Alejandro Molina Zarca

dblp:226/9251 · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
6since 2021 · last 2026
0000-0003-0038-9012ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Automating 5G Traffic Generation With Virtual UEs: A Scalable Network Testing Infrastructure
abstract
5G technology represents a transformative leap in wireless networks, promising advancements in smart cities, autonomous transport, and IoT through high data speeds, reduced latency, and support for numerous devices. However, realizing these benefits requires overcoming significant security challenges, particularly in anomaly detection, as the vast device flow increases the risk of vulnerabilities. While AI is critical for this task, the availability of models for AI-based 5G analysis remains limited. This paper addresses this gap by presenting a scalable research framework for generating realistic 5G traffic across both control and user planes without actual 5G devices. The framework enables non-5G devices, such as mobile phones or PCs, to connect to a real 5G RAN infrastructure via virtual User Equipments (UEs), allowing them to generate client traffic at reduced costs and without physical 5G devices. This innovative approach supports the generation of large amounts of 5G traffic, for subsequent collection and analysis to create various datasets, simulating diverse network behaviours for cybersecurity purposes. By leveraging this virtualized environment, our framework offers a versatile, cost-effective solution for comprehensive 5G data generation in a controlled setting. Results demonstrate that 5G traffic generated by non-5G devices through this framework is suitable for AI modelling and training, advancing research capabilities in anomaly detection and overall network security.
Emilio Garcia de La Calera Molina, Anthony Joel Pogo Medina, Alejandro Molina Zarca, Pablo Fernández Saura, Antonio F. Skarmeta
IEEE Trans. Netw. Serv. Manag.3
2025 Ai-Based Meta-Orchestration for Fl-Based Anomaly Detection in B5g Networks
abstract
G networks will need to handle Multi-domain, multi-tenant and multi-operator scenarios where the security orchestration of services and network functions will face high complexity of scalability, interoperability and security. In particular, 6G networks will need to manage AI-based network functions to support analytics that can be encapsulated as virtual functions that need to be dynamically orchestrated, configured, deployed, decommissioned, migrated and reconfigured on demand. The distributed nature of these scenarios requires a federated learning FL approach to handle AI-based collaborative learning where FL-agents can be deployed in the continuum of any network segment of the network. This paper proposes an AI-based meta-orchestration approach for multi-domain and multi-tenant 6 G deployments intended to choreograph the FLbased AI functions. The meta-Orchestration encompasses diverse phases, including selection of the orchestration strategy, the orchestration graph building and the selection of best AI-based orchestration algorithm depending on the actual context, thereby maximizing the effectiveness of the allocation of the FL-agents. The implementation and performance evaluation to orchestrate FL agents with diverse AI-based algorithms across the continuum proves our approach to detect anomalies using FL in distributed scenarios.
Pablo Fernández Saura, José Manuel Bernabé Murcia, Alejandro Molina Zarca, Jorge Bernal Bernabé, Antonio F. Skarmeta
NetSoft3
2025 BASTION: Beyond automated service and security orchestration for next-generation networks
abstract
The adoption of 5G technology and beyond introduces advanced capabilities, such as dynamic resource coordination and allocation tailored to specific service and security requirements. To achieve efficient security and network management, service automation and orchestration are essential. This paper presents BASTION, a ZSM-aligned framework for enhanced service and security (meta) orchestration. By leveraging an intent-based, policy-driven approach, it enables the orchestration and enforcement of service and security policies across B5G infrastructures, dynamically adapting to real-time infrastructure conditions. While meta-orchestration capabilities focus on selecting the most suitable orchestration algorithm based on the system’s current status and the received requirements, orchestration capabilities primarily determine what, where, when, and how to enforce services and security policies. Additionally, the modular design and implementation allow for the seamless integration of new security capabilities through plugins, drivers, and managers. This advancement represents a significant step toward building resilient, adaptable, and secure B5G networks capable of meeting the complex demands of modern network environments. The implementation details showcase the full range of capabilities offered by the BASTION framework, highlighting its effectiveness through successful European and national projects. Furthermore, the performance evaluation section provides a comprehensive analysis of orchestration efficiency, breaking down execution times across different phases. In particular, BASTION demonstrates exceptional performance, achieving decision times as low as 1.3 ms and deploying services and security policies, including fully operational dynamic VNFs in less than 30 s, underscoring its ability to deliver fast, scalable, and efficient orchestration in complex environments.
