VLDB 2026 Research / reviewers in the wild / expert
Julio César Hernández Castro
dblp:45/4009 · also Julio C. Hernandez-Castro
· DBLP profile ↗
76ranked-venue papers
13as first author
10since 2021 · last 2024
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 29 · 4 first-author · 9 since 2021Artificial intelligence and machine learning · 21 · 7 first-authorComputer networks · 8 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 1 first-authorSystems, architecture and hardware · 6 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 2Human-computer interaction and ubiquitous computing · 2Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Assessing the Silent Frontlines: Exploring the Impact of DDoS Hacktivism in the Russo-Ukrainian WarabstractThis study assessed the impact and effectiveness of Distributed Denial of Service (DDoS) attacks during a period of about four months of the Russo-Ukrainian war, by observing the exchanges between the opposing sides. The data collection phase took place between the 28thof November 2022 and the 15thof April 2023. In total, we monitored 1,257 websites and web applications targeted in the conflict, with 633 targeted by pro-Russian and 624 by pro-Ukrainian entities. Only a small fraction (1.27%) of the targets remained unaffected, whereas 30.63% faced complete shutdowns. When considering the extent of the attacks conducted by the belligerents in the war, the attacks by pro-Russian entities showed a slightly more successful overall impact, with 36.18% of their targets were taken down, compared to 25.00% on the opposite side. Businesses demonstrated greater resilience against DDoS attacks compared to governmental and educational institutions. An in-depth analysis revealed significant differences in target categories, despite both sides primarily targeting businesses. Our findings regarding the usage of DDoS protection services among the 1,257 analysed targets showed that only 13.37% used such services. Among these minority of users, 70.24% had protection from the beginning of our analysis, while 29.76% adopted it only after experiencing attacks. We also looked into the use of geolocation-based access policies on websites targeted by pro-Ukrainian entities. Our findings indicated that most of these websites do not implement geolocation-based access restrictions. To an extent, such restrictions could have been useful for preventing some unsophisticated attacks. Surprisingly, only a small percentage (4.50%) restricted access to solely Russian addresses, while a fraction (12.56%) seemed to implement adaptive access policies in response to cyberattacks. Lastly, and quite surprisingly for us, we discovered that a significant number of targets on the Russian side were using anti-DDoS services and technology provided by countries that have for a long time imposed economic and commercial sanctions on Russia. This may or may not be strictly illegal, but it is without question against the spirit of these sanctions. Yagiz Yilmaz, Orçun Çetin, Omer Said Ozturk, Emre Ekmekcioglu, Budi Arief, Julio César Hernández Castro |
ACSAC | 6 |
| 2023 | Game Theoretic Modelling of a Ransom and Extortion Attack on Ethereum ValidatorsabstractConsensus algorithms facilitate agreement on and resolution of blockchain functions, such as smart contracts and transactions. Ethereum uses a Proof-of-Stake (PoS) consensus mechanism, which depends on financial incentives to ensure that validators perform certain duties and do not act maliciously. Should a validator attempt to defraud the system, legitimate validators will identify this and then staked cryptocurrency is ‘burned’ through a process of slashing. Alpesh Bhudia, Anna Cartwright 0001, Edward J. Cartwright, Darren Hurley-Smith, Julio César Hernández Castro |
ARES | 5 |
| 2023 | Using Infrastructure-Based Agents to Enhance Forensic Logging of Third-Party Applications
Jennifer Bellizzi, Mark Vella, Christian Colombo 0001, Julio César Hernández Castro |
ICISSP | 4 |
| 2023 | Dark Ending: What Happens when a Dark Web Market Closes downabstractAs the economic hubs of (potentially) illegal transactions, dark web markets are fraught with uncertainty, including their ending. The ending of a dark web market can bring disruption to the stakeholders involved, especially vendors and buyers. Most importantly, there is a growing concern that such an ending can cause financial repercussions or even fraud victimisation. At the moment, there is scant published work about how, why or when dark web markets would end. We aim to fill this gap to help the academic and security research communities to reflect on what would typically happen to dark web markets in their final days. We used crawling and data scraping techniques to gather relevant weekly data from six dark web markets over a span of several months, right up to their closure. We then analysed the data to find common characteristics and predictive features leading to the closure of these markets. We found three main reasons for the ending of dark web markets: (i) exit scam, (ii) voluntary closure, or (iii) taken down by Law Enforcement Agencies (LEAs). We also gained further insights by analysing our data more closely. For instance, markets are