Gabriel Maciá-Fernández

dblp:65/5024 · DBLP profile ↗
← Back
34ranked-venue papers
12as first author
8since 2021 · last 2026
0000-0001-9256-453XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 7 first-author · 2 since 2021Computer networks · 15 · 5 first-author · 6 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 IBRAM: Internet Background Radiation Analysis Methodology
abstract
Internet Background Radiation (IBR) is unsolicited traffic captured by network telescopes, primarily composed of scanning activity, denial-of-service backscatter, and misconfigurations. Its analysis provides a valuable source of cyberintelligence for identifying attack trends, emerging vulnerabilities, and malicious payloads. However, existing analysis approaches lack a standardized methodology tailored to IBR’s distinctive characteristics, and conventional flow abstractions such as NetFlow’s 5-tuple are ill-suited for IBR traffic, where over 96% of TCP flows consist of a single packet. This article introduces IBRAM (Internet Background Radiation Analysis Methodology), a structured and modular methodology for IBR traffic analysis comprising three phases: scope definition, iterative processing (normalization, reassembly, aggregation, enrichment, and correlation), and analysis. Central to IBRAM is the concept of IBRflow, a flow abstraction specifically designed for IBR traffic that supports flexible, payload-aware aggregation and hierarchical composition into higher-level structures called IBRevents, enabling the correlation of related scanning activities across protocols. The methodology is validated through a case study using 67 million packets captured over 31 days by a/24 network telescope, demonstrating that iterative IBRflow aggregation can reduce ICMP traffic to a small set of flows representing over 97% of packets while preserving traffic intent. The analysis reproduces findings consistent with prior IBR studies and reveals cross-protocol scanning patterns through IBRevents correlation. Both the analysis tools and the dataset have been made publicly available to the community.
Rodolfo García-Peñas, Rafael Rodríguez-Gómez, Gabriel Maciá-Fernández
Comput. Networks3
2025 Characterizing Internet Background Traffic from a Spain-Based Network Telescope
abstract
Internet background traffic (or Internet Background Radiation, IBR) consists of unsolicited packets. It is traffic usually generated in the preliminary phases of attacks by computers making enumerations of targets and available services, sent as responses to denial of service attacks, or sent by mistake due to incorrect configurations and commands. Capturing and analysing this traffic enables the observation of Internet activity and serves as an important tool for identifying new types of attacks and attackers. This traffic is captured by “network telescopes”, nodes that advertise blocks of unused IP addresses and store the traffic sent to them. This article studies the traffic received by a network telescope located in Spain during 2023, with more than 4.7 billion packets and 362.39 GB of information. A statistical breakdown of the packets by protocol shows that TCP accounts for 95.96%, UDP for 3.74%, and ICMP for 0.51%. In addition, the behaviour of the traffic generators targeting the telescope’s addresses is examined, and the main attacks – such as NTP and DNS reflection – are analysed. The characteristics of the traffic are compared with those of previous studies, highlighting changes in behaviour and the most common attacks.
Rodolfo García-Peñas, Rafael Rodríguez-Gómez, Gabriel Maciá-Fernández
Comput. Secur.3
2024 Collaborative credentials for the Internet of Things
abstract
The Self-Sovereign Identity (SSI) paradigm has emerged as a decentralized Identity Management model with interesting capabilities for the Internet of Things (IoT). However, current standard SSI protocols and procedures only consider that individuals store their own identity, failing to provide an accurate solution for the identity management of groups where participants might use credentials from different identities and collaborate to meet a set of verifier´s requirements. The present work introduces the concept of Collaborative Credentials (CCs) to formalize identity management procedures that model the collaboration within a group of participants. CCs allow to leverage use cases requiring collaboration that cannot be solved with standard SSI verifiable credentials, increase the privacy of group participants and enable the development of a software framework that any verifier/holder could use to generate a generic application. In the paper, a generic model for CCs is presented, together with an implementation example that is subsequently evaluated in an experimental testbed.
Santiago de Diego, Cristina Regueiro, Gabriel Maciá-Fernández
Comput. Networks3
2024 HoDiNT: Distributed architecture for collection and analysis of Internet Background Radiation
abstract
Attacks on the Internet are constant, with different typologies and processes. The initial stages usually involve an enumeration of targets and available services, generating what is known as Internet Background Radiation (IBR). Capturing and analysing this traffic has proven to be crucial for the early identification and detection of attacks. Commonly used architectures for the acquisition of background traffic are based on “black holes”, which are systems that collect this traffic by advertising large blocks of unused IP addresses to the Internet, identifying the traffic received as IBR. These systems have a number of inherent drawbacks, such as the requirement to process large volumes of data, and deal with the existence of a large amount of repetitive data, the fact that they are easily identifiable by the IP addresses used and, finally, that they are expensive to maintain. With the aim of improving the above undesired characteristics, this paper proposes “HoDiNT” (HOme DIstributed Network Telescope), a distributed architecture for the acquisition of Internet Background Radiation. HoDiNT is implemented with low-cost advanced acquisition techniques and without the need to use specific IP address ranges, making it easier to hide the sensors. An initial scan of the traffic received for one month is performed on the probes deployed, and a subsequent analysis is performed on the collected data to draw conclusions.
