Diego Kreutz

dblp:72/10127 · also Diego Luis Kreutz · DBLP profile ↗
← Back
16ranked-venue papers
6as first author
7since 2021 · last 2026
0000-0003-0830-0238ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 3 since 2021Computer networks · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 1 first-authorSystems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Adaptive Compression of Clinical Signals: A Hybrid TinyML-Federated Learning Approach in Edge-Fog Environments
João Medeiros Dinis, Jean Schmith, Diego Kreutz, Guilherme Galante, Dalvan Griebler, Rodrigo da Rosa Righi
CLOSER3
2025 Assessing the Impact of Post-Quantum Digital Signature Algorithms on Blockchains
Alison Gonçalves Schemitt, Henrique Fan da Silva, Roben Castagna Lunardi, Diego Kreutz, Rodrigo B. Mansilha, Avelino Francisco Zorzo
TrustCom4
2024 Assessing the Performance of Docker in Docker Containers for Microservice-Based Architectures
abstract
We provide a comprehensive and updated assessment of Docker versus Docker in Docker (DinD), evaluating its impact on CPU, memory, disk, and network. Using different workloads, we evaluate DinD's performance across distinct hardware platforms and GNU/Linux distributions on cloud Infrastructure as a Service (laaS) platforms like Google Compute Engine (GCE) and traditional server-based environments. We developed an automated tools suite to achieve our goal. We execute four well-known benchmarks on Docker and its nested-container variant. Our findings indicate that nested-containers require up to 7 seconds for startup, while the Docker standard containers require less than 0.5 seconds for Debian and Alpine operating systems. Our results suggest that Docker containers based on Debian consistently outperform their Alpine counter-parts, showing lower CPU latency. A key distinction among these Docker images lies in the varying number of installed libraries (e.g., stretching from 13 to 119) across different Linux distributions for the same system (e.g., MySQL). Furthermore, the number of events and CPU latency indicates that the influence of DinD over Docker proves that it is insignificant for both operating systems. In terms of memory, running containers of Debian-based images consume 20% more size of memory than those based on Alpine. No significant differences are between nested-containers and Dockers for disk and network IO. It is worth emphasizing that some of the disparities, such as a bigger memory footprint, appear to be a direct result of the software stack in use, including different kernel versions. libraries. and other essential packages.
Felipe Bedinotto Fava, Luiz Felipe Laviola Leite, Luís Fernando Alves Da Silva, Pedro Ramires Da Silva Amalfi Costa, Angelo Gaspar Diniz Nogueira, Amanda Fagundes Gobus Lopes, Claudio Schepke, Diego Kreutz, Rodrigo B. Mansilha
PDP8
2024 Auth4App: Streamlining authentication for integrated cyber-physical environments
Vagner Ereno Quincozes, Rodrigo B. Mansilha, Diego Kreutz, Charles Miers, Roger Immich
J. Inf. Secur. Appl.3
2023 Performance analysis of the Raft consensus algorithm on Hyperledger Fabric and Ethereum on cloud
abstract
The use of private or consortium blockchains in organizations’ applications is growing. A relevant aspect of blockchains is the choice of consensus mechanism. This decision delimits which blockchain solutions are suitable for the private scenario. Once the consensus mechanism is chosen, more than one blockchain may be enabled. However, this decision making is not trivial and requires detailed experimental indicators about algorithms and blockchains performance. In this context, we provide a comprehensive performance analysis of the Raft consensus mechanism based on its implementation in Hyperledger Fabric and Ethereum blockchain solutions. We performed our experiments on an OpenStack private cloud using each blockchain developer’s default settings for virtual machines. Our findings show how the implementation of each solution can impact the application’s performance under certain conditions.
Joao Henrique Faes Battisti, Vitor E. Batista, Guilherme P. Koslovski, Maurício Aronne Pillon, Charles Miers, Marco A. Marques, Marcos A. Simplício Jr., Diego Kreutz
CloudCom8
2023 Analyzing the Performance of the Inter-Blockchain Communication Protocol
abstract
With the increasing demand for communication between blockchains, improving the performance of cross-chain communication protocols becomes an emerging challenge. We take a first step towards analyzing the limitations of cross-chain communication protocols by comprehensively evaluating Cosmos Network's Inter-Blockchain Communication Protocol. To achieve our goal we introduce a novel framework to guide empirical evaluations of cross-chain communication protocols. We implement an instance of our framework as a tool to evaluate the IBC protocol. Our findings highlight several challenges, such as high transaction confirmation latency, bottlenecks in the blockchain's RPC implementation and concurrency issues that hinder the scalability of the cross-chain message relayer. We also demonstrate how to reduce the time required to complete cross-chain transfers by up to 70% when submitting large amounts of transfers. Finally, we discuss challenges faced during deployment with the objective of contributing to the development and advancement of cross-chain communication.
