VLDB 2026 Research / reviewers in the wild / expert
Jorge Bernal Bernabé
dblp:77/3800
· DBLP profile ↗
35ranked-venue papers
6as first author
15since 2021 · last 2026
0000-0002-7538-4788ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 11 · 5 since 2021Systems, architecture and hardware · 7 · 3 first-author · 1 since 2021Security and privacy · 7 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 5 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1Theory of computation · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Enhancing federated intrusion detection through LLM-Driven alert enrichment and collaborative threat information sharing
Pablo Fernández Saura, Jorge Bernal Bernabé, Antonio F. Skarmeta |
Future Gener. Comput. Syst. | 2 |
| 2025 | On Automating Security Policies with Contemporary LLMs (Short Paper)abstractThe complexity of modern computing environments and the growing sophistication of cyber threats necessitate a more robust, adaptive, and automated approach to security enforcement. In this paper, we present a framework leveraging large language models (LLMs) for automating attack mitigation policy compliance through an innovative combination of in-context learning and retrieval-augmented generation (RAG). We begin by describing how our system collects and manages both tool and API specifications, storing them in a vector database to enable efficient retrieval of relevant information. We then detail the architectural pipeline that first decomposes high-level mitigation policies into discrete tasks and subsequently translates each task into a set of actionable API calls. Our empirical evaluation, conducted using publicly available CTI policies in STIXv2 format and Windows API documen-tation, demonstrates significant improvements in precision, recall, and Fl-score when employing RAG compared to a non-RAG baseline. Pablo Fernández Saura, K. R. Jayaram, Vatche Isahagian, Jorge Bernal Bernabé, Antonio F. Skarmeta |
SSE | 4 |
| 2025 | The Resilmesh Architecture: Situation Aware Enabled Cyber Resilience for Dispersed, Heterogenous Cyber SystemsabstractCyber systems (CyS) are becoming more and more complex as they are comprised of several infrastructure layers, heterogeneous technologies and dispersed deployments over wide geographical areas (cloud/edge/endpoint) that facilitates multiple attack entry points (vectors). At the same time, CyS attacks are constantly evolving and have become more complex and sophisticated. To address these issues, the ResilMesh architecture aims to provide critical infrastructure security teams with a greater cyber resilience capability by improving cyber resilience using Cyber Situational Awareness (CSA) based security orchestration and analytics framework. The framework enables organizations to achieve real-time defense, reducing attack surface impact by developing tools to combat complexity, disperse infrastructure, delivering flexible placement of security controls across the CyS infrastructure. The architecture combats Advanced Persistent Threat (APT) sophistication by leveraging advanced AI algorithms and tools for early and ongoing attack detection and prediction and improved situation. This paper presents the Resilmesh architecture, a first PoC implementation, as well as an evaluation of the Resilmesh capabilities to detect and mitigate APTs. Jorge Bernal Bernabé, Martin Husák, Lukás Sadlek, Branka Stojanovic, Michael Somma, Jorgeley Inacio de Oliveira, Ekam Puri Nieto, Pablo Fernández Saura, Antonio F. Skarmeta, Vinh Hoa La |
NetSoft | 1 |
| 2025 | Real-Time Network Cyber Situational Awareness in B5G NetworksabstractThe dynamic nature of beyond 5G network (B5G) topologies imposes continuous and real-time cyber situational awareness (CSA) to make cognitive security orchestration according to the actual context. In this sense, security orchestration decisions such as virtual network security functions placement or (re)configuration of the system to counter cyberthreats can benefit of these kind of CSA models. Traditional infrastructure and service models for CSA such as CRUSOE capture the security posture, missions, networks and assets, that can be used as baseline for cognitive functions such as cyber asset attack surface management, risk-trust assessment as well as