VLDB 2026 Research / reviewers in the wild / expert
Joaquín García 0001
dblp:g/JoaquinGarcia · also Joaquín García-Alfaro
· DBLP profile ↗
71ranked-venue papers
8as first author
14since 2021 · last 2026
0000-0002-7453-4393ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 49 · 8 first-author · 11 since 2021Computer networks · 9 · 1 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Systems, architecture and hardware · 2Software engineering, systems software and programming languages · 2Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Game-Theoretic Approach for Optimal Multi-Target Defense Strategies in Programmable Networking
Jamil Kassem 0001, Helena Rifà-Pous, Joaquín García 0001 |
SECRYPT (1) | 3 |
| 2026 | Assessing the Operational Impact of Poisoning Attacks over Augmented 3D Point Cloud Public Datasets for Connected and Autonomous VehiclesabstractInternational audience Marwan Lazrag, Badis Hammi, Lorena González-Manzano, Joaquín García 0001 |
SECRYPT (1) | 4 |
| 2026 | Codebook-based uplink interference management for millimeter-wave cellular-connected uncrewed autonomous vehicle networks
Fatemeh Banaeizadeh, Michel Barbeau, Joaquín García 0001, Evangelos Kranakis |
Eng. Appl. Artif. Intell. | 3 |
| 2026 | Distributed Denial-of-Service Attack Vector Identification in IoT Networks Using Wavelet Transform and Hybrid Deep LearningabstractInternational audience Tohid Behdadnia, Klaas Thoelen, Joaquín García 0001, Geert Deconinck |
IEEE Internet Things J. | 3 |
| 2025 | LUMIA: Linear Probing for Unimodal and MultiModal Membership Inference Attacks Leveraging Internal LLM States
Luis Ibañez-Lissen, Lorena González-Manzano, José María de Fuentes, Nicolas Anciaux, Joaquín García 0001 |
ESORICS (1) | 5 |
| 2025 | A Quantum Algorithm for Assessing Node Importance in the st-Connectivity Attack
Iain Burge, Michel Barbeau, Joaquín García 0001 |
SEC (2) | 3 |
| 2025 | On the Resilience of Traditional AI Algorithms Toward Poisoning Attacks for Vulnerability DetectionabstractThe complexity of implementations and the interconnection of assorted systems and devices facilitate the emergence of vulnerabilities. Detection systems are developed to fight against this security issue, being the use of artificial intelligence (AI) a common practice. However, the use of AI is not without its problems, especially those affecting the training phase. This article tackles this issue by characterizing the resilience against poisoning attacks using a benchmark for vulnerability detection, extracting simple code features while applying traditional AI algorithms. These choices are beneficial for the fast processing of vulnerabilities required in a triage process. The study is carried out in C#, C/C++, and PHP. Results show that the vulnerability detection process is specially affected beyond 20% of false data. Remarkably, detecting some of the most frequent common weakness enumeration (CWE) is altered even with lower poison rates. Overall, K ‐nearest‐neighbor (KNN) and support vector machine (SVM) are the most resilient in C# and C/C++, while multilayer perceptron (MLP) in PHP. Indeed, vulnerability detection in PHP is less affected by attacks, while C# and C/C++ present comparable results. Lorena González-Manzano, Joaquín García 0001 |
IET Inf. Secur. | 2 |
| 2024 | ZW-IDS: Zero-Watermarking-based network Intrusion Detection System using data provenanceabstractIn the rapidly evolving digital world, network security is a critical concern. Traditional security measures often fail to detect unknown attacks, making anomaly-based Network Intrusion Detection Systems (NIDS) using Machine Learning (ML) vital. However, these systems face challenges such as computational complexity and misclassification errors. This paper presents ZW-IDS, an innovative approach to enhance anomaly-based NIDS performance. We propose a two-layer classification NIDS integrating zero-watermarking with data provenance and ML. The first layer uses Support Vector Machines (SVM) with ensemble learning model for feature selection. The second layer generates unique zero-watermarks for each data packet using data provenance information. This approach aims to reduce false alarms, improve computational efficiency, and boost NIDS classification performance. We evaluate ZW-IDS using the CICIDS2017 dataset and compare its performance with other multi-method ML and Deep Learning (DL) solutions. Omair Faraj, David Megías 0001, Joaquín García 0001 |
