Projects: Network Security
2021 – 2024 - Security with zero trust: algorithms, protocols and architectures.
- Coordinator: Marcos Antonio Simplicio Junior
- Description: Following the growing concern about cyberattacks worldwide, security technologies have gained importance in which system protection can be implemented and measured without the need to place a large degree of trust in specific entities, a model known as zero trust. This approach seeks to create distributed systems that are more resilient to attacks by (I) avoiding single points of failure, (II) engaging system entities to act collaboratively in their security, and (III) preventing breaches even in the event of collusion between one or more nodes participating in the network. Illustrative examples of technologies (classic or more modern) that follow this principle include: digital signatures, which allow verifying the integrity, authenticity and authorship of documents; blockchain, used to define and verify the relative order between various events in a system; Zero-knowledge proofs and homomorphic cryptography, through which it is possible to prove characteristics or perform calculations on certain encrypted data without revealing its value openly; among others. In this context, this research project aims to evaluate the use of this type of security technology in different application scenarios considered relevant and for which security is an important requirement. As a result, it is expected to: (I) specify new cryptographic algorithms and protocols that are suitable for the needs of the target scenario (e.g., resource constraints, mobility, regulations); and (II) design security architectures resilient to cyberattacks from their conception. CNPq Productivity Grant 304643/2020-3.
2020 – 2024 - Protecting software supply-chains via (semi)automatic detection of built-in malicious code.
- Coordinator: Marcos Antonio Simplicio Junior
- Description: The goals of the project are: (1) to identify and characterize different types of Built-in Malicious Code (BiMC) in software and their possible/probable origins; and then (2) to develop techniques and tools to (semi)automatically detect them or mitigate their effects. The proposed solutions should complement other techniques for secure software development, such as: component inventory for better visibility; repository authentication for reducing the attack surface of the software supply chain; automatic updates and attack monitoring for after-fact mitigation; and static code analysis for bug removal. The end result should be better-quality software that does what it should, how it should, and nothing else.
2020 – 2022 - Analysis and implementation of a reference Protocol and Data Model for Security (SPDM).
- Coordinator: Marcos Antonio Simplicio Junior
- Description: There are some works in the literature focused on dealing with firmware modification attacks. One of the main and most comprehensive initiatives in this regard is the Security Protocol and Data Model (SPDM). Essentially, its specification defines a set of mechanisms and formats for hardware and firmware authentication, in the form of an open industry standard. Furthermore, ongoing work on SPDM incorporates a key agreement protocol to protect the confidentiality and integrity of data transmitted between components. The main objective of this project is to comprehensively evaluate the SPDM security architecture, identifying potential flaws or improvements in the protocol, and providing a reference implementation to assess its experimental performance.
2020 – 2021 - Silent Threat Detection.
- Coordinator: Wilson Vicente Ruggiero
- Description: The advent of APT (Advanced Persistent Threats) cyber threats has brought new challenges to cybersecurity teams, as it involves advanced attack techniques, with the use of prolonged, differentiated, and targeted attacks that, due to their characteristics, may not be detected by conventional tools. The objective of this project was to define a solution for detecting APT attacks in their initial stages, according to Lockheed Martin's Cyber Kill Chain model, through continuous monitoring and the use of Big Data and Artificial Intelligence techniques. Project certified by coordinator Wilson Vicente Ruggiero on 02/15/2026.
2018 – 2020 - Security in Electronic Transactions.
- Coordinator: Wilson Vicente Ruggiero
- Description: This project addressed four research topics: 1) Silent Threats: Advanced Persistent Threat - APT and semi-automatic backdoor detection; 2) Capture, Processing, and Analysis of Large Data Sets using Deep Learning algorithms; 3) Intelligent Systems: Ontologies, Sentiment, and Memory; 4) Natural Language Processing in Portuguese.
2017 – 2020 - Key Management for vehicular communications.
- Coordinator: Marcos Antonio Simplicio Junior
- Description: The goal of the project is to provide a secure, efficient, privacy-preserving, and scalable key management architecture for use in vehicular communications. This includes solutions for: (1) the lightweight establishment of public/private key pairs, so the process can be repeated frequently if necessary with low overhead in terms of processing, memory usage, and bandwidth for the end users; (2) a lightweight key revocation procedure; (3) a privacy-preserving mechanism for the messages exchanged, whereas privacy can be revoked in case of misbehavior; (4) a lightweight approach for authenticating broadcast messages; and (5) a (set of) mechanisms for group keying to handle scenarios such as vehicle platooning.. Project certified by the company LG Electronics do Brasil on 07/07/2017.
2016 – 2019 - Security and Mobility with High Scalability – 2.
