VLDB 2026 Research / reviewers in the wild / expert
Roben Castagna Lunardi
dblp:95/7493
· DBLP profile ↗
21ranked-venue papers
4as first author
7since 2021 · last 2026
0000-0002-8118-0802ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 1 first-author · 1 since 2021Security and privacy · 3 · 2 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Federated Learning for IoT Forensics: Enabling Privacy-Preserving Machine Learning
Mateus G. Haas, Roben Castagna Lunardi, Avelino Francisco Zorzo |
WorldCIST (2) | 2 |
| 2025 | Assessing the Impact of Post-Quantum Digital Signature Algorithms on Blockchains
Alison Gonçalves Schemitt, Henrique Fan da Silva, Roben Castagna Lunardi, Diego Kreutz, Rodrigo B. Mansilha, Avelino Francisco Zorzo |
TrustCom | 3 |
| 2025 | Stordy: Efficient Data Retrieval and Storage for Appendable-Block Blockchains
Leonardo Barbosa da Rosa, Roben Castagna Lunardi, Avelino Francisco Zorzo |
WorldCIST (1) | 2 |
| 2024 | Machine Learning for Forensic Occupancy Detection in IoT Environments
Guilherme Dall'Agnol Deconto, Avelino Francisco Zorzo, Daniel Dalalana Bertoglio, Edson OliveiraJr, Roben Castagna Lunardi |
WorldCIST (1) | 5 |
| 2023 | Data Management in Appendable-Block Blockchains: A Case Study for IT Life-Cycle Management
Rodrigo W. Silveira, Roben Castagna Lunardi, Avelino Francisco Zorzo |
MobiQuitous (1) | 2 |
| 2022 | Understanding the Penetration Test Workflow: a security test with Tramonto in an e-Government applicationabstractSecurity and privacy became vital to any of the current computational systems or applications. Particularly, investigating possible security issues - to mitigate possible data leaks or tampering - is an important step in the current software development. Currently, penetration tests (pentest) are performed to detect possible system flaws and to prevent/correct eventual security issues. However pentesting (the act of performing pentest) a system can be complex and hard to control. There are many activities throughout the pentesting process and it is common to find difficulties in controlling them. At the same time, it is not easy to determine precisely what activities will be performed, since each tester can follow a specific methodology or even use their own testing model. Based on the main security assessment test methodologies, we created a framework for penetration testing that aims to improve the test workflow in terms of management, organization, standardization, and flexibility. This framework is called Tramonto. This paper presents and discusses a pentest case study performed by a security company using the Tramonto framework. To present this case, we introduce the Tramonto-App, a software that was implemented using the definitions present in the Tramonto framework. Tramonto-App was designed to assist testers in penetration tests based on features that help to organize scripts, handle the testing workflow, and generate reports. As a result, the Tramonto-App resulted in a reduced number of pentesting problems and reduced (human) effort required to perform the penetration, allowing the tester to improve the quality of the Pentest. Daniel Dalalana Bertoglio, Luis G. B. Schüler, Avelino Francisco Zorzo, Roben Castagna Lunardi |
TrustCom | 4 |
| 2022 | Consensus Algorithms on Appendable-Block Blockchains: Impact and Security Analysis
Roben Castagna Lunardi, Regio A. Michelin, Henry C. Nunes, Charles V. Neu, Avelino Francisco Zorzo, Salil S. Kanhere |
Mob. Networks Appl. | 1 |
| 2020 | Data-Driven Model-Based Analysis of the Ethereum Verifier's DilemmaabstractIn proof-of-work based blockchains such as Ethereum, verification of blocks is an integral part of establishing consensus across nodes. However, in Ethereum, miners do not receive a reward for verifying. This implies that miners face the Verifier's Dilemma: use resources for verification, or use them for the more lucrative mining of new blocks? We provide an extensive analysis of the Verifier's Dilemma, using a data-driven model-based approach that combines closed-form expressions, machine learning techniques and discrete-event simulation. We collect data from over 300,000 smart contracts and experimentally obtain their CPU execution times. Gaussian Mixture Models and Random Forest Regression transform the data into distributions and inputs suitable for the simulator. We show that, indeed, it is often economically rational not to verify, in particular for miners with less hashing power. We consider two approaches to mitigate the implications of the Verifier's Dilemma, namely parallelization and active insertion of invalid blocks, both will be shown to be effective. Maher Alharby, Roben Castagna Lunardi, Amjad Aldweesh, Aad P. A. van Moorsel |
DSN | 2 |
