VLDB 2026 Research / reviewers in the wild / expert
Manuel Gil Pérez
dblp:36/6495
· DBLP profile ↗
37ranked-venue papers
4as first author
16since 2021 · last 2026
0000-0002-7768-9665ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 1 first-author · 7 since 2021Security and privacy · 6 · 3 since 2021Artificial intelligence and machine learning · 5 · 3 since 2021Software engineering, systems software and programming languages · 3 · 1 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Reactive cyber deception: Stealth-based adaptive redirection to on-demand honeypots with AI-driven data generationabstractCybersecurity is evolving rapidly, incorporating paradigms such as Cyber Deception (CYDEC) and Moving Target Defense (MTD) to counter sophisticated attacks. CYDEC misleads adversaries by diverting their actions into controlled environments where they unknowingly interact with decoy assets. This work introduces a deception mechanism based on stealthy TCP redirection to dynamically instantiated honeypots. Unlike static decoys, the system creates a honey server on-demand that replicates the victim asset in real time. To enhance credibility, the replica is enriched with fake but coherent data generated by a Large Language Model (LLM), producing realistic documents, logs, or configurations tailored to the compromised pillar, that is, confidentiality, integrity, or availability. The architecture builds on Software-Defined Networking (SDN), enabling flexible deployment and adaptive deception at scale. The SDN Controller manages redirection and cloning while preserving TCP session continuity through sequence-number manipulation, making the diversion virtually undetectable. Experiments validated the approach in diverse environments. Results show negligible latency overheads, even under encrypted protocols, seamless honeypot instantiation, and highly plausible LLM-generated honeydata that deceives Attackers while enriching threat intelligence. Deployment on resource-constrained hardware such as Raspberry Pi demonstrates feasibility for IoT and embedded contexts. Overall, combining SDN and LLM technologies enables a scalable, adaptive, and robust CYDEC-based defense capable of deceiving adversaries in real time while strengthening cyber threat intelligence. Pedro Beltrán López, Manuel Gil Pérez, Emmanouil Vasilomanolakis, Pantaleone Nespoli |
Comput. Networks | 2 |
| 2026 | RepuNet: A Reputation System for Mitigating Malicious Clients in DFLabstractDecentralized Federated Learning (DFL) enables nodes to collaboratively train models without a central server, introducing new vulnerabilities since each node independently selects peers for model aggregation. Malicious nodes may exploit this autonomy by sending corrupted models (model poisoning), delaying model submissions (delay attack), or flooding the network with excessive messages, negatively affecting system performance. Existing solutions often rely on rigid configurations or additional infrastructure, such as blockchains, which can incur computational overhead, introduce scalability issues, or limit adaptability. To overcome these limitations, this paper proposes RepuNet, a decentralized reputation system that categorizes threats in DFL and dynamically evaluates node behavior using metrics like model similarity, parameter changes, message latency, and communication volume. Node influence in model aggregation is adjusted based on each node’s reputation score. RepuNet was integrated into the Nebula platform and experimentally evaluated with MNIST and CIFAR-10 datasets under non-IID distributions, using federations of up to 25 nodes in both fully connected and random topologies. The evaluation considers different attack intensities, frequencies, and activation intervals, and includes comparisons with Byzantine-resilient aggregation mechanisms (Krum and Trimmed Mean), stronger structured poisoning strategies (Signed Neuron Remapping and GLL Neuro Inversion), as well as an ablation study of the exclusion threshold and a communication overhead analysis. Results demonstrate that RepuNet effectively detects and mitigates malicious behavior, achieving F1 scores above 95% on MNIST and approximately 76% on CIFAR-10. These outcomes highlight the adaptability, robustness, and practical potential of RepuNet for mitigating threats in decentralized environments. Isaac Marroqui Penalva, Enrique Tomás Martínez Beltrán, Manuel Gil Pérez, Alberto Huertas Celdrán |
Comput. Networks | 3 |
| 2026 | Trust-based intent management for 6G: A level of trust assessment functionabstract• Trust as a new intent for orchestrating the future 6G networks. • Continuous network assurance for cloud continuum services. • The Level of Trust framework monitors and double checks trust level agreements. • Trust-oriented ontology for Cloud Continuum and intent-based scenarios. Intent-Based Networking (IBN) has gained prominence from both industry and research communities for boosting network automation and reducing network complexity in multi-stakeholder scenarios. IBN helps service and network providers understand and translate high-level business goals by escaping from technical details. Nevertheless, the rapid evolution of service requirements in dynamic multi-stakeholder environments needs to be considered by suppliers in order to meet the continuous demands of their customers. In this regard, trustworthiness is recognized as a key feature to assess reliability, compliance, and user perception of 6G services. In that spirit, this article aims to pave the way for encompassing trustworthiness, or Level of Trust (LoT), as a new intent to