detection and mitigation of cyber-attacks. However, these infrastructure data models and tools have not been adapted to complex B5G domains and do not support real-time processing of 6 G network traffic that, once supported, can boost context awareness and decision making. This paper describes the design, implementation and evaluation of the extension to the CRUSOE infrastructure model to enable the real-time modeling of 6G network flows, thereby increasing cyber security awareness capabilities in 6 G Security Operation Centers (6G-SOC), that ultimately, can help to improve cognitive security management of 6 G networks. The implementation and performance evaluation carried out shows promising results to capture and model in real time the dynamicity of 6G network topologies and traffic. José Antonio Pastor, Martin Husák, Jorge Bernal Bernabé, Antonio F. Skarmeta |
NetSoft | 3 |
| 2025 | Ai-Based Meta-Orchestration for Fl-Based Anomaly Detection in B5g NetworksabstractG networks will need to handle Multi-domain, multi-tenant and multi-operator scenarios where the security orchestration of services and network functions will face high complexity of scalability, interoperability and security. In particular, 6G networks will need to manage AI-based network functions to support analytics that can be encapsulated as virtual functions that need to be dynamically orchestrated, configured, deployed, decommissioned, migrated and reconfigured on demand. The distributed nature of these scenarios requires a federated learning FL approach to handle AI-based collaborative learning where FL-agents can be deployed in the continuum of any network segment of the network. This paper proposes an AI-based meta-orchestration approach for multi-domain and multi-tenant 6 G deployments intended to choreograph the FLbased AI functions. The meta-Orchestration encompasses diverse phases, including selection of the orchestration strategy, the orchestration graph building and the selection of best AI-based orchestration algorithm depending on the actual context, thereby maximizing the effectiveness of the allocation of the FL-agents. The implementation and performance evaluation to orchestrate FL agents with diverse AI-based algorithms across the continuum proves our approach to detect anomalies using FL in distributed scenarios. Pablo Fernández Saura, José Manuel Bernabé Murcia, Alejandro Molina Zarca, Jorge Bernal Bernabé, Antonio F. Skarmeta |
NetSoft | 4 |
| 2024 | Network slicing as 6G security mechanism to mitigate cyber-attacks: the RIGOUROUS approachabstractWith the emergence of 6G, novel approaches are demanded to identify and address cyber-security, trust and privacy risks threatening the softwarised and virtualised networks and computing infrastructure, and next-generation services. One of the main innovations beyond State-of-the-Art envisioned is to deliver End-to-End Multi-domain Multi-tenant 6G Network Slicing capabilities over Zero-touch Security Network Management.This paper introduces a novel security enabler deployed in the data plane where network slicing is explored as a security mitigation mechanism. In this way, legitimate traffic can be isolated from harmful traffic and the attacker will have near zero vulnerability surface to compromise the implemented security measures. The proposed solution is centred on Network Self-Protection (NSP) based on the Open Virtual Switch (OVS) platform, to which significant extensions have been undertaken to support Network Slicing capabilities in multi-tenant multi-domain beyond 5G networks.Preliminary experiments show promising results in terms of overhead introduced in the data plane (in the order of microseconds) and high scalability when deploying up to 2048 network slices. The proposed software network slicing enabler is a suitable candidate for coping with network traffic with different levels of nested encapsulation associated with this kind of virtualised infrastructures. Antonio Matencio-Escolar, Jorge Bernal Bernabé, José M. Alcaraz Calero, Qi Wang 0001, Antonio F. Skarmeta |
NetSoft | 2 |
