VLDB 2026 Research / reviewers in the wild / expert
Carlos Gañán
dblp:22/7256 · also Carlos Hernandez Gañán
· DBLP profile ↗
60ranked-venue papers
10as first author
36since 2021 · last 2026
0000-0002-4699-3007ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 44 · 6 first-author · 31 since 2021Computer networks · 6 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The End of Anarchy? Understanding the Life of HTTP Exploits Used in IoT Malware Infections
Ryu Kuki, Takayuki Sasaki, Arwa Abdulkarim Al Alsadi, Carlos Gañán, Katsunari Yoshioka |
AsiaCCS | 4 |
| 2026 | Aliens Among Us: Observing Private or Reserved IPs on the Public Internet
Radu Anghel, Carlos Gañán, Qasim Lone, Matthew J. Luckie, Yury Zhauniarovich |
NDSS | 2 |
| 2025 | Bits and Pieces: Piecing Together Factors of IoT Vulnerability Exploitation
Arwa Abdulkarim Al Alsadi, Mathew Vermeer, Takayuki Sasaki, Katsunari Yoshioka, Michel van Eeten, Carlos Gañán |
AsiaCCS | 6 |
| 2025 | Can IOCs Impose Cost? The Effects of Publishing Threat Intelligence on Adversary BehaviorabstractExposing intrusion campaigns has become a geopolitical tool, with governments and commercial firms publishing threat intelligence reports about hacking attempts and modus operandi. U.S. government officials have explained this as not just a defensive practice but also as a way to 'impose cost' on attackers by forcing them to develop new infrastructure, tools, and techniques. We empirically examine this claim by analyzing attacker behavior before and after publication of indicators of compromise (IOCs). Using IOC feeds from two leading commercial providers, we matched IOCs against a large dataset of real-world network traffic metadata. This enabled us to generate sightings retroactively, capturing malicious activity up to 150 days before and after publication. Unlike prior work focused on post-publication malicious activity, our method provides a more complete view over time. Our results show that most IOCs point to resources that attackers had already abandoned by publication, limiting their utility for detecting ongoing attacks and undermining the idea of 'imposing costs'. Statistical modeling further reveals that publication status has low explanatory power for sightings, suggesting that confounding variables exist. We also observed a 30-day delay between the peak of threat actor activity and IOC publication for one provider. This study is the first empirical assessment linking threat intelligence publication to attacker behavior, bridging computer science and international relations. Xander Bouwman, Aksel Ethembabaoglu, Bart Hermans, Carlos Gañán, Michel van Eeten |
CCS | 4 |
| 2025 | Exposing the Roots of DNS Abuse: A Data-Driven Analysis of Key Factors Behind Phishing Domain RegistrationsabstractCybercriminals have long depended on domain names for phishing, spam, malware distribution, and botnet operation. To facilitate the malicious activities, they continually register new domain names for exploitation. Previous work revealed an abnormally high concentration of malicious registrations in a handful of registrars and TLDs. However, no existing study systematically analyzed the factors driving abuse, leaving a critical gap in understanding how different variables influence malicious registrations. In this paper, we carefully distill the inclinations and aversions of malicious actors during the registration of new phishing domain names. Having compiled a list of 14.5 k malicious and 15.4 k benign domains, we collect a comprehensive set of 73 features for all the domains encompassing three main latent factors: registration attributes, proactive verification, and reactive security practices. With a GLM regression analysis, we found that each dollar reduction in registration fees corresponds to a 49% increase in malicious domain registrations. The availability of free bundled services, such as web hosting, drives an 88% surge in phishing activities. Conversely, stringent registration restrictions cut down abuse by 63%, while registrars providing API access for domain registration or account creation experience a staggering 401% rise in malicious domains. The results enable intermediaries involved in domain registration to develop tailored anti-abuse practices, yet aligning them with their economic interests. Yevheniya Nosyk, Maciej Korczynski, Carlos Gañán, Sourena Maroofi, Jan Bayer, Zul Odgerel, Samaneh Tajalizadehkhoob, Andrzej Duda |
CCS | 3 |
| 2025 | "All Sorts of Other Reasons to Do It": Explaining the Persistence of Sub-optimal IoT Security Advice
Veerle van Harten, Carlos Gañán, Michel van Eeten, Simon Edward Parkin |
CHI | 2 |
| 2025 | Poster: Exploring the Zero-Shot Potential of Large Language Models for Detecting Algorithmically Generated Domains
Tomás Pelayo-Benedet, Ricardo J. Rodríguez, Carlos Gañán |
DIMVA (2) | 3 |
| 2025 | Patching Up: Stakeholder Experiences of Security Updates for Connected Medical Devices
Lorenz Kustosch, Carlos Gañán, Michel van Eeten, Simon Edward Parkin |
USENIX Security Symposium | 2 |
| 2025 | Regulating Smart Device Support Periods: User Expectations and the European Cyber Resilience Act
Lorenz Kustosch, Carlos Gañán, Mattis van 't Schip, Michel van Eeten, Simon Edward Parkin |
USENIX Security Symposium | 2 |
| 2025 | RAMPAGE: a software framework to ensure reproducibility in algorithmically generated domains detectionabstractAs part of its life cycle, malware can establish communication with its command and control server. To bypass static protection techniques, such as blocking certain IPs in firewalls or DNS server deny lists, malware can use algorithmically generated domains (AGD). Many different solutions based on deep learning have been proposed during the last years to detect this type of domains. However, there is a lack of ability to compare the proposed models because there is no common framework that allows experiments to be replicated under the same conditions. Each previous work shows its evaluation results, but under different experimentation conditions and even with different datasets. In this paper, we address this gap by proposing a software framework, dubbed rampage ( fRAMework to comPAre aGd dEtectors ), focused on training and comparing machine learning models for AGD detection. Furthermore, we propose a new model that uses logistic regression and, using rampage to obtain a fair comparison with different state-of-the-art models, achieves slightly better results than those obtained so far. In addition, the dataset built from real-world samples for evaluation, as well as the source code of rampage , are also publicly released to facilitate its use and promote experimental reproducibility in this research field. Tomás Pelayo-Benedet, Ricardo J. Rodríguez, Carlos Gañán |
Expert Syst. Appl. | 3 |