ARES | 3 |
| 2024 | Platelet: Pioneering Security and Privacy Compliant Simulation for Intelligent Transportation Systems and V2XabstractThe development and testing of new applications in Cooperative Intelligent Transportation Systems (C-ITS) environments, which rely on Vehicle-to-Everything (V2X) communication, is frequently supported through simulations. Nevertheless, most of existing simulators are either outdated or do not consider the latest adopted standards. Especially, the security and privacy mechanisms of vehicles and V2X communications. Which leads to incorrect and biased assessments in numerous privacy-aware applications such as Intrusion detection. In this context, we introduce Platelet, which stands as the first V2X simulator compliant with security and privacy standards.Source code: https://gitlab.com/Matk3z/plateletVideo: https://www.youtube.com/watch?v=WuIl59mwxi0 Mathias Kautz, Badis Hammi, Joaquín García 0001 |
NCA | 3 |
| 2024 | ZIRCON: Zero-watermarking-based approach for data integrity and secure provenance in IoT networks
Omair Faraj, David Megías 0001, Joaquín García 0001 |
J. Inf. Secur. Appl. | 3 |
| 2023 | Automated Enrichment of Logical Attack Graphs via Formal Ontologies
Kéren Saint-Hilaire, Frédéric Cuppens, Nora Cuppens, Joaquín García 0001 |
SEC | 4 |
| 2023 | On the self-adjustment of privacy safeguards for query log streams
David Pàmies-Estrems, Joaquín García 0001 |
Comput. Secur. | 2 |
| 2022 | Switched-based Control Testbed to Assure Cyber-physical Resilience by DesignabstractInternational audience Mariana Segovia, Jose Rubio-Hernan, Ana R. Cavalli, Joaquín García 0001 |
SECRYPT | 4 |
| 2022 | Implementation of a Stateful Network Protocol Intrusion Detection SystemsabstractInternational audience S. Seng, Joaquín García 0001, Y. Laarouci |
SECRYPT | 2 |
| 2020 | Taxonomy and challenges in machine learning-based approaches to detect attacks in the internet of thingsabstractThe insecure growth of Internet-of-Things (IoT) can threaten its promising benefits to our daily life activities. Weak designs, low computational capabilities, and faulty protocol implementations are just a few examples that explain why IoT devices are nowadays highly prone to cyber-attacks. In this survey paper, we review approaches addressing this problem. We focus on machine learning-based solutions as a representative trend in the related literature. We survey and classify Machine Learning (ML)-based techniques that are suitable for the construction of Intrusion Detection Systems (IDS) for IoT. We contribute with a detailed classification of each approach based on our own taxonomy. Open issues and research challenges are also discussed and provided. Omair Faraj, David Megías 0001, Abdel-Mehsen Ahmad, Joaquín García 0001 |
ARES | 4 |
| 2020 | Cyber-Resilience Evaluation of Cyber-Physical SystemsabstractCyber-Physical Systems (CPS) use computational resources to control physical processes and provide critical services. For this reason, an attack in these systems may have dangerous consequences in the physical world. Hence, cyber- resilience is a fundamental property to ensure the safety of the people, the environment and the controlled physical processes. In this paper, we present metrics to quantify the cyber-resilience level based on the design, structure, stability, and performance under the attack of a given CPS. The metrics provide reference points to evaluate whether the system is better prepared or not to face the adversaries. This way, it is possible to quantify the ability to recover from an adversary using its mathematical model based on actuators saturation. Finally, we validate our approach using a numeric simulation on the Tennessee Eastman control challenge problem. Mariana Segovia, Jose Rubio-Hernan, Ana R. Cavalli, Joaquín García 0001 |
NCA | 4 |