| 2024 | Beyond selective disclosure: Extending distributed p-ABC implementations by commit-and-prove techniquesabstractThe increasing user awareness and regulatory framework (e.g., GDPR, eIDAS2) have contributed to considering data minimization and privacy-by-design as central guiding principles for new systems. Among others, this has led to a paradigm shift towards Self-Sovereign Identity solutions to put the user in full control over their data. Despite the promising landscape, privacy-preserving Attribute-Based Credentials (p-ABC) have not been widely adopted, mainly due to the lack of secure, flexible and efficient implementations that cover the basic and advanced needs in p-ABC systems. In this work, we tackle this gap by developing an improved zero-knowledge showing protocol of a distributed p-ABC scheme based on Pointcheval-Sanders Multi-Signatures to allow for modular extensions through commit-and-prove techniques. We use it to implement a flexible p-ABC system with decentralized issuance that, apart from the basic notions of p-ABCs, covers range proofs, pseudonyms, inspection and revocation. Lastly, we thoroughly evaluate the performance of the system under different testbed conditions, showing a significant efficiency improvement over previous implementations. Jesús García Rodríguez, Stephan Krenn, Jorge Bernal Bernabé, Antonio F. Skarmeta |
Comput. Networks | 3 |
| 2023 | Intrusion Detection Based on Privacy-Preserving Federated Learning for the Industrial IoTabstractFederated learning (FL) has attracted significant interest given its prominent advantages and applicability in many scenarios. However, it has been demonstrated that sharing updated gradients/weights during the training process can lead to privacy concerns. In the context of the Internet of Things (IoT), this can be exacerbated due to intrusion detection systems (IDSs), which are intended to detect security attacks by analyzing the devices’ network traffic. Our work provides a comprehensive evaluation of differential privacy techniques, which are applied during the training of an FL-enabled IDS for industrial IoT. Unlike previous approaches, we deal with nonindependent and identically distributed data over the recent ToN_IoT dataset, and compare the accuracy obtained considering different privacy requirements and aggregation functions, namely FedAvg and the recently proposed Fed+. According to our evaluation, the use of Fed+ in our setting provides similar results even when noise is included in the federated training process. Pedro Ruzafa Alcazar, Pablo Fernández Saura, Enrique Mármol Campos, Aurora González-Vidal, José Luis Hernández-Ramos, Jorge Bernal Bernabé, Antonio F. Skarmeta |
IEEE Trans. Ind. Informatics | 6 |
| 2022 | Automatic, verifiable and optimized policy-based security enforcement for SDN-aware IoT networks
Daniele Bringhenti, Jalolliddin Yusupov, Alejandro Molina Zarca, Fulvio Valenza, Riccardo Sisto, Jorge Bernal Bernabé, Antonio F. Skarmeta |
Comput. Networks | 6 |
| 2022 | Evaluating Federated Learning for intrusion detection in Internet of Things: Review and challengesabstractThe application of Machine Learning (ML) techniques to the well-known intrusion detection systems (IDS) is key to cope with increasingly sophisticated cybersecurity attacks through an effective and efficient detection process. In the context of the Internet of Things (IoT), most ML-enabled IDS approaches use centralized approaches where IoT devices share their data with data centers for further analysis. To mitigate privacy concerns associated with centralized approaches, in recent years the use of Federated Learning (FL) has attracted a significant interest in different sectors, including healthcare and transport systems. However, the development of FL-enabled IDS for IoT is in its infancy, and still requires research efforts from various areas, in order to identify the main challenges for the deployment in real-world scenarios. In this direction, our work evaluates a FL-enabled IDS approach based on a multiclass classifier considering different data distributions for the detection of different attacks in an IoT scenario. In particular, we use three different settings that are obtained by partitioning the recent ToN_IoT dataset according to IoT devices’ IP address and types of attack. Furthermore, we evaluate the impact of different aggregation functions according to such setting by using the recent IBMFL framework as FL implementation. Additionally, we identify a set of challenges and future directions based on the existing literature and the analysis of our evaluation results. Enrique Mármol Campos, Pablo Fernández Saura, Aurora González-Vidal, José Luis Hernández-Ramos, Jorge Bernal Bernabé, Gianmarco Baldini, Antonio F. Skarmeta |
