Michele Nogueira Lima

dblp:22/4022 · also Michele Nogueira · DBLP profile ↗
← Back
91ranked-venue papers
4as first author
33since 2021 · last 2026
0000-0001-5427-2384ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 68 · 3 first-author · 27 since 2021Security and privacy · 3 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A New $k$k-Anonymity Method Based on Generalization First $k$k-Member Clustering for Healthcare Data
abstract
Advances in microelectronics and the evolution of IoHT devices allow the collection and, consequently, generation of a greater volume of health data, intensifying the need for robust data privacy solutions. Traditionalk-anonymity-based anonymization techniques often suffer from high information loss, especially as the anonymity parameter k increases. To address these challenges, this article proposes Generalization Firstk-Member Clustering (GFKMC), a novelk-anonymity method that applies early generalization to quasi-identifiers, reducing computational overhead and minimizing information loss. Unlike traditional methods (e.g., Mondrian, Top-Down Greedy (TDG), and Clustering-Based (CB)), GFKMC maintains nearly constant information loss (≈ 25%) across varyingkvalues and better preserves machine learning model performance, especially in lowkscenarios. Empirical evaluations demonstrate that GFKMC outperforms baseline methods by significantly minimizing the trade-off between data utility and privacy. Moreover, GFKMC preserves the performance of machine learning models more effectively.
Kristtopher Coelho, Maurício M. Okuyama, Michele Nogueira Lima, Alex Borges Vieira, Edelberto Franco Silva, José A. M. Nacif
IEEE Trans. Dependable Secur. Comput.3
2025 Exploratory Performance Evaluation of VM Migration as MQTT Moving Target Defense
abstract
The Message Queuing Telemetry Transport (MQTT) protocol is a cornerstone of IoT communications. It relies on service brokers to enable reliable data delivery between devices and clients. In modern deployments, MQTT brokers are frequently hosted in virtualized environments to support scalability, flexibility, and resource efficiency. However, virtualization enlarges the attack surface, posing challenges to service reliability and security. This paper investigates the use of Virtual Machine (VM) migration as a Moving Target Defense (MTD) to enhance security in MQTT-based IoT services. While VM migration is an established technique in network and service management for workload balancing and fault tolerance, its impact, when used as a proactive security mechanism in MQTT deployments, remains unexplored. This work shows a comprehensive performance evaluation of VM migration under both normal and active attack scenarios. The results demonstrate that the security benefits of VM migration come with minimal performance degradation, characterized by a modest effect size (Cohen D measure<0.5), thus ensuring service continuity and operational stability. However, it comes with a cost of increased performance oscillation (i.e., higher incidences of peaks in the response time). This paper also introduces an interactive, web-based tool that enables pre-deployment MTD simulation. This work offers insights into integrating security-aware VM migration within IoT service management.
Matheus D'Eça Torquato de Melo, Tiago Cruz 0001, Denis do Rosário, Michele Nogueira Lima, Eduardo Cerqueira
CNSM4
2025 Unsupervised Online Automl for Ddos of Things Prediction by Multimodal Analysis
abstract
Distributed Denial of Service (DDoS) of Things are becoming increasingly severe, characterized by unprecedented traffic volumes and rates. Predicting these attacks before they escalate is critical for reducing costs. However, the complex and multidimensional nature of DDoS attacks demands adaptive defense strategies, which are lacking in current approaches. Existing methods often depend on labeled datasets, offline processing or context-specific models, resulting in low prediction accuracy. Further, they tend to rely on homogeneous data sources, limiting their adaptability to the variability of real-world network environments. This paper introduces DELIBERATE, a novel technique for DDoS attack prediction that utilizes unsupervised online AutoML and ordinal pattern transformation through multimodal correlation analysis. DELIBERATE adapts itself to changes in network traffic by leveraging the correlation of heterogeneous data and ordinal patterns transformation, a noisetolerant method suitable for IoT environments. It predicts DDoS attacks up to 47 minutes in advance. The method outperforms traditional approaches that depend on labeled data, extensive training, and complex neural networks.
Ligia F. Borges, Anderson Bergamini de Neira, Lucas Albano, Michele Nogueira Lima
ICC4
2025 Methodology for Evaluating k-Anonymity-Based Anonymization in Machine Learning Models
abstract
The increasing volume of sensitive data generated by various domains demands robust approaches to privacy protection. Anonymization based on k-anonymity stands out for mitigating the risks of re-identification of personal data. However, the impact on the performance of machine learning models is commonly neglected. This work proposes a novel comparative method to evaluate the effects of anonymization on the performance of machine learning models, considering privacy, information loss, and performance metrics. The empirical results show how generalization based on k-anonymity impacts federated learning solutions and provides insights for developing and improving methods that reconcile data privacy and efficiency.
Kristtopher Coelho, Maurício M. Okuyama, Michele Nogueira Lima, Alex Borges Vieira, Edelberto Franco Silva, José A. M. Nacif
ISCC3
2025 Enhancing Biometric Security with Multimodal EEG and PPG Identification
abstract
The growing prevalence of interconnected devices in the Internet of Things (IoT) has intensified concerns about data security and user authentication. This study investigates a multimodal biometric authentication approach integrating Photoplethysmography (PPG) and Electroencephalography (EEG) signals to enhance accuracy and robustness. We adapted a previously validated PPG and Electrocardiogram (ECG) model, replacing the ECG component with an EEG-based method optimized through hyperparameter tuning. Our findings demonstrate that combining brain and heart signals improves authentication performance, with the multimodal approach surpassing unimodal methods. The optimized model achieved a precision of $97.05 \%$, a recall of $97.19 \%$, a F1-Score of $96.96 \%$, and an accuracy of $97.05 \%$, highlighting the potential of EEG-PPG fusion in secure biometric authentication.
Eduardo T. Tristão, Kristtopher Coelho, Caio Menezes, Lucas L. C. Freitas, Michele Nogueira Lima, Alex Borges Vieira, Edelberto Franco Silva, José A. M. Nacif
ISCC5
2025 Transformers model for DDoS attack detection: A survey
Euclides Peres Farias, Anderson Bergamini de Neira, Ligia F. Borges, Michele Nogueira Lima
Comput. Networks4
2025 Guest Editorial: Special Issue on Zero Trust for Next-Generation Networking
Moayad Aloqaily, Qian Zhang 0001, Martin Andreoni, Michele Nogueira Lima, Xiaojiang Du, Ang Chen 0001
IEEE J. Sel. Areas Commun.4
2024 Optimal Packet Padding for IoT Traffic Obfuscation
abstract
The Internet of Things (IoT) brings numerous benefits for society. However, it also allows the leakage of sensitive information (e.g., habits, behaviors, and health-related data), posing privacy risks. Solutions have tried to obfuscate network traffic and address this challenge. They typically involve padding and fragmentation techniques, that come with tradeoffs. This paper presents an optimal packet padding solution to define the most efficient number of bytes to insert into packets and achieve obfuscation. The approach is based on dynamic programming and relies on a discrete method, which exhibits the time complexity is Θ(mn2) and the memory complexity is Θ(mn). As the number of packets increases, memory consumption increases. Then, it introduces an approximate solution leveraging probability distributions to address scalability. Performance evaluation follows a trace-driven approach and employs metrics as accuracy, F1-score, and overhead. The proposal has obfuscated the identification of IoT devices by up to 50%, reducing overhead by up to 4 times compared to the traditional state-of-the-art methods.
Críston P. de Souza, Antônio J. Pinheiro, Jeandro M. Bezerra, Michele Nogueira Lima
GLOBECOM4
2024 A Dynamic Approach to Health Data Anonymization by Separatrices
abstract
Technological advances enable the integration of Internet of Things (IoT) devices to perform continuous and proactive patient monitoring. These devices collect a large volume of sensitive data that requires privacy. Anonymization provides privacy by removing or modifying information that identifies an individual. However, traditional anonymization techniques, such as k-anonymity, depend on a fixed and pre-defined k value, susceptible to attribute disclosure attacks. This article presents Dynamic Anonymization by Separatrices (DAS), an approach for defining the ideal value k and for dynamic grouping of data to be anonymized using separatrices measurements. Results show that the proposed approach efficiently mitigates attribute disclosure attacks.
Kristtopher Coelho, Maurício M. Okuyama, Michele Nogueira Lima, Alex Borges Vieira, Edelberto Franco Silva, José A. M. Nacif
ISCC3
2024 Context-Sensitive Access Control and Zero Trust for Security in E-Health
abstract
In an increasingly connected world, ensuring security in e-health is a challenge. Traditional security models based on perimeter trust are insufficient to guarantee the protection of these systems. Since these models work by directly assigning trust to the user, the entire network becomes vulnerable if the user’s credentials or device are compromised. Thus, this work proposes and evaluates a model based on Zero Trust to considerably increase security in e-health environments. The proposed model uses privilege reduction and user confidence analysis to perform access control. The evaluation follows simulation in different scenarios, assessing their assertiveness in delegating access. The results show the effective detection of anomalies in accesses by the model.
Lucas L. C. Freitas, Kristtopher Coelho, Michele Nogueira Lima, Alex Borges Vieira, José A. M. Nacif, Edelberto Franco Silva
ISCC3
2024 Identity management for Internet of Things: Concepts, challenges and opportunities
Bruno Marques Cremonezi, Alex Borges Vieira, José A. M. Nacif, Edelberto Franco Silva, Michele Nogueira Lima
Comput. Commun.5
2023 Panel: Faculty Leadership
abstract
This faculty leadership panel will be held jointly by the IEEE Education Society (IEEE EdSoc) and IEEE Educational Activities Board (EAB) Faculty Resources Committee (FRC). The panel intends to provide participants introductory knowledge and skills. Two moderators and four panelists will focus on discussing their various academic leadership experiences and practices. The panel will be held in an interactive way so that the participants will have enough time to ask questions or communicate with the panelists. It is expected that this joint panel may potentially help to build up networks and mentorships.
