Mauricio Papa

dblp:46/4926 · DBLP profile ↗
← Back
19ranked-venue papers
4as first author
6since 2021 · last 2026
0009-0000-5628-0548ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Cyber-Physical Windowed Feature Learning for Unsupervised Anomaly Detection in Smart Grid Substations
abstract
Advances in monitoring and control technologies have made modern electric substations more efficient but also more vulnerable to cyber–physical threats. This study investigates anomaly detection by fusing network and load signatures on an automated substation testbed. Network traffic and electrical load variations were captured under three regimes: normal (no load), reasonable load (1–10 A), and overload (11–14 A) using a Chroma programmable AC electronic load device. Cyber features extracted from Common Industrial Protocol (CIP) communications were integrated with physical current measurements and aggregated into fixed temporal windows (5s, 1s, and 0.1s) to evaluate the role of granularity in anomaly detection. The performances of five unsupervised models, including Elliptic Envelope, Local Outlier Factor (LOF), One-Class SVM, MLP Autoencoder, and Isolation Forest models, were compared based on detection rate (DR), false alarm rate (FAR), accuracy, F1-score, AUROC, and AUPRC. Results indicate that window size has a great impact on detection performance, and that 1s window size offers the best compromise between sensitivity and stability. Isolation Forest consistently showed high-recall and low-false-alarm rates, while LOF and Elliptic Envelope were unstable. The above results indicate that the proposed windowed fused feature learning (WFFL) solutions, that include Isolation Forest, are effective in identifying operational anomalies using both digital and physical features.
Momodou Lamin Barrow, Arafat Asim, Alex Howe, Mauricio Papa
CCNC4
2026 Passive Device Fingerprinting for OT Networks Using Byte Histograms
abstract
Device fingerprinting is a promising approach for securing Operational Technology (OT) networks by modeling the communication patterns of each device and using them to classify future network activity. This work proposes three byte-based fingerprinting strategies: byte histograms, n-grams, and machine learning models. Operating directly on raw packet bytes, these methods provide granular, protocol-agnostic fingerprints that avoid reliance on deep packet inspection or domain-specific feature engineering. The three strategies balance complementary strengths: byte histograms excel in modeling device-specific behavior, n-grams capture structural dependencies across consecutive bytes, and machine learning models prove most effective for generalizing to different network architectures. Experimental evaluation across two OT network testbeds demonstrates the robust classification performance for three device identification tasks: device-specific, unknown device, and cross-architecture testing. Results show that byte histograms and machine learning techniques achieve highest accuracy depending on the classification scenario, highlighting the practicality and adaptability of byte-level approaches for real-world OT device identification.
Jack Nunnelee, Alex Howe, Mauricio Papa
CCNC3
2025 Operational Technology Network Anomaly Detection Using N-Grams
Jack Nunnelee, Alex Howe, Mauricio Papa
CRITIS3
2024 Graph Autoencoders for Detecting Anomalous Intrusions in OT Networks Through Dynamic Link Detection
abstract
This paper evaluates the use of graph neural network (GNN) based autoencoders for detecting network intrusions or anomalous traffic in Operational Technology (OT) networks. Traditional intrusion detection methods often struggle to capture the complex relationships and interdependencies found in OT network communications. These spatial relationships can provide information vital for identifying harder to detect attacks (i.e. Advanced Persistent Threats). GNNs are a machine learning technique which operate on graph-structured data and can be used to identify underlying patterns and relationships between the nodes. Graph autoencoders (GAEs) are an unsupervised GNN-based learning technique that incorporates an encoder-decoder architecture and can be used for anomaly detection in graph structured data. This work evaluates the use of graph autoencoders for detecting anomalous edges (extracted from packets) in OT network data. Additionally, we introduce a method for encoding raw network traffic into discrete temporal graphs which can be used to apply GAEs for real-time intrusion detection. The proposed network traffic encoding scheme incorporates multi-dimensional edge attributes in order to capture information for determining the relevance of a given network packet. The approach is evaluated using two OT network datasets each containing labeled examples of commonly encountered malicious attack traffic. Results are compared against baseline anomaly detection methods including K-Nearest Neighbors, Deep Autoencoders, and Isolation Forest. The proposed graph autoencoder outperforms the baseline cases in terms of detection accuracy achieving a 31.05% and 8.64% improvement in F1 scores over the baseline models on the two OT network datasets.
Alex Howe, Dale Peasley, Mauricio Papa
CCNC3
2024 A Cost-Sensitive Approach for Managing Intrusion Alerts in OT Environments
Alex Howe, Andrew Morin, Mauricio Papa, Tyler Moore 0001
CRITIS3
2023 Feature Engineering in Machine Learning-Based Intrusion Detection Systems for OT Networks
abstract
This paper evaluates the importance of feature exploration and engineering when applying machine learning for intrusion detection in OT (Operational Technology) networks. Data used consisted of raw network traffic captures from a simulated OT environment communicating over the Modbus/TCP protocol. Feature engineering efforts identified thirty eight attributes of interest at the different layers of the network stack. The Random Forest algorithm was used to analyze the importance of each feature for the detection of anomalous network behavior. Both supervised and unsupervised learning methods were evaluated including Random Forest, Support Vector Machines, K-Nearest Neighbors, K-Means Clustering, and Isolation Forest. Results indicate that statistical based features as well as features derived from the protocol and application layers contained information best suited for detecting anomalous OT behavior. Additionally, variable importance-based feature selection helped reduce complexity and improved detection rate when compared with models trained on the original high dimensional data. Random Forest and Support Vector Machines had the best detection performance but required a large amount of labeled data for training and validation. Notably, Isolation Forest shows potential for anomaly detection in OT networks as it requires no labeled data and produced promising results.
