Eduardo Alchieri

dblp:06/2528 · also Eduardo A. P. Alchieri, Eduardo Adílio Pelinson Alchieri · DBLP profile ↗
← Back
38ranked-venue papers
7as first author
11since 2021 · last 2026
0000-0002-6022-3631ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 9 · 1 first-author · 5 since 2021Security and privacy · 7 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 5 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Computer networks · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021
YearPublicationVenuePosition
2026 On the challenges of enhancing blockchain privacy
abstract
Most blockchain and smart contract platforms store transactions publicly on the ledger. User accounts in these systems rely on public keys to prevent direct identification of the parties. However, various de-anonymization techniques have been used to disclose users’ data, highlighting the weakness of this approach. As a result, the implementation of certain decentralized applications is challenging, especially those involving personal and financial data. In this context, several solutions have been proposed to provide privacy for users of blockchain and smart contract applications. Nonetheless, implementing these solutions is not trivial and introduces additional challenges related to performance, transaction costs, and application complexity. This article describes the practical implementation of Miles2Coins, a blockchain application for buying and selling tokenized airline miles, and details the intricate process of integrating it with Anonymous Zether, a solution designed to provide privacy and anonymity for the parties involved in these transactions. The challenges faced during this integration are explored, revealing key limitations and highlighting the ongoing need for improved privacy approaches in this scenario.
Daniel Almendra, Eduardo Alchieri
J. Comput. Secur.2
2024 Probabilistic Byzantine Fault Tolerance
abstract
Consensus is a fundamental building block for constructing reliable and fault-tolerant distributed services. Many Byzantine fault-tolerant consensus protocols designed for partially synchronous systems adopt a pessimistic approach when dealing with adversaries, ensuring safety even under the worst-case scenarios that adversaries can create. Following this approach typically results in either an increase in the message complexity (e.g., PBFT) or an increase in the number of communication steps (e.g., HotStuff). In practice, however, adversaries are not as powerful as the ones assumed by these protocols. Furthermore, it might suffice to ensure safety and liveness properties with high probability. To accommodate more realistic and optimistic adversaries and improve the scalability of BFT consensus, we propose ProBFT (Probabilistic Byzantine Fault Tolerance). ProBFT is a leader-based probabilistic consensus protocol with a message complexity of [EQUATION] and an optimal number of communication steps that tolerates Byzantine faults in permissioned partially synchronous systems. It is built on top of well-known primitives, such as probabilistic Byzantine quorums and verifiable random functions. ProBFT guarantees safety and liveness with high probability even with faulty leaders, as long as a supermajority of replicas is correct and using only a fraction (e.g., 20%) of messages exchanged in PBFT. We provide a detailed description of ProBFT's protocol and its analysis.
Diogo Avelas, Hasan Heydari, Eduardo Alchieri, Tobias Distler, Alysson Neves Bessani
PODC3
2024 DDoS attack detection in SDN: Enhancing entropy-based detection with machine learning
abstract
Summary Software defined network (SDN) has emerged as a new paradigm in terms of network architecture, providing flexibility, agility, and programmability to network management. These benefits boosted the SDN adoption, bringing new challenges mainly related to security, in particular, those related to Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks. The detection, prevention, and mitigation of these attacks are important since they can affect the entire network. Many current security measures use statistical techniques, as entropy, or machine learning (ML) algorithms to detect DoS and DDoS attacks. While the definition of a threshold to determine whether a traffic is an attack is not trivial in statistical techniques, ML solutions may provide better accuracy but require considerable computational resources and time to converge to a model able to detect these attacks. Trying to circumvent these limitations, current hybrid approaches either use the results from entropy as input in ML algorithms (EntropyML) or use entropy as a filter and ML algorithms to identify attacks. This work goes one step ahead and combines these techniques in a three‐step approach (EntropyMLEntropy), called ML‐Entropy, which inherits the intelligence of ML algorithms to adjust the threshold used by entropy. The proposed solution was implemented and evaluated in two datasets, the well‐known synthetic DARPA dataset and a dataset composed by traffic collected from a real‐corporate environment. Experimental results show that, in general, ML‐Entropy presents an accuracy above 99%, similar to support vector machine (SVC) and random forest (RF) algorithms, being able to converge to a detection model up to and faster than RF and SVC, respectively.
