EDBT 2026 Demo / reviewers in the wild / expert
Carlos Maziero
dblp:m/CarlosMaziero · also Carlos Alberto Maziero
· DBLP profile ↗
27ranked-venue papers
0as first author
11since 2021 · last 2026
0000-0003-2592-3664ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 12 · 4 since 2021Security and privacy · 10 · 7 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fast and Effective Syscall-Based IDS with Categories
Diogo Bortolini, Rafael R. Obelheiro, Carlos Maziero |
SECRYPT (1) | 3 |
| 2025 | How Risky Is It? A Closer Look at Game Anti-Cheat SoftwareabstractAnti-cheat software is a system designed to detect cheats (or hacks) in a video game. This paper investigates operations executed by anti-cheat software and their impact on user privacy. We collected data and analyzed three popular anticheat solutions: BattlEye, FACEIT, and Vanguard. Our analysis reveals that these programs interact with system files, memory, and users’ directories. In addition, the privileged access of these anti-cheat solutions to the operating system and the lack of clarity on what data is collected directly affect user privacy. This conduct risks not complying with current regulations. Amanda B. Viescinski, Tiago Heinrich, Vinicius Fulber-Garcia, Carlos Maziero |
ISCC | 4 |
| 2024 | Anywhere on Earth: A Look at Regional Characteristics of DRDoS Attacks
Tiago Heinrich, Newton Carlos Will, Rafael R. Obelheiro, Carlos Maziero |
ICISSP | 4 |
| 2024 | A Categorical Data Approach for Anomaly Detection in WebAssembly Applications
Tiago Heinrich, Newton Carlos Will, Rafael R. Obelheiro, Carlos Maziero |
ICISSP | 4 |
| 2024 | Enclave Management Models for Safe Execution of Software Components
Newton Carlos Will, Carlos Maziero |
ICISSP | 2 |
| 2024 | I See Syscalls by the Seashore: An Anomaly-based IDS for Containers Leveraging Sysdig DataabstractIntrusion detection in virtualized environments is vital due to the widespread adoption of virtualization technology. A common strategy for achieving this task involves collecting data from the virtual environment and providing it to intrusion detection solutions. However, these solutions can be affected by other elements present in the virtual environment. An approach that has gained prominence is applying machine learning (ML) models to perform anomaly-based intrusion detection based on system call traces. In Linux-based environments, many tools can be used for collecting the system calls issued by processes and containers; two of the most popular are strace and sysdig. This paper introduces a dataset of system call traces collected with sysdig with a focus on anomaly-based intrusion detection for containerized applications and uses this dataset to compare the effectiveness of strace and sysdig data and evaluate the performance of five different ML models for anomaly detection. The results reveal that sysdig is an attractive option, enabling the collection of system call traces with lower overhead than strace while achieving good detection performance with several ML models. Anderson Aparecido do Carmo Frasão, Tiago Heinrich, Vinicius Fulber-Garcia, Newton Carlos Will, Rafael R. Obelheiro, Carlos Maziero |
ISCC | 6 |
| 2024 | The Use of the DWARF Debugging Format for the Identification of Potentially Unwanted Applications (PUAs) in WebAssembly Binaries
Calebe Helpa, Tiago Heinrich, Marcus Botacin, Newton Carlos Will, Rafael R. Obelheiro, Carlos Maziero |
SECRYPT | 6 |
| 2022 | How DRDoS attacks vary across the globe?abstractIn this study we characterize Distributed Reflection Denial of Service (DRDoS) attack traffic taking into consideration the geographical distribution of victims. This type of characterization is not widely explored in the literature and could help to better understand this type of attack. We aim to explore this gap in the literature using data collected by four honeypots over three and a half years. Our findings highlight attack similarities and differences across continents. Tiago Heinrich, Carlos Maziero, Newton Carlos Will, Rafael R. Obelheiro |
IMC | 2 |
| 2022 | Behavior Modeling of a Distributed Application for Anomaly Detection
Amanda B. Viescinski, Tiago Heinrich, Newton Carlos Will, Carlos Maziero |
SECRYPT | 4 |
| 2021 | Taking a Peek: An Evaluation of Anomaly Detection Using System calls for ContainersabstractThe growth in the use of virtualization in the last ten years has contributed to the improvement of this technology. The practice of implementing and managing this type of isolated environment raises doubts about the security of such systems. Considering the host's proximity to a container, approaches that use anomaly detection systems attempt to monitor and detect unexpected behavior. Our work aims to use system calls to identify threats within a container environment, using machine learning based strategies to distinguish between expected and unexpected behaviors (possible threats). Gabriel R. Castanhel, Tiago Heinrich, Fabricio Ceschin, Carlos Maziero |