Alex Howe, Mauricio Papa
SMARTCOMP2
2006 An Architecture for SCADA Network Forensics
Tim Kilpatrick, Jesús González 0004, Rodrigo Chandia, Mauricio Papa, Sujeet Shenoi
IFIP Int. Conf. Digital Forensics4
2005 A Framework for Hybrid Fuzzy Logic Intrusion Detection Systems
abstract
This paper describes a framework for implementing intrusion detection systems using fuzzy logic. A fuzzy data-mining algorithm is used to extract fuzzy rules for the inference engine. The modular architecture is implemented using the Java expert system shell (Jess) and the FuzzyJess toolkit developed by Sandia National Laboratories and the National Research Council of Canada respectively. Experimental results for a hybrid prototype system using anomaly-based and fuzzy signatures are provided using data sets from MIT Lincoln Laboratory
Aly El-Semary, Janica Edmonds, Jesús González 0004, Mauricio Papa
FUZZ-IEEE4
2003 Integrating Logics and Process Calculi for Cryptographic Protocol Analysis
Mauricio Papa, Oliver Bremer, John Hale, Sujeet Shenoi
SEC1
2003 Programmable Access Control
abstract
Software developers rely on sophisticated programming language protection models and APIs to manifest security policies for Internet applications. These tools do not provide suitable expressiveness for fine-grained, configurable policies. Nor do they ensure the consistency of a given policy impleme ntation across objects in a heterogeneous environment. Programmable access control provides syntactic and semantic constructs in programming languages for systematically embedding security functionality within applications. Secure interoperability is of utmost importance in a distributed heterogeneous environment. This paper introduces a methodology for programmable security by language extension, as well as a prototype model and implementation of JPAC, a programmable access control extension to Java. A coordination language is also presented to support secure interoperability within the framework.
John Hale, Mauricio Papa, Sujeet Shenoi
J. Comput. Secur.2
2002 On Modeling Computer Networks for Vulnerability Analysis
Clinton Campbell, Jerald Dawkins, Brandon Pollet, Kenneth Fitch, John Hale, Mauricio Papa
DBSec6
2002 Implementation and Verification of Programmable Security
Stephen Magill, Bradley Skaggs, Mauricio Papa, John Hale
DBSec3
2001 Formal Analysis of E-Commerce Protocols
abstract
The paper presents a formalism for the analysis of e-commerce protocols. The approach integrates logics and process calculi, providing an expressive message passing semantics and sophisticated constructs for modeling principals. A common set of inference rules for communication, reduction and information analysis supports proofs about message passing, the knowledge and behavior of principals, and protocol properties. The power of the formalism is illustrated with an analysis of the NetBill Protocol.
Mauricio Papa, Oliver Bremer, John Hale, Sujeet Shenoi
ISADS1
2001 Evaluating controller robustness using cell mapping
Mauricio Papa, Jason Wood, Sujeet Shenoi
Fuzzy Sets Syst.1
2000 Extending Java for Package based Access Control
abstract
This paper describes an extension of the Java language that provides programmable security. The approach augments the Java syntax with constructs for specifying various access control policies for Java packages, including DAC, MAC, RBAC and TBAC. A primitive ticket based mechanism serves as the foundation for programmable security. The implementation incorporates a preprocessor for language translation and a security service library that implements the ticket management infrastructure. The preprocessor translates the extended Java source code to native Java for eventual bytecode interpretation simultaneously binding security services to the native code. The design is simple and flexible and provides developers with an effective tool for programming security within Java packages.
John Hale, Mauricio Papa, Oliver Bremer, Rodrigo Chandia, Sujeet Shenoi
ACSAC2
2000 Simulation and Analysis of Cryptographic Protocols
Mauricio Papa, Oliver Bremer, Stephen Magill, John Hale, Sujeet Shenoi
DBSec1
1999 Security Policy Coordination for Heterogeneous Information Systems
abstract
Coordinating security policies in information enclaves is challenging due to their heterogeneity and autonomy. Administrators must reconcile the semantic diversity of data and security models before negotiating secure interoperation. This paper proposes an architecture that uses mediators and a primitive ticket-based authorization model to manage disparate policies in information enclaves. The formal foundation of the architecture facilitates static and dynamic analysis of global consistency and policy enforcement.
John Hale, Pablo Galiasso, Mauricio Papa, Sujeet Shenoi
ACSAC3
1998 Programmable Security for Object-Oriented Systems
John Hale, Mauricio Papa, Sujeet Shenoi
DBSec2
1997 An Environment for Developing Securely Interoperable Heterogeneous Distributed Objects
M. Berryman, C. Rummel, Mauricio Papa, John Hale, Jody Threet, Sujeet Shenoi
DBSec3