EDBT 2026 Demo / reviewers in the wild / expert
Alysson Neves Bessani
dblp:68/1448 · also Alysson Bessani
· DBLP profile ↗
77ranked-venue papers
18as first author
21since 2021 · last 2026
0000-0002-8386-1628ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 32 · 11 first-author · 9 since 2021Security and privacy · 29 · 3 first-author · 6 since 2021Software engineering, systems software and programming languages · 11 · 3 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Computer networks · 3 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MVP-ORAM: a Wait-free Concurrent ORAM for Confidential BFT Storage
Robin Vassantlal, Hasan Heydari, Bernardo Ferreira, Alysson Neves Bessani |
NDSS | 4 |
| 2026 | False alarms, real damage: Adversarial attacks using LLM-based models on text-based Cyber Threat Intelligence systemsabstractCyber Threat Intelligence (CTI) has emerged as a vital complementary approach that operates in the early phases of the cyber threat lifecycle. CTI involves collecting, processing, and analysing threat data to provide a more accurate and rapid understanding of cyber threats. Due to the large volume of data, automation through Machine Learning (ML) and Natural Language Processing (NLP) models is essential for effective CTI extraction. These automated systems leverage Open Source Intelligence (OSINT) from sources like social networks, forums, and blogs to identify Indicators of Compromise (IoCs). Although prior research has focused on adversarial attacks on specific ML models, this study expands the scope by investigating vulnerabilities within various components of the entire CTI pipeline and their susceptibility to adversarial attacks. It particularly focuses on a system-level analysis of how existing adversarial techniques interact with and across multiple stages of this pipeline, resulting in cascading attack effects. These vulnerabilities arise because they ingest textual inputs from various open sources, including real and potentially fake content. Three types of attacks against CTI pipelines are analysed – evasion, flooding, and poisoning – and their impact on the system’s information selection capabilities is assessed. Specifically, focusing on fake text generation, the work demonstrates how adversarial text generation techniques can create fake cybersecurity and cybersecurity-like text that misleads classifiers, degrades performance, and disrupts system functionality. The focus is primarily on the evasion attack, as it precedes and enables flooding and poisoning attacks within the CTI pipeline. The findings reveal that the False Positive Rate (FPR) for evasion attacks reached 97% with a specialised ML classifier model, indicating the model’s high vulnerability to adversarial samples. Additionally, an FPR of 75% is observed for ChatGPT-4o as a classifier, indicating its susceptibility to adversarial examples. These results underscore the need for an additional verification component at the early stage of the CTI pipeline to detect and filter out misinformation before it spreads through the system. Samaneh Shafee, Alysson Neves Bessani, Pedro M. Ferreira 0001 |
Future Gener. Comput. Syst. | 2 |
| 2025 | CCE: A Cloud-Based SIEM Correlation Engine Built on Serverless FunctionsabstractCybersecurity has been one of the most critical aspects for enterprises in the digital era. Security Information and Event Management (SIEM) systems have been essential in cybersecurity, helping security teams analyse and correlate millions of security events and discover indicators of compromise within an organisation's assets. Deploying and maintaining SIEMs on-premise is expensive, making it difficult for companies with limited budgets to acquire them. Cloud-based SIEMs have emerged as a more cost-effective and viable alternative for such companies. However, they do not fully use the pay-per-use model, requiring additional resources and service subscriptions, which makes them more expensive than initially promised. We present CCE, a Cloud-based SIEM Correlation Engine for processing and correlating events in a Function-as-a-service (FaaS) cloud infrastructure. The core of CCE is a novel method for translating SIEM rules into a set of cost-efficient functions to be deployed in a FaaS infrastructure. We evaluated CCE experimentally in various scenarios, considering different configurations of the FaaS cloud and quality-of-service levels, to study the monetary cost of operating CCE for monitoring different infrastructures. The results show that CCE is significantly cheaper than existing cloud-based SIEMs, costing as little as 272 monthly for processing the generated events by a medium-sized real infrastructure. Adriano Serckumecka, Iberia Medeiros, Alysson Neves Bessani |
SRDS | 3 |
| 2025 | Evaluation of LLM-based chatbots for OSINT-based Cyber Threat Awareness
Samaneh Shafee, Alysson Neves Bessani, Pedro M. Ferreira 0001 |
Expert Syst. Appl. | 2 |
| 2024 | Knowledge Connectivity Requirements for Solving BFT Consensus with Unknown Participants and Fault ThresholdabstractConsensus is a fundamental building block for constructing reliable and fault-tolerant distributed services. The increasing demand for high-performance and scalable blockchain protocols has brought attention to solving consensus in scenarios where each participant joins the system knowing only a subset of participants. In such scenarios, the participants' initial knowledge about the existence of other participants can collectively be represented by a directed graph known as knowledge connectivity graph. The Byzantine Fault Tolerant Consensus with Unknown Participants (BFT-CUP) problem aims to solve consensus in those scenarios by identifying the necessary and sufficient conditions that the knowledge connectivity graphs must satisfy when a fault threshold is provided to all participants. This work extends BFT-CUP by eliminating the requirement to provide the fault threshold to the participants. We indeed address the problem of solving BFT consensus in settings where each participant initially knows a subset of participants, and although a fault threshold exists, no participant is provided with this information – referred to as BFT Consensus with Unknown Participants and Fault Threshold (BFT-CUPFT). With this aim, we first demonstrate that the conditions identified for knowledge connectivity graphs by BFT-CUP are insufficient to solve BFT-CUPFT. Accordingly, we introduce a new type of knowledge connectivity graph that is sufficient for solving such a problem. To validate its sufficiency, we design a protocol for solving BFT-CUPFT. Hasan Heydari, Robin Vassantlal, Alysson Neves Bessani |
ICDCS | 3 |
| 2024 | Chasing Lightspeed Consensus: Fast Wide-Area Byzantine Replication with MercuryabstractBlockchain technology sparked renewed interest in planetary-scale Byzantine fault-tolerant (BFT) state machine replication (SMR). While recent works predominantly focused on improving the scalability and throughput of these protocols, few of them addressed latency. We present Mercury, a novel transformation to autonomously optimize the latency of quorum-based BFT consensus. Mercury employs a dual resilience threshold that enables faster transaction ordering when the system contains few faulty replicas. Mercury allows forming compact quorums that substantially accelerate consensus using a smaller resilience threshold. Nevertheless, Mercury upholds standard SMR safety and liveness guarantees with optimal resilience, thanks to its judicious use of a dual operation mode and BFT forensics techniques. Our experiments spread tens of replicas across continents and reveal that Mercury can order transactions with finality in less than 0.4s, half the time of a PBFT-like protocol (optimal in terms of number of communication steps and resilience) in the same network. Furthermore, Mercury matches the latency of running its base protocol on theoretically optimal internet links (transmitting at 67% of the speed of light). Christian Berger 0006, Lívio Rodrigues, Hans P. Reiser, Vinicius Vielmo Cogo, Alysson Neves Bessani |
Middleware | 5 |
| 2024 | The Power of Simplicity on Dependable Distributed Systems (Invited Talk)
Alysson Neves Bessani |
OPODIS | 1 |
| 2024 | Probabilistic Byzantine Fault ToleranceabstractConsensus is a fundamental building block for constructing reliable and fault-tolerant distributed services. Many Byzantine fault-tolerant consensus protocols designed for partially synchronous systems adopt a pessimistic approach when dealing with adversaries, ensuring safety even under the worst-case scenarios that adversaries can create. Following this approach typically results in either an increase in the message complexity (e.g., PBFT) or an increase in the number of communication steps (e.g., HotStuff). In practice, however, adversaries are not as powerful as the ones assumed by these protocols. Furthermore, it might suffice to ensure safety and liveness properties with high probability. To accommodate more realistic and optimistic adversaries and improve the scalability of BFT consensus, we propose ProBFT (Probabilistic Byzantine Fault Tolerance). ProBFT is a leader-based probabilistic consensus protocol with a message complexity of [EQUATION] and an optimal number of communication steps that tolerates Byzantine faults in permissioned partially synchronous systems. It is built on top of well-known primitives, such as probabilistic Byzantine quorums and verifiable random functions. ProBFT guarantees safety and liveness with high probability even with faulty leaders, as long as a supermajority of replicas is correct and using only a fraction (e.g., 20%) of messages exchanged in PBFT. We provide a detailed description of ProBFT's protocol and its analysis. Diogo Avelas, Hasan Heydari, Eduardo Alchieri, Tobias Distler, Alysson Neves Bessani |