Lina J. Karam, Georges Zissis, Jason Yao, Jill K. Nelson, Minho Jo 0001, Rafal Sliz, Michele Nogueira Lima, Steve Watkins
FIE7
2023 Multidomain transformer-based deep learning for early detection of network intrusion
abstract
Timely response of Network Intrusion Detection Systems (NIDS) is constrained by the flow generation process which requires accumulation of network packets. This paper introduces Multivariate Time Series (MTS) early detection into NIDS to identify malicious flows prior to their arrival at target systems. With this in mind, we first propose a novel feature extractor, Time Series Network Flow Meter (TS-NFM), that represents network flow as MTS with explainable features, and a new benchmark dataset is created using TS-NFM and the meta-data of CICIDS2017, called SCVIC-TS-2022. Additionally, a new deep learning-based early detection model called Multi-Domain Transformer (MDT) is proposed, which incorporates the frequency domain into Transformer. This work further proposes a Multi-Domain Multi-Head Attention (MD-MHA) mechanism to improve the ability of MDT to extract better features. Based on the experimental results, the proposed methodology improves the earliness of the conventional NIDS (i.e., percentage of packets that are used for classification) by 5 ×104times and duration-based earliness (i.e., percentage of duration of the classified packets of a flow) by a factor of 60, resulting in a 84.1% macro F1 score (31% higher than Transformer) on SCVIC-TS-2022. Additionally, the proposed MDT outperforms the state-of-the-art early detection methods by 5% and 6% on ECG and Wafer datasets, respectively.
Jinxin Liu 0001, Murat Simsek, Michele Nogueira Lima, Burak Kantarci
GLOBECOM3
2023 Unsupervised Feature Engineering Approach to Predict DDoS Attacks
abstract
Predicting Distributed Denial of Service (DDoS) attacks is crucial given the large volume of generated attack traffic, particularly that generated by infected Internet of Things (IoT) devices. Attackers conceal their actions to delay detection as much as possible, increasing their damage when effectively launched. Hence, predicting signals of the attack plays a vital role in anticipating DDoS attacks and enhancing service protection. This work presents SEE, an unsupervised feature engineering approach to assist in predicting DDoS attacks. SEE evaluations encompass four experiments employing multiple datasets (CTU- 13, CIC-DDoS2019, and IoT-23) and DDoS attacks. The approach predicts a DDoS attack 30 minutes before it effectively starts, reaching up to 100% accuracy.
Anderson Bergamini de Neira, Ligia F. Borges, Alex Medeiros de Araújo, Michele Nogueira Lima
GLOBECOM4
2023 A Scalable Cyber Security Framework for the Experimentation of DDoS Attacks of Things
abstract
The Internet of Things (IoT) has amplified cyber security challenges for governments, businesses, and individuals. IoT is a straightforward attack target once it comprises resource-constrained and heterogeneous devices that often present security vulnerabilities easily exploited in different attack vectors. Recent Distributed Denial of Service (DDoS) attacks leverage thousands of IoT devices connected to the Internet called DDoS of things (a.k.a. DoT). DoT requires systematic cyber security research, but advancing the state-of-the-art depends on methods and tools that jointly manage scalability and performance. Experimentation is an essential and well-known tool for scientific research. However, experimental environments for investigating DoT are challenging, given limitations in scale and IoT heterogeneity. Hence, the main contribution of this work lies in presenting a cyber security framework for DoT experimentation that manages scalability and performance in scenarios under attack. It is the first initiative to create a framework of reference to assist in implementing cyber security testbeds. Hence, this work also presents an instantiation of this framework, called the MENTORED testbed, and the results of a case study using it.
Davi D. Gemmer, Bruno Henrique Meyer, Emerson Ribeiro de Mello, Marcos F. Schwarz, Michelle S. Wangham, Michele Nogueira Lima
NOMS6
2023 A method for vulnerability detection by IoT network traffic analytics
Uelinton Q. Brezolin, Andressa Vergütz, Michele Nogueira Lima
Ad Hoc Networks3
2023 A dynamic method to protect user privacy against traffic-based attacks on smart home
Bruna V. Dos Santos, Andressa Vergütz, Ricardo T. Macedo, Michele Nogueira Lima
Ad Hoc Networks4
2023 Distributed denial of service attack prediction: Challenges, open issues and opportunities
Anderson Bergamini de Neira, Burak Kantarci, Michele Nogueira Lima
Comput. Networks3
2023 A survey on federated learning for security and privacy in healthcare applications
Kristtopher Coelho, Michele Nogueira Lima, Alex Borges Vieira, Edelberto Franco Silva, José A. M. Nacif
Comput. Commun.2
2023 An Intelligent System for DDoS Attack Prediction Based on Early Warning Signals
abstract
Among the different threats causing significant losses in cyberspace, the distributed denial of service (DDoS) attack is one of the most dangerous. The literature shows that the most reasonable manner to reduce the impacts of a DDoS attack is to prevent an attacker from launching it. Prevention is essential because attack sophistication allows them to reach massive traffic volumes, bypassing defenses. Defense mechanisms need time to detect and mitigate attacks. Hence, it is paramount to manage signals of the attack preparation before the attacker effectively launches it. This work presents COOPRED DDoS, a cooperative system for predicting DDoS attacks based on early warning signals extracted from the preparation of DDoS attacks. Its goal lies in increasing the time to prevent DDoS attacks. This work has followed four experiments utilizing two datasets widely employed in the literature. The results show that COOPRED DDoS identifies signals of attacks before the attacker effectively launches them. The system predicts one of the investigated attacks up to 3 minutes and 49 seconds in advance and the other attack up to 3 minutes and 55 seconds. The accuracy of the experiments varies from 99.60% to 99.87%.
Anderson Bergamini de Neira, Alex Medeiros de Araújo, Michele Nogueira Lima
IEEE Trans. Netw. Serv. Manag.3
2023 Intelligent VNF Placement to Mitigate DDoS Attacks on Industrial IoT
abstract
The Internet of Things (IoT) has undergone rapid popularization, reaching a wide range of application domains, such as manufactures. Hence, more and more heterogeneous IoT devices have been deployed in a variety of industrial environments, progressively becoming common objects to the supply chain. The physical infrastructure of manufacturing systems has become complex and requires efficient and dynamic solutions for managing network performance and security. Network Function Virtualization (NFV) has attracted attention when the intention is to respond to security threats on Industrial IoT (IIoT). Few works use NFV to detect and mitigate security threats on IIoT networks, but even less consider performance indicators of the network context when placing the Virtual Network Functions (VNFs). Thus, this work introduces a Machine Learning (ML) approach to place security VNFs based on NFV performance to mitigate Distributed Denial of Service (DDoS) attacks on IIoT. Experiments considering a new composed data set and diverse ML techniques show ML classification as an alternative for IIoT scenarios, achieving, according to the best-performing technique, 99.40% of accuracy in relation to the ideal placement. To facilitate the reproduction of the work, all the code and data produced are publicly available.
Guilherme Werneck de Oliveira, Michele Nogueira Lima, Aldri Luiz dos Santos, Daniel M. Batista
IEEE Trans. Netw. Serv. Manag.2
2023 Data Instrumentation From IoT Network Traffic as Support for Security Management
abstract
The Internet of Things revolutionizes human life by inaugurating scenarios such as smart homes. However, IoT devices contain much sensitive information about users and devices from a security and privacy perspective. Through traffic-based attacks, adversaries map changes in traffic rates to a particular in-home user’s actions. An efficient IoT data instrumentation may protect users against traffic-based attacks by giving valuable information to adaptive network security solutions. Nonetheless, no work performs data instrumentation or uses feature exploration to reveal relevant features to assist network security management. Thus, this article introduces IoTReGuard, an IoT Method to Reveal and Guard IoT Network Traffic Features. IoTReguard aims to explore network traffic features to reveal the most relevant ones and hide them to protect users’ privacy. By IoT network feature exploration and data instrumentation, IoTReGuard provides valuable information on network traffic features to mask critical features. Results showed that IoTReGuard reduced from 70% to 20% of F1-Score on identifying the IoT devices, improving user privacy.
Andressa Vergütz, Bruna V. Dos Santos, Burak Kantarci, Michele Nogueira Lima
IEEE Trans. Netw. Serv. Manag.4
2022 Lifelong Autonomous Botnet Detection
abstract
Botnet-driven attacks have attracted attention due to their diversity, high potential to cause damage and massive data generation. Existing botnet detection solutions are usually specific to a type of attack behavior. This particularity makes attack detection challenging because it involves a high operational overhead for manually calibrating and managing a large set of solutions for different attacks and variations. Hence, this work presents LBDS, a botnet detection system that acts autonomously in dynamic environments. It relies on concept drift and AutoML, two main techniques that consider dynamic behavior on data distribution. The LBDS evaluation has followed a diverse set of attacks and protocols. Results demonstrate that the system detects botnets utilizing different detection techniques, indicating its ability to consider various aspects of data and attacks.
