VLDB 2026 Research / reviewers in the wild / expert
Jorge Blasco Alís
dblp:27/7270 · also Jorge Blasco
· DBLP profile ↗
29ranked-venue papers
7as first author
15since 2021 · last 2026
0000-0003-4392-9023ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 4 first-author · 12 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 since 2021Computer networks · 2 · 2 first-authorArtificial intelligence and machine learning · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SynthCTI: LLM-driven synthetic CTI generation to enhance MITRE technique mappingabstract• SynthCTI, a LLM-guided method generates synthetic CTI data to address class imbalance. • LLM prompts for augmentation guided by clustering and topic extraction. • Enables lightweight models to outperform larger ones without augmentation. Cyber Threat Intelligence (CTI) mining extracts structured insights from unstructured threat data, enabling organizations to understand and respond to evolving adversarial behavior. A key task is mapping threat descriptions to MITRE ATT&CK techniques. However, this is often performed manually, requiring expert knowledge and substantial effort. Automated approaches face two major challenges: scarcity of high-quality labeled CTI data and class imbalance. While domain-specific Large Language Models (LLMs) such as SecureBERT have improved performance, most recent work focuses on model architecture rather than data limitations. We hypothesize that semantically guided synthetic CTI generation can mitigate such limitations. To test this hypothesis, we present SynthCTI, a data augmentation framework designed to generate high-quality synthetic CTI sentences for underrepresented MITRE ATT&CK techniques. The methodology converts CTI sentences into semantic vector representations, clusters them with HDBSCAN to identify semantically coherent groups, and extracts contextual features to construct prompts. These prompts guide an LLM to produce diverse and semantically faithful synthetic CTI sentences. We evaluate SynthCTI on two publicly available CTI datasets, CTI-to-MITRE and TRAM, using models with different capacities. Incorporating synthetic data leads to consistent macro-F1 improvements: for example, ALBERT improves from 0.35 to 0.52 (48.6 % relative gain), and SecureBERT from 0.4412 to 0.6558. Smaller models augmented with SynthCTI outperform larger models trained without augmentation, demonstrating the value of data generation for CTI classification. These results confirm our hypothesis and highlight the practicality of enabling smaller organizations to adopt advanced CTI analytics without requiring high-performance computing infrastructure. Álvaro Ruiz-Ródenas, Jaime Pujante Sáez, Daniel García-Algora, Mario Rodríguez Béjar, Jorge Blasco Alís, José Luis Hernández-Ramos |
Future Gener. Comput. Syst. | 5 |
| 2025 | CloudFlow: Identifying Security-sensitive Data Flows in Serverless Applications
Giuseppe Raffa, Jorge Blasco Alís, Dan O'Keeffe, Santanu Kumar Dash 0001 |
USENIX Security Symposium | 2 |
| 2025 | Expert Insights into Advanced Persistent Threats: Analysis, Attribution, and Challenges
Aakanksha Saha, James Mattei, Jorge Blasco Alís, Lorenzo Cavallaro, Daniel Votipka, Martina Lindorfer |
USENIX Security Symposium | 3 |
| 2024 | DocFlow: Extracting Taint Specifications from Software DocumentationabstractSecurity practitioners routinely use static analysis to detect security problems and privacy violations in Android apps. The soundness of these analyses depends on how the platform is modelled and the list of sensitive methods. Collecting these methods often becomes impractical given the number of methods available, the pace at which the Android platform is updated, and the proprietary libraries Google releases on each new version. Despite the constant evolution of the Android platform, app developers cope with all these new features thanks to the documentation that comes with each new Android release. In this work, we take advantage of the rich documentation provided by platforms like Android and propose DocFlow, a framework to generate taint specifications for a platform, directly from its documentation. DocFlow models the semantics of API methods using their documentation to detect sensitive methods (sources and sinks) and assigns them semantic labels. Our approach does not require access to source code, enabling the analysis of proprietary libraries for which the code is unavailable. We evaluate DocFlow using Android platform packages and closed-source Google Play Services libraries. Our results show that our framework detects sensitive methods with high precision, adapts to new API versions, and can be easily extended to detect other method types. Our approach provides evidence that Android documentation encodes rich semantic information to categorise sensitive methods, removing the need to analyse source code or perform feature extraction. Marcos Tileria, Jorge Blasco Alís, Santanu Kumar Dash 0001 |
ICSE | 2 |