most likely to be closed down when they are most visible, when they are under attack or when they are growing rapidly to their peak. In particular, more mature markets (i.e. markets that have been in operation for a long period of time) are more likely to disappear when their economic patterns start to change (for example, there might be a rapid growth or a sudden – or even gradual, but noticeable – economic decline). When a market was closed down, vendors and buyers would typically move on quickly to other alternative markets – which might grow rapidly as a result – and in turn, those alternative markets’ risk of being closed down would become higher. Whether a market is still accepting new vendors (or not) appears to be a valuable indicator for predicting the market’s next move. These insights can be useful in anticipating potential market closure, so that sufficient warning can be provided to avoid people being victimised. Budi Arief, Julio César Hernández Castro |
ICISSP | 3 |
| 2022 | Sensitivity and uniformity in statistical randomness tests
Elena Almaraz Luengo, Marcos Brian Leiva Cerna, Luis Javier García Villalba, Darren Hurley-Smith, Julio César Hernández Castro |
J. Inf. Secur. Appl. | 5 |
| 2022 | On the Unbearable Lightness of FIPS 140-2 Randomness TestsabstractRandom number generation is critical to many applications. Gaming, gambling, and particularly cryptography all require random numbers that are uniform and unpredictable. For testing whether supposedly random sources feature particular characteristics commonly found in random sequences, batteries of statistical tests are used. These are fundamental tools in the evaluation of random number generators and form part of the pathway to certification of secure systems implementing them. Although there have been previous studies into this subject (Becker, 2013), RNG manufacturers and vendors continue to use statistical tests known to be of dubious reliability, in their RNG verification processes. Our research shows that FIPS-140-2 cannot identify adversarial biases effectively, even very primitive ones. Concretely, this work illustrates the inability of the FIPS 140 family of tests to detect bias in three obviously flawed PRNGs. Deprecated by official standards, these tests are nevertheless still widely used, for example in hardware-level self-test schemes incorporated into the design of many True RNGs (TRNGs). They are also popular with engineers and cryptographers for quickly assessing the randomness characteristics of security primitives and protocols, and even with manufacturers aiming to market the randomness features of their products to potential customers. In the following, we present threebiased-by-designRNGs to show in explicit detail how simple, glaringly obvious biases are not detected by any of the FIPS 140–2 tests. One of these RNGs is backdoored, leaking key material, while others suffer from significantly reduced unpredictability in their output sequences. To make our point even more straightforward, we show how files containing images can also fool the FIPS 140 family of tests. We end with a discussion on the security issues affecting an interesting and active project to create a randomness beacon. Their authors only tested the quality of their randomness with the FIPS 140 family of tests, and we will show how this has led them to produce predictable output that, albeit passing FIPS fails other randomness tests quite catastrophically. Darren Hurley-Smith, Constantinos Patsakis, Julio César Hernández Castro |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | Responding to Living-Off-the-Land Tactics using Just-In-Time Memory Forensics (JIT-MF) for Android
Jennifer Bellizzi, Mark Vella, Christian Colombo 0001, Julio César Hernández Castro |
SECRYPT | 4 |
| 2021 | On the Effectiveness of Ransomware Decryption Tools
Burak Filiz, Budi Arief, Orçun Çetin, Julio César Hernández Castro |
Comput. Secur. | 4 |
| 2021 | Investigating the impact of ransomware splash screens
Yagiz Yilmaz, Orçun Çetin, Budi Arief, Julio César Hernández Castro |
J. Inf. Secur. Appl. | 4 |
| 2021 | Intercepting Hail Hydra: Real-time detection of Algorithmically Generated Domains
Fran Casino, Nikolaos Lykousas, Ivan Homoliak, Constantinos Patsakis, Julio César Hernández Castro |
J. Netw. Comput. Appl. | 5 |
| 2020 | PaperW8: an IoT bricking ransomware proof of conceptabstractInternet of Things (IoT) devices are used in many facets of modern life, from smart homes to smart cities, including Internet-enabled healthcare systems and industrial control systems. The prevalence and ubiquity of IoT devices makes them extremely attractive targets for malicious actors, in particular for taking control of vulnerable devices and demand ransom from their owners. The aim of this paper is twofold: to investigate the viability of a ransomware-type attack being carried out on IoT devices; and to explore what damage can be inflicted upon devices after they have been compromised. To test whether ransomware is a viable method for attacking IoT devices, we developed our own proof of concept malware for Linux-based IoT devices dubbed "PaperW8". We looked at feasible ways for infecting IoT devices, as well as potential methods