VLDB 2026 Research / reviewers in the wild / expert
Gabriel Maciá-Fernández
dblp:65/5024
· DBLP profile ↗
34ranked-venue papers
12as first author
8since 2021 · last 2026
0000-0001-9256-453XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 7 first-author · 2 since 2021Computer networks · 15 · 5 first-author · 6 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | IBRAM: Internet Background Radiation Analysis MethodologyabstractInternet Background Radiation (IBR) is unsolicited traffic captured by network telescopes, primarily composed of scanning activity, denial-of-service backscatter, and misconfigurations. Its analysis provides a valuable source of cyberintelligence for identifying attack trends, emerging vulnerabilities, and malicious payloads. However, existing analysis approaches lack a standardized methodology tailored to IBR’s distinctive characteristics, and conventional flow abstractions such as NetFlow’s 5-tuple are ill-suited for IBR traffic, where over 96% of TCP flows consist of a single packet. This article introduces IBRAM (Internet Background Radiation Analysis Methodology), a structured and modular methodology for IBR traffic analysis comprising three phases: scope definition, iterative processing (normalization, reassembly, aggregation, enrichment, and correlation), and analysis. Central to IBRAM is the concept of IBRflow, a flow abstraction specifically designed for IBR traffic that supports flexible, payload-aware aggregation and hierarchical composition into higher-level structures called IBRevents, enabling the correlation of related scanning activities across protocols. The methodology is validated through a case study using 67 million packets captured over 31 days by a/24 network telescope, demonstrating that iterative IBRflow aggregation can reduce ICMP traffic to a small set of flows representing over 97% of packets while preserving traffic intent. The analysis reproduces findings consistent with prior IBR studies and reveals cross-protocol scanning patterns through IBRevents correlation. Both the analysis tools and the dataset have been made publicly available to the community. Rodolfo García-Peñas, Rafael Rodríguez-Gómez, Gabriel Maciá-Fernández |
Comput. Networks | 3 |
| 2025 | Characterizing Internet Background Traffic from a Spain-Based Network TelescopeabstractInternet background traffic (or Internet Background Radiation, IBR) consists of unsolicited packets. It is traffic usually generated in the preliminary phases of attacks by computers making enumerations of targets and available services, sent as responses to denial of service attacks, or sent by mistake due to incorrect configurations and commands. Capturing and analysing this traffic enables the observation of Internet activity and serves as an important tool for identifying new types of attacks and attackers. This traffic is captured by “network telescopes”, nodes that advertise blocks of unused IP addresses and store the traffic sent to them. This article studies the traffic received by a network telescope located in Spain during 2023, with more than 4.7 billion packets and 362.39 GB of information. A statistical breakdown of the packets by protocol shows that TCP accounts for 95.96%, UDP for 3.74%, and ICMP for 0.51%. In addition, the behaviour of the traffic generators targeting the telescope’s addresses is examined, and the main attacks – such as NTP and DNS reflection – are analysed. The characteristics of the traffic are compared with those of previous studies, highlighting changes in behaviour and the most common attacks. Rodolfo García-Peñas, Rafael Rodríguez-Gómez, Gabriel Maciá-Fernández |
Comput. Secur. | 3 |
| 2024 | Collaborative credentials for the Internet of ThingsabstractThe Self-Sovereign Identity (SSI) paradigm has emerged as a decentralized Identity Management model with interesting capabilities for the Internet of Things (IoT). However, current standard SSI protocols and procedures only consider that individuals store their own identity, failing to provide an accurate solution for the identity management of groups where participants might use credentials from different identities and collaborate to meet a set of verifier´s requirements. The present work introduces the concept of Collaborative Credentials (CCs) to formalize identity management procedures that model the collaboration within a group of participants. CCs allow to leverage use cases requiring collaboration that cannot be solved with standard SSI verifiable credentials, increase the privacy of group participants and enable the development of a software framework that any verifier/holder could use to generate a generic application. In the paper, a generic model for CCs is presented, together with an implementation example that is subsequently evaluated in an experimental testbed. Santiago de Diego, Cristina Regueiro, Gabriel Maciá-Fernández |
Comput. Networks | 3 |
