EDBT 2026 Demo / reviewers in the wild / expert
Nuno Antunes
dblp:97/7524
· DBLP profile ↗
31ranked-venue papers
6as first author
11since 2021 · last 2024
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 14 · 4 first-author · 3 since 2021Security and privacy · 11 · 2 first-author · 5 since 2021Systems, architecture and hardware · 6 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 4 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | MONDEO-Tactics5G: Multistage botnet detection and tactics for 5G/6G networksabstractMobile malware is a malicious code specifically designed to target mobile devices to perform multiple types of fraud. The number of attacks reported each day is increasing constantly and is causing an impact not only at the end-user level but also at the network operator level. Malware like FluBot contributes to identity theft and data loss but also enables remote Command & Control (C2) operations, which can instrument infected devices to conduct Distributed Denial of Service (DDoS) attacks. Current mobile device-installed solutions are not effective, as the end user can ignore security warnings or install malicious software. This article designs and evaluates MONDEO-Tactics5G - a multistage botnet detection mechanism that does not require software installation on end-user devices, together with tactics for 5G network operators to manage infected devices. We conducted an evaluation that demonstrates high accuracy in detecting FluBot malware, and in the different adaptation strategies to reduce the risk of DDoS while minimising the impact on the clients' satisfaction by avoiding disrupting established sessions. Bruno Sousa, Nuno Antunes, Javier Cámara 0001, Ryan Wagner, Bradley R. Schmerl, David Garlan, Pedro Fidalgo |
Comput. Secur. | 3 |
| 2024 | Evaluating intrusion detection for microservice applications: Benchmark, dataset, and case studiesabstractMicroservices are predominant for cloud-based applications, which serve millions of customers daily, that commonly run business-critical systems on software containers and multi-tenant environments; so, it is of utmost importance to secure these systems. Intrusion detection is a widely applied technique that is now being used in microservices to build behavior detection models and report possible attacks during runtime. However, it is cumbersome to evaluate and compare the effectiveness of different approaches. Standardized frameworks are non-existent and without fairly comparing new techniques to the state-of-the-art, it is difficult to understand their pros and cons. This paper presents a comprehensive approach to evaluate and compare different intrusion detection approaches for microservice applications. A benchmarking methodology is proposed to allow users to standardize the process for a representative and reproducible evaluation. We also present a dataset that applies representative workloads and technologies based on microservice applications state-of-the-art. The benchmark and dataset are used in three case studies, characterized by dynamicity, scalability, and continuous delivery, to evaluate and compare state-of-the-art algorithms with the objective of tackling intrusion detection in microservices. Experiments show the usefulness and wide application range of the benchmark while showing the capacity of intrusion detection algorithms in different applications and deployments. José Flora, Nuno Antunes |
J. Syst. Softw. | 2 |
| 2023 | Intrusion Injection for Virtualized Systems: Concepts and ApproachabstractVirtualization is drawing attention due to countless benefits, leaving Hypervisors with the paramount responsibility for performance, dependability, and security. However, while there are consolidated approaches to assessing the performance and dependability of virtualized systems, solutions to assess security are very limited. Key difficulties are evaluating the system in the presence of unknown attacks and vulnerabilities and comparing the security attributes of different systems and configurations when an intrusion occurs. In this paper, we propose a novel concept and approach of intrusion injection for virtualized environments, which consists of directly driving the system into the erroneous states that mimic the ones resulting from actual intrusions (in the same way errors are injected to mimic the effects of residual faults). We present a prototype capable of injecting erroneous states related to memory-corruption in the Xen Hypervisor to show that the concept and approach proposed here are feasible. The prototype is evaluated using publicly disclosed exploits across three different versions of Xen. Results show that our tool can inject erroneous states equivalent to those resulting from attacks that exploit existing vulnerabilities, even on versions where those vulnerabilities do not exist. Charles F. Gonçalves, Nuno Antunes, Marco Vieira |