for gaining control and applying persistent changes to the target device. We successfully created a proof of concept ransomware, which we tested against six vulnerable IoT devices of various brands and functions, some of which are known to have been targeted in the past but are still widely in use today. Developing this proof of concept tool allowed us to identify the main requirements for a successful ransomware attack against IoT devices. We also determined some limitations of IoT devices that may discourage attackers from developing IoT-specific ransomware, while highlighting workarounds that more determined attackers may use to overcome these obstacles. This paper has demonstrated that IoT ransomware is a credible threat. We implemented a proof of concept tool that can compromise many IoT devices of varying types. We envisage that this work can be used to assist current and future IoT developers to improve the security of their devices, and also to help security researchers in implementing more effective ransomware countermeasures, including for IoT devices. Calvin Brierley, Jamie Pont, Budi Arief, David J. Barnes, Julio César Hernández Castro |
ARES | 5 |
| 2020 | What Is Your MOVE: Modeling Adversarial Network Environments
Karlo Knezevic, Stjepan Picek, Domagoj Jakobovic, Julio César Hernández Castro |
EvoApplications | 4 |
| 2020 | Using Eyetracker to Find Ways to Mitigate RansomwareabstractRansomware is a form of malware designed to prevent access to data by either locking out the victims from their system or encrypting some or all of their files until a ransom has been paid to the attacker. Victims would know that they had been hit by ransomware because a ransom demand (splash screen) would be displayed on their compromised device. This study aims to identify key user interface features of ransomware splash screens and see how these features affect victims' likelihood to pay, and how this information may be used to create more effective countermeasures to mitigate the threat of ransomware. We devised an experiment that contained three broad types of splash screens (Text, Time-Sensitive Counter, and Other). A total of nine splash screens were shown to each participant, from which data on the participants' eye behaviour were collected. After each splash screen, participants were also asked a set of questions that would help describe their experience and be cross-referenced with the eye tracking data to aid analysis. Our experiment collected quantitative eye tracker data and qualitative data regarding willingness to pay from 25 participants. Several key components of the splash screens such as the text, logo, images, and technical information were analysed. Comments from the participants on whether they would pay the ransom or not, and the reasons behind their decision were also recorded. We found that there is no clear indication that one type of splash screen would have a higher chance of success with regard to ransom payment. Our study revealed that there are some characteristics in splash screens that would strongly discourage some victims from paying. Further investigation will be carried out in this direction, in order to design and develop more effective countermeasures to ransomware. Budi Arief, Andy Periam, Orçun Çetin, Julio César Hernández Castro |
ICISSP | 4 |
| 2020 | Why Current Statistical Approaches to Ransomware Detection Fail
Jamie Pont, Budi Arief, Julio César Hernández Castro |
ISC | 3 |
| 2020 | Quantum Leap and Crash: Searching and Finding Bias in Quantum Random Number GeneratorsabstractRandom numbers are essential for cryptography and scientific simulation. Generating truly random numbers for cryptography can be a slow and expensive process. Quantum physics offers a variety of promising solutions to this challenge, proposing sources of entropy that may be genuinely unpredictable, based on the inherent randomness of certain physical phenomena. These properties have been employed to design Quantum Random Number Generators (QRNGs), some of which are commercially available. In this work, we present the first published analysis of the Quantis family of QRNGs (excluding AIS-31 models), designed and manufactured by ID Quantique (IDQ). Our study also includes Comscire’s PQ32MU QRNG, and two online services: the Australian National University’s (ANU) QRNG, and the Humboldt Physik generator. Each QRNG is analysed using five batteries of statistical tests: Dieharder, National Institute of Standards and Technology (NIST) SP800-22, Ent, Tuftests and TestU01, as part of our thorough examination of their output. Our analysis highlights issues with current certification schemes, which largely rely on NIST SP800-22 and Diehard tests of randomness. We find that more recent tests of randomness identify issues in the output of QRNG, highlighting the need for mandatory post-processing even for low-security usage of random numbers sourced from QRNGs. Darren Hurley-Smith, Julio César Hernández Castro |
ACM Trans. Priv. Secur. | 2 |
| 2018 | Security Analysis of Contiki IoT Operating System
Jack McBride, Budi Arief, Julio César Hernández Castro |
EWSN | 3 |
