Ricardo Morla

dblp:65/3466 · also Ricardo S. Morla, Ricardo Santos Morla · DBLP profile ↗
← Back
31ranked-venue papers
1as first author
3since 2021 · last 2023
0000-0002-5162-3019ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 13 · 1 since 2021Security and privacy · 5Artificial intelligence and machine learning · 3 · 2 since 2021Systems, architecture and hardware · 3 · 1 first-authorDatabases, data management, data science and information retrieval · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 2Software engineering, systems software and programming languages · 1Graphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Software maintenance and evolution · 44% Program synthesis and code generation · 44% Software testing · 13%

Topics — the 3 heaviest of 3, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Software maintenance and evolution › code reuse
code search and reuse
0.112007
CodeGenie: using test-cases to search and reuse source code · ASE 2007
Program synthesis and code generation
programming by example
0.112007
CodeGenie: using test-cases to search and reuse source code · ASE 2007
Software testing
test-driven development
0.012007
CodeGenie: using test-cases to search and reuse source code · ASE 2007

Methods — techniques the papers use, named apart from their topics

source code infrastructure · 0.1automated weaving and testing · 0.1
YearPublicationVenuePosition
2023 Attacking DoH and ECH: Does Server Name Encryption Protect Users' Privacy?
abstract
Privacy on the Internet has become a priority, and several efforts have been devoted to limit the leakage of personal information. Domain names, both in the TLS Client Hello and DNS traffic, are among the last pieces of information still visible to an observer in the network. The Encrypted Client Hello extension for TLS, DNS over HTTPS or over QUIC protocols aim to further increase network confidentiality by encrypting the domain names of the visited servers. In this article, we check whether an attacker able to passively observe the traffic of users could still recover the domain name of websites they visit even if names are encrypted. By relying on large-scale network traces, we show that simplistic features and off-the-shelf machine learning models are sufficient to achieve surprisingly high precision and recall when recovering encrypted domain names. We consider three attack scenarios, i.e., recovering the per-flow name, rebuilding the set of visited websites by a user, and checking which users visit a given target website. We next evaluate the efficacy of padding-based mitigation, finding that all three attacks are still effective, despite resources wasted with padding. We conclude that current proposals for domain encryption may produce a false sense of privacy, and more robust techniques should be envisioned to offer protection to end users.
Martino Trevisan, Francesca Soro, Marco Mellia, Idilio Drago, Ricardo Morla
ACM Trans. Internet Techn.5
2022 JavaScript&Me, A Tool to Support Research into Code Transformation and Browser Security
abstract
Doing research into code variations and their applications to browser security is challenging. One of the most important aspects of this research is to choose a relevant dataset on which machine learning algorithms can be applied to yield useful results. Although JavaScript code is widely available on various sources, such as package managers, code hosting platforms, and websites, collecting a large corpus of JavaScript and curating it is not a simple task. We present a novel open-source tool that helps with this task by allowing the automatic and systematic collection, processing, and transformation of JavaScript code. These three steps are performed by independent modules, and each one can be extended to incorporate new features, such as additional code sources, or transformation tools, adding to the flexibility of our tool and expanding its usability. Additionally, we use our tool to create a corpus of around 270k JavaScript files, including regular, minified, and obfuscated code, on which we perform a brief analysis. The conclusions from this analysis show the importance of properly curating a dataset before using it in research tasks, such as machine learning classifiers, reinforcing the relevance of our tool.
