People
Nuno Antunes
Address
Departamento de Engenharia Informática daFaculdade de Ciências e Tecnologia da Universidade de Coimbra
Pólo II
Pinhal de Marrocos
3030-290 Coimbra
Home Page
http://eden.dei.uc.pt/~nmsa/CV Long
Member
Software and Systems EngineeringResearch interests
- Dependable and Secure Software- Vulnerability and Intrusion Detection
- Cloud Security
- Verification and Validation
Affiliation
Department of Informatics EngineeringFaculty of Sciences and Technology
University of Coimbra
Short Bio
Nuno Antunes is an Assistant Professor at the Department of Informatics Engineering of the University of Coimbra.Since 2008 he has been actively researching topics of secure and dependable software with the Software and Systems Engineering group of CISUC. His expertise includes testing techniques, fault injection, vulnerability injection and benchmarking, which are applied to the assessment of web services, web and mobile applications, virtualized environments and data management systems.
Recently he is working intensively in cloud security. In particular, he is involved on the H2020 project EUBra-BIGSEA, which aims at applying cloud services for Big Data analytics in a scenario with high social and business relevance: the processing and analysis of huge quantities of data from massively connected societies.
National Projects
METRICS: Monitoring and Measuring the Trustworthiness of Critical Cloud Systems
International Projects
H2020 ATENA (Advanced Tools to assEss and mitigate the criticality of ICT compoNents and their dependencies over Critical InfrAstructures)
ALIOT: Internet of Things: Emerging Curriculum for Industry and Human Applications
FCT/ CAPES - SORTS: Supporting the Orchestration of Resilient and Trustworthy Fog Services
ATMOSPHERE Adaptive, Trustworthy, Manageable, Orchestrated, Secure, Privacy-assuring, Hybrid Ecosystem for REsilient Cloud Computing
PoSeID-on, EU H2020 IA – Protection and control of Secured Information by means of a privacy enhanced Dashboard
ATMOSPHERE: Adaptive, Trustworthy, Manageable, Orchestrated, Secure, Privacy-assuring, Hybrid Ecosystem for REsilient Cloud Computing.
Past Projects
CRITICAL Software Technology for an Evolutionary Partnership (CRITICAL STEP)
Menon@WS - Methodologies for the Development of Non-Vulnerable Web Services
CECRIS – CErtification of CRItical Systems
DEVASSES: DEsign, Verification and VAlidation of large-scale, dynamic Service SystEmS
CABRIOLET – Model-Oriented Approach and Intelligent Knowledge-Based System for Evolvable Academia-Industry Cooperation in Electronic and Computer Engineering
V-SIS – Validação de Sistemas Críticos
EUBrasilCloudFORUM: Fostering an International dialogue between Europe & Brazil
EUBra-BIGSEA: Europe – Brazil Collaboration of BIG Data Scientific Research through Cloud-Centric Applications
COST Action IC1402: Runtime Verification beyond Monitoring (ARVI)
Journal Articles
2020
(2 publications)- Casaleiro, R. and Paulo Silva and Simões, P. and Boavida, F. and Edmundo Monteiro and Marilia Curado and Tiago Cruz and Nuno Antunes and Marco Vieira and Riccio, G.M. and Verzillo, M.P. and Marek, P. and Goncalves, L. and Bagnato, A. and Valentini, A. and Intonti, B. and Manzo, R. and Posta, V.D. and Zampolini, L. and Rooij, J.v. and Houf, R. and Rios, E. and Iturbe, E. and Gutierrez, I. and Anguita, S. and Gomez, C. and Echevarria, J. and Houf, H. and Nicoletti, L. and Lotti, R. and Natale, D. and Pizzo, L.d. and Pane, F. and Schiavo, F. , "Protection and control of personal identifiable information: The PoSeID-on approach", Journal of Data Protection & Privacy, vol. 3, 2020
- Paulo Silva and Casaleiro, R. and Simões, P. and Nuno Antunes and Marilia Curado and Edmundo Monteiro , "Risk Management and Privacy Violation Detection in the PoSeID-on Data Privacy Platform", SN Computer Science, vol. 1, 2020 [ DOI ]
2019
(2 publications)- Alic, A.S. and Almeida, J. and Aloisio, G. and Andrade, N. and Nuno Antunes and Ardagna, D. and Badia, R.M. and Basso, T. and Blanquer, I. and Braz, T. and Brito, A. and Elia, D. and Fiore, S. and Guedes, D. and Lattuada, M. and Lezzi, D. and Maciel, M. and Jr, W.M. and Mestre, D. and Moraes, R. and Morais, F. and Pires, C.E. and Kozievitchi, N.P. and Santos, W.d. and Paulo Silva and Marco Vieira , "BIGSEA: A Big Data analytics platform for public transportation information", Future Generation Computer Systems, 2019 [ DOI ]
- Braga, A.M. and Dahab, R. and Nuno Antunes and Laranjeiro, N. and Marco Vieira , "Understanding How to Use Static Analysis Tools for Detecting Cryptography Misuse in Software", IEEE Transactions on Reliability, 2019 [ DOI ]