Marcos J. Santos-Neto, Jacir Luiz Bordim, Eduardo Alchieri, Edison Ishikawa
Concurr. Comput. Pract. Exp.3
2023 SEMFOGO: An Intelligent Fire Detection System for the Cerrado Biome
abstract
Forest fires have the potential to cause enormous social, economic and, above all, environmental damage. Nowadays, the intelligent and early detection of forest fires is a fundamental technological tool for rescue and emergency agencies in mitigating damage. Among the possibilities, video surveillance technology in conjunction with artificial intelligence and computer vision techniques proves to be an interesting solution. This work proposes the SEMFOGO system, an intelligent system for monitoring and rapid detection of fires in the cerrado region, which currently in South America has an area of 2,045,000 km2between Brazil, Bolivia and Paraguay. The SEMFOGO solution uses the massive capture and processing of video streams through a distributed and scalable system and applies a deep learning model that performs a grid classification on parts of the image. This work also presents a new training dataset specific to the cerrado region with smoke contour annotations. The experimental results compared the metrics of several models and show the practical feasibility of the proposed solution for real time fire detection.
Natalia O. Borges, Lívia G. C. Fonseca, Priscila Solís Barreto, Eduardo Alchieri, Marcos F. Caetano, Daniel C. Araujo 0001, Paulo Angelo A. Resende, Leonardo Brandão
CLEI4
2023 FlexCast: Genuine Overlay-based Atomic Multicast
abstract
Atomic multicast is a communication abstraction where messages are propagated to groups of processes with reliability and order guarantees. Atomic multicast is at the core of strongly consistent storage and transactional systems. This paper presents FlexCast, the first genuine overlay-based atomic multicast protocol. Genuineness captures the essence of atomic multicast in that only the sender of a message and the message's destinations coordinate to order the message, leading to efficient protocols. Overlay-based protocols restrict how process groups can communicate. Limiting communication leads to simpler protocols and reduces the amount of information each process must keep about the rest of the system. FlexCast implements genuine atomic multicast using a complete DAG overlay. We experimentally evaluate FlexCast in a geographically distributed environment using gTPC-C, a variation of the TPC-C benchmark that takes into account geographical distribution and locality. We show that, by exploiting genuineness and workload locality, FlexCast outperforms well-established atomic multicast protocols without the inherent communication overhead of state-of-the-art non-genuine multicast protocols.
Elia Batista, Paulo R. Coelho, Eduardo Alchieri, Fernando Luís Dotti, Fernando Pedone
Middleware3
2023 5G-RCOLAB: A system level simulator for 5G and beyond in rural areas
Gabriel de Carvalho Ferreira, Priscila Solís Barreto, Marcos F. Caetano, Eduardo Alchieri, Daniel C. Araujo 0001, Francisco Rodrigo Porto Cavalcanti, Diego Aguiar Sousa
Comput. Commun.4
2023 DataPlane-ML: An integrated attack detection and mitigation solution for software defined networks
abstract
Summary Software defined network (SDN) is a paradigm that emphasizes the separation of the control plane from the data plane, offering advantages such as flexibility and programmability. However, from a security perspective, SDN also introduces new vulnerabilities due to the communication required between these planes. SYN Flood attacks are typical distributed denial‐of‐service (DDoS) attacks that especially challenge network administrators since they produce a large volume of semi‐open TCP connections to a target, compromising its availability. Most of the current solutions to detect and mitigate these attacks are designed to operate at the control plane, imposing an additional overhead on controller functions. Moreover, traffic‐blocking mechanisms, a widely used alternative to protect network resources, have the drawback of restricting legitimate traffic. This work proposes DataPlane‐ML, an integrated solution to detect and mitigate DDoS attacks on SDN, acting directly in the data plane. DataPlane‐ML uses machine learning techniques for attack detection and a mitigation solution based on the node's reputation to avoid blocking legitimate traffic during an attack. Experimental results show that DataPlane‐ML is faster than statistical‐based solutions for attack detection while presenting better accuracy. Moreover, the DataPlane‐ML mitigation solution can preserve more than of legitimate traffic during an attack.