| 2018 | Certifiably Biased: An In-Depth Analysis of a Common Criteria EAL4+ Certified TRNGabstractThis paper reports the first in-depth analysis of the DESFire EV1's EAL4+ certified TRNG and raises some difficult questions regarding the certification of non-deterministic random number generators. We start by analyzing the quality of the purportedly true random number generator (TRNG) on the DESFire EV1 card. Clear and consistent biases are identified, despite good performance in most randomness tests. These statistical tests, commonly used in popular certification processes, such as Common Criteria EAL4+, are found not to be able to detect these anomalies. The means we employ for the detection and characterization of the bias are explored, highlighting both novel and existing ways of spotting deficient TRNG output. Further analysis shows systemic issues affecting TRNG output at the byte level, for which we have developed an accurate explanation. Our results have been acknowledged by the manufacturer, after responsible disclosure. Darren Hurley-Smith, Julio César Hernández Castro |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2017 | Evolutionary generation and degeneration of randomness to assess the indepedence of the Ent test batteryabstractRandomness tests are a key tool to assess the quality of pseudo-random and true random (physical) number generators. They exploit some properties of random numbers to quantify to what extent the observed behavior of the tested sequence approximates the expected one. Given the many sides of randomness, there is not an unique test providing the whole picture, instead a suite of tests assessing different aspects randomness. A robust test suite must include independent tests, otherwise tests would assess the same property, providing redundant information. This paper addresses the independence assessment of a popular test suite named Ent. To this end we generate a large number of pseudo-random numbers with different degrees of randomness by evolving them with a Genetic Algorithm. The numbers are generated to maximize their diversity attending different criteria based on Ent output, used as fitness. We encourage diversity by maximizing and minimizing randomness measures. Once a diverse set of pseudo-random numbers is generated, the Ent test suite is run on them, and their statistics studied by means of a classical correlation analysis. The results show high correlation among some statistics used in the literature, which could be overestimating the quality of their randomness source. Julio César Hernández Castro, David F. Barrero |
CEC | 1 |
| 2017 | A PRNU-based counter-forensic method to manipulate smartphone image source identification techniques
Luis Javier García Villalba, Ana Lucila Sandoval Orozco, Jocelin Rosales Corripio, Julio César Hernández Castro |
Future Gener. Comput. Syst. | 4 |
| 2017 | Detecting discussion communities on vaccination in twitter
Gema Bello Orgaz, Julio César Hernández Castro, David Camacho |
Future Gener. Comput. Syst. | 2 |
| 2017 | No Bot Expects the DeepCAPTCHA! Introducing Immutable Adversarial Examples, With Applications to CAPTCHA GenerationabstractRecent advances in deep learning (DL) allow for solving complex AI problems that used to be considered very hard. While this progress has advanced many fields, it is considered to be bad news for Completely Automated Public Turing tests to tell Computers and Humans Apart (CAPTCHAs), the security of which rests on the hardness of some learning problems. In this paper, we introduce DeepCAPTCHA, a new and secure CAPTCHA scheme based on adversarial examples, an inherit limitation of the current DL networks. These adversarial examples are constructed inputs, either synthesized from scratch or computed by adding a small and specific perturbation called adversarial noise to correctly classified items, causing the targeted DL network to misclassify them. We show that plain adversarial noise is insufficient to achieve secure CAPTCHA schemes, which leads us to introduce immutable adversarial noise-an adversarial noise that is resistant to removal attempts. In this paper, we implement a proof of concept system, and its analysis shows that the scheme offers high security and good usability compared with the best previously existing CAPTCHAs. Margarita Osadchy, Julio César Hernández Castro, Stuart J. Gibson, Orr Dunkelman, Daniel Pérez-Cabo |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2016 | Identification of smartphone brand and model via forensic video analysis
Luis Javier García Villalba, Ana Lucila Sandoval Orozco, Raquel Ramos López, Julio César Hernández Castro |
Expert Syst. Appl. | 4 |
| 2016 | Image source acquisition identification of mobile devices based on the use of features
Ana Lucila Sandoval Orozco, Jocelin Rosales Corripio, Luis Javier García Villalba, Julio César Hernández Castro |
Multim. Tools Appl. | 4 |
| 2016 | Pitfalls in Ultralightweight Authentication Protocol DesignsabstractThis article introduces prudent engineering practices and offers recommendations to follow, together with typical mistakes to avoid, when designing new ultralightweight authentication protocols. This work can help, as a sanity check, designers of RFID, NFC, and sensor networks based security solutions to improve the security, reliability, and longevity of ultralightweight authentication protocol designs. Additionally, it aims to help reviewers to quickly distinguish what is really new and worthy in a research area that has been flooded lately with proposals of dubious quality. Gildas Avoine, Xavier Carpent, Julio César Hernández Castro |