- Coordinator: Wilson Vicente Ruggiero
- Description: This research project in collaboration with industry aims to continue the work carried out in the previous stage, with the potential to produce new publications and innovations in the area of information security in large-scale environments. Work is being deepened in the areas of: Homomorphic cryptography, transferable digital currencies, blockchain, automatic document processing, capture and recognition, fraud detection and prevention in mobile devices, and recommendation systems for distributed environments. Project certified by SCOPUS SOLU ES EM TI LTDA on 03/13/2017.
2016 – 2017 - Post Quantum Cryptography.
- Coordinator: Wilson Vicente Ruggiero
- Description: This research project in collaboration with industry aims to continue the work carried out in the previous stage, with the potential to produce new publications and innovations in the area of information security in large-scale environments. Work is being deepened in the areas of: Homomorphic cryptography, transferable digital currencies, blockchain, automatic document processing, capture and recognition, fraud detection and prevention in mobile devices, and recommendation systems for distributed environments. Project certified by SCOPUS SOLU ES EM TI LTDA on 03/13/2017
2014 – 2019 - Information Security and Reliability: Theory and Practice.
- Coordinator: Marcelo Firer
- Description: FAPESP Thematic Project: continues the efforts made over the last twelve years, supported by three Thematic Projects funded by FAPESP, aiming to develop research that can be summarized under the title "Information Security and Reliability: Theory and Applications", which covers topics related to Information Theory, Error-Correcting Codes and Cryptography (in their broad meanings), involving researchers in engineering, mathematics and computer science. Research objectives include theoretical questions and applications to diverse areas, including genomics, image transmission and processing, and sensor networks. (AU). FAPESP Project 13/25977-7.
2012 – 2016 - Security and Mobility with High Scalability – 1.
- Coordinator: Wilson Vicente Ruggiero
- Description: The Security and Mobility with High Scalability - 1 research project aims to develop new technologies that boost financial transactions through new means of payment or value transfer. These technologies should stimulate the expansion of access through cell phones, smartphones, smart cards, and other low-cost electronic devices to segments of the Brazilian population that are not yet integrated into the banking or e-commerce system.
2012 – 2014 - Security in Peer-to-Peer IPTV Systems.
- Coordinator: Marcos Antonio Simplicio Junior
- Description: The focus of this project is on the specification and development of security mechanisms for P2P-based IPTV systems, providing services such as privacy, detection of network abuse for the dissemination of invalid content or the promotion of attacks (e.g., denial of service), data availability guarantee, among others. The objective is to create and evaluate an architecture that efficiently combines advanced IPTV services (e.g., time-shifted transmission) with such security services. (FAPESP Project 2011/21592-8).
2012 – 2013 - Prevention of cheating in peer-to-peer online games.
- Coordinator: Marcos Antonio Simplicio Junior
- Description: This project has the specific objective of applying cryptographic mechanisms for the detection of cheating in collectible card games (CCGs) supported by a P2P architecture. More specifically, the developed security mechanisms aim to create a software CCG capable of capturing the characteristics of a game played with physical cards, including as minimum security requirements the ability to: (1) Ensure that the order of cards in all players' decks is random and cannot be manipulated by any player; (2) Ensure the confidentiality of the cards until the moment they actually need to be revealed by the player; (3) Allow players to verify that their opponents' cards were acquired legitimately; (4) Prevent two or more players from collaborating to violate any of the previous properties.
2011 – 2013 - Cryptography and Security for Devices with Limited Resources.
- Coordinator: Paulo S. L. M. Barreto
- Description: Abstract: Applications in areas such as pervasive computing and the Internet of Things (IoT) intensively utilize devices such as wireless sensors, smart cards, and radio frequency identification (RFID) tags. A challenge in this context refers to the limited availability of resources such as memory, processing power, and energy in these devices, which hinders or even prevents the application of security mechanisms used in traditional networks. This paper proposes to conduct research to provide security mechanisms (including algorithms and protocols) specifically adapted to platforms with limited resources, creating a framework of security solutions for applications that depend on devices with these characteristics.
2009 – 2011 - Project of a rule machine for online fraud detection.
- Coordinator: Wilson Vicente Ruggiero
- Description: Project funded by Scopus Tecnologia for the specification and development of a proof of concept for a rules machine capable of detecting electronic fraud situations in real time.
2007 – 2009 - Security in Wireless Sensor Networks.
- Coordinator: Tereza Cristina Melo de Brito Carvalho
- Description: This project aims to study, specify, and implement symmetric and asymmetric encryption algorithms that can be used for authentication and encryption of data exchanged in a sensor network, whose components have processing, memory, and battery limitations. Project certified by Ericsson Telecomunicações - Matriz on 04/05/2023.
2006 – 2008 - MPSD Phase II.