properly deliver service provisioning in 6G solutions. In particular, the LoT framework introduces a set of functionalities to guarantee a proper definition of requirements (Trust Level Agreements, TLAs), their interpretation, translation, consistency, and assurance during an ongoing relationship. To this end, this article presents a trust-based intent management approach with an ad-hoc interpreter that is, in turn, powered by a trust-based ontology for Cloud Continuum scenarios. Besides, a Level of Trust Assessment Function (LoTAF) is designed to monitor and report updates and events regarding LoT continuously. Such a monitoring engine follows the IETF basics of service assurance for IBN architecture. Last but not least, experiments in a collaborative robot warehouse scenario showcase that LoTAF enables workload allocation to the most trustworthy compute nodes, improving confidence in service orchestration, while introducing negligible overheads (1.40 % RAM, 5.01 % CPU, and 0.1069s latency). José María Jorquera Valero, Alfonso Serrano Gil, Javier Paredes Serrano, Ignacio Dominguez Martinez-Casanueva, Lucía Cabanillas Rodríguez, Riccardo Nicolicchia, Diego R. López, Manuel Gil Pérez, Vasiliki Lamprousi, Sokratis Barmpounakis, Panagiotis Demestichas |
Comput. Networks | 8 |
| 2024 | Unlocking the Potential of Knowledge Graphs: A Cyber Defense Ontology for a Knowledge Representation and Reasoning SystemabstractIn today’s dynamic and complex warfare landscape, characterized by the convergence of traditional and emerging threats, the significance of cybersecurity in shaping modern conflicts cannot be overstated. Such trend presents a challenging paradigm shift in how military organizations approach mosaic warfare in the digital age since new attack vectors and targets appear in their landscapes. In this vein, it is pivotal for military teams to have a clear and concise roadmap for cybersecurity incidents linked to potential mosaic warfare. This manuscript introduces a novel approach to bolstering mosaic warfare strategies by integrating an advanced Knowledge Representation and Reasoning system and a tailored ontology. Motivated by the critical role of cybersecurity in contemporary warfare, the proposed system aims to enhance situational awareness, decision-making capabilities, and operational effectiveness in the face of evolving cyber threats. In this sense, this manuscript entails a new ontology that not only covers the cybersecurity realm but also introduces key concepts related to strategic and operational military levels at the same time. The ad-hoc ontology is also compared against other well-known ones, such as MITRE, NATO, or UCO approaches and manifests a significant performance by employing standardized quality metrics for ontologies. Lastly, a realistic mosaic warfare scenario is contextualized to demonstrate the deployment of the proposed system and how it can properly represent all information gathered from heterogeneous data sources. José María Jorquera Valero, Antonio López Martínez, Pedro Miguel Sánchez Sánchez, Daniel Navarro-Martínez, Rodrigo Varas López, Javier Ignacio Rojo Lacal, Antonio Lopez Vivar, Marco Antonio Sotelo Monge, Manuel Gil Pérez, Gregorio Martínez Pérez |
ARES | 9 |
| 2024 | Corrigendum to "Fedstellar: A platform for decentralized federated learning" [Expert Syst. Appl. 242 (2024) 122861]
Enrique Tomás Martínez Beltrán, Ángel Luis Perales Gómez, Chao Feng 0001, Pedro Miguel Sánchez Sánchez, Pedro Guijas Bravo, Sergio López Bernal, Gérôme Bovet, Manuel Gil Pérez, Gregorio Martínez Pérez, Alberto Huertas Celdrán |
Expert Syst. Appl. | 8 |
| 2024 | Fedstellar: A Platform for Decentralized Federated LearningabstractIn 2016, Google proposed Federated Learning (FL) as a novel paradigm to train Machine Learning (ML) models across the participants of a federation while preserving data privacy. Since its birth, Centralized FL (CFL) has been the most used approach, where a central entity aggregates participants’ models to create a global one. However, CFL presents limitations such as communication bottlenecks, single point of failure, and reliance on a central server. Decentralized Federated Learning (DFL) addresses these issues by enabling decentralized model aggregation and minimizing dependency on a central entity. Despite these advances, current platforms training DFL models struggle with key issues such as managing heterogeneous federation network topologies, adapting the FL process to virtualized or physical deployments, and using a limited number of metrics to evaluate different federation scenarios for efficient implementation. To overcome these challenges, this paper presents Fedstellar, a novel platform designed to train FL models in a decentralized, semi-decentralized, and centralized fashion across diverse federations of physical or virtualized devices. Fedstellar allows users to create federations by customizing parameters like the number and type of devices training FL models, the network topology connecting them, the machine and deep learning algorithms, or the datasets of each participant, among others. Additionally, it offers real-time monitoring of model and network performance. The Fedstellar implementation encompasses a web application with an interactive graphical interface, a controller for deploying federations of nodes using physical or virtual devices, and a core deployed on each device, which provides the logic needed to train, aggregate, and communicate in the network. The effectiveness of the platform has been demonstrated in two scenarios: a physical deployment involving single-board devices such as Raspberry Pis for detecting cyberattacks and a virtualized deployment comparing various FL approaches in a controlled environment using MNIST and CIFAR-10 datasets. In both scenarios, Fedstellar demonstrated consistent performance and adaptability, achieving F1scores of 91%, 98%, and 91.2% using DFL for detecting cyberattacks and classifying MNIST and CIFAR-10, respectively, reducing training time by 32% compared to centralized approaches. Enrique Tomás Martínez Beltrán, Ángel Luis Perales Gómez, Chao Feng 0001, Pedro Miguel Sánchez Sánchez, Sergio López Bernal, Gérôme Bovet, Manuel Gil Pérez, Gregorio Martínez Pérez, Alberto Huertas Celdrán |