IEEE Trans. Mob. Comput. | 3 |
| 2015 | On the limits of engine analysis for cheating detection in chess
David J. Barnes, Julio César Hernández Castro |
Comput. Secur. | 2 |
| 2015 | Smartphone image acquisition forensics using sensor fingerprintabstractThe forensic analysis of digital images from mobile devices is particularly important given their quick expansion and everyday use in the society. A further consequence of digital images' widespread use is that they are used today as silent witnesses in legal proceedings, as crucial evidence of the crime. This study specifically addresses the description of a technique that allows the identification of the image source acquisition, for the specific case of mobile devices images. This approach is to extract wavelet‐based features from sensor pattern noise which are then classified using a support vector machine. Moreover, there are a number of parameters that allows the authors to adapt the execution of the algorithm to specific situations desired for the forensic analyst (a variety of types and sizes of image or optimising the average accuracy rate in terms of processing time). This article describes a set of experiments with the same set of images that can obtain general conclusions for the different configurations. Ana Lucila Sandoval Orozco, Luis Javier García Villalba, David Manuel Arenas González, Jocelin Rosales Corripio, Julio César Hernández Castro, Stuart J. Gibson |
IET Comput. Vis. | 5 |
| 2015 | Analysis of errors in exif metadata on mobile devices
Ana Lucila Sandoval Orozco, David Manuel Arenas González, Luis Javier García Villalba, Julio César Hernández Castro |
Multim. Tools Appl. | 4 |
| 2014 | A genetic tango attack against the David-Prasad RFID ultra-lightweight authentication protocolabstractAbstract Radio frequency identification (RFID) is a powerful technology that enables wireless information storage and control in an economical way. These properties have generated a wide range of applications in different areas. Due to economic and technological constrains, RFID devices are seriously limited, having small or even tiny computational capabilities. This issue is particularly challenging from the security point of view. Security protocols in RFID environments have to deal with strong computational limitations, and classical protocols cannot be used in this context. There have been several attempts to overcome these limitations in the form of new lightweight security protocols designed to be used in very constrained (sometimes called ultra‐lightweight) RFID environments. One of these proposals is the David–Prasad ultra‐lightweight authentication protocol. This protocol was successfully attacked using a cryptanalysis technique named Tango attack. The capacity of the attack depends on a set of boolean approximations. In this paper, we present an enhanced version of the Tango attack, named Genetic Tango attack, that uses Genetic Programming to design those approximations, easing the generation of automatic cryptanalysis and improving its power compared to a manually designed attack. Experimental results are given to illustrate the effectiveness of this new attack. David F. Barrero, Julio César Hernández Castro, Pedro Peris-Lopez, David Camacho, María Dolores Rodríguez-Moreno |
Expert Syst. J. Knowl. Eng. | 2 |
| 2013 | Cryptanalysis of the RNTS system
Pablo Picazo-Sanchez, Lara Ortiz-Martin, Pedro Peris-Lopez, Julio César Hernández Castro |
J. Supercomput. | 4 |
| 2012 | Another Fallen Hash-Based RFID Authentication Protocol
Julio César Hernández Castro, Pedro Peris-Lopez, Masoumeh Safkhani, Nasour Bagheri, Majid Naderi |
WISTP | 1 |
| 2012 | Bypassing information leakage protection with trusted applications
Jorge Blasco Alís, Julio César Hernández Castro, Juan Tapiador, Arturo Ribagorda |
Comput. Secur. | 2 |
| 2012 | A framework for avoiding steganography usage over HTTP
Jorge Blasco Alís, Julio César Hernández Castro, José María de Fuentes, Benjamín Ramos |
J. Netw. Comput. Appl. | 2 |
| 2012 | A secure distance-based RFID identification protocol with an off-line back-end databaseabstractThe design of a secure RFID identification scheme is a thought-provoking challenge, and this paper deals with this problem adopting a groundbreaking approach. The proposed protocol, called Noent, is based on cryptographic puzzles to avoid the indiscriminate disclose of the confidential information stored on tags and on an innovative role reversal distance-bounding protocol to distinguish between honest and rogue readers. The protocol provides moderate privacy protection (data and location) to single tags but its effectiveness increases hugely when it is used to protect a large population of tags (e.g., protection against inventory disclosure). Moreover, in comparison with classical approaches, Noent does not require an on-line database, which facilitates key updating and mitigates desynchronization attacks. Pedro Peris-Lopez, Agustín Orfila, Esther Palomar, Julio César Hernández Castro |