Rodolfo García-Peñas, Rafael Rodríguez-Gómez, Gabriel Maciá-Fernández
Comput. Networks3
2022 Bypassing Current Limitations for Implementing a Credential Delegation for the Industry 4.0
abstract
Publisher Copyright: © 2021 by SCITEPRESS – Science and Technology Publications, Lda. All rights reserved.
Santiago de Diego, Oscar Lage, Cristina Regueiro, Sergio Anguita, Gabriel Maciá-Fernández
SECRYPT5
2022 A novel zero-trust network access control scheme based on the security profile of devices and users
Pedro García-Teodoro, José Camacho 0001, Gabriel Maciá-Fernández, José Antonio Gómez-Hernández, Victor José López-Marín
Comput. Networks3
2022 Leveraging a Probabilistic PCA Model to Understand the Multivariate Statistical Network Monitoring Framework for Network Security Anomaly Detection
abstract
Network anomaly detection is a very relevant research area nowadays, especially due to its multiple applications in the field of network security. The boost of new models based on variational autoencoders and generative adversarial networks has motivated a reevaluation of traditional techniques for anomaly detection. It is, however, essential to be able to understand these new models from the perspective of the experience attained from years of evaluating network security data for anomaly detection. In this paper, we revisit anomaly detection techniques based on PCA from a probabilistic generative model point of view, and contribute a mathematical model that relates them. Specifically, we start with the probabilistic PCA model and explain its connection to the Multivariate Statistical Network Monitoring (MSNM) framework. MSNM was recently successfully proposed as a means of incorporating industrial process anomaly detection experience into the field of networking. We have evaluated the mathematical model using two different datasets. The first, a synthetic dataset created to better understand the analysis proposed, and the second, UGR’16, is a specifically designed real-traffic dataset for network security anomaly detection. We have drawn conclusions that we consider to be useful when applying generative models to network security detection.
Fernando Pérez-Bueno, Luz García 0001, Gabriel Maciá-Fernández, Rafael Molina 0001
IEEE/ACM Trans. Netw.3
2021 Unveiling the I2P web structure: A connectivity analysis
abstract
Web is a primary and essential service to share information among users and organizations at present all over the world. Despite the current significance of such a kind of traffic on the Internet, the so-called Surface Web traffic has been estimated in just about 5% of the total. The rest of the volume of this type of traffic corresponds to the portion of Web known as Deep Web. These contents are not accessible by search engines because they are authentication protected contents or pages that are only reachable through the well known as darknets. To browse through darknets websites special authorization or specific software and configurations are needed. Despite TOR is the most used darknet nowadays, there are other alternatives such as I2P or Freenet, which offer different features for end users. In this work, we perform an analysis of the connectivity of websites in the I2P network (named eepsites) aimed to discover if different patterns and relationships from those used in legacy web are followed in I2P, and also to get insights about its dimension and structure. For that, a novel tool is specifically developed by the authors and deployed on a distributed scenario. Main results conclude the decentralized nature of the I2P network, where there is a structural part of interconnected eepsites while other several nodes are isolated probably due to their intermittent presence in the network.
Roberto Magán-Carrión, Alberto Abellán-Galera, Gabriel Maciá-Fernández, Pedro García-Teodoro
Comput. Networks3
2019 Multivariate Big Data Analysis for intrusion detection: 5 steps from the haystack to the needle
José Camacho 0001, José Manuel García-Giménez, Noemí Marta Fuentes García, Gabriel Maciá-Fernández
Comput. Secur.4
2019 Semi-Supervised Multivariate Statistical Network Monitoring for Learning Security Threats
abstract
This paper presents a semi-supervised approach for intrusion detection. The method extends the unsupervised multivariate statistical network monitoring approach based on the principal component analysis by introducing a supervised optimization technique to learn the optimum scaling in the input data. It inherits the advantages of the unsupervised strategy, capable of uncovering new threats, with that of supervised strategies, capable of learning the pattern of a targeted threat. The supervised learning is based on an extension of the gradient descent method based on partial least squares (PLS). Moreover, we enhance this method by using sparse PLS variants. The practical application of the system is demonstrated on a recently published real case study, showing relevant improvements in detection performance and in the interpretation of the attacks.