| 2024 | HoDiNT: Distributed architecture for collection and analysis of Internet Background RadiationabstractAttacks on the Internet are constant, with different typologies and processes. The initial stages usually involve an enumeration of targets and available services, generating what is known as Internet Background Radiation (IBR). Capturing and analysing this traffic has proven to be crucial for the early identification and detection of attacks. Commonly used architectures for the acquisition of background traffic are based on “black holes”, which are systems that collect this traffic by advertising large blocks of unused IP addresses to the Internet, identifying the traffic received as IBR. These systems have a number of inherent drawbacks, such as the requirement to process large volumes of data, and deal with the existence of a large amount of repetitive data, the fact that they are easily identifiable by the IP addresses used and, finally, that they are expensive to maintain. With the aim of improving the above undesired characteristics, this paper proposes “HoDiNT” (HOme DIstributed Network Telescope), a distributed architecture for the acquisition of Internet Background Radiation. HoDiNT is implemented with low-cost advanced acquisition techniques and without the need to use specific IP address ranges, making it easier to hide the sensors. An initial scan of the traffic received for one month is performed on the probes deployed, and a subsequent analysis is performed on the collected data to draw conclusions. Rodolfo García-Peñas, Rafael Rodríguez-Gómez, Gabriel Maciá-Fernández |
Comput. Networks | 3 |
| 2022 | Bypassing Current Limitations for Implementing a Credential Delegation for the Industry 4.0abstractPublisher Copyright: © 2021 by SCITEPRESS – Science and Technology Publications, Lda. All rights reserved. Santiago de Diego, Oscar Lage, Cristina Regueiro, Sergio Anguita, Gabriel Maciá-Fernández |
SECRYPT | 5 |
| 2022 | A novel zero-trust network access control scheme based on the security profile of devices and users
Pedro García-Teodoro, José Camacho 0001, Gabriel Maciá-Fernández, José Antonio Gómez-Hernández, Victor José López-Marín |
Comput. Networks | 3 |
| 2022 | Leveraging a Probabilistic PCA Model to Understand the Multivariate Statistical Network Monitoring Framework for Network Security Anomaly DetectionabstractNetwork anomaly detection is a very relevant research area nowadays, especially due to its multiple applications in the field of network security. The boost of new models based on variational autoencoders and generative adversarial networks has motivated a reevaluation of traditional techniques for anomaly detection. It is, however, essential to be able to understand these new models from the perspective of the experience attained from years of evaluating network security data for anomaly detection. In this paper, we revisit anomaly detection techniques based on PCA from a probabilistic generative model point of view, and contribute a mathematical model that relates them. Specifically, we start with the probabilistic PCA model and explain its connection to the Multivariate Statistical Network Monitoring (MSNM) framework. MSNM was recently successfully proposed as a means of incorporating industrial process anomaly detection experience into the field of networking. We have evaluated the mathematical model using two different datasets. The first, a synthetic dataset created to better understand the analysis proposed, and the second, UGR’16, is a specifically designed real-traffic dataset for network security anomaly detection. We have drawn conclusions that we consider to be useful when applying generative models to network security detection. Fernando Pérez-Bueno, Luz García 0001, Gabriel Maciá-Fernández, Rafael Molina 0001 |
IEEE/ACM Trans. Netw. | 3 |
| 2021 | Unveiling the I2P web structure: A connectivity analysisabstractWeb is a primary and essential service to share information among users and organizations at present all over the world. Despite the current significance of such a kind of traffic on the Internet, the so-called Surface Web traffic has been estimated in just about 5% of the total. The rest of the volume of this type of traffic corresponds to the portion of Web known as Deep Web. These contents are not accessible by search engines because they are authentication protected contents or pages that are only reachable through the well known as darknets. To browse through darknets websites special authorization or specific software and configurations are needed. Despite TOR is the most used darknet nowadays, there are other alternatives such as I2P or Freenet, which offer different features for end users. In this work, we perform an analysis of the connectivity of websites in the I2P network (named eepsites) aimed to discover if different patterns and relationships from those used in legacy web are followed in I2P, and also to get insights about its dimension and structure. For that, a novel tool is specifically developed by the authors and deployed on a distributed scenario. Main results conclude the decentralized nature of the I2P network, where there is a structural part of interconnected eepsites while other several nodes are isolated probably due to their intermittent presence in the network. Roberto Magán-Carrión, Alberto Abellán-Galera, Gabriel Maciá-Fernández, Pedro García-Teodoro |
Comput. Networks | 3 |
| 2019 | Multivariate Big Data Analysis for intrusion detection: 5 steps from the haystack to the needle
José Camacho 0001, José Manuel García-Giménez, Noemí Marta Fuentes García, Gabriel Maciá-Fernández |
Comput. Secur. | 4 |
| 2019 | Semi-Supervised Multivariate Statistical Network Monitoring for Learning Security ThreatsabstractThis paper presents a semi-supervised approach for intrusion detection. The method extends the unsupervised multivariate statistical network monitoring approach based on the principal component analysis by introducing a supervised optimization technique to learn the optimum scaling in the input data. It inherits the advantages of the unsupervised strategy, capable of uncovering new threats, with that of supervised strategies, capable of learning the pattern of a targeted threat. The supervised learning is based on an extension of the gradient descent method based on partial least squares (PLS). Moreover, we enhance this method by using sparse PLS variants. The practical application of the system is demonstrated on a recently published real case study, showing relevant improvements in detection performance and in the interpretation of the attacks. José Camacho 0001, Gabriel Maciá-Fernández, Noemí Marta Fuentes García, Edoardo Saccenti |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | UGR'16: A new dataset for the evaluation of cyclostationarity-based network IDSs
