Marta Beltrán

dblp:67/6200 · DBLP profile ↗
← Back
31ranked-venue papers
16as first author
11since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 3 first-author · 7 since 2021Systems, architecture and hardware · 8 · 7 first-author · 1 since 2021Artificial intelligence and machine learning · 5 · 3 since 2021Computer networks · 3 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2 · 2 first-author
YearPublicationVenuePosition
2025 LSTM-based text analysis to automatically adapt cyberattack detection capabilities
Miguel Calvo, Anca Butnar, Marta Beltrán
Appl. Intell.3
2025 AI algorithms under scrutiny: GDPR, DSA, AI Act and CRA as pillars for algorithmic security and privacy in the European Union
abstract
The General Data Protection Regulation (GDPR), Digital Services Act (DSA), Artificial Intelligence Act (AI Act) and Cyber Resilience Act (CRA) are essential pillars for algorithmic security and privacy in the European Union. Each of these regulations addresses specific aspects of technology, such as personal data protection, trustworthy online services, safe AI systems, and secure digital products while fostering trust in algorithm-based systems. Together, they can establish a robust framework for ensuring the security and privacy of AI algorithms in the EU by addressing critical concerns through a risk-based approach. This paper proposes a multi-layered approach to algorithmic security and privacy, based on these four instruments, considering organisational risk, risks to rights and freedoms, systemic risks and risks to national security. An illustrative example demonstrates how the EU can establish a global standard for trustworthy innovation and the protection of fundamental rights by leveraging the direct and indirect synergies of these laws.
Marta Beltrán
Comput. Secur.1
2024 Applying the Goal, Question, Metric method to derive tailored dynamic cyber risk metrics
abstract
Purpose This paper aims to propose a new method to derive custom dynamic cyber risk metrics based on the well-known Goal, Question, Metric (GQM) approach. A framework that complements it and makes it much easier to use has been proposed too. Both, the method and the framework, have been validated within two challenging application domains: continuous risk assessment within a smart farm and risk-based adaptive security to reconfigure a Web application firewall. Design/methodology/approach The authors have identified a problem and provided motivation. They have developed their theory and engineered a new method and a framework to complement it. They have demonstrated the proposed method and framework work, validating them in two real use cases. Findings The GQM method, often applied within the software quality field, is a good basis for proposing a method to define new tailored cyber risk metrics that meet the requirements of current application domains. A comprehensive framework that formalises possible goals and questions translated to potential measurements can greatly facilitate the use of this method. Originality/value The proposed method enables the application of the GQM approach to cyber risk measurement. The proposed framework allows new cyber risk metrics to be inferred by choosing between suggested goals and questions and measuring the relevant elements of probability and impact. The authors’ approach demonstrates to be generic and flexible enough to allow very different organisations with heterogeneous requirements to derive tailored metrics useful for their particular risk management processes.
Miguel Calvo, Marta Beltrán
Inf. Comput. Secur.2
2023 A privacy threat model for identity verification based on facial recognition
abstract
The proliferation of different types of photographic and video cameras makes it relatively simple and non-intrusive to acquire facial fingerprints with sufficient quality to perform individuals’ identity verification. In most democratic societies, a debate has been occurring regarding using such techniques in different application domains. Discussions usually revolve around the tradeoffs between utility (security in access control, mobile phone unlocking, payment processing, etc.), usability or economic gain and risks to citizens’ rights and freedoms (privacy) or ethics. This paper identifies the common aspects of different solutions for identity verification based on facial recognition techniques within different application domains. It then performs a privacy threat modelling based on these common aspects to identify the most critical risk factors and a minimum set of safeguards to be considered for their management.
