David Fernández 0002

dblp:56/6459-2 · also David Fernández Cambronero · DBLP profile ↗
← Back
15ranked-venue papers
0as first author
3since 2021 · last 2023
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 2 since 2021Human-computer interaction and ubiquitous computing · 3Computer networks · 2Security and privacy · 2Applied, interdisciplinary, general and emerging computing · 2Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2023 A Feature Selection Approach Towards the Standardization of Network Security Datasets
abstract
The increasing reliance on telematic applications has made networks attractive targets for cybercriminals. To address this concern, securing sensitive data by including a Network Intrusion Detection System (NIDS) is effective and feasible. Several approaches based on machine learning have been proposed to improve the detection accuracy of these systems and overcome associated drawbacks. However, machine learning is poorly adopted in the network domain, mainly because most datasets are outdated and guidance on selecting features that significantly contribute to a more efficient and effective learning process is needed. In this light, this paper proposes a standard set of features by applying feature selection techniques. A search on the feature space is conducted on five datasets to determine the best subset per dataset. The commonalities among the best subsets are then identified to define a standard set. Validation shows that, beyond improving the learning process, feature selection provides encouraging results for standardization of network datasets.
Ricardo Flores Moyano, Alejandro Duque, Daniel Riofrío, Diego S. Benítez, Noel Pérez-Pérez, Maria G. Baldeon Calisto, David Fernández 0002
NetSoft7
2023 Design of a 5G Multimedia Broadcast Application Function Supporting Adaptive Error Recovery
abstract
The demand for mobile multimedia streaming services has been steadily growing in recent years. Mobile multimedia broadcasting addresses the shortage of radio resources but introduces a network error recovery problem. Retransmitting multimedia segments that are not correctly broadcast can cause service disruptions and increased service latency, affecting the quality of experience perceived by end users. With the advent of networking paradigms based on virtualization technologies, mobile networks have been enabled with more flexibility and agility to deploy innovative services that improve the utilization of available network resources. This paper discusses how mobile multimedia broadcast services can be designed to prevent service degradation by using the computing capabilities provided by multiaccess edge computing (MEC) platforms in the context of a 5G network architecture. An experimental platform has been developed to evaluate the feasibility of a MEC application to provide adaptive error recovery for multimedia broadcast services. The results of the experiments carried out show that the proposal provides a flexible mechanism that can be deployed at the network edge to lower the impact of transmission errors on latency and service disruptions.
Carlos M. Lentisco, Luis Bellido, Andrés Cárdenas, Ricardo Flores Moyano, David Fernández 0002
IEEE Trans. Multim.5
2022 Model-Driven Network Monitoring Using NetFlow Applied to Threat Detection
abstract
In recent years, several research works have proposed the analysis of network flow information using machine learning in order to detect threats or anomalous activities. In this sense, NetFlow-based systems stand out as one of the main sources of network flow information. In these systems, NetFlow collectors provide the flow monitoring information to be analyzed, but the particular information structure and format provided by different collector implementations is a recurring problem. In this paper, a new YANG data model is proposed as a standard model to use NetFlow-based monitoring data. In order to validate the proposal, a NetFlow collector incorporating the proposed NetFlow YANG model has been developed, to be integrated in a network scenario in which network flows are analyzed to detect malicious cryptomining activity. This collector extends an existing one, and provides design patterns to incorporate other existing collectors into this common data model. Our results show how, by using the YANG modeling language, network flow information can be handled and aggregated in a formal and unified way that provides flexibility and facilitates data analysis applied to threat detection.