José Camacho 0001, Gabriel Maciá-Fernández, Noemí Marta Fuentes García, Edoardo Saccenti
IEEE Trans. Inf. Forensics Secur.2
2018 UGR'16: A new dataset for the evaluation of cyclostationarity-based network IDSs
Gabriel Maciá-Fernández, José Camacho 0001, Roberto Magán-Carrión, Pedro García-Teodoro, Roberto Therón
Comput. Secur.1
2017 Network-wide intrusion detection supported by multivariate analysis and interactive visualization
abstract
In this paper, we introduce a new visualization tool for network-wide intrusion detection. It is based in multivariate anomaly detection with a combination between Principal Component Analysis (PCA) and a new variant called Group-wise PCA (GPCA). Combining these methodologies with the capabilities of interactive visualization, the resulting tool is a highly flexible and intuitive interface that allows the user to navigate through the enormous amount of data collected in the network, in order to find anomalous or unexpected behaviors. We use a real case study to illustrate the capability of the tool to unveil the complex mixture of information that can be found in network security/traffic data and identify and diagnose anomalies in it.
Roberto Therón, Roberto Magán-Carrión, José Camacho 0001, Gabriel Maciá-Fernández
VizSEC4
2016 PCA-based multivariate statistical network monitoring for anomaly detection
José Camacho 0001, Alejandro Pérez-Villegas, Pedro García-Teodoro, Gabriel Maciá-Fernández
Comput. Secur.4
2015 A model of data forwarding in MANETs for lightweight detection of malicious packet dropping
Leovigildo Sánchez-Casado, Gabriel Maciá-Fernández, Pedro García-Teodoro, Roberto Magán-Carrión
Comput. Networks2
2015 Identification of contamination zones for sinkhole detection in MANETs
Leovigildo Sánchez-Casado, Gabriel Maciá-Fernández, Pedro García-Teodoro, Nils Aschenbruck
J. Netw. Comput. Appl.2
2014 Resource monitoring for the detection of parasite P2P botnets
Rafael Rodríguez-Gómez, Gabriel Maciá-Fernández, Pedro García-Teodoro, Moritz Steiner, Davide Balzarotti
Comput. Networks2
2013 Stochastic Traffic Identification for Security Management: eDonkey Protocol as a Case Study
Rafael Rodríguez-Gómez, Gabriel Maciá-Fernández, Pedro García-Teodoro
NSS2
2013 A model-based survey of alert correlation techniques
Saeed Salah, Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo
Comput. Networks2
2012 An Efficient Cross-Layer Approach for Malicious Packet Dropping Detection in MANETs
abstract
This paper introduces a novel IDS approach for detecting malicious packet dropping behaviors in MANETs. Although some similar proposals can be found in the specialized literature, two main differences exist with ours. First, mobility aspects are explicitly considered into the approach by means of a heuristic which considers the operation of the forwarding process at the nodes. Second, this fact results in a significant improvement in the detection performance of the system, especially in terms of low false positive rate. The different experimental results obtained show the promising nature of our approach, both in terms of the detection capabilities exhibited and from the point of view of the simplicity of the scheme.
Leovigildo Sánchez-Casado, Gabriel Maciá-Fernández, Pedro García-Teodoro
TrustCom2
2012 Extracting user web browsing patterns from non-content network traces: The online advertising case study
Gabriel Maciá-Fernández, Rafael Rodríguez-Gómez, Aleksandar Kuzmanovic
Comput. Networks1
2011 Understanding the Network and User-Targeting Properties of Web Advertising Networks
abstract
Advertising has become an integral and inseparable part of the World Wide Web. However, neither public auditing nor monitoring mechanisms still exist in this emerging area. In this paper, we present our initial efforts on building a network and content-level auditing service for Web-based ad networks. Our network-level measurements -- charting the network infrastructure and quantifying the ad platforms' delay performance -- can help commissioners to evaluate their networks from end users' perspective, and let advertisers choose commissioners that better fit their needs. Our content-level measurements -- understanding the ad distribution mechanisms and evaluating location-based and behavioral targeting approaches -- bring useful auditing information to all entities involved in the on line advertising business. We extensively evaluate Google's, AOL's, and Ad blade's ad networks and demonstrate how their different design philosophies dominantly affect their performance at both network and content levels.