Alex Medeiros de Araújo, Anderson Bergamini de Neira, Michele Nogueira Lima
GLOBECOM3
2022 Improving the attribute retrieval on ABAC using opportunistic caches for Fog-Based IoT Networks
Bruno Marques Cremonezi, Airton Ribeiro Gomes Filho, Edelberto Franco Silva, José A. M. Nacif, Alex Borges Vieira, Michele Nogueira Lima
Comput. Networks6
2022 A Resilience Management Architecture for Communication on Portable Assisted Living
abstract
The Internet of Health Things interconnects wearable and portable devices, supporting critical healthcare applications such as Ambient Assisted Living (AAL) that retrieve crucial information from users (e.g., vital signs, activity tracking, fall detection) towards smart medicine. However, existing assisted living systems cover a pre-established area, limiting users to small spaces and constraining daily activities. These systems have restricted requirements in terms of latency and availability, compelling to fast advances in network infrastructure and essential services as sensing, connectivity, and end-to-end communication. This article presents a novel resilience management architecture for communication on portable assisted living, considering that IoHT devices have access to multiple access networks, such as fixed and mobile, and the concurrent use of those networks, extending the communication range and managing communication resilience. Based on the architecture, this work details a Portable Assisted Living System and its performance evaluation, achieving low delay and high throughput as well as increasing communication resilience.
Fernando Nakayama, Paulo Lenz, Michele Nogueira Lima
IEEE Trans. Netw. Serv. Manag.3
2022 Learning From Network Data Changes for Unsupervised Botnet Detection
abstract
The networks of infected devices (a.k.a., botnets) threaten network security due to their dynamic nature and support to different attacks (e.g., Distributed Denial of Services and personal data theft). Detecting botnets is a challenging task because the infected devices (bots) are numerous, widely and geographically spread. Significant attention has been given to improve the efficiency, robustness and adaptability of network security approaches. However, in the literature, botnet detection techniques usually ignore fast changes in statistical data distribution, performing over static windows, i.e., fixed intervals of time or fixed quantity of flows. Changes in statistical data distribution are known as concept drifts and they make the classification models obsolete. Furthermore, those works employing approaches aware of concept drift use supervised machine learning, which is slow, costly, and prone to error. Therefore, this article presents TRUSTED, a system for online and unsupervised botnet detection aware of concept drifts. Unlike other works, the TRUSTED system improves the learning process for botnet detection, applying concept drift in an online and unsupervised classification. Evaluations comprise offline and online scenarios. Results show that the TRUSTED system detects botnets using concept drift identification, reaching 87% to 95% accuracy, precision, recall, and F1-scores.
Bruno Henrique Schwengber, Andressa Vergütz, Nelson G. Prates, Michele Nogueira Lima
IEEE Trans. Netw. Serv. Manag.4
2021 Anomaly Detection in Smart Environments using AI over Fog and Cloud Computing
abstract
Modern society claims for smart environments (SEs) to make efficient the management of infrastructures, resources, and services. However, SEs comprise numerous heterogeneous devices and follow different protocols, making it harder to detect network anomalous behavior. Hence, this paper proposes ISAD, an intelligent system for network anomaly detection in SE managing Fog and Cloud computing approaches, improving the data processing and traffic exchange of the system. The system evaluation takes as workload a real network traffic, deploying locally the Fog environment and using Microsoft Azure platform as Cloud. Results show that the system detects network anomalies with an accuracy of 96%.
Diego A. B. Moreira, Humberto P. Marques, Wanderson L. Costa, Joaquim Celestino Jr., Rafael L. Gomes, Michele Nogueira Lima
CCNC6
2021 Lightweight Data Compression for Low Energy Consumption in Industrial Internet of Things
abstract
Industrial Internet of Things (IIoT) plays a crucial role towards efficient industrial environments. IEEE 802.11/WiFi is key technology for IIoT, but it results in higher energy consumption, due to the size of transmitted packets and the Maximum Transmission Unit (MTU). Within this context, this paper presents a lightweight data compression approach to reduce the amount of data to be transmitted and the MTU, aiming to reduce energy consumption. Results from real experiments suggest that the proposed method reduces the energy consumption.
Marcus de V. D. da Silva, Alexandre Rocha, Rafael L. Gomes, Michele Nogueira Lima
CCNC4
2021 A Synchronization Protocol for Multi-User Cell Signaling-Based Molecular Communication
abstract
Molecular Communications (MC) networks comprise multiple devices performing coordinated complex tasks, such as detecting types of cancer and smart drug delivery. Signaling-based MC uses molecules as information carriers between signaling cells. In this context, synchronization is jointly paramount and challenging since the system must overcome the limitation of molecular propagation to make sure computationally deprived bio-devices can communicate. On top of that, a multi-user increases this system challenges as possible co-channel interference causes errors or failures. Bio-devices present severe computational and communication limitations, being this last one essentially unidirectional. This paper presents the first synchronization protocol between signaling cells for multi-user MC. Results have shown the convergence time concerning different network sizes from 12 to 60 nodes.
Ligia F. Borges, Michael Taynnan Barros, Michele Nogueira Lima
GLOBECOM3
2021 Opportunistic Attribute Caching: Improving the Efficiency of ABAC in Fog-Based IoT Networks
abstract
The performance of Attribute-Based Access Control is negatively affected by communications over the network between the policy decision point and policy information point for each attribute request. Attribute caching is a standard solution to mitigate this problem. However, due to the dynamic nature of attributes, the cost to keep them refreshed increases for each new attribute replica. This paper presents a method that predicts each request and anticipate the positioning of the attributes closer to the requester exploring the tradeoff between the cost of creating a new replica versus updating a replica. The proposed method follows a two-way approach, where it deals with the current attribute requests and their estimates based on user mobility and the best positions for the attributes. Through trace-driven simulations, considering traces from a large university campus, the method shows a reduction of up to 80% in the number of hops to get the needed attributes at negligible refreshment cost.
Airton Ribeiro Gomes Filho, Bruno Marques Cremonezi, José A. M. Nacif, Michele Nogueira Lima, Edelberto Franco Silva, Alex Borges Vieira
ICC4
2021 Performance Management on Multiple Communication Paths for Portable Assisted Living
Fernando Nakayama, Paulo Lenz, Antonin Le Floch, André-Luc Beylot, Aldri Luiz dos Santos, Michele Nogueira Lima
IM6
2021 Relational Consensus-Based Cooperative Task Allocation Management for IIoT-Health Networks
Carlos Pedroso 0001, Yan Uehara de Moraes, Michele Nogueira Lima, Aldri Luiz dos Santos
IM3
2021 Data-Driven C-RAN Optimization Exploiting Traffic and Mobility Dynamics of Mobile Users
abstract
The surging traffic volumes and dynamic user mobility patterns pose great challenges for cellular network operators to reduce operational costs and ensure service quality. Cloud-radio access network (C-RAN) aims to address these issues by handling traffic and mobility in a centralized manner, separating baseband units (BBUs) from base stations (RRHs) and sharing BBUs in a pool. The key problem in C-RAN optimization is to dynamically allocate BBUs and map them to RRHs under cost and quality constraints, since real-world traffic and mobility are difficult to predict, and there are enormous numbers of candidate RRH-BBU mapping schemes. In this work, we propose a data-driven framework for C-RAN optimization. First, we propose a deep-learning-based Multivariate long short term memory (MuLSTM) model to capture the spatiotemporal patterns of traffic and mobility for accurate prediction. Second, we formulate RRH-BBU mapping with cost and quality objectives as a set partitioning problem, and propose a resource-constrained label-propagation (RCLP) algorithm to solve it. We show that the greedy RCLP algorithm is monotone suboptimal with worst-case approximation guarantee to optimal. Evaluations with real-world datasets from Ivory Coast and Senegal show that our framework achieves a BBU utilization above 85.2 percent, with over 82.3 percent of mobility events handled with high quality, outperforming the traditional and the state-of-the-art baselines.
Longbiao Chen, Thi Mai Trang Nguyen, Dingqi Yang, Michele Nogueira Lima, Cheng Wang 0003, Daqing Zhang 0001
IEEE Trans. Mob. Comput.4
2020 A Defense Mechanism for Timing-based Side-Channel Attacks on IoT Traffic
abstract
This work proposes FISHER: a deFense mechanIsm against timing-based Side-channel attack related to response time on the intERnet of things (IoT). IoT connects objects that support important applications, such as electronic health, smart homes, and Industry 4.0. However, timing-based side-channel attacks on IoT network traffic compromise user privacy. Related works present a limited view of side-channel leakages and as a solution, these works try to mask them. However, they ignore that devices have unique behaviors that intensify the problem of privacy leaks through response time. Hence, FISHER follows two modules: (i) vulnerability test and (ii) privacy protection. The vulnerability test module identifies timing-based side-channel leakages and reveals new vulnerabilities associated with the response time. The privacy protection module implements two methods that mask the identified time-based leakages on the network traffic. Results from an experimental scenario show that FISHER identifies precisely the side-channel leakages related to response time and efficiently masks them.
Nelson G. Prates, Andressa Vergütz, Ricardo T. Macedo, Aldri Luiz dos Santos, Michele Nogueira Lima
GLOBECOM5
2020 A Method Aware of Concept Drift for Online Botnet Detection
abstract
Botnets deeply threaten cybersecurity due to their distributed and dynamic nature, causing attacks with severe consequences for users and companies, such as Distributed Denial of Service. Detecting botnets is challenging once they constantly evolve, resulting in fast behavior changes in network. Current techniques usually detect botnets without considering these changes and their fast adaptation to new behavior. Hence, this paper presents CONFRONT, a method aware of concept drift (fast changes in network behavior) for online botnet detection. Different from the literature, this paper introduces a new technique to detect concept drift and optimize botnet classification. CONFRONT employs features from network flow on the unsupervised concept drift detector and a supervised incremental botnet classifier. Results show CONFRONT feasibility, reaching 95% of accuracy in less than 1 ms.
