Otto Carlos M. B. Duarte

dblp:18/2077 · also Otto Carlos Muniz Bandeira Duarte · DBLP profile ↗
← Back
71ranked-venue papers
0as first author
5since 2021 · last 2022
0000-0002-6642-4100ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 57 · 4 since 2021Systems, architecture and hardware · 5 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4
YearPublicationVenuePosition
2022 Enhancing Automatic Attack Detection through Spectral Decomposition of Network Flows
abstract
Flow classification employs machine learning techniques to identify attacks on computer networks. This classification relies on quantitative features that synthesize the information of packets from the same flow. Conventional features, however, such as packet size and the number of bytes, generate redundancies and do not capture the temporal correlations between the packets in a flow. Automated network attacks generate periodic patterns observable through spectral decomposition, which facilitates classification. This paper proposes FENED (Feature Extraction by Network spEctrum Decomposition), a method to extract features from network data. We consider the packet-arrived order within the same flow using the fast Fourier transform for binary classification. The proposed feature vector contains the module of the spectral components of the flow. Experimental results show that FENED outperforms conventional proposals because it extracts features that consider intra-flow packet-arrival order.
Lucas Airam C. de Souza, Gustavo Franco Camilo, Miguel Elias M. Campista, Luís Henrique Maciel Kosmalski Costa, Otto Carlos M. B. Duarte
GLOBECOM5
2022 A Blockchain-based System for Secure and Distributed Virtual Network Functions Orchestration
abstract
Service provisioning in next-generation networks, such as 5G and 6G, relies on virtualization to carry out multi-domain and multi-tenant connections. In these scenarios, virtual network functions (VNF) orchestration becomes susceptible to security threats once trust between peers cannot be assumed. This paper1proposes a blockchain-based system for an agile, secure, and distributed provisioning of virtual network functions in scenarios with multiple administrative domains. Our proposal employs smart contracts to deliver all stages of a service-level-agreement management life cycle automatically. We develop, implement, and evaluate a prototype of the proposed system using smart contracts running on Hyperledger Fabric. The performance evaluation results show that the system guarantees high-rate VNF provisioning, reaching hundreds of slice requests per second in a trustful way.
Gustavo Franco Camilo, Lucas Airam C. de Souza, Miguel Elias M. Campista, Luís Henrique Maciel Kosmalski Costa, Otto Carlos M. B. Duarte
ICC5
2022 Securing Wireless Payment-Channel Networks With Minimum Lock Time Windows
abstract
Payment-channel networks (PCN) enhance the impact of cryptocurrencies by providing a fast and consensus-free solution to the scalability problems of traditional blockchain protocols. However, PCNs often rely on powerful nodes with high availability, large storage capacity, and strong computational power, which hinders their adoption in mobile environments. In this paper, we consider a PCN architecture that extends the functionalities of traditional PCNs to wireless resource-constrained devices. We address the token theft problem, a vulnerability that is critical on wireless PCNs, and propose a countermeasure based on minimum time windows that lock tokens whenever a user disconnects. We evaluate our proposal with real data from Bitcoin’s Lightning Network and 3G/4G mobile broadband networks. The results show that the countermeasure is most effective when devices present high availability and that there is a security-efficiency trade-off when connectivity is low.
Gabriel A. F. Rebello, Maria Potop-Butucaru, Marcelo Dias de Amorim, Otto Carlos M. B. Duarte
ICC4
2022 A fast and accurate threat detection and prevention architecture using stream processing
abstract
Summary Late detection of security breaches increases the risk of irreparable damages and limits any mitigation attempts. We propose a fast and accurate threat detection and prevention architecture that combines the advantages of real‐time streaming with batch processing over a historical database. We create a dataset by capturing both legitimate and malicious traffic and propose two ways of combining packets into flows, one considering a time window and the other analyzing the first few packets of each flow per period. We also investigate the effectiveness of our proposal on real‐world network traces obtained from a significant Brazilian network operator providing broadband Internet to their customers. We implement and evaluate three classification algorithms and two anomaly detection methods. The results show an accuracy higher than 95% and an excellent trade‐off between attack detection and false‐positive rates. We further propose an improved scheme based on software defined networks that automatically prevents threats by analyzing only the first few packets of a flow. The proposal promptly and efficiently blocks threats, is robust, and can scale up, even when the attacker employs spoofed IP.
Antonio G. P. Lobato, Martin Andreoni, Alvaro A. Cárdenas, Otto Carlos M. B. Duarte, Guy Pujolle
Concurr. Comput. Pract. Exp.4
2021 Architecture and Performance Comparison of Permissioned Blockchains Platforms for Smart Contracts
abstract
Blockchain and Smart Contracts ensure security and automation in trustless scenarios, leading to innovative solutions in various industry branches. The Hyperledger open-source project adopts these technologies in the corporate business, providing platforms for developing distributed applications. This paper analyses and compares two widely used platforms to develop applications based on permissioned blockchains: Hyper-ledger Sawtooth and Hyperledger Fabric. We implement two prototypes based on the same smart contract to evaluate the performance of each tool. The results show that: i) Sawtooth parallel transaction execution performs up to 30% better than serial execution only if the number of conflicting transactions remains low, and ii) Fabric has a much faster consensus protocol, but presents a low performance if the transactions are conflicting.
Guilherme A. Thomaz, Gustavo Franco Camilo, Lucas Airam C. de Souza, Otto Carlos M. B. Duarte
GLOBECOM4
2020 AutAvailChain: Automatic and Secure Data Availability through Blockchain
abstract
The trust centralization in current data sharing systems restricts the owner's control over their data. Furthermore, the owner's intervention to authorize his/hers data access for each request makes frequent access to popular data tiresome. In this paper, we propose AutAvailChain, an architecture based on software defined networking (SDN) and blockchain to provide secure, automatic, and distributed sharing of IoT data. We develop a prototype using the Hyperledger Fabric platform to implement the blockchain and a smart contract. The results show a quick, secure, and excellent performance of dozens of transactions per second.