PODC | 5 |
| 2023 | VEDLIoT: Next generation accelerated AIoT systems and applicationsabstractThe VEDLIoT project aims to develop energy-efficient Deep Learning methodologies for distributed Artificial Intelligence of Things (AIoT) applications. During our project, we propose a holistic approach that focuses on optimizing algorithms while addressing safety and security challenges inherent to AIoT systems. The foundation of this approach lies in a modular and scalable cognitive IoT hardware platform, which leverages microserver technology to enable users to configure the hardware to meet the requirements of a diverse array of applications. Heterogeneous computing is used to boost performance and energy efficiency. In addition, the full spectrum of hardware accelerators is integrated, providing specialized ASICs as well as FPGAs for reconfigurable computing. The project's contributions span across trusted computing, remote attestation, and secure execution environments, with the ultimate goal of facilitating the design and deployment of robust and efficient AIoT systems. The overall architecture is validated on use-cases ranging from Smart Home to Automotive and Industrial IoT appliances. Ten additional use cases are integrated via an open call, broadening the range of application areas. Kevin Mika, René Griessl, Nils Kucza, Florian Porrmann, Martin Kaiser, Lennart Tigges, Jens Hagemeyer, Pedro Trancoso, Muhammad Waqar Azhar, Fareed Qararyah, Stavroula Zouzoula, Jämes Ménétrey, Marcelo Pasin, Pascal Felber, Carina Marcus, Oliver Brunnegård, Olof Eriksson, Hans Salomonsson, Daniel Ödman, Andreas Ask, António Casimiro, Alysson Neves Bessani, Tiago Carvalho 0002, Karol Gugala, Piotr Zierhoffer, Grzegorz Latosinski, Marco Tassemeier, Mario Porrmann, Hans-Martin Heyn, Eric Knauss, Yufei Mao, Franz Meierhöfer |
CF | 22 |
| 2023 | How Hard is Asynchronous Weight Reassignment?abstractThe performance of distributed storage systems deployed on wide-area networks can be improved using weighted (majority) quorum systems instead of their regular variants due to the heterogeneous performance of the nodes. A significant limitation of weighted majority quorum systems lies in their dependence on static weights, which are inappropriate for systems subject to the dynamic nature of networked environments. To overcome this limitation, such quorum systems require mechanisms for reassigning weights over time according to the performance variations. We study the problem of node weight reassignment in asynchronous systems with a static set of servers and static fault threshold. We prove that solving such a problem is as hard as solving consensus, i.e., it cannot be implemented in asynchronous failure-prone distributed systems. This result is somewhat counter-intuitive, given the recent results showing that two related problems – replica set reconfiguration and asset transfer – can be solved in asynchronous systems. Inspired by these problems, we present two versions of the problem that contain restrictions on the weights of servers and the way they are reassigned. We propose a protocol to implement one of the restricted problems in asynchronous systems. As a case study, we construct a dynamic-weighted atomic storage based on such a protocol. We also discuss the relationship between weight reassignment and asset transfer problems and compare our dynamic-weighted atomic storage with reconfigurable atomic storage. Hasan Heydari, Guthemberg Silvestre, Alysson Neves Bessani |
ICDCS | 3 |
| 2023 | On the Minimal Knowledge Required for Solving Stellar ConsensusabstractByzantine Consensus is fundamental for building consistent and fault-tolerant distributed systems. In traditional quorum-based consensus protocols, quorums are defined using globally known assumptions shared among all participants. Motivated by decentralized applications on open networks, the Stellar blockchain relaxes these global assumptions by allowing each participant to define its quorums using local information. A similar model called Consensus with Unknown Participants (CUP) studies the minimal knowledge required to solve consensus in ad-hoc networks where each participant knows only a subset of other participants of the system. We prove that Stellar cannot solve consensus using the initial knowledge provided to participants in the CUP model, even though CUP can. We propose an oracle called sink detector that augments this knowledge, enabling Stellar participants to solve consensus. Robin Vassantlal, Hasan Heydari, Alysson Neves Bessani |
ICDCS | 3 |
| 2023 | Poster: Faster Quorums with FlashConsensusabstractBlockchain technology has renewed interest in planetary-scale Byzantine fault-tolerant (BFT) state machine replication (SMR). While recent works focus on scalability and throughput, few address latency.We present the idea of FlashConsensus, a transformation for quorum-based BFT consensus that uses an adaptive resilience threshold. FlashConsensus employs adaptive weighted replication to assign high voting power to specific replicas, thus yielding smaller quorums that speed up consensus. To maintain SMR safety and liveness guarantees with optimal resilience, FlashConsensus employs two modes of operation and BFT forensics. Experiments with replicas worldwide show FlashConsensus orders client requests in less than 0.4 s, which is half the time needed by a PBFT-like protocol with optimal consensus latency. Christian Berger 0006, Lívio Rodrigues, Hans P. Reiser, Vinicius Vielmo Cogo, Alysson Neves Bessani |
PRDC | 5 |
| 2022 | VEDLIoT: Very Efficient Deep Learning in IoTabstractThe VEDLIoT project targets the development of energy-efficient Deep Learning for distributed AIoT applications. A holistic approach is used to optimize algorithms while also dealing with safety and security challenges. The approach is based on a modular and scalable cognitive IoT hardware platform. Using modular microserver technology enables the user to configure the hardware to satisfy a wide range of applications. VEDLIoT offers a complete design flow for Next-Generation IoT devices required for collaboratively solving complex Deep Learning applications across distributed systems. The methods are tested on various use-cases ranging from Smart Home to Automotive and Industrial IoT appliances. VEDLIoT is an H2020 EU project which started in November 2020. It is currently in an intermediate stage with the first results available. Martin Kaiser, René Griessl, Nils Kucza, Carola Haumann, Lennart Tigges, Kevin Mika, Jens Hagemeyer, Florian Porrmann, Ulrich Rückert 0001, Micha vor dem Berge, Stefan Krupop, Mario Porrmann, Marco Tassemeier, Pedro Trancoso, Fareed Qararyah, Stavroula Zouzoula, António Casimiro, Alysson Neves Bessani, José Cecílio, Stefan Andersson, Oliver Brunnegård, Olof Eriksson, Roland Weiss 0001, Franz Meierhöfer, Hans Salomonsson, Elaheh Malekzadeh, Daniel Ödman, Anum Khurshid, Pascal Felber, Marcelo Pasin, Valerio Schiavoni, Jämes Ménétrey, Karol Gugala, Piotr Zierhoffer, Eric Knauss, Hans-Martin Heyn |
DATE | 18 |
| 2022 | COBRA: Dynamic Proactive Secret Sharing for Confidential BFT ServicesabstractByzantine Fault-Tolerant (BFT) State Machine Replication (SMR) is a classical paradigm for implementing trustworthy services that has received renewed interest with the emergence of blockchains and decentralized infrastructures. A fundamental limitation of BFT SMR is that it provides integrity and availability despite a fraction of the replicas being controlled by an active adversary, but does not offer any confidentiality protection. Previous works addressed this issue by integrating secret sharing with the consensus-based framework of BFT SMR, but without providing all features required by practical systems, which include replica recovery, group reconfiguration, and acceptable performance when dealing with a large number of secrets. We present COBRA, a new protocol stack for Dynamic Proactive Secret Sharing that allows implementing confidentiality in practical BFT SMR systems. COBRA exhibits the best asymptotic communication complexity and optimal storage overhead, being able to renew 100k shares in a group of ten replicas $5 \times $ faster than the current state of the art. Robin Vassantlal, Eduardo Alchieri, Bernardo Ferreira, Alysson Neves Bessani |
SP | 4 |
| 2022 | AWARE: Adaptive Wide-Area Replication for Fast and Resilient Byzantine ConsensusabstractWith upcoming blockchain infrastructures, world-spanning Byzantine consensus is getting practical and necessary. In geographically distributed systems, the pace at which consensus is achieved is limited by the heterogeneous latencies of connections between replicas. If deployed on a wide-area network, consensus-based systems benefit from weighted replication, an approach that utilizes extra replicas and assigns higher voting weights to well-connected replicas. This approach enables more choice in quorum formation and replicas can leverage proportionally smaller quorums to advance, thus decreasing consensus latency. However, the system needs a solution to autonomously adjust to its environment if network conditions change or faults occur. We present Adaptive Wide-Area REplication (AWARE), a mechanism that improves the geographical scalability of consensus with nodes being widely spread across the world. Essentially, AWARE is an automated and dynamic voting-weight tuning and leader positioning scheme, which supports the emergence of fast quorums in the system. It employs a reliable self-monitoring process and provides a prediction model seeking to minimize the system’s consensus latency. In experiments using several AWS EC2 regions, AWARE dynamically optimizes consensus latency by self-reliantly finding a fast configuration yielding latency gains observed by clients located across the globe. Christian Berger 0006, Hans P. Reiser, João Sousa 0002, Alysson Neves Bessani |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | Making Reads in BFT State Machine Replication Fast, Linearizable, and Live