Bruno Henrique Schwengber, Andressa Vergütz, Nelson G. Prates, Michele Nogueira Lima
GLOBECOM4
2020 Social-based Cooperation of Vehicles for Data Dissemination of Critical Urban Events
abstract
Critical urban events need to be efficiently handled, for instance, through rapid notification. VANETs are a promising choice in supporting notification of information on arbitrary critical events. Although the dynamicity of VANETs compromises the dissemination process, the connections among vehicles based on users' social interests allow for optimizing message exchange and data dissemination. This paper introduces SOCIABLE, a robust data dissemination system for critical urban events that operates in a SIoV network. It is based on vehicles' community with common interests and/or similar routines and employs social influence of vehicles according to their network location to select relay vehicles. In a comparative analysis on NS3 with the MINUET system, SOCIABLE achieved 36.56% less packets transmitted in a dense VANET and a maximum packet delivery delay of 28ms in a sparse VANET, delivering critical event data in a real-time and robust way without overloading the network.
Alisson Yury, Everaldo Andrade, Michele Nogueira Lima, Aldri Luiz dos Santos, Fernando Matos 0001
GLOBECOM3
2020 A Multi-Carrier Molecular Communication Model for Astrocyte Tissues
abstract
This paper presents a multi-carrier molecular communication model for astrocyte tissues. The model considers molecular diversity and analyses channel path loss and capacity for molecular communication based on the concentration of Inositol Triphosphate (IP3) and calcium (Ca2+) molecules. Without loss of generality, we investigate the spatiotemporal concentration of these molecules and how both intracellular and intercellular signaling dictates signal propagation inside astrocytes tissues. Astrocytes are the most abundant glial cell type in the adult brain and play essential roles in brain function, such as modulating neuronal excitation, inhibition, and synaptic transmission. Results show that using combined these two molecules reduces path loss, improves data propagation, and can be an alternative for data encoding and transmission. The multi-carrier molecular communication using IP3and Ca2+has overall superior performance, showing the potential benefits of molecular diversity.
Ligia F. Borges, Michael Taynnan Barros, Michele Nogueira Lima
ICC3
2020 Managing Consensus-Based Cooperative Task Allocation for IIoT Networks
abstract
Current IoT services include industry-oriented services, which often require objects to run more than one task. However, the exponential growth of objects in IoT poses the challenge of distributing and managing task allocation among objects. One of the main goals of task allocation is to improve the quality of information and maximize the tasks to be performed. Although there are approaches that optimize and manage the dynamics of nodes, not all consider the quality of information and the distributed allocation over the cluster service. This paper proposes the mechanism CONTASKI for task allocation in IIoT networks to distribute tasks among objects. It relies on collaborative consensus to allocate tasks and similarity capabilities to know which objects can play in accomplishing those tasks. CONTASKI was evaluated on NS-3 and achieved 100% of allocated tasks in cases with 75 and 100 nodes, and, on average, more than 80% clusters performed tasks in a low response time.
Carlos Pedroso 0001, Yan Uehara de Moraes, Michele Nogueira Lima, Aldri Luiz dos Santos
ISCC3
2020 Double Authentication Model based on PPG and ECG Signals
abstract
Wearable devices in e-Health provide easy usage access as well as an information return to the user. In general, such devices possess a range of sensors that capture several information from both the environment and the user. The most popular information collected by smartwatches and bracelets is about the measurement of heartbeats, steps, oxygenation, and photoplethysmogram (PPG) and electrocardiogram (ECG) signals. These wearable devices rely on mobile devices for user authentication. If the user needs validation, he will resort to traditional methods on other equipment that possesses recognition sensors such as iris, face, or fingerprints. In this paper, we introduce a model for double authentication based on PPG and ECG signals for promoting another layer of security to the user, ensuring data security, and avoid weak dependence on a single biosignal for validation. The proposed model has a algorithm with two zones, namely the Algorithm for PPG and ECG Signals and Error Rate zones. The experimental results indicate that the proposed model presented up to 99.98% of accuracy.
Lucas Bastos, Thais Tavares, Denis do Rosário, Eduardo Cerqueira, Aldri Luiz dos Santos, Michele Nogueira Lima
IWCMC6
2020 Early Botnet Detection for the Internet and the Internet of Things by Autonomous Machine Learning
abstract
The high costs generated by attacks and the increasing number of different devices on the Internet and the Internet of Things (IoT) propel the early detection of botnets (i.e., network of infected devices) as a way to gain advantage against attacks. However, botnet early detection is challenging due to the continuous mutation, sophistication, and massive data volume, this last mainly resulted from sensor networks and IoT. The literature addresses botnets by modeling the behavior of malware spread, the classification of malicious traffic, and the analysis of traffic anomalies. This paper presents ANTE, a system for ANTicipating botnEts signals based on machine learning algorithms. The ANTE design allows it to adapt to different scenarios by learning to detect different types of botnets throughout its execution. Hence, ANTE autonomously selects the most appropriate machine learning pipeline for each type of botnet to maximize the correct classification before an attack effectively begins. The ANTE evaluation follows a comparison of its results to others from the literature considering three datasets: ISOT HTTP Botnet, CTU-13, and CICDDoS2019. Results show an average accuracy of 99.87% and an average botnet detection precision of 100%.
Anderson Bergamini de Neira, Alex Medeiros de Araújo, Michele Nogueira Lima
MSN3
2019 A Method for Identifying eHealth Applications Using Side-Channel Information
abstract
eHealth applications become popular with the increasing incidence of cancer and postoperative rehabilitation, that require continuous remote monitoring of patients. Given the huge diversity of eHealth applications, their proper and non- invasive identification assist in attaining important requirements as low latency and reliability. But, their identification is not trivial once they have similar characteristics to common applications. Also, the time taken to identify an eHealth application is crucial, however usually it is not addressed as relevant. This paper presents MOTIF, a method for identifying eHealth applications from side-channel information extracted from network traffic. It is non-invasive and does not inspect packet payload, employing machine learning algorithms for the particularities of healthcare scenarios. Results show MOTIF feasibility and point out an accuracy higher than 90% in less than 30 seconds.
Andressa Vergütz, Iago Medeiros, Denis do Rosário, Eduardo Cerqueira, Aldri Luiz dos Santos, Michele Nogueira Lima
GLOBECOM6
2019 Delay Sensitivity-Aware Aggregation of Smart Microgrid Data Over Heterogeneous Networks
abstract
Smart grids require high reliability and sufficient bandwidth from wireless networks to support critical real-time applications and massive smart microgrid data. In general, smart microgrids need to guarantee delays at the order of a few μs for highly delay-sensitive data delivery; as well as delays within few seconds for regular data delivery. This paper presents a framework and its performance analysis for microgrid data aggregation where the microgrid is served by a wireless heterogeneous network. Using unsupervised machine learning, the framework introduces a multi-class and delay sensitivity-aware aggregation of microgrid data within the small cells of the heterogeneous network to ensure that clustering reduces the processing time for highly delay-sensitive messages. Thus, at each Transmission Time Interval (TTI), if there is queued delay-sensitive data, they are dequeued ahead of the delay-tolerant data at the scheduler. Through simulations, we show that the proposed approach successfully reduces the queuing delay by 93% for the packets of delay-sensitive (urgent) messages and the Packet Loss Rate (PLR) by 7% when compared to the benchmark where no aggregation mechanism exists prior to the small cell base stations.
Ahmed Omara, Burak Kantarci, Michele Nogueira Lima, Melike Erol-Kantarci, Lei Wu 0004, Jie Li 0013
ICC3
2019 Secure On-skin Biometric Signal Transmission using Galvanic Coupling
abstract
Increasing threats of malicious eavesdropping raise concerns in confidential data reporting by body-worn sensors. We propose a secure, body-guided transmission channel through the use of galvanic coupling (GC). This method involves injecting weak electrical current into the body, which propagates primarily through the skin. The proposed approach makes the transmission of biometric data impervious to sniffing attacks, enabling the body to serve as a waveguide. This paper makes the following contributions: (i) An analytical channel model using a tissue equivalent circuit of the human arm-wrist-palm GC-propagation path is formulated and empirically verified. (ii) A simulation study is conducted for a comparative analysis of various modulation schemes, leveraging the validated GC-channel behavior. (iii) A GC-transceiver with optimized communication parameters (modulation, frequency, power) is designed and implemented using a dielectrically equivalent tissue phantom, and (iv) through experimental trials, resilience to over-the-air susceptibility (i.e., likelihood of adversarial eavesdropping) of the GC-signal and similar body communication techniques are demonstrated. Performance results of the GC-transceiver prototype yield a bit error rate of 10-6with a transmit power of -2dBm, in addition to over 7x reduction of signal radiation outside the body compared to capacitive coupling.
