Eduardo Fernández-Medina

dblp:f/EduardoFernandezMedina · DBLP profile ↗
← Back
79ranked-venue papers
7as first author
13since 2021 · last 2026
0000-0003-2553-9320ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 37 · 5 since 2021Software engineering, systems software and programming languages · 16 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 11 · 4 since 2021Databases, data management, data science and information retrieval · 10 · 4 first-author · 3 since 2021Artificial intelligence and machine learning · 9 · 2 first-author · 4 since 2021Systems, architecture and hardware · 1Computer networks · 1
YearPublicationVenuePosition
2026 Operational fairness diagnostics for AI-based detection systems: Metrics and methodology
abstract
AI systems operating in complex, high-frequency environments often make critical decisions such as generating alerts, prioritizing events or assigning severity scores , under conditions of partial ground truth , uneven group visibility and implicit, context-dependent logic. In such settings, it becomes difficult to assess whether behavior is consistent across sources, categories or technical modules. This challenge is particularly relevant in domains such as cybersecurity, where automated decisions directly influence threat prioritization, resource allocation and system-level risk exposure. Fairness metrics have been extensively studied in machine learning, yet most approaches assume supervised classification tasks with complete labels and explicit demographic groups. These assumptions often break down in operational AI systems, where decisions are decentralized, labels are partial or delayed, and group-defining attributes are technical , such as protocol type, sensor origin or detection source. As a result, classical fairness metrics often fail to detect or characterize structural disparities in real-world, partially supervised deployments. To address this gap, we propose a structured six-phase methodology for adapting fairness metrics, specifically independence , separation and sufficiency , to decision systems operating under dynamic and context-sensitive conditions. The framework is applied to the domain of cybersecurity, where the analysis of system behavior is challenged by alert inflation, detection imbalance and score inconsistency. The metrics are characterized using four synthetic scenarios, crafted to reproduce typical diagnostic conditions and to verify the selective sensitivity of each metric, and a real-world intrusion detection dataset (UNSW-NB15), in which a trained Random Forest classifier is evaluated via 5-fold stratified cross-validation to reflect operational conditions. Results show that, even under a high-performing classifier (global F1 = 0.98), the proposed metrics reveal protocol-level disparities not captured by aggregate performance measures, and remain stable under consistency-preserving conditions. Statistical testing confirms that the observed disparities are highly significant ( p < 1 0 − 300 ), with effect size analysis confirming their practical magnitude, and comparative analysis with standard fairness metrics reveals the limited diagnostic resolution of these classical indicators in operational settings . The resulting metrics are mutually compatible and respond independently across decision dimensions without conflict. Their interpretability and traceability support structured diagnostic analysis of system behavior. We formally derive their theoretical properties , and discuss how they complement the diagnostic objectives promoted by governance frameworks such as the EU AI Act, the NIST AI Risk Management Framework and ISO/IEC 42001. These results position the resulting metrics as diagnostic instruments for analyzing system-level behavior in environments characterized by partial supervision and evolving behavior .
Carlos Mario Braga Ortuño, Manuel A. Serrano, Eduardo Fernández-Medina
Knowl. Based Syst.3
2025 Early detection of backdoor attacks in federated learning via ecosystemic symmetry breaking
abstract
Evasive poisoning attacks such as semantic backdoors pose a growing threat to federated learning because they mimic benign client updates and evade detectors under secure aggregation. We introduce an unsupervised, per-client structural check that runs after each local round, before aggregation, requiring only compact statistical summaries derived from each client update after a geometric transformation that removes dependence on the global model. Client-update statistics are compared against a calibrated benign reference, and deviations are detected through statistical distances. Energy and Wasserstein-1 jointly define an operational pattern where threshold exceedances across projections reveal structural deviations even in apparently benign updates. Evaluated on canonical backdoor scenarios from Bagdasaryan et al., the method detects both strong and stealthy attacks in the first local round through consistent multi-projection threshold excesses, while benign updates show only isolated ones. The procedure is lightweight, unsupervised, compatible with secure aggregation, and does not require trigger datasets. By providing early per-client warnings before aggregation, it complements classical defenses such as norm clipping, differential privacy, and robust aggregation, enabling proactive mitigation of poisoning in federated learning.
Carlos Mario Braga Ortuño, Manuel A. Serrano, Eduardo Fernández-Medina
BDCAT3
2025 Towards a Framework for Personal and Domestic Cybersecurity
abstract
The expansion of the digital world increasingly surrounds us, making our lives easier and more connected. However, it also brings a range of risks and threats that we accept—sometimes consciously, sometimes unconsciously—for the sake of productivity or convenience. These cybersecurity risks affect almost every sector of society and have been mainly analyzed within government and corporate contexts. Despite this, comprehensive studies are still lacking for the personal and domestic sphere. In this domain, cybersecurity risks have a wide scope: they can affect the physical safety of individuals, lead to privacy breaches, or expose personal data for criminal use. Many other situations may also arise, severely impacting people in their everyday digital environment. This article analyzes previous work related to the lack of cybersecurity solutions for individuals in the personal domain. In addition, and given the absence of comprehensive approaches, it presents an initial version of a personal cybersecurity framework and a conceptual application model.
Ángel Suarez-Bárcena, Antonio Santos-Olmo, Eduardo Fernández-Medina
BDCAT3
2025 Guided and Federated RAG: Architectural Models for Trustworthy AI in Data Spaces
Carlos Mario Braga Ortuño, Manuel A. Serrano, Eduardo Fernández-Medina
IDEAL (2)3
2025 Towards a sustainable cybersecurity framework for Agriculture 4.0 based on a systematic analysis of proposals
abstract
The world is currently experiencing a profound transformation driven by the convergence of disruptive technologies under the concept of Industry 4.0. These technologies have driven sectors such as agriculture to modernize and automate for greater sustainability, leading to what is now referred to as Agriculture 4.0 However, this transformation entails risks and requires new frameworks that address cybersecurity, sustainability, and knowledge reuse. In this paper, we conduct a systematic review of these new systems with the aim of identifying their main shortcomings and proposing a new framework. The review revealed a significant gap in comprehensively addressing cybersecurity, AI, and sustainability. This highlights the need for deeper exploration of how these elements interact to benefit the agricultural sector. To this end, we propose the development of the QUILLAQUA framework, oriented towards secure, intelligent, and sustainable agriculture, with a focus on fostering effective synergies among these crucial components. This framework integrates advanced technologies in cybersecurity, IoT, and AI to optimise the management of water and nutritional resources in hydroponic systems, ensuring sustainability and data security. This approach aims to enhance technological efficiency in agriculture. It also aims to foster greater awareness to tackle present and future challenges in sustainable agriculture. By doing so, it ensures a successful transition toward more digitized and secure agricultural practices.