DSN | 2 |
| 2023 | Intrusion Detection for Scalable and Elastic Microservice ApplicationsabstractThe growing complexity and dynamicity of microservices, combined with their ability to scale, present significant challenges to security monitoring tools. Integrating these tools into a DevSecOps pipeline is currently impractical, necessitating research into adaptive intrusion detection approaches. This paper introduces three data processing techniques that enable intrusion detection in scalable and elastic microservice applications utilizing CI/CD approaches. These techniques manipulate data collected from active microservice replicas and feed it to algorithms, resulting in reliable intrusion detection even after scaling operations. To evaluate these techniques, we integrate them into a state-of-the-art intrusion detection tool developed for microservice environments. Their effectiveness is evaluated using two lightweight algorithms (STIDE and BoSC) with representative workloads, attacks, and a microservice-based application, demonstrating their ability to detect most attacks, even in scenarios involving multiple replicas. José Flora, Paulo Gonçalves 0005, Nuno Antunes |
PRDC | 3 |
| 2023 | µDetector: Automated Intrusion Detection for MicroservicesabstractThe recent adoption of microservice-based applications divides an application into small independent services that communicate using lightweight mechanisms, improving flexibility and scalability in dynamic DevOps environments that leverage containers and orchestration tools such as Kubernetes. However, this growing popularity raises concerns related to their dependability and security, aggravated by several attacks and the lack of intrusion detection tools that target microservices. Thus, developing solutions that can be deployed in real-world scenarios and whose purpose is to keep applications and businesses secure is of the utmost importance. This paper presents µDetector, an intrusion detection tool for microservice-based applications. This tool uses intrusion detection techniques from previous research and automates their functioning for Kubernetes and KubeEdge deployments. The user provides a configuration file and the tool uses monitoring agents to collect system calls from the containers and transfers them over to the IDS module that performs anomaly-based intrusion detection. Anomalous activity will trigger alarms indicating a possible intrusion. The user can interact with the tool and its monitoring capabilities through a command-line interface or a web dashboard. µDetector was validated using functional testing and performance and scalability tests. Results show that µDetector performs well and does not impact the proper functioning of the microservices: in scenarios with over 100 000 system calls being collected per second, the CPU and memory usage of the worker nodes did not exceed 10% of the total resources available.The source code repository can be accessed here: https://github.com/micro-sec/detector. José Flora, Miguel Teixeira, Nuno Antunes |
SANER | 3 |
| 2023 | Editorial: Software Reliability and Dependability EngineeringabstractAs software plays an increasingly important role in our lives, it is essential to maintain its reliability, and generally dependability. Software bugs can cause huge financial losses and dangerous accidents; the safety risks from software are underscored these days to even the non-technical public by the emergence of autonomous software-based systems. Thus, it is important to explore principled approaches to reduce the harm from defects in software, preferably by removing them as early as possible, but also by fault tolerance and by predicting their effects so as to inform mitigation actions. Zheng Zheng 0001, Lorenzo Strigini, Nuno Antunes, Kishor S. Trivedi |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | BIANFE: Object identification and authentication in federated scenariosabstractFederated Identity Management enables convenient mechanisms to authenticate users and to authorize services, applications to specific users’ resources. SAML and OpenID Connect that relies on OAuth 2.0 are commonly employed to enable Single-Sign-On features. Despite their wide usage in several domains (enterprise, web applications) they only aim to identify entities like persons and do not consider the different trust levels that a person can have with its devices, or even with the services provided by organisations participating or not in federated scenarios. BIANFE stands as a proposal for object identification and authentication in federated and non federated scenarios, considering the trust relations between end-users and the applications/services running in its devices. As work in progress, BIANFE tackles primarily the identification issue for objects, considering interoperability and privacy issues. Carolina Gonçalves, Bruno Sousa, Nuno Antunes |