Ranyelson Neres Carvalho, Lucas Rodrigues Costa, Jacir Luiz Bordim, Eduardo Alchieri
Concurr. Comput. Pract. Exp.4
2022 COBRA: Dynamic Proactive Secret Sharing for Confidential BFT Services
abstract
Byzantine Fault-Tolerant (BFT) State Machine Replication (SMR) is a classical paradigm for implementing trustworthy services that has received renewed interest with the emergence of blockchains and decentralized infrastructures. A fundamental limitation of BFT SMR is that it provides integrity and availability despite a fraction of the replicas being controlled by an active adversary, but does not offer any confidentiality protection. Previous works addressed this issue by integrating secret sharing with the consensus-based framework of BFT SMR, but without providing all features required by practical systems, which include replica recovery, group reconfiguration, and acceptable performance when dealing with a large number of secrets. We present COBRA, a new protocol stack for Dynamic Proactive Secret Sharing that allows implementing confidentiality in practical BFT SMR systems. COBRA exhibits the best asymptotic communication complexity and optimal storage overhead, being able to renew 100k shares in a group of ten replicas $5 \times $ faster than the current state of the art.
Robin Vassantlal, Eduardo Alchieri, Bernardo Ferreira, Alysson Neves Bessani
SP2
2022 Early scheduling on steroids: Boosting parallel state machine replication
abstract
State machine replication (SMR) is a standard approach to fault tolerance in which replicas execute requests deterministically and often serially. For performance, some techniques allow concurrent execution of requests in SMR while keeping determinism. Such techniques exploit the fact that independent requests can execute concurrently. A promising category of early scheduling solutions trades scheduling freedom for simplicity, allowing to expedite decisions during scheduling. This paper generalizes early scheduling and proposes a general method to schedule requests to threads, restricting scheduling overhead. Moreover, it explores improvements to the original early scheduling mechanism, namely the use of busy-wait synchronization and work-stealing techniques. We integrate early scheduling and its proposed improvements to a popular SMR framework. Performance results of the basic mechanism and its improvements are presented and compared to more classic approaches, where it is shown that early scheduling with our proposed enhancements can outperform the original early scheduling and other systems by a large margin in many scenarios.
Elia Batista, Eduardo Alchieri, Fernando Luís Dotti, Fernando Pedone
J. Parallel Distributed Comput.2
2022 Exploiting Concurrency in Sharded Parallel State Machine Replication
abstract
State machine replication (SMR) is a well-known approach to implementing fault-tolerant services, providing high availability and strong consistency. In classic SMR, commands are executed sequentially, in the same order by all replicas. To improve performance, two classes of protocols have been proposed to parallelize the execution of commands. Early scheduling protocols reduce scheduling overhead but introduce costly synchronization of worker threads; late scheduling protocols, instead, reduce the cost of thread synchronization but suffer from scheduling overhead. Depending on the characteristics of the workload, one class can outperform the other. We introduce a hybrid scheduling technique that builds on the existing protocols. An experimental evaluation has revealed that the hybrid approach not only inherits the advantages of each technique but also scales better than either one of them, improving the system performance by up to$3\times$in a workload with conflicting commands.
