Manuel Eduardo Correia

dblp:48/5437 · DBLP profile ↗
← Back
15ranked-venue papers
0as first author
5since 2021 · last 2025
0000-0002-2348-8075ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 4 · 1 since 2021Security and privacy · 4 · 2 since 2021Systems, architecture and hardware · 2Computer networks · 2Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 2Applied, interdisciplinary, general and emerging computing · 2Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2025 EVSOAR: Security Orchestration, Automation and Response via EV Charging Stations
abstract
Vehicle cybersecurity has emerged as a critical concern, driven by innovation in the automotive industry, e.g., autonomous, electric, or connected vehicles. Current efforts to address these challenges are constrained by the limited computational resources of vehicles and the reliance on connected infrastructures. This motivated the foundation of Vehicle Security Operations Centers (VSOCs) that extend IT-based Security Operations Centers (SOCs) to cover the entire automotive ecosystem, both the in-vehicle and off-vehicle scopes. Security Orchestration, Automation, and Response (SOAR) tools are considered key for implementing an effective cybersecurity solution. However, existing state-of-the-art solutions depend on infrastructure networks such as 4G, 5G, and WiFi, which often face scalability and congestion issues. To address these limitations, we propose a novel SOAR architecture EVSOAR that leverages the EV charging stations for connectivity and computing to enhance vehicle cybersecurity. Our EV-specific SOAR architecture enables real-time analysis and automated responses to cybersecurity threats closer to the EV, reducing cellular latency, bandwidth, and interference limitations. Our experimental results demonstrate a significant improvement in latency, stability, and scalability through the infrastructure and the capacity to deploy computationally intensive applications that are otherwise infeasible within the resource constraints of individual vehicles.
Tadeu Freitas, Erick Silva, Rehana Yasmin, Ali Shoker, Manuel Eduardo Correia, Rolando Martins, Paulo Veríssimo
VTC2025-Spring5
2025 A Risk Manager for Intrusion Tolerant Systems: Enhancing HAL 9000 With New Scoring and Data Sources
abstract
ABSTRACT Background Intrusion Tolerant Systems (ITS) aim to maintain system security despite adversarial presence by limiting the impact of successful attacks. Current ITS risk managers rely heavily on public databases like NVD and Exploit DB, which suffer from long delays in vulnerability evaluation, reducing system responsiveness. Objective This work extends the HAL 9000 Risk Manager to integrate additional real‐time threat intelligence sources and employ machine learning techniques to automatically predict and reassess vulnerability risk scores, addressing limitations of existing solutions. Methods A custom‐built scraper collects diverse cybersecurity data from multiple Open Source Intelligence (OSINT) platforms, such as NVD, CVE, AlienVault OTX, and OSV. HAL 9000 uses machine learning models for CVE score prediction, vulnerability clustering through scalable algorithms, and reassessment incorporating exploit likelihood and patch availability to dynamically evaluate system configurations. Results Integration of newly scraped data significantly enhances the risk management capabilities, enabling faster detection and mitigation of emerging vulnerabilities with improved resilience and security. Experiments show HAL 9000 provides lower risk and more resilient configurations compared to prior methods while maintaining scalability and automation. Conclusions The proposed enhancements position HAL 9000 as a next‐generation autonomous Risk Manager capable of effectively incorporating diverse intelligence sources and machine learning to improve ITS security posture in dynamic threat environments. Future work includes expanding data sources, addressing misinformation risks, and real‐world deployments.
Tadeu Freitas, Carlos Novo, Inês de Castro Dutra, João Soares 0003, Manuel Eduardo Correia, Benham Shariati, Rolando Martins
Softw. Pract. Exp.5
2023 Deterministic or probabilistic? - A survey on Byzantine fault tolerant state machine replication
abstract
Byzantine Fault tolerant (BFT) protocols are implemented to guarantee the correct system/application behavior even in the presence of arbitrary faults (i.e., Byzantine faults). Byzantine Fault tolerant State Machine Replication (BFT-SMR) is a known software solution for masking arbitrary faults and malicious attacks (Liu et al., 2020). In this survey, we present and discuss relevant BFT-SMR protocols, focusing on deterministic and probabilistic approaches. The main purpose of this paper is to discuss the characteristics of proposed works for each approach, as well as identify the trade-offs for each different approach.
Tadeu Freitas, João Soares 0003, Manuel Eduardo Correia, Rolando Martins
Comput. Secur.3
2022 A Decentralised Real Estate Transfer Verification based on Self-Sovereign Identity and Smart Contracts
Abubakar-Sadiq Shehu, António Pinto, Manuel Eduardo Correia
SECRYPT3
2021 Forensic Analysis of Tampered Digital Photos
Sara Ferreira, Mário Antunes 0002, Manuel Eduardo Correia
CIARP3
2019 Security and Fairness in IoT Based e-Health System: A Case Study of Mobile Edge-Clouds
abstract
Through IoT, humans and objects can be connected seamlessly, to guaranty improved quality of service (QoS). IoT-driven e-Health systems benefit from such rich network setting, to transmit health information and deliver health services. It is expected to grow massively in scale, but for that to happen, several issues need to be addressed, including security and trust. Edge computing paradigms, such as Fog computing and Cloudlet, are already popular in IoT based e-Health domain. Fog nodes are leveraged to reduce latency between IoT devices and remote cloud computing infrastructure. In this work, we explain how Mobile edge-clouds, which is a less popular edge computing paradigm, can be employed to achieve similar or lower latency, at a lower cost. We also propose a lightweight mechanism for security and fairness in e-Health protocols that are based on mobile edge-clouds and other paradigms. Detailed simulation experiments show that the proposed method is scalable and can efficiently mitigate attacks that are targeted at e-Health information and the network.
