João M. Ceron

dblp:03/9064 · also João Marcelo Ceron · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
4since 2021 · last 2022
0000-0001-6847-8025ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 2 first-author · 1 since 2021Security and privacy · 2 · 2 since 2021
YearPublicationVenuePosition
2022 On the Asymmetry of Internet eXchange Points -Why Should IXPs and CDNs Care?
abstract
Internet eXchange Points (IXPs) provide an infrastructure where content providers and consumers can freely exchange network traffic. The main incentive for connecting to an IXP is to decrease costs and improve the user experience by having content closer to consumers. Despite these benefits, several small Content Delivery Networks (CDNs) avoid exchanging traffic on IXPs due to the poor routing quality via IXP paths. In this paper, we investigate how traffic asymmetry affects the quality of paths. IXP asymmetry occurs when traffic is sent (or received) via a direct IXP peering but received (or sent) on an alternative path outside the IXP. We employ a new method to quantify a symmetry rate for an IXP, which we evaluate on five IXPs. Our method covers three times more ASes than alternatives, such as using RIPE ATLAS. Our results show that IXPs have 15% asymmetric paths at a distance of one AS hop, i.e., when sending traffic to a given peer on the IXP, 15% of this traffic will be responded via a transit AS that does not use the IXP path. We also identify deaf neighbors, i.e., ASes that never return traffic to the IXP. We identify egress-only paths as a major cause of asymmetries and show that this occurs only for a small number of ASes. We also quantify the impact of traffic asymmetry at IXPs in terms of latency and show that traditional traffic engineering on IXP prefixes can actually make route quality worse.
Leandro Marcio Bertholdo, Sandro L. A. Ferreira, João M. Ceron, Lisandro Z. Granville, Ralph Holz, Roland van Rijswijk-Deij
CNSM3
2022 Old but Gold: Prospecting TCP to Engineer and Live Monitor DNS Anycast
Giovane Cesar Moreira Moura, John S. Heidemann, Wes Hardaker, Pithayuth Charnsethikul, Jeroen Bulten, João M. Ceron, Cristian Hesselman
PAM6
2022 Anycast Agility: Network Playbooks to Fight DDoS
A. S. M. Rizvi, Leandro Marcio Bertholdo, João M. Ceron, John S. Heidemann
USENIX Security Symposium3
2021 TANGLED: A Cooperative Anycast Testbed
Leandro Marcio Bertholdo, João M. Ceron, Wouter B. de Vries, Ricardo de Oliveira Schmidt, Lisandro Z. Granville, Roland van Rijswijk-Deij, Aiko Pras
IM2
2020 BGP Anycast Tuner: Intuitive Route Management for Anycast Services
abstract
IP anycast has become a vital technology for DNS and CDN operators alike. Yet, while big operators have their tools to monitor and configure anycast routing, most of anycast networks are still configured manually. In this paper, we introduce a new approach to anycast management. Our solution is based on active measurements combined with traffic engineering. We propose the concept of a "BGP Cookbook" that allows operators to forecast the effects of routing policy changes over their services. We also introduce a web-based interface, called "BGP Anycast Tuner", that allows operators to gain insight into their service's performance and provides easy management through automation. We evaluate our approach by implementing a prototype running in a testbed composed of 12 anycast sites covering 5 continents. We demonstrate our tool in two different use cases: discovering and fixing a sub-optimal anycast routing issue, and shifting traffic between continents, which is useful during service disruptions.
Leandro Marcio Bertholdo, João M. Ceron, Lisandro Z. Granville, Giovane Cesar Moreira Moura, Cristian Hesselman, Roland van Rijswijk-Deij
CNSM2
2020 MikroTik Devices Landscape, Realistic Honeypots, and Automated Attack Classification
abstract
In 2018, several malware campaigns targeted and succeed to infect millions of low-cost routers (malwares e.g., VPN-Filter, Navidade, and SonarDNS). These routers were used, then, for all sort of cybercrimes: from DDoS attacks to ransomware. MikroTik routers are a peculiar example of low-cost routers. These routers are used to provide both last mile access to home users and are used in core network infrastructure. Half of the core routers used in one of the biggest Internet exchanges in the world are MikroTik devices. The problem is that vulnerable firmwares (RouterOS) used in homeusers houses are also used in core networks. In this paper, we are the first to quantify the problem that infecting MikroTik devices would pose to the Internet. Based on more than 4 TB of data, we reveal more than 4 million MikroTik devices in the world. Then, we propose an easy-to-deploy MikroTik honeypot and collect more than 17 millions packets, in 45 days, from sensors deployed in Australia, Brazil, China, India, Netherlands, and the United States. Finally, we use the collected data from our honeypots to automatically classify and assess attacks tailored to MikroTik devices. All our source-codes and analysis are publicly available. We believe that our honeypots and our findings in this paper foster security improvements in MikroTik devices worldwide.
