EDBT 2026 Demo / reviewers in the wild / expert
David R. Matos
dblp:191/4609
· DBLP profile ↗
13ranked-venue papers
4as first author
6since 2021 · last 2025
0000-0001-6834-705XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 first-authorSystems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | EvoChain: A Recovery Approach for Permissioned Blockchain ApplicationsabstractBlockchain technology provides decentralized data storage and processing. It can ensure data integrity and auditability. Many applications now adopt it in scenarios with multiple stakeholders and shared ownership, such as supply chain management. However, strict immutability makes it difficult to correct mistakes or intrusions in real-world deployments.This paper presents EvoChain, a chaincode extension for Hyperledger Fabric, a permissioned blockchain platform. EvoChain adds controlled mutability, allowing data to be corrected or recovered under time-limited or specific conditions. Changes can be made during a grace period, after which immutability is enforced again.We evaluated our approach with WineTracker, a supply chain application. It was modified to allow some users to cancel unwanted operations while preserving the security and consistency of data in the blockchain. Performance results show minimal overhead with functional benefits. Francisco Faria, Samih Eisa, David R. Matos, Miguel L. Pardal |
NCA | 3 |
| 2025 | Bonsai: A Recovery Approach for Ethereum ERC-20 TransactionsabstractBlockchain technology offers a mechanism for storing data with cryptographic links between blocks, creating a tamper-resistant ledger. Although this immutability ensures data integrity, it complicates recovery in cases of errors or intrusions. This work proposes Bonsai, an error and intrusion recovery system designed for token exchanges on Ethereum based applications. The system includes a custom ERC-20 token (BON) that maintains a one to one peg with ETH tokens while enabling transaction reversals through arbitration trials and an insurance mechanism to protect users against losses. Our experimental evaluation on Ethereum Sepolia and ZKsync Sepolia demonstrates that Bonsai can successfully trace and reverse token flows through up to five wallets in under 20 seconds, at an average cost of approximately ${\$}$0.30 on ZKsync. Existing blockchain recovery approaches are slow and costly, with reversal operations taking up to 126 seconds, and some may not be able to complete the reversal. The system provides a practical solution for blockchain applications requiring error and intrusion correction capabilities while preserving the authentication, integrity, immutability, and non-repudiation properties of Blockchain. Diogo Melita, David R. Matos, Miguel L. Pardal |
NCA | 2 |
| 2025 | Rûm: Multivalued Loss-Tolerant Byzantine Consensus for Mobile Ad-Hoc NetworksabstractWe present Rûm, a randomized asynchronous multivalued byzantine consensus algorithm designed for mobile ad-hoc networks, operating under the message omission/loss model of Santoro-Widmayer. Rûm is optimal with respect to the byzantine fault bound, and makes progress in rounds where the number of message omissions is bounded, while always ensuring safety. Through network simulations conducted in ns-3, Rûm’s performance is evaluated against Turquois and Ezhilchelvan et al.’s multivalued consensus algorithm, demonstrating its ability to achieve consensus in the presence of byzantine faults and message loss. The results indicate that Rûm can efficiently handle message omissions and byzantine faults, maintaining reliable decision-making processes, making it a suitable solution for consensus in mobile ad-hoc networks. João Pedro 0001, Guilherme Ramos, David R. Matos |
NCA | 3 |
| 2023 | MultiTLS: using multiple and diverse ciphers for stronger secure channels
Ricardo Moura, Ricardo Lopes, David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
Comput. Secur. | 3 |
| 2023 | MIRES: Intrusion Recovery for Applications Based on Backend-As-a-ServiceabstractThe Backend-as-a-Service (BaaS) cloud computing model supports many modern popular mobile applications because it simplifies the development and management of services such as data storage, user authentication, and notifications. However, vulnerabilities and other issues may allow malicious actions on the client side to have impact on the backend, i.e., to corrupt the state of the application in the cloud. To deal with these attacks – after they occur and are successful – it is necessary to remove the direct effects of malicious requests and the effects derived from later operations on corrupted data. We introduce MIRES, the first intrusion recovery service for mobile applications based on the BaaS model. MIRES uses a two-stage recovery process that restores the integrity of the mobile application and minimizes its unavailability. MIRES provides multi-service recovery for applications that use more than one data store. We implemented MIRES for Android and for the Firebase cloud-based BaaS platform. We did experiments on 4 mobile applications which showed that MIRES can revert hundreds to thousands of operations in seconds, with an associated unavailability of the application also in the range of seconds. Diogo Vaz, David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
IEEE Trans. Cloud Comput. | 2 |
| 2023 | Sanare: Pluggable Intrusion Recovery for Web ApplicationsabstractWeb applications are exposed to many threats and, despite the best defensive efforts, are often successfully attacked. Reverting the effects of an attack on the state of such an application requires a profound knowledge about the application, to understand what data did the attack corrupt. Furthermore, it requires knowing what steps are needed to revert the effects without modifying legitimate data created by legitimate users. Existing intrusion recovery systems are capable of reverting the effects of the attack but they require modifications to the source code of the application, which may be unpractical. We presentSanare, a pluggable intrusion recovery system designed for web applications that use different data storage systems to keep their state. Sanare does not require any modification to the source code of the application or the web server. Instead, it uses a new deep learning scheme that we also introduce in the article,Matchare, that learns the matches between the HTTP requests and the database statements, file system operations, and web service requests that the HTTP requests caused. We evaluated Sanare with three open source web applications: WordPress, GitLab and ownCloud. In our experiments, Matchare achieved precision and recall higher than 97.5% with a performance overhead