- Coordinator: Wilson Vicente Ruggiero
- Description: Duration 6 months. Funded by Ericsson Research Sweden, Value: R$ 250,000.00. This project is a continuation of the previous MPSD project. The objective of this phase is to conduct a study on the trade-off between security, privacy, and ease of use in personal domain environments. The project will produce a technical specification demonstrating the trade-off between these conflicting factors. An implementation will also be carried out to conduct a field study evaluating, from the point of view of a typical user, the effectiveness of the established trade-off between the factors of security, privacy, and ease of use.
2006 – 2008 - GIM - Security and Business Monitoring.
- Coordinator: Wilson Vicente Ruggiero
- Description: Project for online monitoring of information security aspects and online systems and businesses.
2005 – 2007 - Security in ATCA (Advanced Telecom Computing Architecture) Systems.
- Coordinator: Tereza Cristina Melo de Brito Carvalho
- Description: The objective of this project is to evaluate the level of security offered by a Data Center when it is based on the use of ATCA (Advanced Telecom Computing Architecture). To this end, potential internal and external attacks were identified and tests were carried out, performing such attacks and observing the system's behavior. In this case, different types of blade server allocation in ATCA can be assumed, for example, each company may have a different blade within the same blade server. Security solutions for these attacks will be evaluated in a future project. Project certified by Ericsson Telecomunicações - Headquarters on 04/05/2023.
2005 – 2007 - Platform for Secure Computing.
- Coordinator: Wilson Vicente Ruggiero
- Description: Research Project: Secure Computing Platform: Period: 2005 - 2006 - 6 months; Partner: Ericsson Research Sweden, Ericsson Research Canada; Value: R$250,000.00. Sponsor: Ericsson Brazil, Ericsson Research Sweden, Ericsson Research Canada. Areas: Ad hoc Networks, Personal Area Networks, Security, Middleware. Advanced Telecom Computing Architecture (A-TCA) aims to take the widely deployed network paradigm and within a site, offer a layered framework to the application nodes of a telecom network, using standard server blades and open standard network interfaces and protocols. This makes the applications nodes act as network elements within a framework. In this project, they will be investigating security aspects related to their A-TCA. At first, it will be identified: the main security threats of an A-TCA. Based on this study and security evaluation, it will be specified security services and mechanisms and proposed a security system for A-TCA.
2004 – 2006 – SEL.
- Coordinator: Tereza Cristina Melo de Brito Carvalho
- Description: Security Enforcement Layer (SEL) Duration: 15 months; Financier: Ericsson; Value: R$230,000.00. A Personal Security Domain (PSD) is an enhancement of PAN/ad-hoc networks where devices can be either link-local (e.g. Bluetooth) or remote (IP access over Internet). Furthermore, a PSD can be both centralized ("My Devices") as well as ad-hoc ("My Mates PSD"). Again, in the latter case, some friends may be local, others in distant locations. The generic application of a PSD is resource sharing (files, music, calendar, contact lists, connectivity, printing facility etc). Secure sharing requires that applications go via a Security Enforcement Layer (SEL) that enforces sharing policy (e.g. access control), security and privacy. The goal of the project is to explore, define and implement the concept of SEL for MPSD environments. Different functionality of SEL must be defined in order to provide the devices with necessary mechanisms to implement the MPSD. A valid architecture for the SEL must be proposed. The architecture and different functionality soundness must be validated through the prototyping on top of Linux environment. It should result in Research papers and possibly also ideas for Intellectual properties requests (IPR). Even though, the target operating system is Linux, all concepts must be implemented with possible extensions to other OSs (especially embedded ones) in mind..
2004 – 2006 - Multiple Secure Personal Domains.
- Coordinator: Tereza Cristina Melo de Brito Carvalho
- Description: The objective of this project was to implement a prototype version of a Multiple Secure Personal Domains (MPSDs) system, with the basic premise being the usability of this system by people without technological expertise. Each Personal Secure Domain (PSD) consisted of a set of devices and applications, belonging to a single user, interconnected through a PAN (Personal Area Domain) implemented through a BT (Bluetooth) or IEEE 802.11 network. Operations such as adding and removing devices and applications; reading and/or transferring files between devices could be performed using security mechanisms such as authentication and encryption of data channels. As users can gather and bring their Secure Personal Domains (SPDs) with them, it becomes necessary to create MPSDs, which correspond to several networked SPDs with the possibility of communication and information exchange between them. The user of this system could choose to use the basic or advanced security service associated with intra- or inter-domain operations. The basic service prioritized usability, and access to various operations and services was obtained using one or a few passwords. The advanced service prioritized security, and access to each application and service required a new password. This Multiple Secure Personal Domains environment was implemented and tested using two basic applications: file transfer and electronic calendar. Project certified by coordinator Tereza Cristina Melo de Brito Carvalho on 08/15/2014.
2004 – 2006 - MPSD - Phase I.
