EDBT 2026 Demo / reviewers in the wild / expert
Miguel Correia 0001
dblp:64/2768-1 · also Miguel P. Correia 0001, Miguel Pupo Correia
· DBLP profile ↗
132ranked-venue papers
13as first author
29since 2021 · last 2025
0000-0001-7873-5531ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 42 · 4 first-author · 15 since 2021Systems, architecture and hardware · 34 · 5 first-author · 4 since 2021Software engineering, systems software and programming languages · 17 · 2 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 12 · 2 first-author · 5 since 2021Computer networks · 8 · 1 since 2021Human-computer interaction and ubiquitous computing · 2Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorTheory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | XChainWatcher: Identifying Anomalies in Cross-Chain BridgesabstractCross-chain bridges are a blockchain interoperability middleware that supports the transfer of assets and data across blockchains. However, several of these bridges have vulnerabilities that have caused 3.2 billion dollars in losses since May 2021. Some studies have revealed the existence of these vulnerabilities, but there is little quantitative research available, and there are no safeguard mechanisms to protect bridges from such attacks. Furthermore, no studies are available on the practices of cross-chain bridges that can cause financial losses. We propose XChainWatcher (Cross-Chain Watcher), a modular and extensible logic-driven anomaly detector for cross-chain bridges. It operates in three main phases: (1) decoding events and transactions from multiple blockchains, (2) building logic relations from the extracted data, and (3) evaluating these relations against a set of detection rules. Using XChainWatcher, we analyze data from two previously attacked bridges: the Ronin and Nomad bridges. XChainWatcher successfully identified the transactions that led to losses of $611M and $190M (USD) and surpassed the results obtained by a reputable security firm in the latter. We not only uncover successful attacks, but also reveal other anomalies, such as 37 cross-chain transactions (cctx) that should not have accepted, failed attempts to exploit Nomad, over $7.8M worth of tokens locked on one chain but never released on Ethereum, and $200K lost by users due to inadequate interaction with bridges. We provide the first open dataset of 81,000 cctxs across three blockchains, capturing more than $4.2B in token transfers. André Augusto, Rafael Belchior, Jonas Pfannschmidt, André Vasconcelos 0001, Miguel Correia 0001 |
Middleware | 5 |
| 2025 | Decentralised Land Registration and Transaction with Blockchain and Self-Sovereign IdentityabstractLand registry systems maintain public records of land ownership, transactions, and property boundaries, offering legal documentation and information on titles and associated rights. However, there are challenges in the security, accuracy, efficiency, and transparency of the current registries. The paper proposes the Decentralised Land Registry (DLR), a system that leverages a permissioned blockchain, Hyperledger Fabric, enabling a secure and controlled environment for land registration and transaction validation. The use of smart contracts ensures consensus and immutability and allows support for legitimate property transactions overseen by registry authorities. Decentralised identities and ownership proofs are issued using a Self-Sovereign Identity approach, leveraging Hyperledger Indy as the ledger and Hyperledger Aries as the agent representing government entities and issuing these credentials. This solution would mark a pivotal shift in land registry systems, revolutionising traditional practices by addressing their limitations and fostering a transparent, reliable, and efficient landscape for managing property rights and transactions. Pedro C. Henriques, Miguel Correia 0001 |
SRDS | 2 |
| 2025 | An efficient blockchain for decentralized ABAC policy decision pointabstractBlockchain-enabled Policy Decision Point (PDP) has been a promising solution to the centralization concern in practical deployment of Attribute-Based Access Control (ABAC). However, existing blockchain systems cannot support PDP adequately since PDP functionalities introduce extra latency to blockchain’s execution process and limits system throughput. This paper proposes an efficient PDP Blockchain (PDPB) by exploiting a minimum-redundancy execution paradigm. Concretely, we design a novel Echo-Based Execution Conclude (EBEC) mechanism to enable minimum redundancy request evaluation while ensure blockchain safety and liveness. Two optimization techniques, Echo Compacting (EC) and Load Balancing (LB), are proposed to reduce the communication and computation overhead of PDPB and further enhance its performance. We implement a prototype of PDPB and evaluate it on Amazon Web Services (AWS) servers. The results show that PDPB achieves more than 35.6% performance improvement over existing methods. Miguel Correia 0001, Tao Jiang 0002 |
Future Gener. Comput. Syst. | 2 |
| 2024 | Multi-Party Cross-Chain Asset TransfersabstractExisting interoperability mechanisms usually en-compass asset exchanges, asset transfers, and general data transfers. However, most of the solutions based on these mechanisms work only for pairs of permissionless blockchains, falling short in use cases that require more complex business relationships. Furthermore, contrary to existing legacy systems, there is little standardization for cross-domain communication, which multiple players in industry and academia are exploring. We present the Multi-Party Secure Asset Transfer Protocol (MP-SATP), a resilient multi-party asset transfer protocol built on top of the Secure Asset Transfer Protocol (SATP), which is being developed by theInternet Engineering Task Force(IETF). Furthermore, we enhance SATP’s crash recovery mechanism to improve the reliability and performance of our solution. Using MP-SATP, we explain how to perform N -to-N resilient asset transfers in permissioned environments by decoupling them into multiple 1-to-1 asset transfers. Our results show that the latency of the protocol is driven by the latency of the slowest 1-to-1 session and that the use of backup gateways avoids the overhead caused by rollbacks. André Augusto, Rafael Belchior, André Vasconcelos 0001, Miguel Correia 0001, Thomas Hardjono |
ICBC | 4 |
| 2024 | SoK: Security and Privacy of Blockchain InteroperabilityabstractRecent years have witnessed significant advancements in cross-chain technology. However, the field faces two pressing challenges. On the one hand, hacks on cross-chain bridges have led to monetary losses of around 3.1 billion USD, highlighting flaws in security models governing interoperability mechanisms and the ineffectiveness of incident response frameworks. On the other hand, users and bridge operators experience restricted privacy, which broadens the potential attack surface.In this paper, we present the most comprehensive study to date on the security and privacy of blockchain interoperability. We employ a systematic literature review, yielding a corpus of 212 relevant documents, including 58 academic papers and 154 gray literature documents, out of a pool of 531 results. We systematically categorize 57 interoperability solutions based on a novel security and privacy taxonomy. Our dataset, comprising academic research, disclosures from bug bounty programs, and audit reports, exposes 45 cross-chain vulnerabilities, 4 privacy leaks, and 92 mitigation strategies. Leveraging this data, we analyze 18 notable bridge hacks accounting for over 2.9 billion USD in losses, mapping them to the identified vulnerabilities.Our findings reveal that a substantial portion (65.8%) of stolen funds originates from projects secured by intermediary permissioned networks with unsecured cryptographic key operations. Privacy-wise, we demonstrate that achieving unlinkability in cross-chain transactions is contingent on the underlying ledgers providing some form of confidentiality. Our study offers 17 critical insights into the security and privacy of cross-chain systems. We pinpoint promising future research directions, underscoring the urgency of enhancing security and privacy efforts in cross-chain technology. The identified improvements have the potential to mitigate the financial risks associated with bridge hacks, fostering user trust in the blockchain ecosystem and, consequently, wider adoption. André Augusto, Rafael Belchior, Miguel Correia 0001, André Vasconcelos 0001, Luyao Zhang 0001, Thomas Hardjono |
SP | 3 |
| 2024 | BUNGEE: Dependable Blockchain Views for InteroperabilityabstractWith the evolution of distributed ledger technology (DLT), several blockchains that provide enhanced privacy guarantees and features, including Corda, Hyperledger Fabric, and Canton, are being increasingly adopted. These distributed ledgers only provide partial consistency, meaning that participants can observe the same ledger differently, i.e., observe some transactions but not others, providing higher levels of privacy to the end-user. Choosing privacy instead of transparency leads to delicate trade-offs that are difficult to manage during runtime, hampering the development of applications that depend on reasoning about shared state, e.g., asset transfers across blockchains. We propose using the concept of blockchain view (view) – an abstraction of the state a participant can access at a certain point to address this problem. Views allow us to systematically reason about either state partitions within the same DLT or an integrated view spanning across several DLTs. We introduce BUNGEE (Blockchain UNifier view GEnErator), the first DLT view generator, to allow capturing snapshots, constructing views from these snapshots, and merging views according to a set of rules specified by the view stakeholders. Creating views and operating views allows new applications built on top of dependable blockchain interoperability, such as stakeholder-centric snapshots for audits, cross-chain analysis, blockchain migration, and combined on-chain-off-chain analytics. Rafael Belchior, Limaris Torres, Jonas Pfannschmidt, André Vasconcelos 0001, Miguel Correia 0001 |
Distributed Ledger Technol. Res. Pract. | 5 |
| 2024 | PoTR: Accurate and Efficient Proof of Timely-Retrievability for Storage SystemsabstractThe use of remote storage has become prevalent both by organizations and individuals. By relying on third-party storage, such as cloud or peer-to-peer storage services, availability, fault tolerance, and low access latency can be attained in a cost-efficient manner. Unfortunately, storage providers may misbehave and violate Service-Level Agreements (SLAs). In this article, we propose a new Proof of Timely-Retrievability (PoTR) that aims at assessing whether a provider is able to retrieve data objects with a latency lower than some SLA-specific threshold δ. We have implemented the PoTR and evaluated two distinct configurations of the proof, one tailored to estimate the average latency experience by clients and the other tailored to assess its variance. We leverage Trusted Execution Environments (e.g., Intel SGX) to ensure that the proof is produced by the node being audited and to reduce the communication between the auditor and the audited node. We have experimentally evaluated our prototypes considering a challenging edge computing setting, where storage services are provided by resource-constrained fog nodes, and the distance between the auditor and the audited node can be large. Despite the noise introduced by edge network delays, we show that the auditor is able to effectively detect SLA violations. Cláudio Correia, Rita Prates, Luís Fonseca, Miguel Correia 0001, Luís E. T. Rodrigues |
Formal Aspects Comput. | 4 |
| 2024 | Editorial: Special issue on software protection and attacks
Michele Ianni, Mila Dalla Preda, Kim-Kwang Raymond Choo, Miguel Correia 0001 |
J. Inf. Secur. Appl. | 4 |
| 2024 | Hephaestus: Modeling, Analysis, and Performance Evaluation of Cross-Chain TransactionsabstractEcosystems of multiple blockchains are now a reality. Multichain applications and protocols are perceived as necessary to enable scalability, privacy, and composability. Despite being a promising emerging area, we have been witnessing devastating attacks on cross-chain bridges that have caused billions of dollars in losses, and no apparent solution seems to emerge from the ongoing chaos. In this article, we present our contribution to minimizing bridge attacks, by monitoring across-chain model. In particular, we aggregatecross-chain eventsintocross-chain transactions, and verify if they follow a set ofcross-chain rules, which then generate a model. We proposeHephaestus, the first cross-chain model generator that captures the operational complexity of cross-chain applications.Hephaestuscan generate cross-chain models from local transactions in different ledgers, realizing arbitrary cross-chain use cases and allowing operators to monitor their applications. Monitoring helps identify outliers and malicious behavior, which can enable programmatically stopping attacks (“a circuit breaker”), including bridge hacks. We conduct a detailed evaluation of our system, where we implement a cross-chain bridge use case. Our experimental results show thatHephaestuscan process 600 cross-chain transactions in less than 5.5 s in an environment with two blockchains using sublinear storage, paving the way for more resilient bridge designs. Rafael Belchior, Peter Somogyvari, Jonas Pfannschmidt, André Vasconcelos 0001, Miguel Correia 0001 |
IEEE Trans. Reliab. | 5 |
| 2023 | Using Range-Revocable Pseudonyms to Provide Backward Unlinkability in the EdgeabstractIn this paper we propose a novel abstraction that we have named Range-Revocable Pseudonyms (RRPs). RRPs are a new class of pseudonyms whose validity can be revoked for any time-range within its original validity period. The key feature of RRPs is that the information provided to revoke a pseudonym for a given time-range cannot be linked with the information provided when using the pseudonym outside the revoked range. We provide an algorithm to implement RRPs using efficient cryptographic primitives where the space complexity of the pseudonym is constant, regardless of the granularity of the revocation range, and the space complexity of the revocation information only grows logarithmically with the granularity; this makes the use of RRPs far more efficient than the use of many short-lived pseudonyms. We have used RRPs to design EDGAR, an access control system for VANET scenarios that offers backward unlinkability. The experimental evaluation of EDGAR shows that, when using RRPs, the revocation can be performed efficiently (even when using time slots as small as 1 second) and that users can authenticate with low latency (0.5-3.5ms ). Cláudio Correia, Miguel Correia 0001, Luís E. T. Rodrigues |
CCS | 2 |
| 2023 | Decentralised Autonomous Organisations for Public ProcurementabstractBlockchain has been recognised as a technological breakthrough with the ability to support new decentralised security-based solutions in sectors such as information technology and finance. Blockchain allows different communities to create Decentralised Autonomous Organisations (DAOs), which are self-organised democratic organisations controlled by smart contracts. This paper presents a new DAO model for the procurement of services by public organisations, such as government agencies. To demonstrate the advantages of this solution, this work looks specifically at current public procurement systems that resort to third-party contractors that manage these negotiations. Third parties lack the transparency, security, and democratic representation that a DAO can provide. We present the implementation of a DAO as a set of smart contracts executed on Ethereum-compatible permissionless blockchains, supported by a consensus algorithm, replacing third-party contractors. Felix Monteiro, Miguel Correia 0001 |
EASE | 2 |