Gabriel Maciá-Fernández, José Camacho 0001, Roberto Magán-Carrión, Pedro García-Teodoro, Roberto Therón |
Comput. Secur. | 1 |
| 2017 | Network-wide intrusion detection supported by multivariate analysis and interactive visualizationabstractIn this paper, we introduce a new visualization tool for network-wide intrusion detection. It is based in multivariate anomaly detection with a combination between Principal Component Analysis (PCA) and a new variant called Group-wise PCA (GPCA). Combining these methodologies with the capabilities of interactive visualization, the resulting tool is a highly flexible and intuitive interface that allows the user to navigate through the enormous amount of data collected in the network, in order to find anomalous or unexpected behaviors. We use a real case study to illustrate the capability of the tool to unveil the complex mixture of information that can be found in network security/traffic data and identify and diagnose anomalies in it. Roberto Therón, Roberto Magán-Carrión, José Camacho 0001, Gabriel Maciá-Fernández |
VizSEC | 4 |
| 2016 | PCA-based multivariate statistical network monitoring for anomaly detection
José Camacho 0001, Alejandro Pérez-Villegas, Pedro García-Teodoro, Gabriel Maciá-Fernández |
Comput. Secur. | 4 |
| 2015 | A model of data forwarding in MANETs for lightweight detection of malicious packet dropping
Leovigildo Sánchez-Casado, Gabriel Maciá-Fernández, Pedro García-Teodoro, Roberto Magán-Carrión |
Comput. Networks | 2 |
| 2015 | Identification of contamination zones for sinkhole detection in MANETs
Leovigildo Sánchez-Casado, Gabriel Maciá-Fernández, Pedro García-Teodoro, Nils Aschenbruck |
J. Netw. Comput. Appl. | 2 |
| 2014 | Resource monitoring for the detection of parasite P2P botnets
Rafael Rodríguez-Gómez, Gabriel Maciá-Fernández, Pedro García-Teodoro, Moritz Steiner, Davide Balzarotti |
Comput. Networks | 2 |
| 2013 | Stochastic Traffic Identification for Security Management: eDonkey Protocol as a Case Study
Rafael Rodríguez-Gómez, Gabriel Maciá-Fernández, Pedro García-Teodoro |
NSS | 2 |
| 2013 | A model-based survey of alert correlation techniques
Saeed Salah, Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo |
Comput. Networks | 2 |
| 2012 | An Efficient Cross-Layer Approach for Malicious Packet Dropping Detection in MANETsabstractThis paper introduces a novel IDS approach for detecting malicious packet dropping behaviors in MANETs. Although some similar proposals can be found in the specialized literature, two main differences exist with ours. First, mobility aspects are explicitly considered into the approach by means of a heuristic which considers the operation of the forwarding process at the nodes. Second, this fact results in a significant improvement in the detection performance of the system, especially in terms of low false positive rate. The different experimental results obtained show the promising nature of our approach, both in terms of the detection capabilities exhibited and from the point of view of the simplicity of the scheme. Leovigildo Sánchez-Casado, Gabriel Maciá-Fernández, Pedro García-Teodoro |
TrustCom | 2 |
| 2012 | Extracting user web browsing patterns from non-content network traces: The online advertising case study
Gabriel Maciá-Fernández, Rafael Rodríguez-Gómez, Aleksandar Kuzmanovic |
Comput. Networks | 1 |
| 2011 | Understanding the Network and User-Targeting Properties of Web Advertising NetworksabstractAdvertising has become an integral and inseparable part of the World Wide Web. However, neither public auditing nor monitoring mechanisms still exist in this emerging area. In this paper, we present our initial efforts on building a network and content-level auditing service for Web-based ad networks. Our network-level measurements -- charting the network infrastructure and quantifying the ad platforms' delay performance -- can help commissioners to evaluate their networks from end users' perspective, and let advertisers choose commissioners that better fit their needs. Our content-level measurements -- understanding the ad distribution mechanisms and evaluating location-based and behavioral targeting approaches -- bring useful auditing information to all entities involved in the on line advertising business. We extensively evaluate Google's, AOL's, and Ad blade's ad networks and demonstrate how their different design philosophies dominantly affect their performance at both network and content levels. Daniel Burgener, Aleksandar Kuzmanovic, Gabriel Maciá-Fernández |
ICDCS | 4 |
| 2011 | Analysis of Botnets through Life-cycle
Rafael Rodríguez-Gómez, Gabriel Maciá-Fernández, Pedro García-Teodoro |
SECRYPT | 2 |