Comput. Networks | 5 |
| 2022 | QoS and Resource-Aware Security Orchestration and Life Cycle ManagementabstractZero-touch network and service management (ZSM) exploits network function virtualization (NFV) and software-defined networking (SDN) to efficiently and dynamically orchestrate different service function chaining (SFC), whereby reducing capital expenditure and operation expenses. The SFC is an optimization problem that shall consider different constraints, such as Quality of Service (QoS), and actual resources, to achieve cost-efficient scheduling and allocation of the service functions. However, the large-scale, complexity and security issues brought by virtualized IoT networks, which embrace different network segments, e.g., Fog, Edge, Core, Cloud, that can also exploit proximity (computation offloading of virtualized IoT functions to the Edge), imposes new challenges for ZSM orchestrators intended to optimize the SFC, thereby achieving seamless user-experience, minimal end-to-end delay at a minimal cost. To cope with these challenges, this paper proposes a cost-efficient optimized orchestration system that addresses the whole life-cycle management of different SFCs, that considers QoS (including end-to-end delay, bandwidth, jitters), actual capacities of Virtual Network Functions (VNFs), potentially deployed across multiple Clouds-Edges, in terms of resources (CPU, RAM, storage) and current network security levels to ensure trusted deployments. The proposed orchestration system has been implemented and evaluated in the scope of H2020 Anastacia EU project,1showing its feasibility and performance to efficiently manage SFC, optimizing deployment costs, reducing overall end-to-end delay and optimizing VNF instances distribution. Miloud Bagaa, Tarik Taleb, Jorge Bernal Bernabé, Antonio F. Skarmeta |
IEEE Trans. Mob. Comput. | 3 |
| 2021 | Towards a standardized model for privacy-preserving Verifiable CredentialsabstractLack of standardization and the subsequent difficulty of integration has been one of the main reasons for the scarce adoption of privacy-preserving Attribute-Based Credentials (p-ABC). Integration with the W3C’s Verifiable Credentials (VC) specification would help by encouraging homogenization between different p-ABC schemes and bringing them all closer to other digital credentials. What is more, p-ABCs can help to solve privacy issues that have been identified in applications of VCs to use cases like vaccination passports. However, there has not been much work focusing on the collaboration between p-ABCs and VCs. We address this topic by establishing initial steps for extra standardization of elements that will help with the integration of p-ABCs into the standard. Namely, we propose a data model for predicates, which are a staple of p-ABC systems, and tools and guidelines to ease the adaptation process like a validation meta-schema. These ideas have been applied in a proof-of-concept implementation of the OLYMPUS distributed p-ABC scheme paired with serialization following the VC data model. Jesús García Rodríguez, Rafael Torres Moreno, Jorge Bernal Bernabé, Antonio F. Skarmeta |
ARES | 3 |
| 2021 | Implementation and evaluation of a privacy-preserving distributed ABC scheme based on multi-signaturesabstractDespite the latest efforts to foster the adoption of privacy-enhancing Attribute-Based Credential (p-ABC) systems in electronic services, those systems are not yet broadly adopted. The main reasons behind this are performance efficiency issues, lack of interoperability with standards, and the centralized architectural scheme that relies on a unique Identity Provider (IdP) for credential issuance. To cope with these limitations, this paper describes the first implementation of the Pointcheval–Sanders Multi-Signatures (PS-MS) crypto scheme proposed by Camenisch et al. and its integration in a distributed and privacy-preserving identity management system proposed in OLYMPUS H2020 European research project. Our efficient