Gustavo Franco Camilo, Gabriel A. F. Rebello, Lucas Airam C. de Souza, Otto Carlos M. B. Duarte
GLOBECOM4
2019 Providing a Sliced, Secure, and Isolated Software Infrastructure of Virtual Functions Through Blockchain Technology
abstract
Network slicing, network function virtualization (NFV), and software defined network (SDN) technologies provide agile on-demand end-to-end services. The identification of a faulty virtual function becomes mandatory because services allocate resources across a distributed and trustless environment composed by multi-tenant competing service providers. In this paper, we propose and develop a blockchain-based architecture to provide auditability to orchestration operations of network slices and to provide secure VNF configuration updates while ensuring isolation and privacy between network slices. A proof of concept prototype using the Hyperledger Fabric platform was developed in which network slice runs on an isolated channel. The results show that we can secure a network slice creation, but that the consensus and the number of transaction required by the slices are a great challenge.
Gabriel A. F. Rebello, Gustavo Franco Camilo, Leonardo G. C. Silva, Lucas C. B. Guimarães, Lucas Airam C. de Souza, Igor D. Alvarenga, Otto Carlos M. B. Duarte
HPSR7
2019 BSec-NFVO: A Blockchain-Based Security for Network Function Virtualization Orchestration
abstract
Network Function Virtualization (NFV) and Service Function Chaining (SFC) offer flexible end-to-end services that deploy virtual network functions in clouds of competing providers. Orchestration of virtual network functions occurs in a distributed and trustless environment that must tolerate byzantine failures and collusion attacks. This paper proposes BSec-NFVO, a blockchain-based system that secures orchestration operations in virtualized networks, ensuring auditability, non-repudiation and integrity. We propose an NFV-tailored blockchain and a transaction model. BSec-NFVO provides a modular architecture to secure orchestration in a simple and agile way. We develop a prototype of BSec-NFVO for the Open Platform for Network Function Virtualization (OPNFV) with an adaptation of the normal-case of a collusion-resistant consensus protocol. The results show BSec-NFVO incurs low overhead to the cloud orchestrator and presents stable performance as the number of consensus participants increases.
Gabriel A. F. Rebello, Igor D. Alvarenga, Igor Jochem Sanz, Otto Carlos M. B. Duarte
ICC4
2019 Toward a monitoring and threat detection system based on stream processing as a virtual network function for big data
abstract
Summary The late detection of security threats causes a significant increase in the risk of irreparable damages and restricts any defense attempt. In this paper, we propose a sCAlable TRAffic Classifier and Analyzer (CATRACA). CATRACA works as an efficient online Intrusion Detection and Prevention System implemented as a Virtualized Network Function. CATRACA is based on Apache Spark, a Big Data Streaming processing system, and it is deployed over the Open Platform for Network Functions Virtualization (OPNFV), providing an accurate real‐time threat‐detection service. The system presents a friendly graphical interface that provides real‐time visualization of the traffic and the attacks that occur in the network. Our prototype can differentiate normal traffic from denial of service (DoS) attacks and vulnerability probes over 95% accuracy under three different datasets. Moreover, CATRACA handles streaming data under concept drift detection with more than 85% of accuracy.
Martin Andreoni, Diogo M. F. Mattos, Otto Carlos M. B. Duarte, Guy Pujolle
Concurr. Comput. Pract. Exp.3
2018 An Adaptive Real-Time Architecture for Zero-Day Threat Detection
abstract
Attackers create new threats and constantly change their behavior to mislead security systems. In this paper, we propose an adaptive threat detection architecture that trains its detection models in real time. The major contributions of the proposed architecture are: i) gather data about zero-day attacks and attacker behavior using honeypots in the network; ii) process data in real time and achieve high processing throughput through detection schemes implemented with stream processing technology; iii) use of two real datasets to evaluate our detection schemes, the first from a major network operator in Brazil and the other created in our lab; iv) design and development of adaptive detection schemes including both online trained supervised classification schemes that update their parameters in real time and learn zero-day threats from the honeypots, and online trained unsupervised anomaly detection schemes that model legitimate user behavior and adapt to changes. The performance evaluation results show that proposed architecture maintains an excellent trade-off between threat detection and false positive rates and achieves high classification accuracy of more than 90%, even with legitimate behavior changes and zero-day threats.
Antonio G. P. Lobato, Martin Andreoni, Igor Jochem Sanz, Alvaro A. Cárdenas, Otto Carlos M. B. Duarte, Guy Pujolle
ICC5
2018 Securing configuration management and migration of virtual network functions using blockchain
abstract
The integration of network function visualization (NFV) and service function chaining (SFC) adds intelligence to the core of the network. The programmability of the network core, however, raises new vulnerabilities and increases the number of victims, since a simple modification in the core can affect multiple network users. Thus, the provision of secure virtual network service functions (VNFs) is mandatory to guarantee a correct chaining of network functions. This paper proposes a blockchain-based architecture for secure management, configuration and migration of VNFs, which ensures: (i) immutability, non-repudiation, and auditability of the configuration update history; (ii) integrity and consistency of stored information; and (iii) the anonymity of VNFs, tenants, and configuration information. Furthermore, the proposed architecture guarantees the secure update and migration of configurations at the core of the network. A prototype of the proposed architecture using the Open Platform for NFV (OPNFV) indicates parameter trade-offs and performance bottlenecks.
Igor D. Alvarenga, Gabriel A. F. Rebello, Otto Carlos M. B. Duarte
NOMS3
2018 SFCPerf: An automatic performance evaluation framework for service function chaining
abstract
Network Function Virtualization allows the provi-sioning and composition of on-demand network function chains tailored to an application or a service. Repeatable compliance tests and performance comparison of network functions and the whole function chains are required for virtual network function manufacturers and telecommunication operators. In this paper, we propose and develop SFCPerf, a framework for an automatic performance evaluation of service function chaining. SFCPerf describes all experimental configuration as a single workflow and provides automatic: (i) environment creation and setup; (ii) network configuration; (iii) experimental data measurement; (iv) experiment execution and control; and (v) data preliminary analysis. Our framework provides repeatability for experimenting different network functions and virtualization infrastructures. To demonstrate SFCPerf functionality, we design and implement a prototype of a service function chain that complies with the Network Service Header (NSH). We show the results of an SFCPerf experiment that evaluates the performance of our prototype, composed of an intrusion detection system (IDS) and a firewall, running on top of the open platform for network function virtualization (OPNFV).