Diegof Bustamantev, Luis Enrique Sánchez Crespo, David Garcia Rosado, Antonio Santos-Olmo, Eduardo Fernández-Medina
Comput. Secur.5
2025 Integrated maritime protection: Innovation for the safeguarding of maritime systems based on MARISMA
abstract
The maritime sector is becoming increasingly susceptible to sophisticated cyber-attacks, underscoring the pressing necessity for advanced research and development to establish robust safeguards for maritime assets. Although risk assessment methods for traditional IT systems are now highly developed, they are not directly applicable to risk assessment in maritime environments due to the specific characteristics and particularities of the latter. Therefore, there is an urgent need to define approaches that adequately support risk assessment in maritime environments. To contribute to this important challenge, we propose a novel risk analysis technique, specifically tailored for the maritime sector, based on MARISMA, a security management methodology, and eMARISMA, its cloud-based technological support tool. Our work contributes to the state of the art by defining the MARISMA-SHIPS maritime cybersecurity pattern, which includes a set of reusable and adaptable elements that enable risk management and control in a maritime environment, and is aligned with major international standards such as ENISA and NIST, as well as existing maritime regulations, becoming a key part of our ongoing POSEIDON maritime cybersecurity framework. A case study is presented for a ship developed in the main shipyard in Colombia, which shows how the reusability and adaptability of the proposal allows the proposed MARISMA-SHIPS pattern to be easily adapted to any maritime environment, and which allowed the identification of critical areas of cybersecurity that could be improved. The application of the process in the maritime domain has proven its value in improving the efficiency and security management of maritime assets.
Ferney Martínez 0001, Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, David Garcia Rosado, Eduardo Fernández-Medina
Comput. Secur.5
2025 Towards a methodology for ethical artificial intelligence system development: A necessary trustworthiness taxonomy
abstract
Recently, generative artificial intelligence (GenAI) has arisen and been rapidly adopted; due to its emergent abilities, there is a significantly increased need for risk management in the implementation of such systems. At the same time, many proposals for translating ethics into AI, as well as the first agreements by regulators governing the use of artificial intelligence (AI), have surfaced. This underscores the need for Trustworthy AI, which implies reliability, compliance, and ethics. However, there is still a lack of unified criteria, and more critically, a lack of systematic methodologies for operationalizing trustworthiness within AI development processes . Trustworthiness is crucial, as it ensures that the system performs consistently under expected conditions while adhering to moral and legal standards. The problem of ensuring trustworthiness must be addressed as a preliminary step in creating a methodology for building AI systems with these desirable features. Based on a systematic literature review (SLR), we analyze the ethical, legal, and technological challenges that AI projects face , identifying key considerations and gaps in current approaches. This article presents a detailed and structured sociotechnical taxonomy related to the concept of Trustworthy AI, grounded in the analysis of all relevant texts on the topic, and designed to enable the systematic integration of ethical, legal, and technological principles into AI development processes. The taxonomy establishes a sociotechnical foundation that reflects the interconnected nature of technological, ethical, and legal considerations, and serves as the conceptual basis for CRISP-TAI, a proposed specialized development lifecycle currently under validation, aimed at systematically operationalizing trustworthiness principles across all phases of AI system engineering.
Carlos Mario Braga Ortuño, Manuel A. Serrano, Eduardo Fernández-Medina
Expert Syst. Appl.3
2024 Towards an integrated risk analysis security framework according to a systematic analysis of existing proposals
abstract
Abstract The information society depends increasingly on risk assessment and management systems as means to adequately protect its key information assets. The availability of these systems is now vital for the protection and evolution of companies. However, several factors have led to an increasing need for more accurate risk analysis approaches. These are: the speed at which technologies evolve, their global impact and the growing requirement for companies to collaborate. Risk analysis processes must consequently adapt to these new circumstances and new technological paradigms. The objective of this paper is, therefore, to present the results of an exhaustive analysis of the techniques and methods offered by the scientific community with the aim of identifying their main weaknesses and providing a new risk assessment and management process. This analysis was carried out using the systematic review protocol and found that these proposals do not fully meet these new needs. The paper also presents a summary of MARISMA, the risk analysis and management framework designed by our research group. The basis of our framework is the main existing risk standards and proposals, and it seeks to address the weaknesses found in these proposals. MARISMA is in a process of continuous improvement, as is being applied by customers in several European and American countries. It consists of a risk data management module, a methodology for its systematic application and a tool that automates the process.
Antonio Santos-Olmo, Luis Enrique Sánchez Crespo, David Garcia Rosado, Manuel A. Serrano, Carlos Blanco 0001, Haralambos Mouratidis, Eduardo Fernández-Medina
Frontiers Comput. Sci.7
2024 Enabling security risk assessment and management for business process models
abstract
Business processes (BP) are considered the enterprise’s cornerstone but are increasingly in the spotlight of attacks. Therefore, the design of business processes must consider the security risks and be adequately integrated into the information and operational systems. However, security risk assessment and management are rarely considered at the level of business processes during design time, let alone considering a risk architecture that takes into account the connection and dependencies of risks at these levels of the organisation, business processes, and information systems. In general, most approaches deal with integrating new artefacts for business process models to support risk analysis, but sometimes, the notation can increase complexity, making it difficult to have a risk management tool to support the analysis. After analysing the current risk processes and frameworks, we have realised that they are often neglected when considering organisational and business process levels. In this paper, MARISMA-BP (MARISMA for Business Process) pattern is proposed, a security risk pattern to enable the assessment and management of risks for business process models. This approach is an artefact that has been validated in a real scenario following the design science methodology. Further, MARISMA-BP pattern is supported by eMARISMA, an automated infrastructure that allows the definition and reuse of each risk component, helping us to carry out the risk assessment and management process in an efficient and dynamic way. To demonstrate the applicability of the proposal, MARISMA-BP pattern is applied to a real health-based business process scenario. The findings illustrate the efficacy of MARISMA-BP within eMARISMA for comprehensive risk assessment and management, underscoring its versatility and practical relevance in any business process environment.
