Jose Antonio Onieva

dblp:22/4296 · DBLP profile ↗
← Back
14ranked-venue papers
5as first author
2since 2021 · last 2026
0000-0002-7280-090XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 3 first-author · 2 since 2021Computer networks · 3 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 2
YearPublicationVenuePosition
2026 Adversarial red teaming and imbalance correction in heterogeneous NIDS: A class-specific adaptive GAN framework
abstract
Modern network infrastructures face a structural long-tail imbalance where malicious events are statistically negligible against benign traffic. This bias causes Machine Learning-based Network Intrusion Detection Systems (NIDS) to systematically overlook rare, high-severity intrusions. While Generative Adversarial Networks (GANs) offer a solution for minority class synthesis, standard monolithic architectures suffer from majority-class gradient dominance, inevitably leading to conditional mode collapse. To address this, we propose the Adaptive Manifold-Decoupled GAN (AMD-GAN), a novel framework that applies class-wise architectural decoupling to feature manifolds and dynamically adapts its optimization regime to each category’s cardinality. This decoupled design mitigates inter-class interference and empirically reduces critic memorization. Evaluated across three heterogeneous NIDS benchmarks (CIC-IDS2017, UNSW-NB15, Edge-IIoTset 2022), AMD-GAN achieves a mean global empirical Wasserstein distance of (across five independent seeds), confirming robust distributional fidelity. Under a Train-Synthetic-Test-Real (TSTR) protocol, balanced synthetic augmentation consistently improves Multiclass Macro F1-Scores. Specifically, in CIC-IDS2017, it yields a 10.1 pp absolute improvement (+45.2% Botnet, +22.9% Web Attack), demonstrating statistically significant superiority over interpolation methods like ADASYN and Borderline-SMOTE. An extensive ablation study isolates the adaptive engine as the causal driver of manifold recovery, while Distance to Closest Record (DCR) analysis confirms the absence of exact-match memorization. Furthermore, interpretability techniques (SHAP and LIME) validate that the generated flows preserve authentic protocol semantics, enabling unambiguous attribution for Security Operations Centers (SOC). Deployed offensively as an automated Red Teaming engine, AMD-GAN exposes structural fragility in operational tree ensembles, inducing up to 0.909 Macro F1-Score degradation under volumetric stress scenarios. Finally, the decoupled sequential training architecture restricts peak GPU VRAM to 1,575 MB while generating 90,000 synthetic flows in 15.7 s, establishing AMD-GAN as a computationally efficient, low-VRAM solution potentially suitable for resource-constrained deployments for robust data augmentation and adversarial NIDS auditing.
Antonio Lara-Gutierrez, Carmen Fernández Gago, Jose Antonio Onieva
J. Inf. Secur. Appl.3
2024 Malware similarity and a new fuzzy hash: Compound Code Block Hash (CCBHash)
abstract
In the last few years, malware analysis has become increasingly important due to the rise of sophisticated cyberattacks. One of the objectives of this cybersecurity branch is to find similarities between different files or functions used by malware programmers, thus allowing malware detection, classification and even attribution in a timely manner. In this article we survey the state of the art in this area, reviewing the different techniques that can be applied to the field, with the objective of studying similarity, and therefore detecting, classifying and attributing malware samples. We have developed a fuzzy hash capable of characterizing malware by generating an easily comparable and storable signature of its functions. Since our goal is to detect these similarities in huge amounts of data within a reasonable time-frame, the size of the hash must be limited while retaining as much information as possible.
Jose Antonio Onieva, Pablo Pérez Jiménez, Javier López 0001
Comput. Secur.1
2019 Edge-Assisted Vehicular Networks Security
abstract
Edge computing paradigms are expected to solve some major problems affecting current application scenarios that rely on cloud computing resources to operate. These novel paradigms will bring computational resources closer to the users and by doing so they will not only reduce network latency and bandwidth utilization but will also introduce some attractive context-awareness features to these systems. In this paper we show how the enticing features introduced by edge computing paradigms can be exploited to improve security and privacy in the critical scenario of vehicular networks (VNs), especially existing authentication and revocation issues. In particular, we analyze the security challenges in VN and describe three deployment models for vehicular edge computing, which refrain from using vehicular-to-vehicular communications. The result is that the burden imposed to vehicles is considerably reduced without sacrificing the security or functional features expected in vehicular scenarios.