| 2024 | ADAPT it! Automating APT Campaign and Group Attribution by Leveraging and Linking Heterogeneous FilesabstractRecent years have witnessed a surge in the growth of Advanced Persistent Threats (APTs), with significant challenges to the security landscape, affecting industry, governance, and democracy. The ever-growing number of actors and the complexity of their campaigns have made it difficult for defenders to track and attribute these malicious activities effectively. Traditionally, researchers relied on threat intelligence to track APTs. However, this often led to fragmented information, delays in connecting campaigns with specific threat groups, and misattribution. Aakanksha Saha, Jorge Blasco Alís, Lorenzo Cavallaro, Martina Lindorfer |
RAID | 2 |
| 2024 | Towards Inter-Service Data Flow Analysis of Serverless ApplicationsabstractThe recent advent of serverless applications has created a need for static analysis tools to analyse them. However, the event-driven architecture of serverless applications, along with the black-box nature of the services they invoke, make static analysis challenging. In this work, we propose a novel approach to statically analysing serverless applications, with a focus on the identification of data flows that can lead to code injection and information leakage. To reach our goal, we first design a new suite of microbenchmarks, which we publicly release. The microbenchmarks are based on documented serverless-specific vulnerabilities and the characterization of an existing dataset. We then introduce our static analysis approach and show how it can factor in the effect of platform services and eventtriggered code execution by extracting relevant information from both infrastructure and application code. This information is used to obtain a synchronous equivalent of the underlying asynchronous system, which can be inspected with a general-purpose static analysis tool. Preliminary evaluation results using a prototype implementation of our approach and the microbenchmark suite confirm the potential of our analysis technique. Giuseppe Raffa, Jorge Blasco Alís, Dan O'Keeffe, Santanu Kumar Dash 0001 |
SANER | 2 |
| 2023 | Uncovering Vulnerabilities of Bluetooth Low Energy IoT from Companion Mobile Apps with Ble-GuuideabstractIncreasingly, with embedded intelligence and control, IoT devices are being adopted faster than ever. However, the IoT landscape and its security implications are not yet fully understood. This paper seeks to shed light on this by focusing on a particular type of IoT devices, namely the ones using Bluetooth Low Energy (BLE). Our contributions are two-fold: First, we present Ble-Guuide, a framework for performing mobile app-centric security issue identification. We exploit Universally Unique Identifiers (UUIDs), which underpin data transmissions in BLE, to glean rich information regarding device functionality and the underlying security issues. We combine this with information from app descriptions and BLE libraries, to identify the corresponding security vulnerabilities in BLE devices and determine the security or privacy impact they could have depending on the device functionality. Second, we present a large-scale analysis of 17,243 free, BLE-enabled Android APKs, systematically crawled from the official Google Play store. By applying Ble-Guuide to this dataset, we uncover that more than 70% of these APKs contain at least one security vulnerability. We also obtain insights into the identified security vulnerabilities and their impact. Pallavi Sivakumaran, Chaoshun Zuo, Zhiqiang Lin 0001, Jorge Blasco Alís |
AsiaCCS | 4 |
| 2022 | PeriScope: Comprehensive Vulnerability Analysis of Mobile App-defined Bluetooth PeripheralsabstractMany IoT devices today talk to each other via Bluetooth Low Energy (BLE), a wireless communication technology often used to exchange data between a paired central and peripheral. These peripheral devices include not only firmware-defined bare-metal peripherals but also mobile application defined peripherals where a mobile app turns a smartphone into a peripheral instead of their usual central role. However, this role reversal increases the attack surface and brings vulnerabilities in bare-metal Bluetooth peripherals to mobile apps where relevant security and privacy have not been well studied. To fill this knowledge gap, this paper presents PeriScope, an automated tool to unveil the security and privacy vulnerabilities at the link layer of app-defined Bluetooth peripherals in the procedures of broadcasting, pairing, and communication by systematically analyzing their companion mobile apps. PeriScope has analyzed 1,160 Bluetooth peripheral apps from Google Play and identified 69.13% of them that broadcast device or personal identifiable information in cleartext, and, in addition, there are 95% pieces of data managed by these apps (e.g., personal health data and digital keys to unlock doors) to exchange with connected devices can be accessed without authentication. Finally, a set of guidelines for secure app-defined Bluetooth peripherals development is also provided. Qingchuan Zhao, Chaoshun Zuo, Jorge Blasco Alís, Zhiqiang Lin 0001 |