Christian Berger 0006, Hans P. Reiser, Alysson Neves Bessani |
SRDS | 3 |
| 2021 | Brief Announcement: Auditable Register EmulationsabstractThe widespread prevalence of data breaches amplifies the importance of auditing storage systems. In this work, we initiate the study of auditable storage emulations, which provide the capability for an auditor to report the previously executed reads in a register. We precisely define the notion of auditable register and its properties, and establish tight bounds and impossibility results for auditable storage emulations in the presence of faulty storage objects. Our formulation considers loggable read-write registers that securely store data using information dispersal and support fast reads. In such a scenario, given a maximum number~$f$ of faulty storage objects and a minimum number~$τ$ of data blocks required to recover a stored value, we prove that (1) auditability is impossible if $τ\leq 2f $; (2) implementing a weak form of auditability requires $τ\geq 3f+1$; and (3) a stronger form of auditability is impossible. We also show that signing read requests overcomes the lower bound of weak auditability, while totally ordering operations or using non-fast reads enables strong auditability. Vinicius Vielmo Cogo, Alysson Neves Bessani |
DISC | 2 |
| 2021 | Processing tweets for cybersecurity threat awareness
Fernando Alves, Aurélien Bettini, Pedro M. Ferreira 0001, Alysson Neves Bessani |
Inf. Syst. | 4 |
| 2021 | Field surveillance of fuel dispensers using IoT-based metering and blockchains
Wilson S. Melo Jr., Luiz V. G. Tarelho, Bruno A. Rodrigues Filho, Alysson Neves Bessani, Luiz Fernando Rust da Costa Carmo |
J. Netw. Comput. Appl. | 4 |
| 2021 | GenoDedup: Similarity-Based Deduplication and Delta-Encoding for Genome Sequencing DataabstractThe vast datasets produced in human genomics must be efficiently stored, transferred, and processed while prioritizing storage space and restore performance. Balancing these two properties becomes challenging when resorting to traditional data compression techniques. In fact, specialized algorithms for compressing sequencing data favor the former, while large genome repositories widely resort to generic compressors (e.g., GZIP) to benefit from the latter. Notably, human beings have approximately 99.9 percent of DNA sequence similarity, vouching for an excellent opportunity for deduplication and its assets: leveraging inter-file similarity and achieving higher read performance. However, identity-based deduplication fails to provide a satisfactory reduction in the storage requirements of genomes. In this article, we balance space savings and restore performance by proposing \sf GenoDedupGenoDedup, the first method that integrates efficient similarity-based deduplication and specialized delta-encoding for genome sequencing data. Our solution currently achieves 67.8 percent of the reduction gains of SPRING (i.e., the best specialized tool in this metric) and restores data 1.62×1.62× faster than SeqDB (i.e., the fastest competitor). Additionally, GenoDedupGenoDedup restores data 9.96×9.96× faster than SPRING and compresses files 2.05×2.05× more than SeqDB. Vinicius Vielmo Cogo, João Paulo 0001, Alysson Neves Bessani |
IEEE Trans. Computers | 3 |
| 2021 | Charon: A Secure Cloud-of-Clouds System for Storing and Sharing Big DataabstractWe presentCharon, a cloud-backed storage system capable of storing and sharing big data in a secure, reliable, and efficient way using multiple cloud providers and storage repositories to comply with the legal requirements of sensitive personal data.Charonimplements three distinguishing features: (1) it does not require trust on any single entity, (2) it does not require any client-managed server, and (3) it efficiently deals with large files over a set of geo-dispersed storage services. Besides that, we developed a novel Byzantine-resilient data-centric leasing protocol to avoid write-write conflicts between clients accessing shared repositories. We evaluateCharonusing micro and application-based benchmarks simulating representative workflows from bioinformatics, a prominent big data domain. The results show that our unique design is not only feasible but also presents an end-to-end performance of up to$2.5\times$2.5×better than other cloud-backed solutions. Ricardo Mendes, Tiago Oliveira 0008, Vinicius Vielmo Cogo, Nuno Neves 0001, Alysson Neves Bessani |
IEEE Trans. Cloud Comput. | 5 |
| 2020 | From Byzantine Replication to Blockchain: Consensus is Only the BeginningabstractThe popularization of blockchains leads to a resurgence of interest in Byzantine Fault-Tolerant (BFT) state machine replication protocols. However, much of the work on this topic focuses on the underlying consensus protocols, with emphasis on their lack of scalability, leaving other subtle limitations unaddressed. These limitations are related to the effects of maintaining a durable blockchain instead of a write-ahead log and the requirement for reconfiguring the set of replicas in a decentralized way. We demonstrate these limitations using a digital coin blockchain application and BFT-SMaRt, a popular BFT replication library. We show how they can be addressed both at a conceptual level, in a protocol-agnostic way, and by implementing SMaRtChain, a blockchain platform based on BFT-SMaRt. SMaRtChain improves the performance of our digital coin application by a factor of eight when compared with a naive implementation on top of BFT-SMaRt. Moreover, SMaRtChain achieves a throughput 8x and 33x better than Tendermint and Hyperledger Fabric, respectively, when ensuring strong durability on its blockchain. Alysson Neves Bessani, Eduardo Alchieri, João Sousa 0002, André Oliveira 0002, Fernando Pedone |
DSN | 1 |
| 2020 | Smart Contracts on the MoveabstractBlockchain systems have received much attention and promise to revolutionize many services. Yet, despite their popularity, current blockchain systems exist in isolation, that is, they cannot share information. While interoperability is crucial for blockchain to reach widespread adoption, it is difficult to achieve due to differences among existing blockchain technologies. This paper presents a technique to allow blockchain interoperability. The core idea is to provide a primitive operation to developers so that contracts and objects can switch from one blockchain to another, without breaking consistency and violating key blockchain properties. To validate our ideas, we implemented our protocol in two popular blockchain clients that use the Ethereum virtual machine. We discuss how to build applications using the proposed protocol and show examples of applications based on real use cases that can move across blockchains. To analyze the system performance we use a real trace from one of the most popular Ethereum applications and replay it in a multi-blockchain environment. Enrique Fynn, Alysson Neves Bessani, Fernando Pedone |
DSN | 2 |
| 2020 | Follow the Blue Bird: A Study on Threat Data Published on Twitter
Fernando Alves, Ambrose Andongabo, Ilir Gashi, Pedro M. Ferreira 0001, Alysson Neves Bessani |
ESORICS (1) | 5 |
| 2020 | Towards end-to-end Cyberthreat Detection from Twitter using Multi-Task LearningabstractContinuously striving for cyberthreat awareness is an essential task to secure an IT infrastructure. Analysts must guarantee access to information on the most up-to-date cybersecurity events and threats. This monitoring process is often the job of a security information and event management system, which relies on the timeliness and relevance of its feeds. There has been growing interest in exploiting open source intelligence for this purpose, mainly due to its timeliness and volume. Social media sites such as Twitter, are capable of aggregating numerous cybersecurity-related sources and act as a stream of information that can be used to feed a cyberthreat intelligence platform. In this paper, we present a multi-task learning approach combining two Natural Language Processing tasks for cyberthreat intelligence. Our pipeline is capable of reading a stream of tweets from a set of Twitter accounts and, through a shared deep neural network architecture, simultaneously identify relevant cybersecurity-related content and extract indicators of compromise therein. We show that in comparison to the traditional independent tasks baseline, one of the tasks achieves a slight F1 score improvement, while the other task is able to maintain its performance. Thus, the proposed approach greatly simplifies the pipeline and the requirements for data and online model adaptation over time, without sacrificing functional performance. Nuno Dionísio, Fernando Alves, Pedro M. Ferreira 0001, Alysson Neves Bessani |
IJCNN | 4 |