Jose Antonio Onieva, Ruben Rios, Rodrigo Roman, Javier López 0001
IEEE Internet Things J.1
2019 Immune System for the Internet of Things Using Edge Technologies
abstract
The Internet of Things (IoT) and edge computing are starting to go hand in hand. By providing cloud services close to end-users, edge paradigms enhance the functionality of IoT deployments, and facilitate the creation of novel services such as augmented systems. Furthermore, the very nature of these paradigms also enables the creation of a proactive defense architecture, an immune system, which allows authorized immune cells (e.g., virtual machines) to traverse edge nodes and analyze the security and consistency of the underlying IoT infrastructure. In this paper, we analyze the requirements for the development of an immune system for the IoT, and propose a security architecture that satisfies these requirements. We also describe how such a system can be instantiated in edge computing infrastructures using existing technologies. Finally, we explore the potential application of immune systems to other scenarios and purposes.
Rodrigo Roman, Ruben Rios, Jose Antonio Onieva, Javier López 0001
IEEE Internet Things J.3
2013 Covert communications through network configuration messages
Ruben Rios, Jose Antonio Onieva, Javier López 0001
Comput. Secur.2
2012 HIDE_DHCP: Covert Communications through Network Configuration Messages
Ruben Rios, Jose Antonio Onieva, Javier López 0001
SEC2
2010 Certified electronic mail: Properties revisited
Josep-Lluís Ferrer-Gomila, Jose Antonio Onieva, Magdalena Payeras-Capellà, Javier López 0001
Comput. Secur.2
2007 Estimation of TTP Features in Non-repudiation Service
Mildrey Carbonell Castro, José María Sierra, Jose Antonio Onieva, Javier López 0001, Jianying Zhou 0001
ICCSA (2)3
2006 A Synchronous Multi-Party Contract Signing Protocol Improving Lower Bound of Steps
abstract
Contract signing is a fundamental service in doing business. The Internet has facilitated the electronic commerce, and it is necessary to find appropriate mechanisms for contract signing in the digital world. A number of two-party contract signing protocols have been proposed with various features. Nevertheless, in some applications, a contract may need to be signed by multiple parties. Less research has been done on multi-party contract signing. In this paper, we propose a new synchronous multi-party contract signing protocol that, with n parties, it reaches a lower bound of 3( n − 1) steps in the all-honest case and 4 n − 2 steps in the worst case (i.e., all parties contact the trusted third party). This is so far the most efficient synchronous multi-party contract signing protocol in terms of the number of messages required. We further consider the additional features like timeliness and abuse-freeness in the improved version. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.
Jianying Zhou 0001, Jose Antonio Onieva, Javier López 0001
SEC2
2005 Optimized multi-party certified email protocols
abstract
Purpose As a value‐added service to deliver important data over the internet with guaranteed receipt for each successful delivery, certified email has been discussed for years and a number of research papers appeared in the literature. This paper aims to present two optimized multi‐party certified email protocols. Design/methodology/approach Reviews two existing email protocols and provides a modified version to overcome their security flaws and weaknesses. Extends the two‐party protocol to a multi‐party scenario. Findings Both of the protocols have three major features. A sender could notify multiple recipients of the same information while only those recipients who acknowledged are able to get the information. Both the sender and the recipients can end a protocol run at any time without breach of fairness. The exchange protocols are optimized, each of which has only three steps, and the trusted third party will not be involved unless an exception (e.g. a network failure or a party's misbehavior) occurs. Originality/value Provides a focus on a value‐added service – certified email.
Jianying Zhou 0001, Jose Antonio Onieva, Javier López 0001
Inf. Manag. Comput. Security2
2004 Timeout Estimation Using a Simulation Model for Non-repudiation Protocols
Mildrey Carbonell Castro, Jose Antonio Onieva, Javier López 0001, Deborah Galpert, Jianying Zhou 0001
ICCSA (1)2
2004 Non-repudiation protocols for multiple entities
Jose Antonio Onieva, Jianying Zhou 0001, Javier López 0001
Comput. Commun.1
2003 Practical Service Charge for P2P Content Distribution
Jose Antonio Onieva, Jianying Zhou 0001, Javier López 0001
ICICS1
2003 A Multi-Party Non-Repudiation Protocol for Exchange of Different Messages
Jose Antonio Onieva, Jianying Zhou 0001, Mildrey Carbonell Castro, Javier López 0001
SEC1