Altair Olivo Santin

dblp:38/5417 · also Altair O. Santin · DBLP profile ↗
← Back
68ranked-venue papers
1as first author
31since 2021 · last 2026
0000-0002-2341-2177ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 30 · 11 since 2021Systems, architecture and hardware · 11 · 3 since 2021Artificial intelligence and machine learning · 4 · 3 since 2021Security and privacy · 4 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Theory of computation · 1
YearPublicationVenuePosition
2026 A Large Language Model Framework for Predicting Judicial Outcomes in Civil Law Systems
Alan Alves Araújo, Altair Olivo Santin, Eduardo Viegas 0001
ICPR (1)2
2026 Sparse Mixture of Experts for Image-Based Multi-View Android Malware Detection
Jhonatan Geremias, Alceu S. Britto Jr., Altair Olivo Santin, Eduardo Viegas 0001
IWCMC3
2026 A Feature Selection Model for Lightweight Network Intrusion Detection on Resource-constrained Devices
Wadson S. Pereira, Eliane Maria T. Barbosa, Altair Olivo Santin, Eduardo Viegas 0001
IWCMC3
2026 Diversity as a Security Primitive for ML-Based Network Intrusion Detection
Allan Espindola, Altair Olivo Santin, Eduardo Viegas 0001, Pedro M. Ferreira 0001, António Casimiro
NetSoft2
2026 Enhancing intrusion detection generalization via diversity-driven multi-view ensemble learning in industrial systems
abstract
Traditional Intrusion Detection Systems (IDSs) struggle with unseen attacks, a critical gap in industrial settings, while single-view approaches lack cross-context detection for attacks that manifest across host and network layers. We propose DIversity-driven Multi-view Ensemble IDS (DIME-IDS), a diversity-driven multi-view ensemble for Supervisory Control and Data Acquistion (SCADA) systems, which manage critical industrial infrastructures. Our work introduces: (i) A public hybrid SCADA dataset with 16 attack behaviors synchronized across four Linux/Windows views (network, host, user-activity, system-activity); (ii) A novel Nondominated Sorting Genetic Algorithm II (NSGA-II) optimization constructing ensembles that maximize both accuracy and inter-view diversity; (iii) Dynamic classifier selection at inference using Pareto-optimal operation points. Evaluated against strong baselines (XGB/RF/MLP), DIME-IDS achieves 0.86 accuracy, 0.95 AUC, and 6.51% False Negative (FN) rate, outperforming single-view (10.03%) and concatenated (14.38%) approaches, with lowest FN rates in 3 of 4 unseen attacks. These results demonstrate that explicit multi-view diversity and dynamic selection significantly enhance generalization against novel threats in industrial environments.
Allan Espindola, António Casimiro, Altair Olivo Santin, Pedro M. Ferreira 0001, Eduardo Viegas 0001
Future Gener. Comput. Syst.3
2025 On the Challenges of Implementing MLOps for Stream Learning Algorithms
Miguel G. Rodrigues, Eduardo Viegas 0001, Fabrício Enembreck, Altair Olivo Santin, Juliano S. Langaro, Adilson G. Filho
AINA (3)4
2025 Evaluating Parental Readiness to Manage Children's Privacy Across Social Media Platforms
abstract
Children’s widespread use of digital platforms has intensified concerns about the adequacy of privacy protections. Current legislation places the responsibility for managing children’s privacy on parents and guardians, assuming they possess the necessary knowledge to make informed decisions. In light of this, this work assesses parental maturity in managing children’s privacy on social platforms. First, we identify the main privacy attributes relevant to children’s online data protection by analyzing existing laws and regulations, including the GDPR, COPPA, and LGPD. This phase establishes a regulatory baseline for evaluating parental responsibilities and expectations. In the second phase, we surveyed 77 parents and guardians to assess their level of maturity in managing privacy-related measures and to evaluate how effectively they can protect their children’s data in digital environments. Our results reveal a significant discrepancy between perceived and actual knowledge, suggesting that many parents may not be adequately prepared to fulfill the role expected by current regulations. These findings support the need for clearer policies and a shared responsibility model between platforms and guardians to ensure child privacy.
Mykaele F. Abreu, Eduardo Viegas 0001, Altair Olivo Santin, Jhonatan Geremias
SMC3
2025 An Energy-Efficient Intrusion Detection Offloading Based on DNN for Edge Computing
abstract
To address the computational limitations associated with implementing Deep Neural Network (DNN)–based intrusion detection on resource-constrained devices, this work proposes an energy-efficient edge architecture that integrates distributed early-exit DNN models to minimize processing overhead while preserving detection performance. Our approach employs multi-objective optimization to dynamically offload complex tasks to the cloud, thereby balancing the trade-off between accuracy and energy consumption under operator constraints. Furthermore, it incorporates a rejection mechanism and confidence calibration via temperature scaling to ensure reliability as network traffic evolves. Experiments on a 7TB year-long dataset demonstrate that the system reduces edge energy consumption to only 1% while offloading only 10% of events, all without compromising detection accuracy and even improving the F1-Score by 0.02 compared to traditional approaches.
João A. Simioni, Eduardo Viegas 0001, Altair Olivo Santin, Everton de Matos
IEEE Internet Things J.3
2025 A MLOps architecture for near real-time distributed Stream Learning operation deployment
Miguel G. Rodrigues, Eduardo Viegas 0001, Altair Olivo Santin, Fabrício Enembreck
J. Netw. Comput. Appl.3
2024 A Review of Social Network Regulations and Mechanisms for Safeguarding Children's Privacy
Mykaele F. Abreu, Eduardo Viegas 0001, Altair Olivo Santin
AINA (5)3
2024 A Non-interactive One-Time Password-Based Method to Enhance the Vault Security
Juarez Oliveira, Altair Olivo Santin, Eduardo Viegas 0001, Pedro Horchulhack
AINA (4)2
2024 Towards a Feasible Palm Vein Verification Scheme Using Deep Autoencoder and Siamese Networks
abstract
Palm vein pattern recognition offers a unique personal identification feature. Unfortunately, these techniques typically require a Near Infrared (NIR) camera sensor to extract the individual's venous pattern, challenging their wide deployment. This paper proposes a new feasible palm vein verification scheme using a Deep Autoencoder and a Siamese Network, implemented threefold. First, we capture the individual's palm using a traditional visible spectrum camera sensor and perform preprocessing tasks to correct imprecise positioning, easing palm support accessories requirements. Second, we eliminate NIR sensor requirement by fine-tuning a Deep Autoencoder model to convert images from the visible spectrum to their infrared counterparts. Third, generated images are processed by a lightweight Siamese network using a contrastive loss function for individual verification. Experiments conducted on a publicly available dataset with over a hundred individuals confirmed the feasibility of our proposal. Our scheme reaches up to 0.97 of true-negative rate, with only 0.01 decrease compared to traditional NIR-based approaches. In addition, individual identification can be conducted in less than 6 seconds in a resource-constrained environment thanks to our lightweight model's implementation.