Expert Syst. Appl. | 7 |
| 2024 | SLA-Driven Trust and Reputation Management Framework for 5G Distributed Service MarketplacesabstractThe fifth generation (5G) of mobile telecommunications is characterized by massive growth in the number of stakeholders, interconnected devices, and available services distributed under different administrative domains. Distributed marketplaces aim at facilitating stakeholders in the quest and hiring of third party resources and services. Establishing trustworthiness in such an open ecosystem is a cornerstone for the final deployment of these marketplaces in 5G networks and beyond. Hence, building trust management systems that ensure the selection of reliable parties or assets in 5G distributed marketplaces is essential. Thus, a reputation-based trust management framework is proposed to analyze stakeholder behavior patterns and predict trust scores to establish trustworthy relationships across domains. Furthermore, an Service Level Agreement (SLA)-driven reward and punishment mechanism is designed and developed on top of the reputation-based trust framework. Such a mechanism enables continuously adapting trust scores by gathering breach predictions, breach detections, and SLA violations in real time. Furthermore, an edge-based use case is presented to contextualize our reputation-based framework in a tangible enforcement scenario. In conclusion, three experiments were conducted on real-life testbeds demonstrating that our framework fairly distinguishes bad-mouthing attacks with 67% accuracy, when 50% recommenders are corrupted, and is resilient to continuous misbehavior bursts. José María Jorquera Valero, Vasileios Theodorou, Manuel Gil Pérez, Gregorio Martínez Pérez |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Mitigating communications threats in decentralized federated learning through moving target defenseabstractAbstract The rise of Decentralized Federated Learning (DFL) has enabled the training of machine learning models across federated participants, fostering decentralized model aggregation and reducing dependence on a server. However, this approach introduces unique communication security challenges that have yet to be thoroughly addressed in the literature. These challenges primarily originate from the decentralized nature of the aggregation process, the varied roles and responsibilities of the participants, and the absence of a central authority to oversee and mitigate threats. Addressing these challenges, this paper first delineates a comprehensive threat model focused on DFL communications. In response to these identified risks, this work introduces a security module to counter communication-based attacks for DFL platforms. The module combines security techniques such as symmetric and asymmetric encryption with Moving Target Defense (MTD) techniques, including random neighbor selection and IP/port switching. The security module is implemented in a DFL platform, Fedstellar, allowing the deployment and monitoring of the federation. A DFL scenario with physical and virtual deployments have been executed, encompassing three security configurations: (i) a baseline without security, (ii) an encrypted configuration, and (iii) a configuration integrating both encryption and MTD techniques. The effectiveness of the security module is validated through experiments with the MNIST dataset and eclipse attacks.The results showed an average F1 score of 95%, with the most secure configuration resulting in CPU usage peaking at 68% (± 9%) in virtual deployments and network traffic reaching 480.8 MB (± 18 MB), effectively mitigating risks associated with eavesdropping or eclipse attacks. Enrique Tomás Martínez Beltrán, Pedro Miguel Sánchez Sánchez, Sergio López Bernal, Gérôme Bovet, Manuel Gil Pérez, Gregorio Martínez Pérez, Alberto Huertas Celdrán |
Wirel. Networks | 5 |
| 2023 | Approach to harmonisation of technological solutions, operating procedures, preparedness and cross-sectorial collaboration opportunities for first aid response in cross-border mass-casualty incidentsabstractThis paper focuses on identifying possible approaches to harmonising technological solutions, operative procedures, preparedness and cross-sectorial collaboration in the case of cross-border Mass Casualty Incidents (MCI). It presents some of the results obtained in the framework of the VALKYRIES project (Harmonisation and Pre-Standardization of Equipment, Training and Tactical Coordinated Procedures for First Aid Vehicles Deployment on European Multi-Victim Disasters). The first part of the paper presents and analyses the current situation concerning the technological solutions in support of first aid responders, the usual operative procedures and protocols in place, the existing Education and Training (E&T) courses, and the status of cross-border and cross-sectorial cooperation. The second part of the paper summarises identified capability gaps and needs of the first responders (e.g., medical emergency services, firefighters, civil protection authorities, police, military units, and local authorities) in the technologies domain, operative procedures, preparedness and collaboration for effective implementation of their tasks in a cross-border MCI. The third part summarises the prioritised harmonisation opportunities in the above-discussed technological, procedural, E&T and collaboration domains. Finally, some conclusions and next steps are formulated. Yantsislav Yanakiev, Sergio López Bernal, Alberto Montarelo Navajo, Nikolai Stoianov, Manuel Gil Pérez, Carmen Curto Martin |