Aldenio Burgos, Eduardo Alchieri, Fernando Luís Dotti, Fernando Pedone
IEEE Trans. Parallel Distributed Syst.2
2021 DoSSec: A Reputation-Based DoS Mitigation Mechanism on SDN
Ranyelson Neres Carvalho, Lucas Rodrigues Costa, Jacir Luiz Bordim, Eduardo Alchieri
AINA (2)4
2020 New Programmable Data Plane Architecture Based on P4 OpenFlow Agent
Ranyelson Neres Carvalho, Lucas Rodrigues Costa, Jacir Luiz Bordim, Eduardo Alchieri
AINA4
2020 A Secure and Distributed Control Plane for Software Defined Networks
Jefferson Pereira da Silva, Eduardo Alchieri, Jacir Luiz Bordim, Lucas Rodrigues Costa
AINA2
2020 From Byzantine Replication to Blockchain: Consensus is Only the Beginning
abstract
The popularization of blockchains leads to a resurgence of interest in Byzantine Fault-Tolerant (BFT) state machine replication protocols. However, much of the work on this topic focuses on the underlying consensus protocols, with emphasis on their lack of scalability, leaving other subtle limitations unaddressed. These limitations are related to the effects of maintaining a durable blockchain instead of a write-ahead log and the requirement for reconfiguring the set of replicas in a decentralized way. We demonstrate these limitations using a digital coin blockchain application and BFT-SMaRt, a popular BFT replication library. We show how they can be addressed both at a conceptual level, in a protocol-agnostic way, and by implementing SMaRtChain, a blockchain platform based on BFT-SMaRt. SMaRtChain improves the performance of our digital coin application by a factor of eight when compared with a naive implementation on top of BFT-SMaRt. Moreover, SMaRtChain achieves a throughput 8x and 33x better than Tendermint and Hyperledger Fabric, respectively, when ensuring strong durability on its blockchain.
Alysson Neves Bessani, Eduardo Alchieri, João Sousa 0002, André Oliveira 0002, Fernando Pedone
DSN2
2019 Transparent State Machine Replication for Kubernetes
Felipe Borges, Luís Pacheco 0001, Eduardo Alchieri, Marcos F. Caetano, Priscila Solís Barreto
AINA3
2019 Reducing the IEEE 802.11 Beacon Overhead in Low Mobility Networks
Gabriel de Carvalho Ferreira, Priscila Solís Barreto, Eduardo Alchieri
AINA3
2019 Pentest on Internet of Things Devices
abstract
Internet of Things (IoT) is one of the key enabling technologies for an always-connected world and also a main enabler for generating information of interest in various application domains. A growing problem in recent years in this technology is security, as power-constrained devices that are typical of IoT applications may not always provide these implementations properly. These conditions can compromise entire environments and allow malicious agents to take control and perform malicious activities. In this article, we provide a summary of the principal vulnerabilities reported for IoT devices based on the OWASP Internet of Things Project, classified by test routine groups. Using models based on standard architectures to define and detail reproducible verification routines for each test, a selection of independent analyzes of each identified category was performed to ensure more comprehensive and accurate testing. Finally, the proposed routines are performed in a test environment to exemplify and ensure their operation, thus contributing to meeting the demand in the area for more accurate information and to assist in understanding the most common vulnerabilities.
Cristoffer Leite, João J. C. Gondim, Priscila Solís Barreto, Marcos F. Caetano, Eduardo Alchieri
CLEI5
2019 Performance Analysis of an Hyperconverged Infrastructure using Docker Containers and GlusterFS
abstract
The adoption of hyperconverged infrastructures is a trend in datacenters, because it merges different type of computing and storage resources. Hyperconverged infrastructures use distributed file systems (DFS) to store and replicate data between multiple servers while using computing resources of the same servers to host virtual machines or containers. In this work, the distributed file system GlusterFS and the hypervisor VMware ESXi are used to build an hyperconverged system to host Docker containers, with the goal of evaluate the storage performance of this system compared to traditional approach where data is stored directly on the server’s disks. The performance of the container’s persistent storage is evaluated using the benchmark tool Yahoo Cloud Service Benchmark (YCSB) against the NoSQL databases Cassandra and MongoDB under differents workloads. The NoSQL database’s performance was compared between the hyperconverged system with multiples disk configurations and a traditional system with local storage.