| 2023 | CBDC Bridging between Hyperledger Fabric and Permissioned EVM-based BlockchainsabstractThe last few years have seen a steep increase in blockchain interoperability research. Most solutions connect public blockchains, where the main cross-chain use case is token transfer. By-design platform transparency, tamper resistance, and auditability make blockchains a candidate infrastructure for Central Bank Digital Currencies (CBDCs), but bridging CBDCs is an important missing piece in that scenario. In this paper, we leverage an asset transfer protocol, SATP, to define an extendable and dependable blockchain interoperability middleware that can bridge CBDC between Hyperledger Fabric and EVM-based permissioned blockchains. The key interoperation enabler in the solution is a shared asset definition enforced by both sides of the bridge, accompanied by a mapping between Fabric identities and Ethereum addresses for identity management. We implemented our design using Hyperledger Cacti. A preliminary evaluation shows that latency is more influenced by the ledgers than the bridging components. André Augusto, Rafael Belchior, Imre Kocsis, László Gönczy, André Vasconcelos 0001, Miguel Correia 0001 |
ICBC | 6 |
| 2023 | I Can't Escape Myself: Cloud Inter-Processor Attestation and Sealing using Intel SGXabstractSGX enclaves protect the code and data within from untrusted software, but do not retain their state when destroyed. Sealing allows preserving this data for future use by storing it outside the enclave boundary: the data is encrypted with a fresh secret key, and this key is bound to the processor that sealed the data and, either to the enclave measurement, or the public key of the enclave author. However, in a cloud environment, customers do not choose in which processor their code executes: the enclave that seals some data (for backup or future use) may be destroyed and later instantiated on a different processor or migrated to another processor. In those cases, the new processor would not be able to unseal the data, since the secret key is bound to the sealing processor.This paper presents Inter-Processor Attestation and Sealing (IPAS), a novel sealing mechanism for cloud environments and Intel SGX. In IPAS, sealed data is no longer bound to the sealing processor, but only to the enclave measurement or the public key of the enclave author, thus enabling other processors to unseal the sealed data. This is achieved without exporting the sealing secret key outside the enclave and without trusting third parties. Daniel Andrade, João Nuno Silva, Miguel Correia 0001 |
PRDC | 3 |
| 2023 | PoTR: Accurate and Efficient Proof of Timely-Retrievability for Storage SystemsabstractThe use of remote storage has become prevalent both by organizations and individuals. By relying on third-party storage, such as cloud or peer-to-peer storage services, availability, fault tolerance, and low access latency can be attained in a cost-efficient manner. Unfortunately, storage providers may misbehave and violate Service-Level Agreements (SLAs). In this paper, we propose, implement and evaluate a new Proof of Timely-Retrievability (PoTR) that aims at assessing whether a provider is able to retrieve data objects with a latency lower than some SLA-specific threshold δ. We leverage Trusted Execution Environments (e.g., Intel SGX) to ensure that the proof is produced by the node being audited and to reduce the communication between the auditor and the audited node. We have experimentally evaluated our design considering a challenging edge computing setting, where storage services are provided by resource-constrained fog nodes, and the distance between the auditor and the audited node can be large. Despite the variance in edge network delays, we show that the auditor is able to effectively detect SLA violations. Cláudio Correia, Rita Prates, Miguel Correia 0001, Luís E. T. Rodrigues |
PRDC | 3 |
| 2023 | Poster: In-Network ML Feature Computation for Malicious Traffic DetectionabstractWe present Peregrine, a malicious traffic detector that offloads part of its computation to a programmable switch. The idea is to partition detection, by moving the ML feature computation module from a middlebox server to a switch data plane. The key innovation unlocked---computing the ML input features over all traffic---results in a significant improvement in detection performance: in our evaluation, up to 5.7x over the state of the art. João Romeiras Amado, Francisco Chamiça Pereira, Salvatore Signorello, Miguel Correia 0001, Fernando M. V. Ramos |
SIGCOMM | 4 |
| 2023 | TrustGlass: Human-Computer Trusted Paths with Augmented Reality Smart GlassesabstractHumans constantly interact with computing devices. Many times, these interactions involve sensitive information and/or sensitive commands, leading to the need for trusted paths between humans and computers. For computer-to-computer interactions, secure communication is not an issue thanks to cryptographic protocols such as Transport Layer Security (TLS) and the IP Security Protocol (IPSec). However, the same does not yet apply to interactions between humans and computers due to the inability of humans to execute non-trivial cryptographic algorithms. This results in interactions that are vulnerable to shoulder surfing, man-in-the-browser malware, and web page spoofing, among other attacks. This consequently puts at risk the use of sensitive services in uncontrolled environments.We present TrustGlass, a scheme that uses augmented reality smart glasses to solve this security problem. TrustGlass uses such glasses to extend human capabilities, to execute the cryptographic algorithms needed to establish a trusted path between the user and the trusted service, which can be executed in a Trusted Execution Environment (TEE). With this approach, we can guarantee that only the user equipped with the glasses is capable of interacting with the service. We implemented TrustGlass using commercial smart glasses and show experimental performance and usability results. Hélio Borges, Daniel Andrade, João Nuno Silva, Miguel Correia 0001 |
TrustCom | 4 |
| 2023 | MultiTLS: using multiple and diverse ciphers for stronger secure channels
Ricardo Moura, Ricardo Lopes, David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
Comput. Secur. | 5 |
| 2023 | Do You Need a Distributed Ledger Technology Interoperability Solution?abstractEntrepreneurs, enterprises, and governments are using distributed ledger technology (DLT) as a component of complex information systems, and therefore interoperability capabilities are required. Interoperating DLTs enable network effects and synergies, and similarly to the rise of the Internet, it unlocks the full potential of the technology. However, due to the novelty of the area, interoperability mechanisms (IMs) are still not well understood, as interoperability is studied in silos. Consequently, choosing the proper IM for a use case is challenging. Our article has three contributions: first, we systematically study the research area of DLT interoperability by dissecting and analyzing previous work. We study the logical separation of interoperability layers, how a DLT can connect to others (connection mode), the object of interoperation (interoperation mode), and propose a new categorization for IMs. Second, we propose the first interoperability assessment for DLTs that systematically evaluates the interoperability degree of an IM. This framework allows comparing the potentiality, compatibility, and performance among solutions. Finally, we propose two decision models to assist in choosing an IM, considering different requirements. The first decision model assists in choosing the infrastructure of an IM, while the second decision model assists in choosing its functionality. Rafael Belchior, Luke Riley, Thomas Hardjono, André Vasconcelos 0001, Miguel Correia 0001 |
Distributed Ledger Technol. Res. Pract. | 5 |
| 2023 | Monintainer: An orchestration-independent extensible container-based monitoring solution for large clustersabstractContainer virtualization has recently gained popularity due to its low performance and resource allocation overhead. The rise of this technology can be attributed to the advancement of cloud computing and the adoption of micro-services architecture. These new approaches offer a more efficient and fine-grained system design through the benefits of containerization, such as isolation, portability, and improved performance. However, container-based systems have created new challenges in monitoring due to their automated flexibility, ephemerality, and the increasing number of containers in a system. So there is a practical need for effective monitoring and performance management tools. This paper analyses the key performance metrics for machine, container and application services, including CPU usage, memory usage, disk usage, and network usage. Furthermore, we review several widespread tools for collecting and monitoring these metrics and present the Monintainer tool. It is a solution designed to monitor entire container-based systems, from applications to their underlying infrastructure, allowing users to better understand their systems’ behaviour in run-time. The tool’s results can aid container-based systems’ design, implementation and optimization. Miguel Correia 0001, Wellington Oliveira, José Cecílio |
J. Syst. Archit. | 1 |
| 2023 | MIRES: Intrusion Recovery for Applications Based on Backend-As-a-ServiceabstractThe Backend-as-a-Service (BaaS) cloud computing model supports many modern popular mobile applications because it simplifies the development and management of services such as data storage, user authentication, and notifications. However, vulnerabilities and other issues may allow malicious actions on the client side to have impact on the backend, i.e., to corrupt the state of the application in the cloud. To deal with these attacks – after they occur and are successful – it is necessary to remove the direct effects of malicious requests and the effects derived from later operations on corrupted data. We introduce MIRES, the first intrusion recovery service for mobile applications based on the BaaS model. MIRES uses a two-stage recovery process that restores the integrity of the mobile application and minimizes its unavailability. MIRES provides multi-service recovery for applications that use more than one data store. We implemented MIRES for Android and for the Firebase cloud-based BaaS platform. We did experiments on 4 mobile applications which showed that MIRES can revert hundreds to thousands of operations in seconds, with an associated unavailability of the application also in the range of seconds. Diogo Vaz, David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
IEEE Trans. Cloud Comput. | 4 |
| 2023 | Sanare: Pluggable Intrusion Recovery for Web ApplicationsabstractWeb applications are exposed to many threats and, despite the best defensive efforts, are often successfully attacked. Reverting the effects of an attack on the state of such an application requires a profound knowledge about the application, to understand what data did the attack corrupt. Furthermore, it requires knowing what steps are needed to revert the effects without modifying legitimate data created by legitimate users. Existing intrusion recovery systems are capable of reverting the effects of the attack but they require modifications to the source code of the application, which may be unpractical. We presentSanare, a pluggable intrusion recovery system designed for web applications that use different data storage systems to keep their state. Sanare does not require any modification to the source code of the application or the web server. Instead, it uses a new deep learning scheme that we also introduce in the article,Matchare, that learns the matches between the HTTP requests and the database statements, file system operations, and web service requests that the HTTP requests caused. We evaluated Sanare with three open source web applications: WordPress, GitLab and ownCloud. In our experiments, Matchare achieved precision and recall higher than 97.5% with a performance overhead of less than 18% to the application. David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | Anonymous Trusted Data Relocation for TEEs
Vasco Guita, Daniel Andrade, João Nuno Silva, Miguel Correia 0001 |
SEC | 4 |
| 2022 | Integrating an academic management system with blockchain: A case studyabstractThis paper reports the design, implementation, and experimental phases of the EU H2020 QualiChain pilot “Staffing the Public Sector—The Case of Portugal”. The overall purpose of this pilot is to ensure the authenticity and integrity of the diplomas for all involved stakeholders and therefore to contribute to solving the diploma counterfeiting and/or falsification that is a great threat to the recruitment of qualified personnel. The main innovative aspect of this solution is the integration that is offered between an Academic Management System (the Fenix.edu platform) and a Blockchain (Ethereum) to automatically deploy diplomas. This solution helps the involved stakeholders trust the diplomas provided. The case study involves four different stakeholders and studies, specifically, the increase in their satisfaction in terms of diploma control, diploma veracity, and diploma credibility. The developed system was tested with external participants who were asked to follow a set of guidelines and complete a survey to assess their perceptions. All system interactions were recorded, and the data were analyzed. The results indicated that the participants successfully executed the guidelines and that a perception increase toward diploma control, veracity, and credibility was identified. Sérgio Guerreiro 0001, João F. Ferreira 0001, Tiago Fonseca, Miguel Correia 0001 |
Blockchain Res. Appl. | 4 |
| 2022 | Hermes: Fault-tolerant middleware for blockchain interoperability
Rafael Belchior, André Vasconcelos 0001, Miguel Correia 0001, Thomas Hardjono |
Future Gener. Comput. Syst. | 3 |
| 2022 | Omega: A Secure Event Ordering Service for the EdgeabstractThe edge computing paradigm extends cloud computing with storage and processing capacity close to the edge of the network, which can be materialized by using many fog nodes placed in multiple geographic locations. Fog nodes are likely to be vulnerable to tampering, so it is important to protect the functions they provide from attacks. A key building block of many distributed applications is an ordering service that keeps track of cause-effect dependencies among events and that allows events to be processed in an order that respects causality. This article presents the design and implementation of a secure event ordering service for fog nodes. Our service, named Omega, leverages the availability of a Trusted Execution Environment (TEE), based on SGX technology, to offer fog clients guarantees regarding the order in which events are applied and served, even when fog nodes are compromised. We have also built OmegaKV, a key-value store that uses Omega to offer causal consistency. Experimental results show that the ordering service can be secured without violating the latency constraints of time-sensitive edge applications, despite the overhead associated with using a TEE. Omega introduces an additional latency of approximately 4ms, that contrary to cloud based solutions, allows latency values in the 5ms-30ms range, as required by time-sensitive edge applications. Cláudio Correia, Miguel Correia 0001, Luís E. T. Rodrigues |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Statically Detecting Vulnerabilities by Processing Programming Languages as Natural LanguagesabstractWeb applications continue to be a favorite target for hackers due to a combination of wide adoption and rapid deployment cycles, which often lead to the introduction of high-impact vulnerabilities. Static analysis tools are important to search for vulnerabilities automatically in the program source code, supporting developers on their removal. However, building these tools requires programming the knowledge on how to discover the vulnerabilities. This article presents an alternative approach in which toolslearnto detect flaws automatically by resorting to artificial intelligence concepts, more concretely to natural language processing. The approach employs a sequence model to learn to characterize vulnerabilities based on an annotated corpus. Afterwards, the model is utilized to discover and identify vulnerabilities in the source code. It was implemented in the DEKANT tool and evaluated experimentally with a large set of PHP applications and WordPress plugins. Overall, we found several thousand vulnerabilities belonging to 15 classes of input validation vulnerabilities, where 4143 of them were zero-day. Iberia Medeiros, Nuno Neves 0001, Miguel Correia 0001 |