| 2019 | Cyberthreat Detection from Twitter using Deep Neural NetworksabstractTo be prepared against cyberattacks, most organizations resort to security information and event management systems to monitor their infrastructures. These systems depend on the timeliness and relevance of the latest updates, patches and threats provided by cyberthreat intelligence feeds. Open source intelligence platforms, namely social media networks such as Twitter, are capable of aggregating a vast amount of cybersecurity-related sources. To process such information streams, we require scalable and efficient tools capable of identifying and summarizing relevant information for specified assets. This paper presents the processing pipeline of a novel tool that uses deep neural networks to process cybersecurity information received from Twitter. A convolutional neural network identifies tweets containing security-related information relevant to assets in an IT infrastructure. Then, a bidirectional long short-term memory network extracts named entities from these tweets to form a security alert or to fill an indicator of compromise. The proposed pipeline achieves an average 94% true positive rate and 91% true negative rate for the classification task and an average F1-score of 92% for the named entity recognition task, across three case study infrastructures. Nuno Dionísio, Fernando Alves, Pedro M. Ferreira 0001, Alysson Neves Bessani |
IJCNN | 4 |
| 2019 | Lazarus: Automatic Management of Diversity in BFT SystemsabstractA long-standing promise of Byzantine Fault-Tolerant (BFT) replication is to maintain the service correctness despite the presence of malicious failures. The key challenge here is how to ensure replicas fail independently, i.e., avoid that a single attack compromises more than f replicas at once. The obvious answer for this is the use of diverse replicas, but most works in BFT simply assume such diversity without supporting mechanisms to substantiate this assumption. Lazarus is a control plane for managing the deployment and execution of diverse replicas in BFT systems. Lazarus continuously monitors the current vulnerabilities of the system replicas (reported in security feeds such as NVD and ExploitDB) and employs a metric to measure the risk of having a common weakness in the replicas set. If such risk is high, the set of replicas is reconfigured. Our evaluation shows that the devised strategy reduces the number of executions where the system becomes compromised and that our prototype supports the execution of full-fledged BFT systems in diverse configurations with 17 OS versions, reaching a performance close to a homogeneous bare-metal setup. Miguel Garcia 0002, Alysson Neves Bessani, Nuno Neves 0001 |
Middleware | 2 |
| 2019 | SLICER: Safe Long-Term Cloud Event ArchivalabstractSecurity Information and Event Management (SIEM) systems have been adopted by organizations to enable holistic monitoring of malicious activities in their IT infrastructures. SIEMs receive events from several devices of the organization's IT infrastructure (e.g., servers, firewalls, IDS), correlate these events, and present reports for security analysts. Given the large number of events collected by SIEMs, it is costly to store such data for long periods. Besides, since organizations store a relatively limited time-frame of events, the forensic analysis capabilities severely become reduced. We present SL I CER an archival system for long-term storage that makes use of multi-cloud storage to guarantee data security, low cost and high scalability, and ensures cost-effectiveness by grouping events in blocks and using indexing techniques to recover them. The system was evaluated using a real dataset, and the results show that it is significantly more cost-efficient than competing alternatives. Adriano Serckumecka, Iberia Medeiros, Bernardo Ferreira, Alysson Neves Bessani |
PRDC | 4 |
| 2019 | Resilient Wide-Area Byzantine Consensus Using Adaptive Weighted ReplicationabstractIn geo-replicated systems, the heterogeneous latencies of connections between replicas limit the system's ability to achieve consensus fast. State machine replication (SMR) protocols can be refined for their deployment in wide-area networks by using a weighting scheme for active replication that employs additional replicas and assigns higher voting power to faster replicas. Utilizing more variability in quorum formation allows replicas to swiftly proceed to subsequent protocol stages, thus decreasing consensus latency. However, if network conditions vary during the system's lifespan or faults occur, the system needs a solution to autonomously adjust to new conditions. We incorporate the idea of self-optimization into geographically distributed, weighted replication by introducing AWARE, an automated and dynamic voting weight tuning and leader positioning scheme. AWARE measures replica-to-replica latencies and uses a prediction model, thriving to minimize the system's consensus latency. In experiments using different Amazon EC2 regions, AWARE dynamically optimizes consensus latency by self-reliantly finding a fast weight configuration yielding latency gains observed by clients located across the globe. Christian Berger 0006, Hans P. Reiser, João Sousa 0002, Alysson Neves Bessani |
SRDS | 4 |
| 2019 | Low-Cost Serverless SIEM in the CloudabstractSecurity systems such as the Security Information and Event Management (SIEMs) have been used to monitor logs and correlate data to quickly detect and respond to incidents. Despite their advantages, SIEMs are expensive to deploy and maintain, requiring extra budget and specialized staff. Another concern is the event retention period, which events are stored for a short period of time, missing important information about how threats may have affected the company infrastructure in the past. This thesis aims to improve these issues by using low-cost cloud services to correlate and store security events. We will investigate techniques to index, compress and store events in the cloud in a cost-efficient and safe way for a long time. We will create a cloud correlation engine using a serverless platform, such as Amazon Lambda. This approach can minimize the complexity of managing SIEMs in place, charging the customer only for the time actually spent processing events. Finally, we will integrate the storage and correlation engine into a cloud SIEM, providing also a monitoring tool, building a complete and innovative low-cost cloud-based security monitoring solution. Adriano Serckumecka, Iberia Medeiros, Alysson Neves Bessani |
SRDS | 3 |
| 2019 | BigFlow: Real-time and reliable anomaly-based intrusion detection for high-speed networks
Eduardo Viegas 0001, Altair Olivo Santin, Alysson Neves Bessani, Nuno Neves 0001 |
Future Gener. Comput. Syst. | 3 |
| 2018 | Byzantine Fault-Tolerant Atomic MulticastabstractAtomic multicast is an important building block in the architecture of scalable and highly available services. Atomic multicast reliably propagates and orders messages addressed to one or more groups of processes. Despite the large body of literature on atomic multicast, existing protocols target benign failures. This paper presents ByzCast, the first Byzantine Fault-Tolerant atomic multicast. Byzantine Fault Tolerance has become increasingly appealing as services can be deployed in inexpensive hardware (e.g., cloud environments) and new applications (e.g., blockchain) become more sensitive to malicious behavior. ByzCast has two important characteristics: it was designed to use existing BFT abstractions and it scales with the number of groups, for messages addressed to a single group. We discuss the design of ByzCast and how it can be optimized for particular workloads. Besides proposing a novel atomic multicast protocol, we extensively assess its performance experimentally. Paulo R. Coelho, Tarcisio Ceolin Junior, Alysson Neves Bessani, Fernando Luís Dotti, Fernando Pedone |
DSN | 3 |
| 2018 | On the Challenges of Building a BFT SCADAabstractIn the last decade, Industrial Control Systems have been a frequent target of cyber attacks. As the current defenses sometimes fail to prevent more sophisticated threats, it is necessary to add advanced protection mechanisms to guarantee that correct operation is (always) maintained. In this work, we describe a Supervisory Control and Data Acquisition (SCADA) system enhanced with Byzantine fault-tolerant (BFT) techniques. We document the challenges of building such system from a "traditional" non-BFT solution. This effort resulted in a prototype that integrates the Eclipse NeoSCADA and the BFT-SMaRt open-source projects. We also present an evaluation comparing Eclipse NeoSCADA with our BFT solution. Although the results show a decrease in performance, our solution is still more than enough to accommodate realistic workloads. André Nogueira, Miguel Garcia 0002, Alysson Neves Bessani, Nuno Neves 0001 |
DSN | 3 |
| 2018 | A Byzantine Fault-Tolerant Ordering Service for the Hyperledger Fabric Blockchain PlatformabstractHyperledger Fabric is a flexible operating system for permissioned blockchains designed for business applications beyond the basic digital coin addressed by Bitcoin and other existing networks. A key property of this system is its extensibility, and in particular the support for multiple ordering services for building the blockchain. However, version 1 was launched in 2017 without an implementation of a Byzantine fault-tolerant (BFT) ordering service. To overcome this limitation, we designed, implemented, and evaluated a BFT ordering service for this system on top of the BFT-SMART state machine replication/consensus library, with optimizations for wide-area deployment. Our results show that our ordering service can process up to ten thousand transactions per second and write a transaction irrevocably in the blockchain in half a second, even with peers spread across different continents. João Sousa 0002, Alysson Neves Bessani, Marko Vukolic |