Pers. Ubiquitous Comput. | 4 |
| 2011 | AKARI-X: A pseudorandom number generator for secure lightweight systemsabstractIn order to obtain more secure and reliable systems, the vast majority of RFID protocols include a Pseudorandom Number Generator (PRNG) in its design. However, the authors often do not specify the PRNG to use and standard solutions exceed the capabilities of low-cost RFID tags. In this paper, we propose two lightweight PRNGs (AKARI-1 and AKARI-2) that meet the requirements of these systems while improving their reliability and security. They may be supported on commercial tags of low price. Honorio Martín, Enrique San Millán, Luis Entrena, Julio César Hernández Castro, Pedro Peris-Lopez |
IOLTS | 4 |
| 2011 | On the Strength of Egglue and Other Logic CAPTCHAs
Carlos Javier Hernández-Castro, Arturo Ribagorda, Julio César Hernández Castro |
SECRYPT | 3 |
| 2011 | Cryptanalysis of an EPC Class-1 Generation-2 standard compliant authentication protocol
Pedro Peris-Lopez, Julio César Hernández Castro, Juan Tapiador, Jan C. A. van der Lubbe |
Eng. Appl. Artif. Intell. | 2 |
| 2011 | Flaws on RFID grouping-proofs. Guidelines for future sound protocols
Pedro Peris-Lopez, Agustín Orfila, Julio César Hernández Castro, Jan C. A. van der Lubbe |
J. Netw. Comput. Appl. | 3 |
| 2010 | Quasi-Linear Cryptanalysis of a Secure RFID Ultralightweight Authentication Protocol
Pedro Peris-Lopez, Julio César Hernández Castro, Raphael C.-W. Phan, Juan Tapiador, Tieyan Li |
Inscrypt | 2 |
| 2010 | Fine-Grained Timing Using Genetic Programming
David Robert White, Juan Tapiador, Julio César Hernández Castro, John A. Clark |
EuroGP | 3 |
| 2010 | A Strong Authentication Protocol Based on Portable One-Time Dynamic URLsabstractThis work proposes a new strong authentication protocol for the prevention of identity and private personal data theft suffered by users in the Internet. Identity theft is a problem of rising impact amongst Internet users and service providers and it occurs, very frequently, through techniques like phishing. The main reason for the high rates of success is user unexperience and their inability to pay attention to the details that allow them to tell a legitimate site from its fake version. In this paper we present a new strong 3-phase authentication protocol which makes use of Portable One-Time Dynamic URLs for the prevention of identity theft over the Internet. Moreover, a prototype of such a scheme has been implemented to measure the usability and scalability of the proposal. Elena Castro, Julio César Hernández Castro, Almudena Alcaide, Arturo Ribagorda |
Web Intelligence | 2 |
| 2010 | Vulnerability analysis of RFID protocols for tag ownership transfer
Pedro Peris-Lopez, Julio César Hernández Castro, Juan Tapiador, Tieyan Li, Yingjiu Li |
Comput. Networks | 2 |
| 2009 | Weaknesses in Two Recent Lightweight RFID Authentication Protocols
Pedro Peris-Lopez, Julio César Hernández Castro, Juan Tapiador, Tieyan Li, Jan C. A. van der Lubbe |
Inscrypt | 2 |
| 2009 | Metaheuristic traceability attack against SLMAP, an RFID lightweight authentication protocolabstractWe present a metaheuristic-based attack against the traceability of an ultra-lightweight authentication protocol for RFID environments called SLMAP, and analyse its implications. The main interest of our approach is that it is a complete black-box technique that doesn't make any assumptions on the components of the underlying protocol and can thus be easily generalised to analyse many other proposals. Julio César Hernández Castro, Juan Tapiador, Pedro Peris-Lopez, John A. Clark, El-Ghazali Talbi |
IPDPS | 1 |
| 2009 | Steganalysis of Hydan
Jorge Blasco Alís, Julio César Hernández Castro, Juan Tapiador, Arturo Ribagorda, Miguel A. Orellana-Quiros |
SEC | 2 |
| 2009 | Practical attacks on a mutual authentication scheme under the EPC Class-1 Generation-2 standard
Pedro Peris-Lopez, Tieyan Li, Julio César Hernández Castro, Juan Tapiador |
Comput. Commun. | 3 |
| 2008 | On the Salsa20 Core Function
Julio César Hernández Castro, Juan Tapiador, Jean-Jacques Quisquater |
FSE | 1 |
| 2008 | Nature-Inspired Synthesis of Rational Protocols
Almudena Alcaide, Juan Tapiador, Julio César Hernández Castro, Arturo Ribagorda |
PPSN | 3 |
| 2008 | CSteg: Talking in C Code - Steganography of C Source Code in Text
Jorge Blasco Alís, Julio César Hernández Castro, Juan Tapiador, Arturo Ribagorda |
SECRYPT | 2 |
| 2008 | Secure content access and replication in pure P2P networks
Esther Palomar, Juan Tapiador, Julio César Hernández Castro, Arturo Ribagorda |
Comput. Commun. | 3 |