William J. Tomlinson, Stella Banou, Michele Nogueira Lima, Kaushik R. Chowdhury
INFOCOM4
2019 MPTCP robustness against large-scale man-in-the-middle attacks
Chi-Dung Phung, Benevid Felix, Michele Nogueira Lima, Stefano Secci
Comput. Networks3
2019 Context-aware network selection in heterogeneous wireless networks
Alex Monteiro, Eduardo Souto, Richard Werner Nelem Pazzi, Michele Nogueira Lima
Comput. Commun.4
2019 A Continuous User Authentication System Based on Galvanic Coupling Communication for s-Health
abstract
Smart health (s-health) is a vital topic and an essential research field today, supporting the real-time monitoring of user’s data by using sensors, either in direct or indirect contact with the human body. Real-time monitoring promotes changes in healthcare from a reactive to a proactive paradigm, contributing to early detection, prevention, and long-term management of health conditions. Under these new conditions, continuous user authentication plays a key role in protecting data and access control, once it focuses on keeping track of a user’s identity throughout the system operation. Traditional user authentication systems cannot fulfill the security requirements of s-health, because they are limited, prone to security breaches, and require the user to frequently authenticate by, e.g., a password or fingerprint. This interrupts the normal use of the system, being highly inconvenient and not user friendly. Also, data transmission in current authentication systems relies on wireless technologies, which are susceptible to eavesdropping during the pairing stage. Biological signals, e.g., electrocardiogram (ECG) and electroencephalogram (EEG), can offer continuous and seamless authentication bolstered by exclusive characteristics from each individual. However, it is necessary to redesign current authentication systems to encompass biometric traits and new communication technologies that can jointly protect data and provide continuous authentication. Hence, this article presents a novel biosignal authentication system, in which the photoplethysmogram (PPG) biosignal and a galvanic coupling (GC) channel lead to continuous, seamless, and secure user authentication. Furthermore, this article contributes to a clear organization of the state of the art on biosignal-based continuous user authentication systems, assisting research studies in this field. The evaluation of the system feasibility presents accuracy in keeping data integrity and up to 98.66% accuracy in the authentication process.
Fernando Nakayama, Paulo Lenz, Stella Banou, Michele Nogueira Lima, Aldri Luiz dos Santos, Kaushik R. Chowdhury
Wirel. Commun. Mob. Comput.4
2018 A Self-Adaptable System for DDoS Attack Prediction Based on the Metastability Theory
abstract
Distributed Denial of Service (DDoS) attacks grow in volume, sophistication and impact. An example is the largest DDoS attack ever recorded against the developer platform GitHub, that reached 1.35 terabytes per second - an unprecedented volume of malicious traffic. DDoS attacks have been detected or mitigated only when they are in unrecoverable stages, being late to prevent their effects. Thus, differently from other works, we advocate for the early prediction of DDoS attacks to assist in reducing or avoiding costs and losses resulted from DDoS attacks. This paper presents STARK, a self- adaptable DDoS attack prediction system. STARK identifies signs of attack before it reaches an unrecoverable stage being founded on the metastability theory. Its evaluation follows a trace-driven approach, taking as input two databases containing records of DDoS attacks. Results show the prediction of DDoS attacks with minutes or hours in advance.
Mateus Pelloso, Andressa Vergütz, Aldri Luiz dos Santos, Michele Nogueira Lima
GLOBECOM4
2018 Redundant Packet Scheduling by Uncorrelated Paths in Heterogeneous Wireless Networks
abstract
Heterogeneous wireless networks operate under un-certainties as traffic load variation and failures. Redundant packet scheduling algorithms seek to timely cope with these uncertainties to meet the latency and throughput requirements for delay-sensitive applications, such as online gaming, voice and video streaming. The Multipath Transmission Control Protocol (MPTCP) can rely on a redundant scheduler to fulfill this demand, replicating data packets on multiple paths to mitigate negative effects of heterogeneity, such as fluctuations in delay, loss rate, and bandwidth. However, shared bottlenecks among paths can compromise the benefits of the redundant scheduler and restrain the MPTCP performance. Thus, this paper introduces a new scheduler, called RED (REdundant Diversity scheduling), to prioritize packet replication by uncorrelated paths. RED selects paths and replicates packets based on the Spearman's correlation coefficient. Results show that RED achieves low delay and enhances the usage of low correlated paths, improving transmission performance.
Benevid Felix, Igor Steuck, Aldri Luiz dos Santos, Stefano Secci, Michele Nogueira Lima
ISCC5
2018 Does OpenFlow Really Decouple The Data Plane from The Control Plane?
abstract
Software Defined Networks (SDNs) offer flexibility to current networks, allowing operators to manage network elements using software on an external server. SDNs are founded on a key feature: the separation of the control plane from the data plane. OpenFlow is the most popular SDN southbound interface today. However, does OpenFlow really decouple the data plane from the control plane? This is the leading question in this work. The literature has sought to quantity the impact of OpenFlow commands from control plane on data plane performance. Particularly, we argue that it is possible to damage the date plane by too many flow updates. Attackers, for instance, can use this effect in a cloud environment to reduce the performance of a collocated virtual network. However, it is not clear what is the exact impact of this coupling on production hardware and software switches. We investigate this through experiments, under representative scenarios, and propose a threshold mechanism to mitigate the effect of malicious administrators. We have observed that both hardware and software switches suffer from this limitation, presenting an average RTT degradation of up to 12.35% in the hardware switch, and 25.9% on the software switch. Finally, the proposed mechanism mitigates the lack of decoupling and malicious behavior.
Thiago M. Peixoto, Alex Borges Vieira, Michele Nogueira Lima, Daniel F. Macedo
ISCC3
2018 Confidentiality-Aware Decision on Handoffs under Uncertainty on Heterogeneous Wireless Networks
abstract
The handoff process in heterogeneous wireless networks (HetNets) focuses on the maintenance of mobile users connectivity, seeking to keep them continuously connected to the best available network. By supporting a better user connectivity on HetNets, handoff decision methods should take into account in the choice procedure both QoS and security issues jointly with performance. Unfortunately, such methods have slightly addressed security by ignoring its properties, and such fragility can lead to risky set up for user's data confidentiality transmission. Particularly, handoff decision methods ignore the existing uncertainty in HetNets. But, uncertain information is common when handling wireless networks transition. Therefore, this work presents a method to support confidentiality-aware decision making in the mobile device handoff process by adapting the expected-utility theory. Simulation results show how this method brings advantages to the user connectivity providing both less risky choices and low handoff cost.
Alisson Puska, Michele Nogueira Lima, Aldri Luiz dos Santos
ISCC2
2017 Can MPTCP secure Internet communications from man-in-the-middle attacks?
abstract
Multipath communications at the Internet scale have been a myth for a long time, with no actual protocol being deployed so that multiple paths could be taken by a same connection on the way towards an Internet destination. Recently, the Multipath Transmission Control Protocol (MPTCP) extension has been standardized and is undergoing rapid adoption in many different use-cases, from mobile to fixed access networks, from data-centers to core networks. Among its major benefits - i.e., reliability thanks to backup path rerouting, throughput increase thanks to link aggregation, and confidentiality being more difficult to intercept a full connection - the latter has attracted lower attention. How effective would be to use MPTCP to exploit multiple Internet-scale paths and decrease the probability of Man-in-the-Middle (MITM) attacks is a question which we try to answer. By analyzing the Autonomous System (AS) level graph, we identify which countries and regions show a higher level of robustness against MITM AS-level attacks, for example due to core cable tapping or route hijacking practices.
Ho Dac Duy Nguyen, Chi-Dung Phung, Stefano Secci, Benevid Felix, Michele Nogueira Lima
CNSM5
2017 A Survival Performance degrAdation fRamework for lArge-scale neTworked systems
abstract
Large scale networked systems, such as Identity Management (IdM) systems and software defined networks (SDN), have contributed to technological evolution. They simplify user and network device management. However, they strengthen Distributed Denial-of-Services (DDoS) attacks. These attacks are able to compromise system availability and harm legitimate users. The main approaches against DDoS attacks apply external resources (replication) or try to detect DDoS attacks. The first approach increases solution cost. The second is prone to high false positives. In other contexts, research into resilient approaches has increased for addressing emergent threats. In this work, we advocate that networked systems can self-manage to provide resilience. We propose a framework to guide the system design to follow the ideas defended in this thesis. The framework comprises the survival, collaboration, and analysis modules. Following the framework, networked systems can preserve their lifetime without external computer resources. The DDoS attack mitigation process starts when the system capacity overcomes a pre-established threshold. A protocol and a scheme showcase the framework over IdM systems and SDN. We conducted performance evaluations by experiments and simulations. Results show an increase in throughput and a decrease in latency of essential services when we use the proposed framework.
Ricardo T. Macedo, Yacine Ghamri-Doudane, Michele Nogueira Lima
IM3
2017 CD-ASM: A new queuing paradigm to overcome bufferbloat effects in HetNets
abstract
Recent works have sought to improve network performance by employing Multipath Transmission Control Protocol (MPTCP) to aggregate flows from heterogeneous wireless interfaces in a single connection. Although existing proposals are powerful, coupled congestion control algorithms suffer from high variation in path delays, bandwidth and loss rate, typical issues on heterogeneous wireless networks. Such variations are even higher over concurrent multipath transmissions, and they are enhanced in presence of bufferbloat, i.e. high delays caused by long queues. Hence, to cope with this limitation, we propose a major shift from the Active Queue Management (AQM) concept to Active Stack Management (ASM) concept, namely Controlled Delay ASM (CD-ASM) for HetNets to handle with the dropped packet ratio in the MPTCP congestion control mechanism. Differently from other approaches, CD-ASM gives priority to the most recent packets, being a promising solution. Moreover, we provide a detailed simulation analysis over congestion control algorithms by comparing CD-ASM to CoDel and DropTail schemes. Results indicate that our proposal reduces queue drops, and thus diminishing the impact on congestion control; keeping RTT low and improving in 20% the goodput.
Benevid Felix, Aldri Luiz dos Santos, Burak Kantarci, Michele Nogueira Lima
PIMRC4
2017 A multilayer link quality estimator for reliable machine-to-machine communication
abstract
An ever-growing number of embedded devices supports different kinds of applications, such as healthcare, surveillance, gas monitoring, and others, that require an elevated level of communication reliability. However, the expected high density of those embedded devices increases the competition for frequency spectrum, making it difficult to achieve a reliable machine-to-machine (M2M) communication. To overcome these difficulties, the use of link quality estimators (LQE) is crucial to provide a solid communication. In order to provide robust and faster communication under harsh conditions, this paper proposes a new LQE, called PRR2, which uses two metrics and two levels of PRR (Packet Received Ratio). The use of two PRR sliding windows captures link quality variations in the short term and also considers the long-term. PRR2is compared against the state of the art on a prototype using USRPs, and the results show that the proposal reduces the number of retransmissions and increases the delivery rate, which are two important metrics for link layer reliability.