José Manuel Bernabé Murcia, Alejandro Molina Zarca, Antonio F. Skarmeta
Comput. Networks2
2025 Decentralised Identity Management solution for zero-trust multi-domain Computing Continuum frameworks
abstract
The adoption of the Computing Continuum is characterised by the seamless integration of diverse computing environments and devices. In this dynamic landscape, sharing resources across the continuum is becoming a reality and security must move an step forward, specially in terms of authentication and authorisation for such a distributed and heterogeneous environments. The need for robust identity management is paramount and, in this regard, Decentralised Identity Management (DIM) emerges as a promising solution. It leverages decentralised technologies to secure and facilitate identity interactions across the Computing Continuum. Particularly, to enhance security and privacy, it would be desirable to apply the principles of Self-Sovereign Identity (SSI). In this paradigm, users have full ownership and control of their digital identities that empowers individuals to manage and share their identity data on a need-to-know basis. These mechanisms could contribute to improve security properties during continuum resource management operations. In this context, this paper presents the design, workflows and implementation of a solution that provides authentication/authorisation features to distributed zero-trust based infrastructures across the continuum, enhancing security in resource sharing and resource acquisition stages. To this aim, the solution relies on key aspects like decentralisation, interoperability, trust management and privacy-enhancing capabilities. The decentralisation leverages distributed ledger technologies, such as blockchain, to establish a decentralised identity ecosystem. The solution prioritises interoperability, enabling nodes to seamlessly access and share their identities across different domains and environments. Trustworthiness is at the core of DIM, and privacy is also considered, incorporating privacy-preserving techniques that individuals to selectively disclose identity attributes while safeguarding sensitive information. The implementation includes different operations for allowing continuum frameworks to be enhanced with decentralised authentication and authorisation features. The performance has been evaluated measuring the impact for the adoption of the solution. The most expensive task, the self-identity generation, takes only a few seconds (in our deployment) and it is only executed once. Authorisation tasks operate in the millisecond range, which is a totally invaluable time if incorporated into resource acquisition processes in frameworks such as Liqo, used in the scope of FLUIDOS project.
José Manuel Bernabé Murcia, Eduardo Cánovas, Jesús García Rodríguez, Alejandro Molina Zarca, Antonio F. Skarmeta
Future Gener. Comput. Syst.4
2023 By-default Security Orchestration on distributed Edge/Cloud Computing Framework
abstract
Next generation networks and the strength of the distributed computing paradigm (edge/cloud) are transforming how services are provisioned, mainly when solutions focus on collaboration and aggregation of resources provided by different entities or organisations, that becomes essential to satisfy the most demanding computation and storage service requirements. However, it also entails challenges such as infrastructure and technologies heterogeneity, which directly impacts infrastructure management and especially security, that usually tends to be relegated to a second place. This paper provides a by-default security orchestrator approach to mitigate the above mentioned challenges in distributed edge/cloud computing frameworks. We use an Intent-based/policy-based orchestration paradigm for dealing with heterogeneity, allowing users to request service deployments securely without requiring knowledge about the underlying distributed infrastructure. By-default security orchestration will decide how to provide the requested services, ensuring that they are compliant with the security requirements provided by the user and the ones gathered by the system, locally and from reliable external sources1. We provide design and use-cases based workflows for managing by-default security orchestration in proactive and reactive ways. In the future, it is expected to perform the implementation and validation of the proposed approach inside the scope of the FLUIDOS EU project.1https://www.cisa.gov/known-exploited-vulnerabilities-catalog
José Manuel Bernabé Murcia, José Francisco Pérez Zarca, Alejandro Molina Zarca, Antonio F. Skarmeta
NetSoft3
2022 Automatic, verifiable and optimized policy-based security enforcement for SDN-aware IoT networks
Daniele Bringhenti, Jalolliddin Yusupov, Alejandro Molina Zarca, Fulvio Valenza, Riccardo Sisto, Jorge Bernal Bernabé, Antonio F. Skarmeta
Comput. Networks3
2020 Virtual IoT HoneyNets to Mitigate Cyberattacks in SDN/NFV-Enabled IoT Networks
abstract
As the IoT adoption is growing in several fields, cybersecurity attacks involving low-cost end-user devices are increasing accordingly, undermining the expected deployment of IoT solutions in a broad range of scenarios. To address this challenge, emerging Network Function Virtualization (NFV) and Software Defined Networking (SDN) technologies can introduce new security enablers, thereby endowing IoT systems and networks with higher degree of scalability and flexibility required to cope with the security of massive IoT deployments. In this sense, honeynets can be enhanced with SDN and NFV support, to be applied into IoT scenarios thereby strengthening the overall security. IoT honeynets are virtualized services simulating real IoT networks deployments, so that attackers can be distracted from the real target. In this paper, we present a novel mechanism leveraging SDN and NFV aimed to autonomously deploy and enforce IoT honeynets. The system follows a security policy-based approach that facilitates management, enforcement and orchestration of the honeynets and it has been successfully implemented and tested in the scope of H2020 EU project ANASTACIA, showing its feasibility to mitigate cyber-attacks.
Alejandro Molina Zarca, Jorge Bernal Bernabé, Antonio F. Skarmeta, José M. Alcaraz Calero
IEEE J. Sel. Areas Commun.1
2019 Security Management Architecture for NFV/SDN-Aware IoT Systems
abstract
The Internet of Things (IoT) brings a multidisciplinary revolution in several application areas. However, security and privacy concerns are undermining a reliable and resilient broad-scale deployment of IoT-enabled critical infrastructures (IoT-CIs). To fill this gap, this paper proposes a comprehensive architectural design that captures the main security and privacy challenges related to cyber-physical systems and IoT-CIs. The architecture is devised to empower IoT systems and networks to make autonomous security decisions through the usage of novel technologies such as software defined networking and network function virtualization, as well as endowing them with intelligent and dynamic security reaction capabilities by relying on monitoring methodologies and cyber-situational tools. The architecture has been successfully implemented and evaluated in the scope of ANASTACIA H2020 EU research project.
Alejandro Molina Zarca, Jorge Bernal Bernabé, Rubén Trapero, Jesus Villalobos, Antonio F. Skarmeta, Stefano Bianchi, Anastasios Zafeiropoulos, Panagiotis Gouvas
IEEE Internet Things J.1