implementation provides remarkable privacy-preservation features for identity management in online transactions leveraging p-ABC systems, including unforgeability, minimal disclosure of personal data through zero-knowledge proofs, unlinkability in online transactions and fully distributed credential issuance across different IdPs, thereby removing the IdP as a unique point of failure. The performance of the implementation has been exhaustively analyzed and evaluated with different curves, signers and number of attributes, and compared against Identity Mixer, the best known p-ABC system, outperforming significantly the credential issuance and zero-knowledge proving and verification processes (2–4 times less execution time). Jesús García Rodríguez, Rafael Torres Moreno, Jorge Bernal Bernabé, Antonio F. Skarmeta |
J. Inf. Secur. Appl. | 3 |
| 2021 | Distributed real-time SlowDoS attacks detection over encrypted traffic using Artificial Intelligence
Norberto Garcia, Tomás Alcañiz, Aurora González-Vidal, Jorge Bernal Bernabé, Antonio F. Skarmeta |
J. Netw. Comput. Appl. | 4 |
| 2021 | Advanced spatial network metrics for cognitive management of 5G networksabstractAbstract The emerging fifth-generation (5G) mobile networks are empowered by softwarization and programmability, leading to the huge potentials of unprecedented flexibility and capability in cognitive network management such as self-reconfiguration and self-optimization. To help unlock such potentials, this paper proposes a novel framework that is able to monitor and calculate 5G network topological information in terms of advanced spatial metrics. These metrics, together with enabling and optimization algorithms, are purposely designed to address the complexity of 5G network topologies introduced by network virtualization and infrastructure sharing among operators (multi-tenancy). Consequently, this new framework, centred on a topology monitoring agent (TMA), enables on-demand 5G networks’ spatial knowledge and topological awareness required by 5G cognitive network management in making smart decisions in various autonomous network management tasks including but not limited to virtual network function placement strategies. The paper describes several technical use cases enabled by the proposed framework, including proactive cache allocation, computation offloading, node overloading alerting, and load balancing. Finally, a realistic 5G testbed is deployed with the central component TMA, together with the new spatial metrics and associated algorithms, implemented. Experimental results empirically validate the proposed approach and demonstrate the scalability and performance of the TMA component. Ignacio Sanchez-Navarro, Jorge Bernal Bernabé, José M. Alcaraz Calero, Qi Wang 0001 |
Soft Comput. | 2 |
| 2020 | INSPIRE-5Gplus: intelligent security and pervasive trust for 5G and beyond networksabstractThe promise of disparate features envisioned by the 3GPP for 5G, such as offering enhanced Mobile Broadband connectivity while providing massive Machine Type Communications likely with very low data rates and maintaining Ultra Reliable Low Latency Communications requirements, create a very challenging environment for protecting the 5G networks themselves and associated assets. To overcome such complexity, future 5G networks must employ a very high degree of network and service management automation, which is a security challenge by itself as well as an opportunity for smarter and more efficient security functions. In this paper, we present the smart, trustworthy and liable 5G security platform being designed and developed in the INSPIRE-5Gplus1 project. This platform takes advantage of new techniques such as Machine Learning (ML), Artificial Intelligence (AI), Distributed Ledger Technologies (DLT), network softwarization and Trusted Execution Environment (TEE) for closed-loop and end-to-end security management following a zero-touch model in 5G and Beyond 5G networks. To this end, we specifically elaborate on two key aspects of our platform, namely security management with Security Service Level Agreements (SSLAs) and liability management, in addition to the description of the overall architecture. Jordi Ortiz 0001, Ramon Sanchez-Iborra, Jorge Bernal Bernabé, Antonio F. Skarmeta, Chafika Benzaid, Tarik Taleb, Pol Alemany, Raul Muñoz 0001, Ricard Vilalta, Chrystel Gaber, Jean-Philippe Wary, Dhouha Ayed, Pascal Bisson, Maria Christopoulou, Georgios Xilouris, Edgardo Montes de Oca, Gürkan Gür, Gianni Santinelli, Vincent Lefebvre, Antonio Pastor 0001, Diego R. López |