Marta Beltrán, Miguel Calvo
Comput. Secur.1
2023 Cybersecurity in the digital world
Lorena González-Manzano, Marta Beltrán, José María de Fuentes, Gianluca Dini, Cristina Alcaraz
Future Gener. Comput. Syst.2
2022 An Adaptive Web Application Firewall
Miguel Calvo, Marta Beltrán
SECRYPT2
2022 A Model For risk-Based adaptive security controls
abstract
Security controls and countermeasures have shifted from static desktop-based and corporate network environments to heterogeneous, distributed and dynamic environments (e.g., cloud and mobile computing or Internet of Things). Due to this paradigm shift, adaptive and risk-based approaches have gained significant importance. These approaches allow security managers to perform context-aware decision making, adapting controls’ deployment, configuration or use to every specific situation, depending on the current value of risk indicators or scores and on the level of risk tolerated by the organisation at any given time. This paper proposes a model to automatically adapt security controls to different risk scenarios in almost real-time (if required). This model is based on a three-layer architecture and a three-step flow (measurement-decision-adaptation), relying on a scalable policies&rules framework capable of integrating with different kinds of controls. Furthermore, the proposed model is validated and evaluated with an actual use case.
Miguel Calvo, Marta Beltrán
Comput. Secur.2
2022 Combining user behavioural information at the feature level to enhance continuous authentication systems
abstract
The scientific and business communities are proposing new authentication methods more robust than traditional solutions relying on a single security point such as passwords (i.e. “something you know”). User and Entity Behavior Analysis (UEBA) has postulated as an excellent solution to improve authentication systems by performing continuous authentication to extend the authentication process over time. UEBA is based on detecting anomalies in the intrinsic behaviour of each user or entity (i.e. it is based on “something you are/do”). This paper presents a method for performing continuous authentication using UEBA techniques that allows combining information from multiple sources at the feature level. This combination is achieved through a novel Symbolic Aggregate approximation (SAX) using Random Trees Embeddings for each information source, producing a sequence of symbols. Then, these sequences of symbols are combined into a single sequence using temporal information. The resulting sequence of symbols feeds a density-based clustering model that uses a distance based on DNA sequence alignment techniques to extract behavioural cores. Finally, new samples are compared against these cores to detect anomalies using a risk model that evaluates if a behaviour is anomalous (suspected user impersonation). The model has been extensively tested and evaluated against well-known state-of-the-art datasets.
Alejandro G. Martín, Isaac Martín de Diego, Alberto Fernández-Isabel, Marta Beltrán, Rubén R. Fernández
Knowl. Based Syst.4
2021 Protecting End User's Privacy When using Social Login through GDPR Compliance
Carlos Villarán, Marta Beltrán
SECRYPT2
2021 A survey for user behavior analysis based on machine learning techniques: current models and applications
Alejandro G. Martín, Alberto Fernández-Isabel, Isaac Martín de Diego, Marta Beltrán
Appl. Intell.4
2021 An approach to detect user behaviour anomalies within identity federations
abstract
User and Entity Behaviour Analytics (UEBA) mechanisms rely on statistical techniques and Machine Learning to determine when a significant deviation from patterns or trends established as a standard for users and entities is occurring. These mechanisms are beneficial within cybersecurity contexts because they allow managers and administrators to have early alerts warning about potential security incidents. This paper proposes the utilisation of UEBA to improve the security of Federated Identity Management (FIM) solutions. The proposed UEBA workflow allows Relying Parties within identity federations to build a session fingerprint characterising each user’s behaviour from available information. Furthermore, it enables anomaly detection based on this fingerprint, integrating raised alerts within current identity management specifications. The proposed workflow is validated and evaluated in a real use case based on a web chat application using OpenID Connect for identity management.