- Coordinator: Wilson Vicente Ruggiero
- Description: Research Project: Multiple Personal Security Domains (MPSD): Duration: 15 months; Financier: Ericsson; Value: R$ 250,000.00 One of the most important technology advances of these last decades is related to mobile wireless communications. As a result, it has been created wireless communication support not only for voice systems but also for domestic and other types of daily use data devices. These devices are able to communicate with each other and also to connect to the Internet. Such mobile devices impose a highly dynamic behavior to such networks. It is not possible to count for sure with the guaranteed presence of any network element to ensure a reliable and secure operation. Additionally, the availability of anything, anywhere at anytime creates an ideal environment to offer important and convenient services through the network. In this scenario, new security and trust issues must be considered. In recent days, home or small-office networking and collaborative computing with portable devices in a small area (e.g. a conference or classroom, single building, convention center) has emerged as one major area of potential application of this technology. In addition, people also recognize that ad-hoc networking has obvious potential application in all traditional areas of interest for mobile computing. Security is an important issue in all network environments, but in wireless networks it assumes an even more dramatic importance. Wireless networks are naturally open: it is not possible to prevent others from getting data being transmitted. In our previous project, it was defined the concept of virtual domain as being a local domain where the devices were connected through a wireless networks, based on IEEE 802.11 or Bluetooth technologies that provide support for ad hoc networks. In this case, it was possible to create several domains associated with some specific places such as home, school or office. The same device could belong to several domains..
2004 – 2006 - Security Reinforcement Layer.
- Coordinator: Tereza Cristina Melo de Brito Carvalho
- Description: The objective of this project was to develop a security reinforcement layer implemented between the application layer and the transport layer, taking the TCP/IP protocol architecture as a reference. The main functions of this layer were to authenticate users, applications, and network services using the exchange of X.509 type certificates with associated trust values, and to encrypt data transferred between users and network services when necessary. As a proof of concept, this layer was implemented within the context of ad hoc networks for Multiple Secure Personal Domains (MPSDs), developed within the scope of another research project. Project certified by Ericsson Telecommunications - Headquarters on 04/05/2023.
2002 – 2003 - Security in Ad-Hoc Networks.
- Coordinator: Wilson Vicente Ruggiero
- Description: Security in Ad-Hoc network environments. Duration: 2 years; Funding: ERICSSON - Sweden; Value: R$ 975,000.00. One of the most important technological advances of recent decades is related to wireless communication. As a result of these advances, wireless communications have been developed to support not only telephony, but also household devices and other types of daily use. These devices must be enabled to communicate with other devices in any environment and also connected to the Internet. Devices can be: computers, telephones, audio/video equipment, air conditioning/heating systems, etc. A home environment will be a mixture of reasonably stable networks and an Ad-Hoc network, where some devices are present in the home environment for a long period of time, and on the other hand, others are present sporadically. As can be inferred, security is an important aspect in any network environment; however, in wireless networks, different aspects are considered. A wireless network is naturally open, where it is not possible to prevent malicious individuals from eavesdropping on a connection and obtaining transmitted data; thus, it is a naturally insecure environment. In traditional networks, security aspects are usually supported in different protocol layers. Typically, data encryption is performed at the session layer, and its development depends on the type of application supported. More recently, due to the increased importance of security, encryption objectives have been incorporated into network protocols. Therefore, the main purpose of this project is to identify threats and security problems in these Ad-Hoc network environments, specify, implement, and develop a security model and architecture for this environment, based on an application scenario. Project certified by Ericsson Telecommunications - Headquarters on 02/02/2024. Project certified by coordinator Wilson Vicente Ruggiero on 09/16/2013.
1998 – 2010 – Security.
- Coordinator: Wilson Vicente Ruggiero
- Description: Research Project - Software and Security Systems Development: Duration: 8 years; Funding: SCOPUS Tecnologia S.A.-Banco Bradesco; Value: R$ 8,000,000.00 Most recent projects: Web Search Systems with Phonetic Characteristics and Lexical Inaccuracies. The objective of this project is the development of a search system for information in specific contexts (defined in a configurable way) on the web. The search system must take into account the phonetic aspects and lexical inaccuracies that may eventually occur in the system's data entry when defining the key to be searched. Specifically, the system to be developed must be specialized for its initial application: searching for products and prices in online stores. Initially, consideration should be given to using a commercially available search infrastructure suitable for the project's purpose. Based on this identified infrastructure or another specified one, the development of the specified search system should begin, highlighting the configuration features available in the systems to define the universe and interests of the searches performed. The expected result should be a search component that can be easily integrated into generic web portal projects, for both Microsoft Windows NT and Unix Solaris environments. Sensitive Navigation System Based on Dynamic User Profiles The objective of this project is to define an architecture and implement a series of components that enable the tracking of user navigation sequences within a portal through sensitive points, defined a priori, allowing the creation of a dynamic user interest profile within the portal.