ARES | 5 |
| 2023 | Fedstellar: A Platform for Training Models in a Privacy-preserving and Decentralized FashionabstractThis paper presents Fedstellar, a platform for training decentralized Federated Learning (FL) models in heterogeneous topologies in terms of the number of federation participants and their connections. Fedstellar allows users to build custom topologies, enabling them to control the aggregation of model parameters in a decentralized manner. The platform offers a Web application for creating, managing, and connecting nodes to ensure data privacy and provides tools to measure, monitor, and analyze the performance of the nodes. The paper describes the functionalities of Fedstellar and its potential applications. To demonstrate the applicability of the platform, different use cases are presented in which decentralized, semi-decentralized, and centralized architectures are compared in terms of model performance, convergence time, and network overhead when collaboratively classifying hand-written digits using the MNIST dataset. Enrique Tomás Martínez Beltrán, Pedro Miguel Sánchez Sánchez, Sergio López Bernal, Gérôme Bovet, Manuel Gil Pérez, Gregorio Martínez Pérez, Alberto Huertas Celdrán |
IJCAI | 5 |
| 2023 | Trust-as-a-Service: A reputation-enabled trust framework for 5G network resource provisioningabstractTrust, security, and privacy are three of the major pillars to assemble the fifth-generation network and beyond. Despite such pillars are principally interconnected, a multitude of challenges arise that need to be addressed separately. 5G networks ought to offer flexible and pervasive computing capabilities across multiple domains according to user demands and assure trustworthy network providers. To this end, distributed marketplaces expect to boost the trading of heterogeneous resources so as to enable the establishment of pervasive service chains between cross-domains. Yet, the need for selecting reliable parties as “marketplace operators” plays a pivotal role in achieving a trustworthy ecosystem. Two of the principal blockages in managing foreseeable networks are the need to consider trust as a property in the resource provisioning process and adapt previous trust models to accomplish the new network and business requirements. In this regard, this article is centered on the trust management of 5G multi-party network resource provisioning. As a result, a reputation-based trust framework is proposed as a Trust-as-a-Service (TaaS) solution for a distributed multi-stakeholder environment where requirements such as zero trust and zero-touch principles should be met. Besides, a literature review is also conducted to recognize the network and business requirements currently envisaged. Finally, the validation of the proposed trust framework was performed in a real research environment, the 5GBarcelona testbed, leveraging 12% of a 2.1 GHz CPU with 20 cores and 2% of the 30 GiB memory. These outcomes reveal the TaaS solution’s feasibility and conservative approach in the context of determining reliable network operators. José María Jorquera Valero, Pedro Miguel Sánchez Sánchez, Manuel Gil Pérez, Alberto Huertas Celdrán, Gregorio Martínez Pérez |
Comput. Commun. | 3 |
| 2023 | Adaptive vulnerability-based risk identification software with virtualization functions for dynamic managementabstractOver the years, risk management has become increasingly important for all companies, varying from large, medium-sized to micro-enterprises.The growing increase in cyber threats and the costs they cause has forced companies to consider new types of risks.This problem mainly affects medium, small, and micro-enterprises because of their limited resources or because they do not have sufficient technological knowledge.For this reason, this article studies different frameworks associated with risk management in different business areas.In addition, an open-source, automatic (plug and play) solution is proposed, which uses few resources thanks to virtualization through containerization.It takes care of identifying wired and wireless network devices.It generates a risk report with qualitative and quantitative values by reassessing the risk over time and provides mitigation if possible.Finally, a proof of concept was generated using a simulation of a medium-sized enterprise with various types of assets.As a result, we explored over 20 business days how network devices were detected and assessed without interacting with the framework, except to collect the results.It also showed how the risks evolve and increases if not addressed by the organization. Alberto García Pérez, Antonio López Martínez, Manuel Gil Pérez |
J. Netw. Comput. Appl. | 3 |