ARES | 3 |
| 2020 | QoS and Resource aware Security Orchestration SystemabstractNetwork Function Virtualization (NFV) and Software Distributed Networking (SDN) technologies play a crucial role in enabling 5G system and beyond. A synergy between these both technologies has been identified for enabling a new concept dubbed service function chains (SFC) that aims to reduce both the capital expenditures (CAPEX) and operating expenses (OPEX). The SFC paradigm considers different constraints and key performance indicators (KPIs), that includes QoS and different resources, for enabling network slice services. However, the large-scale, complexity and security issues brought by these technologies create an extra overhead for ensuring secure network slicing. To cope with these challenges, this paper proposes a cost-efficient optimized SFC management system that enables the creation of SFCs for enabling efficient and secure network slices. The proposed system considers the network and computational resources and current network security levels to ensure trusted deployments. The simulation results demonstrated the efficiency of the proposed solution for achieving its designed objectives. The proposed solution efficiently manages the SFCs by optimizing deployment costs and reducing overall end-to-end delay. Miloud Bagaa, Tarik Taleb, Jorge Bernal Bernabé, Antonio F. Skarmeta |
GLOBECOM | 3 |
| 2020 | ARIES: Evaluation of a reliable and privacy-preserving European identity management framework
Jorge Bernal Bernabé, Martin David, Rafael Torres Moreno, Javier Presa Cordero, Sébastien Bahloul, Antonio F. Skarmeta |
Future Gener. Comput. Syst. | 1 |
| 2020 | Virtual IoT HoneyNets to Mitigate Cyberattacks in SDN/NFV-Enabled IoT NetworksabstractAs the IoT adoption is growing in several fields, cybersecurity attacks involving low-cost end-user devices are increasing accordingly, undermining the expected deployment of IoT solutions in a broad range of scenarios. To address this challenge, emerging Network Function Virtualization (NFV) and Software Defined Networking (SDN) technologies can introduce new security enablers, thereby endowing IoT systems and networks with higher degree of scalability and flexibility required to cope with the security of massive IoT deployments. In this sense, honeynets can be enhanced with SDN and NFV support, to be applied into IoT scenarios thereby strengthening the overall security. IoT honeynets are virtualized services simulating real IoT networks deployments, so that attackers can be distracted from the real target. In this paper, we present a novel mechanism leveraging SDN and NFV aimed to autonomously deploy and enforce IoT honeynets. The system follows a security policy-based approach that facilitates management, enforcement and orchestration of the honeynets and it has been successfully implemented and tested in the scope of H2020 EU project ANASTACIA, showing its feasibility to mitigate cyber-attacks. Alejandro Molina Zarca, Jorge Bernal Bernabé, Antonio F. Skarmeta, José M. Alcaraz Calero |
IEEE J. Sel. Areas Commun. | 2 |
| 2020 | Distributed Security Framework for Reliable Threat Intelligence SharingabstractComputer security incident response teams typically rely on threat intelligence platforms for information about sightings of cyber threat events and indicators of compromise. Other security building blocks, such as Network Intrusion Detection Systems, can leverage the information to prevent malicious adversaries from spreading malware across critical infrastructures. The effectiveness of threat intelligence platforms heavily depends on the willingness to share among organizations and the responsible use of sensitive information that may potentially harm the reputation of the reporting organization. The challenge that we address is the lack of trust in the source providing the threat intelligence and the information itself. We enhance our security framework TATIS—offering fine-grained protection for threat intelligence platform APIs—with distributed ledger capabilities to enable reliable and trustworthy threat intelligence sharing with the ability to audit the provenance of threat intelligence. We have implemented and evaluated the feasibility of our distributed framework on top of the Malware Information Sharing Platform (MISP) solution, and we evaluate the performance impact using real-world open-source threat intelligence feeds. Davy Preuveneers, Wouter Joosen, Jorge Bernal Bernabé, Antonio F. Skarmeta |
