João S. Resende

dblp:183/9115 · DBLP profile ↗
← Back
11ranked-venue papers
2as first author
8since 2021 · last 2026
0000-0003-0125-4240ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 2 first-author · 6 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 RunPBA - Runtime attestation for microcontrollers with PACBTI
abstract
The widespread adoption of embedded systems has led to their deployment in critical real-world applications, making them attractive targets for malicious actors. This paper presents RunPBA , a hardware-based runtime attestation system designed to defend against control flow attacks while maintaining minimal performance overhead and adhering to strict power consumption constraints. RunPBA leverages Pointer Authentication and Branch Target Identification (PACBTI), a new processor extension tailored for the ARM Cortex M processor family, allowing robust protection without requiring hardware modifications, a limitation present in similar solutions. We implemented a proof-of-concept and evaluated it using two benchmark suites, Coremark PRO and BEEBS. Experimental results indicate that RunPBA imposes a geometric mean performance overhead of only 1.3% and 6.8% across the benchmarks, underscoring its efficiency and suitability for real-world deployment.
André Cirne, Patrícia R. Sousa, João S. Resende, Luis Filipe Coelho Antunes
Comput. Secur.3
2026 Obscura: Enabling Ephemeral Proxies for Traffic Encapsulation in WebRTC Media Streams Against Cost-Effective Censors
abstract
Recent research on online censorship has provided valuable insights into common censorship strategies and censors' tolerance for collateral damage. A consistent finding across these studies is that censors tend to favour cost-effective techniques such as proxy enumeration, active probing, and deep packet inspection (DPI), rather than more complex and non-deterministic methods such as deep learning-based traffic analysis. For example, a recent study on the Snowflake censorship evasion system reinforced this finding by demonstrating that authoritarian regimes primarily relied on DPI to target the system. However, as censorship techniques continue to evolve, two critical questions arise: (1) What future attack vectors are likely to emerge based on current research and observed censor capabilities? (2) How can these emerging threats, along with previously utilised censorship methods, be effectively mitigated? In this paper, we present Obscura, a censorship evasion system designed to resist cost-effective, historically grounded censorship techniques while also defending against a class of plausible future attacks within a cost-effective threat model targeting WebRTC-based censorship evasion systems. Obscura is built upon four core features: (1) encapsulation of traffic within WebRTC media streams, (2) the use of a reliability layer, (3) support for both browser-based and Pion-based clients and proxy instances, and (4) the use of ephemeral proxies. Each feature is intended to mitigate either a known attack observed in the wild or a theoretically plausible attack consistent with the capabilities of a cost-effective censor. We provide a security analysis to justify our design choices and a performance evaluation to demonstrate that Obscura maintains reasonable throughput for typical online activities.
João Afonso Vilalonga, Kevin Gallagher 0001, João S. Resende, Henrique Domingos
Proc. Priv. Enhancing Technol.3
2023 Online Influence Forest for Streaming Anomaly Detection
Inês Martins, João S. Resende, João Gama 0001
IDA2
2023 TorKameleon: Improving Tor's Censorship Resistance with K-anonymization and Media-based Covert Channels
abstract
Anonymity networks like Tor significantly enhance online privacy but are vulnerable to correlation attacks by state-level adversaries. While covert channels encapsulated in media protocols, particularly WebRTC-based encapsulation, have demonstrated effectiveness against passive traffic correlation attacks, their resilience against active correlation attacks remains unexplored, and their compatibility with Tor has been limited. This paper introduces TorKameleon, a censorship evasion solution designed to protect Tor users from both passive and active correlation attacks. TorKameleon employs K-anonymization techniques to fragment and reroute traffic through multiple TorKameleon proxies, while also utilizing covert WebRTC-based channels or TLS tunnels to encapsulate user traffic.
João Afonso Vilalonga, João S. Resende, Henrique Domingos
TrustCom2
2022 Threat Detection and Mitigation with Honeypots: A Modular Approach for IoT
Simão Silva, Patrícia R. Sousa, João S. Resende, Luis Filipe Coelho Antunes
TrustBus3
2022 IoT security certifications: Challenges and potential approaches
André Cirne, Patrícia R. Sousa, João S. Resende, Luis Filipe Coelho Antunes
Comput. Secur.3
2022 Host-based IDS: A review and open issues of an anomaly detection system in IoT
Inês Martins, João S. Resende, Patrícia R. Sousa, Simão Silva, Luis Filipe Coelho Antunes, João Gama 0001
Future Gener. Comput. Syst.2
2021 Hardening cryptographic operations through the use of secure enclaves
André Brandão, João S. Resende, Rolando Martins
Comput. Secur.2
2020 Employment of Secure Enclaves in Cheat Detection Hardening
André Brandão, João S. Resende, Rolando Martins
TrustBus2
2018 Enforcing Privacy and Security in Public Cloud Storage
abstract
Cloud storage allows users to remotely store their data, giving access anywhere and to anyone with an Internet connection. The accessibility, lack of local data maintenance and absence of local storage hardware are the main advantages of this type of storage. The adoption of this type of storage is being driven by its accessibility. However, one of the main barriers to its widespread adoption is the sovereignty issues originated by lack of trust in storing private and sensitive information in such a medium. Recent attacks to cloud-based storage show that current solutions do not provide adequate levels of security and subsequently fail to protect users' privacy. Usually, users rely solely on the security supplied by the storage providers, which in the presence of a security breach will ultimate lead to data leakage. In this paper, we propose and implement a broker (ARGUS) that acts as a proxy to the existing public cloud infrastructures by performing all the necessary authentication, cryptography and erasure coding. ARGUS uses erasure code as a way to provide efficient redundancy (opposite to standard replication) while adding an extra layer to data protection in which data is broken into fragments, expanded and encoded with redundant data pieces that are stored across a set of different storage providers (public or private). The key characteristics of ARGUS are confidentiality, integrity and availability of data stored in public cloud systems.
João S. Resende, Rolando Martins, Luis Filipe Coelho Antunes
PST1
2018 Evaluating the Privacy Properties of Secure VoIP Metadata
João S. Resende, Patrícia R. Sousa, Luis Filipe Coelho Antunes
TrustBus1