Rodrigo Leite, Priscila Solís Barreto, Eduardo Alchieri
CLOSER3
2019 Boosting concurrency in Parallel State Machine Replication
abstract
State machine replication (SMR) is a well-known approach to implementing fault-tolerant services, providing high availability and strong consistency. To boost the performance of SMR, some proposals execute independent commands concurrently, while dependent commands execute sequentially in the total delivery order. The most general approach to handling command dependencies resorts to a directed acyclic graph (DAG), where nodes represent commands and edges represent dependencies. In this paper we show that due to the command arrival and multithreaded execution rates of SMR, a highly concurrent implementation of a DAG is needed. We show that a typical coarse-grained DAG implementation, where the whole graph is a critical section, results in a bottleneck in the replica. We propose two improvements to the coarse-grained DAG approach: fine-grained algorithms, using lock-coupling, and lock-free algorithms. Our fine-grain algorithms lock individual vertices in the DAG. The lock-free algorithms use nonblocking synchronization, with atomic operations, and lazy synchronization to postpone physical removal of nodes. All algorithms were integrated in a parallel SMR prototype. Experimental evaluation revealed that the fine-grained algorithms are also subject to a bottleneck. The lock-free implementation, however, sports linear speedup with the number of working threads, in some cases scaling up to 64 threads.
Ian Aragon Escobar, Eduardo Alchieri, Fernando Luís Dotti, Fernando Pedone
Middleware2
2019 Waste Flooding: A Phishing Retaliation Tool
abstract
Phishing is a well known attack technique that is still a growing threat in the security area. The Internet popularity and the always connected users increased phishing possibilities by giving attackers new instruments and allowing closer contact to their focus. By applying social engineering methods, phishing thrives on misinformation and because of this, current main phishing response methods focus only on educating users or blocking phishing attempts, without any response to derail the already implemented attacks. These conditions may leave targeted users unprotected, as any leaked information can not be tracked to determine which person suffered from phishing and compromised data that can not be saved or easily detected. In this paper, we present, analyse and evaluate a new response tool that aims to furtively retaliate these attacks by automatic detecting phishing forms and using them to clutter phishing databases with useless information and conceal user data. The evaluation shows that the tool may be useful as a detection-resistant solution and gives a fair response to phishing attempts by flooding the phishing databases.
Cristoffer Leite, João J. C. Gondim, Priscila Solís Barreto, Eduardo Alchieri
NCA4
2019 Building secure protocols for extensible distributed coordination through secure extensions
Edson Floriano, Eduardo Alchieri, Diego F. Aranha, Priscila Solís Barreto
Comput. Secur.2
2018 Diversity on State Machine Replication
abstract
The dependability and security properties of a system could be impaired by a system failure or by an opponent that exploits its vulnerabilities, respectively. An alternative to mitigate this risk is the implementation of fault- and intrusion-tolerant systems, in which the system properties are ensured even if some of its components fail (e.g., because a software bug or a failure in the runtime environment) or are compromised by a successful attack. State Machine Replication (SMR) is widely used to implement these systems. In SMR, servers are replicated and client requests are deterministically executed in the same order by all replicas in a way that the system behavior remains correct even if some of them are compromised since the correct replicas mask the misbehavior of the faulty ones. Unfortunately, the proposed solutions for SMR do not consider diversity in the implementation and all replicas execute the same software. Consequently, the same attack or software bug could compromise all the system. Trying to circumvent this problem, this work proposes an architecture to allow diversity in SMR, allowing the implementation and execution of replicas in different development languages. The main problems addressed by the proposed architecture are twofold: (1) communication among different languages; and (2) data representation. The proposed architecture was integrated in BFT-SMART, a SMR library, and a set of experiments showed its practical feasibility.