DSN | 2 |
| 2018 | Detecting Malicious Web Scraping Activity: A Study with Diverse DetectorsabstractWe present results on the use of diverse monitoring tools for the detection of malicious web scraping activity. We have carried out an analysis of a real dataset of Apache HTTP Access logs for an e-commerce application provided by a large multinational IT provider for the global travel and tourism industry. Two tools have been used to detect scraping activities based on the HTTP requests: a commercial tool, and an in-house tool called Arcane. We show the benefits that can be achieved through the use of both systems, in terms of overall sensitivity and specificity, and we discuss the potential sources of diversity between the tool's alert patterns. Zayani Dabbabi, Miruna-Mihaela Mironescu, Olivier Thonnard, Alysson Neves Bessani, Frances V. Buontempo, Ilir Gashi |
PRDC | 5 |
| 2018 | Knowledge Connectivity Requirements for Solving Byzantine Consensus with Unknown ParticipantsabstractConsensus is a fundamental building block to solve many practical problems that appear on reliable distributed systems. In spite of the fact that consensus is being widely studied in the context of standard networks, few studies have been conducted in order to solve it in dynamic and self-organizing systems characterized by unknown networks. While in a standard network the set of participants is static and known, in an unknown network, such set and number of participants are previously unknown. This work studies the problem of Byzantine Fault-Tolerant Consensus with Unknown Participants, namely BFT-CUP. This new problem aims at solving consensus in unknown networks with the additional requirement that participants in the system may behave maliciously. It presents the necessary and sufficient knowledge connectivity conditions in order to solve BFT-CUP under minimal synchrony requirements. In this way, it proposes algorithms that are shown to be optimal in terms of synchrony and knowledge connectivity among participants in the system. Eduardo Alchieri, Alysson Neves Bessani, Fabíola Greve, Joni da Silva Fraga |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2018 | SieveQ: A Layered BFT Protection System for Critical ServicesabstractFirewalls play a crucial role in assuring the security of today's critical infrastructures, forming a first line of defense by being placed strategically at the front-end of the networks. Sometimes, however, they have exploitable weaknesses, allowing an adversary to bypass them in different ways. Therefore, their design should include improved resilience capabilities to allow them to operate correctly in highly adverse environments. This paper proposes SieveQ, a message queue service that protects and regulates the access to critical systems, in a way similar to an application-level firewall. SieveQ achieves fault and intrusion tolerance by employing an architecture based on two filtering layers, enabling efficient removal of invalid messages at early stages and decreasing the costs associated with Byzantine Fault-Tolerant (BFT) replication of previous solutions. Our experimental evaluation shows that SieveQ improves existing replicated-firewalls resilience in the presence of corrupted messages by faulty nodes. Furthermore, it accommodates high loads, as it is able to handle sixteen times more security events per second than what was processed by the Security Information and Event Management (SIEM) infrastructure employed in the 2012 Summer Olympic Games. Miguel Garcia 0002, Nuno Neves 0001, Alysson Neves Bessani |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2017 | A Resilient Stream Learning Intrusion Detection Mechanism for Real-Time Analysis of Network TrafficabstractThe number of novel attacks observed in networked systems increases every day. Due to the large amount of generated data over the network, its storage for further analysis may not be feasible. Moreover, current attacks are becoming more sophisticated, as the attackers are attempting to evade traditional intrusion detection mechanisms by perverting their properties. This paper presents a novel real-time (ongoing) network traffic measurement approach that supports resilient analysis for stream learning intrusion detection. The network data is grouped at runtime according to its characteristics, while each network traffic flow is discretized at regular time intervals. Each network flow is classified by a multi-view stream learning classifiers pool, defining the network flow class through a majority voting approach. The proposal is able to provide resiliency to the classifiers even for the detection of unknown attacks. The evaluation tests for the average operation point (25 views) provides an increase in the system resilience to adversarial attacks of 22 % when compared to traditional approaches. Moreover, in the scalability experiments with a 10-node (single core each) cluster testbed, the network flow measurement solution (1 view) reached 1.38 Gbps throughput, while the proposed resilient stream learning intrusion detection with 25 views reached a throughput of 1.19 Gbps. Eduardo Viegas 0001, Altair Olivo Santin, Nuno Neves 0001, Alysson Neves Bessani, Vilmar Abreu |
GLOBECOM | 4 |
| 2017 | Ginja: one-dollar cloud-based disaster recovery for databasesabstractDisaster Recovery (DR) is a crucial feature to ensure availability and data protection in modern information systems. A common DR approach requires the replication of services in a set of virtual machines running in the cloud as backups. This leads to considerable monetary costs and managing efforts to keep such cloud VMs. We present Ginja, a DR solution for transactional database management systems (DBMS) that uses only cloud storage services such as Amazon S3. Ginja works at file-system level to efficiently capture and replicate data updates to a remote cloud storage service, achieving three important goals: (1) reduces the costs for maintaining a cloud-based DR to less than one dollar per month for relevant databases' sizes and workloads (up to 222 x less than the traditional approach of having a DBMS replica in a cloud VM); (2) allows a precise control of the operational costs, durability and performance trade-offs; and (3) introduces a small performance overhead to the DBMS (e.g., less than 5% overhead for the TPC-C workload with ≈ 10 seconds of data loss in case of disasters). Joel Alcântara, Tiago Oliveira 0008, Alysson Neves Bessani |
Middleware | 3 |
| 2017 | Efficient and Modular Consensus-Free Reconfiguration for Fault-Tolerant StorageabstractQuorum systems are useful tools for implementing consistent and available storage in the presence of failures. These systems usually comprise a static set of servers that provide a fault-tolerant read/write register accessed by a set of clients. We consider a dynamic variant of these systems and propose FreeStore, a set of fault-tolerant protocols that emulates a register in dynamic asynchronous systems in which processes are able to join/leave the servers set during the execution. These protocols use a new abstraction called view generators, that captures the agreement requirements of reconfiguration and can be implemented in different system models with different properties. Particularly interesting, we present a reconfiguration protocol that is modular, efficient, consensus-free and loosely coupled with read/write protocols, improving the overall system performance. Eduardo Alchieri, Alysson Neves Bessani, Fabíola Greve, Joni da Silva Fraga |
OPODIS | 2 |
| 2017 | Elastic State Machine ReplicationabstractState machine replication (SMR) is a fundamental technique for implementing stateful dependable systems. A key limitation of this technique is that the performance of a service does not scale with the number of replicas hosting it. Some works have shown that such scalability can be achieved by partitioning the state of the service into shards. The few SMR-based systems that support dynamic partitioning implement ad-hoc state transfer protocols and perform scaling operations as background tasks to minimize the performance degradation during reconfigurations. In this work we go one step further and propose a modular partition transfer protocol for creating and destroying such partitions at runtime, thus providing fast elasticity for crash and Byzantine fault tolerant replicated state machines and making them more suitable for cloud systems. André Nogueira, António Casimiro, Alysson Neves Bessani |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2016 | Exploring Key-Value Stores in Multi-Writer Byzantine-Resilient Register EmulationsabstractResilient register emulation is a fundamental technique to implement dependable storage and distributed systems. In data-centric models, where servers are modeled as fail-prone base objects, classical solutions achieve resilience by using fault-tolerant quorums of read-write registers or read-modify-write objects. Recently, this model has attracted renewed interest due to the popularity of cloud storage providers (e.g., Amazon S3), that can be modeled as key-value stores (KVSs) and combined for providing secure and dependable multi-cloud storage services. In this paper we present three novel wait-free multi-writer multi-reader regular register emulations on top of Byzantine-prone KVSs. We implemented and evaluated these constructions using five existing cloud storage services and show that their performance matches or surpasses existing data-centric register emulations. Tiago Oliveira 0008, Ricardo Mendes, Alysson Neves Bessani |