| 2010 | ISP-Enabled Behavioral Ad Targeting without Deep Packet InspectionabstractOnline advertising is a rapidly growing industry currently dominated by the search engine 'giant' Google. In an attempt to tap into this huge market, Internet Service Providers (ISPs) started deploying deep packet inspection techniques to track and collect user browsing behavior. However, such techniques violate wiretap laws that explicitly prevent intercepting the contents of communication without gaining consent from consumers. In this paper, we show that it is possible for ISPs to extract user browsing patterns without inspecting contents of communication. Our contributions are threefold. First, we develop a methodology and implement a system that is capable of extracting web browsing features from stored non-content based records of online communication, which could be legally shared. When such browsing features are correlated with information collected by independently crawling the Web, it becomes possible to recover the actual web pages accessed by clients. Second, we systematically evaluate our system on the Internet and demonstrate that it can successfully recover user browsing patterns with high accuracy. Finally, our findings call for a comprehensive legislative reform that would not only enable fair competition in the online advertising business, but more importantly, protect the consumer rights in a more effective way. Gabriel Maciá-Fernández, Rafael Rodríguez-Gómez, Aleksandar Kuzmanovic |
INFOCOM | 1 |
| 2010 | Analyzing content-level properties of the web adversphereabstractAdvertising has become an integral and inseparable part of the World Wide Web. However, neither public auditing nor monitoring mechanisms still exist in this emerging area. In this paper, we present our initial efforts on building a content-level auditing service for web-based ad networks. Our content-level measurements - understanding the ad distribution mechanisms and evaluating location-based and behavioral targeting approaches - bring useful auditing information to all entities involved in the online advertising business. We extensively evaluate Google's, AOL's, and Adblade's ad networks and demonstrate how their different design philosophies dominantly affect their performance at the content level. Daniel Burgener, Aleksandar Kuzmanovic, Gabriel Maciá-Fernández |
WWW | 4 |
| 2010 | Defense techniques for low-rate DoS attacks against application servers
Gabriel Maciá-Fernández, Rafael Rodríguez-Gómez, Jesús Esteban Díaz Verdejo |
Comput. Networks | 1 |
| 2009 | Anomaly-based network intrusion detection: Techniques, systems and challenges
Pedro García-Teodoro, Jesús Esteban Díaz Verdejo, Gabriel Maciá-Fernández, Enrique Vázquez |
Comput. Secur. | 3 |
| 2009 | Mathematical model for low-rate DoS attacks against application serversabstractIn recent years, variants of denial of service (DoS) attacks that use low-rate traffic have been proposed, including the Shrew attack, reduction of quality attacks, and low-rate DoS attacks against application servers (LoRDAS). All of these are flooding attacks that take advantage of vulnerability in the victims for reducing the rate of the traffic. Although their implications and impact have been comprehensively studied, mainly by means of simulation, there is a need for mathematical models by which the behaviour of these sometimes complex processes can be described. In this paper, we propose a mathematical model for the LoRDAS attack. This model allows us to evaluate its performance by relating it to the configuration parameters of the attack and the dynamics of network and victim. The model is validated by comparing the performance values given against those obtained from a simulated environment. In addition, some applicability issues for the model are contributed, together with interpretation guidelines to the model's behaviour. Finally, experience of the model enables us to make some recommendations for the challenging task of building defense techniques against this attack. Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo, Pedro García-Teodoro |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2008 | Evaluation of a low-rate DoS attack against application servers
Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo, Pedro García-Teodoro |
Comput. Secur. | 1 |
| 2007 | LoRDAS: A Low-Rate DoS Attack against Application Servers
Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo, Pedro García-Teodoro, Francisco de Toro-Negro |
CRITIS | 1 |
| 2007 | Evaluation of a low-rate DoS attack against iterative servers
Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo, Pedro García-Teodoro |
Comput. Networks | 1 |
| 2006 | Assessment of a Vulnerability in Iterative Servers Enabling Low-Rate DoS Attacks
Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo, Pedro García-Teodoro |
ESORICS | 1 |
| 2006 | Mathematical Foundations for the Design of a Low-Rate DoS Attack to Iterative Servers (Short Paper)
Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo, Pedro García-Teodoro |
ICICS | 1 |
| 2006 | On the Design of a Low-Rate DoS Attack Against Iterative Servers
Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo, Pedro García-Teodoro |
SECRYPT | 1 |
| 2005 | PIM-DM Cost Analysis in Loop Free TopologiesabstractThis paper presents an approach to estimate the cost of the PIM-DM protocol in terms of the number of packets, both for data and control traffic. The proposed approach assumes a loop-free network topology and that all links have equal parameters. Although restrictive at a first glance, the results show a good performance in simulated real networks when mean values for the parameters are used. The expressions are deduced from the protocol functioning, overcoming limitations and approximations of previously published works. Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo, Juan Tapiador |
ISCC | 1 |