João Otávio Massari Chervinski, Diego Kreutz, Xiwei Xu 0001, Jiangshan Yu
DSN2
2022 Fix Me If You Can: Using Neural Networks to Regenerate Networked Systems' Monitoring Traces
abstract
Monitoring principal entities in distributed systems is paramount to understanding the behavior of such systems and replicating their dynamics, e.g., for offline analysis or simulated evaluation. Examples of principal entities include users of distributed applications or online hosts on the internet. In many systems, monitoring can be done via periodic sampling of the entities online at a given instant. However, the monitoring process may be flawed. Some entities may fail to appear in one or more samples even though online when those samples were captured, thus compromising the quality of the monitoring traces. Previous investigations have applied statistical methods to identify such failures and used thresholds to correct them. In this paper, we turn our attention to machine learning methods as a means to regenerate monitoring traces collected via sampling. We propose a deep learning procedural method and two neural network topologies for correcting traces. We provide evidence that precision, accuracy, and recall can be substantially improved compared to existing statistical methods, thus opening an entire research avenue for improving the quality of monitoring traces of live distributed systems.
Kayuã Oleques Paim, Vagner Ereno Quincozes, Diego Kreutz, Rodrigo B. Mansilha, Weverton Luis da Costa Cordeiro
NOMS3
2019 ANCHOR: Logically Centralized Security for Software-Defined Networks
abstract
Software-defined networking (SDN) decouples the control and data planes of traditional networks, logically centralizing the functional properties of the network in the SDN controller. While this centralization brought advantages such as a faster pace of innovation, it also disrupted some of the natural defenses of traditional architectures against different threats. The literature on SDN has mostly been concerned with the functional side, despite some specific works concerning non-functional properties such as security or dependability. Though addressing the latter in an ad-hoc, piecemeal way may work, it will most likely lead to efficiency and effectiveness problems. We claim that the enforcement of non-functional properties as a pillar of SDN robustness calls for a systemic approach. We further advocate, for its materialization, the reiteration of the successful formula behind SDN: ‘logical centralization’. As a general concept, we propose anchor , a subsystem architecture that promotes the logical centralization of non-functional properties. To show the effectiveness of the concept, we focus on security in this article: we identify the current security gaps in SDNs and we populate the architecture middleware with the appropriate security mechanisms in a global and consistent manner. Essential security mechanisms provided by anchor include reliable entropy and resilient pseudo-random generators, and protocols for secure registration and association of SDN devices. We claim and justify in the article that centralizing such mechanisms is key for their effectiveness by allowing us to define and enforce global policies for those properties; reduce the complexity of controllers and forwarding devices; ensure higher levels of robustness for critical services; foster interoperability of the non-functional property enforcement mechanisms; and promote the security and resilience of the architecture itself. We discuss design and implementation aspects, and we prove and evaluate our algorithms and mechanisms, including the formalisation of the main protocols and the verification of their core security properties using the T amarin prover.
Diego Kreutz, Jiangshan Yu, Fernando M. V. Ramos, Paulo Veríssimo
ACM Trans. Priv. Secur.1
2018 Towards a Hybrid Storage Architecture for IoT
abstract
Internet of Things (IoT) is becoming part of our daily life. Indeed, studies predict a sharp market growth by 2020. One of the challenges of this fast-growing market is how to store and manage the amount of non-structured data generated by IoT devices. In this paper, we propose a hybrid storage architecture for IoT for addressing scalability, performance, and heterogeneity issues. We selected three of the most commonly used NoSQL databases (Redis, MongoDB, and Cassandra) to perform the first evaluation of our architecture. Our results suggest that the hybrid storage architecture is a feasible and promising approach to address some of the issues related to the ever-growing amount of data generated by IoT devices. Additionally, our findings also show that Redis achieves a better overall performance for the two chosen types of data, namely scalar and positional.