2018
(1 publication)- Paulo Silva and Basso, T. and Nuno Antunes and Moraes, R. and Marco Vieira and Simões, P. and Edmundo Monteiro , "A Europe-Brazil Context for Secure Data Analytics in the Cloud", IEEE Security & Privacy, vol. 16, pp. 52-60, 2018 [ DOI ]
2016
(1 publication)- Nuno Antunes and Marco Vieira , "Designing vulnerability testing tools for web services: approach, components, and tools", International Journal of Information Security, pp. 1-23, 2016 [ DOI ]
2015
(1 publication)- Nuno Antunes and Marco Vieira , "Assessing and Comparing Vulnerability Detection Tools for Web Services: Benchmarking Approach and Examples", IEEE Transactions on Services Computing, 2015 [ DOI ]
2014
(1 publication)- Nuno Antunes and Marco Vieira , "Penetration Testing for Web Services", IEEE Computer, vol. 47, pp. 30-36, 2014 [ DOI ]
2012
(1 publication)Conference Articles
2020
(3 publications)- Paulo Silva and Godinho, C. and Gonçalves, C. and Nuno Antunes and Marilia Curado , "Using Natural Language Processing to Detect Privacy Violations in Online Contracts", in The 35th ACM/SIGAPP Symposium on AppliedComputing (SAC ’20), 2020 [ DOI ]
- Casaleiro, R. and Paulo Silva and Simões, P. and Nuno Antunes and Marilia Curado and Edmundo Monteiro and Boavida, F. , "Gestão e Análise de Riscos na Plataforma de Proteção de Dados Pessoais Poseidon", in 9º Congresso Luso-Moçambicano de Engenharia, 2020
- Naghmeh Ivaki and Nuno Antunes , "SIDE: Security-aware Integrated Development Environment", in The 31st International Symposium on Software Reliability Engineering (ISSRE 2020), 2020
2019
(3 publications)- Cardoso, W. and Martins, E. and Laranjeiro, N. and Nuno Antunes , "Combining State and Interface -Based Robustness Testing for OpenStack Components", in 9th Latin-American Symposium on Dependable Computing (LADC 2019), 2019
- Valentim, I. and Lourenço, Nuno and Nuno Antunes , "The Impact of Data Preparation on the Fairness of Software Systems", in International Symposium on Software Reliability Engineering (ISSRE 2019), 2019
- José Flora and Nuno Antunes , "Studying the Applicability of Intrusion Detection to Multi-Tenant Container Environments", in 2019 15th European Dependable Computing Conference (EDCC), 2019 [ DOI ]
2018
(1 publication)2017
(2 publications)- Ivano Alessandro Elia and Nuno Antunes and Laranjeiro, N. and Marco Vieira , "An Analysis of OpenStack Vulnerabilities", in 13th European Dependable Computing Conference (EDCC), 2017 [ DOI ]
- Braga, A.M. and Dahab, R. and Nuno Antunes and Laranjeiro, N. and Marco Vieira , "Practical Evaluation of Static Code Analysis Tools for Cryptography: Benchmarking Method and Case Study", in The IEEE 28th International Symposium on Software Reliability Engineering (ISSRE 2017), 2017 [ DOI ]
2016
(4 publications)- Milenkoski, A. and Jayaram, K.R. and Nuno Antunes and Marco Vieira and Kounev, S. , "Quantifying the Attack Detection Accuracy of Intrusion Detection Systems in Virtualized Environments", in International Symposium on Software Reliability Engineering (ISSRE) , 2016 [ DOI ]
- Luís Ventura and Nuno Antunes , "Experimental Assessment of NoSQL Databases Dependability", in European Dependable Computing Conference (EDCC2016), 2016 [ DOI ]
- Alves, H. and Fonseca, B. and Nuno Antunes , "Software Metrics and Security Vulnerabilities: Dataset and Exploratory Study", in 12th European Dependable Computing Conference (EDCC), 2016, 2016 [ DOI ]
- Matsunaga, A.P.S. and Nuno Antunes and Moraes, R. , "Coverage Metrics and Detection of Injection Vulnerabilities: An Experimental Study", in 12th European Dependable Computing Conference (EDCC), 2016, 2016 [ DOI ]
2015
(3 publications)- Milenkoski, A. and Payne, B.D. and Nuno Antunes and Marco Vieira and Kounev, S. and Avritzer, A. and Luft, M. , "Evaluation of Intrusion Detection Systems in Virtualized Environments Using Attack Injection", in 18th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2015, 2015
- Nuno Antunes and Marco Vieira , "On the Metrics for Benchmarking Vulnerability Detection Tools", in Dependable Systems and Networks (DSN), 2015 45th Annual IEEE/IFIP International Conference on, 2015 [ DOI ]
- Carvalho, D. and Nuno Antunes and Milenkoski, A. and Kounev, S. , "Challenges of Assessing the Hypercall Interface Robustness (fast abstract)", in 45th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2015, 2015
2014
(4 publications)- Areias, C. and Nuno Antunes and Cunha, J.C. , "On Applying FMEA to SOAs: A Proposal and Open Challenges", in 6th International Workshop on Software Engineering for Resilient Systems (SERENE'14), 2014 [ DOI ]