David Garcia Rosado, Luis Enrique Sánchez Crespo, Angel Jesus Varela-Vaca, Antonio Santos-Olmo, María Teresa Gómez-López, Rafael M. Gasca, Eduardo Fernández-Medina
J. Inf. Secur. Appl.7
2024 Minimizing incident response time in real-world scenarios using quantum computing
abstract
Abstract The Information Security Management Systems (ISMS) are global and risk-driven processes that allow companies to develop their cybersecurity strategy by defining security policies, valuable assets, controls, and technologies for protecting their systems and information from threats and vulnerabilities. Despite the implementation of such management infrastructures, incidents or security breaches happen. Each incident has associated a level of severity and a set of mitigation controls, so in order to restore the ISMS, the appropriate set of controls to mitigate their damage must be selected. The time in which the ISMS is restored is a critical aspect. In this sense, classic solutions are efficient in resolving scenarios with a moderate number of incidents in a reasonable time, but the response time increases exponentially as the number of incidents increases. This makes classical solutions unsuitable for real scenarios in which a large number of incidents are handled and even less appropriate for scenarios in which security management is offered as a service to several companies. This paper proposes a solution to the incident response problem that acts in a minimal amount of time for real scenarios in which a large number of incidents are handled. It applies quantum computing, as a novel approach that is being successfully applied to real problems, which allows us to obtain solutions in a constant time regardless of the number of incidents handled. To validate the applicability and efficiency of our proposal, it has been applied to real cases using our framework (MARISMA).
Manuel A. Serrano, Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, David Garcia Rosado, Carlos Blanco 0001, Vita Santa Barletta, Danilo Caivano, Eduardo Fernández-Medina
Softw. Qual. J.8
2022 Security policies by design in NoSQL document databases
abstract
The importance of data security is currently increasing owing to the number of data transactions that are continuously taking place. Large amounts of data are generated, stored, modified and transferred every second, signifying that databases require an appropriate capacity, control and protection that will enable them to maintain a secure environment for so much data. Big Data is becoming a prominent trend in our society, and increasing amounts of data, including sensitive and personal information, are being loaded into NoSQL and other Big Data technologies for analysis and processing. However, current security approaches do not take into account the special characteristics of these technologies, leaving sensitive and personal data unprotected and consequently risking considerable financial losses and brand damage. In this paper, we focus on NoSQL document databases and present a proposal for the design and implementation of security policies in this type of databases. We first follow the concept of security by design in order to propose a metamodel that allows the specification of both the structure and the security policies required for document databases. We also define an implementation model by analysing the implementation features provided by a specific NoSQL document database management system (MongoDB). Having obtained the design and implementation models, we follow the model-driven development philosophy and propose a set of transformation rules that allow the automatic generation of the final implementation of security policies. We additionally provide a technological solution in which the Eclipse Modelling Framework environment is employed in order to implement both the design metamodel (Emfatic) and the transformations (Epsilon, EGL). Finally, we apply the proposed framework to a case study carried out in the airport domain. This proposal, in addition to saving development time and costs, generates more robust solutions by considering security by design. This, therefore, abstracting the designer from both specific aspects of the target tool and having to choose the best strategies for the implementation of security policies.
Carlos Blanco 0001, Diego García-Saiz, David Garcia Rosado, Antonio Santos-Olmo, Jesús Peral Cortés, Alejandro Maté, Juan Trujillo 0001, Eduardo Fernández-Medina
J. Inf. Secur. Appl.8
2021 MARISMA-BiDa pattern: Integrated risk analysis for big data
David Garcia Rosado, Julio Moreno, Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, Manuel A. Serrano, Eduardo Fernández-Medina
Comput. Secur.6
2021 Improving security in NoSQL document databases through model-driven modernization
abstract
Abstract NoSQL technologies have become a common component in many information systems and software applications. These technologies are focused on performance, enabling scalable processing of large volumes of structured and unstructured data. Unfortunately, most developments over NoSQL technologies consider security as an afterthought, putting at risk personal data of individuals and potentially causing severe economic loses as well as reputation crisis. In order to avoid these situations, companies require an approach that introduces security mechanisms into their systems without scrapping already in-place solutions to restart all over again the design process. Therefore, in this paper we propose the first modernization approach for introducing security in NoSQL databases, focusing on access control and thereby improving the security of their associated information systems and applications. Our approach analyzes the existing NoSQL solution of the organization, using a domain ontology to detect sensitive information and creating a conceptual model of the database. Together with this model, a series of security issues related to access control are listed, allowing database designers to identify the security mechanisms that must be incorporated into their existing solution. For each security issue, our approach automatically generates a proposed solution, consisting of a combination of privilege modifications, new roles and views to improve access control. In order to test our approach, we apply our process to a medical database implemented using the popular document-oriented NoSQL database, MongoDB. The great advantages of our approach are that: (1) it takes into account the context of the system thanks to the introduction of domain ontologies, (2) it helps to avoid missing critical access control issues since the analysis is performed automatically, (3) it reduces the effort and costs of the modernization process thanks to the automated steps in the process, (4) it can be used with different NoSQL document-based technologies in a successful way by adjusting the metamodel, and (5) it is lined up with known standards, hence allowing the application of guidelines and best practices.
