Roger Robson dos Santos

dblp:261/8247 · DBLP profile ↗
← Back
9ranked-venue papers
5as first author
6since 2021 · last 2023
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 3 first-author · 5 since 2021Systems, architecture and hardware · 2Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2023 Federated learning for reliable model updates in network-based intrusion detection
Roger Robson dos Santos, Eduardo Viegas 0001, Altair Olivo Santin, Pietro Tedeschi
Comput. Secur.1
2023 Reinforcement Learning for Intrusion Detection: More Model Longness and Fewer Updates
abstract
Several works have used machine learning techniques for network-based intrusion detection over the past few years. While proposed schemes have been able to provide high detection accuracies, they do not adequately handle the changes in network traffic behavior as time passes. Researchers often assume that model updates can be performed periodically as needed, although this is not easily feasible in real-world scenarios. This paper proposes a new intrusion detection model based on a reinforcement learning approach that aims to support extended periods without model updates. The proposal is divided into two strategies. First, it applies machine learning scheme as a reinforcement learning task to long-term learning -maintaining high reliability and high classification accuracies over time. Second, model updates are performed using a transfer learning technique coped with a sliding window mechanism that significantly decreases the need for computational resources and human intervention. Experiments performed using a new dataset spanning 8TB of data and four years of real network traffic indicate that current approaches in the literature cannot handle the evolving behavior of network traffic. Nevertheless, the proposed technique without periodic model updates achieves similar accuracy rates to traditional detection schemes implemented with semestral updates. In the case of performing periodic updates on our proposed model, it decreases the false positives up to 8%, false negatives up to 34%, with an accuracy variation up to only 6%, while demanding only seven days of training data and almost five times fewer computational resources when compared to traditional approaches.
Roger Robson dos Santos, Eduardo Viegas 0001, Altair Olivo Santin, Vinicius Vielmo Cogo
IEEE Trans. Netw. Serv. Manag.1
2021 Improving Intrusion Detection Confidence Through a Moving Target Defense Strategy
abstract
Despite the promising results reported in the literature, the intrusion detection schemes cannot deal with new network traffic behaviors making such proposals unfeasible to be deployed in production environments. This paper presents an intrusion detection model that relies on a moving target defense strategy to face new network traffic behavior in a two stage process. First, the system select the most suitable classifiers set to assign a class (normal or attack) according to the current event behavior. Second, we evaluate if the performed classification is reliable by validating its confidence values. The goal is to ensure that only the higher confident classifications from the most suitable classifiers are used to trigger intrusion detection alerts, keeping the system reliable over time. Experiments performed on a dataset that spans over 97GB of data with seven categories of network traffic shows that current machine learning techniques cannot cope with novel traffic behavior, failing to detect up to four new traffic categories. In contrast, the proposed model can select the most confident classifiers, reducing the average false-negative rates by up to 39%, regardless of the current network traffic category.
Roger Robson dos Santos, Eduardo Viegas 0001, Altair Olivo Santin
GLOBECOM1
2021 A Reminiscent Intrusion Detection Model Based on Deep Autoencoders and Transfer Learning
abstract
Machine learning techniques for network-based intrusion detection often assume that network traffic does not change over time or that model updates can be easily performed. This paper proposes a novel, reminiscent intrusion detection model based on deep autoencoders and transfer learning to ease the model update burden in a twofold implementation. First, a deep autoencoder is used as an additional feature extraction stage to obtain a historical feature representation of network traffic. Second, at model updates, the deep autoencoder parameters are updated through a transfer learning procedure, thus, significantly decreasing the amount of needed labeled training data and the computational costs. Experiments performed on a 8TB dataset containing real and valid network traffic ranging for one year have shown that approaches in the literature cannot handle with the network traffic behavior changes over time, requiring impractical amounts of labeled data to be provided during model training tasks. In addition, if no model updates are performed, the proposed scheme can improve the true-negative rate by up to 23.9%. If done so, it can provide similar accuracy rates of traditional techniques while demanding only 22% of labeled training data and 28% of computational costs.