| 2019 | Impact of consensus on appendable-block blockchain for IoTabstractThe Internet of Things (IoT) is transforming our physical world into a complex and dynamic system of connected devices on an unprecedented scale. Connecting everyday physical objects is creating new business models, improving processes and reducing costs and risks. Recently, blockchain technology has received a lot of attention from the community as a possible solution to overcome security issues in IoT. However, traditional blockchains (such as the ones used in Bitcoin and Ethereum) are not well suited to the resource-constrained nature of IoT devices and also with the large volume of information that is expected to be generated from typical IoT deployments. To overcome these issues, several researchers have presented lightweight instances of blockchains tailored for IoT. For example, proposing novel data structures based on blocks with decoupled and appendable data. However, these researchers did not discuss how the consensus algorithm would impact their solutions, i.e., the decision of which consensus algorithm would be better suited was left as an open issue. In this paper, we improved an appendable-block blockchain framework to support different consensus algorithms through a modular design. We evaluated the performance of this improved version in different emulated scenarios and studied the impact of varying the number of devices and transactions and employing different consensus algorithms. Even adopting different consensus algorithms, results indicate that the latency to append a new block is less than 161ms (in the more demanding scenario) and the delay for processing a new transaction is less than 7ms, suggesting that our improved version of the appendable-block blockchain is efficient and scalable, and thus well suited for IoT scenarios. Roben Castagna Lunardi, Regio A. Michelin, Charles V. Neu, Henry C. Nunes, Avelino Francisco Zorzo, Salil S. Kanhere |
MobiQuitous | 1 |
| 2018 | SpeedyChain: A framework for decoupling data from blockchain for smart citiesabstractThere is increased interest in smart vehicles acting as both data consumers and producers in smart cities. Vehicles can use smart city data for decision-making, such as dynamic routing based on traffic conditions. Moreover, the multitude of embedded sensors in vehicles can collectively produce a rich data set of the urban landscape that can be used to provide a range of services. Key to the success of this vision is a scalable and private architecture for trusted data sharing. This paper proposes a framework called SpeedyChain, that leverages blockchain technology to allow smart vehicles to share their data while maintaining privacy, integrity, resilience, and non-repudiation in a decentralized and tamper-resistant manner. Differently from traditional blockchain usage (e.g., Bitcoin and Ethereum), the proposed framework uses a blockchain design that decouples the data stored in the transactions from the block header, thus allowing fast addition of data to the blocks. Furthermore, an expiration time for each block is proposed to avoid large sized blocks. This paper also presents an evaluation of the proposed framework in a network emulator to demonstrate its benefits. Regio A. Michelin, Ali Dorri, Marco Steger, Roben Castagna Lunardi, Salil S. Kanhere, Raja Jurdak, Avelino Francisco Zorzo |
MobiQuitous | 4 |
| 2018 | Distributed access control on IoT ledger-based architectureabstractDue to increased number of attacks on the Internet of Things (IoT) devices, the security of IoT networks became critical. Some recent researches proposed the adoption of blockchain in IoT networks without a thorough discussion on the impact of the solution on the devices performance. Furthermore, blockchain employment in the context of IoT can be challenging due to the devices hardware limitations. To fill this gap, this paper proposes an IoT ledger-based architecture to ensure access control on heterogeneous scenarios. This research applies conventional devices used on IoT networks, such as Arduino, Raspberry and Orange Pi boards. Finally, we perform performance evaluation focused on access control of IoT devices and on information propagation through peers on a private IoT network scenario. Roben Castagna Lunardi, Regio A. Michelin, Charles V. Neu, Avelino Francisco Zorzo |
NOMS | 1 |
| 2018 | Lightweight IPS for port scan in OpenFlow SDN networksabstractSecurity has been one of the major concerns for the computer network community due to resource abuse and malicious flows intrusion. Before a network or a system is attacked, a port scan is typically performed to discover vulnerabilities, like open ports, which may be used to access and control them. Several studies have addressed Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) methods for detecting malicious activities, based on received flows or packet data analysis. However, those methods lead to an increase in switching latency, due to the need to analyze flows or packets before routing them. This may also increase network overhead when flows or packets are duplicated to be parsed by an external IDS. On the one hand, an IDS/IPS may be a bottleneck on the network and may not be useful. On the other hand, the new paradigm called Software Defined Networking (SDN) and the OpenFlow protocol provide some statistical information about the network that may be used for detecting malicious activities. Hence, this work presents a new port scan IPS for SDN based on the OpenFlow switch counters data. A non-intrusive and lightweight method was developed and implemented, with low network overhead, and low memory and processing power consumption. The results showed that our method is effective on detecting and preventing port scan attacks. Charles V. Neu, Cassio G. Tatsch, Roben Castagna Lunardi, Regio A. Michelin, Alex M. S. Orozco, Avelino Francisco Zorzo |
NOMS | 3 |
| 2013 | Identifying the root cause of failures in IT changes: Novel strategies and trade-offs
Ricardo Luis dos Santos, Juliano Araújo Wickboldt, Bruno Lopes Dalmazo, Lisandro Z. Granville, Luciano Paschoal Gaspary, Roben Castagna Lunardi |
IM | 6 |
