VLDB 2026 Research / reviewers in the wild / expert
Iñaki Garitano
dblp:12/10094
· DBLP profile ↗
10ranked-venue papers
1as first author
4since 2021 · last 2026
0000-0002-0387-9167ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 3 · 1 first-authorSecurity and privacy · 3 · 2 since 2021Computer networks · 2 · 2 since 2021Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Replica-Based Moving Target Defense Against Injection Attacks in Software-Defined Industrial Control SystemsabstractRecent incidents have demonstrated the increasing vulnerability of Industrial Control Systems (ICSs) to sophisticated and targeted attacks orchestrated by adversaries with high motivation, resources, and domain knowledge. Among these threats, False Data Injection (FDI) attacks have emerged as one of the main security threats to ICSs, involving the deliberate manipulation or injection of false data into the control system to deceive or disrupt operations. FDI attacks pose a significant risk due to their high capacity of concealment and ability to evade intrusion detection systems that rely on accurate ICS models. In this paper, we presentdefclon, a novel Software-Defined Networking (SDN)-based Moving Target Defense (MTD) approach against FDI attacks.Defclonproactively replicates network packets across multiple network paths and adaptively selects a single path using a signaling game model to reach the destination end-device. We demonstrate the effectiveness of our approach through simulations, numerical analysis, and experiments on ICS network traffic and topologies. Experimental results show thatdefclonis able to not only mitigate the effects of FDI attacks, but also to introduce different levels of uncertainty without degrading network performance, significantly increasing the difficulty for adversaries to gather information and launch attacks. Xabier Etxezarreta, Federico Turrin, Iñaki Garitano, Mikel Iturbe, Urko Zurutuza, Mauro Conti |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Mitigation of PFCP Attacks in 5G Networks: Dynamic Defense Through Moving Target Defense and Honeynets
Aitor Landa-Arrue, Jasone Astorga, Iñaki Garitano, Aitor Urbieta |
ARES (1) | 3 |
| 2024 | Low delay network attributes randomization to proactively mitigate reconnaissance attacks in industrial control systemsabstractAbstract Industrial Control Systems are used in a wide variety of industrial facilities, including critical infrastructures, becoming the main target of multiple security attacks. A malicious and successful attack against these infrastructures could cause serious economic and environmental consequences, including the loss of human lives. Static networks configurations and topologies, which characterize Industrial Control Systems, represent an advantage for attackers, allowing them to scan for vulnerable devices or services before carrying out the attack. Identifying active devices and services is often the first step for many attacks. This paper presents a proactive network reconnaissance defense mechanism based on the temporal randomization of network IP addresses, MAC addresses and port numbers. The obtained information distortion minimizes the knowledge acquired by the attackers, hindering any attack that relies on network addressing. The temporal randomization of network attributes is performed in an adaptive way, minimizing the overhead introduced in the network and avoiding any error and latency in communications. The implementation as well as the tests have been carried out in a laboratory with real industrial equipment, demonstrating the effectiveness of the presented solution. Xabier Etxezarreta, Iñaki Garitano, Mikel Iturbe, Urko Zurutuza |
Wirel. Networks | 2 |
| 2024 | On the use of MiniCPS for conducting rigorous security experiments in Software-Defined Industrial Control SystemsabstractAbstract Software-Defined Networking (SDN) offers a global view over the network and the ability of centrally and dynamically managing network flows, making them ideal for creating security threat detection and mitigation solutions. Industrial networks possess specific characteristics that make them well-suited for such solutions, leading to extensive research efforts in this area. However, due to the high economic cost and potential risks associated with real equipment interaction, most studies rely on testbeds for demonstration purposes. Therefore, it becomes crucial to understand the limitations and safe operating ranges of testbed environments to ensure the development of scientifically rigorous experiments and accurate result measurements. This study focuses on analyzing MiniCPS-based testbeds in terms of network performance, experiment replicability, and the effects of different attacker implementation modes. The findings demonstrate that utilizing MiniCPS on actual hardware enables the development of highly replicable and high-performance testbeds, as long as they operate within the predefined safe operating ranges. Additionally, this work provides an in-depth analysis of various attacker implementation techniques and their impact on the network. Xabier Etxezarreta, Iñaki Garitano, Mikel Iturbe, Urko Zurutuza |
Wirel. Networks | 2 |
| 2020 | Data-Driven Industrial Human-Machine Interface Temporal Adaptation for Process OptimizationabstractThe application of Artificial Intelligence (AI) into Industrial Human-Machine Interfaces (HMIs) moved old systems with physical buttons and analogue actuators into adaptive interaction models and context-based self adjusted interfaces. To date, little attention has been paid to industrial Human-Machine Interfaces (HMI) which play a vital role in the communication between operator and complex productive systems. Current industrial HMIs do not take into account operator behaviour, but rather focus on the production process. To enhance User Experience (UX) and improve performance it is necessary to adapt the interface to the needs of the operator. This paper proposes a Machine Learning (ML) based operator interaction Data-Driven methodology to extract a set of interface adaptation rules. The methodology optimizes the interaction by reducing the number of actions and hence the amount of time and possible errors in repetitive monitoring and control tasks. An experiment with real operators was conducted to validate the proposed approach. The system was able to extract their interaction patterns and propose temporal interface adaptations, leading to a personalized, adaptive and more effective interaction. Daniel Reguera-Bakhache, Iñaki Garitano, Roberto Uribeetxeberria, Carlos Cernuda, Urko Zurutuza |
ETFA | 2 |