Roger Robson dos Santos, Eduardo Viegas 0001, Altair Olivo Santin
GLOBECOM1
2021 A Machine Learning Model for Detection of Docker-based APP Overbooking on Kubernetes
abstract
Resource allocation overbooking is an approach used by cloud providers that allocates more virtual resources than available on physical hardware, which may imply service quality degradation. Docker in cloud computing environments is being increasingly used due to their fast provisioning and deployment, while the impact of overbooking of resources allocation due to multi-tenancy remains overlooked. This paper proposes a machine learning model to detect overbooking in Kubernetes environments within the docker container. The proposed model continuously monitors distributed container OS usage and application performance metrics. The collected metrics are used as input to a machine learning model that identifies multi-tenancy interference incurring in application performance degradation. Experiments performed on a Kubernetes cluster with a Docker-based Big Data processing application showed that our proposed model could detect resource overbooking with up to 98% accuracy. This implies an overbooking on a resource of up to 1.2 in the client’s domain.
Felipe Ramos, Eduardo Viegas 0001, Altair Olivo Santin, Pedro Horchulhack, Roger Robson dos Santos, Allan Espindola
ICC5
2021 A Multi-View Intrusion Detection Model for Reliable and Autonomous Model Updates
abstract
Changes in network traffic behavior over time are neglected by authors who use machine learning techniques applied to intrusion detection. In general, it is assumed that periodic model updates are performed, regardless of the challenges related to such a task. This paper proposes a new multi-view intrusion detection model capable of reliably performing model updates without human assistance while also maintaining its accuracy over time. The proposal evaluates the classification’s confidence values in a multi-view configuration to maintain its reliability over time, even without model updates. Besides, it is able to perform model updates autonomously, according to the result of the multi-view classification. Our experiments, performed with 7TB of real network traffic over a 2-year interval, show that our proposed scheme can maintain its accuracy over time without model updates, rejecting only 14.2% of its classification. However, when autonomous model updates are performed, the rejection rate drops to just 8.8%, while also improving the model’s accuracy by 4.3%.
Rivaldo L. Tomio, Eduardo Viegas 0001, Altair Olivo Santin, Roger Robson dos Santos
ICC4
2020 A Long-Lasting Reinforcement Learning Intrusion Detection Model
Roger Robson dos Santos, Eduardo Viegas 0001, Altair Olivo Santin, Vinicius Vielmo Cogo
AINA1
2020 A Host-based Intrusion Detection Model Based on OS Diversity for SCADA
abstract
Supervisory Control and Data Acquisition (SCADA) systems have been a frequent target of cyberattacks in Industrial Control Systems (ICS). As such systems are a frequent target of highly motivated attackers, researchers often resort to intrusion detection through machine learning techniques to detect new kinds of threats. However, current research initiatives, in general, pursue higher detection accuracies, neglecting the detection of new kind of threats and their proposal detection scope. This paper proposes a novel, reliable host-based intrusion detection for SCADA systems through the Operating System (OS) diversity. Our proposal evaluates, at the OS level, the SCADA communication over time and, opportunistically, detects, and chooses the most appropriate OS to be used in intrusion detection for reliability purposes. Experiments, performed through a variety of SCADA OSs front-end, shows that OS diversity provides higher intrusion detection scope, improving detection accuracy by up to 8 new attack categories. Besides, our proposal can opportunistically detect the most reliable OS that should be used for the current environment behavior, improving by up to 8%, on average, the system accuracy when compared to a single OS approach, in the best case.
Bruno B. Bulle, Altair Olivo Santin, Eduardo Viegas 0001, Roger Robson dos Santos
IECON4
2020 PPCensor: Architecture for real-time pornography detection in video streaming
Jackson Mallmann, Altair Olivo Santin, Eduardo Viegas 0001, Roger Robson dos Santos, Jhonatan Geremias
Future Gener. Comput. Syst.4