IEEE Trans. Reliab. | 3 |
| 2021 | CyberVTI: Cyber Visualization Tool for Intrusion DetectionabstractThis paper presents the Cyber Visualization Tool for Intrusion detection (CYBERVTI), a tool that provides intrusion detection algorithms with an effective graphical interface. The goals of the tool are twofold. First, it aims to aid the human analyst on observing ongoing threats as a step towards responding to these attacks. Second, it aims to help the analyst study the performance of the algorithms with different parameters, in order to decide which combination best suits his goals. The tool integrates a set of recently-proposed intrusion detection algorithms based on unsupervised machine learning, which it aims to help configuring. Cybervti follows a client-server system architecture and implements a REST API that mediates the communication between the server and the GUI on the client-side. A significant challenge is to define data structures that allow storing and accessing data efficiently in an interactive manner. A clear and minimalist visual aspect was chosen for the GUI, containing functionalities that enable the user to analyze the network data in a simple and clear way. For system evaluation, we used the ISOIIEC 25010:2011 requirements. For validation, we compared the results obtained by our tool with the results described in the original papers that present the algorithms. Luís Dias, Miguel Correia 0001 |
NCA | 3 |
| 2021 | Virtual Static Security Analyzer for Web ApplicationsabstractWeb applications are popular victims of injection attacks such as SQL injection and cross-site scripting. Vulnerability detection tools allow preventing these attacks but are often bound to a single language and hard to port to new languages. We propose a new approach to support the addition of new languages without much effort. In order to achieve this, our solution does not analyze the source code AST directly, instead, it traverses the source code AST and builds a generic AST (GAST) from it. Then, the tool analyzes the GAST to find vulnerabilities. This way we decouple the analysis and the source code parsing. To add support for a new language we just need to generate a parser and write a converter for that AST, which is usually less than 110 lines of code. We implemented a tool called GT with this approach. The tool currently supports four languages: Java, PHP, Python and JavaScript. It was tested against several web applications written in the same languages. Mihail Brinza, Miguel Correia 0001 |
TrustCom | 2 |
| 2021 | Secure cloud-of-clouds storage with space-efficient secret sharing
Ahad Niknia, Miguel Correia 0001, Jaber Karimpour |
J. Inf. Secur. Appl. | 2 |
| 2020 | Omega: a Secure Event Ordering Service for the EdgeabstractEdge computing is a paradigm that extends cloud computing with storage and processing capacity close to the edge of the network that can be materialized by using many fog nodes placed in multiple geographic locations. Fog nodes are likely to be vulnerable to tampering, so it is important to secure the functions they provide. A key building block of many distributed applications is an ordering service that keeps track of cause-effect dependencies among events and that allows events to be processed in an order that respects causality. In this paper we present the design and implementation of a secure event ordering service for fog nodes. Our service, named Omegae, leverages the availability of a Trusted Execution Environment (TEE) based on Intel SGX technology to offer fog clients guarantees regarding the order in which events are applied and served, even when fog nodes are compromised. We have also built OmegaKV, a key-value store that uses Omega e to offer causal consistency. Experimental results show that the ordering service can be secured without violating the latency constraints of time-sensitive edge applications, despite the overhead associated with using a TEE. Cláudio Correia, Miguel Correia 0001, Luís E. T. Rodrigues |
DSN | 2 |
| 2020 | Poster: Speeding Up Network Intrusion DetectionabstractModern network data planes have enabled new measurement approaches, including efficient sketch-based techniques with provable trade-offs between memory and accuracy, directly in the data plane, at line rate. We thus ask the question: can one leverage this richer measurement plane to improve network intrusion detection? Our answer is SPID, a push-based, feature-rich network monitoring approach to assist learning-based attack detection. SPID switches run a diverse set of measurement primitives and proactively push measurements to the monitoring system when relevant changes occur. Network measurements are then fed as input features to a classifier based on unsupervised learning to detect ongoing attacks, as they occur. In consequence, SPID aims to reduce attack detection time, when comparing to existing solutions present in large scale networks. João Romeiras Amado, Salvatore Signorello, Miguel Correia 0001, Fernando M. V. Ramos |
ICNP | 3 |
| 2020 | MIRES: Recovering Mobile Applications based on Backend-as-a-Service from Cyber AttacksabstractMany popular mobile applications rely on the Backend-as-a-Service (BaaS) cloud computing model to simplify the development and management of services like data storage, user authentication and notifications. However, vulnerabilities and other issues may lead to malicious operations on the mobile application client-side and malicious requests being sent to the backend, corrupting the state of the application in the cloud. To deal with these attacks after they happen and are successful, it is necessary to remove the immediate effects created by the malicious requests and subsequent effects derived from later requests. In this paper, we present MIRES, an intrusion recovery service for mobile applications based on BaaS. MIRES uses a two-phase recovery process that restores the integrity of the mobile application and minimizes its unavailability. We implemented MIRES in Android and with the Firebase platform and made experiments with 3 mobile applications that showed results of 1000 operations reverted in less than 1 minute and with the mobile application inaccessible only for less than 15 seconds. Diogo Vaz, David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
MobiQuitous | 4 |
| 2020 | Go With the Flow: Clustering Dynamically-Defined NetFlow Features for Network Intrusion Detection with DynIDSabstractThe paper presents DynIDS, a network intrusion detection approach that flags malicious activity without previous knowledge about attacks or training data. DynIDS dynamically defines and extracts features from network data, and uses clustering algorithms to aggregate hosts with similar behavior. All previous clustering-based network intrusion detection approaches use a static set of features, restricting their ability to detect certain attacks. Instead, we use a set of features defined dynamically, at runtime, avoiding that restriction without falling into the curse of dimensionality, something that we believe is essential for the adoption of this kind of approaches. We evaluated DynIDS experimentally with an evaluation and a real-world dataset, obtaining better F-Score than alternative solutions. Luís Dias, Simão Valente, Miguel Correia 0001 |
NCA | 3 |
| 2020 | MERLIN: Multi-Language Web Vulnerability DetectionabstractAlthough there is continuous research to improve web security, web applications are constantly being attacked due to vulnerable source code. A common way used to find vulnerabilities in code is with source code static analysis tools. However, these tools have two problems: they must be coded manually to deal with all types of vulnerabilities and they only work with a specific programming language. This paper presents an approach that aims to improve security of web applications by identifying vulnerabilities in code written in different languages. Moreover, we do not hard-code the rules of detection, but instead use machine learning to configure them. The approach was implemented in a tool called MERLIN. This tool was tested with samples from the SRD database and real-world web applications written in Java and PHP. Alexandra Figueiredo, Tatjana Lide, David R. Matos, Miguel Correia 0001 |
NCA | 4 |
| 2020 | Cryptojacking Detection with CPU Usage MetricsabstractCryptojacking is currently being exploited by cyber-criminals. This form of malware runs in the computers of victims without their consent. It often infects browsers and does CPU-intensive computations to mine cryptocurrencies on behalf of the cyber-criminal, which takes the profits without paying for the resources consumed. Such attacks degrade computer performance and potentially reduce the hardware lifetime. We introduce a new cryptojacking detection mechanism based on monitoring the CPU usage of the visited web pages. This may look like an unreliable way to detect mining malware since many web sites are heavy computationally and that malware often throttles CPU usage. However, by combining a set of CPU monitoring features and using machine learning, we manage to obtain metrics like precision and recall close to 1. Fábio Gomes, Miguel Correia 0001 |
NCA | 2 |
| 2020 | CryingJackpot: Network Flows and Performance Counters against CryptojackingabstractCryptojacking, the appropriation of users' computational resources without their knowledge or consent to obtain cryp-tocurrencies, is a widespread attack, relatively easy to implement and hard to detect. Either browser-based or binary, cryptojacking lacks robust and reliable detection solutions. This paper presents a hybrid approach to detect cryptojacking where no previous knowledge about the attacks or training data is needed. Our Cryp-tojacking Intrusion Detection Approach, Cryingjackpot, extracts and combines flow and performance counter-based features, aggregating hosts with similar behavior by using unsupervised machine learning algorithms. We evaluate Cryingjackpot experimentally with both an artificial and a hybrid dataset, achieving F1-scores up to 97%. Gilberto Gomes, Luís Dias, Miguel Correia 0001 |
NCA | 3 |
| 2020 | Towards Quantum-Enhanced Machine Learning for Network Intrusion DetectionabstractNetwork Intrusion Detection Systems (NIDSs) are commonly used today to detect malicious activities. Quantum computers, despite not being practical yet, are becoming available for experimental purposes. We present the first approach for applying unsupervised Quantum Machine Learning (QML) in the context of network intrusion detection from the perspective of quantum information, based on the concept of quantum-assisted ML. We evaluate it using IBM QX in simulation mode and show that the accuracy of a Quantum-Assisted NIDS, based on our approach, can be high, rivaling with the the best conventional SVM results, with a dependence on the characteristics of the dataset. Arnaldo Gouveia, Miguel Correia 0001 |
NCA | 2 |
| 2020 | Recoverable Token: Recovering from Intrusions against Digital Assets in EthereumabstractBlockchain systems allow storing digital assets in a tamper-proof, consensus-based, append-only ledger in a decentralized fashion, where no single party has full control. A blockchain is an immutable, append-only, log of transactions. Unfortunately, in some cases there is the need to undo transactions that result from intrusions, e.g., when the private keys of a wallet are stolen, when one of the transaction participants does not comply with what was agreed upon, or when smart contract vulnerabilities are exploited by attackers. There are also accidental scenarios, e.g., when private keys are lost leaving the associated digital assets inaccessible. Although there have been a few proposals which allow modifications to the blockchain, they break the basic guarantees they are supposed to provide. We propose an approach for wallet owners to recover from attacks against their digital assets and accidental loss, while still assuring fundamental properties of the blockchain technology. We implemented the mechanism for Ethereum / EVM. Filipe F. Martins, David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
NCA | 4 |
| 2020 | P2CSTORE: P2P and Cloud File Storage for Blockchain ApplicationsabstractWe live in an era where storage systems are of major importance. In this work, we focus on storing files for use in blockchain applications. A blockchain is a distributed, replicated system, that contains a ledger of operations and executes programs known as smart contracts. Although a blockchain may be considered a data storage system, public blockchains like Ethereum charge the users per each byte stored making them expensive to store large files. Therefore, applications based on blockchains often use an external file storage system, usually peer-to-peer (P2P). We propose P2CSTORE, a new storage system for blockchain applications using both P2P and cloud subsystems. This way we aim to provide application developers with the flexibility of choosing the best place for their files, depending on aspects such as the trust they place in peers and clouds. We show the benefits of the approach with a blockchain application that manages education certificates. The application stores hashes of the certificates in the cloud and the certificates themselves in our storage system. Miguel Matos, Miguel Correia 0001 |
NCA | 3 |
| 2020 | MultiTLS: Secure Communication Channels with Cipher Suite Diversity
Ricardo Moura, David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
SEC | 4 |
| 2020 | SSIBAC: Self-Sovereign Identity Based Access ControlabstractIneffective data management practices pose serious issues to individuals and companies, e.g., risk of identity theft and online exposure. Self-sovereign identity (SSI) is a new identity management approach that ensures users have full control of their personal data. In this work, we alleviate data breach and user privacy problems by showing how SSI can fit within the context of established enterprise identity and access management technologies. In light of recent endeavors, we explore the use of decentralized identifiers, verifiable credentials, and blockchains that support SSI. We propose Self-Sovereign Identity Based Access Control (SSIBAC), an access control model for cross-organization identity management. SSIBAC leverages conventional access control models and blockchain technology to provide decentralized authentication, followed by centralized authorization. The access control process does not require storing user sensitive data. A prototype was implemented and evaluated, processing 55,000 access control requests per second with a latency of 3 seconds. Rafael Belchior, Benedikt Putz, Günther Pernul, Miguel Correia 0001, André Vasconcelos 0001, Sérgio Guerreiro 0001 |
TrustCom | 4 |
| 2020 | C2BID: Cluster Change-Based Intrusion DetectionabstractThe paper presents a network intrusion detection approach that flags malicious activity without previous knowledge about attacks or training data. The Cluster Change-Based Intrusion Detection approach (C2BID) detects intrusions by monitoring host behavior changes. For that purpose, C2BID defines and extracts features from network data, aggregates hosts with similar behavior using clustering, then analyses how hosts move between clusters along a period of time. This contrasts with previous work in the area that stops at the clustering step. We evaluated C2BID experimentally with two datasets, obtaining better F-Score than previous solutions. Tiago Fernandes, Luís Dias, Miguel Correia 0001 |
TrustCom | 3 |