CCNC | 3 |
| 2022 | Adversarial Robustness Assessment of NeuroEvolution ApproachesabstractNeuroEvolution automates the generation of Artificial Neural Networks through the application of techniques from Evolutionary Computation. The main goal of these approaches is to build models that maximize predictive performance, some-times with an additional objective of minimizing computational complexity. Although the evolved models achieve competitive results performance-wise, their robustness to adversarial examples, which becomes a concern in security-critical scenarios, has received limited attention. In this paper, we evaluate the adversarial robustness of models found by two prominent Neu-roEvolution approaches on the CIFAR-10 image classification task: DENSER and NSGA-Net. Since the models are publicly available, we consider white-box untargeted attacks, where the perturbations are bounded by either the$L_{2}$or the$L_{\infty}$-norm. Similarly to manually-designed networks, our results show that when the evolved models are attacked with iterative methods, their accuracy usually drops to, or close to, zero under both distance metrics. The DENSER model is an exception to this trend, showing some resistance under the$L_{2}$threat model, where its accuracy only drops from 93.70% to 18.10% even with iterative attacks. Additionally, we analyzed the impact of pre-processing applied to the data before the first layer of the network. Our observations suggest that some of these techniques can exacerbate the perturbations added to the original inputs, potentially harming robustness. Thus, this choice should not be neglected when automatically designing networks for applications where adversarial attacks are prone to occur. Inês Valentim, Nuno Lourenço 0002, Nuno Antunes |
CEC | 3 |
| 2022 | Privacy risk assessment and privacy-preserving data monitoringabstractPrivacy regulations press organisations to handle personal data with reinforced caution. Moreover, organisations are dealing with increasing amounts of Personally Identifiable Information in their systems. Thus, there is a high demand not only for privacy-preserving data processing mechanisms but also privacy-enhancing services. As such, we propose the Personal Data Analyser, a tool that increases privacy assurances and minimises privacy risks through automated privacy-preserving data monitoring and privacy risk assessment mechanisms. Automated data monitoring is achieved with a hybrid mechanism that employs Regular Expressions, Natural Language Processing tools, and machine learning models such as Multilayer Perceptron and Random Forests. Our privacy risk assessment mechanism is based on custom-built crisp and fuzzy models, that consider information such as data processor reputation, data sensitiveness and other inputs in order to assess privacy risk associated with data transactions. Our work is integrated and validated under real use cases of the PoSeID-on platform and warns users whenever potential privacy risks are detected. Validation under PoSeID-on’s pilots and its users proved beneficial not only to assess our solution but also to raise users’ awareness of their data. The results of this work show that our solution is an effective Privacy Enhancing Technology that increases privacy assurances between organisations and their users. Paulo Silva 0002, Carolina Gonçalves, Nuno Antunes, Marília Curado, Bogdan Walek |
Expert Syst. Appl. | 3 |
| 2022 | Generating personalized business card designs from images
Nuno Antunes, João Ferreira 0001, Elsa Cardoso |
Multim. Tools Appl. | 1 |
| 2022 | A Multi-Criteria Analysis of Benchmark Results With Expert Support for Security ToolsabstractThe benchmarking of security tools is endeavored to determine which tools are more suitable to detect system vulnerabilities or intrusions. The analysis process is usually oversimplified by employing just a single metric out of the large set of those available. Accordingly, the decision may be biased by not considering relevant information provided by neglected metrics. This article proposes a novel approach to take into account several metrics, different scenarios, and the advice of multiple experts. The proposal relies on experts quantifying the relative importance of each pair of metrics towards the requirements of a given scenario. Their judgments are aggregated using group decision making techniques, and pondered according to the familiarity of experts with the metrics and scenario, to compute a set of weights accounting for the relative importance of each metric. Then, weight-based