| 2023 | A methodology to identify identical single-board computers based on hardware behavior fingerprintingabstractThe connectivity and resource-constrained nature of single-board devices open the door to cybersecurity concerns affecting Internet of Things (IoT) scenarios. One of the most important issues is the presence of unauthorized IoT devices that want to impersonate legitimate ones by using identical hardware and software specifications. This situation can provoke sensitive information leakages, data poisoning, or privilege escalation in IoT scenarios. Combining behavioral fingerprinting and Machine/Deep Learning (ML/DL) techniques is a promising approach to identify these malicious spoofing devices by detecting minor performance differences generated by imperfections in manufacturing. However, existing solutions are not suitable for single-board devices since they do not consider their hardware and software limitations, underestimate critical aspects such as fingerprint stability or context changes, and do not explore the potential of ML/DL techniques. To improve it, this work first identifies the essential properties for single-board device identification: uniqueness, stability, diversity, scalability, efficiency, robustness, and security. Then, a novel methodology relies on behavioral fingerprinting to identify identical single-board devices and meet the previous properties. The methodology leverages the different built-in components of the system and ML/DL techniques, comparing the device internal behavior with each other to detect variations that occurred in manufacturing processes. The methodology validation has been performed in a real environment composed of 15 identical Raspberry Pi 4 Model B and 10 Raspberry Pi 3 Model B+ devices, obtaining a 91.9% average TPR with an XGBoost model and achieving the identification for all devices by setting a 50% threshold in the evaluation process. Finally, a discussion compares the proposed solution with related work, highlighting the fingerprint properties not met, and provides important lessons learned and limitations. Pedro Miguel Sánchez Sánchez, José María Jorquera Valero, Alberto Huertas Celdrán, Gérôme Bovet, Manuel Gil Pérez, Gregorio Martínez Pérez |
J. Netw. Comput. Appl. | 5 |
| 2021 | Mitigation of cyber threats: Protection mechanisms in federated SDN/NFV infrastructures for 5G within FIRE+abstractSummary Cyber attacks are becoming a very common trend in existing networks, expecting to be even more acute in future 5G networks due to greater number of connected devices, higher mobile data volume, low latency, etc. Security mechanisms to tackle cyber threats should be updated when users, possibly carrying devices with some kind of malware, move in highly dynamic mobile networks in order to continue providing the same detection and mitigation capabilities along user's path. This paper presents BotsOnFIRE, an experiment of the EU H2020 SoftFIRE project for the detection and mitigation of botnets in the SoftFIRE federated testbed for 5G within FIRE+, by combining Software‐Defined Networking (SDN) and Network Functions Virtualization (NFV) technologies. Bots' mobility is considered to trigger reconfiguration of security‐related SDN/NFV applications, when needed, so as to update security capabilities of the SoftFIRE infrastructure. The BotsOnFIRE experiment contributes to the wider 5G objective of more secure and resilient networks and services, where botnets are actually one of the most powerful cyber threats capable of orchestrating the remote execution of cyber‐attacks. Experiments confirm that BotsOnFIRE is feasible to conduct the expected detection and mitigation procedures in the SoftFIRE federated environment, being evaluated through some Key Performance Indicators. Manuel Gil Pérez, Alberto Huertas Celdrán, Pietro G. Giardina, Giacomo Bernini, Simone Pizzimenti, Félix J. García Clemente, Gregorio Martínez Pérez, Giovanni Festa, Fabio Paglianti |
Concurr. Comput. Pract. Exp. | 1 |
| 2021 | A novel Machine Learning-based approach for the detection of SSH botnet infectionabstractBotnets are causing severe damages to users, companies, and governments through information theft, abuse of online services, DDoS attacks, etc. Although significant research is being made to detect them and mitigate their effect, they are exponentially increasing due to new zero-day attacks, a variation of their behavior, and obfuscation techniques. High Interaction Honeypots (HIH) are the only honeypots able to capture attacks and log all the information generated by attackers when setting up a botnet. The data generated is being processed using Machine Learning (ML) techniques for detection since they can detect hidden patterns. However, so far, research has been focused on intermediate phases of the botnet’s life cycle during operation, underestimating the initial phase of infection. To the best of our knowledge, this is the first solution in the infection phase of SSH-based botnets. Therefore, we have designed an approach based on an SSH-based HIH to generate a dataset consisting of executed commands and network information. Herein, we have applied ML techniques for the development of a real-time detection model. This approach reached a very high level of prediction and zero false negatives. Indeed, our system detected all known and unknown SSH sessions intended to infect our honeypots. Thus, our research has demonstrated that new SSH infections can be detected through ML techniques. José Tomás Martínez Garre, Manuel Gil Pérez, Antonio Ruiz-Martínez |
Future Gener. Comput. Syst. | 2 |
