VLDB 2026 Research / reviewers in the wild / expert
Ricardo Dahab
dblp:79/6780
· DBLP profile ↗
30ranked-venue papers
1as first author
2since 2021 · last 2023
0000-0002-7002-875XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12Theory of computation · 4 · 1 since 2021Systems, architecture and hardware · 2 · 1 first-authorComputer networks · 2Software engineering, systems software and programming languages · 2Graphics, computer vision, multimedia, augmented reality and games · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Detecting Cryptography Misuses With Machine Learning: Graph Embeddings, Transfer Learning and Data Augmentation in Source Code Related TasksabstractCryptography is a ubiquitous tool in secure software development in order to guarantee security requirements in general. However, software developers have scarce knowledge about cryptography and rely on limited support tools that cannot properly detect bad uses of cryptography, thus generating vulnerabilities in software. In this work, we extend the scarcely use of machine learning to detect cryptography misuse in source code by using a state of the art deep learning model (i.e.,code2vec) through transfer learning to generate features that feed machine learning models. In addition, we compare this approach to previous ones in different types of binary models. Also, we adapt code obfuscation to serve as data augmentation in machine learning source code related tasks. Finally, we show that through transfer learningcode2veccan be a competitive feature generator for cryptography misuse detection and simple code obfuscation can be used to generate data to enhance machine learning models training in source code related tasks. Gustavo Eloi de Paula Rodrigues, Alexandre Melo Braga, Ricardo Dahab |
IEEE Trans. Reliab. | 3 |
| 2021 | Tutte's 3-flow Conjecture for almost even graphsabstractA 3-flow for a graph G is an assignment of directions and weights in {1, 2} to the edges of G, such that the netsum of weights on the edges incident to every vertex of G is equal to zero (weights on incoming and outgoing edges are added with opposite signs). Not every graph admits a 3-flow. Aside from graphs with an edge cut of size one, K4 is the simplest graph that does not admit a 3-flow. Tutte’s famous 3-flow Conjecture postulates that every 2-edge-connected graph without edge cuts of size three (3-cuts) admits a 3-flow. A slightly stronger form of this conjecture allows up to three 3-cuts. In this work, our objective is to study classes of graphs with up to four 3-cuts, in fact four vertices of degree three (3-vertices), that admit a 3-flow. We focus on almost even graphs, i.e., graphs with a small number of odd vertices. We obtain a characterization for graphs with up to four odd vertices. We also obtain partial characterizations for graphs with up to four 3-vertices and two odd vertices of higher degree. As expected, 3-vertices play a central role in blocking the existence of 3-flows. Our attempt at understanding this role is motivated by the need to allow a small number of additional 3-vertices in inductive proofs of restricted forms of Tutte’s Conjecture. Léo Vieira Peres, Ricardo Dahab |
LAGOS | 2 |
| 2020 | Using Graph Embeddings and Machine Learning to Detect Cryptography Misuse in Source CodeabstractCryptography is an essential aspect of software development. Nevertheless, software developers have limited knowledge of cryptography primitives, and support tools are limited. In this work, we present a comparison between graph embedding techniques, node2vec and Bag of Graphs, as embedding generators of source code graph representations. We combined these techniques with machine learning models in order to detect cryptography misuses in source codes. We show that Bag of Graphs outperforms node2vec in this task; also, both techniques outperform previously evaluated tools. Gustavo Eloi de Paula Rodrigues, Alexandre Melo Braga, Ricardo Dahab |
ICMLA | 3 |
| 2019 | High-performance Implementation of Elliptic Curve Cryptography Using Vector InstructionsabstractElliptic curve cryptosystems are considered an efficient alternative to conventional systems such as DSA and RSA. Recently, Montgomery and Edwards elliptic curves have been used to implement cryptosystems. In particular, the elliptic curves Curve25519 and Curve448 were used for instantiating Diffie-Hellman protocols named X25519 and X448. Mapping these curves to twisted Edwards curves allowed deriving two new signature instances, called Ed25519 and Ed448, of the Edwards Digital Signature Algorithm. In this work, we focus on the secure and efficient software implementation of these algorithms using SIMD parallel processing. We present software techniques that target the Intel AVX2 vector instruction set for accelerating prime field arithmetic and elliptic curve operations. Our contributions result in a high-performance software library for AVX2-ready processors. For example, our library computes digital signatures 19% (for Ed25519) and 29% (for Ed448) faster than previous optimized implementations. Also, our library improves by 10% and 20% the execution time of X25519 and X448, respectively. Armando Faz-Hernández, Julio López 0002, Ricardo Dahab |