multi-criteria-decision-making techniques can be used to rank the benchmarked tools. The usefulness of this approach is showed by analyzing two different sets of vulnerability and intrusion detection tools from the perspective of multiple/single metrics and different scenarios. Miquel Martínez, Juan-Carlos Ruiz-Garcia 0001, Nuno Antunes, David de Andrés, Marco Vieira |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | Using Attack Injection to Evaluate Intrusion Detection Effectiveness in Container-based SystemsabstractContainers revolutionized cloud applications, as they are lightweight, highly portable and ideal for microservices. Although they are being adopted in business-critical scenarios, they introduce security concerns which are exacerbated in multi-tenant environments. Intrusion detection techniques can help, but they have received limited attention in this context. This paper presents an approach that uses attack injection to evaluate the effectiveness of intrusion detection in container-based systems. We use a TPC-C workload, with a database engine running as a container, while monitoring its system calls. First, the algorithms are submitted to benign workloads to learn the application profile. Then, we execute a set of attack injection experiments with diverse attacks, and we verify whether the algorithms report them. An experiment was designed to evaluate the algorithms in Docker and LXC containers, and in a traditional OS deployment for comparison. The results show that the approach is effective in evaluating the algorithms in different scenarios. The algorithms consistently detect most of the attacks (89+%). The precision values show more variance, but with careful tuning and richer workloads, this problem can be mitigated. José Flora, Paulo Gonçalves 0005, Nuno Antunes |
PRDC | 3 |
| 2019 | The Impact of Data Preparation on the Fairness of Software SystemsabstractMachine learning models are widely adopted in scenarios that directly affect people. The development of software systems based on these models raises societal and legal concerns, as their decisions may lead to the unfair treatment of individuals based on attributes like race or gender. Data preparation is key in any machine learning pipeline, but its effect on fairness is yet to be studied in detail. In this paper, we evaluate how the fairness and effectiveness of the learned models are affected by the removal of the sensitive attribute, the encoding of the categorical attributes, and instance selection methods (including cross-validators and random undersampling). We used the Adult Income and the German Credit Data datasets, which are widely studied and known to have fairness concerns. We applied each data preparation technique individually to analyse the difference in predictive performance and fairness, using statistical parity difference, disparate impact, and the normalised prejudice index. The results show that fairness is affected by transformations made to the training data, particularly in imbalanced datasets. Removing the sensitive attribute is insufficient to eliminate all the unfairness in the predictions, as expected, but it is key to achieve fairer models. Additionally, the standard random undersampling with respect to the true labels is sometimes more prejudicial than performing no random undersampling. Inês Valentim, Nuno Lourenço 0002, Nuno Antunes |
ISSRE | 3 |
| 2019 | BIGSEA: A Big Data analytics platform for public transportation information
Andy S. Alic, Jussara M. Almeida, Giovanni Aloisio, Nazareno Andrade, Nuno Antunes, Danilo Ardagna, Rosa M. Badia, Tânia Basso, Ignacio Blanquer, Tarciso Braz, Andrey Brito, Donatello Elia, Sandro Fiore, Dorgival O. Guedes, Marco Lattuada 0001, Daniele Lezzi, Matheus Maciel, Wagner Meira Jr., Demetrio Gomes Mestre, Regina Lúcia de Oliveira Moraes, Fábio Morais 0001, Carlos Eduardo S. Pires, Nádia P. Kozievitch, Walter Santos, Paulo Silva 0002, Marco Vieira |
Future Gener. Comput. Syst. | 5 |
| 2019 | Understanding How to Use Static Analysis Tools for Detecting Cryptography Misuse in SoftwareabstractThe use of cryptography is nowadays common in software systems, with cryptographic libraries widely available to software developers. As such, the likely weakest link in sensitive software has moved from cryptographic function implementations to the application code surrounding such functions. Ordinary developers usually lack knowledge in practical cryptography, and support from specialists is rare. Frequently, these difficulties are addressed by running static analysis tools to automatically detect cryptography misuse during coding and reviews. However, the effectiveness of such tools is not yet well understood. This article studies how well programmatic misuse of cryptography is detected by free