João Paulo Barraca

dblp:92/3264 · also Joao Barraca Filipe · DBLP profile ↗
← Back
34ranked-venue papers
5as first author
13since 2021 · last 2026
0000-0002-5029-6191ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 19 · 3 first-author · 5 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 2 since 2021Systems, architecture and hardware · 3 · 1 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Software engineering, systems software and programming languages · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2026 PoliFlow: Inferring Control-Flow Policies from Serverless Workflows
Pedro Escaleira, Vitor A. Cunha, João Paulo Barraca, Diogo Gomes 0001, Rui L. Aguiar
CCGrid3
2026 Automated & Real-Time Privacy Quantification for Microservices Architectures
Catarina Silva 0004, Bernardo Falé, João Paulo Barraca, Paulo Salvador 0001
DATA (1)3
2025 PrivGuide: A Planning Tool for Proactive Privacy Integration in the DevPrivOps Lifecycle
abstract
Privacy concerns are rapidly growing, demanding tighter integration within the Agile software development lifecycle. Existing approaches rely on audits that are not integrated into the DevOps lifecycle, which greatly hinders both the analysis of privacy risks and the correction of privacy flaws. Even integrated tools are primarily reactive, treating privacy as an afterthought rather than a design principle. The currently used privacy engineering methodologies tend to be too general and have lackluster tooling to be enforced. Furthermore, privacy quantification is very domain-dependent, which makes it hard to automate without the help of an expert. DevPrivOps, a proposed extension to DevOps, focused on continuous privacy verification and user transparency, suffers from a lack of concrete tools. This paper proposes a novel tool for the DevPrivOps lifecycle that bridges the gap between privacy engineering methodology and the Agile planning phase, promoting the adoption of privacy by design strategies. This tool serves as a foundation for building and integrating further DevPrivOps tools, fostering a proactive approach to privacy within Agile development. We present the interface of this tool and its role in the DevPrivOps framework
João Felisberto, Catarina Silva 0004, João Paulo Barraca, Paulo Salvador 0001, Pedro Tomás
ISCC3
2025 ASAP 2.0: Autonomous & proactive detection of malicious applications for privacy quantification in 6G network services
abstract
While 6G networks, reliant on software, promise significant advancements, the proliferation of diverse applications deployed closer to users poses considerable privacy challenges. To counter this, privacy-first software development, as advocated by DevPrivOps, becomes essential. While Privacy-Enhancing Technologies (PETs) are frequently used, their limitations are well-documented. DevPrivOps strives to reinforce software privacy through prioritization, compliance, transparency, optimization, and informed decision-making. A promising alternative to PETs involves quantifying privacy to guide development and pinpoint potential threats, thus enhancing application privacy before deployment on OpenSlice network services. Privacy-centric malicious application detection, amongst other features, is a key component of this privacy quantification framework, serving to inform users of potential harm from such applications. In this study, we focus on privacy-centric malicious application detection. ASAP 2.0, an autonomous system, identifies these threats by scrutinizing requested application permissions. Building on its antecedent, ASAP 2.0 employs a tuned autoencoder trained via unsupervised learning. By analyzing reconstruction errors, it differentiates between potentially harmful and benign applications. A dynamically adjusted threshold assists in the decision-making process. Our model, validated on three public datasets, achieved an average Matthews Correlation Coefficient (MCC) of 0.976, outperforming baseline models such as Logistic Regression and Decision Trees. • Privacy Quantification Framework Adhering to the DevPrivOps Methodology. • Tool for detecting privacy-harmful applications through anomaly detection. • Applied during the risk analysis deployment phase of DevPrivOps. • Autoencoder to discriminate between harmful and benign applications. • Evaluated on three datasets, achieving an average MCC of 0.976 across all datasets.
Catarina Silva 0004, João Felisberto, João Paulo Barraca, Paulo Salvador 0001
Comput. Commun.3
2024 Rethinking Security: The Resilience of Shallow ML Models (Extended Abstract)
abstract
The growth of Machine Learning (ML) has led to the commercialization of applications like data analytics, autonomous systems, and security diagnostics. These models are becoming widespread across various domains. However, security and privacy issues accompany this growth. Although actively researched, there's fragmentation in analyzing and defining ML models' resilience. This work examines the resilience of shallow ML models against typical data poisoning attacks. Our study assessed their strengths in adversarial scenarios using the MNIST dataset in a CAPTCHA context. Results show notable resilience, with accuracy and generalization maintained despite malicious inputs, offering insights to strengthen future ML systems. Understanding the mechanisms enabling this resilience can aid in fortifying the security of future ML systems.