Caio Yuri da Silva Costa, Eduardo Alchieri
AINA2
2018 On the Impossibility of Byzantine Collision-Fast Atomic Broadcast
abstract
The inefficiency of Consensus-based Atomic Broadcast protocols in the presence of collisions (concurrent proposals) harms their adoption in the implementation of State Machine Replication. Proposals that are not decided in some instance of Consensus (commands not delivered) must be re-proposed in a new instance, delaying their execution. The CFABCast (Collision-Fast Atomic Broadcast) algorithm uses M-Consensus to decide and deliver multiple values in the same instance. However, CFABCast is not Byzantine fault-tolerant, a requirement for many systems. Our first contribution is a modified version of CFABCast to handle Byzantine failures. Unfortunately, the resulting protocol is not collision-fast due to the possibility of malicious failures. In fact, our second contribution is to prove that there are no Byzantine collision-fast algorithms in an asynchronous model as traditionally extended to solve Consensus. Finally, our third contribution is a Byzantine collision-fast algorithm that bypasses the stated impossibility by means of a USIG (Unique Sequential Identifier Generator) trusted component.
Rodrigo Q. Saramago, Eduardo Alchieri, Tuanir F. Rezende, Lásaro J. Camargos
AINA2
2018 Early Scheduling in Parallel State Machine Replication
abstract
State machine replication, a classic approach to fault tolerance, requires replicas to execute operations deterministically. Deterministic execution is typically ensured by having replicas execute operations serially in the same total order. Two classes of techniques have extended state machine replication to execute operations concurrently: late scheduling and early scheduling. With late scheduling, operations are scheduled for execution after they are ordered across replicas. With early scheduling, part of the scheduling decisions are made before requests are ordered; after requests are ordered, their scheduling must respect these restrictions. This paper generalizes early scheduling techniques. We propose an automated mechanism to schedule operations on worker threads at replicas, integrate our contributions to a popular state machine replication framework, and experimentally compare the resulting system to late scheduling.
Eduardo Alchieri, Fernando Luís Dotti, Fernando Pedone
SoCC1
2018 Security and Privacy in Extensible Distributed Coordination
abstract
Mechanisms for coordination and synchronization, like shared counters and distributed queues, are used in the development of many distributed systems. These mechanisms are implemented on top of coordination infrastructures, such as tuple spaces. A recent study showed that extensibility is fundamental for performance: the main idea is to allow the servers supporting the coordination infrastructure to access and process coordination information, consequently, it is not necessary to transfer information to clients or to reprocess requests due to concurrency. Unfortunately, existing proposals for extensible distributed coordination do not provide security and privacy once servers must access data in plaintext. This work proposes the use of robust cryptographic schemes, recently integrated into DEPSPACE, to develop secure protocols for extensible coordination. Experiments show that the proposed solutions significantly improve system performance.
Edson Floriano, Eduardo Alchieri, Diego F. Aranha, Priscila Solís Barreto
ISCC2
2018 Knowledge Connectivity Requirements for Solving Byzantine Consensus with Unknown Participants
abstract
Consensus is a fundamental building block to solve many practical problems that appear on reliable distributed systems. In spite of the fact that consensus is being widely studied in the context of standard networks, few studies have been conducted in order to solve it in dynamic and self-organizing systems characterized by unknown networks. While in a standard network the set of participants is static and known, in an unknown network, such set and number of participants are previously unknown. This work studies the problem of Byzantine Fault-Tolerant Consensus with Unknown Participants, namely BFT-CUP. This new problem aims at solving consensus in unknown networks with the additional requirement that participants in the system may behave maliciously. It presents the necessary and sufficient knowledge connectivity conditions in order to solve BFT-CUP under minimal synchrony requirements. In this way, it proposes algorithms that are shown to be optimal in terms of synchrony and knowledge connectivity among participants in the system.
Eduardo Alchieri, Alysson Neves Bessani, Fabíola Greve, Joni da Silva Fraga
IEEE Trans. Dependable Secur. Comput.1
2017 PAS-CA: A cloud computing auto-scalability method for high-demand web systems
abstract
This work proposes an auto scaling method for high demanding web applications in a cloud computing system. The proposal has the goal to increase efficiency in containers allocation for processing web requests considering a threshold for applications response time. The method was developed using a control algorithm that applies adjustments based on the properties extracted from workload characterization. The method was evaluated with different types of workloads and the results show that the proposal achieves good results by allocating containers more efficiently than other solutions already well-known in the cloud computing market.
