Andressa Vergütz

dblp:211/9211 · also Andressa Vergutz · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
4since 2021 · last 2023
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8 · 2 first-author · 4 since 2021
YearPublicationVenuePosition
2023 A method for vulnerability detection by IoT network traffic analytics
Uelinton Q. Brezolin, Andressa Vergütz, Michele Nogueira Lima
Ad Hoc Networks2
2023 A dynamic method to protect user privacy against traffic-based attacks on smart home
Bruna V. Dos Santos, Andressa Vergütz, Ricardo T. Macedo, Michele Nogueira Lima
Ad Hoc Networks2
2023 Data Instrumentation From IoT Network Traffic as Support for Security Management
abstract
The Internet of Things revolutionizes human life by inaugurating scenarios such as smart homes. However, IoT devices contain much sensitive information about users and devices from a security and privacy perspective. Through traffic-based attacks, adversaries map changes in traffic rates to a particular in-home user’s actions. An efficient IoT data instrumentation may protect users against traffic-based attacks by giving valuable information to adaptive network security solutions. Nonetheless, no work performs data instrumentation or uses feature exploration to reveal relevant features to assist network security management. Thus, this article introduces IoTReGuard, an IoT Method to Reveal and Guard IoT Network Traffic Features. IoTReguard aims to explore network traffic features to reveal the most relevant ones and hide them to protect users’ privacy. By IoT network feature exploration and data instrumentation, IoTReGuard provides valuable information on network traffic features to mask critical features. Results showed that IoTReGuard reduced from 70% to 20% of F1-Score on identifying the IoT devices, improving user privacy.
Andressa Vergütz, Bruna V. Dos Santos, Burak Kantarci, Michele Nogueira Lima
IEEE Trans. Netw. Serv. Manag.1
2022 Learning From Network Data Changes for Unsupervised Botnet Detection
abstract
The networks of infected devices (a.k.a., botnets) threaten network security due to their dynamic nature and support to different attacks (e.g., Distributed Denial of Services and personal data theft). Detecting botnets is a challenging task because the infected devices (bots) are numerous, widely and geographically spread. Significant attention has been given to improve the efficiency, robustness and adaptability of network security approaches. However, in the literature, botnet detection techniques usually ignore fast changes in statistical data distribution, performing over static windows, i.e., fixed intervals of time or fixed quantity of flows. Changes in statistical data distribution are known as concept drifts and they make the classification models obsolete. Furthermore, those works employing approaches aware of concept drift use supervised machine learning, which is slow, costly, and prone to error. Therefore, this article presents TRUSTED, a system for online and unsupervised botnet detection aware of concept drifts. Unlike other works, the TRUSTED system improves the learning process for botnet detection, applying concept drift in an online and unsupervised classification. Evaluations comprise offline and online scenarios. Results show that the TRUSTED system detects botnets using concept drift identification, reaching 87% to 95% accuracy, precision, recall, and F1-scores.
Bruno Henrique Schwengber, Andressa Vergütz, Nelson G. Prates, Michele Nogueira Lima
IEEE Trans. Netw. Serv. Manag.2
2020 A Defense Mechanism for Timing-based Side-Channel Attacks on IoT Traffic
abstract
This work proposes FISHER: a deFense mechanIsm against timing-based Side-channel attack related to response time on the intERnet of things (IoT). IoT connects objects that support important applications, such as electronic health, smart homes, and Industry 4.0. However, timing-based side-channel attacks on IoT network traffic compromise user privacy. Related works present a limited view of side-channel leakages and as a solution, these works try to mask them. However, they ignore that devices have unique behaviors that intensify the problem of privacy leaks through response time. Hence, FISHER follows two modules: (i) vulnerability test and (ii) privacy protection. The vulnerability test module identifies timing-based side-channel leakages and reveals new vulnerabilities associated with the response time. The privacy protection module implements two methods that mask the identified time-based leakages on the network traffic. Results from an experimental scenario show that FISHER identifies precisely the side-channel leakages related to response time and efficiently masks them.
Nelson G. Prates, Andressa Vergütz, Ricardo T. Macedo, Aldri Luiz dos Santos, Michele Nogueira Lima
GLOBECOM2
2020 A Method Aware of Concept Drift for Online Botnet Detection
abstract
Botnets deeply threaten cybersecurity due to their distributed and dynamic nature, causing attacks with severe consequences for users and companies, such as Distributed Denial of Service. Detecting botnets is challenging once they constantly evolve, resulting in fast behavior changes in network. Current techniques usually detect botnets without considering these changes and their fast adaptation to new behavior. Hence, this paper presents CONFRONT, a method aware of concept drift (fast changes in network behavior) for online botnet detection. Different from the literature, this paper introduces a new technique to detect concept drift and optimize botnet classification. CONFRONT employs features from network flow on the unsupervised concept drift detector and a supervised incremental botnet classifier. Results show CONFRONT feasibility, reaching 95% of accuracy in less than 1 ms.
Bruno Henrique Schwengber, Andressa Vergütz, Nelson G. Prates, Michele Nogueira Lima
GLOBECOM2
2019 A Method for Identifying eHealth Applications Using Side-Channel Information
abstract
eHealth applications become popular with the increasing incidence of cancer and postoperative rehabilitation, that require continuous remote monitoring of patients. Given the huge diversity of eHealth applications, their proper and non- invasive identification assist in attaining important requirements as low latency and reliability. But, their identification is not trivial once they have similar characteristics to common applications. Also, the time taken to identify an eHealth application is crucial, however usually it is not addressed as relevant. This paper presents MOTIF, a method for identifying eHealth applications from side-channel information extracted from network traffic. It is non-invasive and does not inspect packet payload, employing machine learning algorithms for the particularities of healthcare scenarios. Results show MOTIF feasibility and point out an accuracy higher than 90% in less than 30 seconds.
Andressa Vergütz, Iago Medeiros, Denis do Rosário, Eduardo Cerqueira, Aldri Luiz dos Santos, Michele Nogueira Lima
GLOBECOM1
2018 A Self-Adaptable System for DDoS Attack Prediction Based on the Metastability Theory
abstract
Distributed Denial of Service (DDoS) attacks grow in volume, sophistication and impact. An example is the largest DDoS attack ever recorded against the developer platform GitHub, that reached 1.35 terabytes per second - an unprecedented volume of malicious traffic. DDoS attacks have been detected or mitigated only when they are in unrecoverable stages, being late to prevent their effects. Thus, differently from other works, we advocate for the early prediction of DDoS attacks to assist in reducing or avoiding costs and losses resulted from DDoS attacks. This paper presents STARK, a self- adaptable DDoS attack prediction system. STARK identifies signs of attack before it reaches an unrecoverable stage being founded on the metastability theory. Its evaluation follows a trace-driven approach, taking as input two databases containing records of DDoS attacks. Results show the prediction of DDoS attacks with minutes or hours in advance.
Mateus Pelloso, Andressa Vergütz, Aldri Luiz dos Santos, Michele Nogueira Lima
GLOBECOM2