Braulio L. D. C. Junior, Edward D. Moreno, Douglas Dyllon Jeronimo de Macedo, Diego Kreutz, Mario A. R. Dantas
ISCC4
2016 A cyber-resilient architecture for critical security services
Diego Kreutz, Oleksandr Malichevskyy, Eduardo Feitosa, Hugo Cunha, Rodrigo da Rosa Righi, Douglas Dyllon Jeronimo de Macedo
J. Netw. Comput. Appl.1
2015 Software-Defined Networking: A Comprehensive Survey
abstract
The Internet has led to the creation of a digital society, where (almost) everything is connected and is accessible from anywhere. However, despite their widespread adoption, traditional IP networks are complex and very hard to manage. It is both difficult to configure the network according to predefined policies, and to reconfigure it to respond to faults, load, and changes. To make matters even more difficult, current networks are also vertically integrated: the control and data planes are bundled together. Software-defined networking (SDN) is an emerging paradigm that promises to change this state of affairs, by breaking vertical integration, separating the network's control logic from the underlying routers and switches, promoting (logical) centralization of network control, and introducing the ability to program the network. The separation of concerns, introduced between the definition of network policies, their implementation in switching hardware, and the forwarding of traffic, is key to the desired flexibility: by breaking the network control problem into tractable pieces, SDN makes it easier to create and introduce new abstractions in networking, simplifying network management and facilitating network evolution. In this paper, we present a comprehensive survey on SDN. We start by introducing the motivation for SDN, explain its main concepts and how it differs from traditional networking, its roots, and the standardization activities regarding this novel paradigm. Next, we present the key building blocks of an SDN infrastructure using a bottom-up, layered approach. We provide an in-depth analysis of the hardware infrastructure, southbound and northbound application programming interfaces (APIs), network virtualization layers, network operating systems (SDN controllers), network programming languages, and network applications. We also look at cross-layer problems such as debugging and troubleshooting. In an effort to anticipate the future evolution of this new paradigm, we discuss the main ongoing research efforts and challenges of SDN. In particular, we address the design of switches and control platforms - with a focus on aspects such as resiliency, scalability, performance, security, and dependability - as well as new opportunities for carrier transport networks and cloud providers. Last but not least, we analyze the position of SDN as a key enabler of a software-defined environment.
Diego Kreutz, Fernando M. V. Ramos, Paulo Veríssimo, Christian Esteve Rothenberg, Siamak Azodolmolky, Steve Uhlig
Proc. IEEE1
2014 Increasing the Resilience and Trustworthiness of OpenID Identity Providers for Future Networks and Services
abstract
We introduce a set of tools and techniques for increasing the resilience and trustworthiness of identity providers (IdPs) based on OpenID. To this purpose we propose an architecture of specialized components capable of fulfilling the essential requirements for ensuring high availability, integrity and higher confidentiality guarantees for sensitive data and operations. Additionally, we also discuss how trusted components (e.g., TPMs, smart cards) can be used to provide remote attestation on the client and server side, i.e., how to measure the trustworthiness of the system. The proposed solution outperforms related work in different aspects, such as countermeasures for solving different security issues, throughput, and by tolerating arbitrary faults without compromising the system operations. We evaluate the system behavior under different circumstances, such as continuous faults and attacks. Furthermore, the first performance evaluations show that the system is capable of supporting environments with thousands of users.
Diego Kreutz, Eduardo Feitosa, Hugo Cunha, Heiko Niedermayer, Holger Kinkelin
ARES1
2014 A novel framework for supporting the exponential worldwide adoption of electronic transactions
abstract
Electronic transactions have become the mainstream mechanism for performing commerce activities in our daily lives. Aiming at processing them, the most common approach addresses the use of a switch that dispatches transactions to processing machines using the so-called Round-Robin scheduler. Considering this electronic funds transfer (EFT) scenario, we developed a framework model denoted GetLB which comprises not only a new and efficient scheduler, but also a cooperative communication infrastructure for handling heterogeneous and dynamic environments. The GetLB scheduler uses a scheduling heuristic that combines static data from transactions and dynamic information from the processing nodes to overcome the limitations of the Round-Robin based schedulinperiodic interactiong approaches. Scheduling efficiency takes place thanks to the periodic interaction between the switching node and processing machines, enabling local decision making with up-to-date information about the environment. Besides the description of the aforementioned model in detail, this article also presents a prototype evaluation by using both traces and configurations obtained with a real EFT company. The results show improvements in transaction makespan when comparing our approach with the traditional one over homogeneous and heterogeneous clusters.
Rodrigo da Rosa Righi, Vinicius Facco Rodrigues, Cristiano André da Costa, Leonardo Dagnino Chiwiacowsky, Diego Kreutz, Alexandre Luis Andrade
AICCSA5
2014 Towards Secure and Dependable Authentication and Authorization Infrastructures
abstract
We propose a resilience architecture for improving the security and dependability of authentication and authorization infrastructures, in particular the ones based on RADIUS and OpenID. This architecture employs intrusion-tolerant replication, trusted components and entrusted gateways to provide survivable services ensuring compatibility with standard protocols. The architecture was instantiated in two prototypes, one implementing RADIUS and another implementing OpenID. These prototypes were evaluated in fault-free executions, under faults, under attack, and in diverse computing environments. The results show that, beyond being more secure and dependable, our prototypes are capable of achieving the performance requirements of enterprise environments, such as IT infrastructures with more than 400k users.
Diego Kreutz, Alysson Neves Bessani, Eduardo Feitosa, Hugo Cunha
PRDC1
2013 Experiences with Fault-Injection in a Byzantine Fault-Tolerant Protocol
Rolando Martins, Rajeev Gandhi, Priya Narasimhan, Soila M. Pertet, António Casimiro, Diego Kreutz, Paulo Veríssimo
Middleware6
2012 A Trustworthy and Resilient Event Broker for Monitoring Cloud Infrastructures
Diego Kreutz, António Casimiro, Marcelo Pasin
DAIS1