Percorrer por autor "Guerreiro, Joel"
A mostrar 1 - 9 de 9
Resultados por página
Opções de ordenação
- Allocation of resources in SAaaS Clouds managing thing mashupsPublication . Guerreiro, Joel; Rodrigues, Luis; Correia, NoéliaThe sensing and actuation as-a-service is an emerging business model to make sensors, actuators and data from the Internet of Things more attainable to everyday consumer. With the increase in the number of accessible Things, mashups can be created to combine services/data from one or multiple Things with services/data from virtual Web resources. These may involve complex tasks, with high computation requirements, and for this reason cloud infrastructures are envisaged as the most appropriate solution for storage and processing. This means that cloud-based services should be prepared to manage Thing mashups. Mashup management within the cloud allows not only the optimization of resources but also the reduction of the delay associated with data travel between client applications and the cloud. In this article, an optimization model is developed for the optimal allocation of resources in clouds under the sensing and actuation as-a-service paradigm. A heuristic algorithm is also proposed to quickly solve the problem.
- Automated LLM exploit generation framework (ALEGF)Publication . Guerreiro, Joel; João SantosSoftware development frequently suffer from programming defects, mistakes and design flaws introducing critical security vulnerabilities. These weaknesses can be exploited causing significant operational disruption and organizational losses. Identifying and exploiting such vulnerabilities is a complex task that requires binary or source code detailed analysis, operating systems deep knowledge, file system formats and processor architectures, as well as expertise in multiple techniques. Traditional Automatic Exploit Generation (AEG) approaches rely on symbolic execution, fuzzing and heuristicbased methods. In this paper, an automated framework is presented and designed to evaluate Large Language Models (LLMs) to detect vulnerabilities and generate exploits without human intervention. The framework operates within a controlled, sandboxed and fully reproducible environment to prevent real-word security risks while enabling systematic experimentation. The objective is to assess whether LLMs can serve as auxiliary tools for software security testing and vulnerability analysis. The results provide insights into the feasibility, limitations and potential LLM-driven automated exploitation, yet not competitive with AEG tools state-of-the-art.
- RELOAD/CoAP architecture for the federation of wireless sensor networksPublication . Pisco, Luís; Guerreiro, Joel; Correia, NoéliaSensing devices are expected to interconnect over large geographical areas and federations of wireless sensor networks are expected in a near future. In such environments a critical issue is how to discover the resources available at devices in a scalable manner. For this purpose, a Constrained Application Protocol (CoAP) Usage for REsource LOcation And Discovery (RELOAD), a generic self-organizing Peer-to-Peer (P2P) overlay network service, has been defined to be used as a lookup service, to store available device resources and as a cache for sensor data. Each P2P resource, at the RELOAD/CoAP overlay, includes references to device resources, hosted at one or more constrained nodes, but no provision is made for the insertion of bindings/references to P2P resources already available at the P2P overlay network. Such feature would increase the efficiency and consistency of storage, avoiding duplicate references, a very relevant issue for future IoT applications relying on the federation of wireless sensor networks. In this article an extension to the service provided by CoAP Usage is proposed so that resource bindings can be managed. Two binding models, and a heuristic algorithm for their implementation, are proposed. Results show that such models lead to a better resource organization, reducing the number of sensor resource entries and/or fetches to the P2P overlay.
- RELOAD/CoAP architecture with resource aggregation/disaggregation servicePublication . Pisco, Luís; Guerreiro, Joel; Correia, NoéliaM2M communication is expected to occur at a global level and for this reason federations of device networks are also expected. In such large scale environments, a critical issue is how to discover the available resources in a scalable manner. For this purpose CoAP Usage for RELOAD, a generic self-organizing P2P overlay network service, has been proposed to be used as a lookup service, to store available resources and as a cache for sensor data. However, such approach alone does not allow building an aggregate resource hierarchy, a very relevant issue for an efficient organization of data in future IoT applications. Here we address this issue and propose an architecture incorporating a resource aggregation/disaggregation service.