| 2021 | SafeMan: A unified framework to manage cybersecurity and safety in manufacturing industryabstractSummary Industrial control systems (ICS) are considered cyber‐physical systems that join both cyber and physical worlds. Due to their tight interaction, where humans and robots co‐work and co‐inhabit in the same workspaces and production lines, cyber‐attacks targeting ICS can alter production processes and even bypass safety procedures. As an example, these cyber‐attacks could interrupt physical industrial processes and cause potential injuries to workers. In this article, we present SafeMan, a unified management framework based on the Edge Computing paradigm that provides high‐performance applications for the detection and mitigation of both cyber‐attacks and safety threats in industrial scenarios. Three use cases show specific threats in manufacturing as well as the SafeMan actions carried out to detect and mitigate them. In order to validate our proposal, a pool of experiments was performed with Electra, an industrial dataset with normal network traffic and different cyber‐attacks by using a given number of Modbus TCP and S7Comm devices. The experiments measured the runtime performance of anomaly detection techniques based on machine learning and deep learning to detect cyber‐attacks in control networks. The experimental results show that Neural Networks report the best performance, being able to examine 217 feature vectors per second over Electra, and therefore demonstrating that it can be used as detection model for SafeMan in real scenarios. Ángel Luis Perales Gómez, Lorenzo Fernández Maimó, Alberto Huertas Celdrán, Félix J. García Clemente, Manuel Gil Pérez, Gregorio Martínez Pérez |
Softw. Pract. Exp. | 5 |
| 2020 | PROTECTOR: Towards the protection of sensitive data in Europe and the US
Alberto Huertas Celdrán, Manuel Gil Pérez, Izidor Mlakar, José M. Alcaraz Calero, Félix J. García Clemente, Gregorio Martínez Pérez, Md. Zakirul Alam Bhuiyan |
Comput. Networks | 2 |
| 2020 | UMUDGA: A dataset for profiling DGA-based botnet
Mattia Zago, Manuel Gil Pérez, Gregorio Martínez Pérez |
Comput. Secur. | 2 |
| 2020 | Scalable detection of botnets based on DGA: Efficient feature discovery process in machine learning techniques
Mattia Zago, Manuel Gil Pérez, Gregorio Martínez Pérez |
Soft Comput. | 2 |
| 2020 | SELFNET 5G mobile edge computing infrastructure: Design and prototypingabstractSummary This paper presents the design and prototype implementation of the SELFNET fifth‐generation (5G) mobile edge infrastructure. In line with the current and emerging 5G architectural principles, visions, and standards, the proposed infrastructure is established primarily based on a mobile edge computing paradigm. It leverages cloud computing, software‐defined networking, and network function virtualization as core enabling technologies. Several technical solutions and options have been analyzed. As a result, a novel portable 5G infrastructure testbed has been prototyped to enable the preliminary testing of the integrated key technologies and to provide a realistic execution platform for further investigating and evaluating software‐defined networking– and network function virtualization–based application scenarios in 5G networks. Enrique Chirivella-Perez, Ricardo Marco Alaez, Alba Hita, Ana Serrano Mamolar, José M. Alcaraz Calero, Qi Wang 0001, Pedro Neves 0001, Giacomo Bernini, Konstantinos Koutsopoulos, Manuel Gil Pérez, Gregorio Martínez Pérez, Maria João Barros, Anastasius Gavras |
Softw. Pract. Exp. | 10 |
| 2020 | Spotting Political Social Bots in Twitter: A Use Case of the 2019 Spanish General Election
Javier Pastor-Galindo, Mattia Zago, Pantaleone Nespoli, Sergio López Bernal, Alberto Huertas Celdrán, Manuel Gil Pérez, José A. Ruipérez-Valiente, Gregorio Martínez Pérez, Félix Gómez Mármol |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2019 | Policy-Based Management for Green Mobile Networks Through Software-Defined Networking
Alberto Huertas Celdrán, Manuel Gil Pérez, Félix J. García Clemente, Gregorio Martínez Pérez |
Mob. Networks Appl. | 2 |
| 2019 | Dynamic network slicing management of multimedia scenarios for future remote healthcare
Alberto Huertas Celdrán, Manuel Gil Pérez, Félix J. García Clemente, Fabrizio Ippoliti, Gregorio Martínez Pérez |
Multim. Tools Appl. | 2 |
| 2018 | Catalog-Driven Services in a 5G SDN/NFV Self-Managed EnvironmentabstractWith the Fifth-Generation (5G) mobile networks set to arrive within the next years, this new generation will transform the industry with a profound impact on its customers as well as on the existing technologies and network architectures. Software-Defined Networking (SDN) and Network Functions Virtualization (NFV) will play key roles for the network operators as they prepare the migration to 5G, allowing them to quickly scale their networks. This paper presents a research work undertaken on this new paradigm of virtualized and programmable networks, aiming to address Self-Organizing Networks (SON) scenarios in a NFV/SDN context, focusing on detection and prediction of potential network and service anomalies. Towards this end, the performance management system performs aggregation, correlation and analysis of data gathered from the virtualized and programmable network elements. In particular, customized catalog-driven tools are developed, and the results show that they are able to successfully address these requirements. Current performance management platforms in production are designed for non-virtualized (non-NFV) and non-programmable (non-SDN) networks, and the knowledge gathered from this research brings some new understanding on how management platforms must evolve in order to be prepared for the upcoming next-generation mobile networks. Nuno Henriques, Susana Sargento, Pedro Neves 0001, Manuel Gil Pérez, Gregorio Martínez Pérez, Giacomo Bernini, Qi Wang 0001, José M. Alcaraz Calero, Konstantinos Koutsopoulos |
ISCC | 4 |