Daniel González-Sánchez, Ignacio Dominguez Martinez-Casanueva, Antonio Pastor 0001, Luis Bellido, Cristina Pinar Muñoz Zamarro, Alejandro Antonio Moreno Sancho, David Fernández 0002, Diego R. López
NetSoft7
2020 An Initial Approach to a Multi-access Edge Computing Reference Architecture Implementation Using Kubernetes
Ignacio Dominguez Martinez-Casanueva, Luis Bellido, Carlos M. Lentisco, David Fernández 0002
BROADNETS4
2019 HoneyDOC: An Efficient Honeypot Architecture Enabling All-Round Design
abstract
Honeypots are designed to trap the attacker with the purpose of investigating its malicious behavior. Owing to the increasing variety and sophistication of cyber attacks, how to capture high-quality attack data has become a challenge in the context of honeypot area. All-round honeypots, which mean a significant improvement in sensibility, countermeasure, and stealth, are necessary to tackle the problem. In this paper, we propose a novel honeypot architecture termed HoneyDOC to support all-round honeypot design and implementation. Our HoneyDOC architecture clearly identifies three essential independent and collaborative modules, Decoy, Captor, and Orchestrator. Based on the efficient architecture, a software-defined networking-enabled honeypot system is designed, which supplies a high programmability for technically sustaining the features for capturing high-quality data. A proof-of-concept system is implemented to validate its feasibility and effectiveness. The experimental results show the benefits by using the proposed architecture compared with the previous honeypot solutions.
Wenjun Fan, Zhihui Du, Max Smith-Creasey, David Fernández 0002
IEEE J. Sel. Areas Commun.4
2017 NFV-based QoS provision for Software Defined Optical Access and residential networks
abstract
The promises of SDN and NFV technologies to boost innovation and to reduce the time-to-market of new services is changing the way in which residential networks will be deployed, managed and maintained in the near future. New user-centric management models for residential networks combining SDN-based residential gateways and cloud technologies have already been proposed, providing flexibility and ease of deployment. Extending the scope of SDN technologies to optical access networks and bringing cloud technologies to the edge of the network enable the creation of advanced residential networks in which complex service function chains can be established to provide traffic differentiation. In this context, this paper defines a novel network management model based on a user-centric approach that allows residential users to define and control access network resources and the dynamic provision of traffic differentiation to fulfill QoS requirements.
Ricardo Flores Moyano, David Fernández 0002, Luis Bellido, Noemí Merayo, Juan Carlos Aguado, Ignacio de Miguel
IWQoS2
2017 A novel SDN based stealthy TCP connection handover mechanism for hybrid honeypot systems
abstract
Honeypots have been largely used to capture and investigate malicious behavior through deliberately sacrificing their own resources in order to be attacked. Hybrid honeypot architectures consisting of frontends and backends are widely used in the research area, specially due to the benefits of their high scalability and fidelity for detailed attacking data collection. A hybrid honeypot system often needs a facility aimed to tightly control the network traffic, for purposes such as redirecting the traffic from the frontends to the backends for in-depth attack analysis. However, the current traffic redirection approaches, particularly the TCP connection handover mechanisms, are not stealthy and they can be easily detected by attackers. This paper proposes an SDN based network data controller for hybrid honeypot systems that uses a transparent TCP connection handover mechanism and provides a traffic filtering approach based on the Snort alert functionality. The controller is implemented as an application based on the open-source Ryu SDN framework. It allows the users to configure their own network data control rules, which based on the Snort alert messages will forward or redirect the traffic to the corresponding honeypots. The experiments validate the proposed mechanism and the testing results show that the controller can efficiently perform the stealthy TCP connection handover as well.
Wenjun Fan, David Fernández 0002
NetSoft2
2017 Versatile virtual honeynet management framework
abstract
Honeypots are designed to investigate malicious behaviour. Each type of homogeneous honeypot system has its own characteristics in respect of specific security functionality, and also suffers functional drawbacks that restrict its application scenario. In practical scenarios, therefore, security researchers always need to apply heterogeneous honeypots to cope with different attacks. However, there is a lack of general tools or platforms that can support versatile honeynet deployment in order to investigate the malicious behavior. In this study, the authors propose a versatile virtual honeynet management tool to address this problem. It is a flexible tool that offers security researchers the versatility to deploy various types of honeypots. It can also generate and manage the virtual honeynet through a dynamic configuration approach adapting to the mutable network environment. The experimental results demonstrate that this tool is effective to perform automated honeynet deployment toward a variety of heterogeneous honeypots.