Susana Lima, Ricardo Morla, João Routar
CIKM2
2021 Hidden Markov models on a self-organizing map for anomaly detection in 802.11 wireless networks
Anisa Allahdadi, Diogo Pernes, Jaime S. Cardoso 0001, Ricardo Morla
Neural Comput. Appl.4
2019 Rapid detection of spammers through collaborative information sharing across multiple service providers
Muhammad Ajmal Azad, Ricardo Morla
Future Gener. Comput. Syst.2
2019 Predicting throughput in IEEE 802.11 based wireless networks using directional antenna
Saravanan Kandasamy 0001, Ricardo Morla, Patrícia Ramos, Manuel Ricardo 0001
Wirel. Networks2
2018 A Modular Tool for Benchmarking loT Publish-Subscribe Middleware
abstract
With the rise in popularity of the Internet of Things in all kinds of different application scenarios, various middleware solutions have appeared with different use-cases and optimizations in mind. The design space for any specific deployment is thus increasingly large, but little objective support exists to help choose the best middleware for each use-case. From this stems the need to evaluate how different IoT middleware solutions perform in different use-cases. Measuring the performance of IoT middleware in a way that 1) provides common ground among experiments, and 2) makes it easier to integrate new IoT middleware in the benchmark is not straightforward. In this paper, we propose a generic architecture for comparing the performance of publish/subscribe middleware, develop a tool that implements this architecture, and show the benefits in time and effort that can be reaped from our approach. We further validate our approach by using the architecture and tool to benchmark different middleware solutions, taking lessons from the changes necessary to support new middleware, and attempting to quantify the effort through lines of code and to qualitatively assess code structure similarity.
L. Zilhao, Ricardo Morla, Ana Aguiar
WOWMOM2
2018 Systems and methods for SPIT detection in VoIP: Survey and future directions
Muhammad Ajmal Azad, Ricardo Morla, Khaled Salah 0001
Comput. Secur.2
2017 Identifying Persistent and Recurrent QoE Anomalies for DASH Streaming in the Cloud
abstract
Quality of Experience (QoE) anomalies widely exist in all types of video services. As video services migrate to the Cloud, unique challenges occur to deploy video services in the Cloud environment. We study the QoE anomalies for users in a video service deployed in a production Cloud CDN. We use a QoE anomaly identification system, QRank, to identify anomalous systems. We consider Cloud CDN servers, Cloud CDN networks, transit networks, user access networks and different types of user devices. Our extensive experiments in production Cloud find several interesting insights about QoE anomalies of video streaming in the Cloud. 91.4% of QoE anomalies are detected on 15.32% of users. These users experience QoE anomalies persistently and recurrently. The Cloud servers and networks seldom cause QoE anomalies. More than 99.98% of QoE anomalies are identified in anomalous systems including the transit networks, the access networks and user devices. We infer that transit networks are the actual bottleneck systems for QoE anomalies in production Cloud. More than 95% of persistent and recurrent QoE anomalies are identified in less than 10 transit networks. We collect latency measurements to anomalous networks and the analysis indicates that the limited capacity in transit networks are the major cause of QoE anomalies. Resulting anomalies impair user QoEs persistently or recurrently. In order to provide good user QoE, the Cloud provider should identify transit networks that may become bottlenecks for high quality video streaming and appropriate peering with Internet Service Providers (ISPs) to bypass these bottlenecks.
Chen Wang 0039, Hyong S. Kim 0001, Ricardo Morla
CloudCom3
2017 Benchmarking IoT middleware platforms
abstract
Middleware is being extensively used in Internet of Things (IoT) deployments and is available in a variety of flavors - from general-purpose community-driven middleware and telco-developed Machine-to-Machine (M2M) middleware to middleware targeting specific deployments. Despite this extensive use and diversity, little is known about the benefits, disadvantages, and performance of each middleware platform and how the different platforms compare with each other. This comparison is especially relevant to help the design and dimensioning of IoT infrastructure. In this paper, we propose a set of qualitative dimensions and quantitative metrics that can be used for bench-marking IoT middleware. We use the publication-subscription of a large dataset as use case inspired by a smart city scenario to compare two middleware platforms. The methodology enables us to systematically compare the two middleware platforms. Further, we are able to use our approach to identify inefficiencies in implementations and to characterize performance variations throughout the day, showing that the metrics may also be used for monitoring.
