VLDB 2026 Research / reviewers in the wild / expert
Morteza Noferesti
dblp:82/10462
· DBLP profile ↗
8ranked-venue papers
5as first author
5since 2021 · last 2026
0009-0000-5507-1461ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 5 · 3 first-author · 4 since 2021Security and privacy · 2 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | B-Perf: Black-box Performance Antipattern Detection Using System-level Execution TracingabstractPerformance antipatterns capture recurring behaviours that degrade software efficiency. Black-box approaches aim to detect such issues without modifying the application. This paper presents B-Perf, a system-level black-box method that reconstructs execution, memory, and messaging behaviour from kernel-level traces. By analysing scheduling, allocation, and communication events, B-Perf derives workload-dependent behavioural trends and reports antipattern indicators grounded in resource usage and contention. To handle large trace volumes, the approach follows a pipeline of workload generation, event gathering, trace handling, and antipattern inference. Morteza Noferesti, Mahsa Panahandeh, Naser Ezzati-Jivan |
ICPE | 1 |
| 2026 | LMAT: An adaptive tracing approach based on efficient system behavior analysis using language modelsabstractWe introduce LMAT, a Language Model-based Adaptive Tracing framework designed for host-level observability that provides granular monitoring without excessive overhead. LMAT leverages a multi-task architecture to jointly predict kernel event sequences and classify event durations, thereby capturing both control-flow and temporal dynamics. By continuously comparing live trace data against model predictions, LMAT automatically signals deviations, dynamically adjusting trace granularity only when needed. This approach significantly reduces trace volume, along with associated energy and storage costs, achieving a 70.6% reduction in our experiments. Additionally, LMAT utilizes prediction discrepancies to drive an efficient root-cause classifier, mapping detected anomalies directly to their potential fault sources and providing actionable feedback for operations teams. We evaluate LMAT on two architecturally distinct single-host environments—an Apache2 web-server stack and the Sock Shop containerized microservice benchmark—using kernel traces that include standard workloads, duration-centric noise scenarios, and controlled CPU, disk, memory, and network stress injections. On the Apache workload, LMAT demonstrates up to 97.7% accuracy in anomaly detection and root-cause identification, surpassing state-of-the-art methods relying solely on event sequences. On Sock Shop, the same design remains effective for host-local change detection, while root-cause attribution in the microservice setting remains more challenging. A deployment-oriented overhead study shows that under a stable load, asynchronous LMAT inference introduces no measurable additional tail-latency overhead beyond tracing, while maintaining consistent throughput. Our findings illustrate that LMAT is a practical approach for adaptive tracing in the evaluated single-host environments, improving detection quality while keeping deployment overhead negligible. Kasra Darvishi, Morteza Noferesti, Yuvraj Sehgal, Naser Ezzati-Jivan |
J. Syst. Softw. | 2 |
| 2024 | Enhancing empirical software performance engineering research with kernel-level events: A comprehensive system tracing approach
Morteza Noferesti, Naser Ezzati-Jivan |
J. Syst. Softw. | 1 |
| 2023 | PASD: A Performance Analysis Approach Through the Statistical Debugging of Kernel EventsabstractDynamic performance analysis plays a crucial role in optimizing systems and identifying performance bottlenecks. Traditional software debugging methods frequently encounter difficulties when trying to pinpoint performance problems in complex software settings. This is often because performance issues remain hidden during the code execution within debugging tools or under certain run-time circumstances, making them challenging to identify and address. This paper introduces PASD (Performance Analysis through Statistical Debugging), a dynamic performance analysis approach based on statistical debugging of kernel-level trace events. Importantly, this approach requires no application code instrumentation and purely utilizes operating system kernel trace events for analysis. PASD collects kernel trace events generated during software execution and utilizes heuristics to analyze their performance issues and the root-causes. Through statistical debugging techniques, PASD identifies the most important functions correlated with performance problems. It notably does so without disrupting the software’s normal functions and ensuring that any issues are detected in the software’s typical operating conditions, thus avoiding additional complexity in the debugging process. We have conducted two empirical studies to assess the effectiveness of PASD on performance issues in the Firefox web browser as well as the ‘ls’ tool (a common utility in Unix-like systems). Our experiments demonstrate that PASD successfully identifies performance issues and their causes in software without prior knowledge of the architecture or source code instrumentation. By providing an overview of software behavior through the kernel-level, our proposed method can aid developers and testers in quickly pinpointing performance problems in the source code. This, in turn, can result in improved software quality, increased user satisfaction, and the prevention of critical system failures. Mohammed Adib Khan, Morteza Noferesti, Naser Ezzati-Jivan |
SCAM | 2 |
| 2023 | EMD-SCS: A Dynamic Behavioral Approach for Early Malware Detection with Sonification of System Call SequencesabstractThe privacy and security of users are increasingly threatened due to the rising frequency of malware assaults. Both Host-based Intrusion Detection Systems (HIDSes) and Antivirus software rely on signature-based or anomaly-based techniques for malware detection. However, the escalating diversity and sophistication of malware pose significant obstacles. In this research, we introduce EMD-SCS, an early malware detection methodology, employing sonification and system call sequence analysis. In our methodology, we interpret an executing program/process as a sequence of system calls, leveraging a Long Short-Term Memory network (LSTM) to hold a record of preceding system calls within this chain, consequently facilitating the prediction of future calls. After this prediction phase, the BLEU and hamming distance scores are utilized to classify the system call sequence. Importantly, these results are attained by analyzing just a small segment of the data for early prediction, which is crucial for a sonification-based approach as it enables us to notify administrators in advance of potential threats. This early warning system would allow admins to protect the host before a potential compromise. EMD-SCS uses sonification to convey the prediction outcomes using natural and animal sounds, offering a broader monitoring scope than visual observation. Evaluation results from the ADFA-LD dataset suggest that EMD-SCS surpasses prior techniques in early malware detection with an accuracy of 91.2%, a detection rate of 87.7%, and a false-positive rate of 15.3%, achieved by only processing 40% of the input system call sequences before they infiltrate the host. Raghav Bhardwaj, Morteza Noferesti, Madeline Janecek, Naser Ezzati-Jivan |
TrustCom | 2 |
| 2020 | ACoPE: An adaptive semi-supervised learning approach for complex-policy enforcement in high-bandwidth networks
Morteza Noferesti, Rasool Jalili |
Comput. Networks | 1 |
| 2019 | Inline high-bandwidth network analysis using a robust stream clustering algorithmabstractHigh‐bandwidth network analysis is challenging, resource consuming, and inaccurate due to the high volume, velocity, and variety characteristics of the network traffic. The infinite stream of incoming traffic forms a dynamic environment with unexpected changes, which requires analysing approaches to satisfy the high‐bandwidth network processing challenges such as incremental learning, inline processing, and outlier handling. This study proposes an inline high‐bandwidth network stream clustering algorithm designed to incrementally mine large amounts of continuously transmitting network traffic when some outliers can be dropped before determining the network traffic behaviour. Maintaining extended‐meta‐events as abstracting data structures over a sliding window, enriches the algorithm to address the high‐bandwidth network processing challenges. Evaluating the algorithm indicates its robustness, efficiency, and accuracy in analysing high‐bandwidth networks. Morteza Noferesti, Rasool Jalili |
IET Inf. Secur. | 1 |
| 2017 | HB2DS: A behavior-driven high-bandwidth network mining system
Morteza Noferesti, Rasool Jalili |
J. Syst. Softw. | 1 |