Mateus Nunes, Eduardo Viegas 0001, Altair Olivo Santin
ICMLA3
2024 Passive Identification of Rogue Industrial Access Points Using a One-Class Machine Learning Model
abstract
Access point (AP) security has become increasingly important as wireless local area networks (WLANs) proliferate in industrial environments. Rogue APs are often used by attackers to conduct man-in-the-middle (MiTM) attacks. They can redirect users to malicious servers or do eavesdropping and manipulation of their communications.In this paper, we propose a novel one-class machine learning model to passively identify rogue APs in industrial environments. The implementation of the model is twofold. First, we passively extract the hardware and software characteristics of the evaluated AP according to its generated messages. This results in a comprehensive feature set that captures both low-level and high-level behaviors of the evaluated AP.Second, we apply a one-class machine learning model to identify APs that significantly deviate from the previously known profile of legitimate APs. The combined evaluation of hardware and software behaviors integrated with an outlier detection scheme to effectively identify rogue APs is the insight of our proposal. We demonstrate the feasibility of our model, achieving an F1 score of 0.89 and a true positive rate of 0.9 in experiments conducted on our new publicly available dataset of 357 unique AP behaviors.
André L. de S. Paula, Eduardo Viegas 0001, Altair Olivo Santin
IECON3
2024 Toward a Reliable Network-Based Intrusion Detection Model for SCADA: A Classification with Reject Option Approach
abstract
Industrial control systems (ICS) are often targeted by highly motivated attackers seeking to disrupt their services due to its critical nature. Traditional cybersecurity does not provide the necessary reliability for ICS systems. Even when implemented with many layers of defense, including network intrusion detection systems (NIDS). This paper proposes a dynamic and reliable intrusion detection model that is implemented in two steps. First, it proactively classifies each type of possible network attack on the basis of the current network traffic behavior. Second, it evaluates the classification quality through rejection option, which is an indication of its reliability. By adapting to the evolving network traffic, our proposal increases the system robustness against motivated attackers. The proposed model effectiveness has been demonstrated by experimenting in a controlled testbed with more than 14 attack categories. The dynamic selection of security mechanisms allowed us to increase the detection accuracy by up to 26%. Moreover, the classification evaluation in the proposed model achieves up to 99% detection accuracy with only 1% rejection.
Paulo Roberto de Oliveira, Eduardo Viegas 0001, Altair Olivo Santin, Pedro Horchulhack, Everton de Matos
IJCNN3
2024 Network-based Intrusion Detection Through Image-based CNN and Transfer Learning
abstract
Machine learning (ML) techniques for network intrusion detection is still limited in production environments despite promising results reported in the literature. Network traffic behavior exhibits considerable variability and evolves over time, requiring periodic model updates. This paper proposes a new approach to intrusion detection modeling based on CNN and transfer learning to reduce updating overhead. Its implementation is twofold. First, CNN is implemented using flow-based feature expansion derived from neural flattened hyperdimensional space. This expanded space representation contributes to a longer model lifetime and maintains system accuracy over time. Second, the required training data and computational cost are significantly reduced by performing periodic model updates based on a transfer learning approach. Experiments on a novel dataset with over 2.6 TB of data and one year of real-world network traffic demonstrate the feasibility of the proposal. Our proposal improves the average F1 score by up to 0.19 when no model updates are performed. While improving the system’s accuracy, model updates impose only 42.8% of the computational cost.
Pedro Horchulhack, Eduardo Viegas 0001, Altair Olivo Santin, João A. Simioni
IWCMC3
2024 Detection of quality of service degradation on multi-tenant containerized services
Pedro Horchulhack, Eduardo Viegas 0001, Altair Olivo Santin, Felipe Ramos, Pietro Tedeschi
J. Netw. Comput. Appl.3
2023 A Dynamic Machine Learning Scheme for Reliable Network-Based Intrusion Detection
Eduardo Viegas 0001, Everton de Matos, Paulo Roberto de Oliveira, Altair Olivo Santin
AINA (2)4
2023 Towards a Reliable Hierarchical Android Malware Detection Through Image-based CNN
abstract
The number of Android malicious applications keeps growing as time passes, even paving their way to official app markets. In recent years, a promising malware detection approach makes use of the compiled app source codes (dex), through convolutional neural networks (CNN) as an image classification task. Unfortunately, current proposals often rely on unrealistic datasets, focusing their detection on the mal-ware families, while neglecting the detection of malware apps in the first place. In this paper, we propose a reliable and hierarchical Android malware detection through an image-based CNN scheme, implemented twofold. First, Android malware classification is performed in a hierarchically-structured local manner, initially identifying malware apps, then, their related family. Second, to ensure reliability and improve classification accuracy, only highly confident classified apps are reported, in a classification with reject option rationale. Experiments performed in a new dataset with over 26 thousand Android apps, divided into 29 malware families, compounding over 13 GB of app dex images, have shown that current image-based CNN for malware detection is unable to provide high detection accuracies. In contrast, our proposed model is able to reliably detect malware apps, improving the true-negative rates by up to 5.5%, and the average true-positive rate of the malware families of accepted apps by up to 12.7%, while rejecting only 10% of Android apps.
Jhonatan Geremias, Eduardo Viegas 0001, Altair Olivo Santin, Alceu S. Britto Jr., Pedro Horchulhack
CCNC3
2023 A Dynamic Network-based Intrusion Detection Model for Industrial Control Systems
abstract
Industrial Control Systems (ICS) play a crucial role in managing and controlling industrial assets. Due to their critical importance, adversaries are often highly motivated to target these systems, as a successful attack can disrupt the entire industry’s operations. In general, to improve the system’s security, proposed intrusion detection schemes often resort to traditional security mechanisms. As a consequence, due to their static nature, attackers can easily evade designed detection approaches. In light of this, this paper proposes a new dynamic network-based intrusion detection model for ICS, implemented in two phases. First, our scheme extracts network-related features to describe the current ICS environment behavior. Second, the security mechanisms are proactively selected based on the extracted network traffic behavior. As a result, our scheme can adjust the system’s configuration based on the current assessed event. Experiments on a new dataset, featuring over 14 attack categories targeting a SCADA system revealed that traditional detection methods face challenges in handling diverse attack categories. Conversely, our proposed model improved the average true-positive rates by up to 20% while also improving the range of detected attacks.