Igor Jochem Sanz, Diogo M. F. Mattos, Otto Carlos M. B. Duarte
NOMS3
2018 A lightweight protocol for consistent policy update on software-defined networking with multiple controllers
Diogo M. F. Mattos, Otto Carlos M. B. Duarte, Guy Pujolle
J. Netw. Comput. Appl.2
2017 A high-performance Two-Phase Multipath scheme for data-center networks
Lyno Henrique G. Ferraz, Rafael P. Laufer, Diogo M. F. Mattos, Otto Carlos M. B. Duarte, Guy Pujolle
Comput. Networks4
2017 An autonomous and efficient controller-based routing scheme for networking Named-Data mobility
Joao Vitor Torres, Igor D. Alvarenga, Raouf Boutaba, Otto Carlos M. B. Duarte
Comput. Commun.4
2016 A Performance Comparison of Open-Source Stream Processing Platforms
abstract
Distributed stream processing platforms is a new class of real-time monitoring systems that analyze and extracts knowledge from large continuous streams of data. This type of systems is crucial for providing high throughput and low latency required by Big Data or Internet of Things monitoring applications. This paper describes and analyzes three main open-source distributed stream- processing platforms: Storm Flink, and Spark Streaming. We analyze the system architectures and we compare their main features. We carry out two experiments concerning anomaly detection on network traffic to evaluate the throughput efficiency and the resilience to node failures. Results show that the performance of native stream processing systems, Storm and Flink, is up to 15 times higher than the micro-batch processing system, Spark Streaming. On the other hand, Spark Streaming is more robust to node failures and provides recovery without losses.
Martin Andreoni, Antonio G. P. Lobato, Otto Carlos M. B. Duarte
GLOBECOM3
2016 A resilient distributed controller for software defined networking
abstract
Control plane distribution on Software Defined Networking enhances security, performance and scalability of the network. In this paper, we propose an efficient architecture for distribution of controllers. The main contributions of the proposed architecture are: i) A controller distributed areas to ensure security, performance and scalability of the network; ii) A single database maintained by a designated controller to provide consistency to the control plane; iii) An optimized heuristic for locating controllers to reduce latency in the control plane; iv) A resilient mechanism of choosing the designated controller to ensure the proper functioning of the network, even when there are failures. A prototype of the proposal was implemented and the placement heuristic was analyzed in real topologies. The results show that connectivity is maintained even in failure scenarios. Finally, we show that the placement optimization reduces the average latency of controllers. Our proposed heuristic achieves a fair distribution of controllers and outperforms the network resilience of other heuristics up to two times better.
Diogo M. F. Mattos, Otto Carlos M. B. Duarte, Guy Pujolle
ICC2
2016 Orchestrating Virtualized Network Functions
abstract
Middleboxes or network appliances like firewalls, proxies, and WAN optimizers have become an integral part of today's ISP and enterprise networks. Middlebox functionalities are usually deployed on expensive and proprietary hardware that require trained personnel for deployment and maintenance. Middleboxes contribute significantly to a network's capital and operation costs. In addition, organizations often require their traffic to pass through a specific sequence of middleboxes for compliance with security and performance policies. This makes the middlebox deployment and maintenance tasks even more complicated. Network function virtualization (NFV) is an emerging and promising technology that is envisioned to overcome these challenges. It proposes to move packet processing from dedicated hardware middleboxes to software running on commodity servers. In NFV terminology, software middleboxes are referred to as virtualized network functions (VNFs). It is a challenging problem to determine the required number and placement of VNFs that optimizes network operational costs and utilization, without violating service level agreements. We call this the VNF orchestration problem (VNF-OP) and provide an integer linear programming formulation with implementation in CPLEX. We also provide a dynamic programming-based heuristic to solve larger instances of VNF-OP. Trace driven simulations on realworld network topologies demonstrate that the heuristic can provide solutions that are within 1.3 times of the optimal solution. Our experiments suggest that a VNF-based approach can provide more than 4× reduction in the operational cost of a network.
Md. Faizul Bari, Shihabur Rahman Chowdhury, Reaz Ahmed, Raouf Boutaba, Otto Carlos M. B. Duarte
IEEE Trans. Netw. Serv. Manag.5
2015 Providing elasticity to intrusion detection systems in virtualized Software Defined Networks
abstract
This paper presents BroFlow, an Intrusion Detection and Prevention System based on Bro traffic analyzer, and on the global network-view feature of OpenFlow Application Programming Interface. BroFlow main contributions are: i) dynamic and elastic resource provision of machines under demand; ii) real-time detection of DoS attacks through simple algorithms implemented in a policy language for network events; iii) immediate reaction to DoS attacks and malicious packets, dropping flows close from their source; iv) strategic sensor positioning for attack detection in the network infrastructure shared by multi-tenants. A system prototype was developed and evaluated in the virtual environment Future Testbed Internet with Security (FITS). An evaluation of the system under attack shows that BroFlow guarantees the forwarding of legitimate packets at the maximal link rate, up to 90% reduction of the maximal network delay caused by the attack, and 50% of bandwidth gain compared with conventional firewalls approaches, even when the attackers are legitimate tenants acting in collusion.
Martin Andreoni, Otto Carlos M. B. Duarte
ICC2
2014 A two-phase multipathing scheme based on genetic algorithm for data center networking
abstract
Data centers for cloud computing should allocate services with different traffic patterns, provide high data transfer capacity and link fault tolerance. Data center network topologies provide physical connection redundancy, which forwarding mechanisms avail to generate multiple paths. In this paper, we divide multipathing into two phases: (i) Configuration phase based on genetic algorithms to minimize path lengths and maximize link usage diversity; (ii) Path selection phase based on heuristics to minimize path reuse. The proposed multipathing scheme implements minimal modification in infrastructure. Our proposal only requires common network devices features and it avoids any tenant modification. We develop a flow simulator to evaluate multipathing techniques. The simulations model flow behaviors in different data center scenarios and compares the proposed scheme with multipathing techniques in literature. The results show the proposed scheme enhances transmission rates, even in the highest network utilization scenarios.