| 2025 | WFE-Tab: Overcoming limitations of TabPFN in IIoT-MEC environments with a weighted fusion ensemble-TabPFN model for improved IDS performanceabstractIn recent years we have seen the emergence of new industrial paradigms such as Industry 4.0/5.0 or the Industrial Internet of Things (IIoT). As the use of these new paradigms continues to grow, so do the number of threats and exploits that they face, which makes the IIoT a desirable target for cybercriminals . Furthermore, IIoT devices possess inherent limitations, primarily due to their limited resources. As a result, it is often impossible to detect attacks using solutions designed for other environments. Recently, Intrusion Detection Systems (IDS) based on Machine Learning (ML) have emerged as a solution that takes advantage of the large amount of data generated by IIoT devices to implement their functionality and achieve good performance , and the inclusion of the Multi-Access Edge Computing (MEC) paradigm in these environments provides the necessary computational resources to deploy IDS effectively. Furthermore, TabPFN has been considered as an attractive option for solving classification problems without the need to reprocess the data. However, TabPFN has certain drawbacks when it comes to the number of training samples and the maximum number of different classes that the model is capable of classifying. This makes TabPFN unsuitable for use when the dataset exceeds one of these limitations. In order to overcome such limitations, this paper presents a Weighted Fusion-Ensemble-based TabPFN (WFE-Tab) model to improve IDS performance in IIoT-MEC scenarios. The presented study employs a novel weighted fusion method to preprocess data into multiple subsets, generating different ensemble family TabPFN models. The resulting WFE-Tab model comprises four stages: data collection, data preprocessing , model training, and model evaluation. The performance of the WFE-Tab method is evaluated using key metrics such as Accuracy, Precision, Recall, and F1-Score, and validated using the Edge-IIoTset public dataset. The performance of the method is then compared with baseline and modern methods to evaluate its effectiveness, achieving an F1-Score performance of 99.81%. Sergio Ruiz-Villafranca, José Roldán Gómez, Javier Carrillo Mondéjar, José Luis Martínez 0001, Carlos Gañán |
Future Gener. Comput. Syst. | 5 |
| 2025 | The machines are watching: Exploring the potential of Large Language Models for detecting Algorithmically Generated DomainsabstractAlgorithmically Generated Domains (AGDs) are integral to many modern malware campaigns, allowing adversaries to establish resilient command and control channels. While machine learning techniques are increasingly employed to detect AGDs, the potential of Large Language Models (LLMs) in this domain remains largely underexplored. In this paper, we examine the ability of nine commercial LLMs to identify malicious AGDs, without parameter tuning or domain-specific training. We evaluate zero-shot approaches and few-shot learning approaches, using minimal labeled examples and diverse datasets with multiple prompt strategies. Our results show that certain LLMs can achieve detection accuracy between 77.3% and 89.3%. In a 10-shot classification setting, the largest models excel at distinguishing between malware families, particularly those employing hash-based generation schemes, underscoring the promise of LLMs for advanced threat detection. However, significant limitations arise when these models encounter real-world DNS traffic. Performance degradation on benign but structurally suspect domains highlights the risk of false positives in operational environments. This shortcoming has real-world consequences for security practitioners, given the need to avoid erroneous domain blocking that disrupt legitimate services. Our findings underscore the practicality of LLM-driven AGD detection, while emphasizing key areas where future research is needed (such as more robust warning design and model refinement) to ensure reliability in production environments. • LLMs can detect AGDs with an accuracy of up to 89.3%, facilitating AI-based malware defense. • Creating effective detection is crucial; false positives remain a significant obstacle. • LLMs can classify hash-based DGAs, but they struggle with dictionary-based ones. • LLMs degrade in real-world DNS traffic, requiring deployment improvements. Tomás Pelayo-Benedet, Ricardo J. Rodríguez, Carlos Gañán |
J. Inf. Secur. Appl. | 3 |
| 2024 | Poster: Empirical Analysis of Lifespan Increase of IoT C&C DomainsabstractThe increasing prevalence of Internet of Things (IoT) devices have made them attractive targets for malware, highlighting the critical need to understand the dynamics of IoT Command and Control (C&C). While previous research observed short-lived C&Cs, recent observations indicate that the lifespan of domain names linked to IoT botnets is extending, deviating from previously recorded survival rates. To understand and characterize this emerging trend, we collected and examined 1049 IoT malware samples from late 2022 to early 2023, identifying 549 unique domains contacted by these samples. Domains were classified as malicious if detected by VirusTotal or followed a Domain Generation Algorithm pattern. Using data from WhoisXMLAPI and DNSDB Scout, we analyzed registration information and historical DNS resolutions, and identified relationships. Our findings reveal that the majority of C&C domains belong to Qsnatch and Mirai malware families, with an average lifespan of 2.7 years. Notably, seven active domains had an average lifespan of 5.7 years. We also observed a significant number of domains under the .vg and .ws TLDs, but with lack of passive DNS and registration information. Daniel Uroz, Ricardo J. Rodríguez, Carlos Gañán |
IMC | 3 |
| 2024 | VT-SOS: A Cost-effective URL Warning utilizing VirusTotal as a Second Opinion ServiceabstractThe menace of malicious websites, such as online scams or phishing, has exhibited a noteworthy surge. While URL-based blocklists are still used as the primary security solution, previous studies show that the range of protection provided by these lists has little overlap, and the demand to have a second opinion is growing. In this paper, we design a system that aggregates information from multiple security engines in VirusTotal and warns users with malicious URLs that a single antivirus product would dismiss. We introduce VT-SOS, a system utilizing VirusTotal to provide a Second Opinion. Using 47 days of web access logs of real users, we implemented VT-SOS and evaluated effectiveness, affordability, and usability. By simulation, we show that VT-SOS could warn more than 100 users/day and provide a second opinion for more than 30 URLs/day even under a tight budget. We compared VT-SOS with three popular security services and confirmed that it could cover a wider range of malicious websites than those services. By investigating the worst-case user with the most access and warning, we demonstrate that VT-SOS will not deeply affect user experience in practice. Kyohei Takao, Chika Hiraishi, Rui Tanabe, Kazuki Takada, Akira Fujita, Carlos Gañán, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto |
NOMS | 7 |