Rafael Teixeira, Mário Antunes 0001, João Paulo Barraca, Diogo Gomes 0001, Rui L. Aguiar
DSAA3
2024 MoFaaS: A Moving Target Defense Approach to Fortify Functions as a Service
abstract
Serverless computing is becoming increasingly relevant in the cloud and applied in other fields, such as telecom. This paper proposes the Moving Functions as a Service (MoFaaS) system, a Moving Target Defense (MTD) and N-Version Programming (NVP)-based approach designed to improve the protection of applications and services built using Function as a Service (FaaS). The mechanism works by rotating the version to be executed next for each function. Therefore, when an attacker triggers the execution of a specific workflow path in distinct moments, the versions of the functions responding to those requests will probably be different. Consequently, if one or more function variants are vulnerable, the attacker cannot target them reliably. In the end, we conducted a preliminary practical demonstration to prove this system’s effectiveness. Its analysis shows that the attack difficulty increases with the number of versions per function and the versions an attacker has to compromise to achieve its objectives.
Pedro Escaleira, Vitor A. Cunha, João Paulo Barraca, Diogo Gomes 0001, Rui L. Aguiar
ISCC3
2023 Upscaling Operators of Essential Services Incident Response Teams
abstract
The eHealth sector in Portugal faces significant cybersecurity challenges, including increasing cyber threats and vulnerabilities, inadequate cybersecurity measures, and a short-age of skilled cybersecurity professionals. The importance of addressing these challenges has been emphasised by the European Union's Network and Information Systems (NIS) Directive, which aims to ensure a high common level of cybersecurity across the EU by requiring Member States to adopt national cybersecurity measures and cooperate on incident response. In response to these challenges, we propose in this work, a project capable of improving the cybersecurity posture of eHealth systems in Portugal. The project proposes a novel approach to establishing connections with various organisations, including the national CERT.PT and PANORAMA, for incident response and information sharing. The tasks involved in the project include risk assessment, penetration testing, skills gap analysis, training, incident notification and communication, and controls implementation. By implementing these tasks, the project has the potential to improve the incident response capabilities and overall cybersecurity posture of eHealth systems.
João Paulo Barraca, Cristina Cerqueira, José Filipe Alves, Sara Andrade, António Meireles, João Rafael Almeida
CBMS1
2023 Towards Improved Indoor Location with Unmodified RFID Systems
Ricardo Alexandre, Mário Antunes 0001, João Paulo Barraca
ICPRAM5
2022 A secure architecture for exploring patient-level databases from distributed institutions
abstract
One of the main goals of clinical studies consists of identifying diseases' causes and improving the efficacy of medical treatments. Sometimes, the reduced number of participants is a limiting factor for these studies, leading researchers to organise multi-centre studies. However, sharing health data raises certain concerns regarding patients' privacy, namely related to the robustness of anonymisation procedures. Although these techniques remove personal identifiers from registries, some studies have shown that anonymisation procedures can sometimes be reverted using specific patients' characteristics. In this paper, we propose a secure architecture to explore distributed databases without compromising the patient's privacy. The proposed architecture is based on interoperable repositories supported by a common data model.
João Rafael Almeida, João Paulo Barraca, José Luís Oliveira
CBMS2
2022 Multi-access Edge Computing as a Service
abstract
Standardization organizations, such as the European Telecommunications Standards Institute (ETSI), have been gathering efforts to specify the Edge Computing paradigm. However, there is still a lack of complete, interface-wise, actual implementations and evaluations of a fully functional Edge Computing architecture. On these grounds, the work presented in this paper proposes a new Multi-access Edge Computing (MEC)-Network Functions Virtualization (NFV) architecture for a challenging Business to Business to Consumer (B2B2C) model, based on the references provided by ETSI, and provides a prototype implementation to demonstrate its viability. The tests conducted show that the proposed framework can be efficiently deployed, allowing Telecommunications Operators to rapidly instantiate and provide an elastic Edge Infrastructure to their customers.
Pedro Escaleira, Miguel Mota, Diogo Gomes 0001, João Paulo Barraca, Rui L. Aguiar
CNSM4
2021 Three-Tier Fuzzy-based Orchestration in MEC
abstract
Handing over highly demanding tasks to remote or nearby computing units helps accommodate the service Quality of Service (QoS) requirements, and compensates for the limited computational capabilities of User Equipment (UE) such as smartphones and tablets. Task offloading is a promising technique being proposed for Virtualized Edge (VE) environments to solve a wide range of issues, frequently with the aim of enabling resource-intensive low-latency services. However, the volatile nature of 5G and B5G networks, as they continuously change due to dynamic policies, optimization processes, and users' mobility, formalizes a major obstacle facing offloading and overall resource orchestration. To cope with such a challenge, under the scope of Multi-access Edge Computing (MEC), a three-tier fuzzy-based orchestration strategy is proposed with the aim of offloading the users' workload to the optimum computing units to support stricter QoS requirements and reduce the perceived service delay. To evaluate our solution, we compare the proposed workload orchestrator with different employed algorithms. The evaluation shows that our orchestrator achieves nearly ideal performance, and outperforms the state-of-the-art approaches considered.