Marcelo Cerqueira de Abranches, Priscila Solís Barreto, Eduardo Alchieri
NCA3
2017 Enhancing and evaluating an architecture for privacy in the integration of Internet of Things and cloud computing
abstract
Through the Internet of Things (IoT) a large number of devices are connected to the Internet, resulting in a huge amount of produced data. Since these devices have limited resources, it is proposed the use of cloud computing to store, process and control the access to these data. A fundamental challenge related to this integration is the privacy, since confidential information about users may be collected by IoT devices and sent to the cloud. Consequently, it is imperative to provide mechanisms that allow users to control the use of their data. The proposed architectures either do not provide security inside the IoT network or do not evaluate the overhead imposed in the IoT devices. In order to fill this gap, this work evaluates and enhances an architecture for privacy in the integration of IoT and cloud computing by providing a method to protect the data generated by IoT devices without the use of a secure transport layer protocol, decreasing the amount of resources consumed by these devices. The proposed method is analyzed, in terms of delay and energy consumption, by an analytical and an experimental evaluation, comparing its performance with other approaches found in the literature.
Luís Pacheco 0001, Eduardo Alchieri, Priscila Solís Barreto
NCA2
2017 Efficient and Modular Consensus-Free Reconfiguration for Fault-Tolerant Storage
abstract
Quorum systems are useful tools for implementing consistent and available storage in the presence of failures. These systems usually comprise a static set of servers that provide a fault-tolerant read/write register accessed by a set of clients. We consider a dynamic variant of these systems and propose FreeStore, a set of fault-tolerant protocols that emulates a register in dynamic asynchronous systems in which processes are able to join/leave the servers set during the execution. These protocols use a new abstraction called view generators, that captures the agreement requirements of reconfiguration and can be implemented in different system models with different properties. Particularly interesting, we present a reconfiguration protocol that is modular, efficient, consensus-free and loosely coupled with read/write protocols, improving the overall system performance.
Eduardo Alchieri, Alysson Neves Bessani, Fabíola Greve, Joni da Silva Fraga
OPODIS1
2017 Reconfiguring Parallel State Machine Replication
abstract
State Machine Replication (SMR) is a well-known technique to implement fault-tolerant systems. In SMR, servers are replicated and client requests are deterministically executed in the same order by all replicas. To improve performance in multi-processor systems, some approaches have proposed to parallelize the execution of non-conflicting requests. Such approaches perform remarkably well in workloads dominated by non-conflicting requests. Conflicting requests introduce expensive synchronization and result in considerable performance loss. Current approaches to parallel SMR define the degree of parallelism statically. However, it is often difficult to predict the best degree of parallelism for a workload and workloads experience variations that change their best degree of parallelism. This paper proposes a protocol to reconfigure the degree of parallelism in parallel SMR on-the-fly. Experiments show the gains due to reconfiguration and shed some light on the behavior of parallel and reconfigurable SMR.
Eduardo Alchieri, Fernando Luís Dotti, Odorico Machado Mendizabal, Fernando Pedone
SRDS1
2016 Evaluation of Distributed Denial of Service threat in the Internet of Things
abstract
There is a concern about possible threats deriving from the widespread adoption of IoT (Internet of Things). The number of devices connected to the Internet is going to increase dramatically, potentiating their security risks. A Distributed Denial of Service (DDoS) attack is a good candidate to explore IoT security vulnerabilities, because of the enormous number of new devices connected to the Internet there is also an increase in the number of possible compromised devices. This study aims to analyze the efficiency of a DDoS attack in a typical IoT environment, by using simulations that, in the best of our knowledge, have not been conducted yet.