static code analysis tools. The performance of such tools in detecting misuse is correlated to coding tasks and use cases commonly found in development efforts; also, cryptography misuse is classified in comprehensive categories, easily recognizable by software security practitioners. Our research shows that the coverage of public-key cryptography by static code analysis tools is full of blind spots, because tools prioritize only those misuses related to the most frequent coding tasks and use cases, while neglecting infrequent use cases. We found that, in addition to a relatively low recall in our tests, evaluated tools also have a small overlap regarding the misuses detected by all the evaluated tools, as well as an intersection of false alarms, suggesting lack of discrimination between specific misuses and corresponding good uses of cryptography. In spite of that, well-selected tools can be useful when developing cryptographic software, but support of experts is still required for solving complex cases. Alexandre Melo Braga, Ricardo Dahab, Nuno Antunes, Nuno Laranjeiro, Marco Vieira |
IEEE Trans. Reliab. | 3 |
| 2017 | PRIVAaaS: privacy approach for a distributed cloud-based data analytics platformsabstractData privacy is a key challenge that is exacerbated by Big Data storage and analytics processing requirements. Big Data and Cloud Computing are related and allow the users to access data from any device, making data privacy essential as the data sets are exposed through the web. Organizations care about data privacy as it directly affects the confidence that clients have that their personal data are safe. This paper presents a data privacy approach - PRIVAaaS - and its inte-gration to the LEMONADE Web-based platform, developed to compose ETL (Extract, Transform, Load) process and Machine Learning workflows. The 3-level approach of PRIVAaaS, based on data anonymization policies, is implemented in a software toolkit that provides a set of libraries and tools which allows controlling and reducing data leakage in the context of Big Data processing. Tânia Basso, Regina Lúcia de Oliveira Moraes, Nuno Antunes, Marco Vieira, Walter Santos, Wagner Meira Jr. |
CCGrid | 3 |
| 2017 | Practical Evaluation of Static Analysis Tools for Cryptography: Benchmarking Method and Case StudyabstractThe incorrect use of cryptography is a common source of critical software vulnerabilities. As developers lack knowledge in applied cryptography and support from experts is scarce, this situation is frequently addressed by adopting static code analysis tools to automatically detect cryptography misuse during coding and reviews, even if the effectiveness of such tools is far from being well understood. This paper proposes a method for benchmarking static code analysis tools for the detection of cryptography misuse, and evaluates the method in a case study, with the goal of selecting the most adequate tools for specific development contexts. Our method classifies cryptography misuse in nine categories recognized by developers (weak cryptography, poor key management, bad randomness, etc.) and provides the workload, metrics and procedure needed for a fair assessment and comparison of tools. We found that all evaluated tools together detected only 35% of cryptography misuses in our tests. Furthermore, none of the evaluated tools detected insecure elliptic curves, weak parameters in key agreement, and most insecure configurations for RSA and ECDSA. This suggests cryptography misuse is underestimated by tool builders. Despite that, we show that it is possible to benefit from an adequate tool selection during the development of cryptographic software. Alexandre Melo Braga, Ricardo Dahab, Nuno Antunes, Nuno Laranjeiro, Marco Vieira |
ISSRE | 3 |
| 2017 | Smells are sensitive to developers!: on the efficiency of (un)guided customized detectionabstractCode smells indicate poor implementation choices that may hinder program comprehension and maintenance. Their informal definition allows developers to follow different heuristics to detect smells in their projects. Machine learning has been used to customize smell detection according to the developer's perception. However, such customization is not guided (i.e. constrained) to consider alternative heuristics used by developers when detecting smells. As a result, their customization might not be efficient, requiring a considerable effort to reach high effectiveness. In fact, there is no empirical knowledge yet about the efficiency of such unguided approaches for supporting developer-sensitive smell detection. This paper presents Histrategy, a guided customization technique to improve the efficiency on smell detection. Histrategy considers a limited set of detection strategies, produced from different detection heuristics, as input of a customization process. The output of the customization process consists of a detection strategy tailored to each developer. The technique was evaluated in an experimental study with 48 developers and four types of code smells. The results showed that Histrategy is able to outperform six widely adopted machine learning algorithms - used in unguided approaches - both in effectiveness and efficiency. It was also confirmed that most developers benefit from using alternative heuristics to: (i) build their tailored detection strategies, and (ii) achieve efficient smell detection. Mario Hozano, Alessandro F. Garcia 0001, Nuno Antunes, Baldoino Fonseca dos Santos Neto, Evandro de Barros Costa |