| 2020 | Metrics to Enhance the Resilience of Cyber-Physical SystemsabstractWe focus on resilience towards covert attacks on Cyber-Physical Systems (CPS). We define the new k-steerability and l-monitorability control-theoretic concepts. k-steerability reflects the ability to act on every individual plant state variable with at least k different groups of functionally diverse input signals. l-monitorability indicates the ability to monitor every individual plant state variable with £ different groups of functionally diverse output signals. A CPS with k-steerability and l-monitorability is said to be (k, l)-resilient. k and l, when both greater than one, provide the capability to mitigate the impact of covert attacks when some signals, but not all, are compromised. We analyze the influence of k and l on the resilience of a system and the ability to recover its state when attacks are perpetrated. We argue that the values of k and l can be augmented by combining redundancy and diversity in hardware and software techniques that apply the moving target paradigm. Michel Barbeau, Frédéric Cuppens, Nora Cuppens, Romain Dagnas, Joaquín García 0001 |
TrustCom | 5 |
| 2020 | Stateful RORI-based countermeasure selection using hypergraphs
Gustavo Gonzalez Granadillo, Elena Fedorchenko, Joaquín García 0001, Igor V. Kotenko, Andrey Fedorchenko |
J. Inf. Secur. Appl. | 3 |
| 2020 | Stateful RORI-based countermeasure selection using hypergraphs
Gustavo Gonzalez Granadillo, Elena Fedorchenko, Joaquín García 0001, Igor V. Kotenko, Andrey Fedorchenko |
J. Inf. Secur. Appl. | 3 |
| 2019 | On the Difficulty of Hiding the Balance of Lightning Network ChannelsabstractThe Lightning Network is a second layer technology running on top of Bitcoin and other Blockchains. It is composed of a peer-to-peer network, used to transfer raw information data. Some of the links in the peer-to-peer network are identified as payment channels, used to conduct payments between two Lightning Network clients (i.e., the two nodes of the channel). Payment channels are created with a fixed credit amount, the channel capacity. The channel capacity, together with the IP address of the nodes, is published to allow a routing algorithm to find an existing path between two nodes that do not have a direct payment channel. However, to preserve users' privacy, the precise balance of the pair of nodes of a given channel (i.e. the bandwidth of the channel in each direction), is kept secret. Since balances are not announced, second-layer nodes probe routes iteratively, until they find a successful route to the destination for the amount required, if any. This feature makes the routing discovery protocol less efficient but preserves the privacy of channel balances. In this paper, we present an attack to disclose the balance of a channel in the Lightning Network. Our attack is based on performing multiple payments ensuring that none of them is finalized, minimizing the economical cost of the attack. We present experimental results that validate our claims, and countermeasures to handle the attack. Jordi Herrera-Joancomartí, Guillermo Navarro-Arribas, Alejandro Ranchal-Pedrosa, Cristina Pérez-Solà, Joaquín García 0001 |
AsiaCCS | 5 |
| 2019 | Towards an Adaptive Defuzzification: Using Numerical Choquet Integral
Vicenç Torra, Joaquín García 0001 |
MDAI | 2 |
| 2018 | A Pyramidal-based Model to Compute the Impact of Cyber Security EventsabstractThis paper presents a geometrical model that projects malicious and benign events (e.g., attacks, security countermeasures) as pyramidal instances in a multidimensional coordinate system. The approach considers internal event data related to the target system (e.g., users, physical, and logical resources, IP addresses, port numbers, etc.), and external event data related to the attacker (e.g., knowledge, motivation, skills, etc.) that can be obtained a priori and a posteriori. Internal data is used to model the base of the pyramid, whereas external data is used to model its height. In addition, the approach considers state transitions taken by the attacker to model the steps of a multi-stage attack to reach to its final goal. As a result, for each modeled state, new countermeasures are evaluated and the attacker's knowledge a posteriori changes accordingly, making it possible to evaluate the impact of the attack at time Ti, where i denotes the stage at which the attack is executed. A graphical representation of the impact of each evaluated event is depicted for visualization purposes. A use case of a cyber-physical system is proposed at the end of the paper to illustrate the applicability of the proposed geometrical model. Gustavo Gonzalez Granadillo, Jose Rubio-Hernan, Joaquín García 0001 |
ARES | 3 |
| 2018 | Dynamic risk management response system to handle cyber threats