| 2018 | Real-time aggregation framework in a 5G SDN self-management environmentabstractThe next-generation 5G mobile networks are expected to bring a major shift on the management paradigm based on Network Function Virtualization (NFV) and Software-Defined Networking (SDN) compared with its precursor, 4G. Consequently, operators need to significantly change their network architectures, management mechanisms and business models to accommodate and address the 5G challenges. This paper contributes to advancing the operators' management capabilities in the monitoring and analytic domains, looking at the evolution of the existing performance management platform from a leading operator to a new SDN/NFV-enabled platform, in the context of the EU 5G project SELFNET. This work focuses on designing and prototyping the essential functionalities to perform real-time processing over network infrastructure data. This work devises a new Complex Event Processing (CEP) framework, a realtime framework for processing and aggregating big data using a dynamic rule-based approach. This CEP framework has been successfully implemented and deployed, with aggregation rules applied to a Self-Protection use case, which is able to provide in real-time information about detected botnets in the network. From a high-level perspective, this work brings some new understanding about the role of SDN/NFV network management tools for 5G network operators. Rui Pedro, Susana Sargento, Pedro Neves 0001, Manuel Gil Pérez, Gregorio Martínez Pérez, Giacomo Bernini, Qi Wang 0001, José M. Alcaraz Calero |
WCNC | 4 |
| 2016 | MASTERY: A multicontext-aware system that preserves the users' privacyabstractUsers' privacy is a critical challenge for any information management system. The proliferation of mobile devices has promoted the use of context-aware solutions, making the protection of the users' information an even greater challenge. Addressing this requires a given mechanism that allows users to manage and control their personal information. In this sense, this paper proposes a privacy-preserving and context-aware system named MASTERY (Multicontext-Aware System That prEserves the useRs' privacY) that manages the privacy of the users' information in intra- and inter-context scenarios. MASTERY is a trusted third party that suggests to users a pool of privacy policies (profiles) aware to the context in which they are located, who can modify them according to their interests. These policies protect the privacy of the users' information being accessed from others without their consent. The information about users and contexts is managed by using semantic web techniques. This provides a common infrastructure that makes possible to represent, process, and share information between independent systems easily. Alberto Huertas Celdrán, Manuel Gil Pérez, Félix J. García Clemente, Gregorio Martínez Pérez |
NOMS | 2 |
| 2015 | Chasing Offensive Conduct in Social Networks: A Reputation-Based Practical Approach for FrisberabstractSocial network users take advantage of anonymity to share rumors or gossip about others, making it important to provide means to report offensive conduct. This article presents a proposal to automatically manage these reports. We consider not only the users’ public behavior, but also private messages between users. The automatic approach is based, in both cases, on the reporters’ reputation along with other metrics intrinsic to social networks. Promising results from adopting the proposed reporting methods on Frisber, a geolocalized social network in production, are presented as well as some experiments based on real data extracted from Frisber. Santiago Pina Ros, Ángel Pina Canelles, Manuel Gil Pérez, Félix Gómez Mármol, Gregorio Martínez Pérez |
ACM Trans. Internet Techn. | 3 |
| 2014 | Trustworthy placements: Improving quality and resilience in collaborative attack detection
Manuel Gil Pérez, Juan Tapiador, John A. Clark, Gregorio Martínez Pérez, Antonio F. Skarmeta |
Comput. Networks | 1 |
| 2014 | Building a reputation-based bootstrapping mechanism for newcomers in collaborative alert systems
Manuel Gil Pérez, Félix Gómez Mármol, Gregorio Martínez Pérez, Antonio F. Skarmeta |
J. Comput. Syst. Sci. | 1 |
| 2013 | RECLAMO: Virtual and Collaborative Honeynets Based on Trust Management and Autonomous Systems Applied to Intrusion ManagementabstractSecurity intrusions in large systems is a problem due to its lack of scalability with the current IDS-based approaches. This paper describes the RECLAMO project, where an architecture for an Automated Intrusion Response System (AIRS) is being proposed. This system will infer the most appropriate response for a given attack, taking into account the attack type, context information, and the trust and reputation of the reporting IDSs. RECLAMO is proposing a novel approach: diverting the attack to a specific honey net that has been dynamically built based on the attack information. Among all components forming the RECLAMO's architecture, this paper is mainly focused on defining a trust and reputation management model, essential to recognize if IDSs are exposing an honest behavior in order to accept their alerts as true. Experimental results confirm that our model helps to encourage or discourage the launch of the automatic reaction process. Manuel Gil Pérez, Verónica Mateos Lanchas, David Fernández 0002, Gregorio Martínez Pérez, Víctor A. Villagrá |
CISIS | 1 |