ICPC | 3 |
| 2016 | Fishing Monitor System Data: A Naïve Bayes Approach
João Ferreira 0001, Serge Lage, Iola Pinto, Nuno Antunes |
ISDA | 4 |
| 2016 | Quantifying the Attack Detection Accuracy of Intrusion Detection Systems in Virtualized EnvironmentsabstractWith the widespread adoption of virtualization, intrusion detection systems (IDSes) are increasingly being deployed in virtualized environments. When securing an environment, IT security officers are often faced with the question of how accurate deployed IDSes are at detecting attacks. To this end, metrics for assessing the attack detection accuracy of IDSes have been developed. However, these metrics are defined with respect to a fixed set of hardware resources available to the tested IDS. Therefore, IDSes deployed in virtualized environments featuring elasticity (i.e., on-demand allocation or deallocation of virtualized hardware resources during system operation) cannot be evaluated in an accurate manner using existing metrics. In this paper, we demonstrate the impact of elasticity on IDS attack detection accuracy. In addition, we propose a novel metric and measurement methodology for accurately quantifying the accuracy of IDSes deployed in virtualized environments featuring elasticity. We demonstrate their practical use through case studies involving commonly used IDSes. Aleksandar Milenkoski, K. R. Jayaram, Nuno Antunes, Marco Vieira, Samuel Kounev |
ISSRE | 3 |
| 2015 | On the Metrics for Benchmarking Vulnerability Detection ToolsabstractResearch and practice show that the effectiveness of vulnerability detection tools depends on the concrete use scenario. Benchmarking can be used for selecting the most appropriate tool, helping assessing and comparing alternative solutions, but its effectiveness largely depends on the adequacy of the metrics. This paper studies the problem of selecting the metrics to be used in a benchmark for software vulnerability detection tools. First, a large set of metrics is gathered and analyzed according to the characteristics of a good metric for the vulnerability detection domain. Afterwards, the metrics are analyzed in the context of specific vulnerability detection scenarios to understand their effectiveness and to select the most adequate one for each scenario. Finally, an MCDA algorithm together with experts' judgment is applied to validate the conclusions. Results show that although some of the metrics traditionally used like precision and recall are adequate in some scenarios, others require alternative metrics that are seldom used in the benchmarking area. Nuno Antunes, Marco Vieira |
DSN | 1 |
| 2015 | Workshop on Recent Advances in the DependabIlity AssessmeNt of Complex systEms (RADIANCE)abstractThe workshop on Recent Advances in the DependabIlity AssessmeNt of Complex systEms (RADIANCE), in its first edition, aims to discuss novel dependability assessment approaches for complex systems and to promote their adoption in real-world settings through industrial and academic research. The main objective is to promote and foster discussion on novel ideas, constituting a forum where researchers can share both real problems and innovative solutions for the assessment of complex systems. The workshop focuses on assessing complex evolving systems, where increasing complexity and changes are due to the introduction of new components and sensors, and to the extensive usage of software OTS components or black box components in general. In this macro area, the workshop welcomed a broad list of applications ranging from agile development in critical systems to model-driven assessment approaches as well as new needs for verification, validation and certification of dynamic and evolving systems, which also includes solutions for automating the verification and validation processes. Finally, the workshop was interested inexperimental assessment of dependability and security at large. Ariadne Maria Brito Rizzoni Carvalho, Nuno Antunes, Andrea Ceccarelli, András Zentai |
DSN | 2 |