Carlos Pereira, Ana Aguiar, Ricardo Morla
WoWMoM4
2016 QWatch: Detecting and Locating QoE Anomaly for VoD in the Cloud
abstract
Commercial large-scale VoD systems such as Netflix and Hulu rely on CDNs to deliver videos to users around the world. Various anomalies occur often and degrade users' Quality of Experience (QoE). Detecting and locating such anomalies are highly complex due to a large number of different entities involved in the end-to-end video delivery. These entities include VoD provider, CDN/Cloud providers, transit ISPs, access ISPs, and end user devices. QoE perceived by the users is a critical metric for VoD providers. We propose QWatch, a scalable monitoring system, which detects and locates anomalies based on the end user QoE in real-time. We evaluate QWatch in a controlled VoD system and production Microsoft Azure Cloud and CDN. QWatch effectively detects and locates QoE anomalies in our extensive experiments. We discuss insights obtained from running VoD system with 200 worldwide users in production Cloud.
Chen Wang 0039, Hyong S. Kim 0001, Ricardo Morla
CloudCom3
2016 Power interference modeling for CSMA/CA based networks using directional antenna
Saravanan Kandasamy 0001, Ricardo Morla, Manuel Ricardo 0001
Comput. Commun.2
2016 Long-range trajectories from global and local motion representations
Eduardo Marques Pereira, Jaime S. Cardoso 0001, Ricardo Morla
J. Vis. Commun. Image Represent.3
2016 A behavioral reflective architecture for managing the integration of personal ubicomp systems: automatic SNMP-based discovery and management of behavior context in smart-spaces
Rui S. Moreira, Ricardo Morla, Luís P. C. Moreira, Christophe Soares
Pers. Ubiquitous Comput.2
2016 Dynamic adaptation of personal ubicomp environments
Rui S. Moreira, José M. Torres 0001, Pedro Miguel Sobral, Ricardo Morla, Mark Rouncefield, Gordon S. Blair
Pers. Ubiquitous Comput.4
2016 Clustering VoIP caller for SPIT identification
abstract
Abstract The number of unsolicited and advertisement telephony calls over traditional and Internet telephony has rapidly increased over recent few years. Every year, the telecommunication regulators, law enforcement agencies and telecommunication operators receive a very large number of complaints against these unsolicited, unwanted calls. These unwanted calls not only bring financial loss to the users of the telephony but also annoy them with unwanted ringing alerts. Therefore, it is important for the operators to block telephony spammers at the edge of the network so to gain trust of their customers. In this paper, we propose a novel spam detection system by incorporating different social network features for combating unwanted callers at the edge of the network. To this extent the reputation of each caller is computed by processing call detailed records of user using three social network features that are the frequency of the calls between caller and the callee, the duration between caller and the callee and the number of outgoing partners associated with the caller. Once the reputation of the caller is computed, the caller is then places in a spam and non‐spam clusters using unsupervised machine learning. The performance of the proposed approach is evaluated using a synthetic dataset generated by simulating the social behaviour of the spammers and the non‐spammers. The evaluation results reveal that the proposed approach is highly effective in blocking spammer with 2% false positive rate under a large number of spammers. Moreover, the proposed approach does not require any change in the underlying VoIP network architecture, and also does not introduce any additional signalling delay in a call set‐up phase. Copyright © 2016 John Wiley & Sons, Ltd.