Gustavo Gonzalez Granadillo, Samuel Dubus, Alexander Motzek, Joaquín García 0001, Ender Alvarez, Matteo Merialdo, Serge Papillon, Hervé Debar |
Future Gener. Comput. Syst. | 4 |
| 2018 | Doppler Effect in the Acoustic Ultra Low Frequency Band for Wireless Underwater Networks
Abdel Mehsen Ahmad, Jamil Kassem 0001, Michel Barbeau, Evangelos Kranakis, Steven F. T. Porretta, Joaquín García 0001 |
Mob. Networks Appl. | 6 |
| 2017 | Towards a Security Event Data Taxonomy
Gustavo Gonzalez Granadillo, Jose Rubio-Hernan, Joaquín García 0001 |
CRiSIS | 3 |
| 2017 | Security Challenges in e-Assessment and Technical SolutionsabstractE-Assessment is an innovative form for the evaluation of learners' knowledge and skills in online education, as well as in blended-learning environments, where part of the assessment activities is carried out online. As e-assessment involves online communication channel between learners and educators, as well as data transfer and storage, security measures are required to protect the environment against system and network attacks. The issue concerning security is challenging from both educational and technical point of views. Such issues are discussed under the scope of the TeSLA project. Educational challenging problems at e-assessment are analyzed and technical architectural recommendations for securing the e-assessment system according to the General Data Protection Regulation are provided. Christophe Kiennert, Pierre-Olivier Rocher, Malinka Ivanova, Anna Rozeva, Mariana Durcheva, Joaquín García 0001 |
IV | 6 |
| 2017 | Selection of Pareto-efficient response plans based on financial and operational assessmentsabstractFinding adequate responses to ongoing attacks on ICT systems is a pertinacious problem and requires assessments from different perpendicular viewpoints. However, current research focuses on reducing the impact of an attack irregardless of side effects caused by responses. In order to achieve a comprehensive yet accurate response to possible and ongoing attacks on a managed ICT system, we propose an approach that evaluates a response from two perpendicular perspectives: (1) A response financial impact assessment, considering the financial benefits of restoring and protecting potentially threatened operational capabilities while considering implementation and maintenance costs of responses. (2) A response operational impact assessment, which assesses potential impacts that efficient mitigation actions may inadvertently cause on the organization in an operational perspective, e.g., negative side effects of deploying mitigations. It is the key benefit of the presented approach to combine all obtained evaluations with a multi-dimensional optimization procedure such that a response plan is selected which reduces a state of risk below an admissible level while minimizing potential negative side effects of deliberately taken actions. Alexander Motzek, Gustavo Gonzalez Granadillo, Hervé Debar, Joaquín García 0001, Ralf Möller 0001 |
EURASIP J. Inf. Secur. | 4 |
| 2017 | On the use of watermark-based schemes to detect cyber-physical attacksabstractWe address security issues in cyber-physical systems (CPSs). We focus on the detection of attacks against cyber-physical systems. Attacks against these systems shall be handled both in terms of safety and security. Networked-control technologies imposed by industrial standards already cover the safety dimension. However, from a security standpoint, using only cyber information to analyze the security of a cyber-physical system is not enough, since the physical malicious actions that can threaten the correct behavior of the systems are ignored. For this reason, the systems have to be protected from threats to their cyber and physical layers. Some authors have handled replay and integrity attacks using, for example, physical attestation to validate the cyber process and to detect the attacks, or watermark-based detectors which uses also physical parameters to ensure the cyber layers. We reexamine the effectiveness of a stationary watermark-based detector. We show that this approach only detects adversaries that do not attempt to get any knowledge about the system dynamics. We analyze the detection ratio of the original design under the presence of new adversaries that are able to infer the system dynamics and are able to evade the detector with high frequency. We propose a new detection scheme which employs several non-stationary watermarks. We validate the detection efficiency of the new strategy via numeric simulations and via running experiments on a laboratory testbed. Results show that the proposed strategy is able to detect adversaries using non-parametric methods, but it is not equally effective against adversaries using parametric identification methods. Jose Rubio-Hernan, Luca De Cicco, Joaquín García 0001 |
