VLDB 2026 Research / reviewers in the wild / expert
Everton de Matos
dblp:165/3703
· DBLP profile ↗
15ranked-venue papers
8as first author
9since 2021 · last 2026
0000-0001-5888-0969ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 3 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 first-authorSecurity and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Toward an Intrusion Detection System for a Virtualization Framework in Edge ComputingabstractEdge computing pushes computation closer to data sources, but it also expands the attack surface on resource-constrained devices. This work explores the deployment of the Lightweight Deep Anomaly Detection for Network Traffic (LDPI) integrated as an isolated service within a virtualization framework that provides security by separation. LDPI, adopting a Deep Learning approach, achieved strong training performance, reaching AUC 0.999 (5-fold mean) across the evaluated packet-window settings (n, l), with high F1 at conservative operating points. We deploy LDPI on a laptop-class edge node and evaluate its overhead and performance in two scenarios: (i) comparing it with representative signature-based IDSes (Suricata and Snort) deployed on the same framework under identical workloads, and (ii) while detecting network flooding attacks. Everton de Matos, Hazaa Alameri, Willian Tessaro Lunardi, Martin Andreoni, Eduardo Viegas 0001 |
WCNC | 1 |
| 2025 | An Energy-Efficient Intrusion Detection Offloading Based on DNN for Edge ComputingabstractTo address the computational limitations associated with implementing Deep Neural Network (DNN)–based intrusion detection on resource-constrained devices, this work proposes an energy-efficient edge architecture that integrates distributed early-exit DNN models to minimize processing overhead while preserving detection performance. Our approach employs multi-objective optimization to dynamically offload complex tasks to the cloud, thereby balancing the trade-off between accuracy and energy consumption under operator constraints. Furthermore, it incorporates a rejection mechanism and confidence calibration via temperature scaling to ensure reliability as network traffic evolves. Experiments on a 7TB year-long dataset demonstrate that the system reduces edge energy consumption to only 1% while offloading only 10% of events, all without compromising detection accuracy and even improving the F1-Score by 0.02 compared to traditional approaches. João A. Simioni, Eduardo Viegas 0001, Altair Olivo Santin, Everton de Matos |
IEEE Internet Things J. | 4 |
| 2024 | Toward a Reliable Network-Based Intrusion Detection Model for SCADA: A Classification with Reject Option ApproachabstractIndustrial control systems (ICS) are often targeted by highly motivated attackers seeking to disrupt their services due to its critical nature. Traditional cybersecurity does not provide the necessary reliability for ICS systems. Even when implemented with many layers of defense, including network intrusion detection systems (NIDS). This paper proposes a dynamic and reliable intrusion detection model that is implemented in two steps. First, it proactively classifies each type of possible network attack on the basis of the current network traffic behavior. Second, it evaluates the classification quality through rejection option, which is an indication of its reliability. By adapting to the evolving network traffic, our proposal increases the system robustness against motivated attackers. The proposed model effectiveness has been demonstrated by experimenting in a controlled testbed with more than 14 attack categories. The dynamic selection of security mechanisms allowed us to increase the detection accuracy by up to 26%. Moreover, the classification evaluation in the proposed model achieves up to 99% detection accuracy with only 1% rejection. Paulo Roberto de Oliveira, Eduardo Viegas 0001, Altair Olivo Santin, Pedro Horchulhack, Everton de Matos |
IJCNN | 5 |
| 2024 | An seL4-based Trusted Execution Environment on RISC-VabstractIn an era where digital security is paramount, the concept of Trusted Execution Environments (TEEs) is crucial for safeguarding sensitive data within computing systems. This paper introduces an implementation of seL4 as a secure operating system in a TEE on RISC-V hardware. We address integration challenges, offering insights for future secure system designs. A comprehensive performance evaluation of the seL4-based TEE shows enhanced security and operational efficiency. This includes assessments of the Linux Rich Execution Environment’s (REE) performance and analyses of essential TEE services: Random Number Generation, Key Pair Generation, and Digital Signing Operations. Our deployment on the PolarFire SoC Icicle kit demonstrates practicality and viability in a real-world environment. This research contributes to trusted computing area by merging seL4’s robust microkernel architecture with RISC-V’s open-source flexibility, fostering secure, efficient, and adaptable computing solutions. Everton de Matos, Willian Tessaro Lunardi, Jouni Ukkonen, Tero Salminen |
IWCMC | 1 |
| 2023 | Context-Aware Security in the Internet of Things: A Review
Everton de Matos, Eduardo Viegas 0001, Ramão Tiago Tiburski, Fabiano Hessel |
AINA (3) | 1 |
| 2023 | A Dynamic Machine Learning Scheme for Reliable Network-Based Intrusion Detection
Eduardo Viegas 0001, Everton de Matos, Paulo Roberto de Oliveira, Altair Olivo Santin |
AINA (2) | 2 |