Muhammad Ajmal Azad, Ricardo Morla, Junaid Arshad, Khaled Salah 0001
Secur. Commun. Networks2
2016 High-performance network traffic analysis for continuous batch intrusion detection
Ricardo Morla, Jorge G. Barbosa
J. Supercomput.1
2015 QoE Driven Server Selection for VoD in the Cloud
abstract
In commercial Video-on-Demand (VoD) systems, user's Quality of Experience (QoE) is the key factor for user satisfaction. In order to improve user's QoE, VoD providers replicate popular videos in geo-distributed Cloud and deploy cache servers close to users. Generally, the VoD provider selects a server for the user request according to the user's location. Usually geographically closely located servers would provide lower network delay. However, the performance of VoD servers deployed in cloud virtual machines (VM) depends not only on the network delay but also resource contention due to other VMs and highly dynamic user demands. Thus, QoE offered by the server varies greatly over time as user demands and network traffic fluctuate regardless of the location. Selecting a server close to users sometimes reduces the network delay but cannot guarantee QoE in general. We believe that end users have the best perception of server performance in terms of their QoE rather than the servers themselves. What user perceives incorporate performance of all elements, such as network delay and server response time in VoD service. We propose VoD server selection schemes that dynamically select servers according to user's QoE feedback. We integrate our server selection schemes with Dynamic Adaptive Streaming over HTTP (DASH) clients and evaluate our system both in simulation and in Google Cloud. Results show our system improves user QoE up to 20% compared to existing solutions.
Chen Wang 0039, Hyong S. Kim 0001, Ricardo Morla
CLOUD3
2015 Users Know Better: A QoE Based Adaptive Control System for VoD in the Cloud
abstract
As VoD systems migrate to the Cloud, new challenges emerge in managing user Quality-of- Experience (QoE). The complexity of the cloud system due to virtualization and resource sharing complicates the QoE management. Operational failures in the Cloud could be challenging for QoE as well. We believe that end users have the best perception of system performance in terms of their QoE. We propose a QoE based adaptive control system for VoD in the Cloud. The system learns server performance from the user QoE and then adaptively selects servers for users accordingly. We deploy our proposed system in Google Cloud and evaluate it with hundreds of clients deployed all over the world. Results show that given the same amount of resources, our system provides 9% to 30% more users with QoE above the Mean Opinion Score (MOS) "good" level than the existing measurement based server selection systems. The system guarantees a better QoE (above 6% better) for 90% users. Additionally, our system discovers operational failures by monitoring QoE and prevents streaming session crashes. A computational overhead analysis shows that our system can easily scale to large VoD systems containing thousands of servers.
Chen Wang 0039, Hyong S. Kim 0001, Ricardo Morla
GLOBECOM3
2015 Fault diagnosis in DSL networks using support vector machines
Angelos K. Marnerides, Simon Malinowski, Ricardo Morla, Hyong S. Kim 0001
Comput. Commun.3
2014 A graph-based approach for interference free integration of commercial off-the-shelf elements in pervasive computing systems
Christophe Soares, Rui S. Moreira, Ricardo Morla, José M. Torres 0001, Pedro Miguel Sobral
Future Gener. Comput. Syst.3
2013 On the comprehension of DSL SyncTrap events in IPTV networks
abstract
The adequate operation of IPTV distribution networks heavily relies on the effective maintenance and management of their underlay DSL infrastructure. New hardware and software is required in order to improve monitoring capabilities and to directly diagnose anomalies that other segments of the DSL network cannot identify. In this work we initially compare the accuracy performance of SVM-specific formulations for constructing a robust ground truth within our classification procedure regarding abnormalities issued at anomaly-aware Digital Subscriber Line Access Multiplexers (DSLAMs) of the DSL infrastructure. Moreover, we consider the pragmatic cost of repairing anomalies that were misclassified and characterize each classifier according to the overall cost that is possible to incur to the network operator. In parallel, this work attempts to practically improve the network-wide anomaly classification performance by proposing a semi-supervised classification scheme that updates the initial supervised scheme by testing unlabelled anomalies occurring at anomaly-unaware DSLAMs.