| 2024 | Patchy Performance? Uncovering the Vulnerability Management Practices of IoT-Centric VendorsabstractThe enduring problems with IoT security has shifted the attention of researchers and governments to the role of vendors. The security community is no stranger to the repeated claim that vendors are dropping the ball on security and privacy, with numerous papers highlighting the many vulnerabilities in IoT products. Are IoT-centric vendors performing worse than other vendors in the industry? To answer this question, we need to do more than simply count the number of vulnerabilities disclosed by each vendor. In our study we analyze the factors influencing the number of vulnerabilities per vendor, like its size, its location and the presence of a vulnerability disclosure policy. We then statistically estimate if IoT-centric vendors produce more vulnerabilities, while controlling for those other factors. The answer is that they do. We can more directly observe the security performance of a vendor by looking at its patching behavior. We collect a unique dataset on the availability and timeliness of patches for 2,741 IoT and non-IoT vulnerabilities from 104 leading vendors. We also collect data on a set of potential causal factors for vendor patching performance. This allows us to estimate a statistical model of factors to explain why some vendors do better than others. We find that IoT-centric vendors are no worse in terms of releasing patches for their vulnerabilities, in fact, they tend to release more patches on-time than non-IoT-centric vendors. Our study increases our understanding of the factors shaping IoT security and provides an empirical basis for regulatory interventions that aim to improve the security performance of IoT vendors. Sandra Rivera Pérez, Michel van Eeten, Carlos Gañán |
SP | 3 |
| 2024 | IoT Market Dynamics: An Analysis of Device Sales, Security and Privacy Signals, and their Interactions
Swaathi Vetrivel, Brennen Bouwmeester, Michel van Eeten, Carlos Gañán |
USENIX Security Symposium | 4 |
| 2023 | Alert Alchemy: SOC Workflows and Decisions in the Management of NIDS RulesabstractSignature-based network intrusion detection systems (NIDSs) and network intrusion prevention systems (NIPSs) remain at the heart of network defense, along with the rules that enable them to detect threats. These rules allow Security Operation Centers (SOCs) to properly defend a network, yet we know almost nothing about how rules are created, evaluated and managed from an organizational standpoint. In this work, we analyze the processes surrounding the creation, management, and acquisition of rules for network intrusion detection. To understand these processes, we conducted interviews with 17 professionals who work at Managed Security Service Providers (MSSPs) or other organizations that provide network monitoring as a service or conduct their own network monitoring internally. We discovered numerous critical factors, such as rule specificity and total number of alerts and false positives, that guide SOCs in their rule management processes. These lower-level aspects of network monitoring processes have generally been regarded as immutable by prior work, which has mainly focused on designing systems that handle the resulting alert flows by dynamically reducing the number of noisy alerts SOC analysts need to sift through. Instead, we present several recommendations that address these lower-level aspects to help improve alert quality and allow SOCs to better optimize workflows and use of available resources. These recommendations include increasing the specificity of rules, explicitly defining feedback loops from detection to rule development, and setting up organizational processes to improve the transfer of tacit knowledge. Mathew Vermeer, Natalia Kadenko, Michel van Eeten, Carlos Gañán, Simon Edward Parkin |
CCS | 4 |
| 2023 | Peering into the Darkness: The Use of UTRS in Combating DDoS Attacks
Radu Anghel, Swaathi Vetrivel, Elsa Turcios Rodriguez, Kaichi Sameshima, Daisuke Makita, Katsunari Yoshioka, Carlos Gañán, Yury Zhauniarovich |
ESORICS (2) | 7 |
| 2023 | Intercept and Inject: DNS Response Manipulation in the Wild
Yevheniya Nosyk, Qasim Lone, Yury Zhauniarovich, Carlos Gañán, Emile Aben, Giovane Cesar Moreira Moura, Samaneh Tajalizadehkhoob, Andrzej Duda, Maciej Korczynski |
PAM | 4 |
| 2023 | Back-to-the-Future Whois: An IP Address Attribution Service for Working with Historic DatasetsabstractAbstract Researchers and practitioners often face the issue of having to attribute an IP address to an organization. For current data this is comparably easy, using services like whois or other databases. Similarly, for historic data, several entities like the RIPE NCC provide websites that provide access to historic records. For large-scale network measurement work, though, researchers often have to attribute millions of addresses. For current data, Team Cymru provides a bulk whois service which allows bulk address attribution. However, at the time of writing, there is no service available that allows historic bulk attribution of IP addresses. Hence, in this paper, we introduce and evaluate our ‘Back-to-the-Future whois’ service, allowing historic bulk attribution of IP addresses on a daily granularity based on CAIDA Routeviews aggregates. We provide this service to the community for free, and also share our implementation so researchers can run instances themselves. Florian Streibelt, Martina Lindorfer, Seda Gurses, Carlos Gañán, Tobias Fiebig |
PAM | 4 |
| 2023 | How Ready is DNS for an IPv6-Only World?abstractAbstract DNS is one of the core building blocks of the Internet. In this paper, we investigate DNS resolution in a strict IPv6-only scenario and find that a substantial fraction of zones cannot be resolved. We point out, that the presence of an resource record for a zone’s nameserver does not necessarily imply that it is resolvable in an IPv6-only environment since the full DNS delegation chain must resolve via IPv6 as well. Hence, in an IPv6-only setting zones may experience an effect similar to what is commonly referred to as lame delegation. Our longitudinal study shows that the continuing centralization of the Internet has a large impact on IPv6 readiness, i.e., a small number of large DNS providers has, and still can, influence IPv6 readiness for a large number of zones. A single operator that enabled IPv6 DNS resolution–by adding IPv6 glue records–was responsible for around 20.3% of all zones in our dataset not resolving over IPv6 until January 2017. Even today, 10% of DNS operators are responsible for more than 97.5% of all zones that do not resolve using IPv6 . Florian Streibelt, Patrick Sattler, Franziska Lichtblau, Carlos Gañán, Anja Feldmann, Oliver Gasser, Tobias Fiebig |
PAM | 4 |
| 2023 | Bin there, target that: Analyzing the target selection of IoT vulnerabilities in malware binariesabstractFor years, attackers have exploited vulnerabilities in Internet of Things (IoT) devices. Previous research has examined target selection in cybercrime, but there has been little investigation into the factors that influence target selection in attacks on IoT. This study aims to better understand how attackers choose their targets by analyzing the frequency of specific exploits in 11,893 IoT malware binaries that were distributed between 2018–2021. Our findings indicate that 78% of these binary files did not specifically target IoT vulnerabilities but rather scanned the Internet for devices with weak authentication. To understand the usage of exploits in the remaining 2,629 binaries, we develop a theoretical model from relevant literature to examine the impact of four latent variables, i.e. exposure, vulnerability, exploitability, and patchability. We collect indicators to measure these variables and find that they can explain to a significant extent (R2=0.38) why some vulnerabilities are more frequently exploited than others. The severity of vulnerabilities does not significantly increase the frequency with which they are targeted, while the presence of Proof-of-Concept exploit code does increase it. We also observe that the availability of a patch reduces the frequency of being targeted, yet that more complex patches are associated with higher frequency. In terms of exposure, more widespread device models are more likely to be targeted by exploits. We end with recommendations to disincentivize attackers from targeting vulnerabilities. Arwa Abdulkarim Al Alsadi, Kaichi Sameshima, Katsunari Yoshioka, Michel van Eeten, Carlos Gañán |