Paulo Roberto de Oliveira, Altair Olivo Santin, Pedro Horchulhack, Eduardo Viegas 0001, Everton de Matos
TrustCom2
2023 Federated learning for reliable model updates in network-based intrusion detection
Roger Robson dos Santos, Eduardo Viegas 0001, Altair Olivo Santin, Pietro Tedeschi
Comput. Secur.3
2023 Reinforcement Learning for Intrusion Detection: More Model Longness and Fewer Updates
abstract
Several works have used machine learning techniques for network-based intrusion detection over the past few years. While proposed schemes have been able to provide high detection accuracies, they do not adequately handle the changes in network traffic behavior as time passes. Researchers often assume that model updates can be performed periodically as needed, although this is not easily feasible in real-world scenarios. This paper proposes a new intrusion detection model based on a reinforcement learning approach that aims to support extended periods without model updates. The proposal is divided into two strategies. First, it applies machine learning scheme as a reinforcement learning task to long-term learning -maintaining high reliability and high classification accuracies over time. Second, model updates are performed using a transfer learning technique coped with a sliding window mechanism that significantly decreases the need for computational resources and human intervention. Experiments performed using a new dataset spanning 8TB of data and four years of real network traffic indicate that current approaches in the literature cannot handle the evolving behavior of network traffic. Nevertheless, the proposed technique without periodic model updates achieves similar accuracy rates to traditional detection schemes implemented with semestral updates. In the case of performing periodic updates on our proposed model, it decreases the false positives up to 8%, false negatives up to 34%, with an accuracy variation up to only 6%, while demanding only seven days of training data and almost five times fewer computational resources when compared to traditional approaches.
Roger Robson dos Santos, Eduardo Viegas 0001, Altair Olivo Santin, Vinicius Vielmo Cogo
IEEE Trans. Netw. Serv. Manag.3
2022 Detection of Service Provider Hardware Over-commitment in Container Orchestration Environments
abstract
The deployment of container-based services continues to increase as time passes, mainly due to its fast provision time and lower allocation overheads. Yet, the literature still neglects the performance degradation in containers due to multi-tenancy and service provider hardware over-commitment. This paper proposes a new hardware over-commitment detection for container orchestration environments, implemented twofold. First, the containerized hardware usage of deployed containers is continuously monitored in a non-intrusive manner, leveraging the container engine resource management interface. Second, collected features are used by a recurrent neural network model for detecting both container and service level hardware over-commitment, following a time-series rationale. Experiments run on a containerized Apache Spark distribution have shown that multi-tenancy and hardware over-commitment significantly affect its performance. In addition, our proposed model is able to detect hardware over-commitment with up to 91% of true-positive at the container level, and up to 93% true-positive at the service level.
Pedro Horchulhack, Eduardo Viegas 0001, Altair Olivo Santin
GLOBECOM3
2022 Intrusion Detection Model Updates Through GAN Data Augmentation and Transfer Learning
abstract
Current machine learning techniques for network-based intrusion detection cannot handle the evolving behavior of network traffic, requiring periodic model updates to be conducted. Besides requiring huge amounts of labeled network traffic to be provided, traditional model updates demand expressive computational costs. This paper proposes a new feasible model update procedure implemented in two steps. First, we use a Generative Adversarial Network (GAN) to augment the sampled network traffic. Next, we use the augmented dataset to perform model updates through a transfer learning-based approach. Thus, our model can decrease both the number of instances that must be labeled and the computational costs during model updates. Our experiments on a one-year dataset with over 8 TB of data show that literature techniques cannot handle changes in network traffic behavior. In contrast, the proposed model without updates improved true-positive rates by up to 25.6%. With monthly model updates, it requires only 14% of computational costs and 2.3% of instances to be provided.
Pedro Horchulhack, Eduardo Viegas 0001, Altair Olivo Santin, Jhonatan Geremias
GLOBECOM3
2022 A Machine Learning-Based Digital Twin Model for Pressure Prediction in the Fuel Injection System
abstract
Over the last years, the engine calibration task has mostly been conducted based on the engineers’ knowledge. As a result, considering the complexity of modern engines, finding the most suitable configuration for each situation has become an impractical and expensive task. Apart from causing engines to be produced with inadequate calibration configuration, it can also decrease the lifespan of their components, degrading their efficiency. This paper proposes a machine learning-based digital twin model for pressure prediction in a fuel injection system, split into two steps. First, we extract statistical engine features based on a predefined time window to represent the engine behavior over time. Second, a digital twin implemented through a machine learning model is used to predict pressure levels in the fuel injection system. As a result, the predicted values can be used to assist the engine common rail system module in avoiding undesired engine states. Experiments performed on a new dataset, built over a real diesel-based engine, consisting of 208 features and over 1.3 million instances, have shown the feasibility of our proposal. The proposed scheme can predict in an advance time of 0.1 seconds the pressure levels for a fuel injection system with only 0.057 RMSE. Moreover, it increases its error rate by only 10.6% if a 0.5-second time advance is required.
Edwin P. Duarte, Eduardo Viegas 0001, Altair Olivo Santin
IECON3
2022 Towards Multi-view Android Malware Detection Through Image-based Deep Learning
abstract
Over the last years, several works have proposed highly accurate Android malware detection techniques. Surprisingly, modern malware apps can still pave their way to official markets, thus, demanding the provision of more robust and accurate detection approaches. This paper proposes a new multi-view Android malware detection through image-based deep learning, implemented threefold. First, apps are evaluated according to several feature sets in a multi-view setting, thus, increasing the information provided for the classification task. Second, extracted feature sets are converted to an image format while maintaining the principal components of the data distribution, keeping the information for the classification task. Third, built images are jointly represented in a single shot, each in a predefined image channel, enabling the application of deep learning architectures. Experiments on a new version of a publicly available Android malware dataset composed of over 11 thousand Android apps have shown our proposal's feasibility. It reaches true-negative rates of up to 99.5% when implemented with a single-view approach with our new image-building technique. In addition, if our proposed multi-view scheme is used, the classification accuracies of malware families become more stable, reaching a true-positive rate of up to 98.7%.