Hadeel Abdah, João Paulo Barraca, Rui L. Aguiar
GLOBECOM2
2021 Communication technologies for Smart Water Grid applications: Overview, opportunities, and research directions
Yandja Lalle, Mohamed Fourati, Lamia Chaari, João Paulo Barraca
Comput. Networks4
2021 TOTP Moving Target Defense for sensitive network services
Vitor A. Cunha, Daniel Corujo, João Paulo Barraca, Rui L. Aguiar
Pervasive Mob. Comput.3
2020 Handover Prediction Integrated with Service Migration in 5G Systems
abstract
As the research community inclines toward adopting increasingly complex techniques for future networks, and simple methods are often ignored, being labeled as trivial. In this paper, we argue that simple methods can sometimes outperform more sophisticated ones. We demonstrate that by evaluating two prediction mechanisms to forecast mobile user's handovers exploiting user-network association patterns. We perform a series of experiments on real-world data, evaluating the performance characteristics of such methods over more sophisticated and complex prediction techniques. Furthermore, we discuss how to easily bootstrap these mechanisms into the 5G network architecture. We suggest the use of these methods associated with Multi-access Edge Computing (MEC) scenarios, as a mean to identify favorable edge nodes to host the mobile applications, to best provide continuous and QoS-aware service for mobile users.
Hadeel Abdah, João Paulo Barraca, Rui L. Aguiar
ICC2
2020 Power Minimizing BBU-RRH Group Based Mapping in C-RAN with Constrained Devices
abstract
C-RAN presents an advanced mobile networking architecture that promises to tackle various challenging aspects of 5G such as increasing energy efficiency and providing high capacity. Indeed, C-RAN paves the way toward better energy efficiency by centralizing the baseband processing at cloud computing based servers (BBU pool). In this paper, we propose an RRH group based mapping (RGBM) that aims to minimize the power consumption at the BBU pool, while considering users' QoS and BBU capacity constraints. To achieve this, the proposed scheme uses two key steps: i) the formation of RRH groups aimed at improving the QoS of weak users, ii) the formation of RRH cluster to be mapped for minimal number of BBUs requirement. The proposed scheme uses an efficient greedy heuristic to solve the optimization problem. The performance of the proposed approach was evaluated using simulations, which indicate a significant gain in terms of BBU minimization, power reduction and energy efficiency, while preserving QoS constraints, against well studied legacy solutions.
Fatma Marzouk, Tafseer Akhtar, Ilias Politis, João Paulo Barraca, Ayman Radwan
ICC4
2020 Quantifying the Influence of Regulatory Instructions over the Detection of Network Neutrality Violations
Marcio Barbosa de Carvalho, Vitor A. Cunha, Eduardo da Silva, Daniel Corujo, João Paulo Barraca, Rui L. Aguiar, Lisandro Z. Granville
Networking5
2019 Safeguarding from abuse by IoT vendors: Edge messages verification of cloud-assisted equipment
Vitor A. Cunha, Eduardo da Silva, Marcio Barbosa de Carvalho, Daniel Corujo, João Paulo Barraca, Diogo Gomes 0001, Alberto E. Schaeffer Filho, Carlos Raniery Paula dos Santos, Lisandro Z. Granville, Rui L. Aguiar
IM5
2019 A Network Service for Preventing Data Leakage from IoT Cloud-assisted Equipment
abstract
The fact that most IoT solutions are provided by third parties, along with the pervasiveness of the collected data, raises privacy and security concerns. There is a need to verify which data is being sent to the third party, as well as preventing those channels from becoming an exploitation avenue. We propose to use existing API definition languages to create contracts which define the data that can be transmitted, their format and constraints. To verify the compliance with these contracts, we propose a Network Service architecture which validates REST-like API requests/responses against a Swagger schema. We deal with encrypted traffic using an Service Function Chaining (SFC)-enabled Man-in-the-Middle (MITM), allowing verifications in “real-time.” We devised a Proof of Concept and showed that we were able to detect (and stop) contract violations.