| 2015 | Experience report: Evaluating the effectiveness of decision trees for detecting code smellsabstractDevelopers continuously maintain software systems to adapt to new requirements and to fix bugs. Due to the complexity of maintenance tasks and the time-to-market, developers make poor implementation choices, also known as code smells. Studies indicate that code smells hinder comprehensibility, and possibly increase change- and fault-proneness. Therefore, they must be identified to enable the application of corrections. The challenge is that the inaccurate definitions of code smells make developers disagree whether a piece of code is a smell or not, consequently, making difficult creation of a universal detection solution able to recognize smells in different software projects. Several works have been proposed to identify code smells but they still report inaccurate results and use techniques that do not present to developers a comprehensive explanation how these results have been obtained. In this experimental report we study the effectiveness of the Decision Tree algorithm to recognize code smells. For this, it was applied in a dataset containing 4 open source projects and the results were compared with the manual oracle, with existing detection approaches and with other machine learning algorithms. The results showed that the approach was able to effectively learn rules for the detection of the code smells studied. The results were even better when genetic algorithms are used to pre-select the metrics to use. Lucas Amorim, Evandro de Barros Costa, Nuno Antunes, Baldoino Fonseca dos Santos Neto, Márcio Ribeiro 0001 |
ISSRE | 3 |
| 2015 | Evaluation of Intrusion Detection Systems in Virtualized Environments Using Attack Injection
Aleksandar Milenkoski, Bryan D. Payne, Nuno Antunes, Marco Vieira, Samuel Kounev, Alberto Avritzer, Matthias Luft |
RAID | 3 |
| 2015 | Assessing and Comparing Vulnerability Detection Tools for Web Services: Benchmarking Approach and ExamplesabstractSelecting a vulnerability detection tool is a key problem that is frequently faced by developers of security-critical web services. Research and practice shows that state-of-the-art tools present low effectiveness both in terms of vulnerability coverage and false positive rates. The main problem is that such tools are typically limited in the detection approaches implemented, and are designed for being applied in very concrete scenarios. Thus, using the wrong tool may lead to the deployment of services with undetected vulnerabilities. This paper proposes a benchmarking approach to assess and compare the effectiveness of vulnerability detection tools in web services environments. This approach was used to define two concrete benchmarks for SQL Injection vulnerability detection tools. The first is based on a predefined set of web services, and the second allows the benchmark user to specify the workload that best portrays the specific characteristics of his environment. The two benchmarks are used to assess and compare several widely used tools, including four penetration testers, three static code analyzers, and one anomaly detector. Results show that the benchmarks accurately portray the effectiveness of vulnerability detection tools (in a relative manner) and suggest that the proposed benchmarking approach can be applied in the field. Nuno Antunes, Marco Vieira |
IEEE Trans. Serv. Comput. | 1 |
| 2014 | Experience Report: An Analysis of Hypercall Handler VulnerabilitiesabstractHypervisors are becoming increasingly ubiquitous with the growing proliferation of virtualized data centers. As a result, attackers are exploring vectors to attack hypervisors, against which an attack may be executed via several attack vectors such as device drivers, virtual machine exit events, or hyper calls. Hyper calls enable intrusions in hypervisors through their hyper call interfaces. Despite the importance, there is very limited publicly available information on vulnerabilities of hyper call handlers and attacks triggering them, which significantly hinders advances towards monitoring and securing these interfaces. In this paper, we characterize the hyper call attack surface based on analyzing a set of vulnerabilities of hyper call handlers. We systematize and discuss the errors that caused the considered vulnerabilities, and activities for executing attacks triggering them. We also demonstrate attacks triggering the considered vulnerabilities and analyze their effects. Finally, we suggest an action plan for improving the security of hyper call interfaces. Aleksandar Milenkoski, Bryan D. Payne, Nuno Antunes, Marco Vieira, Samuel Kounev |
ISSRE | 3 |
| 2013 | An XML-Based Policy Model for Access Control in Web Applications
Tânia Basso, Nuno Antunes, Regina Lúcia de Oliveira Moraes, Marco Vieira |
DEXA (2) | 2 |