Jhonatan Geremias, Eduardo Viegas 0001, Altair Olivo Santin, Alceu S. Britto Jr., Pedro Horchulhack
IWCMC3
2022 Toward feasible machine learning model updates in network-based intrusion detection
Pedro Horchulhack, Eduardo Viegas 0001, Altair Olivo Santin
Comput. Networks3
2021 Improving Intrusion Detection Confidence Through a Moving Target Defense Strategy
abstract
Despite the promising results reported in the literature, the intrusion detection schemes cannot deal with new network traffic behaviors making such proposals unfeasible to be deployed in production environments. This paper presents an intrusion detection model that relies on a moving target defense strategy to face new network traffic behavior in a two stage process. First, the system select the most suitable classifiers set to assign a class (normal or attack) according to the current event behavior. Second, we evaluate if the performed classification is reliable by validating its confidence values. The goal is to ensure that only the higher confident classifications from the most suitable classifiers are used to trigger intrusion detection alerts, keeping the system reliable over time. Experiments performed on a dataset that spans over 97GB of data with seven categories of network traffic shows that current machine learning techniques cannot cope with novel traffic behavior, failing to detect up to four new traffic categories. In contrast, the proposed model can select the most confident classifiers, reducing the average false-negative rates by up to 39%, regardless of the current network traffic category.
Roger Robson dos Santos, Eduardo Viegas 0001, Altair Olivo Santin
GLOBECOM3
2021 A Reminiscent Intrusion Detection Model Based on Deep Autoencoders and Transfer Learning
abstract
Machine learning techniques for network-based intrusion detection often assume that network traffic does not change over time or that model updates can be easily performed. This paper proposes a novel, reminiscent intrusion detection model based on deep autoencoders and transfer learning to ease the model update burden in a twofold implementation. First, a deep autoencoder is used as an additional feature extraction stage to obtain a historical feature representation of network traffic. Second, at model updates, the deep autoencoder parameters are updated through a transfer learning procedure, thus, significantly decreasing the amount of needed labeled training data and the computational costs. Experiments performed on a 8TB dataset containing real and valid network traffic ranging for one year have shown that approaches in the literature cannot handle with the network traffic behavior changes over time, requiring impractical amounts of labeled data to be provided during model training tasks. In addition, if no model updates are performed, the proposed scheme can improve the true-negative rate by up to 23.9%. If done so, it can provide similar accuracy rates of traditional techniques while demanding only 22% of labeled training data and 28% of computational costs.
Roger Robson dos Santos, Eduardo Viegas 0001, Altair Olivo Santin
GLOBECOM3
2021 A Machine Learning Model for Detection of Docker-based APP Overbooking on Kubernetes
abstract
Resource allocation overbooking is an approach used by cloud providers that allocates more virtual resources than available on physical hardware, which may imply service quality degradation. Docker in cloud computing environments is being increasingly used due to their fast provisioning and deployment, while the impact of overbooking of resources allocation due to multi-tenancy remains overlooked. This paper proposes a machine learning model to detect overbooking in Kubernetes environments within the docker container. The proposed model continuously monitors distributed container OS usage and application performance metrics. The collected metrics are used as input to a machine learning model that identifies multi-tenancy interference incurring in application performance degradation. Experiments performed on a Kubernetes cluster with a Docker-based Big Data processing application showed that our proposed model could detect resource overbooking with up to 98% accuracy. This implies an overbooking on a resource of up to 1.2 in the client’s domain.
Felipe Ramos, Eduardo Viegas 0001, Altair Olivo Santin, Pedro Horchulhack, Roger Robson dos Santos, Allan Espindola
ICC3
2021 A Multi-View Intrusion Detection Model for Reliable and Autonomous Model Updates
abstract
Changes in network traffic behavior over time are neglected by authors who use machine learning techniques applied to intrusion detection. In general, it is assumed that periodic model updates are performed, regardless of the challenges related to such a task. This paper proposes a new multi-view intrusion detection model capable of reliably performing model updates without human assistance while also maintaining its accuracy over time. The proposal evaluates the classification’s confidence values in a multi-view configuration to maintain its reliability over time, even without model updates. Besides, it is able to perform model updates autonomously, according to the result of the multi-view classification. Our experiments, performed with 7TB of real network traffic over a 2-year interval, show that our proposed scheme can maintain its accuracy over time without model updates, rejecting only 14.2% of its classification. However, when autonomous model updates are performed, the rejection rate drops to just 8.8%, while also improving the model’s accuracy by 4.3%.
Rivaldo L. Tomio, Eduardo Viegas 0001, Altair Olivo Santin, Roger Robson dos Santos
ICC3
2021 A Deep Autoencoder and RNN Model for Indoor Localization with Variable Propagation Loss
abstract
Current machine learning techniques for indoor localization of wireless devices assume a single wireless propagation loss setting, making them unfeasible for reliable production deployment. This paper proposes a new indoor localization technique designed for variable propagation loss environments based on deep autoencoder and recurrent neural network (RNN), implemented threefold. This paper proposes a new indoor localization technique designed for variable loss propagation environments based on deep autoencoder and recurrent neural network (RNN), implemented in three stages. First, we extract statistical feature values from collected RSSI. Second, a deep autoencoder is used to remove wireless propagation noises introduced by variable fading settings. Third, an RNN performs the localization task taking into account previous sensor measurements. Experiments performed in 3 simulated testbeds with distinct propagation loss settings have shown that current approaches decrease localization accuracy by up to 30% when a different propagation loss is faced. In addition, our proposed model improved localization accuracy by up to 25.8% regardless of the current environment propagation loss.
Allan Espindola, Eduardo Viegas 0001, Andre Traleski, Marcelo Eduardo Pellenz, Altair Olivo Santin
WiMob5
2020 Identity and Access Management for IoT in Smart Grid
Vilmar Abreu, Altair Olivo Santin, Eduardo Viegas 0001, Vinicius Vielmo Cogo
AINA2
2020 A Long-Lasting Reinforcement Learning Intrusion Detection Model
Roger Robson dos Santos, Eduardo Viegas 0001, Altair Olivo Santin, Vinicius Vielmo Cogo
AINA3
2020 A Reliable Semi-Supervised Intrusion Detection Model: One Year of Network Traffic Anomalies
abstract
Despite the promising results of machine learning for network-based intrusion detection, current techniques are not widely deployed in real-world environments. In general, proposed detection models quickly become obsolete, thus, generating unreliable classifications over time. In this paper, we propose a new reliable model for semi-supervised intrusion detection that uses a verification technique to provide reliable classifications over time, even in the absence of model updates. Additionally, we cope with this verification technique with semi-supervised learning to autonomously update the underlying machine learning models without human assistance. Our experiments consider a full year of real network traffic and demonstrate that our solution maintains the accuracy rate over time without model updates while rejecting only 10.6% of instances on average. Moreover, when autonomous (non-human-assisted) model updates are performed, the average rejection rate drops to just 3.2% without affecting the accuracy of our solution.