OPODIS | 3 |
| 2016 | JITeR: Just-in-time application-layer routing
Alysson Neves Bessani, Nuno Neves 0001, Paulo Veríssimo, Wagner Saback Dantas, Alexandre Fonseca, Pedro Luz, Miguel Correia 0001 |
Comput. Networks | 1 |
| 2015 | Extensible distributed coordinationabstractMost services inside a data center are distributed systems requiring coordination and synchronization in the form of primitives like distributed locks and message queues. We argue that extensibility is a crucial feature of the coordination infrastructures used in these systems. Without the ability to extend the functionality of coordination services, applications might end up using sub-optimal coordination algorithms, possibly leading to low performance. Adding extensibility, however, requires mechanisms that constrain extensions to be able to make reasonable security and performance guarantees. We propose a scheme that enables extensions to be introduced and removed dynamically in a secure way. To avoid performance overheads due to poorly designed extensions, it constrains the access of extensions to resources. Evaluation results for extensible versions of ZooKeeper and DepSpace show that it is possible to increase the throughput of a distributed queue by more than an order of magnitude (17x for ZooKeeper, 24x for DepSpace) while keeping the underlying coordination kernel small. Tobias Distler, Christopher Bahn, Alysson Neves Bessani, Frank Fischer 0004, Flavio Paiva Junqueira |
EuroSys | 3 |
| 2015 | Separating the WHEAT from the Chaff: An Empirical Design for Geo-Replicated State MachinesabstractState machine replication is a fundamental technique for implementing consistent fault-tolerant services. In the last years, several protocols have been proposed for improving the latency of this technique when the replicas are deployed in geographically-dispersed locations. In this work we evaluate some representative optimizations proposed in the literature by implementing them on an open-source state machine replication library and running the experiments in geographically-diverse PlanetLab nodes and Amazon EC2 regions. Interestingly, our results show that some optimizations widely used for improving the latency of geo-replicated state machines do not bring significant benefits, while others - not yet considered in this context - are very effective. Based on this evaluation, we propose WHEAT, a configurable crash and Byzantine fault-tolerant state machine replication library that uses the optimizations we observed as most effective in reducing SMR latency. WHEAT employs novel voting assignment schemes that, by using few additional spare replicas, enables the system to make progress without needing to access a majority of replicas. Our evaluation shows that a WHEAT system deployed in several Amazon EC2 regions presents a median latency up to 56% lower than a "normal" SMR protocol. João Sousa 0002, Alysson Neves Bessani |
SRDS | 2 |
| 2014 | State Machine Replication for the Masses with BFT-SMARTabstractThe last fifteen years have seen an impressive amount of work on protocols for Byzantine fault-tolerant (BFT) state machine replication (SMR). However, there is still a need for practical and reliable software libraries implementing this technique. BFT-SMART is an open-source Java-based library implementing robust BFT state machine replication. Some of the key features of this library that distinguishes it from similar works (e.g., PBFT and UpRight) are improved reliability, modularity as a first-class property, multicore-awareness, reconfiguration support and a flexible programming interface. When compared to other SMR libraries, BFT-SMART achieves better performance and is able to withstand a number of real-world faults that previous implementations cannot. Alysson Neves Bessani, João Sousa 0002, Eduardo Alchieri |
DSN | 1 |
| 2014 | Towards Secure and Dependable Authentication and Authorization InfrastructuresabstractWe propose a resilience architecture for improving the security and dependability of authentication and authorization infrastructures, in particular the ones based on RADIUS and OpenID. This architecture employs intrusion-tolerant replication, trusted components and entrusted gateways to provide survivable services ensuring compatibility with standard protocols. The architecture was instantiated in two prototypes, one implementing RADIUS and another implementing OpenID. These prototypes were evaluated in fault-free executions, under faults, under attack, and in diverse computing environments. The results show that, beyond being more secure and dependable, our prototypes are capable of achieving the performance requirements of enterprise environments, such as IT infrastructures with more than 400k users. Diego Kreutz, Alysson Neves Bessani, Eduardo Feitosa, Hugo Cunha |
PRDC | 2 |
| 2014 | SCFS: A Shared Cloud-backed File System
Alysson Neves Bessani, Ricardo Mendes, Tiago Oliveira 0008, Nuno Neves 0001, Miguel Correia 0001, Marcelo Pasin, Paulo Veríssimo |
USENIX ATC | 1 |
| 2014 | Analysis of operating system diversity for intrusion toleranceabstractOne of the key benefits of using intrusion-tolerant systems is the possibility of ensuring correct behavior in the presence of attacks and intrusions. These security gains are directly dependent on the components exhibiting failure diversity. To what extent failure diversity is observed in practical deployment depends on how diverse are the components that constitute the system. In this paper, we present a study with operating system's (OS's) vulnerability data from the NIST National Vulnerability Database (NVD). We have analyzed the vulnerabilities of 11 different OSs over a period of 18 years, to check how many of these vulnerabilities occur in more than one OS. We found this number to be low for several combinations of OSs. Hence, although there are a few caveats on the use of NVD data to support definitive conclusions, our analysis shows that by selecting appropriate OSs, one can preclude (or reduce substantially) common vulnerabilities from occurring in the replicas of the intrusion-tolerant system. Copyright © 2013 John Wiley & Sons, Ltd. Miguel Garcia 0002, Alysson Neves Bessani, Ilir Gashi, Nuno Neves 0001, Rafael R. Obelheiro |
Softw. Pract. Exp. | 2 |
| 2013 | FITCH: Supporting Adaptive Replicated Services in the Cloud
Vinicius Vielmo Cogo, André Nogueira, João Sousa 0002, Marcelo Pasin, Hans P. Reiser, Alysson Neves Bessani |
DAIS | 6 |
| 2013 | On the Efficiency of Durable State Machine Replication
Alysson Neves Bessani, Marcel Santos, João Felix, Nuno Neves 0001, Miguel Correia 0001 |
USENIX ATC | 1 |
| 2013 | Efficient Byzantine Fault-ToleranceabstractWe present two asynchronous Byzantine fault-tolerant state machine replication (BFT) algorithms, which improve previous algorithms in terms of several metrics. First, they require only 2f+1 replicas, instead of the usual 3f+1. Second, the trusted service in which this reduction of replicas is based is quite simple, making a verified implementation straightforward (and even feasible using commercial trusted hardware). Third, in nice executions the two algorithms run in the minimum number of communication steps for nonspeculative and speculative algorithms, respectively, four and three steps. Besides the obvious benefits in terms of cost, resilience and management complexity-fewer replicas to tolerate a certain number of faults-our algorithms are simpler than previous ones, being closer to crash fault-tolerant replication algorithms. The performance evaluation shows that, even with the trusted component access overhead, they can have better throughput than Castro and Liskov's PBFT, and better latency in networks with nonnegligible communication delays. Giuliana Santos Veronese, Miguel Correia 0001, Alysson Neves Bessani, Lau Cheuk Lung, Paulo Veríssimo |
IEEE Trans. Computers | 3 |
| 2013 | On the Performance of Byzantine Fault-Tolerant MapReduceabstractMapReduce is often used for critical data processing, e.g., in the context of scientific or financial simulation. However, there is evidence in the literature that there are arbitrary (or Byzantine) faults that may corrupt the results of MapReduce without being detected. We present a Byzantine fault-tolerant MapReduce framework that can run in two modes: nonspeculative and speculative. We thoroughly evaluate experimentally the performance of these two versions of the framework, showing that they use around twice more resources than Hadoop MapReduce, instead of the three times more of alternative solutions. We believe this cost is acceptable for many critical applications. Pedro A. R. S. Costa, Marcelo Pasin, Alysson Neves Bessani, Miguel Correia 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2013 | DepSky: Dependable and Secure Storage in a Cloud-of-CloudsabstractThe increasing popularity of cloud storage services has lead companies that handle critical data to think about using these services for their storage needs. Medical record databases, large biomedical datasets, historical information about power systems and financial data are some examples of critical data that could be moved to the cloud. However, the reliability and security of data stored in the cloud still remain major concerns. In this work we present DepSky, a system that improves the availability, integrity, and confidentiality of information stored in the cloud through the encryption, encoding, and replication of the data on diverse clouds that form a cloud-of-clouds. We deployed our system using four commercial clouds and used PlanetLab to run clients accessing the service from different countries. We observed that our protocols improved the perceived availability, and in most cases, the access latency, when compared with cloud providers individually. Moreover, the monetary costs of using DepSky in this scenario is at most twice the cost of using a single cloud, which is optimal and seems to be a reasonable cost, given the benefits. Alysson Neves Bessani, Miguel Correia 0001, Bruno Quaresma, Fernando André, Paulo Sousa 0001 |