Alejandro Maté, Jesús Peral Cortés, Juan Trujillo 0001, Carlos Blanco 0001, Diego García-Saiz, Eduardo Fernández-Medina
Knowl. Inf. Syst.6
2020 Application of security reference architecture to Big Data ecosystems in an industrial scenario
abstract
Summary Big Data environments are typically very complex ecosystems; this means that implementing them is complicated. One possible technique with which to address this complexity is the use of abstraction. Reference architecture (RA) can be useful for an improved understanding of the main components of Big Data. Herein, we propose a security RA that includes the management of security concerns and provides the main elements of a Big Data ecosystem. Application of this architecture to real‐world scenarios facilitates its refinement and improves its usefulness. In this article, we present a case study of a real‐world Big Data ecosystem implemented in a banking environment. This ecosystem was developed by everis, an NTT company with which we collaborated for this study. To conduct this validation case study, a map was established between the elements of the Big Data ecosystem implemented and our proposal. Consequently, a series of valuable lessons that can improve both our architecture and the security of the Big Data environment were obtained. These include recommendations for a set of best practices such as the use of security patterns.
Julio Moreno, Manuel A. Serrano, Eduardo B. Fernández, Eduardo Fernández-Medina
Softw. Pract. Exp.5
2018 Towards a Security Reference Architecture for Big Data
Julio Moreno, Manuel A. Serrano, Eduardo Fernández-Medina, Eduardo B. Fernández
DOLAP3
2018 How the Conceptual Modelling Improves the Security on Document Databases
Carlos Blanco 0001, Diego García-Saiz, Jesús Peral Cortés, Alejandro Maté, Alejandro Oliver, Eduardo Fernández-Medina
ER6
2015 Modernizing Secure OLAP Applications with a Model-Driven Approach
abstract
The majority of the organizations store their historical business information in data warehouses which are queried to make strategic decisions by using online analytical processing (OLAP) tools. This information has to be correctly assured against unauthorized accesses, but nevertheless there are a great amount of legacy OLAP applications that have been developed without considering security aspects or these have been incorporated once the system was implemented. This work defines a reverse engineering process that allows us to obtain the conceptual model corresponding to a legacy OLAP application, and also analyses and represents the security aspects that could have established. This process has been aligned with a model-driven architecture for developing secure OLAP applications by defining the transformations needed to automatically apply it. Once the conceptual model has been extracted, it can be easily modified and improved with security, and automatically transformed to generate the new implementation.
Carlos Blanco 0001, Eduardo Fernández-Medina, Juan Trujillo 0001
Comput. J.2
2015 ISGcloud: a Security Governance Framework for Cloud Computing
abstract
Security risks to organizations’ information assets are hindering the development of cloud computing services. A comprehensive security governance process is needed to foster the massive adoption of cloud services and to facilitate the deployment of a security culture within any company. In this paper, we present a framework focused on the security governance of the cloud computing environment (ISGcloud), which has been built upon standards. Its principal components are based on the ISO/IEC 38500 governance standard and on the ISO/IEC 27036 outsourcing security draft. We propose a systematic collection of activities and their related tasks which detail how security governance can be deployed during the entire cloud service lifecycle. Furthermore, the whole framework is formally modelled following the SPEM 2.0 specification that provides a standardized interface with which to automate and integrate our proposed process. The theoretical definition of our proposal is also accompanied by a practical example of its application, which provides specific details of ISGcloud framework's implementation.
Oscar Rebollo, Daniel Mellado, Eduardo Fernández-Medina
Comput. J.3
2015 An architecture for automatically developing secure OLAP applications from models
Carlos Blanco 0001, Ignacio García Rodríguez de Guzmán, Eduardo Fernández-Medina, Juan Trujillo 0001
Inf. Softw. Technol.3
2015 Empirical evaluation of a cloud computing information security governance framework
Oscar Rebollo, Daniel Mellado, Eduardo Fernández-Medina, Haralambos Mouratidis
Inf. Softw. Technol.3
2014 Enterprise security pattern: a new type of security pattern
abstract
ABSTRACT In recent years, most organizations have suffered attacks against their information systems. For this reason, organizations should seek support from enterprise security architectures (ESAs) in order to secure their information assets. Security patterns can help when building complex ESAs, but they have some limitations that reduce their usability. In this paper, we define the metapattern of a new type of security pattern called Enterprise Security Pattern. This new metapattern provides a model‐driven environment and combines all elements that must be considered when designing and building ESAs. We present here a precise meta‐model and four diagrams to describe the metapattern of the enterprise security patterns. When avoiding a security problem, organizations could use enterprise security patterns to provide their designers with an optimal and proven security guideline and so standardize the design and building of the ESA for that problem. Enterprise security patterns could also facilitate the selection and tailoring of security policies, patterns, mechanisms, and technologies when a designer is building ESAs. To illustrate our ideas, we present an instance of this new type of pattern, showing how it can be used. Copyright © 2014 John Wiley & Sons, Ltd.
Santiago Moral-García, Santiago Moral-Rubio, David Garcia Rosado, Eduardo B. Fernández, Eduardo Fernández-Medina
Secur. Commun. Networks5
2013 Development of Secure XML Data Warehouses with QVT
Belén Vela, Jose-Norberto Mazón, Carlos Blanco 0001, Eduardo Fernández-Medina, Juan Trujillo 0001, Esperanza Marcos
Inf. Softw. Technol.4
2012 A practical application of our MDD approach for modeling secure XML data warehouses
Belén Vela, Carlos Blanco 0001, Eduardo Fernández-Medina, Esperanza Marcos
Decis. Support Syst.3
2011 Secure business process model specification through a UML 2.0 activity diagram profile
Alfonso Rodríguez 0001, Eduardo Fernández-Medina, Juan Trujillo 0001, Mario Piattini
Decis. Support Syst.2
2011 Systematic design of secure Mobile Grid systems
David Garcia Rosado, Eduardo Fernández-Medina, Javier López 0001, Mario Piattini
J. Netw. Comput. Appl.2
2011 Security services architecture for Secure Mobile Grid Systems
David Garcia Rosado, Eduardo Fernández-Medina, Javier López 0001
J. Syst. Archit.2
2010 Managing the Asset Risk of SMEs
abstract
The information society is becoming increasingly dependent on systems for managing and analyzing the risk to which its main information assets are exposed and having access to these systems has become vital for the evolution of SMEs. However, this type of company requires the systems to be adapted to their special characteristics and to be optimized from the point of view of resources required to set them up and maintain them. This article presents a proposed method for carrying out risk analysis adaptation, which is suitable for SMEs, set within the framework of the methodology for security management in small and medium-sized enterprises (MSM2-SME). This model is being applied directly to real cases, and therefore its application is constantly being improved.