Vitor A. Cunha, Rui L. Aguiar, Eduardo da Silva, Marcio Barbosa de Carvalho, Daniel Corujo, João Paulo Barraca, Diogo Gomes 0001, Alberto E. Schaeffer Filho, Carlos Raniery Paula dos Santos, Lisandro Z. Granville
ISCC6
2019 Logging Integrity with Blockchain Structures
Marco Rosa, João Paulo Barraca, Nelson Pacheco da Rocha
WorldCIST (3)2
2019 Access Control for Social Care Platforms Using Fast Healthcare Interoperability Resources
Marco Rosa, João Paulo Barraca, Nelson Pacheco da Rocha
WorldCIST (3)2
2018 An SFC-enabled approach for processing SSL/TLS encrypted traffic in Future Enterprise Networks
abstract
In this paper, we propose an architecture based on NFV and SDN which allows to balance traffic analysis techniques using a Classifier. It steers flows to the appropriate Service Function Chaining (to open traffic or not) according to network requirements (such as, effectiveness, flexibility, scalability, performance, and privacy). The SSL/TLS traffic processing is carried-out by the centerpiece of this work, the SFC-enabled MITM. A Proof-of-Concept was conducted (focusing on our SFC-enabled MITM) which showed that functionalities lost due to encryption (Content Optimization, Caching, Network Anti-virus, and Content Filter) were recovered when processing opened traffic within its Service Function Chains. We also evaluated its impact on performance. The results show that cipher suite overhead plays a role but can be mitigated, the Classifier can alleviate the performance overhead of different traffic analysis techniques, network functions have lower impact to performance, and Service Function Chaining length influences page load time.
Vitor A. Cunha, Marcio Barbosa de Carvalho, Daniel Corujo, João Paulo Barraca, Diogo Gomes 0001, Alberto E. Schaeffer Filho, Carlos Raniery Paula dos Santos, Lisandro Z. Granville, Rui L. Aguiar
ISCC4
2018 Resource discovery for distributed computing systems: A comprehensive survey
Javad Zarrin, Rui L. Aguiar, João Paulo Barraca
J. Parallel Distributed Comput.3
2018 Non-IP Multi-protocol Stack for Vehicular Communications
Muhammad Alam 0002, Joaquim Ferreira 0001, João Paulo Barraca
Mob. Networks Appl.4
2017 Click-on-OSv: A platform for running Click-based middleboxes
abstract
In this paper, we present a modern platform for running Virtualized Network Functions based on the Click Modular Router. The proposed platform leverages of current technologies - such as DPDK, OSv, and REST Web Services - to fulfill the ETSI requirements for Network Functions Virtualization. The obtained results show the feasibility of the platform to consolidate disparate network functions, while demonstrating flexibility from a management point-of-view.
Leonardo da Cruz Marcuzzo, Vinicius Fulber-Garcia, Vitor A. Cunha, Daniel Corujo, João Paulo Barraca, Rui L. Aguiar, Alberto E. Schaeffer Filho, Lisandro Z. Granville, Carlos Raniery Paula dos Santos
IM5
2017 HARD: Hybrid Adaptive Resource Discovery for Jungle Computing
Javad Zarrin, Rui L. Aguiar, João Paulo Barraca
J. Netw. Comput. Appl.3
2015 IMS centric communication supporting WebRTC endpoints
abstract
With the evolution of technologies such as WebRTC and telecommunication (Telco) architectures aligned with the latest 3GPP standards, the search for interoperability between traditional and web-oriented endpoints is vital, with new use-cases and multimedia services to be explored. Currently, convergence goes beyond the standards and, as such, its search and the technological obstacles motivate this work. We make a proposal for the implementation of a platform uniting state-of-the-art Telco networks with WebRTC technologies. To validate the solution, an IMS integrated prototype was built, being evaluated in terms of call throughput and system induced mouth-to-ear delay. Results show that call delay is on par with current mobile network calls, making the current solution a viable alternative for communication bridging in a Telco network.
Bruno Simoes Cruz, João Paulo Barraca
ISCC2
2015 Seamless integration of Cloud and Fog networks
abstract
This work provides a way to merge Cloud Computing infrastructures with traditional or legacy network deployments, leveraging the best in both worlds and enabling a logically centralized control for it. A solution is proposed to extend existing Cloud Computing software stacks so they are able to manage networks outside the Cloud Computing infrastructure, by extending the internal, virtualized network segments. This is useful in a variety of use cases such as incremental Legacy to Cloud network migration, hybrid virtual/traditional networking, centralized control of existing networks, bare metal provisioning, and even offloading of advanced services from typical home gateways into the operator. By using what is called External Drivers, any organization can develop their own driver to support new, specific networking equipment. Our concept solution is prototyped on top of OpenStack, including changes to the API, command line interface and other mechanisms. Test results indicate that there are low penalties on latency and throughput, and that provisioning times are reduced in comparison with similar maintenance operations on traditional computer networks.