Eduardo Viegas 0001, Altair Olivo Santin, Vinicius Vielmo Cogo, Vilmar Abreu
ICC2
2020 A Host-based Intrusion Detection Model Based on OS Diversity for SCADA
abstract
Supervisory Control and Data Acquisition (SCADA) systems have been a frequent target of cyberattacks in Industrial Control Systems (ICS). As such systems are a frequent target of highly motivated attackers, researchers often resort to intrusion detection through machine learning techniques to detect new kinds of threats. However, current research initiatives, in general, pursue higher detection accuracies, neglecting the detection of new kind of threats and their proposal detection scope. This paper proposes a novel, reliable host-based intrusion detection for SCADA systems through the Operating System (OS) diversity. Our proposal evaluates, at the OS level, the SCADA communication over time and, opportunistically, detects, and chooses the most appropriate OS to be used in intrusion detection for reliability purposes. Experiments, performed through a variety of SCADA OSs front-end, shows that OS diversity provides higher intrusion detection scope, improving detection accuracy by up to 8 new attack categories. Besides, our proposal can opportunistically detect the most reliable OS that should be used for the current environment behavior, improving by up to 8%, on average, the system accuracy when compared to a single OS approach, in the best case.
Bruno B. Bulle, Altair Olivo Santin, Eduardo Viegas 0001, Roger Robson dos Santos
IECON2
2020 Towards Real-time Video Content Detection in Resource Constrained Devices
abstract
Convolutional neural networks have been successfully applied for video content detection in the last years. However, such cognitive models usually demand the availability of several gigabytes of memory and present a low detection throughput, as a result, they are not feasible for resource-constrained devices, especially for real-time applications like video streaming. In this paper, we address real-time video content detection in resource-constrained devices in a threefold manner. First, we improve detection throughput by means of a frame sampling technique. Then, we propose a new evaluation measure towards proper deployment of convolutional neural networks in resource-constrained devices. Finally, we address the accuracy degradation caused by the porting of the convolutional neural network, applying a lightweight classification verification technique. The evaluation results, through a real-time demanding application, show that the proposed approach can detect up to 301 frames/sec, demanding only 9 megabytes of memory while reaching up to 89.3% of accuracy. Besides, we can increase the detection throughput by up to 10 times, with no effects on accuracy, and further increase accuracy without effects on processing demands.
Jhonatan Geremias, Altair Olivo Santin, Eduardo Viegas 0001, Alceu S. Britto Jr.
IJCNN2
2020 PPCensor: Architecture for real-time pornography detection in video streaming
Jackson Mallmann, Altair Olivo Santin, Eduardo Viegas 0001, Roger Robson dos Santos, Jhonatan Geremias
Future Gener. Comput. Syst.2
2019 BigFlow: Real-time and reliable anomaly-based intrusion detection for high-speed networks
Eduardo Viegas 0001, Altair Olivo Santin, Alysson Neves Bessani, Nuno Neves 0001
Future Gener. Comput. Syst.2
2019 SDN-based and multitenant-aware resource provisioning mechanism for cloud-based big data streaming
Cleverton Vicentini, Altair Olivo Santin, Eduardo Viegas 0001, Vilmar Abreu
J. Netw. Comput. Appl.2
2018 A Machine Learning Auditing Model for Detection of Multi-Tenancy Issues Within Tenant Domain
abstract
Cloud computing is intrinsically based on multi-tenancy, which enables a physical host to be shared amongst several tenants (customers). In this context, for several reasons, a cloud provider may overload the physical machine by hosting more tenants that it can adequately handle. In such a case, a tenant may experience application performance issues. However, the tenant is not able to identify the causes, since most cloud providers do not provide performance metrics for customer monitoring, or when they do, the metrics can be biased. This study proposes a two-tier auditing model for the identification of multi-tenancy issues within the tenant domain. Our proposal relies on machine learning techniques fed with application and virtual resource metrics, gathered within the tenant domain, for identifying overloading resources in a distributed application context. The evaluation using Apache Storm as a case study, has shown that our proposal is able to identify a node experiencing multi-tenancy interference of at least 6%, with less than 1% false-positive or false-negative rates, regardless of the affected resource. Nonetheless, our model was able to generalize the multi-tenancy interference behavior based on private cloud testbed monitoring, for different hardware configurations. Thus, a system administrator can monitor an application in a public cloud provider, without possessing any hardware-level performance metrics.
Cleverton Vicentini, Altair Olivo Santin, Eduardo Viegas 0001, Vilmar Abreu
CCGrid2
2018 Are fintechs really a hype? A machine learning-based polarity analysis of Brazilian posts on social media
abstract
Fintechs are technology companies that, in contrast to traditional banks, are engaged in digital solutions for payment, money transfers, and real-time notifications. Taking advantage of digital means of communication, most of the service interactions between fintechs and customers occurs via chats or posts in social media. In this work, our goal is to use machine learning to analyze these posts and identify what are the terms used by customers to express positive, neutral and negative customer experiences. During this analysis, we assess the following questions using data from the 3 biggest fintechs in Brazil: (i) what are the most commented topics on social media regarding fintechs, (ii) what are the words more often used by customers to express positive, negative and neutral reactions to the customer service obtained; and (iii) what kind of machine learning model should a fintech use to automatically identify whether a post is positive, negative or neutral.
Marina Ponestke Seara, Andreia Malucelli, Altair Olivo Santin, Jean Paul Barddal
INDIN3
2018 Enabling Anomaly-based Intrusion Detection Through Model Generalization
abstract
Anomaly-based intrusion detection by the means of machine learning techniques is extensively studied in the literature mainly due to its promise to detect new attacks. However, despite the promising reported results, it is hardly deployed to real world environments. The main challenge in its adoption is the discrepancy between the accuracy rates obtained during the classifier development process and the rates obtained during its use in production environments. Such a discrepancy is mainly caused by non-representative training databases and nongeneralizable (scenario-specific) classifier's model. This paper presents a method to create intrusion databases, which aims at mimicking the production environments characteristics by using well-known tools. Moreover, we present and evaluate a new validation technique, which aims at ensuring the generalization capacity of the obtained models, reached using cross-validating with different intrusion databases. The evaluation tests showed the feasibility of the proposed method. The feature selection technique ensured the model generalization capacity, improving its accuracy rate by 13%, while testing in different intrusion databases. Finally, the proposed anomaly-based approach was compared with Snort, reaching an accuracy rate of 99% against 27% of Snort for detecting DoS attacks.
