VLDB 2026 Research / reviewers in the wild / expert
Adrián Lara
dblp:334/3048
· DBLP profile ↗
8ranked-venue papers
5as first author
3since 2021 · last 2024
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 4 first-authorArtificial intelligence and machine learning · 3 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Transfer Learning and Fine-Tuning for Facial Expression Recognition with Class BalancingabstractFacial expression recognition benefits from deep learning models because of their ability to automatically extract features. However, these models face three important challenges: first, training tends to take longer times than with traditional machine learning models. Second, obtaining and labeling enough data samples can become a heavy burden due to the feature complexity usually involved in these problems. Third, it is also common to face class imbalance challenges. In this paper, we address these challenges by implementing transfer learning, oversampling and fine tuning to a facial expression recognition use case. Combining transfer learning with the use of a GPU helped us complete the training for our models in just about one hour. Furthermore, we achieved a 65.75% accuracy with one of the models. We provide measurements for metrics that are helpful when dealing with imbalanced data to assess that the models are not biased like precision, recall, F1 score and loss. Josef Ruzicka, Adrián Lara |
CLEI | 2 |
| 2023 | Tor Traffic Classification using Decision TreesabstractThe amount of users interested in protecting their data and privacy on the Internet has increased lately. This has augmented the popularity of anonymization services such as Tor. However, the anonymization and the complication of being tracked provided by Tor has also been used for illintended purposes, such as evading security policies and controls. In this work, we implemented and evaluated an offline Tor traffic detector using white-box machine learning algorithms such as decision trees and random forests. On the one hand, our classifier achieves precision levels above 99 %. On the other hand, our approach is the first one to allow understanding and interpreting the classifier, thus understanding which variables play a significant role in the classification. We show that TCP window size, packet size and some time-related features can be used to identify Tor traffic. Paulo Calvo, Gabriela Barrantes, José Guevara, Adrián Lara |
CLEI | 4 |
| 2022 | Detecting Malicious Domains using the Splunk Machine Learning ToolkitabstractMalicious domains are often hidden amongst benign DNS requests. Given that DNS traffic is generally permitted, blocking malicious requests is a challenge for most network defenses. Using machine learning to classify DNS requests enables a scalable alternative to programmable blocklists. Studies in this field often reduce their dataset scope to a a single attack behavior. However, organizations are being hit by a myriad of attack patterns across multiple objectives, reducing the scope means closing the door to classifier operationalization in a real-world environment. In this paper, we propose a broader and more challenging scenario for our dataset by combining the four DNS malicious behaviors: malware, phishing, spam and botnet with legitimate domains samples. We use Splunk and its Machine Learning Toolkit to create, test and validate our classifier. We extract 12 static features from the domain name and analyze their weight on the prediction. We compared two supervised learning algorithms and measure their accuracy for such challenging environment. We obtained an 88% of accuracy by using Random Forest algorithm against Decision Tree 87%. Michelle Cersosimo, Adrián Lara |
NOMS | 2 |
| 2018 | Automated Inter-Domain Cut-Through Switching for the Future InternetabstractAs the deployment of software-defined networks increases, so does the manageability of local and wide area networks. Designing intelligent solutions that respond to traffic changes automatically will soon become a mandatory requirement in production networks. In this paper, we focus on designing an intelligent control plane for the MobilityFirst Future Internet architecture. This architecture proposes novel mechanisms to replace the Internet Protocol to better support content delivery and mobility, such as hop-by-hop transfer, storage-aware routing and separation of identifiers and network addresses. In earlier work, we have argued that these mechanisms can be bypassed for certain data flows. Indeed, when there is no mobility involved, it is more convenient to implement cut-through switching at lower layers to bypass the routing mechanisms. In this paper, we propose an inter-domain framework capable of cut-through switching in MobilityFirst. The proposed framework is capable of adding and removing flows from tunnels automatically. It is also capable of creating inter-domain tunnels based on flow behavior and inter-domain latency. Our implementation experiments show that the control plane delay can be reduced by 75% when using inter-domain tunnels. Furthermore, the results also show how our framework needs fewer messages than current protocols such as label distribution protocol to setup intra-domain and inter-domain tunnels. Adrián Lara, Shreyasee Mukherjee, Byrav Ramamurthy, Dipankar Raychaudhuri, K. K. Ramakrishnan |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2016 | Inter-domain routing with cut-through switching for the MobilityFirst Future Internet architectureabstractFuture Internet projects such as MobilityFirst and Named Data Networking have proposed novel mechanisms to replace the Internet Protocol to better support content delivery and mobility. However, the problem of efficient