Cristoffer Leite

dblp:255/7821 · DBLP profile ↗
← Back
5ranked-venue papers in the field
3as first author
3since 2021 · last 2025
0000-0002-6391-4278ORCID · corroborated

Domains — venue-derived; a paper can count in several

Big Data, Cloud & Distributed Data Systems · 3 (1 first)Other / Interdisciplinary · 2 (2 first)
YearPublicationVenuePosition
2025 An Empirical Investigation of Ransomware Encryption Techniques and Forensic Evidence Availability
abstract
Cryptographic ransomware remains one of the most damaging cyber threats. While research on ransomware has advanced, detailed knowledge of encryption tactics and their implications for digital forensics remains fragmented. As a result, the practical applicability of existing methods is limited. This work addresses these gaps through an empirical investigation of prevalent ransomware encryption techniques and their impact on forensic evidence availability. The investigation of prevalent ransomware encryption was performed using a systematic literature review, mapping ransomware encryption configurations and anti-forensic strategies. Realistic experimental scenarios were subsequently created by simulating Operating System (OS)- and hypervisor-level disk encryption. This was followed by artifact carving and parsing to evaluate evidence availability. The results of the literature review provide an overview of contemporary ransomware encryption practices. The overview reveals clear distinctions between OS and hypervisor encryption in terms of complexity, configurations, and forensic impact. Empirical testing also shows that OS encryption typically leaves most artifacts intact except where targeted anti-forensics are applied. Hypervisor encryption, conversely, significantly reduces access to critical sources such as Windows event logs. The findings of this research enhance the field of digital forensics by providing an overview of ransomware encryption practices and revealing their differing impacts on forensic evidence availability.
Tjielke Nabuurs, Cristoffer Leite, Indika Kumara, Roya Nasiri, Matthijs Vos, Justin Hende
IEEE Big Data2
2025 Mind the Shift: A Study on Transfer Learning and Domain Adaptation in Vehicular Intrusion Detection
abstract
This paper addresses the need for adaptable intrusion detection systems (IDS) in intra-vehicle networks. We evaluated two scalable IDS strategies-combined training and transfer learning-on novel traffic data to balance predictive accuracy and computational efficiency under distributional shifts. Previous IDS models for intra-vehicle attacks achieved high accuracy but relied heavily on the simple CarHacking dataset. To address this limitation, we integrate the newer CIC-IoV-2024 dataset, which reflects realistic vehicular traffic. In Strategy 1, we retrain models from scratch on a combined dataset. These models achieve strong classification across all classes, with accuracies ranging from 90.57% to 100% and F1 scores of 88.91% to 100%. However, training takes longer (61-184 minutes) and inference per packet is slower (30-80 ms). In Strategy 2, we apply transfer learning by fine-tuning pre-trained models while freezing earlier layers. This approach reduces training time (4-16 minutes) and improves latency (21.29-126.76 ms), but predictive performance declines. The models primarily distinguish between benign and malicious traffic, with F1 scores ranging from 82.99% to 89.32%, and exhibit high uncertainty in classifying diverse attack types. Our findings highlight a trade-off between predictive power and computational efficiency. These insights can guide the deployment of IDS frameworks in real-time vehicular environments.
Jakob Richard Proos, Giuseppe Cascavilla, Cristoffer Leite, Alfredo Cuzzocrea
IEEE Big Data3
2023 Automated Cyber Threat Intelligence Generation on Multi-Host Network Incidents
abstract
The lack of automation is one of the main issues hindering the broad usage of high-level Cyber Threat Intelligence (CTI). Creating and using such information by capturing Tactics, Techniques and Procedures (TTPs) is currently an arduous manual task for Cyber Security Incident Response Teams (CSIRT). For CSIRTs, a Network Intrusion Detection System (NIDS) automates the detection of cyber threats. It provides relevant information about alerts to the analysts. This information could generate CTI reports to help others better protect themselves from similar attacks. Due to the demanding work involved in manually creating high-level CTI reports for multi-host incidents, automating this process has become increasingly important.In this paper, a solution is presented to automate the creation of verifiable high-level cyber threat intelligence reports by mapping chains of alerts to TTPs. The solution enables visualisation of attack chains and tactics used, but also manual analysis and validation of the reports created. The proposed approach is evaluated by comparing generating reports with existing CTI, validating any additional TTPs found. The evaluation shows that, not only it was able to match existing reports, but it was also able to improve the knowledge about these threats.
Cristoffer Leite, Jerry den Hartog, Daniel Ricardo dos Santos, Elisa Costante
IEEE Big Data1
2020 A Framework for Performance Evaluation of Network Function Virtualisation in 5G Networks
abstract
Fifth Generation of Mobile Communication (5G) integrates the use of telecommunication and computer systems. As virtualisation eases the deployment of new functionalities demanded by many industrial and social use cases, also show many research challenges regarding performance and resource optimisation. In the 5G architecture, while mobile networks are already trying to implement a full virtualisation of hardware resources, the core itself lacks of an integrated performance evaluation proposal. In this paper we propose a performance evaluation framework, based on an evaluation function and an assortment of distributed observation functions acting as monitors for compute nodes in a virtualised. infrastructure. The framework, unlike previous proposals, is designed to be integrated into 5G as a native service. The framework was evaluated in a Ultra-Reliable and Low Latency Communications (URLLC) scenario and the results show success in monitoring and analysing a Network Function Virtualisation (NFV) environment with a standard 5G NFV implementation.
Cristoffer Leite, Priscila Solís Barreto, Marcos F. Caetano, Rafael Amaral Soares
CLEI1
2019 Pentest on Internet of Things Devices
abstract
Internet of Things (IoT) is one of the key enabling technologies for an always-connected world and also a main enabler for generating information of interest in various application domains. A growing problem in recent years in this technology is security, as power-constrained devices that are typical of IoT applications may not always provide these implementations properly. These conditions can compromise entire environments and allow malicious agents to take control and perform malicious activities. In this article, we provide a summary of the principal vulnerabilities reported for IoT devices based on the OWASP Internet of Things Project, classified by test routine groups. Using models based on standard architectures to define and detail reproducible verification routines for each test, a selection of independent analyzes of each identified category was performed to ensure more comprehensive and accurate testing. Finally, the proposed routines are performed in a test environment to exemplify and ensure their operation, thus contributing to meeting the demand in the area for more accurate information and to assist in understanding the most common vulnerabilities.
Cristoffer Leite, João J. C. Gondim, Priscila Solís Barreto, Marcos F. Caetano, Eduardo Alchieri
CLEI1