| 2012 | Evaluating and Improving Penetration Testing in Web ServicesabstractDevelopers often rely on penetration testing tools to detect vulnerabilities in web services, although frequently without really knowing their effectiveness. In fact, the lack of information on the internal state of the tested services and the complexity and variability of the responses analyzed, limits the effectiveness of such technique, highlighting the importance of evaluating and improving existing tools. The goal of this paper is to investigate if attack signatures and interface monitoring can be an effective mean to assess and improve the performance of penetration testing tools in web services environments. In practice, attacks performed by such tools are signed and the interfaces between the target application and external resources are monitored (e.g., between services and a database server), allowing gathering additional information on existing vulnerabilities. A prototype was implemented focusing on SQL injection vulnerabilities. The experimental evaluation results clearly show that the proposed approach can be used in real scenarios. Nuno Antunes, Marco Vieira |
ISSRE | 1 |
| 2010 | Benchmarking Vulnerability Detection Tools for Web ServicesabstractVulnerability detection tools are frequently considered the silver-bullet for detecting vulnerabilities in web services. However, research shows that the effectiveness of most of those tools is very low and that using the wrong tool may lead to the deployment of services with undetected vulnerabilities. In this paper we propose a benchmarking approach to assess and compare the effectiveness of vulnerability detection tools in web services environments. This approach was used to define a concrete benchmark for SQL Injection vulnerability detection tools. This benchmark is demonstrated by a real example of benchmarking several widely used tools, including four penetration-testers, three static code analyzers, and one anomaly detector. Results show that the benchmark accurately portrays the effectiveness of vulnerability detection tools and suggest that the proposed approach can be applied in the field. Nuno Antunes, Marco Vieira |
ICWS | 1 |
| 2009 | Using web security scanners to detect vulnerabilities in web servicesabstractAlthough Web services are becoming business-critical components, they are often deployed with critical software bugs that can be maliciously explored. Web vulnerability scanners allow detecting security vulnerabilities in Web services by stressing the service from the point of view of an attacker. However, research and practice show that different scanners have different performance on vulnerabilities detection. In this paper we present an experimental evaluation of security vulnerabilities in 300 publicly available Web services. Four well known vulnerability scanners have been used to identify security flaws in Web services implementations. A large number of vulnerabilities has been observed, which confirms that many services are deployed without proper security testing. Additionally, the differences in the vulnerabilities detected and the high number of false-positives (35% and 40% in two cases) and low coverage (less than 20% for two of the scanners) observed highlight the limitations of Web vulnerability scanners on detecting security vulnerabilities in Web services. Marco Vieira, Nuno Antunes, Henrique Madeira |
DSN | 2 |
| 2009 | Comparing the Effectiveness of Penetration Testing and Static Code Analysis on the Detection of SQL Injection Vulnerabilities in Web ServicesabstractWeb services are becoming business-critical components that must provide a non-vulnerable interface to the client applications. However, previous research and practice show that many web services are deployed with critical vulnerabilities. SQL injection vulnerabilities are particularly relevant, as Web services frequently access a relational database using SQL commands. Penetration testing and static code analysis are two well-know techniques often used for the detection of security vulnerabilities. In this work we compare how effective these two techniques are on the detection of SQL injection vulnerabilities in Web services code. To understand the strengths and limitations of these techniques, we used several commercial and open source tools to detect vulnerabilities in a set of vulnerable services. Results suggest that, in general, static code analyzers are able to detect more SQL injection vulnerabilities than penetration testing tools. Another key observation is that tools implementing the same detection approach frequently detect different vulnerabilities. Finally, many tools provide a low coverage and a high false positives rate, making them a bad option for programmers. Nuno Antunes, Marco Vieira |
PRDC | 1 |