VLDB 2026 Research / reviewers in the wild / expert
Anderson Bergamini de Neira
dblp:232/8599
· DBLP profile ↗
7ranked-venue papers
4as first author
6since 2021 · last 2025
0000-0003-2742-7568ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 4 first-author · 6 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Unsupervised Online Automl for Ddos of Things Prediction by Multimodal AnalysisabstractDistributed Denial of Service (DDoS) of Things are becoming increasingly severe, characterized by unprecedented traffic volumes and rates. Predicting these attacks before they escalate is critical for reducing costs. However, the complex and multidimensional nature of DDoS attacks demands adaptive defense strategies, which are lacking in current approaches. Existing methods often depend on labeled datasets, offline processing or context-specific models, resulting in low prediction accuracy. Further, they tend to rely on homogeneous data sources, limiting their adaptability to the variability of real-world network environments. This paper introduces DELIBERATE, a novel technique for DDoS attack prediction that utilizes unsupervised online AutoML and ordinal pattern transformation through multimodal correlation analysis. DELIBERATE adapts itself to changes in network traffic by leveraging the correlation of heterogeneous data and ordinal patterns transformation, a noisetolerant method suitable for IoT environments. It predicts DDoS attacks up to 47 minutes in advance. The method outperforms traditional approaches that depend on labeled data, extensive training, and complex neural networks. Ligia F. Borges, Anderson Bergamini de Neira, Lucas Albano, Michele Nogueira Lima |
ICC | 2 |
| 2025 | Transformers model for DDoS attack detection: A survey
Euclides Peres Farias, Anderson Bergamini de Neira, Ligia F. Borges, Michele Nogueira Lima |
Comput. Networks | 2 |
| 2023 | Unsupervised Feature Engineering Approach to Predict DDoS AttacksabstractPredicting Distributed Denial of Service (DDoS) attacks is crucial given the large volume of generated attack traffic, particularly that generated by infected Internet of Things (IoT) devices. Attackers conceal their actions to delay detection as much as possible, increasing their damage when effectively launched. Hence, predicting signals of the attack plays a vital role in anticipating DDoS attacks and enhancing service protection. This work presents SEE, an unsupervised feature engineering approach to assist in predicting DDoS attacks. SEE evaluations encompass four experiments employing multiple datasets (CTU- 13, CIC-DDoS2019, and IoT-23) and DDoS attacks. The approach predicts a DDoS attack 30 minutes before it effectively starts, reaching up to 100% accuracy. Anderson Bergamini de Neira, Ligia F. Borges, Alex Medeiros de Araújo, Michele Nogueira Lima |
GLOBECOM | 1 |
| 2023 | Distributed denial of service attack prediction: Challenges, open issues and opportunities
Anderson Bergamini de Neira, Burak Kantarci, Michele Nogueira Lima |
Comput. Networks | 1 |
| 2023 | An Intelligent System for DDoS Attack Prediction Based on Early Warning SignalsabstractAmong the different threats causing significant losses in cyberspace, the distributed denial of service (DDoS) attack is one of the most dangerous. The literature shows that the most reasonable manner to reduce the impacts of a DDoS attack is to prevent an attacker from launching it. Prevention is essential because attack sophistication allows them to reach massive traffic volumes, bypassing defenses. Defense mechanisms need time to detect and mitigate attacks. Hence, it is paramount to manage signals of the attack preparation before the attacker effectively launches it. This work presents COOPRED DDoS, a cooperative system for predicting DDoS attacks based on early warning signals extracted from the preparation of DDoS attacks. Its goal lies in increasing the time to prevent DDoS attacks. This work has followed four experiments utilizing two datasets widely employed in the literature. The results show that COOPRED DDoS identifies signals of attacks before the attacker effectively launches them. The system predicts one of the investigated attacks up to 3 minutes and 49 seconds in advance and the other attack up to 3 minutes and 55 seconds. The accuracy of the experiments varies from 99.60% to 99.87%. Anderson Bergamini de Neira, Alex Medeiros de Araújo, Michele Nogueira Lima |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2022 | Lifelong Autonomous Botnet DetectionabstractBotnet-driven attacks have attracted attention due to their diversity, high potential to cause damage and massive data generation. Existing botnet detection solutions are usually specific to a type of attack behavior. This particularity makes attack detection challenging because it involves a high operational overhead for manually calibrating and managing a large set of solutions for different attacks and variations. Hence, this work presents LBDS, a botnet detection system that acts autonomously in dynamic environments. It relies on concept drift and AutoML, two main techniques that consider dynamic behavior on data distribution. The LBDS evaluation has followed a diverse set of attacks and protocols. Results demonstrate that the system detects botnets utilizing different detection techniques, indicating its ability to consider various aspects of data and attacks. Alex Medeiros de Araújo, Anderson Bergamini de Neira, Michele Nogueira Lima |
GLOBECOM | 2 |
| 2020 | Early Botnet Detection for the Internet and the Internet of Things by Autonomous Machine LearningabstractThe high costs generated by attacks and the increasing number of different devices on the Internet and the Internet of Things (IoT) propel the early detection of botnets (i.e., network of infected devices) as a way to gain advantage against attacks. However, botnet early detection is challenging due to the continuous mutation, sophistication, and massive data volume, this last mainly resulted from sensor networks and IoT. The literature addresses botnets by modeling the behavior of malware spread, the classification of malicious traffic, and the analysis of traffic anomalies. This paper presents ANTE, a system for ANTicipating botnEts signals based on machine learning algorithms. The ANTE design allows it to adapt to different scenarios by learning to detect different types of botnets throughout its execution. Hence, ANTE autonomously selects the most appropriate machine learning pipeline for each type of botnet to maximize the correct classification before an attack effectively begins. The ANTE evaluation follows a comparison of its results to others from the literature considering three datasets: ISOT HTTP Botnet, CTU-13, and CICDDoS2019. Results show an average accuracy of 99.87% and an average botnet detection precision of 100%. Anderson Bergamini de Neira, Alex Medeiros de Araújo, Michele Nogueira Lima |
MSN | 1 |