Luis Enrique Sánchez Crespo, Eduardo Fernández-Medina, Mario Piattini
ARES3
2010 A Study of Security Approaches for the Development of Mobile Grid Systems
David Garcia Rosado, Eduardo Fernández-Medina, Javier López 0001
ICSOFT (1)2
2010 Building ISMS through the Reuse of Knowledge
Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, Eduardo Fernández-Medina, Mario Piattini
TrustBus3
2010 Security requirements engineering framework for software product lines
Daniel Mellado, Eduardo Fernández-Medina, Mario Piattini
Inf. Softw. Technol.2
2010 Semi-formal transformation of secure business processes into analysis class and use case models: An MDA approach
Alfonso Rodríguez 0001, Ignacio García Rodríguez de Guzmán, Eduardo Fernández-Medina, Mario Piattini
Inf. Softw. Technol.3
2010 Analysis of Secure Mobile Grid Systems: A systematic approach
David Garcia Rosado, Eduardo Fernández-Medina, Javier López 0001, Mario Piattini
Inf. Softw. Technol.2
2009 Including Security Rules Support in an MDA Approach for Secure DWs
abstract
Information security is a crucial aspect for enterprises that has to be considered as a strong requirement from the early stages of the development process and Data Warehouses (DWs) manage highly important information used to make strategic decisions which has to be protected from unauthorized users. In order to develop secure DWs we have proposed a Model Driven Architecture (MDA) composed of several secure metamodels at different abstraction levels and transformations between them. Lately, a specialization of this architecture considering a multidimensional approach towards On-Line Analytical Processing (OLAP) tools has been defined, but the support to automatically transform complex security rules has not been dealt with so far. This paper analyzes this lack and defines improvements in our metamodels and a set of transformations between models in order to fulfill our MDA approach.
Carlos Blanco 0001, Ignacio García Rodríguez de Guzmán, Eduardo Fernández-Medina, Juan Trujillo 0001, Mario Piattini
ARES3
2009 Applying an MDA-Based Approach to Consider Security Rules in the Development of Secure DWs
abstract
Data Warehouses (DWs) manage crucial information for enterprises which must be protected from unauthorized accesses. The question of which security issues are present in all stages of the DW design is therefore of great importance when considering these security constraints in design decisions. We have used the Model Driven Architecture (MDA) approach to propose an MDA architecture with which to develop secure DWs, which defines secure models at different abstraction levels along with their automatic transformation between models. Our approach considers a multidimensional path towards On-Line Analytical Processing (OLAP) tools, but did not, until now, support the transformation of complex security rules from conceptual models. After carrying out a modification of our conceptual metamodel to support a better representation of security rules and to define several sets of transformation rules, this paper shows how to transform these security rules through an example.
Carlos Blanco 0001, Ignacio García Rodríguez de Guzmán, Eduardo Fernández-Medina, Juan Trujillo 0001, Mario Piattini
ARES3
2009 Automated Support for Security Requirements Engineering in Software Product Line Domain Engineering
abstract
Security and requirements engineering are one of the most important factor of success in the development of a software product line due to the complexity and extensive nature of them, given that a weakness in security can cause problems throughout all the products of a product line. However, without a CARE (Computer-Aided Requirements Engineering) tool, the application of any security requirements engineering process or methodology is much more difficult because it has to be manually performed. Therefore, in this paper, we will present a prototype of SREPPLineTool, which provides automated support to facilitate the application of the security quality requirements engineering process for software product lines, SREPPLine. SREPPLineTool simplifies the management of security requirements in product lines by providing us with a guided, systematic and intuitive way to deal with them from the early phases of product lines development, simplifying the management and the visualization of the artefacts variability and traceability links and the integration of the security standards, as well as the management of the security reference model proposed by SREPPLine. Finally we shall illustrate the application of SREPPLineTool by describing a simple example as a preliminary validation of it
Daniel Mellado, Jesús Rodríguez, Eduardo Fernández-Medina, Mario Piattini
ARES3
2009 Towards a Modernization Process for Secure Data Warehouses
Carlos Blanco 0001, Ricardo Pérez-Castillo, Arnulfo Hernández, Eduardo Fernández-Medina, Juan Trujillo 0001
DaWaK4
2009 Model-Driven Development for secure information systems
Eduardo Fernández-Medina, Jan Jürjens, Juan Trujillo 0001, Sushil Jajodia
Inf. Softw. Technol.1
2009 The practical application of a process for eliciting and designing security in web service systems
Carlos Gutiérrez, David Garcia Rosado, Eduardo Fernández-Medina
Inf. Softw. Technol.3
2009 An engineering process for developing Secure Data Warehouses
Juan Trujillo 0001, Emilio Soler, Eduardo Fernández-Medina, Mario Piattini
Inf. Softw. Technol.3
2008 Implementing Multidimensional Security into OLAP Tools
abstract
Data Warehouses (DW) manage historical information for the decision making process and for enterprises, it is vitally important to consider security requirements from the earliest stages of the development process. OLAP tools are the most used tools for implementing and consulting DWs and it is necessary to define security measures to avoid that users can access unauthorized information by executing queries. We have created a MDA architecture for developing secure DW and in this paper, we will propose how to implement the security measures defined at upper abstraction levels using our approach into SQL Server Analysis Services 2008.
Carlos Blanco 0001, Eduardo Fernández-Medina, Juan Trujillo 0001, Mario Piattini
ARES2
2008 A Systematic Review and Comparison of Security Ontologies
abstract
The use of ontologies for representing knowledge provides us with organization, communication and reusability. Information security is a serious requirement which must be carefully considered. Concepts and relations managed by any scientific community need to be formally defined and ontological engineering supports their definition. In this paper, the method of systematic review is applied with the purpose of identifying, extracting and analyzing the main proposals for security ontologies. The main identified proposals are compared using a formal framework and we conclude by stating their early state of development and the need of additional research efforts.