ISCC | 4 |
| 2021 | New Kids on the DRDoS Block: Characterizing Multiprotocol and Carpet Bombing Attacks
Tiago Heinrich, Rafael R. Obelheiro, Carlos Maziero |
PAM | 3 |
| 2019 | An Efficient and Scalable Intrusion Detection System on Logs of Distributed Applications
David Lanoë, Michel Hurfin, Eric Totel, Carlos Maziero |
SEC | 4 |
| 2018 | Using Intel SGX to Protect Authentication Credentials in an Untrusted Operating SystemabstractAn important principle in computational security is to reduce the attack surface, by maintaining the Trusted Computing Base (TCB) small. Even so, no security technique ensures full protection against any adversary. Thus, sensitive applications should be designed with several layers of protection so that, even if a layer might be violated, sensitive content will not be compromised. In 2015, Intel released the Software Guard Extensions (SGX) technology in its processors. This mechanism allows applications to allocate enclaves, which are private memory regions that can hold code and data. Other applications and even privileged code, like the OS kernel and the BIOS, are not able to access enclaves' contents. This paper presents a novel password file protection scheme, which uses Intel SGX to protect authentication credentials in the PAM authentication framework, commonly used in UNIX systems. We defined and implemented an SGX-enabled version of the pam_unix.so authentication module, called UniSGX. This module uses an SGX enclave to handle the credentials informed by the user and to check them against the password file. To add an extra security layer, the password file is stored using SGX sealing. A threat model was proposed to assess the security of the proposed solution. The obtained results show that the proposed solution is secure against the threat model considered, and that its performance overhead is acceptable from the user point of view. The scheme presented here is also suitable to other authentication frameworks. Rafael C. R. Conde, Carlos Maziero, Newton Carlos Will |
ISCC | 2 |
| 2018 | Reducing the number of response time service level objective violations by a cloud-HPC convergence schedulerabstractSummary Job scheduling is an old topic in High‐Performance Computing (HPC), and it is more and more studied in data centers. Large data centers are often split into separate partitions for cloud computing and HPC; each partition normally has its specific scheduler. The possibility of migrating jobs from the HPC partition to the cloud one is a topic widely discussed in the literature. However, job migration from cloud to HPC is a much less explored topic. Nevertheless, such migration may be useful in many situations, in particular when the HPC platform has a low resource usage level, and the cloud usage level is high. A large number of jobs that could migrate from the cloud to the HPC partition may be observed in Google data center workloads. Job scheduling using overbooking strategy is seen as the main reason for the high resource usage level in clouds. However, overbooking can lead to a high rate of rescheduling and job dumping, which potentially causes response time violations. This work shows that HPC platforms can host and execute some cloud jobs with low interference in HPC jobs and a low number of response time violations. We introduce the definition of a cloud‐HPCconvergence areaand propose a job scheduling strategy for it, aiming at reducing the number of response time violations of cloud jobs without interfering with HPC jobs execution. Our proposal is formally defined and then evaluated in different execution scenarios, using theSimGridsimulation framework, with workload data from production HPC grid. The experimental results show that often, there is a large number of empty areas in the scheduling plan of HPC platforms, which makes it possible to allocate cloud jobs by backfilling. This is due to the sparse HPC job submission pattern and the low resource usage level in some HPC platforms. One performed simulation scenario considered a set of 11K parallel HPC jobs running on a 2560‐processor platform having an average resource usage level of 38.0%. The proposed convergence scheduler succeeded to inject around 267K cloud jobs in the HPC platform, with a response time violation rate under 0.00094% for such jobs, considering 80 processors in theconvergence areaand no effects on the HPC workload. This experiment considered cloud jobs based on job features of Google public cloud workloads, with a processing time slack factor of 1.25 (which is considered as high priority in the Google cloud SLA—Service Level Agreement). Usually, most cloud jobs show a slack factor higher than 1.25 (most cloud jobs are medium or low priority). The same simulation, repeated with a higher slack factor (4), showed no response time violations. Alessandro Kraemer, Carlos Maziero, Olivier Richard, Denis Trystram |