| 2023 | Integrating VirtIO and QEMU on seL4 for Enhanced Devices Virtualization SupportabstractVirtualization is a crucial technology for consolidating workloads and improving resource utilization in modern computing systems. seL4 is a small TCB (Trusted Computing Base) microkernel that can be used as a hypervisor to provide virtualization features. However, providing standard device interfaces to it remains a significant challenge in achieving secure and high-performance virtualization solutions for critical systems. To address this challenge, this paper proposes an approach that leverages the VirtIO standard through QEMU to provide a secure and efficient device virtualization solution for seL4. The feature takes advantage of seL4’s isolation guarantees and enables sharing of complex devices for multiple virtual machines, combined with the efficient communication interface provided by the VirtIO standard. We implemented and evaluated the approach using a set of benchmarks. The proposed approach leverages the VirtIO standard through QEMU on top of the seL4, aiming to offer a virtualization solution that accelerates development speed and enhances architectural flexibility by eliminating the need for native drivers. Everton de Matos, Conor Lennon, Eduardo Viegas 0001, Markku Ahvenjärvi, Hannu Lyytinen, Joonas Onatsu, Anh Huy Bui |
TrustCom | 1 |
| 2023 | A Dynamic Network-based Intrusion Detection Model for Industrial Control SystemsabstractIndustrial Control Systems (ICS) play a crucial role in managing and controlling industrial assets. Due to their critical importance, adversaries are often highly motivated to target these systems, as a successful attack can disrupt the entire industry’s operations. In general, to improve the system’s security, proposed intrusion detection schemes often resort to traditional security mechanisms. As a consequence, due to their static nature, attackers can easily evade designed detection approaches. In light of this, this paper proposes a new dynamic network-based intrusion detection model for ICS, implemented in two phases. First, our scheme extracts network-related features to describe the current ICS environment behavior. Second, the security mechanisms are proactively selected based on the extracted network traffic behavior. As a result, our scheme can adjust the system’s configuration based on the current assessed event. Experiments on a new dataset, featuring over 14 attack categories targeting a SCADA system revealed that traditional detection methods face challenges in handling diverse attack categories. Conversely, our proposed model improved the average true-positive rates by up to 20% while also improving the range of detected attacks. Paulo Roberto de Oliveira, Altair Olivo Santin, Pedro Horchulhack, Eduardo Viegas 0001, Everton de Matos |
TrustCom | 5 |
| 2021 | A lightweight virtualization model to enable edge computing in deeply embedded systemsabstractAbstract Edge computing paradigm enables moving Internet of Things (IoT) applications from the Cloud to the edge of the network. Modern software engineering approaches are adhering to microservices to enable the deployment of such applications on edge devices. Microservices consist of the disaggregation of an application into smaller pieces that operate independently. Recent works have explored microservices packaged into containers and advocate that containers result in a reduced footprint and avoid the unwanted overhead caused by traditional virtualization. However, containers cannot be used in many deeply embedded systems (DES) due to an underlying operating system's (OSs) requirement. DES are edge devices with minimal resources regarding storage, memory, and processing power. Thus, they cannot afford large and sophisticated OSs. This article presents the Hellfire hypervisor, a lightweight virtualization implementation that enables separation and improves security in IoT applications on DES. Our proposal simplifies the traditional hypervisor approach and reaches devices where the existing techniques fail. The results show that the proposed model has a small footprint of 23 KB while keeping a low average virtualization overhead of 0.62% for multiple virtual machines execution. Ramão Tiago Tiburski, Carlos Moratelli, Sergio Johann Filho, Everton de Matos, Fabiano Hessel |
Softw. Pract. Exp. | 4 |
| 2020 | Context information sharing for the Internet of Things: A survey
Everton de Matos, Ramão Tiago Tiburski, Carlos Moratelli, Sergio Johann Filho, Leonardo A. Amaral, Gowri Sankar Ramachandran, Bhaskar Krishnamachari, Fabiano Hessel |
Comput. Networks | 1 |
| 2018 | Context Interoperability for IoT Through an Edge-Centric Context Sharing ArchitectureabstractThe adoption of the Internet of Things (IoT) demands advances to cope with the large heterogeneity of IoT entities (i.e., systems, applications, and devices). Context information is an essential characteristic of these entities, which can store relevant details about their environments and related events. However, with the integration of different IoT vertical domains, providing isolated context is no longer enough. Sharing the context information is mandatory to have interoperability. Edge computing emerges as a promising approach to help in filling the context sharing gap by minimizing information overhead and reducing network latency. In this sense, this paper defines an Edge-centric Context Sharing Architecture able to make context sharing based on edge-to-fog approach. We also discuss the requirements for context sharing and the related work in the area to make clear the novelty of the architecture. Everton de Matos, Ramão Tiago Tiburski, Leonardo A. Amaral, Fabiano Hessel |
ISCC | 1 |