Alejandro G. Martín, Marta Beltrán, Alberto Fernández-Isabel, Isaac Martín de Diego
Comput. Secur.2
2020 Edge-centric delegation of authorization for constrained devices in the Internet of Things
Elías Grande, Marta Beltrán
Comput. Commun.2
2019 Understanding and mitigating OpenID Connect threats
Jorge Navas 0002, Marta Beltrán
Comput. Secur.2
2018 Identifying, authenticating and authorizing smart objects and end users to cloud services in Internet of Things
Marta Beltrán
Comput. Secur.1
2016 BECloud: A new approach to analyse elasticity enablers of cloud services
Marta Beltrán
Future Gener. Comput. Syst.1
2015 Automatic provisioning of multi-tier applications in cloud computing environments
Marta Beltrán
J. Supercomput.1
2014 Extending the JCR standard to work efficiently in mobile RCS environments
abstract
Internet companies have been exploiting the massive penetration of smart phones by developing applications of instant messaging, group communication, file sharing, etc. Rich Communication Services (RCS) allow telecom operators to provide their clients experiences beyond voice and SMS, and therefore, to compete against widely extended IP-based services such as Skype or Whatsapp using IP Multimedia Subsystems (IMS). In this context, telecom operators have taken advantage of different technologies, specifications and standards that provide the means to supply innovative, secure and reliable rich communication services. Regarding content storage and management issues, both data and metadata need to be efficiently managed with more sophisticated technologies than traditional file systems or database systems. One of these technologies is JCR (Java Content Repository), suitable for developing file sharing services in mobile environments. This content repository API for Java allows a clear separation between the functionalities to manage the repository and the application-specific functionalities. This work analyses the suitability of the JCR standard to RCS environments and proposes a extension to the standard with the aim of identifying redundant file uploads in order to save network bandwidth.
Francisco Carriedo, Marta Beltrán, Jose Maria Recio
WoWMoM2
2013 The importance of the avatar gender in training simulators based on virtual reality
abstract
The application of simulation techniques in the military and security forces are numerous and in most cases their purpose is the training of staff. Virtual reality techniques have been incorporated to these simulators to enrich the trained professionals' experience. And with this kind of virtual training arises the need of designing avatars representing professionals in the virtual exercises. This work examines the effect of avatar gender on learning outcomes achieved with training simulators based on virtual reality.
Marta Beltrán
ITiCSE1
2013 Using CloudSim to learn cloud computing architecture/system concepts in a graduate course
abstract
The recent expansion of the cloud computing paradigm has motivated educators to include cloud-related topics in computer science and computer engineering curricula. While programming and algorithm topics have been covered in different undergraduate and graduate courses, cloud architecture/system topics are still not usually studied in academic contexts. But design, deployment and management of datacenters, virtualization technologies for cloud, cloud management tools and similar issues should be addressed in current computer science and computer engineering programs. This work presents our approach and experiences in designing and implementing a curricular module covering all these topics. In this approach the utilization of a simulation tool, CloudSim, is essential to allow the students a practical approximation to the course contents.
Marta Beltrán, Antonio Guzmán, Marcos Palomero
ITiCSE1
2012 An automatic machine scaling solution for cloud systems
abstract
The Infrastructure as a Service (IaaS) paradigm allows service providers and/or end-users to outsource the computing resources they need. Cloud providers offer the infrastructure as a utility with a pay-per-use model, relying on virtualization technologies to provide hardware resources to the cloud consumers. IaaS can potentially bring obvious advantages, but the virtualized resources use to be manually controlled by the consumers, and this may lead to unaffordable administration costs. The demand of computing resources can fluctuate from one time to another and managing the virtual machines “rented” to the cloud provider to meet peak requirements but to avoid overprovisioning, is a significant challenge. This paper presents AMAS (Automatic MAchine Scaling), a distributed solution capable of automatically creating and releasing virtual machines in order to minimize the number of virtual resources instantiated to run an application and to meet the consumer performance requirements. Furthermore, the complete design and a first real implementation of this solution is described to validate that it is capable of handling sudden load changes, maintaining the desired quality of service, minimizing the number of virtual machines and significantly reducing the consumer management efforts.
Marta Beltrán, Antonio Guzmán
HiPC1
2011 A Simulation Framework To Help In Lean Manufacturing Initiatives
abstract
Lean Manufacturing initiatives try to understand where the sources of waste are in a manufacturing process in order to minimize or avoid them and to add value to the stakeholders. The improvement actions related to lean methods are always incremental, fast and easy; mainly based on people’s experience and on simple tools. For example, a Value Stream Map (VSM) is created to have a visual representation of the material and information ¤ows involved in the production process, allowing improvement teams to detect where is the waste introduced and where is the value added. The integration of simulation with VSM could considerably improve the results obtained in lean projects, helping the decision makers in adding dynamic information to the usually considered static pictures of the processes. The information obtained from what-if simulations allows to detect improvement opportunities, to prioritize them, to analyze the best implementation alternative, and to quantify the possible bene£ts of the proposed actions. This work presents the LeanSim framework, an easy to use tool based on Matlab and Simulink, capable of integrating a lean method such as VSM with simulation. Furthermore, a case study of an improvement project at a milk production plant is presented to illustrate the utilization of this new framework on a real environment.