Eduardo Viegas 0001, Altair Olivo Santin, Vilmar Abreu, Luiz Eduardo Soares de Oliveira
ISCC2
2018 A reliable and energy-efficient classifier combination scheme for intrusion detection in embedded systems
Eduardo Viegas 0001, Altair Olivo Santin, Luiz Oliveira 0003, André França 0001, Ricardo P. Jasinski, Volnei A. Pedroni
Comput. Secur.2
2018 A Smart Meter and Smart House Integrated to an IdM and Key-based Scheme for Providing Integral Security for a Smart Grid ICT
Vilmar Abreu, Altair Olivo Santin, Alex Xavier, Alison Lando, Adriano Witkovski, Rafael Ribeiro, Maicon Stihler, Lisandro Z. Granville, Ivan Chueiri
Mob. Networks Appl.2
2017 A Resilient Stream Learning Intrusion Detection Mechanism for Real-Time Analysis of Network Traffic
abstract
The number of novel attacks observed in networked systems increases every day. Due to the large amount of generated data over the network, its storage for further analysis may not be feasible. Moreover, current attacks are becoming more sophisticated, as the attackers are attempting to evade traditional intrusion detection mechanisms by perverting their properties. This paper presents a novel real-time (ongoing) network traffic measurement approach that supports resilient analysis for stream learning intrusion detection. The network data is grouped at runtime according to its characteristics, while each network traffic flow is discretized at regular time intervals. Each network flow is classified by a multi-view stream learning classifiers pool, defining the network flow class through a majority voting approach. The proposal is able to provide resiliency to the classifiers even for the detection of unknown attacks. The evaluation tests for the average operation point (25 views) provides an increase in the system resilience to adversarial attacks of 22 % when compared to traditional approaches. Moreover, in the scalability experiments with a 10-node (single core each) cluster testbed, the network flow measurement solution (1 view) reached 1.38 Gbps throughput, while the proposed resilient stream learning intrusion detection with 25 views reached a throughput of 1.19 Gbps.
Eduardo Viegas 0001, Altair Olivo Santin, Nuno Neves 0001, Alysson Neves Bessani, Vilmar Abreu
GLOBECOM2
2017 A multi-domain role activation model
abstract
Organizations establish partnerships in order to achieve a strategic goal. In many cases, resources in a given organization are accessed from external domains, characterizing multi-domain operations. This paper presents an approach to perform role activation in multi-domain environments. The active roles are imported in other domains from a user's home domain. Thus, a Single Role Activation (SRA) is performed, similarly to Single Sign-On (SSO) authentication. The administrative autonomy to define each role permission is kept within each local domain. We evaluated the proposal by implementing a prototype to provide support for SRA, based on RESTful web services and standardized specifications such as XACML and OpenID Connect. The prototype evaluation measured response time for simultaneous access requests, with SRA showing better results when compared to traditional role activation. Furthermore, from a security perspective, the proposal is about 15 times faster than traditional approaches.
Vilmar Abreu, Altair Olivo Santin, Eduardo Viegas 0001, Maicon Stihler
ICC2
2017 Stream learning and anomaly-based intrusion detection in the adversarial settings
abstract
Despite existing many anomaly-based intrusion detection studies in the literature, they are not frequently adopted by the industry in production environments (products). Such a usage gap occurs mainly due to the difficulty to maintain the detection rate in acceptable level, given the occurrence of false alarms. In general, the literature does not consider the adversarial settings, when an opponent attempt to evade the detection system, thus possibly rendering the system unreliable over time. In this paper, we propose and evaluate a new approach to reliably perform real time stream learning for anomaly-based intrusion detection. We employ a class-specific stream outlier detector to automatically update the intrusion detection engine over the time, and a rejection mechanism, which makes it possible to obtain indications that an evasion attempt might being happening. Furthermore, the proposal is resilient to causative attacks, providing a secure intrusion detection mechanism even when the attacker can inject misclassified instances in the training dataset. The evaluation tests show that the proposed approach is resilient to exploratory attacks, allowing the system administrator to know when an evasion attempt might be occurring.
Eduardo Viegas 0001, Altair Olivo Santin, Vilmar Abreu, Luiz Eduardo Soares de Oliveira
ISCC2
2017 Toward a reliable anomaly-based intrusion detection in real-world environments
Eduardo Viegas 0001, Altair Olivo Santin, Luiz Eduardo Soares de Oliveira
Comput. Networks2
2017 Towards an Energy-Efficient Anomaly-Based Intrusion Detection Engine for Embedded Systems
abstract
Nowadays, a significant part of all network accesses comes from embedded and battery-powered devices, which must be energy efficient. This paper demonstrates that a hardware (HW) implementation of network security algorithms can significantly reduce their energy consumption compared to an equivalent software (SW) version. The paper has four main contributions: (i) a new feature extraction algorithm, with low processing demands and suitable for hardware implementation; (ii) a feature selection method with two objectives - accuracy and energy consumption; (iii) detailed energy measurements of the feature extraction engine and three machine learning (ML) classifiers implemented in SW and HW-Decision Tree (DT), Naive-Bayes (NB), and k-Nearest Neighbors (kNN); and (iv) a detailed analysis of the tradeoffs in implementing the feature extractor and ML classifiers in SW and HW. The new feature extractor demands significantly less computational power, memory, and energy. Its SW implementation consumes only 22 percent of the energy used by a commercial product and its HW implementation only 12 percent. The dual-objective feature selection enabled an energy saving of up to 93 percent. Comparing the most energy-efficient SW implementation (new extractor and DT classifier) with an equivalent HW implementation, the HW version consumes only 5.7 percent of the energy used by the SW version.
Eduardo Viegas 0001, Altair Olivo Santin, André França 0001, Ricardo P. Jasinski, Volnei A. Pedroni, Luiz Eduardo Soares de Oliveira
IEEE Trans. Computers2
2016 On the dynamics of the RPL protocol in AMI networks under jamming attacks
abstract
The Advanced Metering Infrastructure (AMI) is a key component of the Smart Grid architecture. The Neighborhood Area Network (NAN) is the portion of the AMI that enables two-way communication between electric, gas and water meters and City Utilities. Many companies are currently deploying wireless NAN architectures based on the IEEE 802.15.4g technology while the Routing Protocol for Low-Power and Lossy Networks (RPL) has been considered as the mesh routing protocol. In this paper, we investigate the dynamics of RPL for routing path maintenance in the presence of jamming attacks. A precise interference model is implemented and tested under a fully compliant RPL draft implementation. The quality of the survivors routing paths in terms of ETX metric is investigated for different density of gateways. The results provide insights for an efficient NAN design in order to minimize the impacts of jamming attacks in the RPL performance.