Carlos Blanco 0001, Joaquín Lasheras, Rafael Valencia-García, Eduardo Fernández-Medina, José Ambrosio Toval Álvarez, Mario Piattini
ARES4
2008 Security Requirements Variability for Software Product Lines
abstract
Software product line engineering has proven to be one of the most successful paradigms for developing a diversity of similar software applications and software-intensive systems at low costs, in short time, and with high quality, by exploiting commonalities and variabilities among products to achieve high levels of reuse. At the same time, due to the complexity and extensive nature of product line development, security and requirements engineering are critical success factors in the development of a software product line. However, most of the current product line practices in requirements engineering do not adequately address the security requirements engineering. Therefore, in this paper we will propose a security requirements decision model driven by security standards along with a security variability model to manage the variability of the security requirements related artefacts. The aim of this approach is to deal with security requirements from the early stages of the product line development in a systematic way, in order to facilitate the conformance to the most relevant security standards with regard to the management of security requirements, such as ISO/IEC 27001 and ISO/IEC 15408.
Daniel Mellado, Eduardo Fernández-Medina, Mario Piattini
ARES2
2008 PSecGCM: Process for the Development of Secure Grid Computing based Systems with Mobile Devices
abstract
Mobile Grid, in relevance to both Grid and Mobile Computing, is a full inheritor of Grid with the additional feature of supporting mobile users and resources in a seamless, transparent, secure and efficient way. Security of these systems, due to their distributed and open nature, receives great interest. A formal approach to security in the software life cycle is essential to protect corporate resources. However, little thought has been given to this aspect of software development. Due to its criticality, security should be integrated as a formal approach in the software life cycle. A methodology of development for secure mobile Grid computing based systems is defined, that is to say, an engineering process that defines the steps to follow so that starting from the necessities to solve, we can design and construct a secure Grid system with support for mobile devices that is able to solve and cover these necessities.
David Garcia Rosado, Eduardo Fernández-Medina, Javier López 0001, Mario Piattini
ARES2
2008 Towards Comprehensive Requirement Analysis for Data Warehouses: Considering Security Requirements
abstract
Data warehouse (DW) systems integrate data from heterogeneous sources and are used by decision makers to analyze the status and the development of an organization. Traditionally, requirement analysis approaches for DWs have focused purely on information needs of decision makers, without considering other kinds of requirements such as security or performance. But modeling these issues in the early stages of the development is a cornerstone for building a DW that satisfies user expectations. In this paper, we define the two kinds of requirements for data warehousing as information and quality-of-service requirements and combine them in a comprehensive approach based on MDA (model driven architecture). This allows a separation of concerns to model requirements without losing the connection between information and quality-of-service, also in the following conceptual or logical design stages. Finally, in this paper, we introduce a security requirement model for data warehousing, and a three-step process for modeling security requirements, thus illustrating the applicability of our approach with an example.
Emilio Soler, Veronika Stefanov, Jose-Norberto Mazón, Juan Trujillo 0001, Eduardo Fernández-Medina, Mario Piattini
ARES5
2008 Security Requirements Engineering Process for Software Product Lines: A Case Study
abstract
The majority of the current product line practices in requirements engineering do not adequately address security requirements engineering despite the fact that security requirements engineering is both a central task and a critical success factor in product line development due to the complexity and extensive nature of product lines. Therefore, our contribution is to present and to demonstrate the applicability of our proposed security quality requirements engineering process (SREPPLine), which is based on a security requirements decision model driven by security standards along with a security variability model. We shall demonstrate our proposal by describing part of a real case study as a preliminary validation of these models. The final aim of this approach is to deal with security requirements variability from the early stages of the product line development in a systematic way, in order to facilitate conformance of the products with the most relevant security standards with regard to the management of security requirements, such as ISO/IEC 27001 and ISO/IEC 15408
Daniel Mellado, Eduardo Fernández-Medina, Mario Piattini
ICSEA2
2008 Security Requirements in Software Product Lines
Daniel Mellado, Eduardo Fernández-Medina, Mario Piattini
SECRYPT2
2008 Practical Application of a Security Management Maturity Model for SMEs based on Predefined Schemas
Luis Enrique Sánchez Crespo, Daniel Villafranca, Eduardo Fernández-Medina, Mario Piattini
SECRYPT3
2007 A Framework for the Development of Secure Data Warehouses based on MDA and QVT
abstract
Data warehouses (DWs) store historical and aggregated information, extracted from multiple heterogeneous, autonomous and distributed sources of information, therefore it is essential to specify security measures from early stages of DW design and to enforce them. Several proposals on DW development have arisen in the last couple of years. However, few approaches represent security measures in the DW conceptual model starting from early stages of development of a DW project. In addition, these security measures cannot be automatically represented at logical level, so heuristic design guides for such transformations have appeared. This paper presents a framework based on model driven architecture (MDA) for the development of secure data warehouses that covers all the phases of design (conceptual, logical and physical) and embeds security measures in all of them. Moreover, transformations between models are clearly and formally established by using query/view/transformation (QVT), to obtain consequently a traceability of the security rules from the early stages of development to the final implementation
Emilio Soler, Juan Trujillo 0001, Eduardo Fernández-Medina, Mario Piattini
ARES3
2007 A set of QVT relations to transform PIM to PSM in the Design of Secure Data Warehouses
abstract
Security represents a crucial aspect in the development of data warehouses (DWs), since they contain confidential data. It becomes therefore necessary to specify security and audit requirements for the multidimensional modelling, that cannot be directly transferred to the relational model of the DW. The standard framework for software development model driven architecture (MDA) allows us to define transformations between models by proposing query/view/transformations (QVT). This proposal allows the definition of formal, elegant and unequivocal transformations between platform independent model (PIM) and platform specific model (PSM). This paper employs QVT to establish a set of relations that allows us to transform security information embedded in the DWs multidimensional conceptual model to a relational logical scheme