| 2008 | On the Distinguishability of Distance-Bounded Permutations in Ordered ChannelsabstractOrdered channels, such as those provided by Internet protocol and transmission control protocol protocols, rely on sequence numbers to recover from packet reordering due to network dynamics. The existence of covert channels in any ordered channel is a well-known fact: Two parties can reorder the elements (packets) to be sent according to some predefined code. Schemes based on distance-bounded permutations have been proposed for steganographic communication with the aim of keeping and controling the increase of latency due to reordering. In this paper, we demonstrate that distance-bounded permutations are highly anomalous from a metric point of view. Our analysis is based on the study of the distribution of distances between normal permutations generated by the channel, and those produced when embedding hidden information. We provide results for four different distances: Kendall's tau, Spearman's rho, Spearman's footrule, and Levenshtein's distance (which is equivalent to Ulam's distance for permutations). In all cases, it is shown how sequences with hidden information can be separated from the normal ones. As a result, very accurate and efficient distinguishers can be easily constructed. Finally, we study the detection capabilities of the associated detectors through a receiver operating characteristic analysis. Juan Tapiador, Julio César Hernández Castro, Almudena Alcaide, Arturo Ribagorda |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2007 | Heuristic search for non-linear cryptanalytic approximationsabstractIn this work, we show that heuristic techniques (particularly Simulated Annealing) can be successfully applied in the search of good non-linear approximations of cryptographic primitives. We also provide some experimental results, including two excellent non-linear approximations for the output of the Salsa20 stream cipher with 2 and 4 rounds. From these two approximations, very efficient distinguishers for Salsa20 could easily be obtained, leading to a much more practical attack that any other published so far against this cipher. Juan Tapiador, Julio César Hernández Castro, John A. Clark |
IEEE Congress on Evolutionary Computation | 2 |
| 2007 | Non-linear Cryptanalysis Revisited: Heuristic Search for Approximations to S-Boxes
Juan Tapiador, John A. Clark, Julio César Hernández Castro |
IMACC | 3 |
| 2006 | Wheedham: An Automatically Designed Block Cipher by means of Genetic ProgrammingabstractIn this work, we present a general scheme for the design of block ciphers by means of Genetic Programming. In this vein, we try to evolve highly nonlinear and efficient functions to be used for the key expansion and the F-function of a Feistel network. Following this scheme, we propose a new block cipher design called Wheedham, that operates on 512 bit blocks and keys of 256 bits, of which we offer its C code (directly translated from the GP Trees) and some preliminary security results. Julio César Hernández Castro, Juan Tapiador, Arturo Ribagorda, Benjamín Ramos |
IEEE Congress on Evolutionary Computation | 1 |
| 2006 | Evolving hash functions by means of genetic programmingabstractProceedings of the 8th annual conference on Genetic and evolutionary computation. Seattle, Washington, USA, July 08-12, 2006 César Estébanez, Julio César Hernández Castro, Arturo Ribagorda, Pedro Isasi Viñuela |
GECCO | 2 |
| 2006 | Certificate-based Access Control in Pure P2P NetworksabstractPure peer-to-peer (P2P) networks are characterized as being extremely decentralized and self-organized, properties which are essential in a number of environments, including teamwork, collaborative, and ad-hoc systems. One of the features offered by P2P networks is the possibility of having several replicas of the same content distributed among multiple nodes. Despite its advantages (e.g. robustness and fault tolerance), it is crucial to guarantee content authenticity, as well as to enforce appropriate access control policies. However, the extremely decentralized nature of these environments makes impossible to apply classic solutions that rely on some kind of fixed infrastructure, typically in the form of on-line trusted third parties. In a previous work, we presented a protocol for content authentication based on public key certificates that does not rely on the existence of a public key infrastructure. In this paper, we show how these certificates can be extended to provide authorization capabilities. In our scheme, each peer classifies her contents according to several security labels. Peers allowed to access a given content must have a security clearance of at least the same level that the content's. These security clearances, which take the form of attributes in public key certificates, can be discretionally issued by the content provider Esther Palomar, Juan Tapiador, Julio César Hernández Castro, Arturo Ribagorda |
Peer-to-Peer Computing | 3 |
| 2006 | Finding State-of-the-Art Non-cryptographic Hashes with Genetic Programming
César Estébanez, Julio César Hernández Castro, Arturo Ribagorda, Pedro Isasi Viñuela |
PPSN | 2 |
| 2006 | Lamar: A New Pseudorandom Number Generator Evolved by Means of Genetic Programming
Carlos Lamenca-Martinez, Julio César Hernández Castro, Juan Tapiador, Arturo Ribagorda |
PPSN | 2 |
| 2006 | M2AP: A Minimalist Mutual-Authentication Protocol for Low-Cost RFID Tags
Pedro Peris-Lopez, Julio César Hernández Castro, Juan Tapiador, Arturo Ribagorda |
UIC | 2 |
| 2006 | Steganography in games: A general methodology and its application to the game of Go
Julio César Hernández Castro, Ignacio Blasco-Lopez, Juan Tapiador, Arturo Ribagorda |
Comput. Secur. | 1 |