| 2020 | Fireplug: Efficient and Robust Geo-Replication of Graph DatabasesabstractAlthough graph-databases have been assuming an increasing relevance in applications that exhibit strong dependability requirements, including tolerance to malicious faults, few works have addressed Byzantine fault tolerance in this particular context, and previous attempts suffer from lack of flexibility and poor performance. This article describes and evaluates Fireplug, a flexible architecture to build robust geo-replicated graph databases. Fireplug can be configured to tolerate from crash to Byzantine faults, both within and across different datacenters. Furthermore, Fireplug is robust to bugs in existing graph database implementations, as it allows to combine multiple graph database instances in a cohesive manner. Thus, Fireplug can support many different deployments, according to the performance/robustness trade-offs imposed by the target application. Our evaluation shows that Fireplug is able implement Byzantine fault tolerance without penalty when compared to the built-in replication mechanism of Neo4j, which only supports crash faults. Additionally, performance optimizations introduced by Fireplug improve the overall performance by up to 900 percent in geo-replicated scenarios. Ray Neiheiser, Luciana Rech, Manuel Bravo, Luís E. T. Rodrigues, Miguel Correia 0001 |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2019 | Pando: Personal Volunteer Computing in BrowsersabstractThe large penetration and continued growth in ownership of personal electronic devices represents a freely available and largely untapped source of computing power. To leverage those, we present Pando, a new volunteer computing tool based on a declarative concurrent programming model and implemented using JavaScript, WebRTC, and WebSockets. This tool enables a dynamically varying number of failure-prone personal devices contributed by volunteers to parallelize the application of a function on a stream of values, by using the devices' browsers. We show that Pando can provide throughput improvements compared to a single personal device, on a variety of compute-bound applications including animation rendering and image processing. We also show the flexibility of our approach by deploying Pando on personal devices connected over a local network, on Grid5000, a French-wide computing grid in a virtual private network, and seven PlanetLab nodes distributed in a wide area network over Europe. Erick Lavoie, Laurie J. Hendren, Frédéric Desprez, Miguel Correia 0001 |
Middleware | 4 |
| 2019 | OutGene: Detecting Undefined Network Attacks with Time Stretching and Genetic Zooms
Luís Dias, Hélder Reia, Rui Ferreira Neves, Miguel Correia 0001 |
NSS | 4 |
| 2019 | SEPTIC: Detecting Injection Attacks and Vulnerabilities Inside the DBMSabstractDatabases continue to be the most commonly used backend storage in enterprises, but they are often integrated with vulnerable applications, such as web frontends, which allow injection attacks to be performed. The effectiveness of such attacks stems from a semantic mismatch between how SQL queries are believed to be executed and the actual way in which databases process them. This leads to subtle vulnerabilities in the way input validation is done in applications. In this paper, we propose SEPTIC, a mechanism for DBMS attack prevention, which can also assist on the identification of the vulnerabilities in the applications. The mechanism was implemented in MySQL and evaluated experimentally with various applications and alternative protection approaches. Our results show no false negatives and no false positives with SEPTIC, on the contrary to other solutions. They also show that SEPTIC introduces a low performance overhead, in the order of 2.2%. Iberia Medeiros, Miguel Beatriz, Nuno Neves 0001, Miguel Correia 0001 |
IEEE Trans. Reliab. | 4 |
| 2018 | Storing Critical Data in the Cloud: Challenges and Solutions
Miguel Correia 0001 |
ICSOFT | 1 |
| 2018 | Koordinator: A Service Approach for Replicating Docker Containers in KubernetesabstractContainer-based virtualization technologies such as Docker and Kubernetes are being adopted by cloud service providers due to their simpler deployment, better performance, and lower memory footprint in relation to hypervisor-based virtualization. Kubernetes supports basic replication for availability, but does not provide strong consistency and may corrupt application state in case there is a fault. This paper presents a state machine replication scheme for Kubernetes that provides high availability and integrity with strong consistency. Replica coordination is provided as a service, with lightweight coupling to applications. Experimental results show the solution feasibility. Hylson Vescovi Netto, Aldelir Fernando Luiz, Miguel Correia 0001, Luciana Rech, Caio Pereira Oliveira |
ISCC | 3 |
| 2018 | RockFS: Cloud-backed File System Resilience to Client-Side AttacksabstractCloud-backed file systems provide on-demand, high-availability, scalable storage. Their security may be improved with techniques such as erasure codes and secret sharing to fragment files and encryption keys in several clouds. Attacking the server-side of such systems involves penetrating one or more clouds, which can be extremely difficult. David R. Matos, Miguel L. Pardal, Georg Carle, Miguel Correia 0001 |
Middleware | 4 |
| 2018 | Leveraging ARM TrustZone and Verifiable Computing to Provide Auditable Mobile FunctionsabstractThe increase of personal data on mobile devices has been followed by legislation that forces service providers to process and maintain users' data under strict data protection policies. In this paper, we propose a new primitive for mobile applications called auditable mobile function (AMF) to help service providers enforcing such policies by enabling them to process sensitive data within users' devices and collecting proofs of function execution integrity. We present SafeChecker, a computation verification system that provides mobile application support for AMFs, and evaluate the practicality of different usage scenario AMFs on TrustZone-enabled hardware. Nuno O. Duarte, Sileshi Demesie Yalew, Nuno Santos 0001, Miguel Correia 0001 |
MobiQuitous | 4 |
| 2018 | Introspection for ARM TrustZone with the ITZ LibraryabstractTrustZone is an extension of the ARM architecture that allows software executed in ARM processors to be split in two environments: the normal world that runs a common operating system (e.g., Android or Linux) and its applications, and the secure world that runs security services or others that need to be isolated from the normal world. This work aims to provide support for analyzing the security status of the normal world from the secure world. For this purpose, we present a Virtual Machine Introspection (VMI) library that leverages the TrustZone architecture. VMI tools and the library run in the secure world and inspect the normal world. We present an experimental evaluation of the library in an i.MX53 development board. Miguel Guerra, Benjamin Taubmann, Hans P. Reiser, Sileshi Demesie Yalew, Miguel Correia 0001 |
QRS | 5 |
| 2018 | Benchmarking Static Analysis Tools for Web SecurityabstractStatic analysis tools are recurrently used by developers to search for vulnerabilities in the source code of web applications. However, distinct tools provide different results depending on factors such as the complexity of the code under analysis and the application scenario; thus, missing some of the vulnerabilities while reporting false problems. Benchmarks can be used to assess and compare different systems or components, however, existing benchmarks have strong representativeness limitations, disregarding the specificities of the environment, where the tools under benchmarking will be used. In this paper, we propose a benchmark for assessing and comparing static analysis tools in terms of their capability to detect security vulnerabilities. The benchmark considers four real-world development scenarios, including workloads composed of real web applications with different goals and constraints, ranging from low budget to high-end applications. Our benchmark was implemented and assessed experimentally using a set of 134 WordPress plugins, which served as the basis for the evaluation of five free PHP static analysis tools. Results clearly show that the best solution depends on the deployment scenario and class of vulnerability being detected; therefore, highlighting the importance of these aspects in the design of the benchmark and of future static analysis tools. Paulo Jorge Costa Nunes, Iberia Medeiros, José Fonseca 0002, Nuno Neves 0001, Miguel Correia 0001, Marco Vieira |
IEEE Trans. Reliab. | 5 |
| 2017 | Chrysaor: Fine-Grained, Fault-Tolerant Cloud-of-Clouds MapReduceabstractMapReduce is a framework for processing large data sets much used in the context of cloud computing. MapReduce implementations like Hadoop can tolerate crashes and file corruptions, but not arbitrary faults. Unfortunately, there is evidence that arbitrary faults do occur and can affect the correctness of MapReduce job executions. Furthermore, many outages of major cloud offerings have been reported, raising concerns about the dependence on a single cloud. In this paper we propose a novel execution system that allows to scale out MapReduce computations to a cloud-of-clouds and tolerate arbitrary faults, malicious faults, and cloud outages. Our system, Chrysaor, is based on a fine-grained replication scheme that tolerates faults at the task level. Our solution has three important properties: it tolerates the above-mentioned classes of faults at reasonable cost, it requires minimal modifications to the users' applications, and it does not involve changes to the Hadoop source code. We performed an extensive evaluation of our system in Amazon EC2, showing that our fine-grained solution is efficient in terms of computation by recovering only faulty tasks. This is achieved without incurring a significant penalty for the baseline case (i.e., without faults) in most workloads. Pedro A. R. S. Costa, Fernando M. V. Ramos, Miguel Correia 0001 |
CCGrid | 3 |
| 2017 | Demonstrating a Tool for Injection Attack Prevention in MySQLabstractDespite the significant efforts put in building more secure web applications, cases of high impact breaches continue to appear. Vulnerabilities in web applications are often created due to inconsistencies in the way SQL queries are believed to be run and the way they are actually executed by a Database Management System (DBMS). This paper presents a demonstration of SEPTIC, a mechanism that detects and blocks injection attacks inside the DBMS. The demonstration considers a scenario of a non-trivial PHP web application, backed by a MySQL DBMS, which was modified to include SEPTIC. It presents how SEPTIC blocks injection attacks without compromising the application correctness and performance. In addition, SEPTIC is compared to alternative approaches, such as sanitizations carried out with standard functions provided language and a web application firewall. Iberia Medeiros, Miguel Beatriz, Nuno Neves 0001, Miguel Correia 0001 |
DSN | 4 |
| 2017 | Rectify: black-box intrusion recovery in PaaS cloudsabstractWeb applications hosted on the cloud are exposed to cyberattacks and can be compromised by HTTP requests that exploit vulnerabilities. Platform as a Service (PaaS) offerings often provide a backup service that allows restoring application state after a serious attack, but all valid state changes since the last backup are lost. We propose Rectify, a new approach to recover from intrusions on applications running in a PaaS. Rectify is a service designed to be deployed alongside the application in a PaaS container. It does not require modifications to the software and the recovery can be performed by a system administrator. Machine learning techniques are used to associate the requests received by the application to the statements issued to the database. Rectify was evaluated using three widely used web applications - Wordpress, LimeSurvey and MediaWiki - and the results show that the effects of malicious requests can be removed whilst preserving the valid application data. David R. Matos, Miguel L. Pardal, Miguel Correia 0001 |
Middleware | 3 |
| 2017 | REPSYS: A Robust and Distributed Reputation System for Delay-Tolerant NetworksabstractDistributed reputation systems can be used to foster cooperation between nodes in decentralized and self-managed systems due to the nonexistence of a central entity. In this paper, a Robust and Distributed Reputation System for Delay-Tolerant Networks (REPSYS) is proposed. REPSYS is robust because despite taking into account first- and second-hand information, it is resilient against false accusations and praise, and distributed, as the decision to interact with another node depends entirely on each node. Simulation results show that the system is capable, while evaluating each node's participation in the network, to detect on the fly nodes that do not accept messages from other nodes and that disseminate false information even while colluding with others, and while evaluating how honest is each node in the reputation system, to classify correctly nodes in most cases. Naércio Magaia, Paulo Rogério Pereira, Miguel Correia 0001 |
MSWiM | 3 |
| 2017 | Hail to the Thief: Protecting data from mobile ransomware with ransomsafedroidabstractThe growing popularity of Android and the increasing amount of sensitive data stored in mobile devices have lead to the dissemination of Android ransomware. Ransomware is a class of malware that makes data inaccessible by blocking access to the device or, more frequently, by encrypting the data; to recover the data, the user has to pay a ransom to the attacker. A solution for this problem is to backup the data. Although backup tools are available for Android, these tools may be compromised or blocked by the ransomware itself. This paper presents the design and implementation of RANSOMSAFEDROID, a TrustZone based backup service for mobile devices. RANSOMSAFEDROID is protected from malware by leveraging the ARM TrustZone extension and running in the secure world. It does backup of files periodically to a secure local persistent partition and pushes these backups to external storage to protect them from ransomware. Initially, RANSOMSAFEDROID does a full backup of the device filesystem, then it does incremental backups that save the changes since the last backup. As a proof-of-concept, we implemented a RANSOMSAFEDROID prototype and provide a performance evaluation using an i.MX53 development board. Sileshi Demesie Yalew, Gerald Q. Maguire Jr., Seif Haridi, Miguel Correia 0001 |
NCA | 4 |
| 2017 | Vulnerability-Tolerant Transport Layer SecurityabstractSSL/TLS communication channels play a very important role in Internet security, including cloud computing and server infrastructures. There are often concerns about the strength of the encryption mechanisms used in TLS channels. Vulnerabilities can lead to some of the cipher suites once thought to be secure to become insecure and no longer recommended for use or in urgent need of a software update. However, the deprecation/update process is very slow and weeks or months can go by before most web servers and clients are protected, and some servers and clients may never be updated. In the meantime, the communications are at risk of being intercepted and tampered by attackers. In this paper we propose an alternative to TLS to mitigate the problem of secure commu- nication channels being susceptible to attacks due to unexpected vulnerabilities in its mechan- isms. Our solution, called Vulnerability-Tolerant Transport Layer Security (vtTLS), is based on diversity and redundancy of cryptographic mechanisms and certificates to ensure a secure communication even when one or more mechanisms are vulnerable. Our solution relies on a combination of k cipher suites which ensure that even if k − 1 cipher suites are insecure or vul- nerable, the remaining cipher suite keeps the communication channel secure. The performance and cost of vtTLS were evaluated and compared with OpenSSL, one of the most widely used implementations of TLS. André Joaquim, Miguel L. Pardal, Miguel Correia 0001 |
OPODIS | 3 |
