VLDB 2026 Research / reviewers in the wild / expert
Marta Moure-Garrido
dblp:323/2801
· DBLP profile ↗
8ranked-venue papers
5as first author
8since 2021 · last 2026
0000-0001-6068-6233ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 4 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GUARDIAN: Gaze User Authentication and Reference Detection for Integrity Analysis on Netflix
Marta Moure-Garrido, Melanie Heck, Christian Becker 0001, Celeste Campo, Carlos García-Rubio |
ETRA | 1 |
| 2026 | CO-DEFEND: Continuous decentralized federated learning for secure DoH-based threat detectionabstractThe use of DNS over HTTPS (DoH) tunneling by an attacker to hide malicious activity within encrypted DNS traffic poses a serious threat to network security, as it allows malicious actors to bypass traditional monitoring and intrusion detection systems while evading detection by conventional traffic analysis techniques. Machine Learning (ML) techniques can be used to detect DoH tunnels; however, their effectiveness relies on large datasets containing both benign and malicious traffic. Sharing such datasets across entities is challenging due to privacy concerns. In this work, we propose CO-DEFEND (Continuous Decentralized Federated Learning for Secure DoH-Based Threat Detection), a Decentralized Federated Learning (DFL) framework that enables multiple entities to collaboratively train a classification machine learning model for DoH threat detection while preserving data privacy, enhancing scalability and resilience against single points of failure. The proposed DFL framework provides a realistic implementation for DoH threat detection, enabling multiple entities to train their local models online with incoming DoH flows in real-time batches as they are processed – an approach that fits naturally within modern Internet architectures. This framework adapts four classical machine learning algorithms, Support Vector Machines (SVM), Logistic Regression (LR), Decision Trees (DT), and Random Forest (RF), for federated scenarios and efficient training. In addition, a key methodological feature of CO-DEFEND is the use of DT and RF as model selection rather than aggregation mechanisms, allowing each participant to retain interpretable and locally optimal decision structures while benefiting from collective updates. We compare our proposed method by using the dataset CIRA-CIC-DoHBrw-2020 with existing machine learning approaches, including more computationally complex alternatives such as neural networks, to demonstrate its effectiveness in detecting malicious DoH tunnels while improving scalability and computational efficiency. Diego Cajaraville-Aboy, Marta Moure-Garrido, Carlos Beis-Penedo, Carlos García-Rubio, Rebeca P. Díaz Redondo, Celeste Campo, Ana Fernández Vilas, Manuel Fernández-Veiga |
Comput. Networks | 2 |
| 2026 | The persistent vulnerability: Characterizing metadata leakage in DNS over QUICabstractWhile DNS over QUIC (DoQ) integrates encryption and transport layer optimizations to ensure confidentiality, the protocol remains susceptible to sophisticated traffic analysis. This paper characterizes the structural metadata leakage of DoQ by evaluating the geographical invariance of traffic signatures across a multi vantage point experimental framework comprising several global nodes. By leveraging Explainable AI (XAI) and systematic feature ablation, we deconstruct the underlying deterministic patterns (specifically temporal mass distribution and burst size sequences) that facilitate high accuracy website fingerprinting. Our findings demonstrate a critical early identification inflection point where domain identification becomes feasible within the initial 200 ms of a connection, effectively bypassing full session establishment. These results quantify the persistent vulnerabilities inherent in the protocol handshake and initial query exchange, remaining consistent across disparate network latencies and regional artifacts. Finally, we discuss the implications of this leakage for privacy preserving DNS architectures and provide a technical benchmark for the development of next generation zero delay traffic obfuscation defenses. Marta Moure-Garrido, Carlos García-Rubio, Celeste Campo |
Comput. Networks | 1 |
| 2025 | Enhancing Privacy in DNS Communications with Energy-Aware MethodologiesabstractThe proliferation of mobile devices and permanent Internet connectivity generates massive data flows that carry personal information and can compromise user privacy. This doctoral research focuses on analyzing privacy vulnerabilities in the Domain Name System (DNS), a fundamental protocol for Internet communications, and its encrypted variants. The research aims to develop novel methodologies that enhance DNS privacy protection while optimizing energy consumption. Initial contributions include the proposal of DNS query forgery techniques as privacy-enhancing mechanisms and the development of PARROT, a reproducible traffic capture system for mobile app analysis. The work demonstrates protocol evolution trends and validates privacy protection strategies through experimental evaluation using synthetic datasets. Future research will focus on energy-aware optimization of DNS privacy solutions and the development of practical implementations for mobile environments. Andrea Jimenez-Berenguel, Celeste Campo, Marta Moure-Garrido |
MSWiM | 3 |