- Milenkoski, A. and Payne, B.D. and Nuno Antunes and Marco Vieira and Kounev, S. , "An Analysis of Hypercall Handler Vulnerabilities ", in 2014 IEEE 25th International Symposium on Software Reliability Engineering (ISSRE), 2014 [ DOI ]
- Duchi, F. and Nuno Antunes and Ceccarelli, A. and Vella, G. and Rossi, F. and Bondavalli, A. , "Cost-Effective Testing for Critical Off-The-Shelf Services", in Workshop Paper, 1st International Workshop on DEvelopment, Verification and VAlidation of cRiTical Systems (DEVVARTS2014), 2014 [ DOI ]
- Basso, T. and Piardi, L. and Moraes, R. and Jino, M. and Nuno Antunes and Marco Vieira , "A Framework for Expressing and Enforcing Purpose-Based Privacy Policies", in XVI Workshop de Testes e Tolerância a Falhas, WTF 2015, 2014 [ DOI ]
2013
(5 publications)- Nuno Antunes and Marco Vieira , "SOA-Scanner: An Integrated Tool to Detect Vulnerabilities in Service-Based Infrastructures", in 10th IEEE International Conference on Services Computing (SCC 2013), 2013
- Areias, C. and Nuno Antunes and Cunha, J.C. and Marco Vieira , "Towards Runtime V&V for Service Oriented Architectures", in Sixth Latin-American Symposium on Dependable Computing, 2013
- Basso, T. and Nuno Antunes and Moraes, R. and Marco Vieira , "An XML-based Policy Model for Access Control in Web Applications", in 24th International Conference on Database and Expert Systems Applications (DEXA '13), 2013 [ DOI ]
- Nuno Antunes and Brancati, F. and Ceccarelli, A. and Bondavalli, A. and Marco Vieira , "A Monitoring and Testing Framework for Critical Off-The-Shelf Applications and Services", in 3rd IEEE International Workshop on Software Certification (WoSoCer2013) co-located with the 24rd IEEE International Symposium on Software Reliability Engineering (ISSRE 2013), 2013
- Milenkoski, A. and Payne, B.D. and Nuno Antunes and Marco Vieira and Kounev, S. , "HInjector: Injecting Hypercall Attacks for Evaluating VMI-based Intrusion Detection Systems", in Poster Paper, The 2013 Annual Computer Security Applications Conference (ACSAC 2013), 2013
2012
(2 publications)- Nuno Antunes and Marco Vieira , "Evaluating and Improving Penetration Testing in WebServices", in 23rd IEEE International Symposium on Software Reliability Engineering (ISSRE 2012), 2012
- Nuno Antunes and Marco Vieira , "Detecting Vulnerabilities in Service Oriented Architectures", in IEEE 23rd International Symposium on Software Reliability Engineering – Student Forum (ISSRE 2012), 2012
2011
(1 publication)2010
(1 publication)2009
(4 publications)- Nuno Antunes and Laranjeiro, N. and Marco Vieira and Madeira, H. , "Effective Detection of SQL/XPath Injection Vulnerabilities in Web Services", in IEEE International Conference on Services Computing (SCC 2009), 2009
- Marco Vieira and Nuno Antunes and Madeira, H. , "Using Web Security Scanners to Detect Vulnerabilities in Web Services", in 39th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN 2009), 2009
- Nuno Antunes and Marco Vieira , "Detecting SQL Injection Vulnerabilities in Web Services", in Fourth Latin-American Symposium on Dependable Computing (LADC 2009), 2009
- Nuno Antunes and Marco Vieira , "Comparing the Effectiveness of Penetration Testing and Static Code Analysis on the Detection of SQL Injection Vulnerabilities in Web Services", in IEEE 15th Pacific Rim International Symposium on Dependable Computing (PRDC'09), 2009
Book Chapters
2017
(1 publication)2013
(3 publications)- Nuno Antunes and Marco Vieira , "Security Testing in SOAs: Techniques and Tools", in Innovative technologies for dependable OTS-based critical systems, vol. 1, pp. 159-174, 2013 [ DOI ]
- Marco Vieira and Nuno Antunes , "Introduction to Software Security Concepts", in Innovative technologies for dependable OTS-based critical systems, vol. 1, pp. 29-38, 2013 [ DOI ]
- Napolitano, A. and Carrozza, G. and Nuno Antunes and Joao Duraes , "Survey on Software Faults Injection in Java Applications", in Innovative technologies for dependable OTS-based critical systems, vol. 1, pp. 101-114, 2013 [ DOI ]
2012
(1 publication)2011
(2 publications)- Rodrigues, D. and Estrella, J. and Nuno Antunes and Mónaco, F. and Branco, K. and Marco Vieira , "Engineering Secure Web Services", in Performance and Dependability in Service Computing: Concepts, Techniques and Research Directions, 2011
- Nuno Antunes and Marco Vieira , "Detecting Vulnerabilities in Web Services: Can Developers Rely on Existing Tools?", in Performance and Dependability in Service Computing: Concepts, Techniques and Research Directions, 2011