VLDB 2026 Research / reviewers in the wild / expert
Erkuden Rios
dblp:41/3822 · also Erkuden Rios Velasco
· DBLP profile ↗
19ranked-venue papers
4as first author
9since 2021 · last 2026
0000-0001-5541-1091ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 3 · 1 first-authorHuman-computer interaction and ubiquitous computing · 3Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Reinforcement Learning in action: Powering intelligent intrusion responses to advanced cyber threats in realistic scenariosabstractGiven the increasing incidence of sophisticated cyber-attacks, particularly Advanced Persistent Threats (APTs), there is a growing need for intelligent and adaptive intrusion response solutions. In this paper, we propose a Reinforcement Learning (RL)-based model for APT intrusion response that can manage dynamic, multi-stage attacks and large observation spaces. The model supports both policy-based and value-based learning approaches, enabling comparative evaluation between different strategies. We introduce a realistic RL training environment based on emulation infrastructure, which accurately reproduces APT scenarios using real systems and executes a wide range of authentic Intrusion Response System (IRS) actions. This setup includes time and variability constraints commonly encountered in operational environments, offering a more practical alternative to traditional simulations. The RL agents, implemented using Proximal Policy Optimization (PPO) and Deep Q-Network (DQN) algorithms, were both trained and evaluated within this industrial-style emulated environment. Empirical results demonstrate that both DRL algorithms successfully learned effective and well-timed defensive actions under realistic constraints, confirming their capability to operate in dynamic, real-world APT scenarios. Eider Iturbe, Angel Rego, Oscar Llorente-Vazquez, Erkuden Rios, Christos Dalamagkas, Dimitris Merkouris, Nerea Toledo |
Expert Syst. Appl. | 4 |
| 2026 | A pattern-aware LSTM-based approach for APT detection leveraging a realistic dataset for critical infrastructure securityabstractAdvanced Persistent Threats (APTs) represent some of the most sophisticated and coordinated cyberattacks, often targeting critical infrastructure with stealthy, multi-stage techniques. Despite the availability of numerous intrusion detection datasets, most fail to capture the sequential and strategic nature of APT campaigns as outlined in frameworks like MITRE ATT&CK. This paper introduces a novel dataset based on a realistic emulation of the Sandworm APT group targeting the Supervisory Control and Data Acquisition (SCADA) system of a Wide Area Measurement System (WAMS). The dataset captures the full lifecycle of an APT attack, from initial access to impact, in a structured and time-ordered manner, enabling the study of both atomic and multi-step intrusion behaviours. We train and evaluate supervised multiclass sequence-aware models, specifically Long Short-Term Memory (LSTM) and Bidirectional LSTM (BiLSTM) architectures, to detect these behaviours using network flow data, assessing their performance and analysing their strengths and limitations. Our results show that BiLSTM models offer greater stability and generalization, while LSTM models achieve competitive performance with optimal configurations. These findings highlight the importance of realistic, sequence-aware datasets for developing robust intrusion detection systems tailored to modern APT threats. Eider Iturbe, Christos Dalamagkas, Panagiotis I. Radoglou-Grammatikis, Erkuden Rios, Nerea Toledo |
Future Gener. Comput. Syst. | 4 |
| 2024 | A Multi-layer Approach through Threat Modelling and Attack Simulation for Enhanced Cyber Security AssessmentabstractThere is a growing concern about the dynamic landscape of cyber security threats escalating, and the need for improvement in defence capabilities against emerging sophisticated incidents. In response, this paper presents a solution called the Cyber Incident Simulation System, which enables system security engineers to simulate cyber-physical attacks and incidents without the requirement to affect or disrupt the ongoing business operation of the system. Leveraging graph-based threat modelling and AI-generated incident data, the system empowers professionals to predict the effect of the incident within the system under study. The synthetic data is used by anomaly-based Intrusion Detection Systems (IDSs) and other additional security controls to improve their detection algorithms to enhance their accuracy and effectiveness. The Cyber Incident Simulation System is designed to enhance the cyber security measures through the simulation of various incident scenarios. Eider Iturbe, Javier Arcas, Erkuden Rios, Nerea Toledo |
ARES | 3 |