| 2017 | A sensing-as-a-service context-aware system for Internet of Things environmentsabstractThe Internet of Things (IoT) will connect billions of devices deployed around the world in a near future by embedding mobile network and processing power capabilities into a wide range of physical computing devices used in everyday life of many people. Recent studies concerning IoT have addressed not only the interoperability of devices, but also the context awareness feature which makes easy to discover, understand, and store relevant information related to IoT devices. This work aims to present a Context-Aware System called CONASYS, a system able to sense the environment and to provide contextualized services to the users, meeting the users needs without specific knowledge of the environment, and improving the Quality of Experience (QoE). We present in details the architecture of CONASYS, the technical issues related to the implementation of the system, and evaluation tests. Everton de Matos, Leonardo A. Amaral, Ramão Tiago Tiburski, Matheus Crespi Schenfeld, Dario F. G. de Azevedo, Fabiano Hessel |
CCNC | 1 |
| 2017 | Evaluating the use of TLS and DTLS protocols in IoT middleware systems applied to E-healthabstractThe evolution of the Internet of Things (IoT) has brought new security requirements in terms of communication services with respect to data transmitted in mobile networks. Although IoT middleware systems have been used to cope with the most relevant requirements demanded by different IoT applications, security is a special topic that is not mature enough in this kind of technology. E-health is an example of environment that exposes sensitive data. The security challenges regarding e-health applications are concentrated mainly on issues surrounding the communication layer, specially those cases where data are transmitted over insecure networks. TLS and DTLS protocols have been chosen by most of the existing IoT systems in order to protect such communications. However, none of them was designed to be used in IoT situations. In addition, none of the existing works analyzes their suitability to the IoT regarding the usage of mobile networks, which are common in real-world scenarios of e-health. In this paper, we analyze the use of TLS and DTLS protocols in IoT middleware systems applied to the e-health environment regarding performance (i.e., response time), overhead, network latency and packet loss when operating in mobile networks. We evaluated both protocols through a specific e-health scenario. Tests revealed the usage of mobile networks increases response time and overhead of both protocols, on average, when compared to traditional networks. Ramão Tiago Tiburski, Leonardo A. Amaral, Everton de Matos, Dario F. G. de Azevedo, Fabiano Hessel |
CCNC | 3 |
| 2015 | Context-based search engine for industrial IoT: Discovery, search, selection, and usage of devicesabstractDuring the past few years, with the fast development and proliferation of the Internet of Things (IoT), many application areas have started to exploit this new computing paradigm. An interesting use of IoT is in the Industrial field, which has resulted in a new business concept called IIoT (Industrial Internet of Things). Another important fact is the number of active computing devices has been growing at a rapid pace in IoT environments around the world. Consequently, a mechanism to deal with this different devices has become necessary. Middleware systems solutions for IoT have been developed in both research and industrial environments to supply this need. However, discover, search, select, and interact with devices remain a critical challenge. In this paper we present COBASEN, a software framework composed of a Context Module and a Search Engine to address the research challenge regarding the discovery and interaction with IoT devices when large number of devices with overlapping and sometimes redundant functionality are available in IoT middleware systems. The search engine of the COBASEN operates based on the semantic characteristics of the devices, which is provided by the context module, and that helps users in their interactions with desired devices. The main goal of this work is to highlight the importance of a context-based search engine in the IoT paradigm and to provide a solution that addresses the proper management of search and usage in IoT middleware environments. We developed a tool that implements all COBASEN concepts. However, for preliminarily tests, we made a functional evaluation of the search engine in terms of performance for indexing and querying response time. Our initial findings suggest that COBASEN provides important approaches that facilitate the development of IIoT applications, which based on the COBASEN systems support, may perform essential roles to improve industrial processes. Willian Tessaro Lunardi, Everton de Matos, Ramão Tiago Tiburski, Leonardo A. Amaral, Sabrina Marczak, Fabiano Hessel |
ETFA | 2 |
| 2015 | Context-aware system for information services provision in the Internet of ThingsabstractIn the last years a new computing paradigm called Internet of Things (IoT) has been gaining more attention. This paradigm has become popular by embedding mobile network and processing capability into a wide range of physical computing devices used in everyday life of many people. An important part that composes the IoT is the middleware, which is a system that abstracts the management of physical devices and provides services based on the information of these devices. Context-aware is an important feature of IoT middleware systems. This feature allows to discover, understand, and store relevant information related to devices and their respective events. In this sense, this work aims to present an ongoing system that has been developed to provide services of contextualized information about IoT devices in heterogeneous environments. Everton de Matos, Leonardo A. Amaral, Ramão Tiago Tiburski, Willian Tessaro Lunardi, Fabiano Hessel, Sabrina Marczak |
ETFA | 1 |