ACM Trans. Storage | 1 |
| 2012 | On the Feasibility of Byzantine Fault-Tolerant MapReduce in Clouds-of-CloudsabstractMapReduce is a framework for processing large data sets largely used in cloud computing. MapReduce implementations like Hadoop can tolerate crashes and file corruptions, but there is evidence that general arbitrary faults do occur and can affect the correctness of job executions. Furthermore, many individual cloud outages have been reported, raising concerns about depending on a single cloud. We present a MapReduce runtime that tolerates arbitrary faults and runs in a set of clouds at a reasonable cost in terms of computation and execution time. The main challenge is to avoid sending through the internet the huge amount of data that would normally be exchanged between map and reduce tasks. Miguel Correia 0001, Pedro A. R. S. Costa, Marcelo Pasin, Alysson Neves Bessani, Fernando M. V. Ramos, Paulo Veríssimo |
SRDS | 4 |
| 2012 | Brief Announcement: Decoupled and Consensus-Free Reconfiguration for Fault-Tolerant Storage
Eduardo Alchieri, Alysson Neves Bessani, Fabíola Greve, Joni da Silva Fraga |
DISC | 2 |
| 2011 | Byzantine Fault-Tolerant MapReduce: Faults are Not Just CrashesabstractMapReduce is often used to run critical jobs such as scientific data analysis. However, evidence in the literature shows that arbitrary faults do occur and can probably corrupt the results of MapReduce jobs. MapReduce runtimes like Hadoop tolerate crash faults, but not arbitrary or Byzantine faults. We present a MapReduce algorithm and prototype that tolerate these faults. An experimental evaluation shows that the execution of a job with our algorithms uses twice the resources of the original Hadoop, instead of the 3 or 4 times more that would be achieved with the direct application of common Byzantine fault-tolerance paradigms. We believe this cost is acceptable for critical applications that require that level of fault tolerance. Pedro A. R. S. Costa, Marcelo Pasin, Alysson Neves Bessani, Miguel Correia 0001 |
CloudCom | 3 |
| 2011 | 5th Workshop on Recent Advances in Intrusion-Tolerant Systems WRAITS 2011abstractThe 5thWorkshop on Recent Advances in Intrusion-Tolerant Systems, held in conjunction with DSN 2011, aims to continue the collaborative discourse on the challenges of building intrusion-tolerant systems and innovative ideas to address them. Alysson Neves Bessani, Partha P. Pal |
DSN | 1 |
| 2011 | OS diversity for intrusion tolerance: Myth or reality?abstractOne of the key benefits of using intrusion-tolerant systems is the possibility of ensuring correct behavior in the presence of attacks and intrusions. These security gains are directly dependent on the components exhibiting failure diversity. To what extent failure diversity is observed in practical deployment depends on how diverse are the components that constitute the system. In this paper we present a study with operating systems (OS) vulnerability data from the NIST National Vulnerability Database. We have analyzed the vulnerabilities of 11 different OSes over a period of roughly 15 years, to check how many of these vulnerabilities occur in more than one OS. We found this number to be low for several combinations of OSes. Hence, our analysis provides a strong indication that building a system with diverse OSes may be a useful technique to improve its intrusion tolerance capabilities. Miguel Garcia 0002, Alysson Neves Bessani, Ilir Gashi, Nuno Neves 0001, Rafael R. Obelheiro |
DSN | 2 |
| 2011 | DepSky: dependable and secure storage in a cloud-of-cloudsabstractThe increasing popularity of cloud storage services has lead companies that handle critical data to think about using these services for their storage needs. Medical record databases, power system historical information and financial data are some examples of critical data that could be moved to the cloud. However, the reliability and security of data stored in the cloud still remain major concerns. In this paper we present DEPSKY, a system that improves the availability, integrity and confidentiality of information stored in the cloud through the encryption, encoding and replication of the data on diverse clouds that form a cloud-of-clouds. We deployed our system using four commercial clouds and used PlanetLab to run clients accessing the service from different countries. We observed that our protocols improved the perceived availability and, in most cases, the access latency when compared with cloud providers individually. Moreover, the monetary costs of using DEPSKY on this scenario is twice the cost of using a single cloud, which is optimal and seems to be a reasonable cost, given the benefits. Alysson Neves Bessani, Miguel Correia 0001, Bruno Quaresma, Fernando André, Paulo Sousa 0001 |
EuroSys | 1 |
| 2010 | Highly Available Intrusion-Tolerant Services with Proactive-Reactive RecoveryabstractIn the past, some research has been done on how to use proactive recovery to build intrusion-tolerant replicated systems that are resilient to any number of faults, as long as recoveries are faster than an upper bound on fault production assumed at system deployment time. In this paper, we propose a complementary approach that enhances proactive recovery with additional reactive mechanisms giving correct replicas the capability of recovering other replicas that are detected or suspected of being compromised. One key feature of our proactive-reactive recovery approach is that, despite recoveries, it guarantees the availability of a minimum number of system replicas necessary to sustain correct operation of the system. We design a proactive-reactive recovery service based on a hybrid distributed system model and show, as a case study, how this service can effectively be used to increase the resilience of an intrusion-tolerant firewall adequate for the protection of critical infrastructures. Paulo Sousa 0001, Alysson Neves Bessani, Miguel Correia 0001, Nuno Neves 0001, Paulo Veríssimo |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2009 | Intrusion-tolerant self-healing devices for critical infrastructure protectionabstractCritical infrastructures like the power grid are essentially physical processes controlled by electronic devices. In the last decades, these electronic devices started to be controlled remotely through commodity computers, often directly or indirectly connected to the Internet. Therefore, many of these systems are currently exposed to threats similar to those endured by normal computer-based networks on the Internet, but the impact of failure of the former can be much higher to society. This paper presents a demonstration of a family of protection devices for critical information infrastructures developed in the context of the EU Crutial project. These devices, called Crutial information switches (CIS), enforce sophisticated access control policies of incoming/outgoing traffic, and are themselves designed with a range of different levels of intrusion tolerance and self healing, to serve different resilience requirements. Paulo Sousa 0001, Alysson Neves Bessani, Wagner Saback Dantas, Fabio Souto, Miguel Correia 0001, Nuno Neves 0001 |
DSN | 2 |
| 2009 | Spin One's Wheels? Byzantine Fault Tolerance with a Spinning PrimaryabstractMost Byzantine fault-tolerant state machine replication (BFT) algorithms have a primary replica that is in charge of ordering the clients requests. Recently it was shown that this dependence allows a faulty primary to degrade the performance of the system to a small fraction of what the environment allows. In this paper we present Spinning, a novel BFT algorithm that mitigates such performance attacks by changing the primary after every batch of pending requests is accepted for execution. This novel mode of operation deals with those attacks at a much lower cost than previous solutions, maintaining a throughput equal or better to the algorithm that is usually consider to be the baseline in the area, Castro and Liskov's PBFT. Giuliana Santos Veronese, Miguel Correia 0001, Alysson Neves Bessani, Lau Cheuk Lung |
SRDS | 3 |
| 2009 | An Efficient Byzantine-Resilient Tuple SpaceabstractOpen distributed systems are typically composed by an unknown number of processes running in heterogeneous hosts. Their communication often requires tolerance to temporary disconnections and security against malicious actions. Tuple spaces are a well-known coordination model for this kind of systems. They can support communication that is decoupled both in time and space. There are currently several implementations of distributed fault-tolerant tuple spaces but they are not Byzantine-resilient, i.e., they do not provide a correct service if some replicas are attacked and start to misbehave. This paper presents an efficient implementation of a linearizable Byzantine fault-tolerant Tuple Space (LBTS) that uses a novel Byzantine quorum systems replication technique in which most operations are implemented by quorum protocols while stronger operations are implemented by more expensive protocols based on consensus. LBTS is linearizable and wait-free, showing interesting performance gains when compared to a similar construction based on state machine replication. Alysson Neves Bessani, Miguel Correia 0001, Joni da Silva Fraga, Lau Cheuk Lung |