| 2011 | An advanced certificate validation service and architecture based on XKMSabstractAbstract The appearance of some laws that make the electronic signature (e‐signature) legally equivalent to the handwritten signature (under some circumstances) has favoured its use in different fields, such as e‐commerce and e‐government. In these fields, the e‐signatures associated to some documents have to remain valid over long periods of time. For these kinds of e‐signatures, Advanced Electronic Signature (AdES) forms have appeared. These forms specify the information to include along with the e‐signature so that it remains valid for a long time after its creation. Basically, this information comprises signers' certificates, a set of certificates up to a trust anchor, certificate validation responses, etc. These data can be gathered by using different Public Key Infrastructure‐compliant protocols. However, the support of different protocols is complex for clients. XML Key Management Specification (XKMS) appeared with the aim of simplifying the certificate management, but it only supports a simple validation mechanism that does not provide the information needed for long‐term validation. As a solution to this problem, we have extended XKMS by defining an advanced certificate validation service to support the obtaining of validation data needed for different scenarios, such as the building of AdES forms or validation data registries. This extension also defines the different components needed to support this kind of a service. Furthermore, the defined service has been implemented and incorporated into an e‐government infrastructure. Copyright © 2010 John Wiley & Sons, Ltd. Antonio Ruiz-Martínez, Daniel Sánchez-Martínez, C. Inmaculada Marín-López, Manuel Gil Pérez, Antonio F. Skarmeta |
Softw. Pract. Exp. | 4 |
| 2010 | PKI-based trust management in inter-domain scenarios
Gabriel López Millán, Manuel Gil Pérez, Gregorio Martínez Pérez, Antonio F. Skarmeta |
Comput. Secur. | 2 |
| 2009 | Parallelizing the Design and Development of a Monitoring System
Francisco José de la Torre, Manuel Gil Pérez |
CDVE | 2 |
| 2008 | ACVS: An Advanced Certificate Validation Service in Service-Oriented ArchitecturesabstractProposals such as CAdES, XAdES and LTANS have made the need of remaining evidences over long periods of time clear. Between these evidences we have electronic signatures, certificates, requests and responses of validation mechanisms and so on. In order to gather these evidences, clients have to support several PKI-compliant protocols. Then, with the aim of simplifying this task XKMS appeared. However, XKMS only provides a simple validation mechanism that does not allow clients to specify some useful aspects needed for purposes of long term validation, such as trust anchors, information to store, responses to obtain, and so on. Therefore, in order to solve this problem, we present both an extension to XKMS and the different modules that are involved in this new specification. Antonio Ruiz-Martínez, Daniel Sánchez-Martínez, C. Inmaculada Marín-López, Manuel Gil Pérez, Antonio F. Skarmeta |
ICIW | 4 |
| 2007 | A Proposal for the Definition of Operational Plans to Provide Dependability and Security
Daniel J. Martínez-Manzano, Manuel Gil Pérez, Gabriel López Millán, Antonio F. Skarmeta |
CRITIS | 2 |
| 2007 | A Linguistic Fuzzy-XCS Classifier SystemabstractData-driven construction of fuzzy systems has followed two different approaches. One approach is termed precise (or approximative) fuzzy modelling, that aims at numerical approximation of functions by rules, but that pays little attention to the interpretability of the resulting rule base. On the other side is linguistic (or descriptive) fuzzy modelling, that aims at automatic rule extraction but that uses fixed human provided and linguistically labelled fuzzy sets. This work follows the linguistic fuzzy modelling approach. It uses an extended Classifier System (XCS) as mechanism to extract linguistic fuzzy rules. XCS is one of the most successful accuracy-based learning classifier systems. It provides several mechanisms for rule generalization and also allows for online training if necessary. It can be used in sequential and non-sequential tasks. Although originally applied in discrete domains it has been extended to continuous and fuzzy environments. The proposed Linguistic Fuzzy XCS has been applied to several well-known classification problems and the results compared with both, precise and linguistic fuzzy models. Javier G. Marín-Blázquez, Gregorio Martínez Pérez, Manuel Gil Pérez |
FUZZ-IEEE | 3 |
| 2005 | Deploying Secure Cryptographic Services in Multi-Domain IPv6 NetworksabstractThere are several reasons to offer PKI (public key infrastructure) services in IPv6 multidomain scenarios. The first reason is to provide IPv6-only or dual-stack connectivity to those Internet users and entities who want to use certification services, but there are other important motivations. If we want to enable and promote security services in IPv6 networks, like end-to-end security, AAA (authentication, authorization and accounting) services, HTTP or DNSsec services, or VPN networks, it is needed to offer the public key services required by the involved protocols. Other relevant reason is to allow services or devices to use X.509 public key certificates containing IPv6 information, such as IPv6 addresses used, for example, by any IPsec-based VPN end point. This is the main motivation of the research work presented in this paper where the most relevant design and implementation issues related with the deployment of PKI services in a multidomain IPv6 network are presented. Gabriel López Millán, Félix J. García Clemente, Manuel Gil Pérez, Gregorio Martínez Pérez, Antonio F. Skarmeta |
AINA | 3 |