Wenjun Fan, David Fernández 0002, Zhihui Du
IET Inf. Secur.2
2015 Dynamic Hybrid Honeypot System Based Transparent Traffic Redirection Mechanism
Wenjun Fan, Zhihui Du, David Fernández 0002, Xinning Hui
ICICS3
2015 Technology Independent Honeynet Description Language
abstract
Several languages have been proposed for the task of describing networks of systems, either to help on managing, simulate or deploy testbeds for testing purposes. However, there is no one specifically designed to describe the honeynets, covering the specific characteristics in terms of applications and tools included in the honeypot systems that make the honeynet. In this paper, the requirements of honeynet description are studied and a survey of existing description languages is presented, concluding that a CIM (Common Information Model) match the basic requirements. Thus, a CIM like technology independent honeynet description language (TIHDL) is proposed. The language is defined being independent of the platform where the honeynet will be deployed later, and it can be translated, either using model-driven techniques or other translation mechanisms, into the description languages of honeynet deployment platforms and tools. This approach gives flexibility to allow the use of a combination of heterogeneous deployment platforms. Besides, a flexible virtual honeynet generation tool (HoneyGen) based on the approach and description language proposed and capable of deploying honeynets over VNX (Virtual Networks over LinuX) and Honeyd platforms is presented for validation purposes.
Wenjun Fan, David Fernández 0002, Víctor A. Villagrá
MODELSWARD2
2013 RECLAMO: Virtual and Collaborative Honeynets Based on Trust Management and Autonomous Systems Applied to Intrusion Management
abstract
Security intrusions in large systems is a problem due to its lack of scalability with the current IDS-based approaches. This paper describes the RECLAMO project, where an architecture for an Automated Intrusion Response System (AIRS) is being proposed. This system will infer the most appropriate response for a given attack, taking into account the attack type, context information, and the trust and reputation of the reporting IDSs. RECLAMO is proposing a novel approach: diverting the attack to a specific honey net that has been dynamically built based on the attack information. Among all components forming the RECLAMO's architecture, this paper is mainly focused on defining a trust and reputation management model, essential to recognize if IDSs are exposing an honest behavior in order to accept their alerts as true. Experimental results confirm that our model helps to encourage or discourage the launch of the automatic reaction process.
Manuel Gil Pérez, Verónica Mateos Lanchas, David Fernández 0002, Gregorio Martínez Pérez, Víctor A. Villagrá
CISIS3
2013 Towards a virtualized Internet for computer networking assignments
abstract
By combining virtualization technologies, virtual private network techniques and parameterization of network scenarios it is possible to enhance a networking laboratory, typically carried out in university laboratory premises using equipment located there, by interconnecting it to virtual networks running on the students' own personal computers. This paper describes some experiences applying this model to create hands-on assignments for a large group of students in computer networking education.
Luis Bellido, David Fernández 0002, Encarna Pastor
EDUCON2
2012 New strategies for learning computer networks
abstract
This paper describes experiences in computer networking education with a large number of students based on two kinds of learning activities: personalized exercises and hands-on experiments using virtualization tools. Using an example of each kind of activity the paper explains the process of creating the activity, the software tools that have been developed to support them in the context of a Learning Management System and the impact of the activities in the learning process.
Luis Bellido, David Fernández 0002, Encarna Pastor, Julio Berrocal
EDUCON2
2008 A model-driven configuration management methodology for testbed infrastructures
abstract
Testbeds are controlled experimentation platforms where solutions (software, architectures, etc.) can be developed, deployed and tested in an environment that resembles real utilization conditions. This paper describes a model-driven methodology for automatic testbed reconfiguration which solves the problems of manual interaction and inter-testbed scenario reutilization. It is based in a high-level testbed-independent model of the desired scenario (so it can be applied to any testbed in general) which is particularized to testbed-specific scenario models for automatic deployment and management by model-based tools. The paper also details our practical experiences applying the methodology to two quite different use cases: VNUML-based virtual testbeds and the GMPLS-enabled optical network of ADRENALINE testbed® (each one with its own model-based automatic deployment tools), thus assessing the feasibility and generality of the proposed approach.
Fermín Galán Márquez, Jorge E. López de Vergara, David Fernández 0002, Raul Muñoz 0001
NOMS3
1997 Using multimedia communication technologies in distance learning
Tomás Robles 0001, David Fernández 0002, Encarna Pastor, Santiago Alamillo
ITiCSE2