Antonio Santos-Olmo

dblp:15/7850 · DBLP profile ↗
← Back
10ranked-venue papers
1as first author
9since 2021 · last 2025
0000-0002-2349-3894ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Towards a Framework for Personal and Domestic Cybersecurity
abstract
The expansion of the digital world increasingly surrounds us, making our lives easier and more connected. However, it also brings a range of risks and threats that we accept—sometimes consciously, sometimes unconsciously—for the sake of productivity or convenience. These cybersecurity risks affect almost every sector of society and have been mainly analyzed within government and corporate contexts. Despite this, comprehensive studies are still lacking for the personal and domestic sphere. In this domain, cybersecurity risks have a wide scope: they can affect the physical safety of individuals, lead to privacy breaches, or expose personal data for criminal use. Many other situations may also arise, severely impacting people in their everyday digital environment. This article analyzes previous work related to the lack of cybersecurity solutions for individuals in the personal domain. In addition, and given the absence of comprehensive approaches, it presents an initial version of a personal cybersecurity framework and a conceptual application model.
Ángel Suarez-Bárcena, Antonio Santos-Olmo, Eduardo Fernández-Medina
BDCAT2
2025 Towards a sustainable cybersecurity framework for Agriculture 4.0 based on a systematic analysis of proposals
abstract
The world is currently experiencing a profound transformation driven by the convergence of disruptive technologies under the concept of Industry 4.0. These technologies have driven sectors such as agriculture to modernize and automate for greater sustainability, leading to what is now referred to as Agriculture 4.0 However, this transformation entails risks and requires new frameworks that address cybersecurity, sustainability, and knowledge reuse. In this paper, we conduct a systematic review of these new systems with the aim of identifying their main shortcomings and proposing a new framework. The review revealed a significant gap in comprehensively addressing cybersecurity, AI, and sustainability. This highlights the need for deeper exploration of how these elements interact to benefit the agricultural sector. To this end, we propose the development of the QUILLAQUA framework, oriented towards secure, intelligent, and sustainable agriculture, with a focus on fostering effective synergies among these crucial components. This framework integrates advanced technologies in cybersecurity, IoT, and AI to optimise the management of water and nutritional resources in hydroponic systems, ensuring sustainability and data security. This approach aims to enhance technological efficiency in agriculture. It also aims to foster greater awareness to tackle present and future challenges in sustainable agriculture. By doing so, it ensures a successful transition toward more digitized and secure agricultural practices.
Diegof Bustamantev, Luis Enrique Sánchez Crespo, David Garcia Rosado, Antonio Santos-Olmo, Eduardo Fernández-Medina
Comput. Secur.4
2025 Integrated maritime protection: Innovation for the safeguarding of maritime systems based on MARISMA
abstract
The maritime sector is becoming increasingly susceptible to sophisticated cyber-attacks, underscoring the pressing necessity for advanced research and development to establish robust safeguards for maritime assets. Although risk assessment methods for traditional IT systems are now highly developed, they are not directly applicable to risk assessment in maritime environments due to the specific characteristics and particularities of the latter. Therefore, there is an urgent need to define approaches that adequately support risk assessment in maritime environments. To contribute to this important challenge, we propose a novel risk analysis technique, specifically tailored for the maritime sector, based on MARISMA, a security management methodology, and eMARISMA, its cloud-based technological support tool. Our work contributes to the state of the art by defining the MARISMA-SHIPS maritime cybersecurity pattern, which includes a set of reusable and adaptable elements that enable risk management and control in a maritime environment, and is aligned with major international standards such as ENISA and NIST, as well as existing maritime regulations, becoming a key part of our ongoing POSEIDON maritime cybersecurity framework. A case study is presented for a ship developed in the main shipyard in Colombia, which shows how the reusability and adaptability of the proposal allows the proposed MARISMA-SHIPS pattern to be easily adapted to any maritime environment, and which allowed the identification of critical areas of cybersecurity that could be improved. The application of the process in the maritime domain has proven its value in improving the efficiency and security management of maritime assets.