Daniel Burgener, Aleksandar Kuzmanovic, Gabriel Maciá-Fernández
ICDCS4
2011 Analysis of Botnets through Life-cycle
Rafael Rodríguez-Gómez, Gabriel Maciá-Fernández, Pedro García-Teodoro
SECRYPT2
2010 ISP-Enabled Behavioral Ad Targeting without Deep Packet Inspection
abstract
Online advertising is a rapidly growing industry currently dominated by the search engine 'giant' Google. In an attempt to tap into this huge market, Internet Service Providers (ISPs) started deploying deep packet inspection techniques to track and collect user browsing behavior. However, such techniques violate wiretap laws that explicitly prevent intercepting the contents of communication without gaining consent from consumers. In this paper, we show that it is possible for ISPs to extract user browsing patterns without inspecting contents of communication. Our contributions are threefold. First, we develop a methodology and implement a system that is capable of extracting web browsing features from stored non-content based records of online communication, which could be legally shared. When such browsing features are correlated with information collected by independently crawling the Web, it becomes possible to recover the actual web pages accessed by clients. Second, we systematically evaluate our system on the Internet and demonstrate that it can successfully recover user browsing patterns with high accuracy. Finally, our findings call for a comprehensive legislative reform that would not only enable fair competition in the online advertising business, but more importantly, protect the consumer rights in a more effective way.
Gabriel Maciá-Fernández, Rafael Rodríguez-Gómez, Aleksandar Kuzmanovic
INFOCOM1
2010 Analyzing content-level properties of the web adversphere
abstract
Advertising has become an integral and inseparable part of the World Wide Web. However, neither public auditing nor monitoring mechanisms still exist in this emerging area. In this paper, we present our initial efforts on building a content-level auditing service for web-based ad networks. Our content-level measurements - understanding the ad distribution mechanisms and evaluating location-based and behavioral targeting approaches - bring useful auditing information to all entities involved in the online advertising business. We extensively evaluate Google's, AOL's, and Adblade's ad networks and demonstrate how their different design philosophies dominantly affect their performance at the content level.
Daniel Burgener, Aleksandar Kuzmanovic, Gabriel Maciá-Fernández
WWW4
2010 Defense techniques for low-rate DoS attacks against application servers
Gabriel Maciá-Fernández, Rafael Rodríguez-Gómez, Jesús Esteban Díaz Verdejo
Comput. Networks1
2009 Anomaly-based network intrusion detection: Techniques, systems and challenges
Pedro García-Teodoro, Jesús Esteban Díaz Verdejo, Gabriel Maciá-Fernández, Enrique Vázquez
Comput. Secur.3
2009 Mathematical model for low-rate DoS attacks against application servers
abstract
In recent years, variants of denial of service (DoS) attacks that use low-rate traffic have been proposed, including the Shrew attack, reduction of quality attacks, and low-rate DoS attacks against application servers (LoRDAS). All of these are flooding attacks that take advantage of vulnerability in the victims for reducing the rate of the traffic. Although their implications and impact have been comprehensively studied, mainly by means of simulation, there is a need for mathematical models by which the behaviour of these sometimes complex processes can be described. In this paper, we propose a mathematical model for the LoRDAS attack. This model allows us to evaluate its performance by relating it to the configuration parameters of the attack and the dynamics of network and victim. The model is validated by comparing the performance values given against those obtained from a simulated environment. In addition, some applicability issues for the model are contributed, together with interpretation guidelines to the model's behaviour. Finally, experience of the model enables us to make some recommendations for the challenging task of building defense techniques against this attack.
Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo, Pedro García-Teodoro
IEEE Trans. Inf. Forensics Secur.1
2008 Evaluation of a low-rate DoS attack against application servers
Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo, Pedro García-Teodoro
Comput. Secur.1
2007 LoRDAS: A Low-Rate DoS Attack against Application Servers
Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo, Pedro García-Teodoro, Francisco de Toro-Negro
CRITIS1
2007 Evaluation of a low-rate DoS attack against iterative servers
Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo, Pedro García-Teodoro
Comput. Networks1
2006 Assessment of a Vulnerability in Iterative Servers Enabling Low-Rate DoS Attacks
Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo, Pedro García-Teodoro
ESORICS1
2006 Mathematical Foundations for the Design of a Low-Rate DoS Attack to Iterative Servers (Short Paper)
Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo, Pedro García-Teodoro
ICICS1
2006 On the Design of a Low-Rate DoS Attack Against Iterative Servers
Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo, Pedro García-Teodoro
SECRYPT1
2005 PIM-DM Cost Analysis in Loop Free Topologies
abstract
This paper presents an approach to estimate the cost of the PIM-DM protocol in terms of the number of packets, both for data and control traffic. The proposed approach assumes a loop-free network topology and that all links have equal parameters. Although restrictive at a first glance, the results show a good performance in simulated real networks when mean values for the parameters are used. The expressions are deduced from the protocol functioning, overcoming limitations and approximations of previously published works.
Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo, Juan Tapiador
ISCC1