer network relax the trade-off between agreement and termination. Experimental results show that the proposal guarantees agreement and termination in case of more permissive formation rules. Besides, the cost of achieving consensus is reduced by up to 46% in more rigorous formation rules with limited impact on termination and agreement. Gabriel R. Carrara, Diogo M. F. Mattos, Célio Vinicius N. de Albuquerque |
GLOBECOM | 2 |
| 2021 | An Entropy-based Hybrid Mechanism for Large-Scale Wireless Network Traffic PredictionabstractThe rising of the Internet of Things (IoT) applications fosters the exponential increase of smart devices, expanding the Internet’s attacking surface. Anomaly prediction mechanisms are mandatory to anticipate security threats. Besides, traffic monitoring and prediction models deliver more resilient and efficient network services. This paper proposes a lightweight user-behavior prediction mechanism based on the decomposition of the network traffic features’ entropy through Discrete Wavelet Transform (DWT) applied to network-flow Shannon Entropy’s time series. The DWT decomposes the entropy into linear and nonlinear components. We compare two forecasting models using Long Short Term Memory (LSTM) Networks and Auto-Regressive Integrated Moving Averages (ARIMA). We evaluate our mechanism in a large-scale academic wireless network, with more than 500 access points. LSTM performs up to 10 times better than ARIMA for predicting the real value of nonlinear flow-source entropy. Considering the transport protocol entropy, LSTM is up to 8 times better than ARIMA, and our results show a high entropy value. LSTM also outperforms ARIMA concerning the prediction time, which is 42% lower for LSTM’s worst-case training time than ARIMA’s best-case training time. Guilherme N. N. Barbosa, Martin Andreoni, Dianne S. V. Medeiros, Diogo M. F. Mattos |
ISNCC | 4 |
| 2020 | Blockchain reputation-based consensus: A scalable and resilient mechanism for distributed mistrusting applicationsabstractConsensus mechanisms in blockchain applications allow mistrusting peers to agree on the global state of the chain. Most of the existing consensus mechanisms, however, are constrained by low efficiency and high energy consumption. In this paper, we propose the Blockchain Reputation-Based Consensus (BRBC) mechanism in which a node must have the reputation score higher than a given network trust threshold before being allowed to insert a new block in the chain. A randomly-selected set of judges monitors the behaviour of each node involved in the consensus and updates the node reputation score. Every cooperative behaviour results in a reward, and a non-cooperative or malicious behaviour results in a punishment. BRBC also uses the reputation score to revoke access to nodes with a reputation score below a given threshold. We present a security analysis, and we demonstrate that BRBC resists against a set of known attacks in the blockchain network. Finally, we simulate a blockchain network to assert the mechanism scalability and resilience to malicious actions in various network scenarios and different rates of malicious actions. The results show BRBC to be efficient to expel all nodes that acted with more than 50% of malicious actions. Marcela Tuler de Oliveira, Lúcio Henrik A. Reis, Dianne S. V. Medeiros, Ricardo Campanha Carrano, Sílvia Delgado Olabarriaga, Diogo M. F. Mattos |
Comput. Networks | 6 |
| 2020 | A Sensitive Stylistic Approach to Identify Fake News on Social NetworkingabstractHuman inefficiency to distinguish between true and false facts poses fake news as a threat to logical truth, which deteriorates democracy, journalism, and credibility in governmental institutions. In this letter, we propose a computational-stylistic analysis based on natural language processing, efficiently applying machine learning algorithms to detect fake news in texts extracted from social media. The analysis considers news from Twitter, from which approximately 33,000 tweets were collected, assorted between real and proven false. In assessing the quality of detection, 86% accuracy, and 94% precision stand out even employing a dimensional reduction to one-sixth of the number of original features. Our approach introduces a minimum overhead, while it has the potential of providing a high confidence index on discriminating fake from real news. Nicollas Rodrigues de Oliveira, Dianne S. V. Medeiros, Diogo M. F. Mattos |