Emilio Soler, Juan Trujillo 0001, Eduardo Fernández-Medina, Mario Piattini
ARES3
2007 Application of QVT for the Development of Secure Data Warehouses: A case study
abstract
Security is a crucial aspect for the development of data warehouses (DW) because they contain sensitive information. The application of the model driven architecture (MDA) in the secure modeling of DWs allows obtaining the secure logical scheme from the conceptual model. In this paper, we apply the query/view/transformations (QVT) language to the development of a secure DW by means of a case study. First, we introduce the case study related to a typical sanitary system. Afterwards, with the application of a set of QVT relations, we transform all the captured security and audit requirements from the multidimensional conceptual model of the DW, to the logical level, by means of the construction of a snowflake model. From this scheme it turns out easier to obtain code for a specific platform that implements security and audit aspects
Emilio Soler, Juan Trujillo 0001, Eduardo Fernández-Medina, Mario Piattini
ARES3
2007 Towards CIM to PIM Transformation: From Secure Business Processes Defined in BPMN to Use-Cases
Alfonso Rodríguez 0001, Eduardo Fernández-Medina, Mario Piattini
BPM2
2007 Defining Security Architectural Patterns Based on Viewpoints
David Garcia Rosado, Carlos Gutiérrez, Eduardo Fernández-Medina, Mario Piattini
ICCSA (3)3
2007 Developing a Model and a Tool to Manage the Information Security in Small and Medium Enterprises
Luis Enrique Sánchez Crespo, Daniel Villafranca, Eduardo Fernández-Medina, Mario Piattini
SECRYPT3
2007 Analysis-Level Classes from Secure Business Processes Through Model Transformations
Alfonso Rodríguez 0001, Eduardo Fernández-Medina, Mario Piattini
TrustBus2
2007 Model-driven multidimensional modeling of secure data warehouses
abstract
Data Warehouses (DW), Multidimensional (MD) databases, and On-Line Analytical Processing (OLAP) applications provide companies with many years of historical information for the decision-making process. Owing to the relevant information managed by these systems, they should provide strong security and confidentiality measures from the early stages of a DW project in the MD modeling and enforce them. In the last years, there have been some proposals to accomplish the MD modeling at the conceptual level. Nevertheless, none of them considers security measures as an important element in their models, and therefore, they do not allow us to specify confidentiality constraints to be enforced by the applications that will use these MD models. In this paper, we present an Access Control and Audit (ACA) model for the conceptual MD modeling. Then, we extend the Unified Modeling Language (UML) with this ACA model, representing the security information (gathered in the ACA model) in the conceptual MD modeling, thereby allowing us to obtain secure MD models. Moreover, we use the OSCL (Object Security Constraint Language) to specify our ACA model constraints, avoiding in this way an arbitrary use of them. Furthermore, we align our approach with the Model-Driven Architecture, the Model-Driven Security and the Model-Driven Data Warehouse, offering a proposal highly compatible with the more recent technologies.
Eduardo Fernández-Medina, Juan Trujillo 0001, Mario Piattini
Eur. J. Inf. Syst.1
2007 Developing secure data warehouses with a UML extension
Eduardo Fernández-Medina, Juan Trujillo 0001, Rodolfo Villarroel, Mario Piattini
Inf. Syst.1
2006 A Comparison of the Common Criteria with Proposals of Information Systems Security Requirements
abstract
Nowadays, security solutions are focused mainly on providing security defences; instead of solving one of the main reasons for security problems that refers to appropriate information systems (IS) design. Fortunately there are several standards, like the Common Criteria, which help to deal with the security requirements along all the IS development cycle. In this paper a comparative analysis of eight different relevant technical proposals, which place great importance on the establishing of security requirements in the development of IS, is carried out. And they provide some significant contributions in aspects related to security. Nevertheless, they only satisfy partly the necessary criteria for the establishment of security requirements, with guarantees and integration in the development of IS. Thus we conclude that they are not specific enough for dealing with security requirements in the first stages of IS development in a systematic and intuitive way.
Daniel Mellado, Eduardo Fernández-Medina, Mario Piattini
ARES2
2006 Security Requirement with a UML 2.0 Profile
abstract
Business processes are important for companies because they allow us to obtain an advanced marketplace position, and then, these enterprises can optimize and assure the quality of their products and services. Moreover, business processes are important for software developers, because they can capture from them the necessary requirements for software design and creation. At the same time, organizations have been opened and this implies more vulnerability. In spite of all these facts, security is an aspect that has been scarcely dealt with in the business process modeling. In this paper, we summarize our UML 2.0 profile for secure business process modeling through activity diagrams, and we apply this approach to a typical health-care business process.
Alfonso Rodríguez 0001, Eduardo Fernández-Medina, Mario Piattini
ARES2
2006 A Study of Security Architectural Patterns
abstract
Security and reliability issues are rarely considered at the initial stages of software development and are not part of the standard procedures in development of software and services. Security patterns are a recent development as a way to encapsulate the accumulated knowledge about secure systems design, and security patterns are also intended to be used and understood by developers who are not security professionals. In this paper, we compare several security patterns to be used when dealing with application security, following an approach that we consider important for measuring the security degree of the patterns, and indicating a fulfilment or not of the properties and attributes common to all security systems.
David Garcia Rosado, Eduardo Fernández-Medina, Mario Piattini, Carlos Gutiérrez
ARES2
2006 Practical Approach of a Secure Management System based on ISO/IEC 17799
abstract
For enterprises to be able to properly use information and communications technologies, it is necessary to have guides, metrics and tools that allow us to always know the level of our security and the points in which we are not covering it. In small and medium-size enterprises, the application of security standards has an additional problem, that is, the fact that they do not have enough resources to perform an appropriate management. In this article we analyze some of the existing maturity models and we compare them to the maturity model we are applying in practice. Finally we introduce a first approach to a scoreboard which is being developed as part of a security management tool for IT systems. This approach is being directly applied to real cases and it is obtaining a constant improvement in its application.