Lyno Henrique G. Ferraz, Diogo M. F. Mattos, Otto Carlos M. B. Duarte
GLOBECOM3
2014 XenFlow: Seamless migration primitive and quality of service for virtual networks
abstract
Next generation networks offer virtual networks on demand, each one with its own features and Quality of Service (QoS) requirements. Besides, live-migration provides a flexible and seamless topology remapping primitive for virtual networks, but it is usually limited to a local area network. In this paper, we propose XenFlow, a hybrid virtualization system, based on Xen and OpenFlow. XenFlow main goals are threefold. First, it provides a flexible virtual network migration primitive, as it deploys a Software Defined Networking between virtual machines, based on OpenFlow. Second, it provides a strong isolation of virtual networks, avoiding denial of service caused by interference of other virtual networks. Third, XenFlow offers inter-network and intra-network QoS provisioning by a consistent resource controller. We developed a prototype and our results show that the proposed system performs better than native mechanism of Xen virtual machine migration. XenFlow allows virtual router migration between different local area networks without creating tunnels or losing packets. Our experiments also show that resource usage controller meets QoS requirements and outperforms other techniques while it redistributes idle network resources.
Diogo M. F. Mattos, Otto Carlos M. B. Duarte
GLOBECOM2
2014 An accurate and precise malicious node exclusion mechanism for ad hoc networks
Lyno Henrique G. Ferraz, Pedro B. Velloso, Otto Carlos M. B. Duarte
Ad Hoc Networks3
2014 FITS: A flexible virtual network testbed architecture
Igor M. Moraes, Diogo M. F. Mattos, Lyno Henrique G. Ferraz, Miguel Elias M. Campista, Marcelo G. Rubinstein, Luís Henrique Maciel Kosmalski Costa, Marcelo Dias de Amorim, Pedro B. Velloso, Otto Carlos M. B. Duarte, Guy Pujolle
Comput. Networks9
2013 Safeguarding ad hoc networks with a self-organized membership control system
Natalia Castro Fernandes, Marcelo Duffles Donato Moreira, Otto Carlos M. B. Duarte
Comput. Networks3
2013 An Efficient and Robust Addressing Protocol for Node Autoconfiguration in Ad Hoc Networks
abstract
Address assignment is a key challenge in ad hoc networks due to the lack of infrastructure. Autonomous addressing protocols require a distributed and self-managed mechanism to avoid address collisions in a dynamic network with fading channels, frequent partitions, and joining/leaving nodes. We propose and analyze a lightweight protocol that configures mobile ad hoc nodes based on a distributed address database stored in filters that reduces the control load and makes the proposal robust to packet losses and network partitions. We evaluate the performance of our protocol, considering joining nodes, partition merging events, and network initialization. Simulation results show that our protocol resolves all the address collisions and also reduces the control traffic when compared to previously proposed protocols.
Natalia Castro Fernandes, Marcelo Duffles Donato Moreira, Otto Carlos M. B. Duarte
IEEE/ACM Trans. Netw.3
2012 A routing protocol suitable for backhaul access in wireless mesh networks
Miguel Elias M. Campista, Luís Henrique Maciel Kosmalski Costa, Otto Carlos M. B. Duarte
Comput. Networks3
2012 Capacity and Robustness Tradeoffs in Bloom Filters for Distributed Applications
abstract
The Bloom filter is a space-efficient data structure often employed in distributed applications to save bandwidth during data exchange. These savings, however, come at the cost of errors in the shared data, which are usually assumed low enough to not disrupt the application. We argue that this assumption does not hold in a more hostile environment, such as the Internet, where attackers can send a carefully crafted Bloom filter in order to break the application. In this paper, we propose the concatenated Bloom filter (CBF), a robust Bloom filter that prevents the attacker from interfering on the shared information, protecting the application data while still providing space efficiency. Instead of using a single large filter, the CBF concatenates small subfilters to improve both the filter robustness and capacity. We propose three CBF variants and provide analytical results that show the efficacy of the CBF for different scenarios. We also evaluate the performance of our filter in an IP traceback application and simulation results confirm the effectiveness of the proposed mechanism in the face of attackers.
Marcelo Duffles Donato Moreira, Rafael P. Laufer, Pedro B. Velloso, Otto Carlos M. B. Duarte
IEEE Trans. Parallel Distributed Syst.4
2011 XNetMon: A Network Monitor for Securing Virtual Networks
abstract
Isolation and performance are critical issues for virtual networking. In this paper, we consider the use of Xen virtualization platform for building software-based virtual routers. We propose a network monitor for Xen to increase the isolation and the performance on packet forwarding. The network monitor controls the use of shared resources and punishes misbehaving virtual routers, guaranteeing an isolated operation of the virtual networks. The results obtained with the developed prototype show that our proposal guarantees availability of the virtual-network control and packet forwarding services and also provides a fair resource sharing.
Natalia Castro Fernandes, Otto Carlos M. B. Duarte
ICC2
2011 A Stateless Traceback Technique for Identifying the Origin of Attacks from a Single Packet
abstract
Anonymity is one of the main motivations for conducting denial-of-service attacks. Currently, there is no mechanism to either identify the true source of an IP packet or to prove its authenticity. In this paper we propose a stateless IP traceback technique that identifies the origin network of each individual packet. We show that the proposed traceback system is the only one that scales with the number of attackers and also satisfies practical requirements, such as no state stored at routers and a header overhead (25 bits) that can be allocated in IPv4 header. The proposed system exploits the customer-provider hierarchy of the Internet at autonomous system (AS) level and introduces the idea of checkpoints, which are the two most important nodes in an AS-level path. Simulation results using a real-world topology trace show that the proposed system narrows the source of an attack packet down to less than two candidate ASes on average. In addition, considering a partial deployment scenario, we show that the proposed system is able to successfully trace more than 90% of the attacks if only 8% of the ASes (i.e., just the core ASes) implement the system. The achieved success rate is quite better than using the classical hop-by-hop path reconstruction.