Joao R. R. Renofio, Marcelo Eduardo Pellenz, Edgard Jamhour, Altair Olivo Santin, Manoel Camillo Penna, Richard Demo Souza
ICC4
2016 Insights on the resilience and capacity of AMI wireless networks
abstract
The Advanced Metering Infrastructure (AMI) is a fundamental component of the Smart Grid architecture. The AMI consists of a collection of Neighborhood Area Networks (NANs), which interconnects the smart meters to the utility company. In this paper, we address two important performance metrics regarding the NAN design, the topology's resilience and the network capacity. We propose an analysis methodology in order to determine the appropriate transmission power and the required number of gateways for wireless-enabled mesh-connected architectures. We employ a graph-theoretic approach for the analysis. Furthermore, we assume wireless NANs based on the new IEEE 802.15.4g standard. A planning tool has been implemented using software Mathematica in order to automate our approach. Simulation results show interesting tradeoffs between the performance metrics and the network design parameters, thus providing useful insights for the NAN designer.
Joao R. R. Renofio, Marcelo Eduardo Pellenz, Altair Olivo Santin, Edgard Jamhour, Manoel Camillo Penna, Richard Demo Souza
ISCC3
2015 An Approach to Deal with Processing Surges in Cloud Computing
abstract
Processing surges are fast and unexpected changes in the processing demand that commonly occur in cloud computing. The cloud elasticity enables to handle processing surges, increasing and decreasing resources as required. However, a surge can be very fast, so that the overhead to provide more resource is greater than the processing benefit. On the other hand, if the surge is slow and continuous, and the required resources are not provided, the application performance may be impaired or interrupted. This paper presents a machine learning-based approach to detect and classify processing surges, in order to improve the cloud resource management, minimizing losses for the application and cloud provider. We use a real cloud dataset to select features, to construct the classifier and to test our approach, which successfully detected and classified 99% of the processing surges.
Darlan Segalin, Altair Olivo Santin, João Eugenio Marynowski, Liandro Segalin
COMPSAC2
2015 An IdM and Key-Based Authentication Method for Providing Single Sign-On in IoT
abstract
Internet of Things (IoT) brings significant challenges to authentication schemes in a scenario with several appliances for a smart house that should be accessed by a technician for maintenance tasks, for instance. An Identity Management (IdM) can be applied to easily authenticate a technician that intend to access the appliances from the Internet. However, Internet context is significantly different from IoT, demanding context adaptation to work. Thus, integrate these contexts to allow the authentication on the Internet and provide Single Sign-On (SSO) in IoT is a challenge. The goal is to allow a technician to access an appliance that is not reachable from the Internet, using IdM and without creating a single compromising point in the gateway that links the two contexts. The proposal interacts two key-based scheme, one for Internet and another for IoT, to reach integration between both contexts. A proof-of-concept implementation shows the proposal is feasible and presents no significant overhead for messages with up to 4096 bytes and 50 appliances.
Adriano Witkovski, Altair Olivo Santin, Vilmar Abreu, João Eugenio Marynowski
GLOBECOM2
2015 The energy cost of network security: A hardware vs. software comparison
abstract
The increasing network speeds, number of attacks, and need for energy efficiency are pushing software-based network security to the limit. A common kind of threat is probing attacks, in which an attacker tries to find vulnerabilities by sending many probe packets to a target machine. In this paper, we evaluate three machine learning classifiers (Decision Tree, Naive Bayes, and k-Nearest Neighbors), implemented in hardware and software, for the detection of probing attacks. We present detailed results showing the tradeoffs between energy consumption, throughput, and accuracy of the three classifiers. The fastest hardware implementation is 926 times as fast as its software counterpart, and its energy consumption per classification is 0.05% that of the software version.
André França 0001, Ricardo P. Jasinski, Paulo Cemin, Volnei A. Pedroni, Altair Olivo Santin
ISCAS5
2015 Managing distributed UCONabc policies with authorization assertions and policy templates
abstract
Managing UCONabc policies in modern distributed computing systems is a challenge for traditional approaches. The provisioning model has trouble to keep track and to synchronize large numbers of distributed policies, outsourcing model may suffer from network overhead and single point of failure. This paper describes an approach to manage distributed UCONabc policies, derived from the combination of authorization assertions and policy templates. It combines the benefits of provisioning and outsourcing, eliminating their respective drawbacks. Prototyping details and performance evaluation are shown, messages are 42.7% smaller than provisioning and response times are faster than outsourcing.
Maicon Stihler, Altair Olivo Santin, Arlindo L. Marcon Jr.
ISCC2
2015 Method for testing the fault tolerance of MapReduce frameworks
João Eugenio Marynowski, Altair Olivo Santin, Andrey R. Pimentel
Comput. Networks2
2014 Algorithms for a distributed IDS in MANETs
Paulo Manoel Mafra, Joni da Silva Fraga, Altair Olivo Santin
J. Comput. Syst. Sci.3
2014 A (UCONABC) Resilient Authorization Evaluation for Cloud Computing
abstract
The business-driven access control used in cloud computing is not well suited for tracking fine-grained user service consumption. UCONABCapplies continuous authorization reevaluation, which requires usage accounting that enables fine-grained access control for cloud computing. However, it was not designed to work in distributed and dynamic authorization environments like those present in cloud computing. During a continuous (periodical) reevaluation, an authorization exception condition, disparity among usage accounting and authorization attributes may occur. This proposal aims to provide resilience to the UCONABCcontinuous authorization reevaluation, by dealing with individual exception conditions while maintaining a suitable access control in the cloud environment. The experiments made with a proof-of-concept prototype show a set of measurements for an application scenario (e-commerce) and allows for the identification of exception conditions in the authorization reevaluation.
Arlindo L. Marcon Jr., Altair Olivo Santin, Maicon Stihler, Juliana Bachtold
IEEE Trans. Parallel Distributed Syst.2
2011 Applying a usage control model in an operating system kernel
Rafael Teigao, Carlos Maziero, Altair Olivo Santin
J. Netw. Comput. Appl.3
2010 Octopus-IIDS: An anomaly based intelligent intrusion detection system
abstract
The intrusion detection systems (IDS) are designed to identify unwanted attempts at manipulating, accessing or disabling of computer systems, mainly through a network, such as the Internet. Additionally, the IDSs can perform other functions like intrusion prevention (IPS), including proactive functions. A recurrent problem in intrusion detection systems is the difficulty to distinguish legitimate access from attacks. A lot of conventional IDSs are signature based, although they do not identify variations of these attacks nor new attacks. This paper presents an intrusion detection system model based on the behavior of network traffic through the analysis and classification of messages. Two artificial intelligence techniques named Kohonen neural network (KNN) and support vector machine (SVM) are applied to detect anomalies. These techniques are used in sequence to improve the system accuracy, identifying known attacks and new attacks, in real time. The paper also makes an analysis of the features used to classify data in order to define which of them are really relevant for each class of attack defined in our experiments.