Luis Enrique Sánchez Crespo, Daniel Villafranca, Eduardo Fernández-Medina, Mario Piattini
ARES3
2006 Representing Security and Audit Rules for Data Warehouses at the Logical Level by Using the Common Warehouse Metamodel
abstract
Data warehouses (DWs) contained high sensitive data, and therefore, it is essential to specify security measures from the early stages of the DW design and enforce them. Access control models for transactional (relational) databases, based on tables, columns and rows, are not appropriate for DWs. Instead, security and audit rules defined for DWs must be specified based on the multidimensional (MD) modeling used to design data warehouses. So far, very few approaches represent security measures in the conceptual modeling of data warehouses form the early stages of a DW project. Moreover these security measures cannot be directly represented in the relational model for data warehouses, thereby having a semantic gap between the conceptual and logical schemas. In this paper, we present an extension of the relational model to consider security and audit measures represented in the conceptual modeling. To accomplish this, we based on the relational package of the common warehouse metamodel (CWM) and extend it to properly represent all security and audit rules defined in the conceptual modelling of data warehouses. Finally, to show the benefit of our approach, we apply our proposal to a health care case study.
Emilio Soler, Rodolfo Villarroel, Juan Trujillo 0001, Eduardo Fernández-Medina, Mario Piattini
ARES4
2006 Representing levels of abstraction to facilitate the Secure Multidimensional Modeling
abstract
In most real world data warehouses (DWs) projects, security aspects are issues that usually rely on DBMS administrators. We argue that the design of security aspects should be considered together with the conceptual modeling of DWs from the early stages of a DW project, and being able to attach user security information to the basic structures of a multidimensional (MD) model (e.g. dimensions, facts, attributes, and so on). In this way, we would be able to generate this information in a semi or automatic way into a target platform and the final DW will better suit user security requirements. In this paper, we will present an extension of the Unified Modeling Language (UML) using a UML profile to represent multidimensional and security aspects of our conceptual modeling. Our approach proposes the use of UML packages in order to group classes together into higher level units creating different levels of abstraction, and therefore, simplifying the final model. In this way, when modeling complex and large DWs systems, the designer is not restricted to use flat UML class diagrams. Finally, we would show an example to illustrate the applicability of our proposal.
Rodolfo Villarroel, Emilio Soler, Eduardo Fernández-Medina, Mario Piattini, Juan Trujillo 0001
ARES3
2006 Quality of Password Management Policy
abstract
The use of passwords is the most common method to carry out the authentication of users in information systems. For this reason, quality in the password management is a need to reach reasonable levels in the typical objectives of security. In this paper, we propose a set of metrics of password policies based on the most outstanding factors in this authentication mechanism. Together with the metrics, we propose a quality indicator derived from these metrics that allows us to have a global vision of the quality of the password management policy used. Finally, we indicate the future works to be performed to check the validity and usefulness of the proposed metrics.
Carlos Villarrubia, Eduardo Fernández-Medina, Mario Piattini
ARES2
2006 Applying a Security Requirements Engineering Process
Daniel Mellado, Eduardo Fernández-Medina, Mario Piattini
ESORICS2
2006 A Comparative Study of Proposals for Establishing Security Requirements for the Development of Secure Information Systems
Daniel Mellado, Eduardo Fernández-Medina, Mario Piattini
ICCSA (3)2
2006 Using UML Packages for Designing Secure Data Warehouses
Rodolfo Villarroel, Emilio Soler, Eduardo Fernández-Medina, Juan Trujillo 0001, Mario Piattini
ICCSA (3)3
2006 Metrics of Password Management Policy
Carlos Villarrubia, Eduardo Fernández-Medina, Mario Piattini
ICCSA (3)2
2006 PWSSec: Process for Web Services Security
abstract
In the last few years, the field of Web services (WS) security has evolved rapidly producing an impressive number of WS-based security standards. This fact has caused that organizations are still reticent about adopting technologies based on this paradigm due to the learning curve necessary to integrate security into their practical deployments. In this paper, we present PWSSec (process for Web services security) as a process that enables the integration of a set of specific stages into the traditional phases of WS-based systems development providing them with security. PWSSec is composed of three stages, WSSecReq (Web services security requirements), WSSecArch (Web services security architecture) and WSSecTech (Web services security technologies) that allow the specification of WS-specific security requirements, the definition of the WS-based security architecture and the identification of the security standards that the security architecture must deploy, respectively
Carlos Gutiérrez, Eduardo Fernández-Medina, Mario Piattini
ICWS2
2006 Security Risk Analysis in Web Services Systems
Carlos Gutiérrez, Eduardo Fernández-Medina, Mario Piattini
SECRYPT2
2006 Secure Information Systems Development - Based on a Security Requirements Engineering Process
Daniel Mellado, Eduardo Fernández-Medina, Mario Piattini
SECRYPT2
2006 Defining Viewpoints for Security Architectural Patterns
David Garcia Rosado, Carlos Gutiérrez, Eduardo Fernández-Medina, Mario Piattini
SECRYPT3
2006 Towards a UML 2.0 Extension for the Modeling of Security Requirements in Business Processes
Alfonso Rodríguez 0001, Eduardo Fernández-Medina, Mario Piattini
TrustBus2
2006 Access control and audit model for the multidimensional modeling of data warehouses
Eduardo Fernández-Medina, Juan Trujillo 0001, Rodolfo Villarroel, Mario Piattini
Decis. Support Syst.1
2005 Secure information systems development - a survey and comparison
Rodolfo Villarroel, Eduardo Fernández-Medina, Mario Piattini
Comput. Secur.2
2005 Designing secure databases
Eduardo Fernández-Medina, Mario Piattini
Inf. Softw. Technol.1
2004 Extending UML for Designing Secure Data Warehouses
Eduardo Fernández-Medina, Juan Trujillo 0001, Rodolfo Villarroel, Mario Piattini
ER1
2004 A Survey of Web Services Security
Carlos Gutiérrez, Eduardo Fernández-Medina, Mario Piattini
ICCSA (1)2
2003 Designing Secure Databases for OLS
Eduardo Fernández-Medina, Mario Piattini
DEXA1
2002 Access Control of SVG Documents
Ernesto Damiani, Sabrina De Capitani di Vimercati, Eduardo Fernández-Medina, Pierangela Samarati
DBSec3