Marcelo Duffles Donato Moreira, Rafael P. Laufer, Natalia Castro Fernandes, Otto Carlos M. B. Duarte
ICC4
2011 An experimental analysis of routing inconsistency in indoor wireless mesh networks
abstract
As of today, many routing protocols for wireless mesh networks have been proposed. Nevertheless, quite a few take the high loss rate of control packets into account. This work analyzes the problem of consistent routing information among wireless network nodes. To accomplish this, we propose a metric to evaluate the level of inconsistency among routing tables. Our experimental analysis demonstrates that the high loss rates seen in indoor environments negatively influence route computation. In addition, we demonstrate that the high network dynamics leads to severe instability in next hop selection. Results show that the effect of loss is significant and that the simple manipulation of routing protocol configuration parameters may be not enough to cope with the problem.
Rodrigo De Souza Couto, Miguel Elias M. Campista, Luís Henrique Maciel Kosmalski Costa, Otto Carlos M. B. Duarte
ISCC4
2011 A lightweight group-key management protocol for secure ad-hoc-network routing
Natalia Castro Fernandes, Otto Carlos M. B. Duarte
Comput. Networks2
2011 A Generalized Bloom Filter to Secure Distributed Network Applications
Rafael P. Laufer, Pedro B. Velloso, Otto Carlos M. B. Duarte
Comput. Networks3
2010 A Lifetime-Based Peer Selection Mechanism for Peer-to-Peer Video-on-Demand Systems
abstract
In this paper, we propose a peer selection mechanism for peer-to-peer video-on-demand (P2P-VoD) systems. The goal of our mechanism is to increase the availability of chunks between a peer and its partners. For this purpose, the process of selecting partners is based on the lifetime of peers, which is time since the beginning of the video playback. Thus, a peer selects as partners other peers with close lifetimes to increase the probability of finding chunks of interest in these selected partners. Results show that the proposed mechanism is efficient for different interactivity patterns. With the proposed mechanism, more than 97% of the video chunks required by a peer are available on its selected partners. This result is achieved even considering that only 10% of the video chunks can be cached by partners. In opposition, the conventional random selection mechanism requires much more disk space, which corresponds to a cache size of at least 70% of chunks, to provide the same level of availability.
Igor M. Moraes, Otto Carlos M. B. Duarte
ICC2
2010 A Self-Organized Mechanism for Thwarting Malicious Access in Ad Hoc Networks
abstract
This paper introduces a self-organized mechanism to control user access in ad hoc networks without requiring any infrastructure or a central administration entity. The proposed mechanism authenticates and monitors nodes with the so-called controller sets, which are resistant to the dynamic network membership. The analysis shows that the proposed scheme is robust even to collusion attacks and provides availability up to 90% better than proposals based on threshold cryptography. The performance improvement arises mostly from the controller sets autonomy to recover after network partitions.
Natalia Castro Fernandes, Marcelo Duffles Donato Moreira, Otto Carlos M. B. Duarte
INFOCOM3
2010 Trust management in mobile ad hoc networks using a scalable maturity-based model
abstract
In this paper, we propose a human-based model which builds a trust relationship between nodes in an ad hoc network. The trust is based on previous individual experiences and on the recommendations of others. We present the Recommendation Exchange Protocol (REP) which allows nodes to exchange recommendations about their neighbors. Our proposal does not require disseminating the trust information over the entire network. Instead, nodes only need to keep and exchange trust information about nodes within the radio range. Without the need for a global trust knowledge, our proposal scales well for large networks while still reducing the number of exchanged messages and therefore the energy consumption. In addition, we mitigate the effect of colluding attacks composed of liars in the network. A key concept we introduce is the relationship maturity, which allows nodes to improve the efficiency of the proposed model for mobile scenarios. We show the correctness of our model in a single-hop network through simulations. We also extend the analysis to mobile multihop networks, showing the benefits of the maturity relationship concept. We evaluate the impact of malicious nodes that send false recommendations to degrade the efficiency of the trust model. At last, we analyze the performance of the REP protocol and show its scalability. We show that our implementation of REP can significantly reduce the number messages.
Pedro B. Velloso, Rafael P. Laufer, Daniel de Oliveira Cunha, Otto Carlos M. B. Duarte, Guy Pujolle
IEEE Trans. Netw. Serv. Manag.4
2009 An Efficient Filter-based Addressing Protocol for Autoconfiguration of Mobile Ad Hoc Networks
abstract
Address autoconfiguration is an important issue for ad hoc networks in order to provide autonomous networking and self-management. The IP address assignment for ad hoc nodes requires a distributed procedure that resolves all the address collisions in a dynamic network with fading channels, frequent partitions, and joining/leaving nodes. We propose a filter-based addressing protocol for autoconfiguration of mobile ad hoc networks that is lightweight and robust to packet losses. We present a probabilistic analysis of address collisions and discuss filters functionalities in the address autoconfiguration. We evaluate the performance of our protocol for static and mobile scenarios, considering joining nodes and partition mergings. Simulation results show that our protocol resolves all the address collisions and reduces up to 22 times the control traffic when compared to the other addressing protocols.
Natalia Castro Fernandes, Marcelo Duffles Donato Moreira, Otto Carlos M. B. Duarte
INFOCOM3
2008 WPR: A Proactive Routing Protocol Tailored to Wireless Mesh Networks
abstract
This work proposes the wireless-mesh-network proactive routing (WPR) protocol for wireless mesh networks. Unlike current routing protocols, such as the optimized link- state routing (OLSR), WPR uses a controlled-flooding algorithm tailored to the typical wireless-mesh-network traffic matrix, which concentrates traffic on links close to the gateway. The goal is to improve efficiency by saving network resources and avoiding network bottlenecks. WPR also avoids redundant messages using the AMPR (adapted multipoint relay) set. In this paper, we provide a complexity analysis of the algorithms used by WPR and OLSR. Besides, simulation results show that WPR outperforms OLSR in throughput and packet delivery rate.