| 2020 | How to Quantify the Security Level of Embedded Systems? A Taxonomy of Security MetricsabstractEmbedded Systems (ES) development has been historically focused on functionality rather than security, and today it still applies in many sectors and applications. However, there is an increasing number of security threats over ES, and a successful attack could have economical, physical or even human consequences, since many of them are used to control critical applications. A standardized and general accepted security testing framework is needed to provide guidance, common reporting forms and the possibility to compare the results along the time. This can be achieved by introducing security metrics into the evaluation or assessment process. If carefully designed and chosen, metrics could provide a quantitative, repeatable and reproducible value that would reflect the level of security protection of the ES. This paper analyzes the features that a good security metric should exhibit, introduces a taxonomy for classifying them, and finally, it carries out a literature survey on security metrics for the security evaluation of ES. In this review, more than 500 metrics were collected and analyzed. Then, they were reduced to 169 metrics that have the potential to be applied to ES security evaluation. As expected, the 77.5% of them is related exclusively to software, and only the 0.6% of them addresses exclusively hardware security. This work aims to lay the foundations for constructing a security evaluation methodology that uses metrics so as to quantify the security level of an ES. Ángel Longueira-Romero, Rosa Iglesias, Iñaki Garitano |
INDIN | 4 |
| 2018 | Implementation of a Reference Architecture for Cyber Physical Systems to support Condition Based MaintenanceabstractThis paper presents the implementation of a reference architecture for Cyber Physical Systems (CPS) to support Condition Based Maintenance (CBM) of industrial assets. The article focuses on describing how the MANTIS Reference Architecture is implemented to support predictive maintenance of clutch-brake assets fleet, and includes the data analysis techniques and algorithms implemented at platform level to facilitate predictive maintenance activities. These technologies are (1) Root Cause Analysis powered by Attribute Oriented Induction Clustering and (2) Remaining Useful Life powered by Time Series Forecasting. The work has been conducted in a real use case within the EU project MANTIS. Felix Larrinaga, Javier Fernandez-Anakabe, Ekhi Zugasti, Iñaki Garitano, Urko Zurutuza, Mikel Anasagasti, Mikel Mondragon |
CoDIT | 4 |
| 2017 | Short Messages Spam Filtering Combining Personality Recognition and Sentiment AnalysisabstractCurrently, short communication channels are growing up due to the huge increase in the number of smartphones and online social networks users. This growth attracts malicious campaigns, such as spam campaigns, that are a direct threat to the security and privacy of the users. While most researches are focused on automatic text classification, in this work we demonstrate the possibility of improving current short messages spam detection systems using a novel method. We combine personality recognition and sentiment analysis techniques to analyze Short Message Services (SMS) texts. We enrich a publicly available dataset adding these features, first separately and after in combination, of each message to the dataset, creating new datasets. We apply several combinations of the best SMS spam classifiers and filters to each dataset in order to compare the results of each one. Taking into account the experimental results we analyze the real inuence of each feature and the combination of both. At the end, the best results are improved in terms of accuracy, reaching to a 99.01% and the number of false positive is reduced. Enaitz Ezpeleta, Iñaki Garitano, Urko Zurutuza, José María Gómez Hidalgo |
Int. J. Uncertain. Fuzziness Knowl. Based Syst. | 2 |
| 2017 | Towards Large-Scale, Heterogeneous Anomaly Detection Systems in Industrial Networks: A Survey of Current TrendsabstractIndustrial Networks (INs) are widespread environments where heterogeneous devices collaborate to control and monitor physical processes. Some of the controlled processes belong to Critical Infrastructures (CIs), and, as such, IN protection is an active research field. Among different types of security solutions, IN Anomaly Detection Systems (ADSs) have received wide attention from the scientific community. While INs have grown in size and in complexity, requiring the development of novel, Big Data solutions for data processing, IN ADSs have not evolved at the same pace. In parallel, the development of Big Data frameworks such as Hadoop or Spark has led the way for applying Big Data Analytics to the field of cyber-security, mainly focusing on the Information Technology (IT) domain. However, due to the particularities of INs, it is not feasible to directly apply IT security mechanisms in INs, as IN ADSs face unique characteristics. In this work we introduce three main contributions. First, we survey the area of Big Data ADSs that could be applicable to INs and compare the surveyed works. Second, we develop a novel taxonomy to classify existing IN-based ADSs. And, finally, we present a discussion of open problems in the field of Big Data ADSs for INs that can lead to further development. Mikel Iturbe, Iñaki Garitano, Urko Zurutuza, Roberto Uribeetxeberria |
Secur. Commun. Networks | 2 |
| 2012 | A method to construct network traffic models for process control systemsabstractNowadays, it is a well-known fact that modern Critical Infrastructures (CIs) depend on Information and Communication Technologies (ICT). Supervisory Control and Data Acquisition (SCADA) systems with off-the-shelf ICT hardware and software found their way in Process Control Systems (PCSs) due to their simplicity and cost-efficiency. However, recent incidents such as Stuxnet, Duqu or Night Dragon revealed new ICT vulnerabilities and attack scenarios in PCSs. Nevertheless, as shown by recent events, security studies on real SCADA systems are challenging due to the lack of proper experimentation environments. Through this work we develop a method to generate realistic network traffic in laboratory conditions without the need of a real PCS installation. This is indeed our main contribution as the basis of future anomaly detection systems. Such method could support experimentation through the recreation of realistic traffic in simulated environments. The accuracy and fidelity of the proposed approach was validated with several statistical methods that compare the predicted traffic with traffic taken from a real in stallation. Iñaki Garitano, Christos Siaterlis, Béla Genge, Roberto Uribeetxeberria, Urko Zurutuza |
ETFA | 1 |