Secur. Commun. Networks | 3 |
| 2020 | Scalable Virtual Network Video-Optimizer for Adaptive Real-Time Video Transmission in 5G NetworksabstractThe increasing popularity of video applications and ever-growing high-quality video transmissions (e.g., 4K resolutions), has encouraged other sectors to explore the growth of opportunities. In the case of health sector, mobile Health services are becoming increasingly relevant in real-time emergency video communication scenarios where a remote medical experts' support is paramount to a successful and early disease diagnosis. To minimize the negative effects that could affect critical services in a heavily loaded network, it is essential for 5G video providers to deploy highly scalable and priorizable in-network video optimization schemes to meet the expectations of a large quantity of video treatments. This paper presents a novel 5G Video Optimizer Virtual Network Function (vOptimizerVNF) that leverages the latest technologies in 5G and video processing to address this important challenge. Advanced traffic filtering is coupled with Scalable H.265 video coding to enable run-time bandwidth-saving video optimization without compromising Quality of Service (QoS); kernel-space video processing is introduced to achieve further performance gains; and the use of a Virtual Network Function (VNF) facilitates dynamic deployment of virtualized video optimizers to achieve scalability and flexibility in this service. The proposed approach is implemented in a realistic 5G testbed and empirical results demonstrate the superior scalability and performance achieved. Pablo Salva-Garcia, José M. Alcaraz Calero, Qi Wang 0001, Miguel Arevalillo-Herráez, Jorge Bernal Bernabé |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2019 | Research challenges in nextgen service orchestration
Luis Miguel Vaquero González, Félix Cuadrado, Yehia El-khatib, Jorge Bernal Bernabé, Satish Narayana Srirama, Mohamed Faten Zhani |
Future Gener. Comput. Syst. | 4 |
| 2019 | Security Management Architecture for NFV/SDN-Aware IoT SystemsabstractThe Internet of Things (IoT) brings a multidisciplinary revolution in several application areas. However, security and privacy concerns are undermining a reliable and resilient broad-scale deployment of IoT-enabled critical infrastructures (IoT-CIs). To fill this gap, this paper proposes a comprehensive architectural design that captures the main security and privacy challenges related to cyber-physical systems and IoT-CIs. The architecture is devised to empower IoT systems and networks to make autonomous security decisions through the usage of novel technologies such as software defined networking and network function virtualization, as well as endowing them with intelligent and dynamic security reaction capabilities by relying on monitoring methodologies and cyber-situational tools. The architecture has been successfully implemented and evaluated in the scope of ANASTACIA H2020 EU research project. Alejandro Molina Zarca, Jorge Bernal Bernabé, Rubén Trapero, Jesus Villalobos, Antonio F. Skarmeta, Stefano Bianchi, Anastasios Zafeiropoulos, Panagiotis Gouvas |
IEEE Internet Things J. | 2 |
| 2018 | Protecting personal data in IoT platform scenarios through encryption-based selective disclosure
José Luis Hernández-Ramos, Salvador Pérez, Christine Hennebert, Jorge Bernal Bernabé, Benoît Denis, Alexandre Macabies, Antonio F. Skarmeta |
Comput. Commun. | 4 |