Miguel Elias M. Campista, Luís Henrique Maciel Kosmalski Costa, Otto Carlos M. B. Duarte
GLOBECOM3
2008 An Efficient Group Key Management for Secure Routing in Ad Hoc Networks
abstract
This paper proposes and specifies a protocol for distributing and managing group keys in ad hoc environments, which applies for the Secure Optimized Link State Routing Protocol. Our protocol manages group keys taking into consideration the frequent network partitions and the absence of infrastructure. The analysis shows that the protocol is energy efficient for high key replacement rates and frequent network partitions. The proposal reduced up to 512 times the control traffic load and 356 times the energy spent with cryptographic operations when compared to contributory algorithms. The proposed protocol is robust even in the presence of non-cooperative nodes and provides an efficient key management in a timely manner.
Natalia Castro Fernandes, Otto Carlos M. B. Duarte
GLOBECOM2
2008 Multilink Performance of the Load-Level-Based Admission Control Mechanism for OBS Networks
abstract
In this paper, we analyze the performance of the load-level-based admission control mechanism (LLAC) for optical burst-switched networks in a multilink scenario. The goal of this mechanism is to differentiate the blocking probability of a given service class according to the network load and a class-associated parameter, called load level. For the proposed mechanism, we develop a multilink analytical model based on the reduced load approximation method, which provides a more accurate blocking probability estimation than a single-link model. With the multilink model, the performance of the load-level- based mechanism is even better than using a single-link model. For the analyzed scenarios, high-priority bursts experiences a blocking probability up to 60% lower than the one provided by the single-link model. The results also show that the load- level-based mechanism effectively differentiates the services in all analyzed scenarios, when compared to other similar mechanisms.
Igor M. Moraes, Otto Carlos M. B. Duarte
ICC2
2008 A Trust Model Robust to Slander Attacks in Ad Hoc Networks
abstract
Slander attacks represent a significant danger to distributed reputation systems. Malicious nodes may collude to lie about the reputation of a particular neighbor and cause serious damage to the overall trust evaluation system. This paper presents and analyzes a trust model robust to slander attacks in ad hoc networks. We provide nodes with a mechanism to build a trust relationship with its neighbors. The proposed model considers the recommendation of trustworthy neighbors and the previous experiences of the node itself. The interactions are limited to direct neighbors in order to scale on mobile networks. The results show the impact of slander attacks to our trust model. We analyze how the main parameters affect the trust evaluation process under a lying collusion attack. We show that our trust model tolerate almost 40% of liars.
Pedro B. Velloso, Rafael P. Laufer, Otto Carlos M. B. Duarte, Guy Pujolle
ICCCN3
2008 Analyzing a human-based trust model for mobile ad hoc networks
abstract
This paper analyzes a trust model for mobile ad hoc networks. We provide nodes with a mechanism to build a trust relationship with its neighbors. The proposed model considers the recommendation of trustworthy neighbors and the experience of the node itself. The interactions are limited to direct neighbors in order to scale on mobile networks. The results show the efficiency and the trade-off of our model in the presence of mobility. We also analyze the advantages of considering the relationship maturity, i.e. for how long nodes know each other, to evaluate the trust level. The maturity parameter can decrease the trust level error up to 50%.
Pedro B. Velloso, Rafael P. Laufer, Otto Carlos M. B. Duarte, Guy Pujolle
ISCC3
2008 An Enhanced Routing Metric for Fading Wireless Channels
abstract
In this paper we propose the enhancement of routing metrics through a more complete view of the physical channel. Using cross-layer optimizations, we develop the distribution based expected transmission count (DBETX), which improves the performance of the network in the presence of varying channels. Through observations of the wireless link, nodes estimate how the wireless link behaves. The proposed metric exploits this estimation to increase routing efficiency. The proposed metric is shown to outperform the conventional ETX metric in the presence of fading. The improvement over ETX increases with the network density because connectivity increases and more routing options become available. Results show a reduction of up to 26% in the Average Number of Transmissions per link and an increase of up to 32% in the end-to-end availability.
Daniel de Oliveira Cunha, Otto Carlos M. B. Duarte, Guy Pujolle
WCNC2
2007 Towards Stateless Single-Packet IP Traceback
abstract
The current Internet architecture allows malicious nodes to disguise their origin during denial-of-service attacks with IP spoofing. A well-known solution to identify these nodes is IP traceback. In this paper, we introduce and analyze a lightweight single-packet IP traceback system that does not store any data in the network core. The proposed system relies on a novel data structure called Generalized Bloom Filter, which is tamper resistant. In addition, an efficient improved path reconstruction procedure is introduced and evaluated. Analytical and simulation results are presented to show the effectiveness of the proposed scheme. The simulations are performed in an Internet-based scenario and the results show that the proposed system locates the real attack path with high accuracy.
Rafael P. Laufer, Pedro B. Velloso, Daniel de Oliveira Cunha, Igor M. Moraes, Marco D. D. Bicudo, Marcelo Duffles Donato Moreira, Otto Carlos M. B. Duarte
LCN7
2006 Improving the multiple access method of CSMA/CA home networks
abstract
A home network is a communication system that aims to interconnect household appliances and share the access to the Internet. This work proposes a novel mechanism which is able to improve the multiple access method of home networks. The Contention window Proactive Increase (CPI) mechanism avoids collisions by increasing the number of times the backoff procedure is called. We applied the CPI mechanism to the IEEE 802.11 and HomePlug standards given their similar access methods. We show the efficiency of the proposed mechanism evaluating through simulations the network throughput gains compared to the original standards. 1.