RAID | 5 |
| 2023 | Phish and Chips: Language-agnostic classification of unsolicited emailsabstractEmail remains a popular communication tool despite the emergence of new messaging systems, however, this popularity also attracts individuals with malicious intentions. Despite the efforts of current email filtering to keep up with the email-based threat vectors, unsolicited emails still keep reaching millions of targets. The current solutions are mainly focused on distinguishing ham from spam/phishing, leaving a gap in the identification and analysis of other unsolicited emails such as scams and adult content. In this paper, we present a study on the development of a more granular approach for sanitizing and categorizing unsolicited emails, specifically focusing on spam, phishing, scam and adult content. We design and evaluate a method for classifying unsolicited emails that can aid incident response teams in extracting contextual potential Threat Indicators (TIs). We train a machine learning language-agnostic classifier that achieves high accuracy with a novel set features such as attachments and TIs characteristics. Our results show that spam continues to drive a great portion of unsolicited emails together with phishing. Our analysis of URLs extracted from unsolicited emails revealed a surprising finding - over 80% of these TIs were not flagged as malicious by other threat feeds. This highlights the need for more effective methods of sharing malicious emails and their associated TIs. Carlos Gañán, Siôn Lloyd, Samaneh Tajalizadehkhoob |
TrustCom | 1 |
| 2023 | Don't Get Hijacked: Prevalence, Mitigation, and Impact of Non-Secure DNS Dynamic UpdatesabstractDNS dynamic updates represent an inherently vulnerable mechanism deliberately granting the potential for any host to dynamically modify DNS zone files. Consequently, this feature exposes domains to various security risks such as domain hijacking, compromise of domain control validation, and man-in-the-middle attacks. Originally devised without the implementation of authentication mechanisms, non-secure DNS updates were widely adopted in DNS software, subsequently leaving domains susceptible to a novel form of attack termed zone poisoning. In order to gauge the extent of this issue, our analysis encompassed over 353 million domain names, revealing the presence of 381,965 domains that openly accepted unsolicited DNS updates. We then undertook a comprehensive three-phase campaign involving the notification of Computer Security Incident Response Teams (CSIRTs). Following extensive discussions spanning six months, we observed substantial remediation, with nearly 54% of nameservers and 98% of vulnerable domains addressing the issue. This outcome serves as evidence that engaging with CSIRTs can prove to be an effective approach for reporting security vulnerabilities. Moreover, our notifications had a lasting impact, as evidenced by the sustained low prevalence of vulnerable domains. Yevheniya Nosyk, Maciej Korczynski, Carlos Gañán, Michal Król, Qasim Lone, Andrzej Duda |
TrustCom | 3 |
| 2023 | Measuring Up to (Reasonable) Consumer Expectations: Providing an Empirical Basis for Holding IoT Manufacturers Legally Responsible
Lorenz Kustosch, Carlos Gañán, Mattis van 't Schip, Michel van Eeten, Simon Edward Parkin |
USENIX Security Symposium | 2 |
| 2023 | Two Sides of the Shield: Understanding Protective DNS adoption factors
Elsa Turcios Rodriguez, Radu Anghel, Simon Edward Parkin, Michel van Eeten, Carlos Gañán |
USENIX Security Symposium | 5 |
| 2023 | Examining Consumer Reviews to Understand Security and Privacy Issues in the Market of Smart Home Devices
Swaathi Vetrivel, Veerle van Harten, Carlos Gañán, Michel van Eeten, Simon Edward Parkin |
USENIX Security Symposium | 3 |
| 2023 | Heads in the Clouds? Measuring Universities' Migration to Public Clouds: Implications for Privacy & Academic FreedomabstractWith the emergence of remote education and work in universities due to COVID-19, the 'zoomification' of higher education, i.e., the migration of universities to the clouds, reached the public discourse. Ongoing discussions reason about how this shift will take control over students' data away from universities, and may ultimately harm the privacy of researchers and students alike. However, there has been no comprehensive measurement of universities' use of public clouds and reliance on Software-as-a-Service offerings to assess how far this migration has already progressed. We perform a longitudinal study of the migration to public clouds among universities in the U.S. and Europe, as well as institutions listed in the Times Higher Education (THE) Top100 between January 2015 and October 2022. We find that cloud adoption differs between countries, with one cluster (Germany, France, Austria, Switzerland) showing a limited move to clouds, while the other (U.S., U.K., the Netherlands, THE Top100) frequently outsources universities' core functions and services---starting long before the COVID-19 pandemic. We attribute this clustering to several socio-economic factors in the respective countries, including the general culture of higher education and the administrative paradigm taken towards running universities. We then analyze and interpret our results, finding that the implications reach beyond individuals' privacy towards questions of academic independence and integrity. Tobias Fiebig, Seda Gurses, Carlos Gañán, Erna Kotkamp, Fernando A. Kuipers, Martina Lindorfer, Menghua Prisse, Taritha Sari |
Proc. Priv. Enhancing Technol. | 3 |
| 2022 | No Spring Chicken: Quantifying the Lifespan of Exploits in IoT Malware Using Static and Dynamic AnalysisabstractThe Internet of things (IoT) is composed by a wide variety of software and hardware components that inherently contain vulnerabilities. Previous research has shown that it takes only a few minutes from the moment an IoT device is connected to the Internet to the first infection attempts. Still, we know little about the evolution of exploit vectors: Which vulnerabilities are being targeted in the wild, how has the functionality changed over time, and for how long are vulnerabilities being targeted? Understanding these questions can help in the secure development, and deployment of IoT networks. Arwa Abdulkarim Al Alsadi, Kaichi Sameshima, Jakob Bleier, Katsunari Yoshioka, Martina Lindorfer, Michel van Eeten, Carlos Gañán |
AsiaCCS | 7 |