Fernando Sevillano, Miguel Serna, Marta Beltrán, Antonio Guzmán
ECMS3
2011 Performance of a 60-GHz DCM-OFDM and BPSK-Impulse Ultra-Wideband System with Radio-Over-Fiber and Wireless Transmission Employing a Directly-Modulated VCSEL
abstract
The performance of radio-over-fiber optical transmission employing vertical-cavity surface-emitting lasers (VCSELs), and further wireless transmission, of the two major ultra-wideband (UWB) implementations is reported when operating in the 60-GHz radio band. Performance is evaluated at 1.44 Gbit/s bitrate. The two UWB implementations considered employ dual-carrier modulation orthogonal frequency-division multiplexing (DCM-OFDM) and binary phase-shift keying impulse radio (BPSK-IR) modulation respectively. Optical transmission distances up to 40 km in standard single-mode fiber and up to 500 m in bend-insensitive single-mode fiber with wireless transmission up to 5 m in both cases is demonstrated with no penalty. A simulation analysis has also been performed in order to investigate the operational limits. The analysis results are in excellent agreement with the experimental work and indicate good tolerance to chromatic dispersion due to the chirp characteristics of electro-optical conversion when a directly-modulated VCSEL is employed. The performance comparison indicates that BPSK-IR UWB exhibits better tolerance to optical transmission impairments requiring lower received optical power than its DCM-OFDM UWB counterpart when operating in the 60-GHz band.
Marta Beltrán, Jesper Bevensee Jensen, Xianbin Yu, Roberto Llorente, Roberto Rodes, Markus Ortsiefer, Christian Neumeyr, Idelfonso Tafur Monroy
IEEE J. Sel. Areas Commun.1
2010 High level performance metrics for FPGA-based multiprocessor systems
Marta Beltrán, Antonio Guzmán, Fernando Sevillano
Perform. Evaluation1
2009 Scalability Analysis to Optimize a Network on Chip
abstract
New high performance architectures combining high and low level techniques are widely used today, and FPGA-based designs offer excellent platforms for this kind of systems. This paper describes the HIPAOC (HIgh Performance Architecture On Chip) system, a general purpose and reconfigurable high performance architecture implemented on a single FPGA. The proposed design can be configured to work as a shared memory system (multiprocessor) or as a distributed memory system (multicomputer or cluster). The selection of the interconnection network topology in this kind of system is a major design decision. Performance metrics are needed to guide the designer and the user in their decisions with quantitative information. This work proposes a scalability metric and a scalability analysis procedure to optimize the design of Networks on Chip.
Marta Beltrán, Antonio Guzmán, Fernando Sevillano
AINA1
2009 Using Simulation For Decision Making In Zero Latency Enterprise Projects
abstract
The concept of Zero Latency Enterprise (ZLE) has received considerable attention through the last years. Many companies and organizations want to see the value of this kind of strategy before changing their IT infrastructure to implement ZLE solution. This paper proposes a new project methodology defining five main steps that should be followed to success in ZLE implementation projects. One of these steps, the Planning and Decision Making stage, is based on simulation techniques, allowing a comparison of the organization performance with and without ZLE strategies. Furthermore, in this work the different approaches for the ZLE simulation are examined and discussed.