Miguel Elias M. Campista, Luís Henrique Maciel Kosmalski Costa, Otto Carlos M. B. Duarte
CCNC3
2006 Incremental service deployment using the hop-by-hop multicast routing protocol
Luís Henrique Maciel Kosmalski Costa, Serge Fdida, Otto Carlos M. B. Duarte
IEEE/ACM Trans. Netw.3
2005 Improving the Data Transmission Throughput over the Home Electrical Wiring
abstract
Powerline communications (PLC) are receiving special attention since they use an already available and ubiquitous infrastructure. The main standard for PLC home networks is HomePlug. This work improves the throughput of HomePlug by modifying the medium access control sub-layer. The key idea is to define a fast collision avoidance mechanism where every station that wants to access the medium increments its contention window after sensing another ongoing transmission. The proposal reduces the number of collisions in the network improving the achievable throughput. We compared our mechanism to the original HomePlug standard through simulation and mathematical analysis. We verified that the improvement is independent from the packet size, the transmission rate and the number of nodes when the network is high loaded
Miguel Elias M. Campista, Luís Henrique Maciel Kosmalski Costa, Otto Carlos M. B. Duarte
LCN3
2005 Improving the accuracy of measurement-based geographic location of Internet hosts
Artur Ziviani, Serge Fdida, José Ferreira de Rezende, Otto Carlos M. B. Duarte
Comput. Networks4
2005 Joint Adoption of QoS Schemes for MPEG Streams
Artur Ziviani, Bernd E. Wolfinger, José Ferreira de Rezende, Otto Carlos M. B. Duarte, Serge Fdida
Multim. Tools Appl.4
2004 Increasing the Throughput of the HomePNA MAC Protocol
abstract
The paper proposes a new mechanism to increase the HomePNA 2.0 MAC protocol throughput. First, we review the HomePNA (Home Phone-line Network Alliance) MAC protocol and its collision resolution mechanism. Then, we use simulations to evaluate the throughput of HomePNA using a module that we implemented in the ns-2 simulator We propose a priority aggregation mechanism that uses the eight HomePNA priority levels in a more efficient way. The simulation results show that the proposed mechanism is able to increase the throughput up to 44%. Moreover, our mechanism does not require modifying the HomePNA specification, and can be easily implemented as a new sublayer above the MAC sublayer.
Aurelio Amodei Jr., Luís Henrique Maciel Kosmalski Costa, Otto Carlos M. B. Duarte
LCN3
2004 Maximum Throughput Analysis in Ad Hoc Networks
Bernardo A. M. Villela, Otto Carlos M. B. Duarte
NETWORKING2
2004 A self-extracting accurate modeling for bounded-delay video services
Marcelo Dias de Amorim, Otto Carlos M. B. Duarte
Comput. Commun.2
2003 Demographic placement for Internet host location
abstract
The deployment of a geographic location service for Internet hosts enables a whole new class of location-aware applications. We focus on a technique that infers host locations using delay measurements to geographically distributed landmarks, which are hosts with a known geographic location. The problem we deal with is where to place such landmarks and the probe machines that perform the delay measurements. We propose a demographic placement approach to improve the representativeness of each landmark with respect to the hosts to be located. Results show that a relatively small number of landmarks is sufficient to cover the most part of hosts to be located. For a fixed number of landmarks, the demographic approach reduces the distances from most hosts to the nearest landmark. Considering the probe machines, we show that they have to be sparsely placed to avoid gathering redundant data.
Artur Ziviani, Serge Fdida, José Ferreira de Rezende, Otto Carlos M. B. Duarte
GLOBECOM4
2003 Reducing the Reservation Establisment Time in IP Tunnels by Using Staged Refresh Timers
abstract
This paper presents a state aggregation mechanism of the RSVP protocol for multicast flows using IP-in-IP tunneling. The mechanism relies on periodic refresh messages between routers to maintain the reservation states (soft-state approach). Because of the loss of tunnel RSVP messages, the mechanism presents a very long latency at reservation establishment. The problem reduces the performance of multimedia applications. We report the use of staged refresh timers in the aggregation mechanism at the set-up procedure of the resource reservation. The simulation results show a significant decrease of the establishment time of multicast sessions.
Paulo Cesar S. Vidal, Otto Carlos M. B. Duarte
NCA2
2003 Distinguishing video quality through differential matrices
Marcelo Dias de Amorim, Otto Carlos M. B. Duarte, Guy Pujolle
Multim. Syst.2
2003 Evaluating the Impact of the Communication System on Distributed Virtual Environments
Renata Cruz Teixeira, Otto Carlos M. B. Duarte
Multim. Tools Appl.2
2002 Optimal Feedback for Quality Source-Adaptive Schemes in Multicast Multi-layered Video Environments
Paulo André da Silva Gonçalves, José Ferreira de Rezende, Otto Carlos M. B. Duarte, Guy Pujolle
NETWORKING3
2002 Evaluating the Performance of a Network Management Application Based on Mobile Agents
Marcelo G. Rubinstein, Otto Carlos M. B. Duarte, Guy Pujolle
NETWORKING2
2002 Developing scalable protocols for three-metric QoS routing
Luís Henrique Maciel Kosmalski Costa, Serge Fdida, Otto Carlos M. B. Duarte
Comput. Networks3
2001 Application-aware multicast
abstract
Measuring the quality of multicast multi-layered applications based only on the amount of data that arrives at the receivers is insufficient in many circumstances. This paper proposes a three-metric approach that improves the global quality/fairness of the multicast sessions. We define a simple function that takes into account the density of satisfied users, the amount of allocated bandwidth in the multicast tree, and the degradation at the receivers. We analyze the proposed multicriteria algorithm in an environment with other competing flows and show the improvement of the global quality of multicast multi-layered applications.
Marcelo Dias de Amorim, Otto Carlos M. B. Duarte, Guy Pujolle
GLOBECOM2
2001 A scalable algorithm for link-state QoS-based routing with three metrics
abstract
Quality of service (QoS) based routing provides QoS guarantees to multimedia applications and an efficient utilization of the network resources. Nevertheless, QoS routing is likely to be a costly process that does not scale when the number of nodes increases. Thus, the routing algorithm must be simple. This paper proposes and analyses the performance of a link-state QoS routing algorithm that takes into account three metrics: propagation delay, available bandwidth, and loss probability. A heuristic based on the residual loss probability and metric-combination is used to turn the algorithm scalable and solvable in polynomial time. The simulation results show that our algorithm is a promising solution to construct paths constrained on three metrics.