ACM Trans. Math. Softw. | 3 |
| 2019 | Understanding How to Use Static Analysis Tools for Detecting Cryptography Misuse in SoftwareabstractThe use of cryptography is nowadays common in software systems, with cryptographic libraries widely available to software developers. As such, the likely weakest link in sensitive software has moved from cryptographic function implementations to the application code surrounding such functions. Ordinary developers usually lack knowledge in practical cryptography, and support from specialists is rare. Frequently, these difficulties are addressed by running static analysis tools to automatically detect cryptography misuse during coding and reviews. However, the effectiveness of such tools is not yet well understood. This article studies how well programmatic misuse of cryptography is detected by free static code analysis tools. The performance of such tools in detecting misuse is correlated to coding tasks and use cases commonly found in development efforts; also, cryptography misuse is classified in comprehensive categories, easily recognizable by software security practitioners. Our research shows that the coverage of public-key cryptography by static code analysis tools is full of blind spots, because tools prioritize only those misuses related to the most frequent coding tasks and use cases, while neglecting infrequent use cases. We found that, in addition to a relatively low recall in our tests, evaluated tools also have a small overlap regarding the misuses detected by all the evaluated tools, as well as an intersection of false alarms, suggesting lack of discrimination between specific misuses and corresponding good uses of cryptography. In spite of that, well-selected tools can be useful when developing cryptographic software, but support of experts is still required for solving complex cases. Alexandre Melo Braga, Ricardo Dahab, Nuno Antunes, Nuno Laranjeiro, Marco Vieira |
IEEE Trans. Reliab. | 2 |
| 2018 | Leveraging ontologies and machine-learning techniques for malware analysis into Android permissions ecosystems
Luiz C. Navarro, Alexandre K. W. Navarro, André Ricardo Abed Grégio, Anderson Rocha 0001, Ricardo Dahab |
Comput. Secur. | 5 |
| 2018 | Connecting the dots: Toward accountable machine-learning printer attribution methods
Luiz C. Navarro, Alexandre K. W. Navarro, Anderson Rocha 0001, Ricardo Dahab |
J. Vis. Commun. Image Represent. | 4 |
| 2017 | Practical Evaluation of Static Analysis Tools for Cryptography: Benchmarking Method and Case StudyabstractThe incorrect use of cryptography is a common source of critical software vulnerabilities. As developers lack knowledge in applied cryptography and support from experts is scarce, this situation is frequently addressed by adopting static code analysis tools to automatically detect cryptography misuse during coding and reviews, even if the effectiveness of such tools is far from being well understood. This paper proposes a method for benchmarking static code analysis tools for the detection of cryptography misuse, and evaluates the method in a case study, with the goal of selecting the most adequate tools for specific development contexts. Our method classifies cryptography misuse in nine categories recognized by developers (weak cryptography, poor key management, bad randomness, etc.) and provides the workload, metrics and procedure needed for a fair assessment and comparison of tools. We found that all evaluated tools together detected only 35% of cryptography misuses in our tests. Furthermore, none of the evaluated tools detected insecure elliptic curves, weak parameters in key agreement, and most insecure configurations for RSA and ECDSA. This suggests cryptography misuse is underestimated by tool builders. Despite that, we show that it is possible to benefit from an adequate tool selection during the development of cryptographic software. Alexandre Melo Braga, Ricardo Dahab, Nuno Antunes, Nuno Laranjeiro, Marco Vieira |
ISSRE | 2 |
| 2015 | Hardware Security Evaluation Using Assurance Case ModelsabstractThe security of computing systems relies heavily on their hardware architecture. Currently, hardware is evaluated using mostly manual processes that are prone to errors, and generate a large, complex workload. In this paper, we are the first to report the use of the Assurance Case methodology to guide a hardware architecture security analysis. We were able to analyze real-world systems, and to detect known and some possibly unknown vulnerabilities. We also show that, by employing Assurance Cases, other benefits are gained, such as better security analysis coverage and better documentation of the security-relevant aspects of the system. Henrique Kawakami, Roberto Gallo, Ricardo Dahab, Erick Nascimento 0002 |
ARES | 3 |