Igor Duarte Cardoso, João Paulo Barraca, Carlos Goncalves, Rui L. Aguiar
NetSoft2
2015 Dynamic, scalable and flexible resource discovery for large-dimension many-core systems
Javad Zarrin, Rui L. Aguiar, João Paulo Barraca
Future Gener. Comput. Syst.3
2014 A self-organizing and self-configuration algorithm for resource management in service-oriented systems
abstract
With the ever increasing deployment of service-oriented distributed systems in large-scale and heterogeneous computing environments, clustering and communication overlay topology design has become more and more important to address several challenging issues and conflicting requirements, such as efficient scheduling and distribution of services among computing resources, reducing communication cost between services, high performance service and resource discovery while considering both inter-service and inter-node properties and also increasing the load distribution and the load balance. In this paper, a four-stage hierarchical clustering algorithm is proposed which automates the process of the optimally composing communicating groups in a dynamic way while preserving the proximity of the nodes. The simulation results show the performance of the algorithm with respect to load balance, scalability and efficiency.
Javad Zarrin, Rui L. Aguiar, João Paulo Barraca
ISCC3
2011 Network interfaces flying over IP networks
abstract
We propose a novel method to export both interface control and data planes across different hosts, effectively enabling hardware specific control of network interfaces over the Internet, or from a host to its virtualized guests. Our solution is a major step towards distributed environments of heterogeneous communication systems, particularly relevant in the scope of custom system composition, remote development and testing, and is especially relevant when considering embedded or geographically constrained devices. Results obtained by our prototype implementation validate the effectiveness of the solution. We present a preliminary characterization of its impact, when considering traffic generation applications, when applied over an IEEE 802.11g communication medium.
João Paulo Barraca, Alexandre Brito, Rui L. Aguiar
ISCC1
2011 Metrics for optimal relay selection in cooperative wireless networks
abstract
A key design issue in relay based cooperative wireless networks is the metrics used for relay selection. Internal operational parameters and network sensing parameters are two categories recently considered as decision factors for cooperation strategies. We focus on the impact of these potential sensing parameters as indicators of the effective cooperation, from the perspective of the network layer, namely: movement, medium access delay and medium delay ratio. Simulation results indicate a strong correlation between network performance and the proposed cooperative metrics. Novel solutions for cooperation should take these metrics into consideration in order to provide better network performance.
Rasool Sadeghi, João Paulo Barraca, Rui L. Aguiar
PIMRC2
2008 Managing community aware Wireless Mesh Networks
abstract
Wireless mesh networks, due to their typical architecture and deployment, are able to respond to user expectations as no other technology allows. Its typical multi-level approach facilitates local interactions by nearby wireless nodes from multiple users. Also, adaptation to user expectations on a dynamic manner is able to of further enhancing the capacity of these networks, while increasing its ubiquity. Nevertheless, these networks have no management model. In the paper we present the foundations for a management model for community aware networking. Design challenges for community management are identified and a management framework supporting the relevant concepts, linking social aspects and technology, is described.
João Paulo Barraca, Rui L. Aguiar
ISCC1
2008 An architecture for community mesh networking
abstract
The advances on wireless mesh networks are shifting the communications paradigm, where users can benefit from their cooperation to exchange information and make use of the spectrum space, forming wireless neighbourhood communities where resources are shared and services are distributed. This paper presents a modular cross-layer community management architecture, which considers that communities are formed and managed at different layers, from physical to application. It focus in more depth on one of its modules, implementing a community discovery mechanism designed to work in wireless mesh networks, and able to perform community advertisement and discovery with low overhead and delay, as compared to current approaches.
João Paulo Barraca, Susana Sargento, Rui Manuel Rocha
PIMRC1
2005 The Polynomial-Assisted Ad Hoc Charging Protocol
abstract
The area of trustworthy charging in self-organized environments has been developed quite recently. This paper introduces a new secure charging-protocol, the polynomial-assisted charging protocol, for these environments. The protocol relies on polynomial composition for speeding the identification process in small groups. This protocol is able to provide strict guarantees of cooperative behavior in traffic forwarding, with minimal network overhead. Protocol performance is evaluated in multiple ad-hoc environments and results are compared with previously proposed work. The performance results show the merits of this protocol in multiple types of environments.
João Paulo Barraca, Susana Sargento, Rui L. Aguiar
ISCC1