Luís Henrique Maciel Kosmalski Costa, Serge Fdida, Otto Carlos M. B. Duarte
ICC3
2001 Enabling the Progressive Multicast Service Deployment
abstract
The IP multicast architecture was not widely deployed because multicast address allocation is difficult and there is no scalable solution to inter-domain multicast routing. Hence, there is an interest in developing protocols that allow the progressive deployment of the multicast service by supporting unicast clouds. This paper proposes HBH (hop-by-hop multicast routing protocol). HBH adopts the source-specific channel abstraction to simplify address allocation and implements multicast distribution using recursive unicast trees. In this model, data packets have unicast destination addresses. Therefore, HBH supports pure unicast routers transparently. The branching-nodes recursively create packet copies to implement the distribution. HBH constructs a shortest-path tree even in the presence of asymmetric unicast routing. Consequently, HBH provides best routes in asymmetric networks, and is suitable for an eventual implementation of QoS-based routing. Additionally HBH reduces tree bandwidth consumption in asymmetric networks when compared to other approaches. The results obtained from simulation support our statements.
Luís Henrique Maciel Kosmalski Costa, Serge Fdida, Otto Carlos M. B. Duarte
ISCC3
2001 Hop by hop multicast routing protocol
abstract
IP Multicast is facing a slow take-off although it is a hotly debated topic since more than a decade. Many reasons are responsible for this status. Hence, the Internet is likely to be organized with both unicast and multicast enabled networks. Thus, it is of utmost importance to design protocols that allow the progressive deployment of the multicast service by supporting unicast clouds. This paper proposes HBH (Hop-By-Hop multicast routing protocol). HBH adopts the source-specific channel abstraction to simplify address allocation and implements data distribution using recursive unicast trees, which allow the transparent support of unicast-only routers. Additionally, HBH is original because its tree construction algorithm takes into account the unicast routing asymmetries. As most multicast routing protocols rely on the unicast infrastructure, these asymmetries impact the structure of the multicast trees. We show through simulation that HBH outperforms other multicast routing protocols in terms of the delay experienced by the receivers and the bandwidth consumption of the multicast trees.
Luís Henrique Maciel Kosmalski Costa, Serge Fdida, Otto Carlos M. B. Duarte
SIGCOMM3
2001 Improving scalability on reliable multicast communications
Daniel A. M. Villela, Otto Carlos M. B. Duarte
Comput. Commun.2
2000 An Improved MPEG Behavioral Analysis with Autonomous Parameter-Extracting Algorithm for Strict Video Applications
abstract
Through a detailed analysis of theoretical and real MPEG-compressed video streams, this paper addresses the task of extracting deterministic parameters from such sources in order to provide deterministic service guarantees. We propose and analyze the single-input single-output (SISO) algorithm with quality adjustment to compute the coherent parameters for the XGOP-B deterministic traffic model. Contrary to other proposals, the SISO algorithm leads to a single set of parameters for each input traffic and does not ask for external decisions to perform this stage. Moreover, the accuracy/complexity can be adjusted by a special variable. Our results show that the proposed approach leads to improved accuracy and that the complexity can be decreased by three orders of magnitude.
Marcelo Dias de Amorim, Guy Pujolle, Otto Carlos M. B. Duarte
ICC (2)3
2000 Multi-criteria Arguments for Improving the Fairness of Layered Multicast Applications
Marcelo Dias de Amorim, Otto Carlos M. B. Duarte, Guy Pujolle
NETWORKING2
2000 Distance-Vector QoS-Based Routing with Three Metrics
Luís Henrique Maciel Kosmalski Costa, Serge Fdida, Otto Carlos M. B. Duarte
NETWORKING3
1999 Guest Editorial
Ana Carolina Salgado, Otto Carlos M. B. Duarte
Multim. Tools Appl.2
1998 Point-to-Multipoint SR ARQ Scheme with Accumulative Acknowledgment for Satellite Communications
Heliomar Medeiros de Lima, Otto Carlos M. B. Duarte
Comput. Networks2
1996 Comments on "Evaluation of the mean error-free interval of a noisy data channel"
abstract
This letter corrects a few results reported in the paper by Georganas et al. (see ibid., vol.26, p.185-7, 1978). It shows that, for very long data strings, the mean error-free interval (MEFI) as a function of the packet error rate P is not discontinuous. In addition, the corrected results are extended to point-to-multipoint environment.
Heliomar Medeiros de Lima, Otto Carlos M. B. Duarte
IEEE Trans. Commun.2
1994 Performance Measurements in a Manufacturing Communication System
abstract
This paper presents and analyses a high performance manufacturing communication system. It consists in the standard TOP profile implemented in single processor computer connected to a LAN. High throughput is achieved by an efficient implementation architecture based on specific layer interfaces and data structures, specialized mechanisms of memory management, timer management and task scheduling. Performance measurement results show a throughput efficiency that attains 6 Mbit/s for a remote communication and 42 Mbit/s for loopback configuration. The most important bottlenecks are analysed and consist in the transport checksum, transport acknowledgment step frequency, LLC memory copy, memory management and task scheduling.>
Célio Vinicius N. de Albuquerque, Marcelo D. Nunes, Otto Carlos M. B. Duarte
ISCAS3
1994 An Improved Point-to-Multipoint GB(N) ARQ Scheme for High Speed Satellite Communications
abstract
This paper proposes and evaluates a point-to-multipoint GB(N) scheme with memory at receivers, suitable for high speed satellite communications. Its key idea is to store errorless messages received during an error recovery procedure. It avoids buffer overflow, reduces the round trip delay effect, is easy to implement and presents a good performance under a wide range of conditions. It is shown that the proposed protocol throughput efficiency is better than the best known multipoint GB(N) scheme results. In addition, in environments with a large number of receivers, it outperforms a known multipoint selective repeat protocol, under a wide range of bit error rate.>
Heliomar Medeiros de Lima, Otto Carlos M. B. Duarte
ISCAS2