VLDB 2026 Research / reviewers in the wild / expert
Rafael R. Obelheiro
dblp:91/1540 · also Rafael Rodrigues Obelheiro
· DBLP profile ↗
16ranked-venue papers
2as first author
8since 2021 · last 2026
0000-0002-4014-6691ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 1 first-author · 5 since 2021Computer networks · 5 · 3 since 2021Software engineering, systems software and programming languages · 3 · 1 first-authorArtificial intelligence and machine learning · 1Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fast and Effective Syscall-Based IDS with Categories
Diogo Bortolini, Rafael R. Obelheiro, Carlos Maziero |
SECRYPT (1) | 2 |
| 2026 | Lessons from an (Unsuccessful?) IPv6 Amplification Honeypot DeploymentabstractWhile DRDoS attacks are well-understood in IPv4, it is not known to what extend attackers also make use of services on the IPv6 Internet to perform DRDoS attacks.In this work, we adapted an IPv4-only DRDoS honeypot to observe DRDoS attacks in IPv6.To attract scanners, we publicized our honeypots' addresses on the TUM IPv6 Hitlist.After one year of data collection, however, we observed little to no attackers exploiting IPv6 UDP services for DRDoS attacks.This paper presents our setup, findings, and the lessons learned from trying attract scanners to our DRDoS honeypot: we analyze the interactions we observed over time as well as the source addresses of scanners, and discuss how our choice of the IPv6 Hitlist as an address exposure method possibly impacted our findings.Although we managed to attract several scanners also observed by previous work, our results show that there are currently no attackers performing DRDoS attacks in IPv6, at least among these that rely on the IPv6 Hitlist to discover vulnerable hots. Tiago Heinrich, Sebastian Kappes, Rafael R. Obelheiro |
SIGCOMM | 3 |
| 2024 | Anywhere on Earth: A Look at Regional Characteristics of DRDoS Attacks
Tiago Heinrich, Newton Carlos Will, Rafael R. Obelheiro, Carlos Maziero |
ICISSP | 3 |
| 2024 | A Categorical Data Approach for Anomaly Detection in WebAssembly Applications
Tiago Heinrich, Newton Carlos Will, Rafael R. Obelheiro, Carlos Maziero |
ICISSP | 3 |
| 2024 | I See Syscalls by the Seashore: An Anomaly-based IDS for Containers Leveraging Sysdig DataabstractIntrusion detection in virtualized environments is vital due to the widespread adoption of virtualization technology. A common strategy for achieving this task involves collecting data from the virtual environment and providing it to intrusion detection solutions. However, these solutions can be affected by other elements present in the virtual environment. An approach that has gained prominence is applying machine learning (ML) models to perform anomaly-based intrusion detection based on system call traces. In Linux-based environments, many tools can be used for collecting the system calls issued by processes and containers; two of the most popular are strace and sysdig. This paper introduces a dataset of system call traces collected with sysdig with a focus on anomaly-based intrusion detection for containerized applications and uses this dataset to compare the effectiveness of strace and sysdig data and evaluate the performance of five different ML models for anomaly detection. The results reveal that sysdig is an attractive option, enabling the collection of system call traces with lower overhead than strace while achieving good detection performance with several ML models. Anderson Aparecido do Carmo Frasão, Tiago Heinrich, Vinicius Fulber-Garcia, Newton Carlos Will, Rafael R. Obelheiro, Carlos Maziero |
ISCC | 5 |
| 2024 | The Use of the DWARF Debugging Format for the Identification of Potentially Unwanted Applications (PUAs) in WebAssembly Binaries
Calebe Helpa, Tiago Heinrich, Marcus Botacin, Newton Carlos Will, Rafael R. Obelheiro, Carlos Maziero |
SECRYPT | 5 |
| 2022 | How DRDoS attacks vary across the globe?abstractIn this study we characterize Distributed Reflection Denial of Service (DRDoS) attack traffic taking into consideration the geographical distribution of victims. This type of characterization is not widely explored in the literature and could help to better understand this type of attack. We aim to explore this gap in the literature using data collected by four honeypots over three and a half years. Our findings highlight attack similarities and differences across continents. Tiago Heinrich, Carlos Maziero, Newton Carlos Will, Rafael R. Obelheiro |