| 2024 | Unleashing offensive artificial intelligence: Automated attack technique code generationabstractArtificial Intelligence (AI) technology is revolutionizing the digital world and becoming the cornerstone of the modern digital systems. The capabilities of cybercriminals are expanding as they adopt new technologies like zero-day exploits or new business models such as hacker-as-a-service. While AI capabilities can improve cybersecurity measures, this same technology can also be utilized as an offensive cyber weapon to create sophisticated and intricate cyber-attacks. This paper describes an AI-powered mechanism for the automatic generation of attack techniques, ranging from initial attack vectors to impact-related actions. It presents a comprehensive analysis of simulated attacks by highlighting the attack tactics and techniques that are more likely to be generated using AI technology, specifically Large Language Model (LLM) technology. The work empirically demonstrates that LLM technology can be easily used by cybercriminals for attack execution. Moreover, the solution can complement Breach and Attack Simulation (BAS) platforms and frameworks that automate the security assessment in a controlled manner. BAS could be enhanced with AI-powered attack simulation by bringing forth new ways to automatically program multiple attack techniques, even multiple versions of the same attack technique. Therefore, AI-enhanced attack simulation can assist in ensuring digital systems are bulletproof and protected against a great variety of attack vectors and actions. Eider Iturbe, Oscar Llorente-Vazquez, Angel Rego, Erkuden Rios, Nerea Toledo |
Comput. Secur. | 4 |
| 2023 | Artificial Intelligence for next generation cybersecurity: The AI4CYBER frameworkabstractArtificial Intelligence (AI) is playing a crucial role both in the technological advances and emerging advanced threats in cybersecurity. Despite efforts by competent authorities in Europe to regulate the use of AI in a way that aligns with the ethics and individuals’ fundamental rights, there are still challenges to be tackled, not to mention the malicious use of AI by cybercriminals. In this paper we present a novel framework that is composed of innovative cybersecurity services that leverage AI to provide support in the management of the incident response and recovery lifecycle of the critical entities’ systems against advanced attacks. The paper describes the main components and architecture of the AI4CYBER framework and provides a clear understanding of the application of the autonomous intelligent cybersecurity services and their role in enforcing defensive actions throughout the entire lifecycle of the systems. Eider Iturbe, Erkuden Rios, Angel Rego, Nerea Toledo |
ARES | 2 |
| 2023 | The DYNABIC approach to resilience of critical infrastructuresabstractWith increasing interdependencies and evolving threats, maintaining operational continuity in critical systems has become a significant challenge. This paper presents the DYNABIC (Dynamic business continuity of critical infrastructures on top of adaptive multi-level cybersecurity) approach as a comprehensive framework to enhance the resilience of critical infrastructures. The DYNABIC approach provides the resilience enhancement through dynamic adaptation, automated response, collaboration, risk assessment, and continuous improvement. By fostering a proactive and collaborative approach to resilience, the DYNABIC framework empowers critical infrastructure sectors to effectively mitigate disruptions and recover from incidents. The paper explores the key components and architecture of the DYNABIC approach and highlights its potential to strengthen the resilience of critical infrastructures using the concept of Digital Twins in the face of evolving threats and complex operating environments involving cascading effects. Erkuden Rios, Eider Iturbe, Angel Rego, Nicolas Ferry 0001, Jean-Yves Tigli, Stéphane Lavirotte, Gérald Rocher, Phu Hong Nguyen, Rustem Dautov, Wissam Mallouli, Ana R. Cavalli |
ARES | 1 |
| 2023 | Towards trustworthy Artificial Intelligence: Security risk assessment methodology for Artificial Intelligence systemsabstractThe digitalization and smartization of modern digital systems include the implementation and integration of emerging innovative technologies, such as Artificial Intelligence. By incorporating new technologies, the surface attack of the system also expands, and specialized cybersecurity mechanisms and tools are required to counter the potential new threats. This paper introduces a holistic security risk assessment methodology that aims to assist Artificial Intelligence system stakeholders guarantee the correct design and implementation of technical robustness in Artificial Intelligence systems. The methodology is designed to facilitate the automation of the security risk assessment of Artificial Intelligence components together with the rest of the system components. Supporting the methodology, the solution to the automation of Artificial Intelligence risk assessment is also proposed. Both the methodology and the tool will be validated when assessing and treating risks on Artificial Intelligence-based cybersecurity solutions integrated in modern digital industrial systems that leverage emerging technologies such as cloud continuum including Software-defined networking (SDN). Eider Iturbe, Erkuden Rios, Nerea Toledo |