Fernando Sevillano, Marta Beltrán, Antonio Guzmán
ECMS2
2009 Experimental Analysis of 3.5 GHz WiMAX 802.16e Interference in WiMedia-defined UWB Radio Transmissions
abstract
The interference produced by WiMAX mobile wireless transmissions operating in the 3.5 GHz band on a WiMedia-defined ultra-wideband (UWB) wireless link is experimentally analyzed in this paper. The investigation includes standard IEEE 802.16e WiMAX, and ECMA-368 UWB equipment as defined by the WiMedia alliance. A conventional meeting room scenario has been considered for the measurements. The experimental results indicate that WiMAX transmitters must be located at distances larger than 5 m from the UWB receiver to guarantee successful UWB communication.
Joaquín Pérez 0001, Marta Beltrán, Maria Morant, Roberto Llorente, Abdur Rahim Biswas, Radoslaw Piesiewicz, Michael G. Cotton, Detlef Führer, Bruno Selva, Isabelle Bucaille, Sven Zeisberg
VTC Spring2
2008 Designing Load Balancing Algorithms Capable of Dealing with Workload Variability
abstract
The workload on a cluster system can be highly variable, increasing the difficulty of balancing the load across its nodes. And the general rule is that high variability leads to wrong load balancing decisions taken with out-of-date information and difficult to correct in real-time during applications execution.In this work the workload variability is studied from theperspective of the load balancing performance, focusing onthe design of algorithms capable of dealing with this variability. Two different robustness metrics are proposed to select the best distribution rule for the algorithm, remote execution or process migration. With the proposed solution only when a high variability causes an intolerable performance degradation the process migration is used to balance the load in the system.
Marta Beltrán, Antonio Guzmán
ISPDC1
2008 A New CPU Availability Prediction Model for Time-Shared Systems
abstract
The success of different computing models, performance analysis and load balancing and algorithms depends on the processor availability information because there is a strong relationship between a process response time and the processor time available for its execution. Therefore, predicting the processor availability for a new process or task in a computer system is a basic problem that arises in in many important contexts. Unfortunately, making such predictions is not easy because of the dynamic nature of current computer systems and their workload, which can vary drastically in a short interval of time. This paper presents two new availability prediction models. The first, called SPAP (Static Process Assignment Prediction) model, is capable of predicting the CPU availability for a new task on a computer system having information about the tasks in its run queue. The second, called DYPAP (DYnamic Process Assignment Prediction) model, is an improvement of the SPAP model capable of making these predictions from real-time measurements provided by a monitoring tool, without any kind of information about the tasks in the run queue. Furthermore, the implementation of this monitoring tool for Linux workstations is presented.
Marta Beltrán, Antonio Guzmán, José Luis Bosque
IEEE Trans. Computers1
2006 Dealing with Heterogeneity in Load Balancing Algorithms
abstract
Cluster heterogeneity increases the difficulty of balancing the load across the system nodes. Although the relationship between heterogeneity and load balancing is difficult to describe analytically, in this paper an exhaustive analysis of the effects of this system feature on load balancing algorithms performance is presented. Considering the performed analysis, there are two main challenges that need to be faced when dealing with cluster heterogeneity in load balancing algorithms: one related to the state measurement stage and another to the initiation rule. In this paper techniques to deal with heterogeneity in these two algorithm stages are proposed. Furthermore, suggestions to improve the performance of the rest of algorithm stages in heterogeneous environments are made too
Marta Beltrán, Antonio Guzmán, José Luis Bosque
ISPDC1
2005 Information policies for load balancing on heterogeneous systems
abstract
Dynamic load balancing decisions on cluster or grid computing systems are always based on some kind of knowledge about the system nodes state. Therefore, to balance the computational workload among the different system nodes, a local or global information exchange is needed. The information policy determines how and when this exchange is performed. This paper discusses and compares the three traditional information policies: periodic, on demand and event-driven, in order to conclude if there is a better approach for the current heterogeneous systems. All the comparisons are performed evaluating a new metric, called information efficiency, defined in this paper to quantify the benefits obtained with an information policy considering the network traffic generated by the information exchange and its effectiveness in the information updating.
Marta Beltrán, José Luis Bosque
CCGRID1
2005 Initiating Load Balancing Operations
Marta Beltrán, José Luis Bosque, Antonio Guzmán
Euro-Par1