| 2022 | Ruling the Rules: Quantifying the Evolution of Rulesets, Alerts and Incidents in Network Intrusion DetectionabstractNotwithstanding the predicted demise of signature-based network monitoring, it is still part of the bedrock of security operations. Rulesets are fundamental to the efficacy of Network Intrusion Detection Systems (NIDS). Yet, they have rarely been studied in production environments. We partner with a Managed Security Service Provider (MSSP) to gain more insight into the evolution of rulesets, the alerts that they trigger and the incidents that get investigated. We analyze a combined ruleset --including both commercial and proprietary rules-- that consists of 130 thousand rules and was used to monitor hundreds of networks. We find that these rulesets keep growing over time but there is almost no overlap among them in terms of detection options or what indicators of compromise they contain. The combined ruleset triggered more than 62 million alerts and led to 150 thousand incident investigations by SOC analysts, though the vast majority of rules never triggered a single alert. We find that just 0.5% of all rules are responsible for more than 80% of the alerts and incidents and only 1.2% of all alerts were deemed to merit closer investigation. Of all incidents, 16% were labeled as false positives and 9% carried significant risk to the client organization. Independently of the type of rule, updating rules is a minor activity. Most rules are never modified and only a fraction is deleted, except for periodic purges in some sets. Seven in-depth interviews with rule developers corroborate the patterns we found in our analysis. Finally, we identify several rule management practices that influence rule and ruleset efficacy, such as supplementing commercial rules with your own and making rules as specific as possible. Mathew Vermeer, Michel van Eeten, Carlos Gañán |
AsiaCCS | 3 |
| 2022 | Difficult for Thee, But Not for Me: Measuring the Difficulty and User Experience of Remediating Persistent IoT MalwareabstractConsumer IoT devices may suffer malware attacks, and be recruited into botnets or worse. There is evidence that generic advice to device owners to address IoT malware can be successful, but this does not account for emerging forms of persistent IoT malware. Less is known about persistent malware, which resides on persistent storage, requiring targeted manual effort to remove it. This paper presents a field study on the removal of persistent IoT malware by consumers. We partnered with an ISP to contrast remediation times of 760 customers across three malware categories: Windows malware, non-persistent IoT malware, and persistent IoT malware. We also contacted ISP customers identified as having persistent IoT malware on their network-attached storage devices, specifically QSnatch. We found that persistent IoT malware exhibits a mean infection duration many times higher than Windows or Mirai malware; QSnatch has a survival probability of 30% after 180 days, whereby most if not all other observed malware types have been removed. For interviewed device users, QSnatch infections lasted longer, so are apparently more difficult to get rid of, yet participants did not report experiencing difficulty in following notification instructions. We see two factors driving this paradoxical finding: First, most users reported having high technical competency. Also, we found evidence of planning behavior for these tasks and the need for multiple notifications. Our findings demonstrate the critical nature of interventions from outside for persistent malware, since automatic scan of an AV tool or a power cycle, like we are used to for Windows malware and Mirai infections, will not solve persistent IoT malware infections. Elsa Turcios Rodriguez, Max Fukkink, Simon Edward Parkin, Michel van Eeten, Carlos Gañán |
EuroS&P | 5 |
| 2022 | Deployment of Source Address Validation by Network Operators: A Randomized Control TrialabstractIP spoofing, sending IP packets with a false source IP address, continues to be a primary attack vector for large-scale Denial of Service attacks. To combat spoofing, various interventions have been tried to increase the adoption of source address validation (SAV) among network operators. How can SAV deployment be increased? In this work, we conduct the first randomized control trial to measure the effectiveness of various notification mechanisms on SAV deployment. We include new treatments using nudges and channels, previously untested in notification experiments. Our design reveals a painful reality that contrasts with earlier observational studies: none of the notification treatments significantly improved SAV deployment compared to the control group. We explore the reasons for these findings and report on a survey among operators to identify ways forward. A portion of the operators indicate that they do plan to deploy SAV and ask for better notification mechanisms, training, and support materials for SAV implementation. Qasim Lone, Alisa Frik, Matthew J. Luckie, Maciej Korczynski, Michel van Eeten, Carlos Gañán |
SP | 6 |
| 2022 | Exposed Infrastructures: Discovery, Attacks and Remediation of Insecure ICS Remote Management DevicesabstractGeographically distributed infrastructures, such as buildings, dams, and solar power plants, are commonly maintained via Internet-connected remote management devices. Previous studies on detecting and securing industrial control systems (ICS) have overlooked these remote management devices, as they do not expose ICS-specific services like Modbus and BACnet and thus do not show up in Internet-wide scans for such services. In this paper, we implement and validate a discovery method for these devices via their Web User Interface (WebUI) and detect 890 devices in Japan alone. We also show that many of these devices are highly insecure. Many allow access to the status or even the control over industrial systems without proper authentication. Taking a closer look at three prevalent remote management devices, we discovered 13 0-day vulnerabilities, several of which were rated as medium or high severity. They have been responsibly disclosed to the manufacturers. By using honeypots that imitate these systems, we show that over time, only a small number of attackers enter these systems, but some do change critical parameters. Attackers appear to interact more with the system when more facility information is displayed on the WebUI. Finally, we notified operators of 317 vulnerable remote management devices by email and telephone. We reached 212 persons in charge of the devices and received confirmation that our method had correctly identified the device. 50% of the persons in charge of the devices stated that they mitigated or will mitigate the problem. We confirmed their actions via a followup scan for vulnerable devices and found that measures were taken for 58% of the devices when we could reach the persons in charge of the device. Takayuki Sasaki, Akira Fujita, Carlos Gañán, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto |
SP | 3 |
| 2022 | Helping hands: Measuring the impact of a large threat intelligence sharing community
Xander Bouwman, Victor Le Pochat, Pawel Foremski, Tom van Goethem, Carlos Gañán, Giovane Cesar Moreira Moura, Samaneh Tajalizadehkhoob, Wouter Joosen, Michel van Eeten |
USENIX Security Symposium | 5 |
