Serverless security · Cloud-native systems

PedroEscaleira

I design transparent runtime defences for serverless applications, from control-flow enforcement to system-call anomaly detection.

Portrait of Pedro Escaleira
PhD student · University of Aveiro
10+Publications and accepted papers
3Master thesis awards (2023)
TSCETSI Open Source MANO member
01

Research

Selected research

My work explores how serverless applications can be protected transparently across workflows, functions, and orchestration layers—while leaving the tenant's application code unchanged.

01Control-flow integrity

PoliFlow

Infers control-flow policies from serverless workflows and enforces them transparently at runtime, protecting the intended execution structure without modifying function code.

02Moving target defence

MoFaaS

Uses moving target defence and n-version programming to improve the resilience of vulnerable serverless functions while preserving the availability expected from cloud-native applications.

03Runtime anomaly detection

FADO

Detects anomalous serverless function behaviour from eBPF system-call traces, extending protection from workflow structure into the function runtime.

02

Current focus

Dynamic Protection of Serverless Applications

My PhD investigates adaptive, transparent mechanisms that can detect and mitigate threats at runtime while preserving cloud-native scalability and performance.

Workflow integrityRuntime detectionAdaptive mitigation
03

Background

About me

I am a PhD student and researcher at the University of Aveiro and Instituto de Telecomunicações. My current work focuses on dynamic protection for serverless applications, building on a background in cybersecurity, 5G, NFV, and edge computing.

Before beginning my PhD, I worked on standards-aligned MEC architectures and moving-target defence. Since 2024, I have served on the Technical Steering Committee of ETSI Open Source MANO.

Serverless ComputingCloud SecurityCybersecurityEdge ComputingNetwork Functions Virtualization
04

Highlights

Selected achievements

Open the complete CV
2024—26

ETSI OSM Technical Steering Committee

Contributing to the technical direction of a standards-aligned open-source network orchestration project.

2023

Three national thesis awards

Recognition from IEEE Portugal, AP2SI, and APDC for the Master's thesis on securing real-world 5G MEC deployments.

2022

CVE-2022-35503

Critical vulnerability disclosed in ETSI OSM and later used as a practical security challenge at an OSM Hackfest.

Selected publications
2026

Enhancing Serverless Function Resilience Against Vulnerabilities with MoFaaS

Journal of Network and Systems Management, Vol. 34, No. 3

2026

PoliFlow: Inferring Control-Flow Policies from Serverless Workflows

IEEE International Symposium on Cluster, Cloud and Internet Computing (IEEE CCGrid)

2025

A systematic review on security mechanisms for serverless computing

Cluster Computing, Vol. 28, No. 7, p. 465