CloudCom | 2 |
| 2023 | Towards Smarter Security Orchestration and Automatic Response for CPS and IoTabstractCurrent security orchestration and response (SOAR) approaches have primarily focused on specific layers of systems, such as Intrusion Detection Systems, the network layer, or the application layer. We aim to find the gaps in the existing SOAR approaches for IoT/CPS-based systems, especially critical infrastructures, and propose some directions to fill in these gaps. This paper presents a literature survey and future research directions for advancing SOAR towards increased automation and more holistic operation, especially for the cyber-physical security of critical infrastructures. We have found 14 primary SOAR studies and discussed the gaps in general. There is a significant gap when it comes to a comprehensive and systematic approach to SOAR for multi-layered systems using IoT/CPS and considering the computing continuum perspective. To address the gap, we present our on-going work on a framework of multi-layer SOAR decision-making methods and orchestration tools that leverage Reinforcement Learning (RL)-based adaptation intelligence, virtual reality, avatar-human interaction and advanced Cyber Threat Intelligence (CTI) tools. Phu Hong Nguyen, Rustem Dautov, Angel Rego, Eider Iturbe, Erkuden Rios, Diego Sagasti, Gonzalo Nicolas, Valeria Valdés Ríos, Wissam Mallouli, Ana R. Cavalli, Nicolas Ferry 0001 |
CloudCom | 6 |
| 2021 | SPEAR SIEM: A Security Information and Event Management system for the Smart GridabstractPublisher Copyright: © 2021 Panagiotis I. Radoglou-Grammatikis, Panagiotis G. Sarigiannidis, Eider Iturbe, Erkuden Rios, Saturnino Martinez, Antonios Sarigiannidis, Georgios Eftathopoulos, Yannis Spyridis, Achilleas Sesis, Nikolaos Vakakis, Dimitrios Tzovaras, Emmanouil Kafetzakis, Ioannis Giannoulakis, Michalis Tzifas, Alkiviadis Giannakoulias, Michail K. Angelopoulos, Francisco Ramos 0003 |
Comput. Networks | 4 |
| 2020 | Secure and Private Smart Grid: The SPEAR ArchitectureabstractInformation and Communication Technology (ICT) is an integral part of Critical Infrastructures (CIs), bringing both significant pros and cons. Focusing our attention on the energy sector, ICT converts the conventional electrical grid into a new paradigm called Smart Grid (SG), providing crucial benefits such as pervasive control, better utilisation of the existing resources, self-healing, etc. However, in parallel, ICT increases the attack surface of this domain, generating new potential cyberthreats. In this paper, we present the Secure and PrivatE smArt gRid (SPEAR) architecture which constitutes an overall solution aiming at protecting SG, by enhancing situational awareness, detecting timely cyberattacks, collecting appropriate forensic evidence and providing an anonymous cybersecurity information-sharing mechanism. Operational characteristics and technical specifications details are analysed for each component, while also the communication interfaces among them are described in detail. Panagiotis I. Radoglou-Grammatikis, Panagiotis G. Sarigiannidis, Eider Iturbe, Erkuden Rios, Antonios Sarigiannidis, Odysseas Nikolis, Dimosthenis Ioannidis, Vasileios Machamint, Michalis Tzifas, Alkiviadis Giannakoulias, Michail K. Angelopoulos, Anastasios Papadopoulos, Francisco Ramos 0003 |
NetSoft | 4 |
| 2019 | A Survey On Honeypots, Honeynets And Their Applications On Smart GridabstractPower grid is a major part of modern Critical Infrastructure (CIN). The rapid evolution of Information and Communication Technologies (ICT) enables traditional power grids to encompass advanced technologies that allow them to monitor their state, increase their reliability, save costs and provide ICT services to end customers, thus converting them into smart grids. However, smart grid is exposed to several security threats, as hackers might try to exploit vulnerabilities of the industrial infrastructure and cause disruption to national electricity system with severe consequences to citizens and commerce. This paper investigates and compares honey-x technologies that could be applied to smart grid in order to distract intruders, obtain attack strategies, protect the real infrastructure and form forensic evidence to be used in court. Christos Dalamagkas, Panagiotis G. Sarigiannidis, Dimosthenis Ioannidis, Eider Iturbe, Odysseas Nikolis, Francisco Ramos 0003, Erkuden Rios, Antonios Sarigiannidis, Dimitrios Tzovaras |
NetSoft | 7 |