AsiaCCS | 3 |
| 2022 | Towards Improving Code Stylometry Analysis in Underground ForumsabstractAbstract Code Stylometry has emerged as a powerful mechanism to identify programmers. While there have been significant advances in the field, existing mechanisms underperform in challenging domains. One such domain is studying the provenance of code shared in underground forums, where code posts tend to have small or incomplete source code fragments. This paper proposes a method designed to deal with the idiosyncrasies of code snippets shared in these forums. Our system fuses a forum-specific learning pipeline with Conformal Prediction to generate predictions with precise confidence levels as a novelty. We see that identifying unreliable code snippets is paramount to generate high-accuracy predictions, and this is a task where traditional learning settings fail. Overall, our method performs as twice as well as the state-of-the-art in a constrained setting with a large number of authors (i.e., 100). When dealing with a smaller number of authors (i.e., 20), it performs at high accuracy (89%). We also evaluate our work on an open-world assumption and see that our method is more effective at retaining samples. Michal Tereszkowski-Kaminski, Sergio Pastrana, Jorge Blasco Alís, Guillermo Suarez-Tangil |
Proc. Priv. Enhancing Technol. | 3 |
| 2022 | Watch Over Your TV: A Security and Privacy Analysis of the Android TV EcosystemabstractThe rapid adoption of Smart TVs has resulted in them becoming another app-based ecosystem. In this context, Android TV is one of the major players as it is widely available across multiple TV manufacturers and has a high integration with other Google products. Yet, the Android TV ecosystem has remained unexplored. This paper presents a deep analysis of the Android TV ecosystem using a large dataset of TV apps. We give an insight into the stakeholder ecosystem, including developers, streaming services, and thirdparty libraries. We analyze the behavior of TV apps in terms of sensitive data collection and communication with other devices using a pipeline of static analysis tools, network traffic collection, and verification via manual analysis. We compare the mobile and TV version of popular streaming apps and found a significant degradation of TV apps in terms of quality and different data collection practices. Our study shows that most TV apps present potentially harmful behaviors, and in most cases, these can be attributed to tracking and advertisement services. We found a prevalence of static identifiers for tracking purposes despite this not being the recommendation. This finding suggests that Google’s new policies limiting advertising identifiers will not have a tangible effect on the TV ecosystem. Marcos Tileria, Jorge Blasco Alís |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | argXtract: Deriving IoT Security Configurations via Automated Static Analysis of Stripped ARM Cortex-M BinariesabstractRecent high-profile attacks on the Internet of Things (IoT) have brought to the forefront the vulnerabilities in “smart” devices, and have revealed poor device configuration to be the root cause in many cases. This has resulted in IoT technologies and devices being subjected to numerous security analyses. For the most part, automated analyses have been confined to IoT hub or gateway devices, which tend to feature traditional operating systems such as Linux or VxWorks. However, most IoT peripherals, by their very nature of being resource-constrained, lacking traditional operating systems, implementing a wide variety of communication technologies, and (increasingly) featuring the ARM Cortex-M architecture, have only been the subject of smaller-scale analyses, typically confined to a certain class or brand of device. We bridge this gap with argXtract, a framework for performing automated static analysis of stripped Cortex-M binaries, to enable bulk extraction of security-relevant configuration data. Through a case study of 200+ Bluetooth Low Energy binaries targeting Nordic Semiconductor chipsets, as well as smaller studies against STMicroelectronics BlueNRG binaries and Nordic ANT binaries, argXtract has discovered widespread security and privacy issues in IoT, including minimal or no protection for data, weakened pairing mechanisms, and potential for device and user tracking. Pallavi Sivakumaran, Jorge Blasco Alís |
ACSAC | 2 |
| 2021 | Mesh Messaging in Large-Scale Protests: Breaking Bridgefy
Martin R. Albrecht, Jorge Blasco Alís, Rikke Bjerg Jensen, Lenka Mareková |
CT-RSA | 2 |
| 2021 | Detecting Video-Game Injectors Exchanged in Game Cheating Communities
Panicos Karkallis, Jorge Blasco Alís, Guillermo Suarez-Tangil, Sergio Pastrana |
ESORICS (1) | 2 |
| 2021 | Who's Accessing My Data? Application-Level Access Control for Bluetooth Low Energy
Pallavi Sivakumaran, Jorge Blasco Alís |
SecureComm (2) | 2 |
| 2021 | Collective Information Security in Large-Scale Urban Protests: the Case of Hong Kong