| 2017 | DroidPosture: A trusted posture assessment service for mobile devicesabstractMobile devices such as smartphones are becoming the majority among computing devices. Currently, millions of persons use such devices to store and process personal data. Unfortunately, smartphones running Android are increasingly being targeted by hackers and infected with malware. Anti-malware software is being used to address this situation, but it may be subverted by the same malware it aims to detect. We present DroidPosture, a posture assessment service for Android devices. This service aims to securely evaluate the level of trust we can have on a device (assess its posture) even if the mobile OS is compromised. For that to be possible, DroidPosture is protected using TrustZone, a security extension for ARM processors. DroidPosture is configurable with a set of application and kernel analysis mechanisms that enable detecting malicious applications and rootkits. We implemented a DroidPosture prototype using a hardware board with an ARM processor with TrustZone, and evaluated its performance and security. Sileshi Demesie Yalew, Gerald Q. Maguire Jr., Seif Haridi, Miguel Correia 0001 |
WiMob | 4 |
| 2017 | TruApp: A TrustZone-based authenticity detection service for mobile appsabstractIn less than a decade, mobile apps became an integral part of our lives. In several situations it is important to provide assurance that a mobile app is authentic, i.e., that it is indeed the app produced by a certain company. However, this is challenging, as such apps can be repackaged, the user malicious, or the app tampered with by an attacker. This paper presents the design of TRUAPP, a software authentication service that provides assurance of the authenticity and integrity of apps running on mobile devices. TRUAPP provides such assurance, even if the operating system is compromised, by leveraging the ARM TrustZone hardware security extension. TRUAPP uses a set of techniques (static watermarking, dynamic watermarking, and cryptographic hashes) to verify the integrity of the apps. The service was implemented in a hardware board that emulates a mobile device, which was used to do a thorough experimental evaluation of the service. Sileshi Demesie Yalew, Pedro Mendonça, Gerald Q. Maguire Jr., Seif Haridi, Miguel Correia 0001 |
WiMob | 5 |
| 2017 | State machine replication in containers managed by Kubernetes
Hylson Vescovi Netto, Lau Cheuk Lung, Miguel Correia 0001, Aldelir Fernando Luiz, Luciana Moreira Sá de Souza |
J. Syst. Archit. | 3 |
| 2016 | Priority-Based State Machine Replication with PRaxosabstractState machine replication is a form of active replication commonly used to create fault-tolerant distributed services. In a nutshell, the approach consists in ensuring that a set of replicas receive and execute the same sequence of deterministic requests, returning the same results. This approach handles all requests evenly, but for some services it is important to consider that some requests have priority over others, i.e., that whenever two or more requests are ready to be executed, the one with higher priority is executed first. Paxos is perhaps the best known protocol to order requests in asynchronous environments, but Paxos has no notion of priority. In this paper we introduce the notion of priority-based state machine replication and modify Paxos to take request priorities into account. The proposed algorithm, PRaxos, works in three steps and satisfies Paxos' safety properties in asynchronous systems, while enforcing priorities when the system behaves synchronously. Paulo R. Pinho Filho, Luciana Rech, Lau Cheuk Lung, Miguel Correia 0001, Lásaro J. Camargos |
AINA | 4 |
| 2016 | Medusa: An Efficient Cloud Fault-Tolerant MapReduceabstractApplications such as web search and social networking have been moving from centralized to decentralized cloud architectures to improve their scalability. MapReduce, a programming framework for processing large amounts of data using thousands of machines in a single cloud, also needs to be scaled out to multiple clouds to adapt to this evolution. The challenge of building a multi-cloud distributed architecture is substantial. Notwithstanding, the ability to deal with the new types of faults introduced by such setting, such as the outage of a whole datacenter or an arbitrary fault caused by a malicious cloud insider, increases the endeavor considerably. In this paper we propose Medusa, a platform that allows MapReduce computations to scale out to multiple clouds and tolerate several types of faults. Our solution fulfills four objectives. First, it is transparent to the user, who writes her typical MapReduce application without modification. Second, it does not require any modification to the widely used Hadoop framework. Third, the proposed system goes well beyond the fault-tolerance offered by MapReduce to tolerate arbitrary faults, cloud outages, and even malicious faults caused by corrupt cloud insiders. Fourth, it achieves this increased level of fault tolerance at reasonable cost. We performed an extensive experimental evaluation in the ExoGENI testbed, demonstrating that our solution significantly reduces execution time when compared to traditional methods that achieve the same level of resilience. Pedro A. R. S. Costa, Xiao Bai 0002, Fernando M. V. Ramos, Miguel Correia 0001 |
CCGrid | 4 |
| 2016 | Hacking the DBMS to Prevent Injection Attacks
Iberia Medeiros, Miguel Beatriz, Nuno Neves 0001, Miguel Correia 0001 |
CODASPY | 4 |
| 2016 | Equipping WAP with WEAPONS to Detect Vulnerabilities: Practical Experience ReportabstractAlthough security starts to be taken into account during software development, the tendency for source code to contain vulnerabilities persists. Open source static analysis tools provide a sensible approach to mitigate this problem. However, these tools are programmed to detect a specific set of vulnerabilities and they are often difficult to extend to detect new ones. WAP is a recent popular open source tool that detects vulnerabilities in the source code of web applications written in PHP. The paper addresses the difficulty of extending these tools by proposing a modular and extensible version of the WAP tool, equipping it with "weapons" to detect (and correct) new vulnerability classes. The new version of the tool was evaluated with seven new vulnerability classes using web applications and plugins of the widely-adopted WordPress content management system. The experimental results show that this extensibility allows WAP to find many new (zero-day) vulnerabilities. Iberia Medeiros, Nuno Neves 0001, Miguel Correia 0001 |
DSN | 3 |
| 2016 | DEKANT: a static analysis tool that learns to detect web application vulnerabilitiesabstractThe state of web security remains troubling as web applications continue to be favorite targets of hackers. Static analysis tools are important mechanisms for programmers to deal with this problem as they search for vulnerabilities automatically in the application source code, allowing programmers to remove them. However, developing these tools requires explicitly coding knowledge about how to discover each kind of vulnerability. This paper presents a new approach in which static analysis tools learn to detect vulnerabilities automatically using machine learning. The approach uses a sequence model to learn to characterize vulnerabilities based on a set of annotated source code slices. This model takes into consideration the order in which the code elements appear and are executed in the slices. The model created can then be used as a static analysis tool to discover and identify vulnerabilities in source code. The approach was implemented in the DEKANT tool and evaluated experimentally with a set of open source PHP applications and WordPress plugins, finding 16 zero-day vulnerabilities. Iberia Medeiros, Nuno Neves 0001, Miguel Correia 0001 |
ISSTA | 3 |
| 2016 | DARSHANA: Detecting route hijacking for communication confidentialityabstractThe Border Gateway Protocol (BGP) plays a critical role in the Internet providing connectivity to hosts across the world. Unfortunately, due to its limited security, attackers can hijack traffic by generating invalid routes. Some detection systems for route hijacking have been presented, but they require non-public information, high resources, or can easily be circumvented by attackers. We propose DARSHANA, a monitoring solution that detects route hijacking based solely on data-plane information, and has enough redundancy to prevent attacker countermeasures such as dropping of traceroute probes. DARSHANA uses active probing techniques that enable detection in near real-time. By using diverse methods, DARSHANA can still detect attacks even if the adversary manages to counter some techniques. We show that our solution allows effective detection of many hijacking attacks by emulating them using PlanetLab and Amazon AWS. Karan Balu, Miguel L. Pardal, Miguel Correia 0001 |
NCA | 3 |
| 2016 | Feature set tuning in statistical learning network intrusion detectionabstractThe detection of security-related events using machine learning approaches has been extensively investigated. In particular, machine learning applied to network intrusion detection systems (NIDS) has attracted a lot of attention due to its good generalization and unknown attack detection capabilities. A number of classification techniques have been used for this purpose, revealing good generalization properties. In this paper we go one step further by evaluating the performance of NIDSs when feature set tuning and reduction are realized. We evaluate a number of state of the art learning algorithms that are raising much interest but have not been used for intrusion detection yet. We compare a representative set of algorithms: Ada, ROC-based learners, two types of Classification Trees, Boosted Logistic Regression, Generalized Linear Models, Gradient Boosting Machines, and Neural Networks. The main objective is to reduce the number of features used - thus also the size of the data processed - to improve speed while maintaining adequate accuracy. Arnaldo Gouveia, Miguel Correia 0001 |
NCA | 2 |
| 2016 | vtTLS: A vulnerability-tolerant communication protocolabstractWe present VTTLS, a vulnerability-tolerant communication protocol. There are often concerns about the strength of some of the encryption mechanisms used in SSL/TLS channels, with some regarded as insecure at some point in time. VTTLS is our solution to mitigate the problem of secure communication channels being vulnerable to attacks due to unexpected vulnerabilities in encryption mechanisms. It is based on diversity and redundancy of cryptographic mechanisms and certificates to provide a secure communication channel even when one or more mechanisms are vulnerable. VTTLS relies on a combination of k cipher suites. Even if k-1 cipher suites are insecure or vulnerable, VTTLS relies on the remaining cipher suites to maintain the channel secure. We evaluated the performance of VTTLS by comparing it to an OpenSSL channel. André Joaquim, Miguel L. Pardal, Miguel Correia 0001 |
NCA | 3 |
| 2016 | NoSQL Undo: Recovering NoSQL databases by undoing operationsabstractNoSQL databases offer high throughput, support for huge data structures, and capacity to scale horizontally at the expense of not supporting relational data, ACID consistency and a standard SQL syntax. Due to their simplicity and flexibility, NoSQL databases are becoming very popular among web application developers. However, most NoSQL databases only provide basic backup and restore mechanisms, which allow recovering databases from a crash, but not to remove undesired operations caused by accidental or malicious actions. To solve this problem we propose NOSQL UNDO, a recovery approach and tool that allows database administrators to remove the effect of undesirable actions by undoing operations, leading the system to a consistent state. NOSQL UNDO leverages the logging and snapshot mechanisms built-in NoSQL databases, and is able to undo operations as long as they are present in the logs. This is, as far as we know, the first recovery service that offers these capabilities for NoSQL databases. The experimental results with MongoDB show that it is possible to undo a single operation in a log with 1,000,000 entries in around one second and to undo 10,000 incorrect operations in less than 200 seconds. David R. Matos, Miguel Correia 0001 |
NCA | 2 |
| 2016 | MACHETE: Multi-path communication for securityabstractCommunication through the Internet raises privacy and confidentiality concerns. Protocols such as HTTPS may be used to protect the communication, but occasionally vulnerabilities that may allow snooping on packet content are discovered. To address this issue, we present MACHETE, an application-layer multi-path communication mechanism that provides additional confidentiality by splitting data streams in different physical paths. MACHETE has to handle two challenges: sending packets over different paths when Internet's routing imposes a single path between pairs of network interfaces; splitting streams of data sent over TCP connections. MACHETE is the first to exploit MultiPath TCP (MPTCP) for security purposes. It leverages overlay networks and multihoming to handle the first challenge and MPTCP to handle the second. MACHETE establishes an overlay network and scatters the data over the available paths, thus reducing the effectiveness of snooping attacks. Mechanisms are provided to select paths based on path diversity. Diogo Raposo, Miguel L. Pardal, Luís E. T. Rodrigues, Miguel Correia 0001 |
NCA | 4 |
| 2016 | Leveraging an homomorphic encryption library to implement a coordination serviceabstractThe paper presents MorphicLib, a new partial homomorphic cryptography library written in Java that can be used to implement a wide-range of applications. The paper shows the use of the library with the HomomorphicSpace coordination service. This service is a tuple space that stores encrypted tuples but still supports operations like returning tuples with values within a certain range. Eugenio A. Silva, Miguel Correia 0001 |
NCA | 2 |
| 2016 | JITeR: Just-in-time application-layer routing
Alysson Neves Bessani, Nuno Neves 0001, Paulo Veríssimo, Wagner Saback Dantas, Alexandre Fonseca, Pedro Luz, Miguel Correia 0001 |
Comput. Networks | 8 |
| 2016 | Detecting and Removing Web Application Vulnerabilities with Static Analysis and Data MiningabstractAlthough a large research effort on web application security has been going on for more than a decade, the security of web applications continues to be a challenging problem. An important part of that problem derives from vulnerable source code, often written in unsafe languages like PHP. Source code static analysis tools are a solution to find vulnerabilities, but they tend to generate false positives, and require considerable effort for programmers to manually fix the code. We explore the use of a combination of methods to discover vulnerabilities in source code with fewer false positives. We combine taint analysis, which finds candidate vulnerabilities, with data mining, to predict the existence of false positives. This approach brings together two approaches that are apparently orthogonal: humans coding the knowledge about vulnerabilities (for taint analysis), joined with the seemingly orthogonal approach of automatically obtaining that knowledge (with machine learning, for data mining). Given this enhanced form of detection, we propose doing automatic code correction by inserting fixes in the source code. Our approach was implemented in the WAP tool, and an experimental evaluation was performed with a large set of PHP applications. Our tool found 388 vulnerabilities in 1.4 million lines of code. Its accuracy and precision were approximately 5% better than PhpMinerII's and 45% better than Pixy's. Iberia Medeiros, Nuno Neves 0001, Miguel Correia 0001 |
IEEE Trans. Reliab. | 3 |
| 2015 | Shuttle: Intrusion Recovery for PaaSabstractThe number of applications being deployed using the Platform as a Service (PaaS) cloud computing model is increasing. Despite the security controls implemented by cloud service providers, we expect intrusions to strike such applications. We present Shuttle, a novel intrusion recovery service. Shuttle recovers from intrusions in applications deployed in PaaS platforms. Our approach allows undoing changes to the state of PaaS applications due to intrusions, without loosing the effect of legitimate operations performed after the intrusions take place. We combine a record-and-replay approach with the elasticity provided by cloud offerings to recover applications deployed on various instances and backed by distributed databases. The service loads a database snapshot taken before the intrusion and replays subsequent requests, as much in parallel as possible, while continuing to execute incoming requests. We present an experimental evaluation of Shuttle on Amazon Web Services. We show Shuttle can replay 1 million requests in 10 minutes and that it can duplicate the number of requests replayed per second by increasing the number of application servers from 1 to 3. Dario Nascimento, Miguel Correia 0001 |