Paulo Manoel Mafra, Vinicius Moll, Joni da Silva Fraga, Altair Olivo Santin
ISCC4
2009 Distributed Usage Control Architecture for Business Coalitions
abstract
The dynamic environment of business coalition (BC) requires a flexible access control approach to deal with user management and policy writing. However, the traditional approach applied to BC assigns to access control a burden, mainly to the service provider, thus requiring ad hoc schemes to mitigate the lack of controls developed to BC needs. We present a brokered access control architecture, based on UCONABC, to obtain an integrated usage control management for BC. The broker intermediates contract establishment between service provider and consumer, and derives from it the policies to regulate the usage at service-level. The consumer defines user-level policies to control the usage of the contracted services. We developed a Web services based prototype to evaluate the feasibility of our proposal. The proposed architecture enables distribution of duties and integration of usage control management in a loosely coupled fashion, providing the flexibility desired in BC environments.
Maicon Stihler, Altair Olivo Santin, Alcides Calsavara, Arlindo L. Marcon Jr.
ICC2
2009 Policy control management for Web Services
abstract
The decentralization of corporate policy administration aiming to maintain the unified management of user permissions is a hard task. The heterogeneity and complexity of corporate environments burdens the security administrator with writing equally complex policies. This paper proposes an architecture based on Web Services, policy provisioning, and authorization certificates, to build up a loosely coupled unified administrative control for corporate environments. A certificate-based permission management scheme is used to derive new policies in the local domains of each branch. These new policies will update the corporate repository which, in turn, will configure the corresponding policies in the local domains of each branch. The Web Services technology provides the underlying protocols for the development of a prototype which shows the feasibility of our proposal.
Arlindo L. Marcon Jr., Altair Olivo Santin, Luiz Augusto de Paula Lima, Rafael R. Obelheiro, Maicon Stihler
Integrated Network Management2
2009 Applying quorum role in network management
abstract
This work presents a proposal for extending the Role-Based Access control (RBAC) model to support activities that demand runtime mutability in their authorization attributes. Such activities cannot be subdivided in a set of subtasks executed sequentially neither can be accomplished by a single role. The approach presented allows the creation of quorum roles, which can only be activated in a session with the endorsement of a quorum of other roles. A prototype illustrates the application of our proposal in a network management scenario. In the illustrative scenario, a previously defined set of roles, by endorsement, activates a quorum role to perform a management task without the participation of the network administrator role.
Edemilson da Silva, Altair Olivo Santin, Edgard Jamhour, Carlos Maziero, Emir Toktar
Integrated Network Management2
2007 Implementing a Peer-to-Peer Web Browser for Publishing and Searching Web Pages on Internet
abstract
This paper presents an implementation of a P2P Web browser, called Web2Peer', for publishing web pages on Internet through peer-to-peer networks. The present proposal overcomes the problems involving entities dependency and content availability, by the user side, changing the conventional way used to publish Web pages on Internet. The proposed solution allows anyone who has a computer connected to the Internet, even through domestic ADSL connection, to publish Web pages on their own machines. By using a peer-to-peer Web browser another mechanism for searching Web pages is offered based on DHT (Distributed Hash Tables). The user interface, provided by Web2Peer, carries all functions needed for creating, editing, publishing, searching, downloading and replicating the web pages on the peer-to-peer network.
Heverson Borba Ribeiro, Lau Cheuk Lung, Altair Olivo Santin, Neander Larsen Brisola
AINA3
2007 A Three-Pass Protocol for Cryptography Based on Padding for Wireless Networks
abstract
This paper proposes an alternative cryptography protocol based on padding for wireless networks. It uses an orthogonal set of rotation matrices and a three-pass exchanging protocol to reach the encryption. The communicating parties do not need to know cryptographically nothing from each other in order to guarantee the communication privacy. The security of the algorithm is based on the continuous changing of the orthogonal matrix set used on the encryption process. The proposed protocol does not require any kind of keys pre- distribution. This feature is desirable for wireless ad hoc networks, where there is no predefined infrastructure, as required on classical secure channel encryption. The prototype shows that the proposal is feasible and can be advantageous when compared to One-Time Padding.
Andre Gustavo Degraf Uchoa, Marcelo Eduardo Pellenz, Altair Olivo Santin, Carlos Maziero
CCNC3
2007 A Grammar for Specifying Usage Control Policies
abstract
Usage control goes beyond traditional access control, addressing its limitations related to attribute mutability and continuous usage permission validation. The recently proposed UCONABCmodel establishes an underlying mathematical framework to deal with the new needs of security and control systems. That model was only described by a logic specification, and this paper proposes implementing it as an LALR(1) grammar, which is defined here. The proposed grammar is then used for representing common access and usage control scenarios, showing its expressiveness and usefulness. The proposed grammar is being incorporated into a file usage control mechanism implemented on a COTS operating system.
Rafael Teigao, Carlos Maziero, Altair Olivo Santin
ICC3
2007 Web2Peer: A Peer-to-Peer Infrastructure for Publishing/Locating/Replicating Web Pages on Internet
abstract
This paper presents a decentralized infrastructure, called Web2Peer, which makes Web pages available on Internet through P2P networks. Different from the conventional Web, the proposed approach does not need, for instance, a HTTP address or a central Web Server. Web2Peer provides a set of functions for publishing, locating, and replicating Web pages on Internet ensuring high availability and fault tolerance. Our infrastructure allows anyone who has a computer connected to the Internet, even through a domestic ADSL connection, to publish Web pages through their own machines without any additional cost
Heverson Borba Ribeiro, Lau Cheuk Lung, Altair Olivo Santin, Neander Larsen Brisola
ISADS3
2003 Federation Web: A Scheme to Compound Authorization Chains on Large-Scale Distributed Systems
abstract
Traditional security systems are not easily scalable and can become single points of failure or performance bottlenecks when used on a large-scale distributed system such as the Internet. This problem occurs also when using a public key infrastructure (PKI) with a hierarchical thrust model. SDSI/SPKI is a PKI that adopts a more scalable trust paradigm, which is focused on the client and based on authorization chains. However, the task of locating the chain that links a client to a server is not completely addressed by SDSI/SPKI. Aiming to overcome this limitation, the paper proposes extensions to the SDSI/SPKI authorization and authentication model. The proposed approach introduces the concept of Federation Webs, which allows the client to build new authorization chains linking it to a server when a direct path does not exist. A prototype implementation of this proposal has shown promising results.
Altair Olivo Santin, Joni da Silva Fraga, Frank Siqueira, Emerson Ribeiro de Mello
SRDS1