| 2018 | 5G NB-IoT: Efficient Network Traffic Filtering for Multitenant IoT Cellular NetworksabstractInternet of Things (IoT) is a key business driver for the upcoming fifth-generation (5G) mobile networks, which in turn will enable numerous innovative IoT applications such as smart city, mobile health, and other massive IoT use cases being defined in 5G standards. To truly unlock the hidden value of such mission-critical IoT applications in a large scale in the 5G era, advanced self-protection capabilities are entailed in 5G-based Narrowband IoT (NB-IoT) networks to efficiently fight off cyber-attacks such as widespread Distributed Denial of Service (DDoS) attacks. However, insufficient research has been conducted in this crucial area, in particular, few if any solutions are capable of dealing with the multiple encapsulated 5G traffic for IoT security management. This paper proposes and prototypes a new security framework to achieve the highly desirable self-organizing networking capabilities to secure virtualized, multitenant 5G-based IoT traffic through an autonomic control loop featured with efficient 5G-aware traffic filtering. Empirical results have validated the design and implementation and demonstrated the efficiency of the proposed system, which is capable of processing thousands of 5G-aware traffic filtering rules and thus enables timely protection against large-scale attacks. Pablo Salva-Garcia, José M. Alcaraz Calero, Qi Wang 0001, Jorge Bernal Bernabé, Antonio F. Skarmeta |
Secur. Commun. Networks | 4 |
| 2016 | Opportunistic smart object aggregation based on clustering and event processingabstractIn the envisioned Internet of Things ecosystems, Smart objects are intended to create groups of devices in order to provide higher level services to be leveraged by citizens. However, because of the dynamic nature of such scenarios, the discovery, management and operation of such dynamic coalitions taking into account security and privacy concerns, is a challenging task that has not been properly addressed yet. In this sense, the present proposal devises a novel approach to automatically compose opportunistic aggregations of objects (bubbles) based on Complex Event Processing (CEP) and fuzzy clustering. While the former detects certain events that could give raise to discover new bubbles, the latter allows compose aggrupations of similar objects acting as candidate bubbles. Finally, the application of the proposal in an educational domain is put forward. Fernando Terroso-Saenz, José Luis Hernández-Ramos, Jorge Bernal Bernabé, Antonio F. Skarmeta |
ICC | 3 |
| 2016 | TACIoT: multidimensional trust-aware access control system for the Internet of Things
Jorge Bernal Bernabé, José Luis Hernández-Ramos, Antonio F. Skarmeta |
Soft Comput. | 1 |
| 2015 | Intercloud Trust and Security Decision Support System: an Ontology-based Approach
Jorge Bernal Bernabé, Gregorio Martínez Pérez, Antonio F. Skarmeta |
J. Grid Comput. | 1 |
| 2015 | SAFIR: Secure access framework for IoT-enabled services on smart buildings
José Luis Hernández-Ramos, María Victoria Moreno Cano, Jorge Bernal Bernabé, Dan García-Carrillo, Antonio F. Skarmeta |
J. Comput. Syst. Sci. | 3 |
| 2014 | Semantic-aware multi-tenancy authorization system for cloud architectures
Jorge Bernal Bernabé, Juan Manuel Marín Pérez, José M. Alcaraz Calero, Félix J. García Clemente, Gregorio Martínez Pérez, Antonio F. Skarmeta |
Future Gener. Comput. Syst. | 1 |
| 2014 | Taxonomy of trust relationships in authorization domains for cloud computing
Juan Manuel Marín Pérez, Jorge Bernal Bernabé, José M. Alcaraz Calero, Félix J. García Clemente, Gregorio Martínez Pérez, Antonio F. Skarmeta |
J. Supercomput. | 2 |
| 2013 | Analyzing the security of Windows 7 and Linux for cloud computing
Khaled Salah 0001, José M. Alcaraz Calero, Jorge Bernal Bernabé, Juan Manuel Marín Pérez, Sherali Zeadally |
Comput. Secur. | 3 |
| 2011 | Towards an Authorization System for Cloud Infrastructure Providers
Jorge Bernal Bernabé, Juan Manuel Marín Pérez, José M. Alcaraz Calero, Félix J. García Clemente, Gregorio Martínez Pérez, Antonio F. Skarmeta |
SECRYPT | 1 |
| 2011 | Semantic-based authorization architecture for Grid
Juan Manuel Marín Pérez, Jorge Bernal Bernabé, José M. Alcaraz Calero, Félix J. García Clemente, Gregorio Martínez Pérez, Antonio F. Skarmeta |
Future Gener. Comput. Syst. | 2 |
| 2010 | Detection of semantic conflicts in ontology and rule-based information systems
José M. Alcaraz Calero, Juan Manuel Marín Pérez, Jorge Bernal Bernabé, Félix J. García Clemente, Gregorio Martínez Pérez, Antonio F. Skarmeta |
Data Knowl. Eng. | 3 |