| 2011 | Leveraging IT project lifecycle data to predict support costsabstractThere is an intuitive notion that the costs associated with project support actions, currently deemed too high and increasing, are directly related to the effort spent during their development and test phases. Despite the importance of systematically characterizing and understanding this relationship, little has been done in this realm mainly due to the lack of proper tooling for both sharing information between IT project phases and learning from past experiences. To tackle this issue, in this paper we propose a solution that, leveraging existing IT project lifecycle data, is able to predict support costs. The solution has been evaluated through a case study based on the ISBSG dataset, producing correct estimates for more than 80% of the assessed scenarios. Bruno Lopes Dalmazo, Weverton Luis da Costa Cordeiro, Abraham Lincoln Rabelo de Sousa, Juliano Araújo Wickboldt, Roben Castagna Lunardi, Ricardo Luis dos Santos, Luciano Paschoal Gaspary, Lisandro Z. Granville, Claudio Bartolini, Marianne Hickey |
Integrated Network Management | 5 |
| 2011 | A solution for identifying the root cause of problems in IT change managementabstractThe reuse of knowledge acquired by operators to diagnose failures in Information Technology (IT) infrastructures has potential to decrease the recurrence of failures and, consequently, reduce possible losses and maintenance costs. Nevertheless, existing solutions to support failure diagnosis lack of flexibility to adapt to a constantly changing IT environment. As a result, diagnostic is performed in an ad hoc and static fashion, which hampers the reuse of knowledge to solve similar failures affecting different elements of an IT infrastructure. To bridge this gap, in this paper we propose an extension of Common Information Model (CIM), supported by a conceptual solution for the identification of the root causes of problems, adaptable to changes in the target infrastructure and applicable to similar failures. Experiments carried out considering typical failures during the deployment of IT changes provide evidence about the efficacy of the proposed solution. Ricardo Luis dos Santos, Juliano Araújo Wickboldt, Roben Castagna Lunardi, Bruno Lopes Dalmazo, Lisandro Z. Granville, Luciano Paschoal Gaspary, Claudio Bartolini, Marianne Hickey |
Integrated Network Management | 3 |
| 2011 | A framework for risk assessment based on analysis of historical information of workflow execution in IT systems
Juliano Araújo Wickboldt, Luís Armando Bianchin, Roben Castagna Lunardi, Lisandro Z. Granville, Luciano Paschoal Gaspary, Claudio Bartolini |
Comput. Networks | 3 |
| 2010 | On strategies for planning the assignment of human resources to IT change activitiesabstractPlanning is a fundamental sub-process of the overarching Information Technology (IT) change management process, proposed by the Information Technology Infrastructure Library to help organizations to deploy and maintain IT services in an effective and efficient way. A major issue behind IT change planning and of special importance for the alignment of changes with business objectives/constraints - the adequate projection of which human resources to assign to change activities - has not been properly addressed in previous investigations. To fill this gap, in this paper we propose and analyze novel strategies for planning the assignment of human resources to change activities. These strategies explore different ways to prioritize humans to activities (i.e., from the most to the less efficient or proficient humans), and to rank/cluster the activities that should be analyzed first. The novel strategies have been experimentally evaluated through ChangeAdvisor, a prototypical implementation of a decision support system that helps IT administrators in the task of understanding the trade-offs between alternative change designs. Roben Castagna Lunardi, Fabrício Girardi Andreis, Weverton Luis da Costa Cordeiro, Juliano Araújo Wickboldt, Bruno Lopes Dalmazo, Ricardo Luis dos Santos, Luís Armando Bianchin, Luciano Paschoal Gaspary, Lisandro Z. Granville, Claudio Bartolini |
NOMS | 1 |
| 2010 | Computer-generated comprehensive risk assessment for IT project managementabstractInformation Technology (IT) products and services provided by modern organizations are designed in projects that often involve large amount of resources (e.g., humans, hardware, and software). It is essential that organizations enforce rational practices for project management, in order to successfully conclude projects and avoid waste of substantial resources. In this context, Risk Management is fundamental to guarantee the accomplishment of project's objectives by dealing with adverse and favorable events. Although important, risk assessment in IT projects is usually performed by stakeholders in interviews and brainstorms which may be a very time/resource-consuming task. Therefore, in this paper, we introduce a solution to automate the risk assessment process, based on the history of previously conducted projects. Furthermore, comprehensive and interactive risk reports are proposed in order to ease the analysis of automatically generated reports. The results show that our solution is not only useful to speed the risk assessment process, but also to assist the decision making of project managers by organizing risk information according to the project structure. Juliano Araújo Wickboldt, Luís Armando Bianchin, Roben Castagna Lunardi, Fabrício Girardi Andreis, Ricardo Luis dos Santos, Bruno Lopes Dalmazo, Weverton Luis da Costa Cordeiro, Abraham Lincoln Rabelo de Sousa, Lisandro Z. Granville, Luciano Paschoal Gaspary, Claudio Bartolini |