- Remote secure online voting system developmentPublication . Matos, Tiago; Guerreiro, JoelRemote online elections have been studied and applied throughout the years in several countries with different approaches and distinct secure mechanisms. Online elections collect sensitive information therefore, the system, must guarantee confidentiality, integrity, privacy, security and be auditable to ensure a successful and creditable election process. A distinct web-based system approach, as far known, was developed using data processing, backend, storage and frontend components secured by cipher suites and an independent developed asymmetric cryptography key management system. Both, cipher suites and the key manage system, ensure authentication, authorization and vote encryption before storage, making it impossible to visualize election results primary to vote counting initiation and user’s votes choices. The developed system implements a mechanism to verify enabled users accesses in a specific election and ensure if they already voted, avoiding repeated votes. Encrypts, stores votes and users in distinct database tables to avoid, even with direct database access, the knowledge of who has voted so far and what was the vote direction, displaying statistics information of the already casted number of votes, being, the election committee, able to monitor effectiveness, before the voting period ends. The developed and implemented databases follows ACID (Atomicity, Consistency, Isolation and Durability) properties, assuring each statement in a transaction is treated as a single unit preventing data loss and corruption, ensuring consistency, isolating user transactions, guaranteeing no transaction interferes with another and, on the event of a system failure, is assured that all executed transactions are saved and no data is lost.
- Resource allocation model for sensor clouds under the sensing as a service paradigmPublication . Guerreiro, Joel; Rodrigues, Luis; Correia, NoéliaThe Sensing as a Service is emerging as a new Internet of Things (IoT) business model for sensors and data sharing in the cloud. Under this paradigm, a resource allocation model for the assignment of both sensors and cloud resources to clients/applications is proposed. This model, contrarily to previous approaches, is adequate for emerging IoT Sensing as a Service business models supporting multi-sensing applications and mashups of Things in the cloud. A heuristic algorithm is also proposed having this model as a basis. Results show that the approach is able to incorporate strategies that lead to the allocation of fewer devices, while selecting the most adequate ones for application needs.
- Resource design in federated sensor networks using RELOAD/CoAP overlay architecturesPublication . Rodrigues, Luis; Guerreiro, Joel; Correia, NoéliaSensor networks can be federated for wide-area geographical coverage using RELOAD/CoAP architectures. In this case, proxy nodes of constrained environments form a P2P overlay to announce device resources or sensor data. Although this is a standard-based solution, consistency problems may arise because P2P resources (data objects stored at the overlay network) may end up including similar device resource entries. This is so because device resource entries, or sensor data, can be announced under different P2P resource umbrellas, meaning that any update to them will require changing multiple P2P resources. Here in this article, a multi-layer approach is proposed to solve this issue, allowing for a more efficient storage/retrieval of IoT data. Information at the overlay network is kept consistent, although additional P2P anonymous resources must be created. A mathematical model is proposed for the planning of such multi-layer organization of P2P resources, together with a heuristic algorithm. A required overlay service is also discussed.
- A secure LoRaWan architecture and infrastructure approachPublication . Guerreiro, JoelThe Internet of Things (IoT) has been widely implemented for objects, uniquely identified, to become accessible through the internet. Several communication protocol technologies were studied and applied to interconnect objects using the internet. Nowadays, one of the most used is Low Power Wide Area Network (LPWAN) implemented over Narrow Band-Internet of Things (NB-IoT) or Long Range Wide Area Network (LoRaWAN) platforms. In this paper, a LoRaWAN architecture and infrastructure implementation is addressed to secure data and communications protecting Network Servers and communication between gateways and the demilitarized zone (DMZ), using several secure techniques and infrastructure virtualization software for containers.
- Sensing and actuation as a service for health data integrationPublication . Guerreiro, JoelIn the last few years, many advances in sensing usage have been developed, and their application on healthcare is substantially growing due to many factors, but the most important one is the patient's physical parameters data gathering for remote monitorization and intervention. Sensing and actuation as a service using clouds as basis may provide a platform to directly connect the patient's sensors to the health care providers and fast monitor or intervene in case of alarm, especially on elderly people. In Portugal, all patient's data is collected to a personal patient data register (health portal), that can be seen by any medical and technical health staff working on public institutions. This study aims to design a framework using sensing and actuation as a service on clouds able to provide data integration into the Portuguese National Patient Data Register and alarm triggering for fast medical intervention.
