VLDB 2026 Research / reviewers in the wild / expert
José Flora
dblp:252/7571
· DBLP profile ↗
4ranked-venue papers
4as first author
3since 2021 · last 2024
0000-0003-0809-4665ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 4 first-author · 3 since 2021Security and privacy · 2 · 2 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Evaluating intrusion detection for microservice applications: Benchmark, dataset, and case studiesabstractMicroservices are predominant for cloud-based applications, which serve millions of customers daily, that commonly run business-critical systems on software containers and multi-tenant environments; so, it is of utmost importance to secure these systems. Intrusion detection is a widely applied technique that is now being used in microservices to build behavior detection models and report possible attacks during runtime. However, it is cumbersome to evaluate and compare the effectiveness of different approaches. Standardized frameworks are non-existent and without fairly comparing new techniques to the state-of-the-art, it is difficult to understand their pros and cons. This paper presents a comprehensive approach to evaluate and compare different intrusion detection approaches for microservice applications. A benchmarking methodology is proposed to allow users to standardize the process for a representative and reproducible evaluation. We also present a dataset that applies representative workloads and technologies based on microservice applications state-of-the-art. The benchmark and dataset are used in three case studies, characterized by dynamicity, scalability, and continuous delivery, to evaluate and compare state-of-the-art algorithms with the objective of tackling intrusion detection in microservices. Experiments show the usefulness and wide application range of the benchmark while showing the capacity of intrusion detection algorithms in different applications and deployments. José Flora, Nuno Antunes |
J. Syst. Softw. | 1 |
| 2023 | Intrusion Detection for Scalable and Elastic Microservice ApplicationsabstractThe growing complexity and dynamicity of microservices, combined with their ability to scale, present significant challenges to security monitoring tools. Integrating these tools into a DevSecOps pipeline is currently impractical, necessitating research into adaptive intrusion detection approaches. This paper introduces three data processing techniques that enable intrusion detection in scalable and elastic microservice applications utilizing CI/CD approaches. These techniques manipulate data collected from active microservice replicas and feed it to algorithms, resulting in reliable intrusion detection even after scaling operations. To evaluate these techniques, we integrate them into a state-of-the-art intrusion detection tool developed for microservice environments. Their effectiveness is evaluated using two lightweight algorithms (STIDE and BoSC) with representative workloads, attacks, and a microservice-based application, demonstrating their ability to detect most attacks, even in scenarios involving multiple replicas. José Flora, Paulo Gonçalves 0005, Nuno Antunes |
PRDC | 1 |
| 2023 | µDetector: Automated Intrusion Detection for MicroservicesabstractThe recent adoption of microservice-based applications divides an application into small independent services that communicate using lightweight mechanisms, improving flexibility and scalability in dynamic DevOps environments that leverage containers and orchestration tools such as Kubernetes. However, this growing popularity raises concerns related to their dependability and security, aggravated by several attacks and the lack of intrusion detection tools that target microservices. Thus, developing solutions that can be deployed in real-world scenarios and whose purpose is to keep applications and businesses secure is of the utmost importance. This paper presents µDetector, an intrusion detection tool for microservice-based applications. This tool uses intrusion detection techniques from previous research and automates their functioning for Kubernetes and KubeEdge deployments. The user provides a configuration file and the tool uses monitoring agents to collect system calls from the containers and transfers them over to the IDS module that performs anomaly-based intrusion detection. Anomalous activity will trigger alarms indicating a possible intrusion. The user can interact with the tool and its monitoring capabilities through a command-line interface or a web dashboard. µDetector was validated using functional testing and performance and scalability tests. Results show that µDetector performs well and does not impact the proper functioning of the microservices: in scenarios with over 100 000 system calls being collected per second, the CPU and memory usage of the worker nodes did not exceed 10% of the total resources available.The source code repository can be accessed here: https://github.com/micro-sec/detector. José Flora, Miguel Teixeira, Nuno Antunes |
SANER | 1 |
| 2020 | Using Attack Injection to Evaluate Intrusion Detection Effectiveness in Container-based SystemsabstractContainers revolutionized cloud applications, as they are lightweight, highly portable and ideal for microservices. Although they are being adopted in business-critical scenarios, they introduce security concerns which are exacerbated in multi-tenant environments. Intrusion detection techniques can help, but they have received limited attention in this context. This paper presents an approach that uses attack injection to evaluate the effectiveness of intrusion detection in container-based systems. We use a TPC-C workload, with a database engine running as a container, while monitoring its system calls. First, the algorithms are submitted to benign workloads to learn the application profile. Then, we execute a set of attack injection experiments with diverse attacks, and we verify whether the algorithms report them. An experiment was designed to evaluate the algorithms in Docker and LXC containers, and in a traditional OS deployment for comparison. The results show that the approach is effective in evaluating the algorithms in different scenarios. The algorithms consistently detect most of the attacks (89+%). The precision values show more variance, but with careful tuning and richer workloads, this problem can be mitigated. José Flora, Paulo Gonçalves 0005, Nuno Antunes |
PRDC | 1 |