Ferney Martínez 0001, Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, David Garcia Rosado, Eduardo Fernández-Medina
Comput. Secur.3
2024 Towards an integrated risk analysis security framework according to a systematic analysis of existing proposals
abstract
Abstract The information society depends increasingly on risk assessment and management systems as means to adequately protect its key information assets. The availability of these systems is now vital for the protection and evolution of companies. However, several factors have led to an increasing need for more accurate risk analysis approaches. These are: the speed at which technologies evolve, their global impact and the growing requirement for companies to collaborate. Risk analysis processes must consequently adapt to these new circumstances and new technological paradigms. The objective of this paper is, therefore, to present the results of an exhaustive analysis of the techniques and methods offered by the scientific community with the aim of identifying their main weaknesses and providing a new risk assessment and management process. This analysis was carried out using the systematic review protocol and found that these proposals do not fully meet these new needs. The paper also presents a summary of MARISMA, the risk analysis and management framework designed by our research group. The basis of our framework is the main existing risk standards and proposals, and it seeks to address the weaknesses found in these proposals. MARISMA is in a process of continuous improvement, as is being applied by customers in several European and American countries. It consists of a risk data management module, a methodology for its systematic application and a tool that automates the process.
Antonio Santos-Olmo, Luis Enrique Sánchez Crespo, David Garcia Rosado, Manuel A. Serrano, Carlos Blanco 0001, Haralambos Mouratidis, Eduardo Fernández-Medina
Frontiers Comput. Sci.1
2024 Enabling security risk assessment and management for business process models
abstract
Business processes (BP) are considered the enterprise’s cornerstone but are increasingly in the spotlight of attacks. Therefore, the design of business processes must consider the security risks and be adequately integrated into the information and operational systems. However, security risk assessment and management are rarely considered at the level of business processes during design time, let alone considering a risk architecture that takes into account the connection and dependencies of risks at these levels of the organisation, business processes, and information systems. In general, most approaches deal with integrating new artefacts for business process models to support risk analysis, but sometimes, the notation can increase complexity, making it difficult to have a risk management tool to support the analysis. After analysing the current risk processes and frameworks, we have realised that they are often neglected when considering organisational and business process levels. In this paper, MARISMA-BP (MARISMA for Business Process) pattern is proposed, a security risk pattern to enable the assessment and management of risks for business process models. This approach is an artefact that has been validated in a real scenario following the design science methodology. Further, MARISMA-BP pattern is supported by eMARISMA, an automated infrastructure that allows the definition and reuse of each risk component, helping us to carry out the risk assessment and management process in an efficient and dynamic way. To demonstrate the applicability of the proposal, MARISMA-BP pattern is applied to a real health-based business process scenario. The findings illustrate the efficacy of MARISMA-BP within eMARISMA for comprehensive risk assessment and management, underscoring its versatility and practical relevance in any business process environment.
David Garcia Rosado, Luis Enrique Sánchez Crespo, Angel Jesus Varela-Vaca, Antonio Santos-Olmo, María Teresa Gómez-López, Rafael M. Gasca, Eduardo Fernández-Medina
J. Inf. Secur. Appl.4
2024 Minimizing incident response time in real-world scenarios using quantum computing
abstract
Abstract The Information Security Management Systems (ISMS) are global and risk-driven processes that allow companies to develop their cybersecurity strategy by defining security policies, valuable assets, controls, and technologies for protecting their systems and information from threats and vulnerabilities. Despite the implementation of such management infrastructures, incidents or security breaches happen. Each incident has associated a level of severity and a set of mitigation controls, so in order to restore the ISMS, the appropriate set of controls to mitigate their damage must be selected. The time in which the ISMS is restored is a critical aspect. In this sense, classic solutions are efficient in resolving scenarios with a moderate number of incidents in a reasonable time, but the response time increases exponentially as the number of incidents increases. This makes classical solutions unsuitable for real scenarios in which a large number of incidents are handled and even less appropriate for scenarios in which security management is offered as a service to several companies. This paper proposes a solution to the incident response problem that acts in a minimal amount of time for real scenarios in which a large number of incidents are handled. It applies quantum computing, as a novel approach that is being successfully applied to real problems, which allows us to obtain solutions in a constant time regardless of the number of incidents handled. To validate the applicability and efficiency of our proposal, it has been applied to real cases using our framework (MARISMA).
