SearcharxivSearch

arXiv subjects

Leandro Bertholdo

Publications and source records attributed to Leandro Bertholdo.

4 recordsLinked to original sources

NetSecBed: A Container-Native Testbed for Reproducible Cybersecurity Experimentation

Cybersecurity research increasingly depends on reproducible evidence, such as traffic traces, logs, and labeled datasets, yet most public datasets remain static and offer limited support for controlled re-execution and traceability, especially in heterogeneous multi-protocol environments. This paper presents NetSecBed, a container-native, scenario-oriented testbed for reproducible generation of network traffic evidence and execution artifacts under controlled conditions, particularly suitable for IoT, IIoT, and pervasive multi-protocol environments. The framework integrates 60 attack scenarios, 9 target services, and benign traffic generators as single-purpose containers, enabling plug-and-play extensibility and traceability through declarative specifications. Its pipeline automates parametrized execution, packet capture, log collection, service probing, feature extraction, and dataset consolidation. The main contribution is a repeatable, auditable, and extensible framework for cybersecurity experimentation that reduces operational bias and supports continuous dataset generation.

cs.CR

IoTEdu: Access Control, Detection, and Automatic Incident Response in Academic IoT Networks

The growing presence of IoT devices in academic environments has increased operational complexity and exposed security weaknesses, especially in academic institutions without unified policies for registration, monitoring, and incident response involving IoT. This work presents IoTEdu, an integrated platform that combines access control, incident detection, and automatic blocking of IoT devices. The solution was evaluated in a controlled environment with simulated attacks, achieving an average time of 28.6 seconds between detection and blocking. The results show a reduction in manual intervention, standardization of responses, and unification of the processes of registration, monitoring, and incident response.

cs.CR

The Effect of the Russian-Ukrainian Conflict from the Perspective of Internet eXchanges

In 2022 the Russian invasion of Ukraine began. It is known that Ukraine faced outages because of the damage to their infrastructure. It is also known that Russia was boycotted by the international community. However the impact on the telecommunications of the two countries remains unknown. In this paper we quantified the degree to which the Internet was affected in both countries by analyzing routing tables from five large Internet Exchange Points (IXPs). IXPs provide a central point of interconnection where internet traffic can be freely exchanged between Autonomous Systems (ASes). This centrality makes IXPs a good vantage point for analyzing changes in the Internet infrastructure. With data collected before and after the start of the conflict we observed considerable damage to the Ukrainian Internet network with numerous outages and minimal damage to the Russian network. An average of 11.12% of Ukrainian ASes were unreachable at each IXP. We identified the biggest outages and the events responsible for them. This paper highlights resilience issues during conflicts to the network and management community, and serves as a basis for future more in-depth research.

cs.NI

Anycast Agility: Network Playbooks to Fight DDoS

IP anycast is used for services such as DNS and Content Delivery Networks (CDN) to provide the capacity to handle Distributed Denial-of-Service (DDoS) attacks. During a DDoS attack service operators redistribute traffic between anycast sites to take advantage of sites with unused or greater capacity. Depending on site traffic and attack size, operators may instead concentrate attackers in a few sites to preserve operation in others. Operators use these actions during attacks, but how to do so has not been described systematically or publicly. This paper describes several methods to use BGP to shift traffic when under DDoS, and shows that a response playbook can provide a menu of responses that are options during an attack. To choose an appropriate response from this playbook, we also describe a new method to estimate true attack size, even though the operator's view during the attack is incomplete. Finally, operator choices are constrained by distributed routing policies, and not all are helpful. We explore how specific anycast deployment can constrain options in this playbook, and are the first to measure how generally applicable they are across multiple anycast networks.

cs.NI