EURASIP J. Inf. Secur. | 3 |
| 2017 | A polytope-based approach to measure the impact of events against critical infrastructures
Gustavo Gonzalez Granadillo, Joaquín García 0001, Hervé Debar |
J. Comput. Syst. Sci. | 2 |
| 2016 | Selection of Mitigation Actions Based on Financial and Operational Impact AssessmentsabstractFinding adequate responses to ongoing attacks on ICT systems is a pertinacious problem and requires assessments from different perpendicular viewpoints. However, current research focuses on reducing the impact of an attack irregardless of side-effects caused by responses. In order to achieve a comprehensive yet accurate response to possible and ongoing attacks on a managed ICT system, we propose an approach that relies on a response system that continuously quantifies risks, and decides how to respond to cyber-threats that target a monitored ICT system. Our Dynamic Risk Management Response (DRMR) model is composed of two main modules: a Response Financial Impact Assessor (RFIA), which provides an assessment concerning the potential financial impact that responses may cause to an organization, and a Response Operational Impact Assessor (ROIA), which assesses potential impacts that efficient mitigation actions may cause on the organization in an operational perspective. As a result, the DRMR model proposes response plans to mitigate identified risks, enable choice of the most suitable response possibilities to reduce identified risks below an admissible level while minimizing potential negative side effects of deliberately taken actions. Gustavo Gonzalez Granadillo, Alexander Motzek, Joaquín García 0001, Hervé Debar |
ARES | 3 |
| 2016 | Revisiting a Watermark-Based Detection Scheme to Handle Cyber-Physical AttacksabstractWe address detection of attacks against cyber-physical systems. Cyber-physical systems are industrial control systems upgraded with novel computing, communication and interconnection capabilities. In this paper we reexamine the security of a detection scheme proposed by Mo and Sinopoli (2009) and Mo et al. (2015). The approach complements the use of Kalman filters and linear quadratic regulators, by adding an authentication watermark signal for the detection of integrity attacks. We show that the approach only detects cyber adversaries, i.e., attackers with the ability to eavesdrop information from the system, but that do not attempt to acquire any knowledge about the system model itself. The detector fails at covering cyber-physical adversaries, i.e., attackers that, in addition to the capabilities of the cyber adversary, are also able to infer the system model to evade the detection. We discuss an enhanced scheme, based on a multi-watermark authentication signal, that properly detects the two adversary models. Jose Rubio-Hernan, Luca De Cicco, Joaquín García 0001 |
ARES | 3 |
| 2016 | An n-Sided Polygonal Model to Calculate the Impact of Cyber Security Events
Gustavo Gonzalez Granadillo, Joaquín García 0001, Hervé Debar |
CRiSIS | 2 |
| 2016 | Channel selection using a multiple radio model
Michel Barbeau, Gimer Cervera, Joaquín García 0001, Evangelos Kranakis |
J. Netw. Comput. Appl. | 3 |
| 2016 | Reputation trust mechanism under the organizational-based access control modelabstractAbstract The spread of high‐speed networks changes the way in which organizations manage information. Distributed environments, such as multi‐cloud environments, can be exploited by users belonging to different organizations. Companies are realizing that they can achieve significant cost savings by outsourcing some of their information technology environments to specialized service companies. This rapid transition has introduced a number of security risks and challenges. The resulting environment cannot succeed at addressing them without the use of access control policies and the definition of trust mechanisms. Access