Concurr. Comput. Pract. Exp. | 2 |
| 2016 | Assessing the impact of cryptographic access control solutions on multimedia delivery in information-centric networksabstractInformation-centric Networks (ICN) aims to improve content delivery by promoting the content as the protagonist of the network layer. By naming, routing, and forwarding named content directly on the network layer, ICN allows the same content to satisfy requests from different users, enabling innetwork caches to place contents strategically near the interested users. This characteristic is especially interesting for multimedia content distribution, since it represents a better quality of experience for users due to low round-trip time, bandwidth use, and load on content providers. However, caching protected multimedia content on uncontrolled third party devices may impair access control policies enforcement by the content providers. Many encryption-based access control solutions have been proposed for ICN, applying different cryptographic strategies leading to distinct features which may not be appropriate for multimedia content protection. In this paper, we simulate, evaluate, and discuss the individual characteristics of three encryption-based access control solutions in light of multimedia distribution in ICN. We show that leveraging cache efficiency, computational load to encrypt and decrypt content, and user revocation are the biggest challenges for the enforcement of access control policies on ICN. Elisa Mannes, Carlos Maziero, Luiz Lassance, Fábio Borges |
NOMS | 2 |
| 2015 | Optimized access control enforcement over encrypted content in information-centric networksabstractThe Information-centric Network (ICN) paradigm is an important initiative toward an Internet architecture more suitable for content distribution. The change it imposes by naming, routing, and forwarding content directly on the network layer empowers the architecture with several interesting characteristics, such as in-network caching. As contents are meaningful for different users, they can be opportunistically cached and easily accessed by them, which improves content delivery and user experience. However, the fact that users can retrieve content through caches without interacting with the content provider raises security concerns regarding unauthorized access and the enforcement of access control policies. In this context, we propose an access control solution for ICN by adapting and optimizing a proxy re-encryption scheme, reducing up to 33% the processing time. The proposed solution is perfectly aligned with ICN demands, simultaneously ensuring content protection against unauthorized access of contents retrieved from unrestricted in-network caches as well as access control policies enforcement for legitimate users. Elisa Mannes, Carlos Maziero, Luiz Lassance, Fábio Borges |
ISCC | 2 |
| 2011 | Applying a usage control model in an operating system kernel
Rafael Teigao, Carlos Maziero, Altair Olivo Santin |
J. Netw. Comput. Appl. | 2 |
| 2009 | Applying quorum role in network managementabstractThis work presents a proposal for extending the Role-Based Access control (RBAC) model to support activities that demand runtime mutability in their authorization attributes. Such activities cannot be subdivided in a set of subtasks executed sequentially neither can be accomplished by a single role. The approach presented allows the creation of quorum roles, which can only be activated in a session with the endorsement of a quorum of other roles. A prototype illustrates the application of our proposal in a network management scenario. In the illustrative scenario, a previously defined set of roles, by endorsement, activates a quorum role to perform a management task without the participation of the network administrator role. Edemilson da Silva, Altair Olivo Santin, Edgard Jamhour, Carlos Maziero, Emir Toktar |
Integrated Network Management | 4 |
| 2009 | Using transparent files in a fault tolerant distributed file systemabstractThe peer-to-peer model and the bandwidth availability are fostering the creation of new distributed file systems. However, files belonging to local application and distributed applications are usually handled in the same way by the local file system, so both contribute equally to consume storage space. This paper presents a peer-to-peer distributed file system which uses the ldquotransparent filerdquo concept to improve its fault tolerance and file availability. Files are kept as transparent/volatile replicas, using the free space available in each local file system. When a replica is invalidated, peers cooperate to restore it. The proposed architecture was implemented and tested; experiments showed its feasibility, and that its costs are proportional to the size of files being replicated. The occurrence of multiple simultaneous replica invalidations did not impose a significant overhead. Marcelo Cheminn Madruga, Sérgio Raymundo Loest, Carlos Maziero |