Francis N. Nwebonyi, Rolando Martins, Manuel Eduardo Correia
WiMob3
2019 Iris: Secure reliable live-streaming with opportunistic mobile edge cloud offloading
Rolando Martins, Manuel Eduardo Correia, Luis Filipe Coelho Antunes, Fernando M. A. Silva
Future Gener. Comput. Syst.2
2019 Reputation based approach for improved fairness and robustness in P2P protocols
Francis N. Nwebonyi, Rolando Martins, Manuel Eduardo Correia
Peer-to-Peer Netw. Appl.3
2018 Reputation-Based Security System For Edge Computing
abstract
Given the centralized architecture of cloud computing, there is a genuine concern about its ability to adequately cope with the demands of connecting devices which are sharply increasing in number and capacity. This has led to the emergence of edge computing technologies, including but not limited to mobile edge-clouds. As a branch of Peer-to-Peer (P2P) networks, mobile edge-clouds inherits disturbing security concerns which have not been adequately addressed in previous methods. P2P security systems have featured many trust-based methods owing to their suitability and cost advantage, but these approaches still lack in a number of ways. They mostly focus on protecting client nodes from malicious service providers, but downplay the security of service provider nodes, thereby creating potential loopholes for bandwidth attack. Similarly, trust bootstrapping is often via default scores, or based on heuristics that does not reflect the identity of a newcomer. This work has patched these inherent loopholes and improved fairness among participating peers. The use cases of mobile edge-clouds have been particularly considered and a scalable reputation based security mechanism was derived to suit them. BitTorrent protocol was modified to form a suitable test bed, using Peersim simulator. The proposed method was compared to some related methods in the literature through detailed simulations. Results show that the new method can foster trust and significantly improve network security, in comparison to previous similar systems.
Francis N. Nwebonyi, Rolando Martins, Manuel Eduardo Correia
ARES3
2018 Are Deep Learning Methods Ready for Prime Time in Fingerprints Minutiae Extraction?
Ana Rebelo, Tiago Oliveira 0004, Manuel Eduardo Correia, Jaime S. Cardoso 0001
CIARP3
2013 Physician's awareness of e-prescribing security risks
abstract
New governmental legislation introduced e-prescription as mandatory in the Portuguese health system. This changes consequences were not properly considered, which caused security problems related to patient and prescriber's data, such as digital identity fraud or access to prescriptions history to build clinical profiles. In order to evaluate the e-prescribing software users awareness to those risks, a survey took place, and the results revealed ignorance of certain obligations and procedures of the e-prescribing process. A significant part of doctors are not conscious about where the patient's data is stored neither about the risks related with prescription's information.
Luis Filipe Coelho Antunes, Cristina Costa-Santos, Manuel Eduardo Correia, Tiago Miguel Pinho, Hilario Gil Magalhaes
CBMS4
2013 A secure RBAC mobile agent access control model for healthcare institutions
abstract
In medical organizations, healthcare providers need to have fast access to patients' medical information in order to make accurate diagnoses as well as to provide appropriate treatments. Efficient healthcare is thus highly dependent on doctors being provided with access to patients' medical information at the right time and place. However it frequently happens that critical pieces of pertinent information end up not being used because they are located in information systems that do not inter-operate in a timely manner. Unfortunately the standard operational mode for many healthcare applications, and even healthcare institutions, is to be managed and operated as isolated islands that do not share information in an efficient manner. There are many reasons that contribute to this grim state of affairs, but what interests us the most is the lack of enforceable security policies for systems interoperability and data exchange and the existence of many heterogeneous legacy systems that are almost impossible to directly include into any reasonable secure interoperable workflow. In this paper we propose a RBAC mobile agent access control model supported by a specially managed public key infrastructure for mobile agent's strong authentication and access control. Our aim is to create the right means for doctors to be provided with timely accurate information, which would be otherwise inaccessible, by the means of strongly authenticated mobile agents capable of securely bridging otherwise isolated institutional eHealth domains and legacy applications.
Cátia Santos-Pereira, Alexandre B. Augusto, Ricardo João Cruz Correia, Manuel Eduardo Correia
CBMS4
2012 OFELIA - A Secure Mobile Attribute Aggregation Infrastructure for User-Centric Identity Management
Alexandre B. Augusto, Manuel Eduardo Correia
SEC2
2007 Storage and retrieval on P2P networks: A DHT based protocol
abstract
In this paper we present the development, implementation and simulation of a simple Distributed Hash Table (DHT) protocol for a Peer to peer (P2P) overlay network inspired by small world [3, 2] concepts. Our simulation and implementation, done on the Peersim [10] Java network simulator, showed results consistent with other state of the art DHT implementations with a more simple and pragmatic approach for the graph construction algorithm. We present the results of simulating this protocol on large P2P networks and compare them with the results obtained in Symphony [14], another small world inspired DHT.
Sergio Bessa, Manuel Eduardo Correia, Pedro Brandão
ISCC2
1999 DAOS - Scalable And-Or Parallelism
Luís Fernando Castro, Vítor Santos Costa, Cláudio Fernando Resin Geyer, Fernando M. A. Silva, Patrícia Kayser Vargas, Manuel Eduardo Correia
Euro-Par6