of less than 18% to the application. David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | MIRES: Recovering Mobile Applications based on Backend-as-a-Service from Cyber AttacksabstractMany popular mobile applications rely on the Backend-as-a-Service (BaaS) cloud computing model to simplify the development and management of services like data storage, user authentication and notifications. However, vulnerabilities and other issues may lead to malicious operations on the mobile application client-side and malicious requests being sent to the backend, corrupting the state of the application in the cloud. To deal with these attacks after they happen and are successful, it is necessary to remove the immediate effects created by the malicious requests and subsequent effects derived from later requests. In this paper, we present MIRES, an intrusion recovery service for mobile applications based on BaaS. MIRES uses a two-phase recovery process that restores the integrity of the mobile application and minimizes its unavailability. We implemented MIRES in Android and with the Firebase platform and made experiments with 3 mobile applications that showed results of 1000 operations reverted in less than 1 minute and with the mobile application inaccessible only for less than 15 seconds. Diogo Vaz, David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
MobiQuitous | 2 |
| 2020 | MERLIN: Multi-Language Web Vulnerability DetectionabstractAlthough there is continuous research to improve web security, web applications are constantly being attacked due to vulnerable source code. A common way used to find vulnerabilities in code is with source code static analysis tools. However, these tools have two problems: they must be coded manually to deal with all types of vulnerabilities and they only work with a specific programming language. This paper presents an approach that aims to improve security of web applications by identifying vulnerabilities in code written in different languages. Moreover, we do not hard-code the rules of detection, but instead use machine learning to configure them. The approach was implemented in a tool called MERLIN. This tool was tested with samples from the SRD database and real-world web applications written in Java and PHP. Alexandra Figueiredo, Tatjana Lide, David R. Matos, Miguel Correia 0001 |
NCA | 3 |
| 2020 | Recoverable Token: Recovering from Intrusions against Digital Assets in EthereumabstractBlockchain systems allow storing digital assets in a tamper-proof, consensus-based, append-only ledger in a decentralized fashion, where no single party has full control. A blockchain is an immutable, append-only, log of transactions. Unfortunately, in some cases there is the need to undo transactions that result from intrusions, e.g., when the private keys of a wallet are stolen, when one of the transaction participants does not comply with what was agreed upon, or when smart contract vulnerabilities are exploited by attackers. There are also accidental scenarios, e.g., when private keys are lost leaving the associated digital assets inaccessible. Although there have been a few proposals which allow modifications to the blockchain, they break the basic guarantees they are supposed to provide. We propose an approach for wallet owners to recover from attacks against their digital assets and accidental loss, while still assuring fundamental properties of the blockchain technology. We implemented the mechanism for Ethereum / EVM. Filipe F. Martins, David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
NCA | 2 |
| 2020 | MultiTLS: Secure Communication Channels with Cipher Suite Diversity
Ricardo Moura, David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
SEC | 2 |
| 2018 | RockFS: Cloud-backed File System Resilience to Client-Side AttacksabstractCloud-backed file systems provide on-demand, high-availability, scalable storage. Their security may be improved with techniques such as erasure codes and secret sharing to fragment files and encryption keys in several clouds. Attacking the server-side of such systems involves penetrating one or more clouds, which can be extremely difficult. David R. Matos, Miguel L. Pardal, Georg Carle, Miguel Correia 0001 |
Middleware | 1 |
| 2017 | Rectify: black-box intrusion recovery in PaaS cloudsabstractWeb applications hosted on the cloud are exposed to cyberattacks and can be compromised by HTTP requests that exploit vulnerabilities. Platform as a Service (PaaS) offerings often provide a backup service that allows restoring application state after a serious attack, but all valid state changes since the last backup are lost. We propose Rectify, a new approach to recover from intrusions on applications running in a PaaS. Rectify is a service designed to be deployed alongside the application in a PaaS container. It does not require modifications to the software and the recovery can be performed by a system administrator. Machine learning techniques are used to associate the requests received by the application to the statements issued to the database. Rectify was evaluated using three widely used web applications - Wordpress, LimeSurvey and MediaWiki - and the results show that the effects of malicious requests can be removed whilst preserving the valid application data. David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
Middleware | 1 |
| 2016 | NoSQL Undo: Recovering NoSQL databases by undoing operationsabstractNoSQL databases offer high throughput, support for huge data structures, and capacity to scale horizontally at the expense of not supporting relational data, ACID consistency and a standard SQL syntax. Due to their simplicity and flexibility, NoSQL databases are becoming very popular among web application developers. However, most NoSQL databases only provide basic backup and restore mechanisms, which allow recovering databases from a crash, but not to remove undesired operations caused by accidental or malicious actions. To solve this problem we propose NOSQL UNDO, a recovery approach and tool that allows database administrators to remove the effect of undesirable actions by undoing operations, leading the system to a consistent state. NOSQL UNDO leverages the logging and snapshot mechanisms built-in NoSQL databases, and is able to undo operations as long as they are present in the logs. This is, as far as we know, the first recovery service that offers these capabilities for NoSQL databases. The experimental results with MongoDB show that it is possible to undo a single operation in a log with 1,000,000 entries in around one second and to undo 10,000 incorrect operations in less than 200 seconds. David R. Matos, Miguel Correia 0001 |
NCA | 1 |