IMC | 4 |
| 2021 | New Kids on the DRDoS Block: Characterizing Multiprotocol and Carpet Bombing Attacks
Tiago Heinrich, Rafael R. Obelheiro, Carlos Maziero |
PAM | 2 |
| 2018 | Automatic Challenge Generation for Teaching Computer SecurityabstractComputer Security is an increasingly important area, considering the sophistication and increase of threats present in the digital world. The need for information protection contrasts with the lack of professionals and the limited space dedicated to the area in Information Technology (IT) courses. Games and competitions have been used to motivate students of Computing to improve their practical knowledge on the subject and also to foster the interest of potential students 'and professionals in Security. The creation of these games requires specialized knowledge to develop new problems, since the novelty of these games is important to reach the desired level of difficulty and to ensure competitiveness. This work proposes the use of randomization to generate problems and entire competitions in an automated way, obtaining exclusive instances of problems for each player. As proof of concept, a tool for generating challenges was developed to evaluate the proposal. Competitions with automatically generated problems were promoted, which included students of undergraduate courses and professional qualification in Computing, in two different institutions. The performance in the competitions and the perception of satisfaction, interest and learning of the students involved were analyzed. The results show that the automatic challenges generation is feasible, and the use of competitions in the teaching of Computer Security is motivating and effective for didactic purposes. Ricardo de la Rocha Ladeira, Rafael R. Obelheiro |
CLEI | 2 |
| 2016 | DReAM - a distributed result-aware monitor for Network Functions VirtualizationabstractNetwork Functions Virtualization (NFV) is a key technology to reduce management costs as well as to improve scalability and elasticity of computer networks. Still, recent research efforts have been exposing additional management challenges. Concerning monitoring in particular, new types of entities and requirements are underexploited. To address these issues, we propose DReAM, a resource management architecture based on management by delegation and distributed monitoring, where each agent runs a diagnostic model to compute the network service state. In this paper, we describe DReAM's proposed architecture and its major components. We also discuss the feasibility of DReAM through experimental and analytical evaluations, where we observed application throughput, CPU utilization, communication overhead, scalability, and diagnosis complexity. We provide a trade-off analysis on the monitoring strategies in NFV scenarios. Our results indicate that a result-aware strategy is a better option when the monitored environment has more than 256 agents or when the diagnosis module induces at least 10% of CPU utilization. Ricardo J. Pfitscher, Eder J. Scheid, Ricardo Luis dos Santos, Rafael R. Obelheiro, Maurício Aronne Pillon, Alberto E. Schaeffer Filho, Lisandro Z. Granville |
ISCC | 4 |
| 2014 | Analysis of operating system diversity for intrusion toleranceabstractOne of the key benefits of using intrusion-tolerant systems is the possibility of ensuring correct behavior in the presence of attacks and intrusions. These security gains are directly dependent on the components exhibiting failure diversity. To what extent failure diversity is observed in practical deployment depends on how diverse are the components that constitute the system. In this paper, we present a study with operating system's (OS's) vulnerability data from the NIST National Vulnerability Database (NVD). We have analyzed the vulnerabilities of 11 different OSs over a period of 18 years, to check how many of these vulnerabilities occur in more than one OS. We found this number to be low for several combinations of OSs. Hence, although there are a few caveats on the use of NVD data to support definitive conclusions, our analysis shows that by selecting appropriate OSs, one can preclude (or reduce substantially) common vulnerabilities from occurring in the replicas of the intrusion-tolerant system. Copyright © 2013 John Wiley & Sons, Ltd. Miguel Garcia 0002, Alysson Neves Bessani, Ilir Gashi, Nuno Neves 0001, Rafael R. Obelheiro |