| 2021 | Can ISPs Help Mitigate IoT Malware? A Longitudinal Study of Broadband ISP Security EffortsabstractFor the mitigation of compromised Internet of Things (IoT) devices we rely on Internet Service Providers (ISPs) and their users. Given that devices are in the hands of their subscribers, what can ISPs realistically do? This study examines the effects of ISP countermeasures on infections caused by variants of the notorious Mirai family of IoT malware, still among the dominant families. We collect and analyze more than 4 years of longitudinal darknet data tracking Mirai-like infections in conjunction with threat intelligence data on various other IoT and non-IoT botnets across the globe from January 2016 to May 2020. We measure the effect of two ISP countermeasures on Mirai variant infection numbers: (i) reducing the attack surface (i.e., closing ports that are used by the malware for propagation) and (ii) ISPs increasing their general network hygiene and malware removal efforts (as observed by proxy of the remediation of infections of other families of IoT and non-IoT malware and reductions in the number of DDoS amplifiers in their networks). We map our infection data to 342 broadband providers that have the bulk of the broadband market share in their respective 83 countries. We find that the number of infections correlates strongly with the number of ISP subscribers ($R^{2}=0.55$). Yet, infection numbers can still vary by three orders of magnitude even for ISPs with comparable subscriber numbers. We observe that many ISPs, together with their subscribers, have reduced their attack surface for IoT compromise by blocking traffic to commonly-exploited infection vectors such as Telnet and FTP. We statistically estimate the impact of these reductions on infection levels and, counter-intuitively, find no significant impact. In contrast, we do find a significant impact for improving general network hygiene and best malware mitigation practices. ISPs that were more successful in reducing DDoS amplifiers and non-Mirai malware infections in their networks also end up with significantly lower Mirai infection rates. In other words, rather than investing in IoT-specific countermeasures like reducing the attack surface, our findings suggest that ISPs might be better off investing in general security efforts to improve network hygiene and clean up abuse. Arman Noroozian, Elsa Turcios Rodriguez, Elmer Lastdrager, Takahiro Kasama, Michel van Eeten, Carlos Gañán |
EuroS&P | 6 |
| 2021 | SoK: A Framework for Asset Discovery: Systematizing Advances in Network Measurements for Protecting OrganizationsabstractAsset discovery is fundamental to any organization's cybersecurity efforts. Indeed, one must accurately know which assets belong to an IT infrastructure before the infrastructure can be secured. While practitioners typically rely on a relatively small set of well-known techniques, the academic literature on the subject is voluminous. In particular, the Internet measurement research community has devised a number of asset discovery techniques to support many measurement studies over the past five years. In this paper, we systematize asset discovery techniques by constructing a framework that comprehensively captures how network identifiers and services are found. We extract asset discovery techniques from recent academic literature in security and networking and place them into the systematized framework. We then demonstrate how to apply the framework to several case studies of asset discovery workflows, which could aid research reproducibility. These case studies further suggest opportunities for researchers and practitioners to uncover and identify more assets than might be possible with traditional techniques. Mathew Vermeer, Jonathan West, Alejandro Cuevas Villalba, Shuonan Niu, Nicolas Christin, Michel van Eeten, Tobias Fiebig, Carlos Gañán, Tyler Moore 0001 |
EuroS&P | 8 |
| 2020 | Disposable botnets: examining the anatomy of IoT botnet infrastructureabstractLarge botnets made up of Internet-of-Things (IoT) devices have been a steady presence in the threat landscape since 2016. Earlier research has found preliminary evidence that the IoT binaries and C&C infrastructure were only seen for very brief periods. It has not explained how attackers maintain control over their botnets. We present a more comprehensive analysis of the infrastructure of IoT botnets based on 23 months of data gathered via honeypots and the monitoring of botnet infrastructure. We collected 59,884 IoT malware samples, 35,494 download servers, and 2,747 C&C servers. We focuse on three dominant families: Bashlite, Mirai, and Tsunami. The picture that emerges is that of highly disposable botnets. IoT botnet are not so much maintained as reconstituted from scratch all the time. Not only are most binaries distributed for less than three days, the connection of bots to the rest of the botnet is also short-lived. To reach the C&C server, the binaries typically contain only a single hard-coded IP address or domain. The C&C servers themselves also have a short lifespan. Long-term dynamic analysis finds no mechanism for the attackers to migrate the bots to a new C&C server. In other words, bots are used only immediately after capture and then abandoned---perhaps to be recaptured again via the aggressive scanning practices that these botnets are known for. While IoT botnets appear less advanced than Windows-based botnets, the advantage of being disposable means that they are very resistant to blacklisting and C&C takedown. Most IP addresses are used only once and never seen again. The question that arises is how attackers source these addresses. We speculate that they might be abusing the IP address allocation practices of cloud providers. Rui Tanabe, Tatsuya Tamai, Akira Fujita, Ryoichi Isawa, Katsunari Yoshioka, Tsutomu Matsumoto, Carlos Gañán, Michel van Eeten |
ARES | 7 |
| 2019 | Tell Me You Fixed It: Evaluating Vulnerability Notifications via Quarantine NetworksabstractMechanisms for large-scale vulnerability notifications have been confronted with disappointing remediation rates. It has proven difficult to reach the relevant party and, once reached, to incentivize them to act. We present the first empirical study of a potentially more effective mechanism: quarantining the vulnerable resource until it is remediated. We have measured the remediation rates achieved by a medium-sized ISP for 1, 688 retail customers running open DNS resolvers or Multicast DNS services. These servers can be abused in UDP-based amplification attacks. We assess the effectiveness of quarantining by comparing remediation with two other groups: one group which was notified but not quarantined and another group where no action was taken. We find very high remediation rates for the quarantined users, 87%, even though they can self-release from the quarantine environment. Of those who received the email-only notification, 76% remediated. Surprisingly, over half of the customers who were not notified at all also remediated, though this is tied to the fact that many observations of vulnerable servers are transient. All in all, quarantining appears more effective than other notification and remediation mechanisms, but it is also clear that it can not be deployed as a general solution for Internet-wide notifications. Orçun Çetin, Carlos Gañán, Lisette Altena, Samaneh Tajalizadehkhoob, Michel van Eeten |
EuroS&P | 2 |
| 2019 | Detect Me If You... Oh Wait. An Internet-Wide View of Self-Revealing Honeypots
Shun Morishita, Takuya Hoizumi, Wataru Ueno, Rui Tanabe, Carlos Gañán, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto |
IM | 5 |
| 2019 | Cleaning Up the Internet of Evil Things: Real-World Evidence on ISP and Consumer Efforts to Remove Mirai
Orçun Çetin, Carlos Gañán, Lisette Altena, Takahiro Kasama, Kazuki Tamiya, Ying Tie, Katsunari Yoshioka, Michel van Eeten |
NDSS | 2 |
| 2019 | Platforms in Everything: Analyzing Ground-Truth Data on the Anatomy and Economics of Bullet-Proof Hosting
Arman Noroozian, Jan Koenders, Eelco van Veldhuizen, Carlos Gañán, Sumayah A. Alrwais, Damon McCoy, Michel van Eeten |
USENIX Security Symposium | 4 |