IEEE Signal Process. Lett. | 3 |
| 2019 | Towards a Blockchain-Based Secure Electronic Medical Record for Healthcare ApplicationsabstractElectronic medical records (EMRs) are highly sensitive information shared among peers to keep up-to-date patient history. Providing security, privacy, and availability to these sensitive data is a challenge because, typically, after data publication the patient loses control over them. In this paper, we propose a blockchain-based approach to secure EMR for healthcare applications, where access control is patient-centric. Our proposal keeps encrypted EMRs in the blockchain, and the patient shares the decryption key only with healthcare professionals in which he/she trusts. Blockchain allows untrusted node, in a distributed peer-to-peer network to correctly and verifiably interact with each other, without any reliable intermediary. We investigate the scalability of our approach through simulations. Results show that it scales well since increasing the number of nodes in the network implies a linear increase in the size of the stored chain. Results also reveal that the time for inserting a new EMR in the blockchain remains low even when the number of nodes in the network increases. Marcela Tuler de Oliveira, Lúcio Henrik A. Reis, Ricardo Campanha Carrano, Flávio Luiz Seixas, Débora C. Muchaluat-Saade, Célio Vinicius N. de Albuquerque, Natalia Castro Fernandes, Sílvia Delgado Olabarriaga, Dianne S. V. Medeiros, Diogo M. F. Mattos |
ICC | 10 |
| 2019 | Toward a monitoring and threat detection system based on stream processing as a virtual network function for big dataabstractSummary The late detection of security threats causes a significant increase in the risk of irreparable damages and restricts any defense attempt. In this paper, we propose a sCAlable TRAffic Classifier and Analyzer (CATRACA). CATRACA works as an efficient online Intrusion Detection and Prevention System implemented as a Virtualized Network Function. CATRACA is based on Apache Spark, a Big Data Streaming processing system, and it is deployed over the Open Platform for Network Functions Virtualization (OPNFV), providing an accurate real‐time threat‐detection service. The system presents a friendly graphical interface that provides real‐time visualization of the traffic and the attacks that occur in the network. Our prototype can differentiate normal traffic from denial of service (DoS) attacks and vulnerability probes over 95% accuracy under three different datasets. Moreover, CATRACA handles streaming data under concept drift detection with more than 85% of accuracy. Martin Andreoni, Diogo M. F. Mattos, Otto Carlos M. B. Duarte, Guy Pujolle |
Concurr. Comput. Pract. Exp. | 2 |
| 2018 | SFCPerf: An automatic performance evaluation framework for service function chainingabstractNetwork Function Virtualization allows the provi-sioning and composition of on-demand network function chains tailored to an application or a service. Repeatable compliance tests and performance comparison of network functions and the whole function chains are required for virtual network function manufacturers and telecommunication operators. In this paper, we propose and develop SFCPerf, a framework for an automatic performance evaluation of service function chaining. SFCPerf describes all experimental configuration as a single workflow and provides automatic: (i) environment creation and setup; (ii) network configuration; (iii) experimental data measurement; (iv) experiment execution and control; and (v) data preliminary analysis. Our framework provides repeatability for experimenting different network functions and virtualization infrastructures. To demonstrate SFCPerf functionality, we design and implement a prototype of a service function chain that complies with the Network Service Header (NSH). We show the results of an SFCPerf experiment that evaluates the performance of our prototype, composed of an intrusion detection system (IDS) and a firewall, running on top of the open platform for network function virtualization (OPNFV). Igor Jochem Sanz, Diogo M. F. Mattos, Otto Carlos M. B. Duarte |
NOMS | 2 |
| 2018 | A lightweight protocol for consistent policy update on software-defined networking with multiple controllers
Diogo M. F. Mattos, Otto Carlos M. B. Duarte, Guy Pujolle |
J. Netw. Comput. Appl. | 1 |