ICDCS | 2 |
| 2015 | Betweenness centrality in Delay Tolerant Networks: A survey
Naércio Magaia, Alexandre P. Francisco, Paulo Rogério Pereira, Miguel Correia 0001 |
Ad Hoc Networks | 4 |
| 2014 | SCFS: A Shared Cloud-backed File System
Alysson Neves Bessani, Ricardo Mendes, Tiago Oliveira 0008, Nuno Neves 0001, Miguel Correia 0001, Marcelo Pasin, Paulo Veríssimo |
USENIX ATC | 5 |
| 2014 | Automatic detection and correction of web application vulnerabilities using data mining to predict false positivesabstractWeb application security is an important problem in today's internet. A major cause of this status is that many programmers do not have adequate knowledge about secure coding, so they leave applications with vulnerabilities. An approach to solve this problem is to use source code static analysis to find these bugs, but these tools are known to report many false positives that make hard the task of correcting the application. This paper explores the use of a hybrid of methods to detect vulnerabilities with less false positives. After an initial step that uses taint analysis to flag candidate vulnerabilities, our approach uses data mining to predict the existence of false positives. This approach reaches a trade-off between two apparently opposite approaches: humans coding the knowledge about vulnerabilities (for taint analysis) versus automatically obtaining that knowledge (with machine learning, for data mining). Given this more precise form of detection, we do automatic code correction by inserting fixes in the source code. The approach was implemented in the WAP tool and an experimental evaluation was performed with a large set of open source PHP applications. Iberia Medeiros, Nuno Neves 0001, Miguel Correia 0001 |
WWW | 3 |
| 2013 | Securing energy metering software with automatic source code correctionabstractIndustry is using power meters to monitor the consumption of energy and achieving cost savings. This monitoring often involves energy metering software with a web interface. However, web applications often have vulnerabilities that can be exploited by cyber-attacks. We present an approach and a tool to solve this problem by analyzing the application source code and automatically inserting fixes to remove the discovered vulnerabilities. We demonstrate the use of the tool with two open source energy metering applications in which it found and corrected 17 vulnerabilities. By looking in more detail into some of these vulnerabilities, we argue that they are very serious, leading to the following impacts: violation of user privacy, counter the benefits of energy metering, and serve as entering points for attacks on other user software. Iberia Medeiros, Nuno Neves 0001, Miguel Correia 0001 |
INDIN | 3 |
| 2013 | Byzantine fault-tolerant state machine replication with twin virtual machinesabstractThe reliability and availability of distributed services can be ensured using replication. We present an architecture and an algorithm for Byzantine fault-tolerant state machine replication. We explore the benefits of virtualization to reliably detect and tolerate faulty replicas, allowing the transformation of Byzantine faults into omission faults. Our approach reduces the total number of physical replicas from 3f+1 to 2f+1. It is based on the concept of twin virtual machines, which involves having two virtual machines in each physical host, each one acting as failure detector of the other. Fernando Dettoni, Lau Cheuk Lung, Miguel Correia 0001, Aldelir Fernando Luiz |
ISCC | 3 |
| 2013 | On the Efficiency of Durable State Machine Replication
Alysson Neves Bessani, Marcel Santos, João Felix, Nuno Neves 0001, Miguel Correia 0001 |
USENIX ATC | 5 |
| 2013 | BFT-TO: Intrusion Tolerance with Less ReplicasabstractState machine replication (SMR) is a generic technique for implementing fault-tolerant distributed services by replicating them in sets of servers. There have been several proposals for using SMR to tolerate arbitrary or Byzantine faults, including intrusions. However, most of these systems can tolerate at most f faulty servers out of a total of 3f+1. We show that it is possible to implement a Byzantine SMR algorithm with only 2f+1 replicas by extending the system with a simple trusted distributed component. Several performance metrics show that our algorithm, BFT-TO, fares well in comparison with others in the literature. Furthermore, BFT-TO is not vulnerable to some recently presented performance attacks that affect alternative approaches. Miguel Correia 0001, Nuno Neves 0001, Paulo Veríssimo |
Comput. J. | 1 |
| 2013 | Efficient Byzantine Fault-ToleranceabstractWe present two asynchronous Byzantine fault-tolerant state machine replication (BFT) algorithms, which improve previous algorithms in terms of several metrics. First, they require only 2f+1 replicas, instead of the usual 3f+1. Second, the trusted service in which this reduction of replicas is based is quite simple, making a verified implementation straightforward (and even feasible using commercial trusted hardware). Third, in nice executions the two algorithms run in the minimum number of communication steps for nonspeculative and speculative algorithms, respectively, four and three steps. Besides the obvious benefits in terms of cost, resilience and management complexity-fewer replicas to tolerate a certain number of faults-our algorithms are simpler than previous ones, being closer to crash fault-tolerant replication algorithms. The performance evaluation shows that, even with the trusted component access overhead, they can have better throughput than Castro and Liskov's PBFT, and better latency in networks with nonnegligible communication delays. Giuliana Santos Veronese, Miguel Correia 0001, Alysson Neves Bessani, Lau Cheuk Lung, Paulo Veríssimo |
IEEE Trans. Computers | 2 |
| 2013 | On the Performance of Byzantine Fault-Tolerant MapReduceabstractMapReduce is often used for critical data processing, e.g., in the context of scientific or financial simulation. However, there is evidence in the literature that there are arbitrary (or Byzantine) faults that may corrupt the results of MapReduce without being detected. We present a Byzantine fault-tolerant MapReduce framework that can run in two modes: nonspeculative and speculative. We thoroughly evaluate experimentally the performance of these two versions of the framework, showing that they use around twice more resources than Hadoop MapReduce, instead of the three times more of alternative solutions. We believe this cost is acceptable for many critical applications. Pedro A. R. S. Costa, Marcelo Pasin, Alysson Neves Bessani, Miguel Correia 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2013 | Byzantine Fault-Tolerant Consensus in Wireless Ad Hoc NetworksabstractWireless ad hoc networks, due to their inherent unreliability, pose significant challenges to the task of achieving tight coordination among nodes. The failure of some nodes and momentary breakdown of communications, either of accidental or malicious nature, should not result in the failure of the entire system. This paper presents an asynchronous Byzantine consensus protocol-called Turquois-specifically designed for resource-constrained wireless ad hoc networks. The key to its efficiency is the fact that it tolerates dynamic message omissions, which allows an efficient utilization of the wireless broadcasting medium. The protocol also refrains from computationally expensive public-key cryptographic during its normal operation. The protocol is safe despite the arbitrary failure of f <; n/3 nodes from a total of n nodes, and unrestricted message omissions. Progress is ensured in rounds where the number of omissions is σ ≤ [n-t/2] (n - k - t) + k - 2, where k is the number of nodes required to terminate and t ≤ f is the number of nodes that are actually faulty. These characteristics make Turquois the first consensus protocol that simultaneously circumvents the FLP and the Santoro-Widmayer impossibility results, which is achieved through randomization. Finally, the protocol was prototyped and subject to a comparative performance evaluation against two well-known Byzantine fault-tolerant consensus protocols. The results show that, due to its design, Turquois outperforms the other protocols by more than an order of magnitude as the number of nodes in the system increases. Henrique Moniz, Nuno Neves 0001, Miguel Correia 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2013 | DepSky: Dependable and Secure Storage in a Cloud-of-CloudsabstractThe increasing popularity of cloud storage services has lead companies that handle critical data to think about using these services for their storage needs. Medical record databases, large biomedical datasets, historical information about power systems and financial data are some examples of critical data that could be moved to the cloud. However, the reliability and security of data stored in the cloud still remain major concerns. In this work we present DepSky, a system that improves the availability, integrity, and confidentiality of information stored in the cloud through the encryption, encoding, and replication of the data on diverse clouds that form a cloud-of-clouds. We deployed our system using four commercial clouds and used PlanetLab to run clients accessing the service from different countries. We observed that our protocols improved the perceived availability, and in most cases, the access latency, when compared with cloud providers individually. Moreover, the monetary costs of using DepSky in this scenario is at most twice the cost of using a single cloud, which is optimal and seems to be a reasonable cost, given the benefits. Alysson Neves Bessani, Miguel Correia 0001, Bruno Quaresma, Fernando André, Paulo Sousa 0001 |
ACM Trans. Storage | 2 |
| 2012 | On the Feasibility of Byzantine Fault-Tolerant MapReduce in Clouds-of-CloudsabstractMapReduce is a framework for processing large data sets largely used in cloud computing. MapReduce implementations like Hadoop can tolerate crashes and file corruptions, but there is evidence that general arbitrary faults do occur and can affect the correctness of job executions. Furthermore, many individual cloud outages have been reported, raising concerns about depending on a single cloud. We present a MapReduce runtime that tolerates arbitrary faults and runs in a set of clouds at a reasonable cost in terms of computation and execution time. The main challenge is to avoid sending through the internet the huge amount of data that would normally be exchanged between map and reduce tasks. Miguel Correia 0001, Pedro A. R. S. Costa, Marcelo Pasin, Alysson Neves Bessani, Fernando M. V. Ramos, Paulo Veríssimo |
SRDS | 1 |
| 2012 | Practical Hardening of Crash-Tolerant Systems
Miguel Correia 0001, Daniel Gómez Ferro, Flavio Paiva Junqueira, Marco Serafini |
USENIX ATC | 1 |
| 2011 | Byzantine Fault-Tolerant MapReduce: Faults are Not Just CrashesabstractMapReduce is often used to run critical jobs such as scientific data analysis. However, evidence in the literature shows that arbitrary faults do occur and can probably corrupt the results of MapReduce jobs. MapReduce runtimes like Hadoop tolerate crash faults, but not arbitrary or Byzantine faults. We present a MapReduce algorithm and prototype that tolerate these faults. An experimental evaluation shows that the execution of a job with our algorithms uses twice the resources of the original Hadoop, instead of the 3 or 4 times more that would be achieved with the direct application of common Byzantine fault-tolerance paradigms. We believe this cost is acceptable for critical applications that require that level of fault tolerance. Pedro A. R. S. Costa, Marcelo Pasin, Alysson Neves Bessani, Miguel Correia 0001 |
CloudCom | 4 |
| 2011 | DepSky: dependable and secure storage in a cloud-of-cloudsabstractThe increasing popularity of cloud storage services has lead companies that handle critical data to think about using these services for their storage needs. Medical record databases, power system historical information and financial data are some examples of critical data that could be moved to the cloud. However, the reliability and security of data stored in the cloud still remain major concerns. In this paper we present DEPSKY, a system that improves the availability, integrity and confidentiality of information stored in the cloud through the encryption, encoding and replication of the data on diverse clouds that form a cloud-of-clouds. We deployed our system using four commercial clouds and used PlanetLab to run clients accessing the service from different countries. We observed that our protocols improved the perceived availability and, in most cases, the access latency when compared with cloud providers individually. Moreover, the monetary costs of using DEPSKY on this scenario is twice the cost of using a single cloud, which is optimal and seems to be a reasonable cost, given the benefits. Alysson Neves Bessani, Miguel Correia 0001, Bruno Quaresma, Fernando André, Paulo Sousa 0001 |
EuroSys | 2 |
| 2011 | Byzantine Fault-Tolerant Transaction Processing for Replicated DatabasesabstractTransaction commit is a problem much investigated, both in the databases and systems communities, from the theoretical and practical sides. We present a modular approach to solve this problem in the context of database replication on environments that are subject to Byzantine faults. Our protocol builds on a total order multicast abstraction and is proven to satisfy a set of safety and liveness properties. On the contrary of previous solutions in the literature, it assures strong consistency for transactions, tolerates Byzantine clients and does not need centralized control or multi-version databases. We present an evaluation of a prototype of the system. Aldelir Fernando Luiz, Lau Cheuk Lung, Miguel Correia 0001 |
NCA | 3 |
| 2011 | N-party BAR Transfer
Xavier Vilaça, João Leitão 0001, Miguel Correia 0001, Luís E. T. Rodrigues |
OPODIS | 3 |
| 2011 | Randomization can be a healer: consensus with dynamic omission failures
Henrique Moniz, Nuno Neves 0001, Miguel Correia 0001, Paulo Veríssimo |
Distributed Comput. | 3 |
| 2011 | RITAS: Services for Randomized Intrusion ToleranceabstractRandomized agreement protocols have been around for more than two decades. Often assumed to be inefficient due to their high expected communication and computation complexities, they have remained overlooked by the community-at-large as a valid solution for the deployment of fault-tolerant distributed systems. This paper aims to demonstrate that randomization can be a very competitive approach even in hostile environments where arbitrary faults can occur. A stack of randomized intrusion-tolerant protocols is described and its performance evaluated under several settings in both local-area-network (LAN) and wide-area-network environments. The stack provides a set of relevant services ranging from basic communication primitives up to atomic broadcast. The experimental evaluation shows that the protocols are efficient, especially in LAN environments where no performance reduction is observed under certain Byzantine faults. Henrique Moniz, Nuno Neves 0001, Miguel Correia 0001, Paulo Veríssimo |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2010 | Intrusion Tolerant Services Through Virtualization: A Shared Memory ApproachabstractMuch research aiming to design practical algorithms to support Byzantine Fault-Tolerant distributed applications has been made in recent years. These solutions are designed to make the applications resistant to successful attacks against the system, thereby making services tolerant to intrusions. Recently, some of these studies have considered the use of virtual machines for building a trusted computing environment. This paper presents SMIT (Shared Memory based Intrusion Tolerance), an architecture for Intrusion Tolerance using virtual machines that benefits from a shared memory to simplify the consensus protocol. Valdir Stumm Jr., Lau Cheuk Lung, Miguel Correia 0001, Joni da Silva Fraga, Jim Lau |