Wendley Souza da Silva, Daniel F. Macedo, Michele Nogueira Lima, Thi Mai Trang Nguyen, José Marcos S. Nogueira
PIMRC3
2017 A Dynamic Channel Allocation Protocol for Medical Environment under Multiple Base Stations
abstract
Health monitoring over wireless networks is at the same time increasingly popular and a challenging task. In fact, in a medical environment, the high density of wireless devices leads to an extensive amount of co-channel interferences, imposing risk to patients' life due to poor network performance (e.g. high latency and packet loss rate). In this work, we present a DynamiC distributed Channel Allocation (DCCA) protocol. DCCA takes into account the existence of co-located wireless body area networks (WBANs) and multiple base stations in a single medical environment. In other words, DCCA avoids co-channel interference and offers workload balancing among base stations by dynamically allocating channels based on a greedy solution to the graph-coloring problem. Simulation results from medical environment scenarios show that DCCA improves the quality of communication when compared with other representative frequency- allocation protocol. On average, DCCA increases 30% the network goodput and reduces 40% network latency.
Bruno Marques Cremonezi, Alex Borges Vieira, José A. M. Nacif, Michele Nogueira Lima
WCNC4
2017 SPARTA: A survival performance degradation framework for identity federations
Ricardo T. Macedo, Leonardo Melniski, Aldri Luiz dos Santos, Yacine Ghamri-Doudane, Michele Nogueira Lima
Comput. Networks5
2017 Corrigendum to "A framework for resilient and secure spectrum sensing on cognitive radio networks" [Computer Networks volume 79 (2015) 313-322]
Julio C. H. Soto, Michele Nogueira Lima
Comput. Networks2
2017 A framework for resilient and secure spectrum sensing on cognitive radio networks
Julio C. H. Soto, Michele Nogueira Lima
Comput. Networks2
2017 PBF: A New Privacy-Aware Billing Framework for Online Electric Vehicles with Bidirectional Auditability
abstract
Recently an online electric vehicle (OLEV) concept has been introduced, where vehicles are propelled by the wirelessly transmitted electrical power from the infrastructure installed under the road while moving. The absence of secure-and-fair billing is one of the main hurdles to widely adopt this promising technology. This paper introduces a new secure and privacy-aware fair billing framework for OLEV on the move through the charging plates installed under the road. We first propose two extreme lightweight mutual authentication mechanisms, a direct authentication and a hash chain-based authentication between vehicles and the charging plates that can be used for different vehicular speeds on the road. Second, we propose a secure and privacy-aware wireless power transfer on move for the vehicles with bidirectional auditability guarantee by leveraging game theoretic approach. Each charging plate transfers a fixed amount of energy to the vehicle and bills the vehicle in a privacy-aware way accordingly. Our protocol guarantees secure, privacy-aware, and fair billing mechanism for the OLEVs while receiving electric power from the infrastructure installed under the road. Moreover, our proposed framework can play a vital role in eliminating the security and privacy challenges in the deployment of power transfer technology to the OLEVs.
Rasheed Hussain, Junggab Son, Donghyun Kim 0001, Michele Nogueira Lima, Heekuck Oh, Alade O. Tokuta, Jung Taek Seo
Wirel. Commun. Mob. Comput.4
2016 Self-Organized SDN Controller Cluster Conformations against DDoS Attacks Effects
abstract
Software Defined Networks (SDN) provide a high simplification of the network management by decoupling the control plane from the data plane through the use of controllers. Distributed-Denial-of-Service (DDoS) attacks can make SDN controllers unavailable to process legitimate flow requests from switches. The main approaches to protect controllers against DDoS attacks are essentially based on the attack detection, that still yield high rates of false negatives and/or false positives, highlighting the importance of mitigating DDoS attacks. Existing mitigation techniques are fundamentally based on external and additional resources or on the network traffic analysis, increasing computational cost or being prone to high rates of false negatives and/or false positives. This work presents PATMOS, a novel Protocol for DDoS Attack miTigation in Multi-contrOller SDN networkS through controller's clustering. PATMOS procedures are organized in three phases. The first one exchanges control messages to identify overloaded controllers, eliminating the dependence on the network traffic analysis. The second phase elects the best performance level controller to coordinate the mitigation process. The third phase minimizes the DDoS attacks effects using operational controllers in the network, differently from the works that employ external resources. Simulations results show PATMOS reducing 52.39% of CPU usage rate, increasing 192.74 fold more the throughput and decreasing 2.5 fold less the latency of flow requests to a target controller.
Ricardo T. Macedo, Rafael de Castro, Aldri Luiz dos Santos, Yacine Ghamri-Doudane, Michele Nogueira Lima
GLOBECOM5
2016 Avoiding Collisions by Time Slot Reduction Supporting Voice and Video in 802.11 Networks
abstract
One of the main challenges on the next generation local wireless networks lies in providing scalable media access control protocols in order to support the predicted high density. Research results have indicated that the current backoff mechanism is ineffective for dense networks, even more under the foreseen growing charge for the next five years. This paper investigates the proposal of the contention window enlargement, particularly by the reduction of time slot. The proposal intends to be implemented in the the 802.11ax amendment. Our main contribution lies in highlighting the impact of this proposal under different classes of traffic, reflecting on the access categories for data priority and their respective window time. Simulation results indicate that the proposal mitigates collision issues inherent to the backoff procedure, and it decreases frame loss. This study shows improvements over throughput and retransmissions, and it also warns to the impact on the clear channel assessment process. Results contribute with the literature pointing out the advantages and disadvantages of the adaptive proposal considering different classes of traffic and promoting the advance of the next generation local wireless networks.
Rafael Araujo da Silva, Aldri Luiz dos Santos, Michele Nogueira Lima, Khaled Boussetta, Nadjib Achir
GLOBECOM3
2016 Offloading cellular networks through V2V communications - How to select the seed-vehicles?
abstract
The rapid increase of portable devices providing a multitude of mobile applications have led to excessive cellular traffic demands and consequently to the overload of cellular networks. Recently, migrating this traffic by opportunistic vehicular networks has attracted a great interest and appeared as a promising solution. Indeed, only a limited set of vehicles (seeds) is selected to download objects from an Internet-content server through the cellular network and then propagate the content gradually by opportunistic communications (i.e. vehicle-to-vehicle V2V). This paper proposes SIEVE, an innovative seed selection scheme, that exploits two key criteria: users' interests and near-future contacts prediction. Based on these criteria, SIEVE allows to select the seeds in order to maximally satisfy the users' interests and, hence, achieve a maximum content utility (i.e. quantitative metric that determines how satisfied are the users). Simulations results show that SIEVE can improve the content utility when compared to other algorithms.
Farouk Mezghani, Riadh Dhaou, Michele Nogueira Lima, André-Luc Beylot
ICC3
2016 A scheme for DDoS attacks mitigation in IdM systems through reorganizations
abstract
Identity management (IdM) systems employ Identity Providers (IdPs), as guardians of users' critical information. However, Distributed Denial-of-Service (DDoS) attacks can make IdPs operations unavailable, compromising legitimate users. In the literature, the main countermeasures against DDoS attacks are based on either the application of external resources to extend the system lifetime (replication) or on the DDoS attacks detection. The first approach increases the solutions cost, and in general the second one is prone to high rates of false negatives and/or false positives. This work presents SAMOS, a first scheme to mitigate DDoS attacks in IdM systems through a novel approach: organizations of IdP clustering using optimization techniques. SAMOS is started based on the monitoring of processing and memory resources, differently from the solutions in the literature that are started based on the attack detection by the network traffic analysis. SAMOS minimizes the DDoS attacks effects using operational IdPs in the system, differently from the works that employ external computer resources. Results considering data from real IdM systems indicate the scheme viability.
Ricardo T. Macedo, Aldri Luiz dos Santos, Yacine Ghamri-Doudane, Michele Nogueira Lima
NOMS4
2016 AoT: Authentication and Access Control for the Entire IoT Device Life-Cycle
abstract
The consumer electronics industry is witnessing a surge in Internet of Things (IoT) devices, ranging from mundane artifacts to complex biosensors connected across disparate networks. As the demand for IoT devices grows, the need for stronger authentication and access control mechanisms is greater than ever. Legacy authentication and access control mechanisms do not meet the growing needs of IoT. In particular, there is a dire need for a holistic authentication mechanism throughout the IoT device life-cycle, namely from the manufacturing to the retirement of the device. As a plausible solution, we present Authentication of Things (AoT), a suite of protocols that incorporate authentication and access control during the entire IoT device life span. Primarily, AoT relies on Identity- and Attribute-Based Cryptography to cryptographically enforce Attribute-Based Access Control (ABAC). Additionally, AoT facilitates secure (in terms of stronger authentication) wireless interoperability of new and guest devices in a seamless manner. To validate our solution, we have developed AoT for Android smartphones like the LG G4 and evaluated all the cryptographic primitives over more constrained devices like the Intel Edison and the Arduino Due. This included the implementation of an Attribute-Based Signature (ABS) scheme. Our results indicate AoT ranges from highly efficient on resource-rich devices to affordable on resource-constrained IoT-like devices. Typically, an ABS generation takes around 27 ms on the LG G4, 282 ms on the Intel Edison, and 1.5 s on the Arduino Due.