NOMS | 3 |
| 2009 | CHANGEMINER: A solution for discovering IT change templates from past execution tracesabstractThe main goal of change management is to ensure that standardized methods and procedures are used for the efficient and prompt handling of changes in IT systems, in order to minimize change-related incidents and service-delivery disruption. To meet this goal, it is of paramount importance reusing the experience acquired from previous changes in the design of subsequent ones. Two distinct approaches may be usefully combined to this end. In a top-down approach, IT operators may manually design change templates based on the knowledge owned/acquired in the past. Considering a reverse, bottom-up perspective, these templates could be discovered from past execution traces gathered from IT provisioning tools. While the former has been satisfactorily explored in previous investigations, the latter - despite its undeniable potential to result in accurate templates in a reduced time scale - has not been subject of research, as far as the authors are aware of, by the service operations and management community. To fill in this gap, this paper proposes a solution, inspired on process mining techniques, to discover change templates from past changes. The solution is analyzed through a prototypical implementation of a change template miner subsystem called CHANGEMINER, and a set of experiments based on a real-life scenario. Weverton Luis da Costa Cordeiro, Guilherme Sperb Machado, Fabrício Girardi Andreis, Juliano Araújo Wickboldt, Roben Castagna Lunardi, Alan Diego dos Santos, Cristiano Bonato Both, Luciano Paschoal Gaspary, Lisandro Z. Granville, David Trastour, Claudio Bartolini |
Integrated Network Management | 5 |
| 2009 | Refined failure remediation for IT change management systemsabstractIn order to deal with failures in the deployment of IT changes and to always leave IT infrastructures into consistent states, we proposed in a previous work, a solution to automate the generation of rollback plans in IT change management systems. The solution was based on a mechanism that treats Requests for Change (RFC) (or parts of them) as a single atomic transaction. In this work, we extend our previous investigation and present more flexible and fine grained treatment of failures. The paper first presents extensions to our conceptual model in order (i) to give IT operators some flexibility in defining rollback actions, for example, by allowing the rollback plan to not only be a reversed change plan; and (ii) to execute different recovery activities depending on the cause and location of a problem. The paper then focuses on a refined manner to handle and treat failures in change deployments. We follow the ITIL version 3 best practises which suggest that, depending on the RFC context, the human operator can classify activities as reversible or irreversible. Such classification allows change management systems to automatically generate more accurate remediation plans. The proposal takes into account not only a precise way to define how rollback plans will be generated, but also an intuitive method enabling the operator to define compensation activities in order to complete the RFC successfully, even with the occurrence of failures. To prove the concept and technical feasibility, we have materialized our solution in the CHANGELEDGE prototype that, using elements of the Business Process Execution Language (BPEL), is able to generate correct remediation plans to handle and treat failures in IT change management systems. Guilherme Sperb Machado, Weverton Luis da Costa Cordeiro, Alan Diego dos Santos, Juliano Araújo Wickboldt, Roben Castagna Lunardi, Fabrício Girardi Andreis, Cristiano Bonato Both, Luciano Paschoal Gaspary, Lisandro Z. Granville, David Trastour, Claudio Bartolini |
Integrated Network Management | 5 |
| 2009 | A solution to support risk analysis on IT Change ManagementabstractThe growing necessity of organizations in using technologies to support to their operations implies that managing IT resources became a mission-critical issue for the health of the primary companies' businesses. Thus, in order to minimize problems in the IT infrastructure, possibly affecting the daily business operations, risks intrinsic to the change process have to be analyzed and assessed. Risk Management is a widely discussed subject in several areas, although for IT Change Management it is quite a new discipline. The Information Technology Infrastructure Library (ITIL) introduces a set of best practices to conduct the management of IT infrastructures. According to ITIL, risks should be investigated, measured, and mitigated before any change is approved. Even with these guidelines, there is no default automatic method for risk assessment in IT Change Management. In this paper we introduce a risk analysis method based on the execution history of past changes. In addition, we propose a failure representation model to capture the feedback of the execution of changes over IT infrastructures. Juliano Araújo Wickboldt, Guilherme Sperb Machado, Weverton Luis da Costa Cordeiro, Roben Castagna Lunardi, Alan Diego dos Santos, Fabrício Girardi Andreis, Cristiano Bonato Both, Lisandro Z. Granville, Luciano Paschoal Gaspary, Claudio Bartolini, David Trastour |
Integrated Network Management | 4 |