AINA | 3 |
| 2010 | 4th workshop on recent advances in intrusion-tolerant systems WRAITS 2010abstractDesign and operational vulnerabilities are accepted as inevitable in today's complex computer systems. The distributed and networked nature of the systems that are currently in use and being developed facilitate discovery and exploitation of these flaws in increasingly new and easier ways. Intrusion Tolerance acknowledges that it is impossible to completely prevent attacks and intrusions, and that it is often impossible to accurately detect the act of intrusion and stop it early enough. Intrusion Tolerance research therefore aims to develop technologies that enable computer systems to continue to operate correctly despite attacks, and deny the attacker/intruder the success they seek. For instance, an intrusion-tolerant system may suffer partial loss of service or resources due to the attack, but it will continue to provide critical services in a degraded mode or trigger automatic mechanisms to regain and recover the compromised services and resources. Similar goals are being pursued in Survivability, Byzantine Fault Tolerance, Self-regenerative and Autonomic Systems. Miguel Correia 0001, Partha P. Pal |
DSN | 1 |
| 2010 | Turquois: Byzantine consensus in wireless ad hoc networksabstractThe operation of wireless ad hoc networks is intrinsically tied to the ability of nodes to coordinate their actions in a dependable and efficient manner. The failure of some nodes and momentary breakdown of communications, either of accidental or malicious nature, should not result in the failure of the entire system. This paper presents Turquois - an intrusion-tolerant consensus protocol specifically designed for resource-constrained wireless ad hoc networks. Turquois allows an efficient utilization of the broadcasting medium, avoids synchrony assumptions, and refrains from public-key cryptography during its normal operation. The protocol is safe despite the arbitrary failure of f <; n/3 processes from a total of n processes, and unrestricted message omissions. The protocol was prototyped and subject to a comparative performance evaluation against two well-known intrusion-tolerant consensus protocols. The results show that, as the system scales, Turquois outperforms the other protocols by more than an order of magnitude. Henrique Moniz, Nuno Neves 0001, Miguel Correia 0001 |
DSN | 3 |
| 2010 | Highly Available Intrusion-Tolerant Services with Proactive-Reactive RecoveryabstractIn the past, some research has been done on how to use proactive recovery to build intrusion-tolerant replicated systems that are resilient to any number of faults, as long as recoveries are faster than an upper bound on fault production assumed at system deployment time. In this paper, we propose a complementary approach that enhances proactive recovery with additional reactive mechanisms giving correct replicas the capability of recovering other replicas that are detected or suspected of being compromised. One key feature of our proactive-reactive recovery approach is that, despite recoveries, it guarantees the availability of a minimum number of system replicas necessary to sustain correct operation of the system. We design a proactive-reactive recovery service based on a hybrid distributed system model and show, as a case study, how this service can effectively be used to increase the resilience of an intrusion-tolerant firewall adequate for the protection of critical infrastructures. Paulo Sousa 0001, Alysson Neves Bessani, Miguel Correia 0001, Nuno Neves 0001, Paulo Veríssimo |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2010 | Vulnerability Discovery with Attack InjectionabstractThe increasing reliance put on networked computer systems demands higher levels of dependability. This is even more relevant as new threats and forms of attack are constantly being revealed, compromising the security of systems. This paper addresses this problem by presenting an attack injection methodology for the automatic discovery of vulnerabilities in software components. The proposed methodology, implemented in AJECT, follows an approach similar to hackers and security analysts to discover vulnerabilities in network-connected servers. AJECT uses a specification of the server's communication protocol and predefined test case generation algorithms to automatically create a large number of attacks. Then, while it injects these attacks through the network, it monitors the execution of the server in the target system and the responses returned to the clients. The observation of an unexpected behavior suggests the presence of a vulnerability that was triggered by some particular attack (or group of attacks). This attack can then be used to reproduce the anomaly and to assist the removal of the error. To assess the usefulness of this approach, several attack injection campaigns were performed with 16 publicly available POP and IMAP servers. The results show that AJECT could effectively be used to locate vulnerabilities, even on well-known servers tested throughout the years. João Antunes, Nuno Neves 0001, Miguel Correia 0001, Paulo Veríssimo, Rui Ferreira Neves |
IEEE Trans. Software Eng. | 3 |
| 2009 | 3rd Workshop on Recent Advances on Intrusion-Tolerant Systems WRAITS 2009abstractThe 3rd Workshop on Recent Advances in Intrusion- Tolerant Systems, held in conjunction with DSN 2009, aims to provide the researchers and practitioners an intimate venue to discuss and collaborate on ground-breaking new ideas and fresh results. Saurabh Bagchi, Miguel Correia 0001, Partha P. Pal |
DSN | 2 |
| 2009 | Intrusion-tolerant self-healing devices for critical infrastructure protectionabstractCritical infrastructures like the power grid are essentially physical processes controlled by electronic devices. In the last decades, these electronic devices started to be controlled remotely through commodity computers, often directly or indirectly connected to the Internet. Therefore, many of these systems are currently exposed to threats similar to those endured by normal computer-based networks on the Internet, but the impact of failure of the former can be much higher to society. This paper presents a demonstration of a family of protection devices for critical information infrastructures developed in the context of the EU Crutial project. These devices, called Crutial information switches (CIS), enforce sophisticated access control policies of incoming/outgoing traffic, and are themselves designed with a range of different levels of intrusion tolerance and self healing, to serve different resilience requirements. Paulo Sousa 0001, Alysson Neves Bessani, Wagner Saback Dantas, Fabio Souto, Miguel Correia 0001, Nuno Neves 0001 |
DSN | 5 |
| 2009 | Spin One's Wheels? Byzantine Fault Tolerance with a Spinning PrimaryabstractMost Byzantine fault-tolerant state machine replication (BFT) algorithms have a primary replica that is in charge of ordering the clients requests. Recently it was shown that this dependence allows a faulty primary to degrade the performance of the system to a small fraction of what the environment allows. In this paper we present Spinning, a novel BFT algorithm that mitigates such performance attacks by changing the primary after every batch of pending requests is accepted for execution. This novel mode of operation deals with those attacks at a much lower cost than previous solutions, maintaining a throughput equal or better to the algorithm that is usually consider to be the baseline in the area, Castro and Liskov's PBFT. Giuliana Santos Veronese, Miguel Correia 0001, Alysson Neves Bessani, Lau Cheuk Lung |
SRDS | 2 |
| 2009 | Randomization Can Be a Healer: Consensus with Dynamic Omission Failures
Henrique Moniz, Nuno Neves 0001, Miguel Correia 0001, Paulo Veríssimo |
DISC | 3 |
| 2009 | An Efficient Byzantine-Resilient Tuple SpaceabstractOpen distributed systems are typically composed by an unknown number of processes running in heterogeneous hosts. Their communication often requires tolerance to temporary disconnections and security against malicious actions. Tuple spaces are a well-known coordination model for this kind of systems. They can support communication that is decoupled both in time and space. There are currently several implementations of distributed fault-tolerant tuple spaces but they are not Byzantine-resilient, i.e., they do not provide a correct service if some replicas are attacked and start to misbehave. This paper presents an efficient implementation of a linearizable Byzantine fault-tolerant Tuple Space (LBTS) that uses a novel Byzantine quorum systems replication technique in which most operations are implemented by quorum protocols while stronger operations are implemented by more expensive protocols based on consensus. LBTS is linearizable and wait-free, showing interesting performance gains when compared to a similar construction based on state machine replication. Alysson Neves Bessani, Miguel Correia 0001, Joni da Silva Fraga, Lau Cheuk Lung |
IEEE Trans. Computers | 2 |
| 2009 | Sharing Memory between Byzantine Processes Using Policy-Enforced Tuple SpacesabstractDespite the large amount of Byzantine fault-tolerant algorithms for message-passing systems designed through the years, only recently algorithms for the coordination of processes subject to Byzantine failures using shared memory have appeared. This paper presents a new computing model in which shared memory objects are protected by fine-grained access policies, and a new shared memory object, the Policy-Enforced Augmented Tuple Space (PEATS). We show the benefits of this model by providing simple and efficient consensus algorithms. These algorithms are much simpler and requires less shared memory operations, using also less memory bits than previous algorithms based on ACLs and sticky bits. We also prove that PEATS objects are universal, i.e., that they can be used to implement any other shared memory object, and present lock-free and wait-free universal constructions. Alysson Neves Bessani, Miguel Correia 0001, Joni da Silva Fraga, Lau Cheuk Lung |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2008 | DepSpace: a byzantine fault-tolerant coordination serviceabstractThe tuple space coordination model is one of the most interesting coordination models for open distributed systems due to its space and time decoupling and its synchronization power. Several works have tried to improve the dependability of tuple spaces through the use of replication for fault tolerance and access control for security. However, many practical applications in the Internet require both fault tolerance and security. This paper describes the design and implementation of DepSpace, a Byzantine fault-tolerant coordination service that provides a tuple space abstraction. The service offered by DepSpace is secure, reliable and available as long as less than a third of service replicas are faulty. Moreover, the content-addressable confidentiality scheme developed for DepSpace bridges the gap between Byzantine fault-tolerant replication and confidentiality of replicated data and can be used in other systems that store critical data. Alysson Neves Bessani, Eduardo Alchieri, Miguel Correia 0001, Joni da Silva Fraga |
EuroSys | 3 |
| 2008 | Finite Memory: A Vulnerability of Intrusion-Tolerant SystemsabstractIn environments like the Internet, faults follow unusual patterns, dictated by the combination of malicious attacks with accidental faults such as long communication delays caused by temporary network partitions. In this scenario, attackers can force buffer overflows in order to leave the system in an inconsistent state or to prevent it from doing progress, causing a denial of service. This paper is about the effects that finite memory has on intrusion-tolerant protocols and systems. We present the problem and propose a generic mitigation technique based on repair nodes that reduces the buffer space requirements. An experimental evaluation of the buffer usage with and without this technique is presented, allowing to assess in practice the effects of finite memory in a real, albeit simple, intrusion-tolerant system. Giuliana Santos Veronese, Miguel Correia 0001, Lau Cheuk Lung, Paulo Veríssimo |
NCA | 2 |
| 2008 | On Byzantine generals with alternative plans
Miguel Correia 0001, Alysson Neves Bessani, Paulo Veríssimo |
J. Parallel Distributed Comput. | 1 |
| 2007 | Exploiting Tuple Spaces to Provide Fault-Tolerant Scheduling on Computational GridsabstractScheduling tasks on large-scale computational grids is difficult due to the heterogeneous computational capabilities of the resources, node unavailability and unreliable network connectivity. This work proposes GRIDTS, a grid infrastructure in which the resources select the tasks they execute, instead of a scheduler finding resources for the tasks. This solution allows scheduling decisions to be made with up-to-date information about the resources. Moreover, GRIDTS provides fault-tolerant scheduling by combining a set of fault tolerance techniques to tolerate crash faults in components of the system. The core of the solution is a tuple space, which supports the communication, but also provides support for the fault tolerance mechanisms Fábio Favarim, Joni da Silva Fraga, Lau Cheuk Lung, Miguel Correia 0001, João Felipe Santos |
ISORC | 4 |
| 2007 | Decoupled Quorum-Based Byzantine-Resilient Coordination in Open Distributed SystemsabstractOpen distributed systems are typically composed by an unknown number of processes running in heterogeneous hosts. Their communication often requires tolerance to temporary disconnections and security against malicious actions. Tuple spaces are a well-known coordination model for this sort of systems. They can support communication that is decoupled both in time and space. There are currently several implementations of distributed fault-tolerant tuple spaces but they are not Byzantine-resilient, i.e., they do not provide a correct service if some replicas are attacked and start to misbehave. This paper presents an efficient implementation of LBTS, a linearizable Byzantine fault-tolerant tuple space. LBTS uses a novel Byzantine quorum systems replication technique in which most operations are implemented by quorum protocols while stronger operations are implemented by more expensive protocols based on consensus. LBTS is linearizable and wait-free, showing interesting performance gains when compared to a similar construction based on state machine replication. Alysson Neves Bessani, Miguel Correia 0001, Joni da Silva Fraga, Lau Cheuk Lung |
NCA | 2 |
| 2007 | GRIDTS: A New Approach for Fault-Tolerant Scheduling in Grid ComputingabstractThis paper proposes GRIDTS, a grid infrastructure in which the resources select the tasks they execute, on the contrary to traditional infrastructures where schedulers find resources for the tasks. This solution allows scheduling decisions to be made with up-to-date information about the resources, which is difficult in the traditional infrastructures. Moreover, GRIDTS provides fault-tolerant scheduling by combining a set of fault tolerance techniques to cope with crash faults in components of the system. The solution is mainly based a tuple space, which supports the scheduling and also provides support for the fault tolerance mechanisms. Fábio Favarim, Joni da Silva Fraga, Lau Cheuk Lung, Miguel Correia 0001 |
NCA | 4 |
| 2007 | Intrusion Tolerance in Wireless Environments: An Experimental EvaluationabstractThis paper presents a study on the performance of intrusion-tolerant protocols in wireless LANs. The protocols are evaluated in several different environmental settings, and also within the context of a car platooning application for distributed cruise control. The experimental evaluation reveals how performance is affected by the various environmental parameters such as the wireless standard, group size, and network topology. The distributed cruise control application demonstrates the practicability of such protocols, even when subjected to malicious faults. Henrique Moniz, Nuno Neves 0001, Miguel Correia 0001, António Casimiro, Paulo Veríssimo |