Martin R. Albrecht, Jorge Blasco Alís, Rikke Bjerg Jensen, Lenka Mareková |
USENIX Security Symposium | 2 |
| 2020 | WearFlow: Expanding Information Flow Analysis To Companion Apps in Wear OS
Marcos Tileria, Jorge Blasco Alís, Guillermo Suarez-Tangil |
RAID | 2 |
| 2020 | How private is your period?: A systematic analysis of menstrual app privacy policiesabstractAbstract Menstruapps are mobile applications that can track a user’s reproductive cycle, sex life and health in order to provide them with algorithmically derived insights into their body. These apps are now hugely popular, with the most favoured boasting over 100 million downloads. In this study, we investigate the privacy practices of a set of 30 Android menstruapps, a set which accounts for nearly 200 million downloads.We measured how the apps present information and behave on a number of privacy related topics, such as the complexity of the language used, the information collected by them, the involvement of third parties and how they describe user rights. Our results show that while common pieces of personal data such as name, email, etc. are treated appropriately by most applications, reproductive-related data is not covered by the privacy policies and in most cases, completely disregarded, even when it is required for the apps to work. We have informed app developers of our findings and have tried to engage them in dialogue around improving their privacy practices. Laura Shipp, Jorge Blasco Alís |
Proc. Priv. Enhancing Technol. | 2 |
| 2019 | A Study of the Feasibility of Co-located App Attacks against BLE and a Large-Scale Analysis of the Current Application-Layer Security Landscape
Pallavi Sivakumaran, Jorge Blasco Alís |
USENIX Security Symposium | 2 |
| 2018 | A Low Energy Profile: Analysing Characteristic Security on BLE PeripheralsabstractBluetooth Low Energy is a ubiquitous technology, with applications in the fitness, healthcare and smart home sectors, to name but a few. In this paper, we present an open-source Profiler for classifying the protection level of data residing on a BLE device. Preliminary results obtained by executing the tool against several devices show that some BLE devices allow unauthenticated reads and writes from third party devices. This could expose them to a number of attacks and compromise the privacy, or even the physical safety, of the device owner. Pallavi Sivakumaran, Jorge Blasco Alís |
CODASPY | 2 |
| 2018 | Detection of app collusion potential using logic programming
Jorge Blasco Alís, Thomas M. Chen, Igor Muttik, Markus Roggenbach |
J. Netw. Comput. Appl. | 1 |
| 2015 | Hindering data theft with encrypted data trees
Jorge Blasco Alís, Juan Tapiador, Pedro Peris-Lopez, Guillermo Suarez-Tangil |
J. Syst. Softw. | 1 |
| 2014 | Dendroid: A text mining approach to analyzing and classifying code structures in Android malware families
Guillermo Suarez-Tangil, Juan Tapiador, Pedro Peris-Lopez, Jorge Blasco Alís |
Expert Syst. Appl. | 4 |
| 2013 | WEVAN - A mechanism for evidence creation and verification in VANETs
José María de Fuentes, Lorena González-Manzano, Ana I. González-Tablas, Jorge Blasco Alís |
J. Syst. Archit. | 4 |
| 2012 | Bypassing information leakage protection with trusted applications
Jorge Blasco Alís, Julio César Hernández Castro, Juan Tapiador, Arturo Ribagorda |
Comput. Secur. | 1 |
| 2012 | A framework for avoiding steganography usage over HTTP
Jorge Blasco Alís, Julio César Hernández Castro, José María de Fuentes, Benjamín Ramos |
J. Netw. Comput. Appl. | 1 |
| 2011 | Analysis of update delays in signature-based network intrusion detection systems
Hugo Gascon, Agustín Orfila, Jorge Blasco Alís |
Comput. Secur. | 3 |
| 2010 | Improving Network Intrusion Detection by Means of Domain-Aware Genetic ProgrammingabstractOne of the central areas in network intrusion detection is how to build effective systems that are able to distinguish normal from intrusive traffic. In this paper we explore the use of Genetic Programming (GP) for such a purpose. Although GP has already been studied for this task, the inner features of network intrusion detection have been systematically ignored. To avoid the blind use of GP shown in previous research, we guide the search by means of a fitness function based on recent advances on IDS evaluation. For the experimental work we use a well-known dataset (i.e. KDD-99) that has become a standard to compare research although its drawbacks. Results clearly show that an intelligent use of GP achieves systems that are comparable (and even better in realistic conditions) to top state-of-the-art proposals in terms of effectiveness, improving them in efficiency and simplicity. Jorge Blasco Alís, Agustín Orfila, Arturo Ribagorda |
ARES | 1 |
| 2009 | Steganalysis of Hydan
Jorge Blasco Alís, Julio César Hernández Castro, Juan Tapiador, Arturo Ribagorda, Miguel A. Orellana-Quiros |
SEC | 1 |
| 2008 | CSteg: Talking in C Code - Steganography of C Source Code in Text
Jorge Blasco Alís, Julio César Hernández Castro, Juan Tapiador, Arturo Ribagorda |
SECRYPT | 1 |