Angelos K. Marnerides, Simon Malinowski, Ricardo Morla, Miguel R. D. Rodrigues, Hyong S. Kim 0001
ISCC3
2013 Abrupt ending of 802.11 AP connections
abstract
Wireless 802.11 users often experience connectivity problems while using 802.11 networks. The task of diagnosing and fixing these problems by looking at usage patterns is one of the major challenges that campus and corporate 802.11 network administrators face. In this paper we identify a usage pattern that we name “abrupt ending“ of 802.11 connections and that happens when a large number of sessions in the same access point (AP) end within a one second window. We observe up to 40 sessions ending at the same second and over 150k abrupt endings in a two and a half year period from 2006 to 2009 in the Faculty of Engineering of the University of Porto. We describe the data set and identify anomaly-related patterns such as AP halt/crash, AP overload, interference, interference across the vicinity of an AP, and AP persistent interference as well as user authentication failure and intermittent connectivity. We validate our analysis by density clustering of the abrupt ending data. In addition we crosscheck the existence of abrupt endings on a 2011 data set of the same location in Porto and on 2011 data from the University of Minho, which was deployed and is managed independently from the one in Porto.
Dossa Massa, Ricardo Morla
ISCC2
2013 Caller-REP: Detecting unwanted calls with caller social strength
Muhammad Ajmal Azad, Ricardo Morla
Comput. Secur.2
2013 Modeling 802.11 AP usage through daily keep-alive event counts
Dossa Massa, Ricardo Morla
Wirel. Networks2
2012 A Single Pass Trellis-Based Algorithm for Clustering Evolving Data Streams
Simon Malinowski, Ricardo Morla
DaWaK2
2012 Towards the improvement of diagnostic metrics Fault diagnosis for DSL-Based IPTV networks using the Rényi entropy
abstract
IPTV networks blindly rely on the adequate operation and management of the underlying infrastructure that in numerous cases is threaten by unexpected anomalous events which consequently cause QoS degradation to the end-user. Thus, it is of great importance to deploy techniques embodied with diagnostic and self-protection metrics for determining and predicting the arrival of such events in order to proactively charge defense mechanisms without the need of an exhaustive manual inspection by the network operator. In this paper we propose and demonstrate the applicability of the Rényi entropy as a useful diagnosis feature for explicitly characterizing DSL-level anomalies issued in an IPTV network of a large European ISP. It is revealed that different orders of the Rényi entropy can formulate meaningful detection and categorization of phenomena occurring on specific Digital Subscriber Line Access Multiplexers (DSLAMs) within the DSL infrastructure. Via the synergistic exploitation of the local maxima peaks generated by each Rényi-based distribution we exhibit the feasibility to extract and identify lightweight anomalies that under simple metrics cannot be detected.
Angelos K. Marnerides, Simon Malinowski, Ricardo Morla, Miguel R. D. Rodrigues, Hyong S. Kim 0001
GLOBECOM3
2012 Mitigating SPIT with Social Strength
abstract
SPIT (Spam over Internet Telephony) is unsolicited, unwanted phone calls made for advertising products or voice phishing. The real time nature of voice calls makes traditional email anti-spam techniques un-applicable to SPIT detection in a VoIP (Voice over Internet Protocol) network. The VoIP users have social network with colleagues, friends, family members, and other acquaintances. Various social reputation approaches have been proposed but these were mainly based on average call duration or require user feedback to assign reputation score. We believe that the computation of reputation should be two fold; firstly it should not involve user feedback and secondly it considers other network features in addition to call duration. In this paper, we propose a social strength for detecting SPIT callers. We analyze how similarities and social ties among VoIP users effect SPIT detection. The local social strength among users are computed considering more features like out-degree, number of repetitive calls, reciprocity and interaction rate. The global strength of the caller is computed using the Eigen trust algorithm and represents the strength of a caller as whole in a network. The global strength values are then compared with the automated threshold value for finally classifying a caller as legitimate and non-legitimate. A distinct feature of our approach is that it does not involve users for feedback and can be easily deployed in real VoIP network without any change in architecture and SIP protocol stack. We evaluate our social strength approach on different types of random network data and shows that the system detects SPIT callers with false positive rate less then 10% and true positive rate of 99% for all type of underlying random networks.