Luís Pacheco 0001, João J. C. Gondim, Priscila Solís Barreto, Eduardo Alchieri
NCA4
2014 State Machine Replication for the Masses with BFT-SMART
abstract
The last fifteen years have seen an impressive amount of work on protocols for Byzantine fault-tolerant (BFT) state machine replication (SMR). However, there is still a need for practical and reliable software libraries implementing this technique. BFT-SMART is an open-source Java-based library implementing robust BFT state machine replication. Some of the key features of this library that distinguishes it from similar works (e.g., PBFT and UpRight) are improved reliability, modularity as a first-class property, multicore-awareness, reconfiguration support and a flexible programming interface. When compared to other SMR libraries, BFT-SMART achieves better performance and is able to withstand a number of real-world faults that previous implementations cannot.
Alysson Neves Bessani, João Sousa 0002, Eduardo Alchieri
DSN3
2012 Intrusion-Tolerant Shared Memory through a P2P Overlay Segmentation
abstract
This paper describes our experience in developing an infrastructure which allows building intrusion-tolerant shared memory for large-scale systems. The infrastructure makes use of a P2P overlay and of the concept of State Machine Replication (SMR). Segmentation is introduced on the overlay key space to allow the use of algorithms for SMR. In this paper we describe the proposed infrastructure in its stratification and corresponding algorithms. An analysis about the algorithms and their costs is also presented.
Davi da Silva Böger, Joni da Silva Fraga, Eduardo Alchieri, Michelle S. Wangham
AINA3
2012 Brief Announcement: Decoupled and Consensus-Free Reconfiguration for Fault-Tolerant Storage
Eduardo Alchieri, Alysson Neves Bessani, Fabíola Greve, Joni da Silva Fraga
DISC1
2008 DepSpace: a byzantine fault-tolerant coordination service
abstract
The tuple space coordination model is one of the most interesting coordination models for open distributed systems due to its space and time decoupling and its synchronization power. Several works have tried to improve the dependability of tuple spaces through the use of replication for fault tolerance and access control for security. However, many practical applications in the Internet require both fault tolerance and security. This paper describes the design and implementation of DepSpace, a Byzantine fault-tolerant coordination service that provides a tuple space abstraction. The service offered by DepSpace is secure, reliable and available as long as less than a third of service replicas are faulty. Moreover, the content-addressable confidentiality scheme developed for DepSpace bridges the gap between Byzantine fault-tolerant replication and confidentiality of replicated data and can be used in other systems that store critical data.
Alysson Neves Bessani, Eduardo Alchieri, Miguel Correia 0001, Joni da Silva Fraga
EuroSys2
2008 A Dependable Infrastructure for Cooperative Web Services Coordination
abstract
A current trend in the web services community is to define coordination mechanisms to execute collaborative tasks involving multiple organizations. Following this tendency, this work presents a dependable (i.e., intrusion-tolerant) infrastructure for cooperative web services coordination that is based on the tuple space coordination model. This infrastructure provides decoupled communication and implements several security mechanisms that allow reliable coordination even in presence of malicious components.This work also investigates the costs related to the use of this infrastructure and possible web service applications that can benefit from it.
Eduardo Alchieri, Alysson Neves Bessani, Joni da Silva Fraga
ICWS1
2008 Byzantine Consensus with Unknown Participants
Eduardo Alchieri, Alysson Neves Bessani, Joni da Silva Fraga, Fabíola Greve
OPODIS1
2006 Evaluation of QoS Metrics in Ad Hoc Networks with the use of Secure Routing Protocols
abstract
An Ad Hoc nework is formed by mobile computer (nodes) with wireless interfaces that communicate amongst themselves without the help of any infrastructure. Due to their characteristics, the Ad Hoc networks are prone to the presence of malicious nodes that can degrade your performance. This fact motivated the appearance of security protocols that implement mechanisms to avoid attacks like DoS. In this article is accomplished a verification the impact caused in the performance of the Ad Hoc networks with the use of security protocols (SEAD and Ariadne) in relation to the use of protocols that don't have security mechanisms (DSDV and DSR). Firstly an Ad Hoc network is simulated using these routing protocols and soon afterwards a comparative study is accomplished through graphs of the values obtained for each basic QoS metrics.
Darlan Vivian, Eduardo Alchieri, Carlos Becker Westphall
NOMS2