Manuel A. Serrano, Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, David Garcia Rosado, Carlos Blanco 0001, Vita Santa Barletta, Danilo Caivano, Eduardo Fernández-Medina
Softw. Qual. J.3
2023 Modelling language for cyber security incident handling for critical infrastructures
abstract
Cyber security incident handling is a consistent methodology with which to ensure overall business continuity. However, specifically handling incidents for critical information infrastructures is challenging owing to the inherent complexity and evolving nature of the threat. Despite the number of contributions made to cyber incident handling, there is little evidence of literature that focuses on modelling activities that will enhance developers’ abilities to model incident handling processes and activities according to different views. Modelling languages of this nature should integrate essential concepts and a descriptive implementation process in order to enable developers to analyse, represent and reason about the crucial incident handling efforts required to support critical information infrastructures. The aim of this paper is, as part of the CyberSANE EU project, to develop a Cyber Incident Handling Modelling Language (CIHML) that focuses explicitly on modelling incident handling in the context of a critical information infrastructure. The work is innovative in its approach because it consolidates concepts from various domains such as security requirements, forensics, threat intelligence, critical infrastructures and cyber incident handling. The approach will allow the phases of the incident handling lifecycle to be modelled from three different views (critical information infrastructures, threat and risk analysis, and incident response). An implementation process is also proposed, which will serve as a comprehensive guide for developers in order to create these modelling views. Finally, CIHML is evaluated using a real-life scenario from the CyberSANE project to demonstrate its applicability. The incident observed had a severe impact on the overall business continuity of the context studied. The results obtained from the study show that CIHML can help critical information infrastructure operators to identify, evaluate, represent and model cyber incidents in critical information systems, in addition to providing the support required to determine the response strategies needed in order to mitigate these cyber-attacks.
Haralambos Mouratidis, Shareeful Islam, Antonio Santos-Olmo, Luis Enrique Sánchez Crespo, Umar Mukhtar Ismail
Comput. Secur.3
2022 Security policies by design in NoSQL document databases
abstract
The importance of data security is currently increasing owing to the number of data transactions that are continuously taking place. Large amounts of data are generated, stored, modified and transferred every second, signifying that databases require an appropriate capacity, control and protection that will enable them to maintain a secure environment for so much data. Big Data is becoming a prominent trend in our society, and increasing amounts of data, including sensitive and personal information, are being loaded into NoSQL and other Big Data technologies for analysis and processing. However, current security approaches do not take into account the special characteristics of these technologies, leaving sensitive and personal data unprotected and consequently risking considerable financial losses and brand damage. In this paper, we focus on NoSQL document databases and present a proposal for the design and implementation of security policies in this type of databases. We first follow the concept of security by design in order to propose a metamodel that allows the specification of both the structure and the security policies required for document databases. We also define an implementation model by analysing the implementation features provided by a specific NoSQL document database management system (MongoDB). Having obtained the design and implementation models, we follow the model-driven development philosophy and propose a set of transformation rules that allow the automatic generation of the final implementation of security policies. We additionally provide a technological solution in which the Eclipse Modelling Framework environment is employed in order to implement both the design metamodel (Emfatic) and the transformations (Epsilon, EGL). Finally, we apply the proposed framework to a case study carried out in the airport domain. This proposal, in addition to saving development time and costs, generates more robust solutions by considering security by design. This, therefore, abstracting the designer from both specific aspects of the target tool and having to choose the best strategies for the implementation of security policies.
Carlos Blanco 0001, Diego García-Saiz, David Garcia Rosado, Antonio Santos-Olmo, Jesús Peral Cortés, Alejandro Maté, Juan Trujillo 0001, Eduardo Fernández-Medina
J. Inf. Secur. Appl.4
2021 MARISMA-BiDa pattern: Integrated risk analysis for big data
David Garcia Rosado, Julio Moreno, Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, Manuel A. Serrano, Eduardo Fernández-Medina
Comput. Secur.4
2010 Building ISMS through the Reuse of Knowledge
Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, Eduardo Fernández-Medina, Mario Piattini
TrustBus2