Muhammad Ajmal Azad, Ricardo Morla
TrustCom2
2012 Interference Free Integration of Pervasive Applications
abstract
Off-the-shelf smart devices and applications are expected to be pivotal in the coming need for massive home care. Deployment and integration of these systems in the same household may result in unplanned interactions involving users and entertainment, communication, and health-related devices. These unplanned interactions are a major concern when, for example, communication or entertainment applications interfere with the behavior of health-related devices. This paper presents a novel graph-based approach for representing the expected behavior of off-the-shelf smart devices and applications, their interactions, and for detecting interference in home care settings. A set of home care scenarios is used to assess the applicability of our approach. Our graph-based interference detection approach is integrated in the Safe Home Care reflective platform, which allows reifying the state of off-the-shelf systems and simulating home care scenarios.
Christophe Soares, Rui S. Moreira, Ricardo Morla, José M. Torres 0001, Pedro Miguel Sobral
TrustCom3
2010 Using Directional Antennas on Stub Wireless Mesh Networks: Impact on Throughput, Delay, and Fairness
abstract
Wireless Mesh Networks (WMNs), which feature infrastructureless broadband network configurations, are attracting attention as an elemental technology when it comes to the extension of current WLAN infrastructures. State of the art solutions addressing WMNs usually assume the use of omnidirectional antennas. In this paper we evaluate the performance improvements obtained when using directional antennas. By using simulations, we analyze the gains in terms of throughput, delay and fairness, considering a grid network topology used to extend an infrastructure network. Simulation results show that by changing the type of antenna in use from omnidirectional to directional, the average throughput of a WMN can increase about 56% and the average network delay can be reduced by approximately 40%, without compromising fairness.
Saravanan Kandasamy 0001, Rui Campos, Ricardo Morla, Manuel Ricardo 0001
ICCCN3
2010 Second life in-world action traffic modeling
abstract
Massive multiplayer online games (MMOGs) are increasingly popular because they can provide entertainment, numerous opportunities for socialization, and the ability for end users to earn money. Cornerstone to MMOGs is the underlying network traffic between MMOG clients and servers; understanding this traffic is important for application developers trying to improve game performance and for ISPs trying to provide a better quality of service for their customers. In this paper we present fine-grained approaches at modeling SL client-server traffic. Our approaches differ from existing modeling work as they focus on the analysis of specific in-world actions, on the decomposition of the collected samples in subsets of packets with the same size, and on modeling the dependencies between packets in the sample. We compare our different approaches between them and with the original collected sample using the Kolmogorov-Smirnov (KS) test statistic on packet size and inter-arrival time. We observed over one order of magnitude improvement of our models in the KS statistic for packet size and three time improvement for packet inter-arrival time compared to a bivariate 2-component Gaussian mixture model.
Mário Lopes Ferreira, Ricardo Morla
NOSSDAV2
2007 CodeGenie: using test-cases to search and reuse source code
abstract
We present CodeGenie, a tool that implements a test-driven approachto search and reuse of code available on large-scale coderepositories. While using CodeGenie developers design test cases fora desired feature first, similar to Test-driven Development (TDD).However, instead of implementing the feature as in TDD, CodeGenieautomatically searches for it based on information available in thetests. To check the suitability of the candidate results in thelocal context, each result is automatically woven into thedeveloper's project and tested using the original tests. Thedeveloper can then reuse the most suitable result. Later, reusedcode can also be unwoven from the project as wished. For the codesearching and wrapping facilities, CodeGenie relies on Sourcerer, anInternet-scale source code infrastructure that we have developed
Otávio Augusto Lazzarini Lemos, Sushil Krishna Bajracharya, Joel Ossher, Ricardo Morla, Paulo César Masiero, Pierre Baldi, Cristina V. Lopes
ASE4