| 2018 | Plug and Prey? Measuring the Commoditization of Cybercrime via Online Anonymous Markets
Rolf van Wegberg, Samaneh Tajalizadehkhoob, Kyle Soska, Ugur Akyazi, Carlos Gañán, Bram Klievink, Nicolas Christin, Michel van Eeten |
USENIX Security Symposium | 5 |
| 2018 | Rotten Apples or Bad Harvest? What We Are Measuring When We Are Measuring AbuseabstractInternet security and technology policy research regularly uses technical indicators of abuse to identify culprits and to tailor mitigation strategies. As a major obstacle, current inferences from abuse data that aim to characterize providers with poor security practices often use a naive normalization of abuse (abuse counts divided by network size) and do not take into account other inherent or structural properties of providers. Even the size estimates are subject to measurement errors relating to attribution, aggregation, and various sources of heterogeneity. More precise indicators are costly to measure at Internet scale. We address these issues for the case of hosting providers with a statistical model of the abuse data generation process, using phishing sites in hosting networks as a case study. We decompose error sources and then estimate key parameters of the model, controlling for heterogeneity in size and business model. We find that 84% of the variation in abuse counts across 45,358 hosting providers can be explained with structural factors alone. Informed by the fitted model, we systematically select and enrich a subset of 105 homogeneous “statistical twins” with additional explanatory variables, unreasonable to collect for all hosting providers. We find that abuse is positively associated with the popularity of websites hosted and with the prevalence of popular content management systems. Moreover, hosting providers who charge higher prices (after controlling for level differences between countries) witness less abuse. These structural factors together explain a further 77% of the remaining variation. This calls into question premature inferences from raw abuse indicators about the security efforts of actors, and suggests the adoption of similar analysis frameworks in all domains where network measurement aims at informing technology policy. Samaneh Tajalizadehkhoob, Rainer Böhme, Carlos Gañán, Maciej Korczynski, Michel van Eeten |
ACM Trans. Internet Techn. | 3 |
| 2017 | The Role of Hosting Providers in Fighting Command and Control Infrastructure of Financial MalwareabstractA variety of botnets are used in attacks on financial services. Banks and security firms invest a lot of effort in detecting and combating malware-assisted takeover of customer accounts. A critical resource of these botnets is their command-and-control (C&C) infrastructure. Attackers rent or compromise servers to operate their C&C infrastructure. Hosting providers routinely take down C&C servers, but the effectiveness of this mitigation strategy depends on understanding how attackers select the hosting providers to host their servers. Do they prefer, for example, providers who are slow or unwilling in taking down C&Cs? In this paper, we analyze 7 years of data on the C&C servers of botnets that have engaged in attacks on financial services. Our aim is to understand whether attackers prefer certain types of providers or whether their C&Cs are randomly distributed across the whole attack surface of the hosting industry. We extract a set of structural properties of providers to capture the attack surface. We model the distribution of C&Cs across providers and show that the mere size of the provider can explain around 71% of the variance in the number of C&Cs per provider, whereas the rule of law in the country only explains around 1%. We further observe that price, time in business, popularity and ratio of vulnerable websites of providers relate significantly with C&C counts. Finally, we find that the speed with which providers take down C&C domains has only a weak relation with C&C occurrence rates, adding only 1% explained variance. This suggests attackers have little to no preference for providers who allow long-lived C&C domains. Samaneh Tajalizadehkhoob, Carlos Gañán, Arman Noroozian, Michel van Eeten |
AsiaCCS | 2 |
| 2017 | Beyond the pretty penny: the Economic Impact of CybercrimeabstractOver the past decade, considerable research effort has been devoted to articulating and measuring the various ways through which cyber crime impacts overall society. The large volume of literature on the topic contains few attempts to produce estimates of the financial impact of specific cyber incidents and little agreement on how to derive such estimates. An important substrata of this literature focuses on placing a monetary value on the costs of cyber crime but little is known about the long-term economic impact to society. In this article, we first assess the shortcomings of existing cost estimates and focus on the relevant issues pertinent to the feasibility of deriving valid and useful estimates beyond cost-benefit analyses. Following a mixed top-down/bottom-up methodology, we propose a theoretical framework to systematically identify the short and long-term impacts of cyber crime both at the agent and societal level. This framework serves as the foundation to assess the economic consequences of cyber crime beyond monetary costs by focusing on the impact on economic growth. Carlos Gañán, Michael Ciere, Michel van Eeten |
NSPW | 1 |
| 2017 | Partial Device Fingerprints
Michael Ciere, Carlos Gañán, Michel van Eeten |
ECML/PKDD (2) | 2 |
| 2016 | Apples, oranges and hosting providers: Heterogeneity and security in the hosting marketabstractHosting services are associated with various security threats, yet the market has barely been studied empirically. Most security research has relied on routing data and equates providers with Autonomous Systems, ignoring the complexity and heterogeneity of the market. To overcome these limitations, we combined passive DNS data with WHOIS data to identify providers and some of their properties. We found 45,434 hosting providers, spread around a median address space size of 1,517 IP addresses. There is surprisingly little consolidation in the market, even though its services seem amenable to economies of scale. We applied cluster analysis on several measurable characteristics of providers. This uncovered a diverse set of business profiles and an indication of what fraction of the market fits each profile. The profiles are associated with significant differences in security performance, as measured by the uptime of phishing sites. This suggests the approach provides an effective way for security researchers to take the heterogeneity of the market into account. Samaneh Tajalizadehkhoob, Maciej Korczynski, Arman Noroozian, Carlos Gañán, Michel van Eeten |
NOMS | 4 |
| 2016 | Who Gets the Boot? Analyzing Victimization by DDoS-as-a-Service
Arman Noroozian, Maciej Korczynski, Carlos Gañán, Daisuke Makita, Katsunari Yoshioka, Michel van Eeten |
RAID | 3 |