João M. Ceron, Christian Scholten, Aiko Pras, Jair Santanna
NOMS1
2019 Are Darknets All The Same? On Darknet Visibility for Security Monitoring
abstract
Darknets are sets of IP addresses that are advertised but do not host any client or server. By passively recording the incoming packets, they assist network monitoring activities. Since packets they receive are unsolicited by definition, darknets help to spot misconfigurations as well as important security events, such as the appearance and spread of botnets, DDoS attacks using spoofed IP address, etc. A number of organizations worldwide deploys darknets, ranging from a few dozens of IP addresses to large /8 networks. We here investigate how similar is the visibility of different darknets. By relying on traffic from three darknets deployed in different contintents, we evaluate their exposure in terms of observed events given their allocated IP addresses. The latter is particularly relevant considering the shortage of IPv4 addresses on the Internet. Our results suggest that some well-known facts about darknet visibility seem invariant across deployments, such as the most commonly contacted ports. However, size and location matter. We find significant differences in the observed traffic from darknets deployed in different IP ranges as well as according to the size of the IP range allocated for the monitoring.
Francesca Soro, Idilio Drago, Martino Trevisan, Marco Mellia, João M. Ceron, José Jair Santanna
LANMAN5
2017 MARS: From traffic containment to network reconfiguration in malware-analysis systems
abstract
Malware analysis systems are essential to characterize malware behavior and to improve defense mechanisms. In dynamic malware analysis, the actions performed by malware in a sandbox are highly dependent on the interactions with other hosts and services. However, the current solutions superficially deal with the network environment that surrounds the sandbox, exposing limitations to traffic containment and network resources reconfiguration. We have already shown how Software-Defined Networking (SDN) could enable network access policies changes and thus exposing distinct malware actions. In this paper, we investigate the malware analysis process by considering the entire analysis environment, including a sandbox and other components that comprise it. We developed a fully-automated malware analysis solution that uses network layer as a tool to reconfigure the analysis environment. In that way, it is possible to implement per-flow containment rules, dynamic resources configuration, and to manipulate network traffic to impersonate services. Our experiments show that it is feasible to identify behavioral deviations in different analysis scenarios and reveal many more malware behaviors than those revealed by the state-of-the-art analysis systems.
João M. Ceron, Cíntia B. Margi, Lisandro Z. Granville
Comput. Networks1
2016 MARS: An SDN-based malware analysis solution
abstract
Mechanisms to detect and analyze malicious software are essential to improve security systems. Current security mechanisms have limited success in detecting sophisticated malicious software. More than to evade analysis system, many malwares require specific conditions to activate their actions in the target system. The flexibility of Software-Defined Networking (SDN) provides an opportunity to develop a malware analysis architecture integrating different systems and networks profile configuration. In this paper we design an architecture specialized in malware analysis using SDN to dynamically reconfigure the network environment based on malware actions. As result, we demonstrate that our solution can trigger more malware's events than traditional solutions that do not consider sandbox surround environment as an important component in malware analysis.
João M. Ceron, Cíntia B. Margi, Lisandro Z. Granville
ISCC1
2010 Botnet master detection using a mashup-based approach
abstract
Botnets are considered by specialists, in both industry and academy, as one of the greatest threats to security on the Internet. These networks are composed by a large number of malware-infected hosts acting under a central command. They are usually employed to perform DDoS attacks or phishing scams. The behaviour of these botnets evolves due the adoption of new and sophisticated infection methods, changing of network protocols, and the employment of different command and control mechanisms. The security community, thus, is always dealing with such constant change. However, most botnet mitigation methods address just specific infection types or C&C protocols. We, therefore, propose a botnet mitigation approach based on the dynamic integration of pre-existing tools that can be employed together to achieve a more efficiently detection solution. To such end, we base our approach on a novel Web 2.0 technology called mashups to perform the information correlation. The proposal is extensible enough to allow even non-security information such as online mapping APIs be integrated to create more sophisticated compositions, and displaying the results in a more meaningful way.
Carlos Raniery Paula dos Santos, Rafael Santos Bezerra, João M. Ceron, Lisandro Z. Granville, Liane Margarida Rockenbach Tarouco
CNSM3