IEEE Trans. Computers | 1 |
| 2009 | Sharing Memory between Byzantine Processes Using Policy-Enforced Tuple SpacesabstractDespite the large amount of Byzantine fault-tolerant algorithms for message-passing systems designed through the years, only recently algorithms for the coordination of processes subject to Byzantine failures using shared memory have appeared. This paper presents a new computing model in which shared memory objects are protected by fine-grained access policies, and a new shared memory object, the Policy-Enforced Augmented Tuple Space (PEATS). We show the benefits of this model by providing simple and efficient consensus algorithms. These algorithms are much simpler and requires less shared memory operations, using also less memory bits than previous algorithms based on ACLs and sticky bits. We also prove that PEATS objects are universal, i.e., that they can be used to implement any other shared memory object, and present lock-free and wait-free universal constructions. Alysson Neves Bessani, Miguel Correia 0001, Joni da Silva Fraga, Lau Cheuk Lung |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2008 | DepSpace: a byzantine fault-tolerant coordination serviceabstractThe tuple space coordination model is one of the most interesting coordination models for open distributed systems due to its space and time decoupling and its synchronization power. Several works have tried to improve the dependability of tuple spaces through the use of replication for fault tolerance and access control for security. However, many practical applications in the Internet require both fault tolerance and security. This paper describes the design and implementation of DepSpace, a Byzantine fault-tolerant coordination service that provides a tuple space abstraction. The service offered by DepSpace is secure, reliable and available as long as less than a third of service replicas are faulty. Moreover, the content-addressable confidentiality scheme developed for DepSpace bridges the gap between Byzantine fault-tolerant replication and confidentiality of replicated data and can be used in other systems that store critical data. Alysson Neves Bessani, Eduardo Alchieri, Miguel Correia 0001, Joni da Silva Fraga |
EuroSys | 1 |
| 2008 | A Dependable Infrastructure for Cooperative Web Services CoordinationabstractA current trend in the web services community is to define coordination mechanisms to execute collaborative tasks involving multiple organizations. Following this tendency, this work presents a dependable (i.e., intrusion-tolerant) infrastructure for cooperative web services coordination that is based on the tuple space coordination model. This infrastructure provides decoupled communication and implements several security mechanisms that allow reliable coordination even in presence of malicious components.This work also investigates the costs related to the use of this infrastructure and possible web service applications that can benefit from it. Eduardo Alchieri, Alysson Neves Bessani, Joni da Silva Fraga |
ICWS | 2 |
| 2008 | Byzantine Consensus with Unknown Participants
Eduardo Alchieri, Alysson Neves Bessani, Joni da Silva Fraga, Fabíola Greve |
OPODIS | 2 |
| 2008 | On Byzantine generals with alternative plans
Miguel Correia 0001, Alysson Neves Bessani, Paulo Veríssimo |
J. Parallel Distributed Comput. | 2 |
| 2007 | Decoupled Quorum-Based Byzantine-Resilient Coordination in Open Distributed SystemsabstractOpen distributed systems are typically composed by an unknown number of processes running in heterogeneous hosts. Their communication often requires tolerance to temporary disconnections and security against malicious actions. Tuple spaces are a well-known coordination model for this sort of systems. They can support communication that is decoupled both in time and space. There are currently several implementations of distributed fault-tolerant tuple spaces but they are not Byzantine-resilient, i.e., they do not provide a correct service if some replicas are attacked and start to misbehave. This paper presents an efficient implementation of LBTS, a linearizable Byzantine fault-tolerant tuple space. LBTS uses a novel Byzantine quorum systems replication technique in which most operations are implemented by quorum protocols while stronger operations are implemented by more expensive protocols based on consensus. LBTS is linearizable and wait-free, showing interesting performance gains when compared to a similar construction based on state machine replication. Alysson Neves Bessani, Miguel Correia 0001, Joni da Silva Fraga, Lau Cheuk Lung |
NCA | 1 |
| 2007 | Resilient Intrusion Tolerance through Proactive and Reactive RecoveryabstractPrevious works have studied how to use proactive recovery to build intrusion-tolerant replicated systems that are resilient to any number of faults, as long as recoveries are faster than an upper-bound on fault production assumed at system deployment time. In this paper, we propose a complementary approach that combines proactive recovery with services that allow correct replicas to react and recover replicas that they detect or suspect to be compromised. One key feature of our proactive-reactive recovery approach is that, despite recoveries, it guarantees the availability of the minimum amount of system replicas necessary to sustain system's correct operation. We design a proactive-reactive recovery service based on a hybrid distributed system model and show, as a case study, how this service can effectively be used to augment the resilience of an intrusion-tolerant firewall adequate for the protection of critical infrastructures. Paulo Sousa 0001, Alysson Neves Bessani, Miguel Correia 0001, Nuno Neves 0001, Paulo Veríssimo |
PRDC | 2 |
| 2007 | Evaluating Byzantine Quorum SystemsabstractReplication is a mechanism extensively used to guarantee the availability and good performance of data storage services. Byzantine Quorum Systems (BQS) have been proposed as a solution to guarantee the consistency of that kind of services, even if some of the replicas fail arbitrarily. Many BQS have been proposed recently, but comparing their performance is not simple. In fact, it has been shown that theoretical metrics like the number of steps or communication rounds say as much about the practical performance of distributed algorithms as they hide. This paper presents a comparative evaluation of several BQS algorithms in the literature. The evaluation is based both on experiments and simulations. For that purpose, a framework for evaluating BQS called BQSNeko was developed. The results of the evaluation allow a better understanding of the algorithms and the tradeoffs involved. Wagner Saback Dantas, Alysson Neves Bessani, Joni da Silva Fraga, Miguel Correia 0001 |
SRDS | 2 |
| 2007 | When 3f+1 Is Not Enough: Tradeoffs for Decentralized Asynchronous Byzantine Consensus
Alysson Neves Bessani, Miguel Correia 0001, Henrique Moniz, Nuno Neves 0001, Paulo Veríssimo |
DISC | 1 |
| 2006 | Sharing Memory between Byzantine Processes using Policy-Enforced Tuple SpacesabstractDespite the large amount of Byzantine fault-tolerant algorithms for message-passing systems designed through the years, only recently algorithms for the coordination of processes subject to Byzantine failures using shared memory have appeared. This paper presents a new computing model in which shared memory objects are protected by fine-grained access policies, and a new shared memory object, the policy-enforced augmented tuple space (PEATS). We show the benefits of this model by providing simple and efficient consensus algorithms. These algorithms are much simpler and use less memory bits than previous algorithms based on ACLs and sticky bits. We also prove that PEATSs are universal (they can be used to implement any shared memory object), and present a universal construction. Alysson Neves Bessani, Joni da Silva Fraga, Miguel Correia 0001, Lau Cheuk Lung |
ICDCS | 1 |
| 2006 | Brief Announcement: Decoupled Quorum-Based Byzantine-Resilient Coordination in Open Distributed Systems
Alysson Neves Bessani, Miguel Correia 0001, Joni da Silva Fraga, Lau Cheuk Lung |
DISC | 1 |
| 2003 | Integrating the Unreliable Multicast Inter-ORB Protocol in MJACO
Alysson Neves Bessani, Lau Cheuk Lung, Joni da Silva Fraga, Alcides Calsavara |
DAIS | 1 |
| 2003 | Implementing the Multicast Inter-ORB ProtocolabstractThis paper presents our experiments for integrating OMG MIOP (Mullicast Inter-ORB Protocol) specifications into a CORBA ORB. We proposed an integration model which allows the coexistence of two different protocol stacks (IIOP/TCP/IP and MIOP/UDP/IP multicast), making possible a large spectrum of middleware support for distributed objects communication. That integration model is discussed in this paper, giving evidence of the compatibility of our approach with the CORBA specifications. We also do some considerations about the implementation of this model in a CORBA compliant ORB. Alysson Neves Bessani, Joni da Silva Fraga, Lau Cheuk Lung |
ISORC | 1 |