| 2019 | Service level agreement-based GDPR compliance and security assurance in (multi)Cloud-based systemsabstractCompliance with the new European General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and security assurance are currently two major challenges of Cloud‐based systems. GDPR compliance implies both privacy and security mechanisms definition, enforcement and control, including evidence collection. This study presents a novel DevOps framework aimed at supporting Cloud consumers in designing, deploying and operating (multi)Cloud systems that include the necessary privacy and security controls for ensuring transparency to end‐users, third parties in service provision (if any) and law enforcement authorities. The framework relies on the risk‐driven specification at design time of privacy and security level objectives in the system service level agreement and in their continuous monitoring and enforcement at runtime. Erkuden Rios, Eider Iturbe, Xabier Larrucea, Massimiliano Rak, Wissam Mallouli, Jacek Dominiak, Victor Muntés-Mulero, Peter Matthews, Luis Gonzalez |
IET Softw. | 1 |
| 2017 | Self-healing Multi-Cloud Application ModellingabstractCloud computing market forecasts and technology trends confirm that Cloud is an IT disrupting phenomena and that the number of companies with multi-cloud strategy is continuously growing. Cost optimization and increased competitiveness of companies that exploit multi-cloud will only be possible when they are able to leverage multiple cloud offerings, while mastering both the complexity of multiple cloud provider management and the protection against the higher exposure to attacks that multi-cloud brings. Erkuden Rios, Eider Iturbe, Maria Carmen Palacios |
ARES | 1 |
| 2017 | Multi-cloud Applications Security Monitoring
Pamela Carvallo, Ana R. Cavalli, Wissam Mallouli, Erkuden Rios |
GPC | 4 |
| 2017 | Security-Centric Evaluation Framework for IT Services
Smrati Gupta, Jaume Ferrarons, Jacek Dominiak, Victor Muntés-Mulero, Peter Matthews, Erkuden Rios |
GPC | 6 |
| 2017 | MUSA Deployer: Deployment of Multi-cloud ApplicationsabstractThe development of applications based on services offered by different, not conscious, providers, is expected to be growing in the next years. In order to offer effectively multicloud applications, many challenges still need to be faced. At this aim, the MUSA framework provides a DevOps approach to develop multi-cloud applications with desired Security Service Level Agreements (SLAs). This paper describes the MUSA Deployer models, which help developers to express their security requirements, and a Deployer tool that automatically provides cloud security services to offer Security SLAs. Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano, Erkuden Rios, Angel Rego, Giancarlo Capone |
WETICE | 5 |
| 2016 | Methodology to Obtain the Security Controls in Multi-cloud ApplicationsabstractPublisher Copyright: Copyright © 2016 by SCITEPRESS-Science and Technology Publications, Lda. All rights reserved. Samuel Olaiya Afolaranmi, Luis E. Gonzalez Moctezuma, Massimiliano Rak, Valentina Casola, Erkuden Rios, José L. Martínez Lastra |
CLOSER (1) | 5 |
| 2015 | Towards Self-Protective Multi-Cloud Applications - MUSA - a Holistic Framework to Support the Security-Intelligent Lifecycle Management of Multi-Cloud ApplicationsabstractThe most challenging applications in heterogeneous cloud ecosystems are those that are able to maximise the benefits of the combination of the cloud resources in use: multi-cloud applications. They have to deal with the security of the individual components as well as with the overall application security including the communications and the data flow between the components. In this paper we present a novel approach currently in progress, the MUSA framework. The MUSA framework aims to support the security-intelligent lifecycle management of distributed applications over heterogeneous cloud resources. The framework includes security-by-design mechanisms to allow application self-protection at runtime, as well as methods and tools for the integrated security assurance in both the engineering and operation of multi-cloud applications. The MUSA framework leverages security-by-design, agile and DevOps approaches to enable the security-aware development and operation of multi-cloud applications. Erkuden Rios, Eider Iturbe, Leire Orue-Echevarria Arrieta, Massimiliano Rak, Valentina Casola |
CLOSER | 1 |
| 2009 | An Architectural Foundation for Security Model Sharing and ReuseabstractWithin the field of software security we have yet to find efficient ways on how to learn from past mistakes and integrate security as a natural part of software development.This situation can be improved by using an online repository, the SHIELDS SVRS, that facilitates fast and easy interchange of security artefacts between security experts, software developers and their assisting tools. Such security artefacts are embedded in or represented as security models containing the needed information to detect, remove and prevent vulnerabilities in software, independent of the applied development process. The purpose of this paper is to explain the main reference architecture description of the repository and the more general tool stereotypes that can communicate with it. Per Håkon Meland, Shanai Ardi, Jostein Jensen, Erkuden Rios, Txus Sanchez, Nahid Shahmehri, Inger Anne Tøndel |
ARES | 4 |