ISADS | 3 |
| 2008 | A Fuzzy Model for the Composition of Intrusion Detectors
Inez Raguenet, Carlos Maziero |
SEC | 2 |
| 2007 | A Three-Pass Protocol for Cryptography Based on Padding for Wireless NetworksabstractThis paper proposes an alternative cryptography protocol based on padding for wireless networks. It uses an orthogonal set of rotation matrices and a three-pass exchanging protocol to reach the encryption. The communicating parties do not need to know cryptographically nothing from each other in order to guarantee the communication privacy. The security of the algorithm is based on the continuous changing of the orthogonal matrix set used on the encryption process. The proposed protocol does not require any kind of keys pre- distribution. This feature is desirable for wireless ad hoc networks, where there is no predefined infrastructure, as required on classical secure channel encryption. The prototype shows that the proposal is feasible and can be advantageous when compared to One-Time Padding. Andre Gustavo Degraf Uchoa, Marcelo Eduardo Pellenz, Altair Olivo Santin, Carlos Maziero |
CCNC | 4 |
| 2007 | A Grammar for Specifying Usage Control PoliciesabstractUsage control goes beyond traditional access control, addressing its limitations related to attribute mutability and continuous usage permission validation. The recently proposed UCONABCmodel establishes an underlying mathematical framework to deal with the new needs of security and control systems. That model was only described by a logic specification, and this paper proposes implementing it as an LALR(1) grammar, which is defined here. The proposed grammar is then used for representing common access and usage control scenarios, showing its expressiveness and usefulness. The proposed grammar is being incorporated into a file usage control mechanism implemented on a COTS operating system. Rafael Teigao, Carlos Maziero, Altair Olivo Santin |
ICC | 2 |
| 2007 | Protecting host-based intrusion detectors through virtual machines
Marcos Laureano, Carlos Maziero, Edgard Jamhour |
Comput. Networks | 2 |
| 2004 | A framework for protecting Web services with IPsecabstractThis work proposes a WSDL extension for describing IPsec policies for protecting Web services communications. By using the proposed extension, a Web service (server) informs to its clients, along with the offered service descriptions, a set of IPsec policies that must be used in order to have access to its services. The proposed extension is based on the IETF policy model for describing IPsec policies. Besides the model, The work presents an approach for transforming the IPsec policies into configuration commands through XSL transformations. Cássio Ditzel Kropiwiec, Edgard Jamhour, Carlos Maziero |
ISCC | 3 |
| 2003 | A Policy Based Framework for Access Control
Ricardo Nabhen, Edgard Jamhour, Carlos Maziero |
ICICS | 3 |
| 2003 | RBPIM: A PCIM-Based Framework for RBACabstractThis paper presents a PCIM-based framework for storing and enforcing RBAC (role based access control) policies in distributed heterogeneous systems. PCIM (policy core information model) is a generic information model proposed by IETF. This paper proposes a PCIM extension, called RBPIM (role-based policy information model), in order to represent network access policies based on the RBAC model. An RBPlM implementation framework based on the POP/PEP (policy decision point/policy enforcement point) approach is also presented. In the proposed framework, the communication between the PDP and the PEPs is implemented using the COPS (common open policy service) protocol, also defined by the IETF. The framework adopts the outsourcing approach, where the policy rules are evaluated by the PDP, as defined by the COPS standard. This paper evaluates the outsourcing model for access control by presenting a case study and the average response time of PDP under different load conditions. Ricardo Nabhen, Edgard Jamhour, Carlos Maziero |
LCN | 3 |
| 1997 | Implementing replicated services in open systems using a reflective approachabstractIn this paper we evaluate the use of an object-oriented open platform based on the CORBA standard for the implementation of replicated services. To improve the flexibility of the implementation, we use a reflective approach, which allows for separation of aspects related to the replication model from those related exclusively to the service being replicated. This separation makes it possible to modify the replication protocol according to the fault tolerance level desired, without any implications for the application code. Joni da Silva Fraga, Carlos Maziero, Lau Cheuk Lung, Orlando Loques |
ISADS | 2 |