| 2017 | A high-performance Two-Phase Multipath scheme for data-center networks
Lyno Henrique G. Ferraz, Rafael P. Laufer, Diogo M. F. Mattos, Otto Carlos M. B. Duarte, Guy Pujolle |
Comput. Networks | 3 |
| 2016 | A resilient distributed controller for software defined networkingabstractControl plane distribution on Software Defined Networking enhances security, performance and scalability of the network. In this paper, we propose an efficient architecture for distribution of controllers. The main contributions of the proposed architecture are: i) A controller distributed areas to ensure security, performance and scalability of the network; ii) A single database maintained by a designated controller to provide consistency to the control plane; iii) An optimized heuristic for locating controllers to reduce latency in the control plane; iv) A resilient mechanism of choosing the designated controller to ensure the proper functioning of the network, even when there are failures. A prototype of the proposal was implemented and the placement heuristic was analyzed in real topologies. The results show that connectivity is maintained even in failure scenarios. Finally, we show that the placement optimization reduces the average latency of controllers. Our proposed heuristic achieves a fair distribution of controllers and outperforms the network resilience of other heuristics up to two times better. Diogo M. F. Mattos, Otto Carlos M. B. Duarte, Guy Pujolle |
ICC | 1 |
| 2014 | A two-phase multipathing scheme based on genetic algorithm for data center networkingabstractData centers for cloud computing should allocate services with different traffic patterns, provide high data transfer capacity and link fault tolerance. Data center network topologies provide physical connection redundancy, which forwarding mechanisms avail to generate multiple paths. In this paper, we divide multipathing into two phases: (i) Configuration phase based on genetic algorithms to minimize path lengths and maximize link usage diversity; (ii) Path selection phase based on heuristics to minimize path reuse. The proposed multipathing scheme implements minimal modification in infrastructure. Our proposal only requires common network devices features and it avoids any tenant modification. We develop a flow simulator to evaluate multipathing techniques. The simulations model flow behaviors in different data center scenarios and compares the proposed scheme with multipathing techniques in literature. The results show the proposed scheme enhances transmission rates, even in the highest network utilization scenarios. Lyno Henrique G. Ferraz, Diogo M. F. Mattos, Otto Carlos M. B. Duarte |
GLOBECOM | 2 |
| 2014 | XenFlow: Seamless migration primitive and quality of service for virtual networksabstractNext generation networks offer virtual networks on demand, each one with its own features and Quality of Service (QoS) requirements. Besides, live-migration provides a flexible and seamless topology remapping primitive for virtual networks, but it is usually limited to a local area network. In this paper, we propose XenFlow, a hybrid virtualization system, based on Xen and OpenFlow. XenFlow main goals are threefold. First, it provides a flexible virtual network migration primitive, as it deploys a Software Defined Networking between virtual machines, based on OpenFlow. Second, it provides a strong isolation of virtual networks, avoiding denial of service caused by interference of other virtual networks. Third, XenFlow offers inter-network and intra-network QoS provisioning by a consistent resource controller. We developed a prototype and our results show that the proposed system performs better than native mechanism of Xen virtual machine migration. XenFlow allows virtual router migration between different local area networks without creating tunnels or losing packets. Our experiments also show that resource usage controller meets QoS requirements and outperforms other techniques while it redistributes idle network resources. Diogo M. F. Mattos, Otto Carlos M. B. Duarte |
GLOBECOM | 1 |
| 2014 | FITS: A flexible virtual network testbed architecture
Igor M. Moraes, Diogo M. F. Mattos, Lyno Henrique G. Ferraz, Miguel Elias M. Campista, Marcelo G. Rubinstein, Luís Henrique Maciel Kosmalski Costa, Marcelo Dias de Amorim, Pedro B. Velloso, Otto Carlos M. B. Duarte, Guy Pujolle |
Comput. Networks | 2 |