PRDC | 3 |
| 2007 | Resilient Intrusion Tolerance through Proactive and Reactive RecoveryabstractPrevious works have studied how to use proactive recovery to build intrusion-tolerant replicated systems that are resilient to any number of faults, as long as recoveries are faster than an upper-bound on fault production assumed at system deployment time. In this paper, we propose a complementary approach that combines proactive recovery with services that allow correct replicas to react and recover replicas that they detect or suspect to be compromised. One key feature of our proactive-reactive recovery approach is that, despite recoveries, it guarantees the availability of the minimum amount of system replicas necessary to sustain system's correct operation. We design a proactive-reactive recovery service based on a hybrid distributed system model and show, as a case study, how this service can effectively be used to augment the resilience of an intrusion-tolerant firewall adequate for the protection of critical infrastructures. Paulo Sousa 0001, Alysson Neves Bessani, Miguel Correia 0001, Nuno Neves 0001, Paulo Veríssimo |
PRDC | 3 |
| 2007 | On the Effects of Finite Memory on Intrusion-Tolerant SystemsabstractIntrusion tolerance has been proposed as a new paradigm for computer systems security. The idea is to apply the fault tolerance paradigm in the domain of systems security accepting that malicious faults (attacks, intrusions) can never be entirely prevented, and that highly resilient systems have to tolerate these faults. Research in this area has produced a set of clever intrusion-tolerant protocols and systems (I/T protocols and I/T systems for short). However, we believe that an issue has been overlooked: that servers have, finite memory, so the number of messages that can be stored in their buffers is limited. Intuitively, this can be a problem in systems in which there are many messages being exchanged. Moreover, all of these systems assume that the environment is essentially asynchronous, i.e., that there are no bounds on communication and processing delays. Assuming this kind of model is very important in order to prevent the success of attacks against time. Giuliana Santos Veronese, Miguel Correia 0001, Lau Cheuk Lung, Paulo Veríssimo |
PRDC | 2 |
| 2007 | Evaluating Byzantine Quorum SystemsabstractReplication is a mechanism extensively used to guarantee the availability and good performance of data storage services. Byzantine Quorum Systems (BQS) have been proposed as a solution to guarantee the consistency of that kind of services, even if some of the replicas fail arbitrarily. Many BQS have been proposed recently, but comparing their performance is not simple. In fact, it has been shown that theoretical metrics like the number of steps or communication rounds say as much about the practical performance of distributed algorithms as they hide. This paper presents a comparative evaluation of several BQS algorithms in the literature. The evaluation is based both on experiments and simulations. For that purpose, a framework for evaluating BQS called BQSNeko was developed. The results of the evaluation allow a better understanding of the algorithms and the tradeoffs involved. Wagner Saback Dantas, Alysson Neves Bessani, Joni da Silva Fraga, Miguel Correia 0001 |
SRDS | 4 |
| 2007 | When 3f+1 Is Not Enough: Tradeoffs for Decentralized Asynchronous Byzantine Consensus
Alysson Neves Bessani, Miguel Correia 0001, Henrique Moniz, Nuno Neves 0001, Paulo Veríssimo |
DISC | 2 |
| 2007 | Specification-based Intrusion Detection System for Carrier Ethernet
Pan Jieke, João Redol, Miguel Correia 0001 |
WEBIST (1) | 3 |
| 2007 | Worm-IT - A wormhole-based intrusion-tolerant group communication system
Miguel Correia 0001, Nuno Neves 0001, Lau Cheuk Lung, Paulo Veríssimo |
J. Syst. Softw. | 1 |
| 2007 | Automated Rule-Based Diagnosis through a Distributed Monitor SystemabstractIn today's world where distributed systems form many of our critical infrastructures, dependability outagesare becoming increasingly common. In many situations, it is necessary to not just detect a failure, but alsoto diagnose the failure, i.e., to identify the source of the failure. Diagnosis is challenging since highthroughput applications with frequent interactions between the different components allow fast errorpropagation. It is desirable to consider applications as black-boxes for the diagnostic process. In thispaper, we propose a Monitor architecture for diagnosing failures in large-scale network protocols. TheMonitor only observes the message exchanges between the protocol entities (PEs) remotely and doesnot access internal protocol state. At runtime, it builds a causal graph between the PEs based on theircommunication and uses this together with a rule base of allowed state transition paths to diagnose thefailure. The tests used for the diagnosis are based on the rule base and are assumed to have imperfectcoverage. The hierarchical Monitor framework allows distributed diagnosis handling failures at individualMonitors. The framework is implemented and applied to a reliable multicast protocol executing on ourcampus-wide network. Fault injection experiments are carried out to evaluate the accuracy and latency ofthe diagnosis. Gunjan Khanna, Mike Yu Cheng, Padma Varadharajan, Saurabh Bagchi, Miguel Correia 0001, Paulo Veríssimo |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2006 | CRUTIAL: The Blueprint of a Reference Critical Information Infrastructure Architecture
Paulo Veríssimo, Nuno Neves 0001, Miguel Correia 0001 |
CRITIS | 3 |
| 2006 | Randomized Intrusion-Tolerant Asynchronous ServicesabstractRandomized agreement protocols, often assumed to be inefficient due to their high expected communication and time complexities, they have remained largely overlooked by the community-at-large as a valid solution for the deployment of fault-tolerant distributed systems. This paper aims to demonstrate that randomization can be a very competitive approach even in hostile environments where arbitrary faults can occur. A stack of randomized intrusion-tolerant protocols is described and its performance evaluated under different faultloads. The stack provides a set of relevant services ranging from basic communication primitives up to atomic broadcast. The experimental evaluation shows that the protocols are efficient and no performance reduction is observed under certain Byzantine faults Henrique Moniz, Nuno Neves 0001, Miguel Correia 0001, Paulo Veríssimo |
DSN | 3 |
| 2006 | Using Attack Injection to Discover New VulnerabilitiesabstractDue to our increasing reliance on computer systems, security incidents and their causes are important problems that need to be addressed. To contribute to this objective, the paper describes a new tool for the discovery of security vulnerabilities on network connected servers. The AJECT tool uses a specification of the server's communication protocol to automatically generate a large number of attacks accordingly to some predefined test classes. Then, while it performs these attacks through the network, it monitors the behavior of the server both from a client perspective and inside the target machine. The observation of an incorrect behavior indicates a successful attack and the potential existence of a vulnerability. To demonstrate the usefulness of this approach, a considerable number of experiments were carried out with several IMAP servers. The results show that AJECT can discover several kinds of vulnerabilities, including a previously unknown vulnerability Nuno Neves 0001, João Antunes, Miguel Correia 0001, Paulo Veríssimo, Rui Ferreira Neves |
DSN | 3 |
| 2006 | Sharing Memory between Byzantine Processes using Policy-Enforced Tuple SpacesabstractDespite the large amount of Byzantine fault-tolerant algorithms for message-passing systems designed through the years, only recently algorithms for the coordination of processes subject to Byzantine failures using shared memory have appeared. This paper presents a new computing model in which shared memory objects are protected by fine-grained access policies, and a new shared memory object, the policy-enforced augmented tuple space (PEATS). We show the benefits of this model by providing simple and efficient consensus algorithms. These algorithms are much simpler and use less memory bits than previous algorithms based on ACLs and sticky bits. We also prove that PEATSs are universal (they can be used to implement any shared memory object), and present a universal construction. Alysson Neves Bessani, Joni da Silva Fraga, Miguel Correia 0001, Lau Cheuk Lung |
ICDCS | 3 |
| 2006 | An Infrastructure for Adaptive Fault Tolerance on FT-CORBAabstractThe fault tolerance provided by FT-CORBA is basically static, that is, once the fault tolerance properties of a group of replicated processes are defined, they cannot be modified in runtime. A support for dynamic reconfiguration of the replication would be highly advantageous since it would allow the implementation of mechanisms for adaptive fault tolerance, enabling FT-CORBA to adapt to the changes that can occur in the execution environment. In this paper, we propose a set of extensions to the FT-CORBA infrastructure in the form of interfaces and object service implementations, enabling it to support dynamic reconfiguration of the replication. Lau Cheuk Lung, Fábio Favarim, Giuliana Teixeira Santos, Miguel Correia 0001 |
ISORC | 4 |
| 2006 | Experimental Comparison of Local and Shared Coin Randomized Consensus ProtocolsabstractThe paper presents a comparative performance study of the two main classes of randomized binary consensus protocols: a local coin protocol, with an expected high communication complexity and cheap symmetric cryptography, and a shared coin protocol, with an expected low communication complexity and expensive asymmetric cryptography. The experimental evaluation was conducted on a LAN environment, by varying several system parameters, such as the fault types and number of processes. The analysis shows that there is a significant gap between the theoretical and the practical performance results of these protocols, and provides an important insight into what actually happens during their execution Henrique Moniz, Nuno Neves 0001, Miguel Correia 0001, Paulo Veríssimo |
SRDS | 3 |
| 2006 | Brief Announcement: Decoupled Quorum-Based Byzantine-Resilient Coordination in Open Distributed Systems
Alysson Neves Bessani, Miguel Correia 0001, Joni da Silva Fraga, Lau Cheuk Lung |
DISC | 2 |
| 2006 | From Consensus to Atomic Broadcast: Time-Free Byzantine-Resistant Protocols without SignaturesabstractThis paper proposes a stack of three Byzantine-resistant protocols aimed to be used in practical distributed systems: multi-valued consensus, vector consensus and atomic broadcast. These protocols are designed as successive transformations from one to another. The first protocol, multi-valued consensus, is implemented on top of a randomized binary consensus and a reliable broadcast protocol. The protocols share a set of important structural properties. First, they do not use digital signatures constructed with public-key cryptography, a well-known performance bottleneck in this kind of protocols. Second, they are time-free, i.e. they make no synchrony assumptions, since these assumptions are often vulnerable to subtle but effective attacks. Third, they are completely decentralized, thus avoiding the cost of detecting corrupt leaders. Fourth, they have optimal resilience, i.e. they tolerate the failure of f = ⌊(n−1)/3⌋ out of a total of n processes. In terms of time complexity, the multi-valued consensus protocol terminates in a constant expected number of rounds, while the vector consensus and atomic broadcast protocols have O(f) complexity. The paper also proves the equivalence between multi-valued consensus and atomic broadcast in the Byzantine failure model without signatures. A similar proof is given for the equivalence between multi-valued consensus and vector consensus. These two results have theoretical relevance since they show once more that consensus is a fundamental problem in distributed systems. Miguel Correia 0001, Nuno Neves 0001, Paulo Veríssimo |
Comput. J. | 1 |
| 2005 | Low complexity Byzantine-resilient consensus
Miguel Correia 0001, Nuno Neves 0001, Lau Cheuk Lung, Paulo Veríssimo |
Distributed Comput. | 1 |
| 2005 | Solving Vector Consensus with a WormholeabstractThis paper presents a solution to the vector consensus problem for Byzantine asynchronous systems augmented with wormholes. Wormholes prefigure a hybrid distributed system model, embodying the notion of an enhanced part of the system with "good" properties otherwise not guaranteed by the "normal" weak environment. A protocol built for this type of system runs in the asynchronous part, where f out of n/spl ges/3f+1 processes might be corrupted by malicious adversaries. However, sporadically, processes can rely on the services provided by the wormhole for the correct execution of simple operations. One of the nice features of this setting is that it is possible to keep the protocol completely time-free and, in addition, to circumvent the FLP impossibility result by hiding all time-related assumptions in the wormhole. Furthermore, from a performance perspective, it leads to the design of a protocol with a good time complexity. Nuno Neves 0001, Miguel Correia 0001, Paulo Veríssimo |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2004 | How to Tolerate Half Less One Byzantine Nodes in Practical Distributed SystemsabstractThe application of dependability concepts and techniques to the design of secure distributed systems is raising a considerable amount of interest in both communities under the designation of intrusion tolerance. However, practical intrusion-tolerant replicated systems based on the state machine approach (SMA) can handle at most f Byzantine components out of a total of n = 3f + 1, which is the maximum resilience in asynchronous systems. This paper extends the normal asynchronous system with a special distributed oracle called TTCB. Using this extended system we manage to implement an intrusion-tolerant service based on the SMA with only 2f + 1 replicas. Albeit a few other papers in the literature present intrusion-tolerant services with this approach, this is the first time the number of replicas is reduced from 3f + 1 to 2f + 1. Another interesting characteristic of the described service is a low time complexity. Miguel Correia 0001, Nuno Neves 0001, Paulo Veríssimo |
SRDS | 1 |
| 2002 | Efficient Byzantine-Resilient Reliable Multicast on a Hybrid Failure ModelabstractThe paper presents a new reliable multicast protocol that tolerates arbitrary faults, including Byzantine faults. This protocol is developed using a novel way of designing secure protocols which is based on a well-founded hybrid failure model. Despite our claim of arbitrary failure resilience, the protocol need not necessarily incur the cost of "Byzantine agreement", in number of participants and round/message complexity. It can rely on the existence of a simple distributed security kernel-the TTCB-where the participants only execute crucial parts of the protocol operation, under the protection of a crash failure model. Otherwise, participants follow an arbitrary failure model. The TTCB provides only a few basic services, which allow our protocol to have an efficiency similar to that of accidental fault-tolerant protocols: for f faults, our protocol requires f+2 processes, instead of 3f+1 in Byzantine systems. Besides, the TTCB (which is synchronous) allows secure operation of timed protocols, despite the unpredictable time behavior of the environment (possibly due to attacks on timing assumptions). Miguel Correia 0001, Lau Cheuk Lung, Nuno Neves 0001, Paulo Veríssimo |
SRDS | 1 |
| 1995 | Low-Level Multimedia Synchronization Algorithms on Broadband NetworksabstractNo abstract available. Miguel Correia 0001, Paulo Pinto 0001 |
ACM Multimedia | 1 |