Antonio Maia, Artur L. F. Souza, Ítalo S. Cunha, Michele Nogueira Lima, Ivan Oliveira Nunes, Leonardo Cotta, Nicolas Gentille, Antonio Alfredo Ferreira Loureiro, Diego F. Aranha, Harsh Kupwade Patil, Leonardo B. Oliveira
SenSys4
2016 Cognitive radio based connectivity management for resilient end-to-end communications in VANETs
Michele Nogueira Lima, Donghyun Kim 0001, Eduardo Cerqueira, Aldri Luiz dos Santos
Comput. Commun.2
2015 Detection of sinkhole attacks for supporting secure routing on 6LoWPAN for Internet of Things
abstract
The Internet of Things (IoT) networks are vulnerable to various kinds of attacks, being the sinkhole attack one of the most destructive since it prevents communication among network devices. In general, existing solutions are not effective to provide protection and security against attacks sinkhole on IoT, and they also introduce high consumption of resources de memory, storage and processing. Further, they do not consider the impact of device mobility, which in essential in urban scenarios, like smart cities. This paper proposes an intrusion detection system, called INTI (Intrusion detection of SiNkhole attacks on 6LoWPAN for InterneT of ThIngs), to identify sinkhole attacks on the routing services in IoT. Moreover, INTI aims to mitigate adverse effects found in IDS that disturb its performance, like false positive and negative, as well as the high resource cost. The system combines watchdog, reputation and trust strategies for detection of attackers by analyzing the behavior of devices. Results show the INTI performance and its effectiveness in terms of attack detection rate, number of false positives and false negatives.
Christian Cervantes, Diego Poplade, Michele Nogueira Lima, Aldri Luiz dos Santos
IM3
2015 A New Privacy-Aware Mutual Authentication Mechanism for Charging-on-the-Move in Online Electric Vehicles
abstract
Recently a new concept of online electric vehicle (OLEV) has been introduced in South Korea, where vehicles are propelled through the transmitted energy from the infrastructure installed underneath the road. However, for billing and audit reasons only authentic vehicles with necessary credentials are allowed to charge their batteries and pay the designated amount to the service provider. Moreover, due to the massive budget requirements for such infrastructure, only designated road segments will offer the charging service. As a result, a tradeoff solution to the charging of electric vehicles is needed to both fulfill the charging requirements of the electric vehicles and reduce the upfront costs for the service providers. To obtain electric charge from the charging plates beneath the road, vehicles need to authenticate themselves beforehand for twofold purposes: to bill the vehicles accordingly and to let the revocation authorities revoke the vehicle in case of a dispute. In this paper, we use the core concept of the OLEV and introduce extreme lightweight privacy-aware authentication schemes for charging-on-the-move through the charging plates installed under the road. More precisely we propose two mutual authentication mechanisms between charging plates and the vehicles, a direct authentication and a hash chain-based authentication. In the direct authentication scheme, we leverage multiple pseudonyms for conditional privacy. Vehicles use different pseudonyms every time they use the charging-on-the-move service. Whereas in case of hash chain-based authentication mechanism, the vehicles mutually authenticate with charging plates through service provider. Our proposed authentication mechanisms preserve conditional privacy throughout the protocol and is computationally lightweight than the existing mechanisms.
Rasheed Hussain, Donghyun Kim 0001, Michele Nogueira Lima, Junggab Son, Alade O. Tokuta, Heekuck Oh
MSN3
2015 Data similarity aware dynamic node clustering in wireless sensor networks
Fernando Gielow, Gentian Jakllari, Michele Nogueira Lima, Aldri Luiz dos Santos
Ad Hoc Networks3
2015 A framework for resilient and secure spectrum sensing on cognitive radio networks
Julio C. H. Soto, Michele Nogueira Lima
Comput. Networks2
2015 Interoperability issues on heterogeneous wireless communication for smart cities
Edson A. M. Avelar, Lorena Marques, Diego dos Passos Silva, Ricardo T. Macedo, Kelvin Lopes Dias, Michele Nogueira Lima
Comput. Commun.6
2015 Firefly-inspired and robust time synchronization for cognitive radio ad hoc networks
Nadine Lipa, Elisa Mannes, Aldri Luiz dos Santos, Michele Nogueira Lima
Comput. Commun.4
2014 Data similarity aware dynamic nodes clustering for supporting management operations
abstract
Wireless Sensor Networks (WSNs) are an important interface between physical and computational environments, where nodes clustering is a common technique to organize its traffic. Although current clustering protocols are focused on various kinds of dynamicity on the network, such as mobility or cluster-head rotations, few solutions consider the readings similarity management, which would provide benefits in terms of better use of compression techniques and reactive detection of anomalous events. This paper proposes a dynamic clustering protocol, called DDFC, that manages spatial similarity between nodes readings. Its operation is based on the biological principles of fireflies to ensure distributed synchronization of the cluster's similar readings aggregations, differentiating thus from the classic use of fireflies. Simulations show that DDFC is capable of maintaining the cluster's readings aggregation synchronized, hence clustering nodes dynamically according to their similar readings.
Fernando Gielow, Michele Nogueira Lima, Aldri Luiz dos Santos
NOMS2
2014 An architecture to manage performance and reliability on hybrid cloud-based firewalling
abstract
Firewalls are the first defense line for the networking services and applications. With the advent of virtualization and Cloud Computing, the explosive growth of network-based services, investigations have emphasized the limitations of conventional firewalls. However, despite of being impressively significant to improve security, cloud-based firewalling approaches still experience severe performance and reliability issues that can lead to non use of these services by companies. Hence, our work presents an efficient architecture to manage performance and reliability on a hybrid cloud-based firewalling service. Being composed of a physical and a virtual part, the architecture follows an approach that supports and complements basic physical firewall functionalities with virtual ones. The architecture was deployed and experimental results show that the proposed approach improve the computational power of traditional firewall with the support of cloud-based firewalling service.
Fouad Amine Guenane, Hajer Boujezza, Michele Nogueira Lima, Guy Pujolle
NOMS3
2014 Utility-based forwarder selection for content dissemination in vehicular networks
abstract
Recent work has shown that content dissemination protocols in vehicular networks can achieve throughput and fan-out delay optimization by either simple network flooding or destination-driven dissemination. While those content dissemination schemes work well, they require all nodes in the network to forward every data packet, which has inherent inefficiencies for non-flooding traffic patterns, where not all nodes need to receive the data. Hence, they support adequately safety applications, being not efficient for non-safety applications, whereby the flow of information is interest-driven rather than destination-driven, e.g. restaurant recommendation and sale advertisement. In this work, the concept of “useful” forwarder is formalized aiming at maximizing content utility for end users. Further, it presents I-SEND, a forwarder selection approach, which enables nodes to choose the most appropriate forwarders. Incorporating I-SEND on trace-driven and synthetic simulation scenarios can produce higher content utility than other concurrent schemes.
Farouk Mezghani, Riadh Dhaou, Michele Nogueira Lima, André-Luc Beylot
PIMRC3
2013 Secure and revocable node authentication in Vehicular Ad-Hoc Networks
abstract
In Vehicular Ad-hoc Networks (VANETs), node authentication is an inherent problem since nodes enter and leave the network freely. In wireless networks, the management of identities becomes important because of the propagation medium, where problems such as the loss of node's privacy, the disclosure of personal information, and particularly identity theft and impersonation should be avoided. This paper proposes a pseudonym-based identification scheme that assures security and revocation of identities protecting identity data through advanced cryptography. The presented scheme is based on the generation of a pseudonym formed by node's real identity and an identifier assigned by a trusted third party (Identity Management Server, IMS) after an identification process. The IMS helps to achieve the privacy desired by nodes and the traceability required by law enforcement.
Jenny Torres 0001, Michele Nogueira Lima, Guy Pujolle
ISCC2
2013 Resilient and multi-dimensional cooperative spectrum sensing on cognitive radio networks
abstract
While great strides have been made in spectrum sensing techniques in cognitive radio networks, these approaches are susceptible to unconventional attacks that may result in catastrophic performance degradation of the spectrum usage efficiency. For example, primary user emulation, intelligent jamming and denial of service for spectrum usage may impact the performance of classical spectrum sensing approaches. To address these challenges, this paper proposes a multi-dimensional cooperative sensing framework that can flexibly incorporate a variety of physical layer features to identify cases related to malicious behavior and genuine node failures. Though our approach is distributed, it is resilient in the sense that it does not simply rely on majority voting by a collection of nearby nodes. The key contributions of this paper are as follows: (i) A multiple criteria analysis technique and a non-parametric Bayesian inference method are formulated for identifying the spectrum holes that are least susceptible to malicious activity and failures, and (ii) Using real traces from the CRAWDAD data repository, we test our framework in a variety of practical settings, to prove the performance benefit of our approach.
Julio C. H. Soto, Michele Nogueira Lima, Kaushik R. Chowdhury
PIMRC2
2013 A flexible multi-criteria scheme to detect primary user emulation attacks in CRAHNs
abstract
Cognitive Radio Ad Hoc Networks (CRAHNs) are prone to Primary User Emulation Attacks (PUEAs), a particular security issue in which malicious unlicensed users manipulate their cognitive radio parameter values to monopolize the spectrum usage pretending transmissions of Primary Users. Works in the literature propose to detect or mitigate these attacks, however they are based on network architectural approaches and node operation, without intending to be flexible to unexpected attack behaviors and prepared for attack adaptations that intend to circumvent defense mechanisms. Existing proposals are intrinsically tied to predefined criteria, and the addition of new one requires the design of a different solution. Intending to fill this gap, we propose INCA, a novel multIple criteria scheme for a deceNtralized and Cooperative Analysis of the PUEA presence in CRAHNs. INCA is composed of two phases that employ, respectively, the Normalized Weighted Additive Utility Function to achieve flexibility, and the Bayes theorem to provide a distributed cooperation among nodes, in which the detection of the presence of attacks by a node is partially conditional to the detection by other nodes. Results from exhaustive simulations show that INCA can improve the analysis of the presence of PUEA in all evaluated scenarios, mostly when both phases are applied.