data transfer across the network core has not been adequately investigated. We tackle the challenge of inter-domain cut-through switching using software-defined networking (SDN). First, we propose and solve an optimization problem that minimizes the total transfer time using inter-domain tunnels. Second, we propose an SDN-based routing framework for the MobilityFirst architecture capable of dynamically creating such tunnels. The main novelty of this framework is to name tunnels as network objects to simplify how tunnels are created and maintained. To validate our framework, we implement on the GENI (Global Environment for Network Innovations) testbed a prototype for the MobilityFirst architecture. Our experiments with the optimization problem show that the inter-domain latency between controllers plays a key role on how tunnels are setup. Furthermore, our implementation experiments show that the control plane delay can be reduced by 75% when using inter-domain tunnels. Finally, we show how our framework needs fewer messages than current protocols such as label distribution protocol (LDP) to setup intra-domain and inter-domain tunnels. Adrián Lara, Shreyasee Mukherjee, Byrav Ramamurthy, Dipankar Raychaudhuri, K. K. Ramakrishnan |
ICC | 1 |
| 2016 | OpenSec: Policy-Based Security Using Software-Defined NetworkingabstractAs the popularity of software-defined networks (SDN) and OpenFlow increases, policy-driven network management has received more attention. Manual configuration of multiple devices is being replaced by an automated approach where a software-based, network-aware controller handles the configuration of all network devices. Software applications running on top of the network controller provide an abstraction of the topology and facilitate the task of operating the network. We propose OpenSec, an OpenFlow-based security framework that allows a network security operator to create and implement security policies written in human-readable language. Using OpenSec, the user can describe a flow in terms of OpenFlow matching fields, define which security services must be applied to that flow (deep packet inspection, intrusion detection, spam detection, etc.) and specify security levels that define how OpenSec reacts if malicious traffic is detected. In this paper, we first provide a more detailed explanation of how OpenSec converts security policies into a series of OpenFlow messages needed to implement such a policy. Second, we describe how the framework automatically reacts to security alerts as specified by the policies. Third, we perform additional experiments on the GENI testbed to evaluate the scalability of the proposed framework using existing datasets of campus networks. Our results show that up to 95% of attacks in an existing data set can be detected and 99% of malicious source nodes can be blocked automatically. Furthermore, we show that our policy specification language is simpler while offering fast translation times compared to existing solutions. Adrián Lara, Byrav Ramamurthy |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2014 | OpenSec: A framework for implementing security policies using OpenFlowabstractAs the popularity of software defined networks (SDN) and OpenFlow increases, policy-driven network management has received more attention. Manual configuration of multiple devices is being replaced by an automated approach where a software-based, network-aware controller handles the configuration of all network devices. Software applications running on top of the network controller provide an abstraction of the topology and facilitate the task of operating the network. We propose OpenSec, an OpenFlow-based security framework that allows a network security operator to create and implement security policies written in human-readable language. Using OpenSec, the user can describe a flow in terms of OpenFlow matching fields, define which security services must be applied to that flow (deep packet inspection, intrusion detection, spam detection, etc) and specify security levels that define how OpenSec reacts if malicious traffic is detected. We implement OpenSec in the GENI testbed to evaluate the flexibility, accuracy and scalability of the framework. The experimental setup includes deep packet inspection, intrusion detection and network quarantining to secure a web server from network scanners. We achieve a constant delay when reacting to security alerts and a detection rate of 98%. Adrián Lara, Byrav Ramamurthy |
GLOBECOM | 1 |
| 2013 | Evaluation of an implementation guide for an IT standard using surveysabstractThis manuscript describes how we evaluated an implementation guide designed to help public organizations in Costa Rica that must implement an IT standard. In CLEI 2011 we described how we created the guide and how we used the guide in one financial entity. In this paper, we continue this effort by describing how we evaluated the quality of the designed implementation guide. To evaluate our product, we relied created surveys that were completed by a group of experts. The sample (nine experts in total) consisted of IT experts both from the entity that designed the IT standard as well as experts from the financial organization that participated of the implementation process of the standard. Therefore, our evaluation takes into consideration the opinion of both designers and implementers of the standard. Our results show that both groups of experts consider that our guide simplifies the implementation and appraisal processes. A majority of experts also believe that it is easier to understand the standard using our guide and that an implementation team would be more efficient if the guide is used. Adrián Lara, Marcelo Jenkins |
CLEI | 1 |