| 2025 | Fingerprinting Encrypted DNS: Exploiting Metadata Leakage in DNS over QUICabstractThe growing adoption of HTTP/3 and its underlying transport protocol, Quick UDP Internet Connections (QUIC), represents a major step forward in Internet communications, improving performance, latency, congestion control, and encryption. Domain Name Server (DNS) over QUIC (DoQ) has emerged to enhance DNS confidentiality and performance, but remains vulnerable to website fingerprinting (WF) attacks, which exploit observable traffic patterns, even in the presence of encryption. In this study, we conduct a detailed analysis into the vulnerability of the DoQ protocol to WF attacks, examining how encrypted DNS traffic can still leak identifiable patterns that adversaries may exploit to infer users’ web activity. We implement a comprehensive feature extraction framework adapted to encrypted DNS traffic. This approach enables accurate classification using a real-world dataset. We apply explainable Artificial Intelligence (XAI) to identify which features drive model predictions, offering new insights into the sources of metadata leakage. The findings of the present study reinforce the efficacy of fingerprinting attacks on DoQ traffic, highlighting the persistent nature of these vulnerabilities despite DoQ’s encryption mechanisms. Consequently, the development of effective fingerprinting mitigation strategies in encrypted environments like DoQ continues to pose a critical challenge for protecting user privacy, underscoring the need for robust mitigation strategies to safeguard user privacy. Marta Moure-Garrido, Celeste Campo, Carlos García-Rubio |
MSWiM | 1 |
| 2024 | Real-Time Analysis of Encrypted DNS Traffic for Threat DetectionabstractDomain Name System (DNS) tunneling is a well-known cyber-attack that allows data exfiltration - the attackers exploit this tunnel to extract sensitive information from the system. Advanced Persistent Threat (APT) attackers encapsulate malicious traffic in a DNS connection to elude security mechanisms such as Intrusion Detection System (IDS). Although different techniques have been implemented to detect these targeted attacks, their rise induces a threat to Cyber-Physical Systems (CPS). The DNS over HTTPS (DoH) tunnel detection is a challenge because the encrypted data prevents an analysis of DNS traffic content. In this paper, we present a novel detection system that identifies malicious DoH tunnels in real time. We study the normal traffic pattern and based on that, we define a profile. The objective of this system is to detect malicious activity on the system as early as possible through a lightweight packet by packet analysis based on a real-time IDS classifier. This system is evaluated on three available data sets and the results obtained are compared with a machine learning technique. We demonstrate that the identification of anomalous activity, in particular DoH tunnels, is possible by analyzing different traffic features. Marta Moure-Garrido, Sajal K. Das 0001, Celeste Campo, Carlos García-Rubio |
ICC | 1 |
| 2024 | Inferring mobile applications usage from DNS trafficabstractIn the digital era, our lives are intrinsically linked to the daily use of mobile applications. As a consequence, we generate and transmit a large amount of personal data that puts our privacy in danger. Despite having encrypted communications, the DNS traffic is usually not encrypted, and it is possible to extract valuable information from the traffic generated by mobile applications. This study focuses on the analysis of the DNS traffic behavior found in mobile application traces, developing a methodology capable of identifying mobile applications based on the domains they query. With this methodology, we were able to identify apps with 98% accuracy. Furthermore, we have validated the effectiveness of the characterization obtained with one dataset by identifying traces from other independent datasets. The evaluation showed that the methodology provides successful results in identifying mobile applications. Celeste Campo, Carlos García-Rubio, Andrea Jimenez-Berenguel, Marta Moure-Garrido, Florina Almenárez, Daniel Díaz Sánchez |
Ad Hoc Networks | 4 |
| 2023 | Real time detection of malicious DoH traffic using statistical analysisabstractThe DNS protocol plays a fundamental role in the operation of ubiquitous networks. All devices connected to these networks need DNS to work, both for traditional domain name to IP address translation, and for more advanced services such as resource discovery. DNS over HTTPS (DoH) solves certain security problems present in the DNS protocol. However, malicious DNS tunnels, a covert way of encapsulating malicious traffic in a DNS connection, are difficult to detect because the encrypted data prevents performing an analysis of the content of the DNS traffic. In this study, we introduce a real-time system for detecting malicious DoH tunnels, which is based on analyzing DoH traffic using statistical methods. Our research demonstrates that it is feasible to identify in real-time malicious traffic by analyzing specific parameters extracted from DoH traffic. In addition, we conducted statistical analysis to identify the most significant features that distinguish malicious traffic from benign traffic. Using the selected features, we achieved satisfactory results in classifying DoH traffic as either benign or malicious. Marta Moure-Garrido, Celeste Campo, Carlos García-Rubio |
Comput. Networks | 1 |