| 2005 | Attacks on Port Knocking Authentication Mechanism
Antonio Izquierdo Manzanares, Joaquín Torres Márquez, Juan Tapiador, Julio César Hernández Castro |
ICCSA (4) | 4 |
| 2005 | Marketing on Internet Communications Security for Online Bank Transactions
José María Sierra, Julio César Hernández Castro, Eva Ponce, Jaime Manera |
ICCSA (4) | 2 |
| 2004 | New results on the genetic cryptanalysis of TEA and reduced-round versions of XTEAabstractRecently, a simple way of creating very efficient distinguishers for cryptographic primitives such as block ciphers or hash functions, was presented by the authors. Here, this cryptanalysis attack is shown to be successful when applied over reduced round versions of the block cipher XTEA. Additionally, a variant of this genetic attack is introduced and its results over TEA shown to be the most powerful published to date. Julio César Hernández Castro, Pedro Isasi Viñuela |
IEEE Congress on Evolutionary Computation | 1 |
| 2004 | On the design of state-of-the-art pseudorandom number generators by means of genetic programmingabstractThe design of pseudorandom number generators by means of evolutionary computation is a classical problem. Today, it has been mostly and better accomplished by means of cellular automata and not many proposals, inside or outside this paradigm could claim to be both robust (passing all the statistical tests, including the most demanding ones) and fast, as is the case of the proposal we present here. Furthermore, for obtaining these generators, we use a radical approach, where our fitness function is not at all based in any measure of randomness, as is frequently the case in the literature, but of nonlinearity. Efficiency is assured by using only very efficient operators (both in hardware and software) and by limiting the number of terminals in the genetic programming implementation. Julio César Hernández Castro, André Seznec, Pedro Isasi Viñuela |
IEEE Congress on Evolutionary Computation | 1 |
| 2004 | The SAC Test: A New Randomness Test, with Some Applications to PRNG Analysis
Julio César Hernández Castro, José María Sierra, André Seznec |
ICCSA (1) | 1 |
| 2004 | Security Issues in Network File Systems
Antonio Izquierdo Manzanares, José María Sierra, Julio César Hernández Castro, Arturo Ribagorda |
ICCSA (1) | 3 |
| 2004 | Validating the Use of BAN LOGIC
José María Sierra, Julio César Hernández Castro, Almudena Alcaide, Joaquín Torres Márquez |
ICCSA (1) | 2 |
| 2004 | Forecasting Time Series by Means of Evolutionary Algorithms
Cristóbal Luque del Arco-Calderón, Pedro Isasi Viñuela, Julio César Hernández Castro |
PPSN | 3 |
| 2004 | Finding Efficient Distinguishers for Cryptographic Mappings, with an Application to the Block Cipher TEAabstractA simple way of creating new and very efficient distinguishers for cryptographic primitives, such as block ciphers or hash functions, is introduced. This technique is then successfully applied over reduced round versions of the block cipher TEA, which is proven to be weak with less than five cycles. Julio César Hernández Castro, Pedro Isasi Viñuela |
Comput. Intell. | 1 |
| 2004 | Introduction to the Applications of Evolutionary Computation in Computer Security and CryptographyabstractProvides information on the applications of evolutionary computation in computer security and cryptography. Main applications of evolutionary computations in cryptology; Achievements of several researchers in the field of artificial intelligence applications to computer security and cryptology; Examples of successful research. Pedro Isasi Viñuela, Julio César Hernández Castro |
Comput. Intell. | 2 |
| 2004 | Low computational cost integrity for block ciphers
José María Sierra, Julio César Hernández Castro, Narayana Jayaram, Arturo Ribagorda |
Future Gener. Comput. Syst. | 2 |
| 2003 | Finding efficient distinguishers for cryptographic mappings, with an application to the block cipher TEAabstractA simple way of creating new and efficient distinguishers for cryptographic primitives such as block ciphers or hash functions is introduced. This technique is then successfully applied over reduced round versions of the block cipher TEA, which is proven to be weak with less than five rounds. Julio César Hernández Castro, Pedro Isasi Viñuela |
IEEE Congress on Evolutionary Computation | 1 |
| 2003 | On MARS's s-boxes Strength against Linear Cryptanalysis
Carlos Javier Hernández-Castro, Luis Javier García Villalba, Julio César Hernández Castro, José María Sierra |
ICCSA (3) | 3 |
| 2003 | Protection of Multiagent Systems
José María Sierra, Julio César Hernández Castro, Eva Ponce, Arturo Ribagorda |
ICCSA (3) | 2 |
| 2003 | Finding Efficient Nonlinear Functions by Means of Genetic Programming
Julio César Hernández Castro, Pedro Isasi Viñuela, Cristóbal Luque del Arco-Calderón |
KES | 1 |
| 2001 | Distinguishing TEA from a Random Permutation: Reduced Round Versions of TEA Do Not Have the SAC or Do Not Generate Random Numbers
Julio César Hernández Castro, José María Sierra, Arturo Ribagorda, Benjamín Ramos, J. Carlos Mex-Perera |
IMACC | 1 |
| 2001 | Robust New Method in Frequency Domain Watermarking
David Sánchez 0005, Agustín Orfila, Julio César Hernández Castro, José María Sierra |
ISC | 3 |