| 2015 | An Empirical Analysis of ZeuS C&C LifetimeabstractBotnets continue to pose a significant threat to network-based applications and communications over the Internet. A key mitigation strategy has been to take down command and control infrastructure of the botnets. The efficiency of those mitigation methods has not been extensively studied. In this paper we investigate several observable characteristics of botnet command and controls (C&C) and estimate the variability in the survival rate of these C&Cs and the factors that are related to such variability. Furthermore, we show that different type of mitigation efforts have different impact. Kaplan-Meier analysis is performed to evaluate C&C survival ratios in the particular case of the ZeuS botnet. Using a lasso penalized Cox regression model, we identify the factors that influence the lifetime of a C&C. Location, malware family type, registrar, hosting type and popularity are the fundamental factors that explain this variability. Our results show that location and type of hosting are the two factors that affect more significantly the C&C lifetime. Thus, ZeuS C&Cs in certain regions of Asia are prone to stay online longer that those located in Europe. Carlos Gañán, Orçun Çetin, Michel van Eeten |
AsiaCCS | 1 |
| 2015 | How dynamic is the ISPs address space? Towards internet-wide DHCP churn estimationabstractIP address counts are typically used as a surrogate metric for the number of hosts in a network, as in the case of ISP rankings based on botnet infected addresses. However, due to effects of dynamic IP address allocation, such counts tend to overestimate the number of hosts, sometimes by an order of magnitude. In the literature, the rate at which hosts change IP addresses is referred to as DHCP churn. Churn rates vary significantly within and among ISP networks, and such variation poses a challenge to any research that relies upon IP addresses as a metric. We present the first attempt towards estimating ISP and Internet-wide DHCP churn rates, in order to better understand the relation between IP addresses and hosts, as well as allow us to correct data relying on IP addresses as a surrogate metric. We propose an scalable active measurement methodology and then validate it using ground truth data from a medium-sized ISP. Next, we build a statistical model to estimate DHCP churn rates and validate against the ground truth data of the same ISP, estimating correctly 72.3% of DHCP churn rates. Finally, we apply our measurement methodology to four major ISPs, triangulate the results to another Internet census, and discuss the next steps to more precisely estimate DHCP churn rates. Giovane Cesar Moreira Moura, Carlos Gañán, Qasim Lone, Payam Poursaied, Hadi Asghari, Michel van Eeten |
Networking | 2 |
| 2015 | A model for revocation forecasting in public-key infrastructures
Carlos Gañán, Jorge Mata-Díaz, Jose L. Muñoz, Oscar Esparza, Juan J. Alins-Delgado |
Knowl. Inf. Syst. | 1 |
| 2015 | EPA: An efficient and privacy-aware revocation mechanism for vehicular ad hoc networks
Carlos Gañán, Jose L. Muñoz, Oscar Esparza, Jorge Mata-Díaz, Juan J. Alins-Delgado |
Pervasive Mob. Comput. | 1 |
| 2014 | Certificate Revocation List Distribution System for the KAD NetworkabstractMany peer-to-peer (p2p) overlays require certain security services which could be provided through a Public Key Infrastructure. However, these infrastructures are bound up with a revocation system, such as Certificate Revocation Lists (CRLs). A system with a client/server structure, where a Certificate Authority plays a role of a central server, is prone to suffer from common problems of a single point of failure. If only one Authority has to distribute the whole CRL to all users, perhaps several millions in a structured p2p overlay, a bottleneck problem appears. Moreover, in these networks, users often have a set of pseudonyms that are bound to a certificate, which gives rise to two additional issues: issuing the CRL and assuring its freshness. On the one hand, the list size grows exponentially with the number of network users. On the other hand, these lists must be updated more frequently; otherwise the revocation data will not be fresh enough. To solve these problems, we propose a new distributed revocation system for the Kademlia network. Our system distributes CRLs using the overlay itself and, to not compromise the storage of nodes, lists are divided into segments. This mechanism improves the accessibility, increases the availability and guarantees the freshness of the revocation data. Juan Caubet, Carlos Gañán, Oscar Esparza, Jose L. Muñoz, Jorge Mata-Díaz, Juan J. Alins-Delgado |
Comput. J. | 2 |
| 2013 | COACH: COllaborative certificate stAtus CHecking mechanism for VANETs
Carlos Gañán, Jose L. Muñoz, Oscar Esparza, Jorge Mata-Díaz, Juan Hernández-Serrano, Juan J. Alins-Delgado |
J. Netw. Comput. Appl. | 1 |
| 2013 | Low-cost group rekeying for unattended wireless sensor networks
Juan Hernández-Serrano, Juan Vera del Campo, Josep Pegueroles 0001, Carlos Gañán |
Wirel. Networks | 4 |
| 2012 | Impact of the Revocation Service in PKI Prices
Carlos Gañán, Jose L. Muñoz, Oscar Esparza, Jorge Mata-Díaz, Juan J. Alins-Delgado |
ICICS | 1 |
| 2012 | On the Self-similarity Nature of the Revocation Data
Carlos Gañán, Jorge Mata-Díaz, Jose L. Muñoz, Oscar Esparza, Juan J. Alins-Delgado |
ISC | 1 |
| 2012 | RAR: Risk Aware Revocation Mechanism for Vehicular NetworksabstractVehicular Ad Hoc Networks (VANETs) require some mechanism to authenticate messages, identify valid vehicles, and remove misbehaving ones. A Public Key Infrastructure (PKI) can provide this functionality using digital certificates. In PKI, key management and corresponding issuance and revocation of digital certificates is one of the key issues that have to be solved. The IEEE 1609.2 standard states that VANETs will rely on the use of certificate revocation lists (CRLs) to achieve revocation. In this paper, we analyze the problems of using CRLs in these type of networks. Moreover, we describe the Risk Aware Revocation (RAR) mechanism that improves the traditional use of CRLs. RAR takes advantage of the two distinct channel types in VANETs to increase the freshness of the revocation information. Moreover, RAR allows users to gauge the risk of operating in a VANET when using CRLs. Carlos Gañán, Jose L. Muñoz, Oscar Esparza, Jorge Mata-Díaz, Juan J. Alins-Delgado, Carlos Silva Cárdenas, Gumercindo Bartra-Gardini |
VTC Spring | 1 |
| 2012 | A Modeling of Certificate Revocation and Its Application to Synthesis of Revocation TracesabstractOne of the hardest tasks of a public key infrastructure (PKI) is to manage revocation. New communication paradigms push the revocation system to the limit and an accurate resource assessment is necessary before implementing a particular revocation distribution system. In this context, a precise modeling of certificate revocation is necessary. In this paper, we analyze empirical data from real certification authorities (CAs) to develop an accurate and rigorous model for certificate revocation. One of the key findings of our analysis is that the certificate revocation process is statistically self-similar. The proposed model is based on an autoregressive fractionally integrated moving average (ARFIMA) process. Then, using this model, we show how to build a synthetic revocation generator that can be used in simulations for resource assessment. Finally, we also show that our model produces synthetic revocation traces that are indistinguishable for practical purposes from those corresponding to actual revocations. Carlos Gañán, Jorge Mata-Díaz, Jose L. Muñoz, Juan Hernández-Serrano, Oscar Esparza, Juan J. Alins-Delgado |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2009 | PKIX Certificate Status in Hybrid MANETs
Jose L. Muñoz, Oscar Esparza, Carlos Gañán, Javier Parra-Arnau |
WISTP | 3 |