Softw. Pract. Exp. | 5 |
| 2011 | OS diversity for intrusion tolerance: Myth or reality?abstractOne of the key benefits of using intrusion-tolerant systems is the possibility of ensuring correct behavior in the presence of attacks and intrusions. These security gains are directly dependent on the components exhibiting failure diversity. To what extent failure diversity is observed in practical deployment depends on how diverse are the components that constitute the system. In this paper we present a study with operating systems (OS) vulnerability data from the NIST National Vulnerability Database. We have analyzed the vulnerabilities of 11 different OSes over a period of roughly 15 years, to check how many of these vulnerabilities occur in more than one OS. We found this number to be low for several combinations of OSes. Hence, our analysis provides a strong indication that building a system with diverse OSes may be a useful technique to improve its intrusion tolerance capabilities. Miguel Garcia 0002, Alysson Neves Bessani, Ilir Gashi, Nuno Neves 0001, Rafael R. Obelheiro |
DSN | 5 |
| 2009 | Policy control management for Web ServicesabstractThe decentralization of corporate policy administration aiming to maintain the unified management of user permissions is a hard task. The heterogeneity and complexity of corporate environments burdens the security administrator with writing equally complex policies. This paper proposes an architecture based on Web Services, policy provisioning, and authorization certificates, to build up a loosely coupled unified administrative control for corporate environments. A certificate-based permission management scheme is used to derive new policies in the local domains of each branch. These new policies will update the corporate repository which, in turn, will configure the corresponding policies in the local domains of each branch. The Web Services technology provides the underlying protocols for the development of a prototype which shows the feasibility of our proposal. Arlindo L. Marcon Jr., Altair Olivo Santin, Luiz Augusto de Paula Lima, Rafael R. Obelheiro, Maicon Stihler |
Integrated Network Management | 4 |
| 2007 | Overlay Network Topology Reconfiguration in Byzantine SettingsabstractMany fault-tolerant systems rely on overprovisioning of system resources to provide spare capacity that can compensate for faulty components. However, this approach often results in idle resources that would be otherwise unnecessary; these resources do not provide an effective contribution to the system functionality but they may adversely affect its performance (as in the case of unused replicas that take part in distributed protocols, generating more messages than would be necessary). In this paper we introduce a mechanism for reconfiguring an overlay network topology in Byzantine settings. Our protocols use backup nodes to replace failed ones while ensuring that a replacement node is able to join the network with a prescribed connectivity. We show that topology reconfiguration is a powerful mechanism that can be used for building intrusion-tolerant distributed systems. Rafael R. Obelheiro, Joni da Silva Fraga |
PRDC | 1 |
| 2006 | A Lightweight Intrusion-Tolerant Overlay NetworkabstractThe Internet routing layer is at times too slow at recovering from faults and makes a sub-optimal use of redundancy available at the IP layer overlay networks can overcome these deficiencies to provide communication infrastructures with greater availability and flexibility. The majority of current experiences, however, are able to tolerate only simple (crash) failures of the underlying network. In this paper we present LITON, an overlay network architecture that aims at providing highly available communication in spite of faults and intrusions in the network. We also present a graph-theoretic model that allows the degree of fault and intrusion tolerance of a given overlay to be determined, as well as simulation results that validate this model and demonstrate that LITON accomplishes its goal even in worst-case scenarios. Rafael R. Obelheiro, Joni da Silva Fraga |
ISORC | 1 |
| 2002 | Policap-Proposal, Development and Evaluation of a Policy. Service and Capabilities for CORBA Security
Carla Merkle Westphall, Joni da Silva Fraga, Michelle S. Wangham, Rafael R. Obelheiro, Lau Cheuk Lung |
SEC | 4 |