| 2015 | Security and system architecture: comparison of Android customizationsabstractSmartphone manufacturers frequently customize Android distributions so as to create competitive advantages by adding, removing and modifying packages and configurations. In this paper we show that such modifications have deep architectural implications for security. We analysed five different distributions: Google Nexus 4, Google Nexus 5, Sony Z1, Samsung Galaxy S4 and Samsung Galaxy S5, all running OS versions 4.4.X (except for Samsung S4 running version 4.3). Our conclusions indicate that serious security issues such as expanded attack surface and poorer permission control grow sharply with the level of customization. Roberto Gallo, Patricia Hongo, Ricardo Dahab, Luiz C. Navarro, Henrique Kawakami, Kaio Galvão, Glauco Barroso Junquera, Luander Ribeiro |
WISEC | 3 |
| 2013 | FORTUNA - A framework for the design and development of hardware-based secure systems
Roberto Gallo, Henrique Kawakami, Ricardo Dahab |
J. Syst. Softw. | 3 |
| 2011 | LWE-based identification schemesabstractSome hard problems from lattices, like LWE (Learning with Errors), are particularly suitable for application in Cryptography due to the possibility of using worst-case to average-case reductions as evidence of strong security properties. In this work, we show two LWE-based constructions of zero-knowledge identification schemes and discuss their performance and security. We also highlight the design choices that make our solution of both theoretical and practical interest. Rosemberg Silva, Antonio C. de A. Campello Jr., Ricardo Dahab |
ITW | 3 |
| 2011 | FORTUNA - A probabilistic framework for early design stages of hardware-based secure systemsabstractThis paper introduces FORTUNA, a probabilistic framework that supports the conception and early design stages of hardware-based secure systems. FORTUNA can point out potential weaknesses of complex systems, involving physical and logical attacks, basic human interaction or even a few classes of unknown threats. FORTUNA consists of two main elements: a) a logical-probabilistic theoretic model in which quantitative and qualitative security assessments of hardware-based systems can be done; and b) a semiautomatic tool, based on the proposed model, that can assist secure system designing from the very initial development stages. To the best of our knowledge, FORTUNA is the first framework (and tool) to support such a broad scope of interactions and also the first aimed at the conception and early design phases of hardware-based systems. Other contributions include a proof of the “policy of least privileges” under our model and an example of use of the framework in the design of a secure microprocessor. Roberto Gallo, Henrique Kawakami, Ricardo Dahab |
NSS | 3 |
| 2011 | E-Commerce and Fair Exchange - The Problem of Item Validation
Fabio Piva, Ricardo Dahab |
SECRYPT | 2 |
| 2011 | TinyPBC: Pairings for authenticated identity-based non-interactive key distribution in sensor networks
Leonardo B. Oliveira, Diego F. Aranha, Conrado Porto Lopes Gouvêa, Michael Scott, Danilo F. Câmara, Julio López 0002, Ricardo Dahab |
Comput. Commun. | 7 |
| 2010 | T-DRE: a hardware trusted computing base for direct recording electronic vote machinesabstractWe present a hardware trusted computing base (TCB) aimed at Direct Recording Voting Machines (T-DRE), with novel design features concerning vote privacy, device verifiability, signed-code execution and device resilience. Our proposal is largely compliant with the VVSG (Voluntary Voting System Guidelines), while also strengthening some of its rec-comendations. To the best of our knowledge, T-DRE is the first architecture to employ multi-level, certification-based, hardware-enforced privileges to the running software. T-DRE also makes a solid case for the feasibility of strong security systems: it is the basis of 165,000 voting machines, set to be used in a large upcoming national election. In short, our contribution is a viable computational trusted base for both modern and classical voting protocols. Roberto Gallo, Henrique Kawakami, Ricardo Dahab, Rafael Azevedo, Saulo Lima, Guido Araujo |
ACSAC | 3 |
| 2009 | SB-RAWVec - A Semi-Blind Watermarking Method for Vector MapsabstractRAWVec is a private watermarking method for vector maps that uses a raster image as watermark. Visually recognizable watermarks can add extra information like integrity and authentication, while blind watermarks do not need the original data to be published for the detection. This work presents a semi-blind version of RAWVec, i.e. a method that uses the original vector map during the detection without revealing it, but maintains the watermark as a raster image. Karina Mochetti, Ricardo Dahab |
ICC | 2 |
| 2008 | NanoECC: Testing the Limits of Elliptic Curve Cryptography in Sensor Networks
Piotr Szczechowiak, Leonardo B. Oliveira, Michael Scott, Martin Collier, Ricardo Dahab |
EWSN | 5 |