Julio C. H. Soto, Saulo Queiroz, Maria Gregori, Michele Nogueira Lima
WOWMOM4
2012 Reliable operational services in MANETs by misbehavior-tolerant quorum systems
Elisa Mannes, Michele Nogueira Lima, Aldri Luiz dos Santos
CNSM2
2012 Managing sensing and cooperation to analyze PUE attacks in Cognitive Radio Ad Hoc Networks
Julio C. H. Soto, Saulo Queiroz, Michele Nogueira Lima
CNSM3
2012 A bio-inspired scheme on quorum systems for reliable services data management in MANETs
abstract
Network services in MANETs, such as resource location and distribution of connectivity information, deal with node mobility and resource constraints to support applications. The reliability and availability of these services can be assured by data management approaches, as replication techniques using quorum systems. However, these systems are vulnerable to selfish and malicious nodes, that intentionally do not collaborate with replication operations or spread malicious data while participating in data replication. In order to handle these issues, this paper proposes QS2, a bio-inspired scheme to tolerate selfish and malicious nodes in replication operation of quorum systems. Differently from existing works on the literature, QS2is distributed and self-organized, and each node has the autonomy to exclude misbehaving nodes. The scheme is inspired by quorum sensing and kin selection, both biological mechanisms resident in bacteria. Simulation results show that QS2improves significantly the reliability of a quorum system for MANETs, detecting more than 80% of misbehaving nodes on replication operations.
Elisa Mannes, Michele Nogueira Lima, Aldri Luiz dos Santos
NOMS2
2012 An autonomic knowledge monitoring scheme for trust management on mobile ad hoc networks
abstract
An important characteristic in trust management frameworks is how nodes obtain information about the trustworthiness of other nodes. Some trust management models are based on local information, while others use both information of neighbors and remote nodes. Despite the wide of information used, the existing trust monitoring approaches are mainly based either on passive monitoring mechanisms or on active monitoring mechanisms. While passive monitoring suffers from limitations ranging from strict antenna requirements to high battery use, active dissemination alternatives generate extra overhead to the resource constrained mobile ad hoc networks (MANETs). In this paper, we propose a new knowledge monitoring scheme for trust management on MANETs based on autonomic principles. The proposed scheme minimizes the overhead using transiting packets on the network to update nodes knowledge about other nodes trustworthiness. Simulation results show that the proposed mechanism improves significantly the performance of underlying network, providing a sufficient correct knowledge about nodes trustworthiness required by trust management frameworks.
Zeinab Movahedi, Michele Nogueira Lima, Guy Pujolle
WCNC2
2012 A Security Management Architecture for Supporting Routing Services on WANETs
abstract
Due to the raising dependence of people on critical applications and wireless networks, high level of reliability, security and availability is claimed to assure secure and reliable service operation. Wireless ad hoc networks (WANETs) experience serious security issues even when solutions employ preventive or reactive security mechanisms. In order to support both network operations and security requirements of critical applications, we present SAMNAR, a Survivable Ad hoc and Mesh Network ARchitecture. Its goal lies in managing adaptively preventive, reactive and tolerant security mechanisms to provide essential services even under attacks, intrusions or failures. We use SAMNAR to design a path selection scheme for WANET routing. The evaluation of this path selection scheme considers scenarios using urban mesh network mobility with urban propagation models, and also random way point mobility with two-ray ground propagation models. Results show the survivability achieved on routing service under different conditions and attacks.
Michele Nogueira Lima, Helber Wagner da Silva, Aldri Luiz dos Santos, Guy Pujolle
IEEE Trans. Netw. Serv. Manag.1
2011 Assessing RoQ attacks on MANETs over aware and unaware TPC techniques
Urlan Barros, Mathieu Bouet, Aldri Luiz dos Santos, Michele Nogueira Lima
CNSM4
2011 Resilient approach for energy management on Hot Spots in WSNs
abstract
Mitigating Hot Spot energy consumption in Wireless Sensor Networks (WSNs) is a demanding task. Hot Spots have their nature bounded on routing - they are areas overloaded with high traffic rate, resulting in expanding energy holes. Hot Spots mitigation approaches have employed several techniques supported by routing protocols, such as multiple or mobile sinks, the deployment of more sensors in the Hot Spot area and unequal clustering. Albeit their advantages, cluster-based routing protocols to mitigate Hot Spots manage route maintenance inefficiently, leading to poor network performance and high energy consumption. This work presents an energy management approach to mitigate Hot Spots in WSN, supported by unequal clustering and low-costly dynamic route maintenance. We also generalize our solution for an energy management architecture that considers Hot Spot issues. Results show resilient routing and an efficient energy management, improving both network lifetime and performance.
Fernando Gielow, Michele Nogueira Lima, Aldri Luiz dos Santos
Integrated Network Management2
2010 A framework for self-configuration on WMNs aware of performance and security issues
abstract
Wireless mesh networks (WMNs) have emerged to support applications on various domains, such as military, financial and healthcare, that claim for high level of both security and performance. Since WMNs are susceptible to security issues, and their devices own limitations that can compromise network performance, this paper presents SECOM, a framework for self-configuration of WMNs to provide simultaneously security and performance. It comprises of different functional blocks to manage and adapt network services guaranteeing application requirements. We employ the framework on routing essential service, applying different security mechanisms and redundancies in network and link layers to assist route selection. Simulation results show that our framework enhances both security and performance, with low cost in terms of latency.
Helber Wagner da Silva, Raimir Holanda, Aldri Luiz dos Santos, Michele Nogueira Lima
CNSM4
2010 A Cross-Layer and Adaptive Scheme for Balancing Performance and Security on WMN Data Routing
abstract
Wireless mesh networks (WMNs) have emerged as support for applications on various domains, such as military,financial and healthcare. Those applications claim for high level of both end-to-end performance and security. However, WMNs are naturally susceptible to security issues that can compromise network performance. This paper presents a cross-layer and adaptive scheme for balancing performance and security on data routing when the network experiences malicious actions from damaged nodes. Simulation results show that our approach based on a Multiple Criteria Decision Making method improves the tradeoff network performance and security even under malicious activity.
Helber Wagner da Silva, Raimir Holanda, Michele Nogueira Lima, Aldri Luiz dos Santos
GLOBECOM3
2010 Implications of Misbehaving Attacks on Probabilistic Quorum System for MANETs
Elisa Mannes, Eduardo da Silva, Michele Nogueira Lima, Aldri Luiz dos Santos
SECRYPT3
2009 Survivable keying for wireless ad hoc networks
abstract
Cryptographic techniques are at the center of security solutions for wireless ad hoc networks. Public key infrastructures (PKIs) are essential for their efficient operation. However, the fully distributed organization of these networks makes a challenge to design PKIs. Moreover, changes in network paradigms and the increasing dependency on technology require more dependable, survivable and scalable PKIs. This paper presents a survivable PKI whose goal is to preserve key management operations even in face of attacks or intrusions. Our PKI is based on the adaptive cooperation among preventive, reactive and tolerant defense lines. It employs different evidences to prove the liability of users for their keys as well as social relationships for helping public key exchanges. Simulation results show the improvements achieved by our proposal in terms of effectiveness and survivability to different attacks.
Michele Nogueira Lima, Guy Pujolle, Eduardo da Silva, Aldri Luiz dos Santos, Luiz Carlos Pessoa Albini
Integrated Network Management1
2008 An Architecture for Survivable Mesh Networking
abstract
Wireless mesh networks have gained increasing interests, but the lack of security guarantee has retarded their deployment. Security solutions have applied preventive or reactive mechanisms, being inefficient to put all attacks off. We design a survivable architecture for ad hoc and mesh networks to enhance the network capability of providing essential services even in face of attacks or intrusions. Our approach integrates preventive, reactive and tolerant defense lines in a self-adaptive way. Based on our architecture, we create a survival path selection scheme, and evaluate it through simulations using urban mesh network mobility and propagation models. Results show a decrease in the impact of routing attacks with minimal performance loss.
Michele Nogueira Lima, Helber Wagner da Silva, Aldri Luiz dos Santos, Guy Pujolle
GLOBECOM1
2008 Survival multipath routing for MANETs
abstract
Many efforts have been made to develop security solutions for MANETs. These networks are vulnerable to diverse types of attacks, where routing is a critical operation. Current secure routing protocols are based on preventive or reactive security mechanisms, monitoring node behavior or controlling the access to networks and information. These mechanisms are insufficient to put all attacks and intrusions off, motivating the use of techniques that can tolerate them as multipath routing. This work proposes a new scheme based on fuzzy logic to select better paths and to increase network survivability. Our approach considers different selection criteria, where some of them represent network status and others are issued by preventive, reactive and tolerant defense lines. Simulations have been carried out comparing AODV and AOMDV with a modified AOMDV protocol. Results show the survivability of our approach under different conditions.
Michele Nogueira Lima, Helber Wagner da Silva, Aldri Luiz dos Santos, Guy Pujolle
NOMS1
2008 Quantifying Misbehaviour Attacks Against the Self-Organized Public Key Management on Manets
Eduardo da Silva, Aldri Luiz dos Santos, Luiz Carlos Pessoa Albini, Michele Nogueira Lima
SECRYPT4