| 2007 | TinyTate: Computing the Tate Pairing in Resource-Constrained Sensor NodesabstractAfter a few years of intense research, wireless sensor networks (WSNs) still demand new secure and cryptographic schemes. On the other hand, the advent of cryptography from pairings has enabled a wide range of novel cryptosystems. In this work we present TinyTate, the first known implementation of pairings for sensor nodes based on the 8-bit/7.3828-MHz ATmega128L microcontroller (e.g., MICA2 and MICAz motes). We then conclude that cryptography from pairings is indeed viable in resource-constrained nodes. Leonardo B. Oliveira, Diego F. Aranha, Eduardo Morais, Felipe Daguano, Julio López 0002, Ricardo Dahab |
NCA | 6 |
| 2007 | Implementing Cryptographic Pairings over Barreto-Naehrig Curves
Augusto Jun Devegili, Michael Scott, Ricardo Dahab |
Pairing | 3 |
| 2007 | Two Notes on the Security of Certificateless Signatures
Rafael Castro, Ricardo Dahab |
ProvSec | 2 |
| 2007 | SecLEACH - On the security of clustered sensor networks
Leonardo B. Oliveira, Adrian Carlos Ferreira, Marcos Aurélio Vilaça, Hao Chi Wong, Marshall W. Bern, Ricardo Dahab, Antonio Alfredo Ferreira Loureiro |
Signal Process. | 6 |
| 2006 | New Point Compression Algorithms for Binary CurvesabstractThis paper presents two new algorithms for point compression for elliptic curves defined over F2m, m odd. The first algorithm works for curves with Tr(a) = 1 and offers computational advantages over previous methods. The second algorithm is based on the λ representation of an elliptic point. The proposed algorithms require m bits to compress an elliptic point and can be used for all random binary curves recommended by NIST. Julio López 0002, Ricardo Dahab |
ITW | 2 |
| 2006 | SecLEACH - A Random Key Distribution Solution for Securing Clustered Sensor NetworksabstractClustered sensor networks have been shown to increase system throughput, decrease system delay, and save energy. While those with rotating cluster heads, such as LEACH, have also advantages in terms of security, the dynamic nature of their communication makes most existing security solutions inadequate for them. In this paper, we show how random key predistribution, widely studied in the context of flat networks, can be used to secure communication in hierarchical (cluster-based) protocols such as LEACH. To our knowledge, it is the first work that investigates random key predistribution as applied to hierarchical WSNs Leonardo B. Oliveira, Hao Chi Wong, Marshall W. Bern, Ricardo Dahab, Antonio Alfredo Ferreira Loureiro |
NCA | 4 |
| 2006 | Software Multiplication Using Gaussian Normal BasesabstractFast algorithms for multiplication in finite fields are required for several cryptographic applications, in particular for implementing elliptic curve operations over binary fields F/sub 2m/. In this paper, we present new software algorithms for efficient multiplication over F/sub 2m/ that use a Gaussian normal basis representation. Two approaches are presented, direct normal basis multiplication and a method that exploits a mapping to a ring where fast polynomial-based techniques can be employed. Our analysis, including experimental results on an Intel Pentium family processor, shows that the new algorithms are faster and can use memory more efficiently than previous methods. Despite significant improvements, we conclude that the penalty in multiplication is still sufficiently large to discourage the use of normal bases in software implementations of elliptic curve systems. Ricardo Dahab, Darrel Hankerson, Men Long, Julio López 0002, Alfred Menezes |
IEEE Trans. Computers | 1 |
| 2005 | A custom instruction approach for hardware and software implementations of finite field arithmetic over F263 using Gaussian normal bases
Marcio Juliato, Guido Araujo, Julio López 0002, Ricardo Dahab |
FPT | 4 |
| 2002 | An Attack on a Protocol for Certified Delivery
José R. M. Monteiro, Ricardo Dahab |
ISC | 2 |
| 1999 | Fast Multiplication on Elliptic Curves over GF(2m) without Precomputation
Julio López 0002, Ricardo Dahab |
CHES | 2 |
| 1998 | A Scheme for Analyzing Electronic Payment SystemsabstractThe paper presents a scheme for the design, analysis and comparison of electronic payment systems. Three systems are described in detail through this scheme. PayWord is a micro payment system designed by R. Rivest and A. Shamir (1995). It is efficient for repeated payments to the same vendor, and is designed to reduce the use of public key algorithms through the use of hash functions and fast symmetric ciphers. Digicash's E-cash is one of the most popular electronic payment systems in use today. It is an Internet based system with full user anonymity by the use of blind signatures (D. Chaum, 1982). The central authority must apply a signature on a blinded user generated token. The Internet Keyed Protocol was designed by IBM's research labs. It is an adequate system for transactions using credit cards or account numbers on open networks, such as the Internet. iKP (P. Janson and M. Waidner, 1996) is in reality, a system that may be used to securely transmit account numbers on the Internet. Lucas C. Ferreira, Ricardo Dahab |
ACSAC | 2 |
| 1998 | Improved Algorithms for Elliptic Curve Arithmetic in GF(2n)
Julio López 0002, Ricardo Dahab |
Selected Areas in Cryptography | 2 |