control ontologies, as a structured way to represent real word elements, are widely employed for making the security interoperable and understandable. Ontologies that have been built for this aim suffer from the lack of crucial elements for distributed environments. In this paper, we tackle the problem of trust‐based access control models. We define a list of trust elements that should be integrated into any access control ontology. We also provide a mapping technique that permits the exchange of trust information. Based on these two contributions, our reputation mechanism, that builds upon the organization‐based access control model (OrBAC), is created. To prove the efficiency of our proposal, we test it in a multi‐cloud environment. Then, we conduct a set of experiments that show the high accuracy level of our system. Copyright © 2016 John Wiley & Sons, Ltd. Khalifa Toumi, Hela Sfar, Joaquín García 0001 |
Secur. Commun. Networks | 3 |
| 2015 | On the Isofunctionality of Network Access Control ListsabstractIn a networking context, Access Control Lists (ACLs) refer to security rules associated to network equipment, such as routers, switches and firewalls. Methods and tools to automate the management of ACLs distributed among several equipment shall verify if the corresponding ACLs are functionally equivalent. In this paper, we address such a verification process. We present a formal method to verify when two ACLs are iso functional and illustrate our proposal over a practical example. Malek Belhaouane, Joaquín García 0001, Hervé Debar |
ARES | 2 |
| 2015 | NACER: A Network-Aware Cost-Efficient Resource Allocation Method for Processing-Intensive Tasks in Distributed CloudsabstractIn the distributed cloud paradigm, data centers are geographically dispersed and interconnected over a wide-area network. Due to the geographical distribution of data centers, communication networks play an important role in distributed clouds in terms of communication cost and QoS. Large-scale, processing-intensive tasks require the cooperation of many VMs, which may be distributed in more than one data center and should communicate with each other. In this setting, the number of data enters serving the given task and the network distance among those data centers have critical impact on the communication cost, traffic and even completion time of the task. In this paper, we present the NACER algorithm, a Network-Aware Cost-Efficient Resource allocation method for optimizing the placement of largemulti-VM tasks in distributed clouds. NACER builds on ideas of the A* search algorithm from Artificial Intelligence research in order to obtain better results than typical greedy heuristics. We present extensive simulation results to compare the performance of NACER with competing heuristics and show its effectiveness. Ehsan Ahvar, Shohreh Ahvar, Noël Crespi, Joaquín García 0001, Zoltán Ádám Mann |
NCA | 4 |
| 2015 | Automated Classification of C&C Connections Through Malware URL Clustering
Nizar Kheir, Gregory Blanc, Hervé Debar, Joaquín García 0001, Dingqi Yang |
SEC | 4 |
| 2015 | Model-Driven Integration and Analysis of Access-control Policies in Multi-layer Information Systems
Salvador Martínez Perez, Joaquín García 0001, Frédéric Cuppens, Nora Cuppens, Jordi Cabot |
SEC | 2 |
| 2015 | Evaluating the Comprehensive Complexity of Authorization-based Access Control Policies using Quantitative MetricsabstractInternational audience Malek Belhaouane, Joaquín García 0001, Hervé Debar |
SECRYPT | 2 |
| 2015 | Using a 3D Geometrical Model to Improve Accuracy in the Evaluation and Selection of Countermeasures Against Complex Cyber Attacks
Gustavo Gonzalez Granadillo, Joaquín García 0001, Hervé Debar |
SecureComm | 2 |
| 2014 | A new analysis of the cognitive radio jump-stay algorithm under the asymmetric modelabstractUnder use of the regulated radio spectrum is being addressed using a cognitive radio network approach termed dynamic spectrum access. Primary users have priority over the regulated radio spectrum. Secondary users may use the residual air time. We focus on the problem of meeting on a common channel by a group of secondary users. Under the asymmetric model, the secondary users have different sets of available channels. If the sets are not disjoint, they can eventually make rendezvous. The goal is to make the secondary users rendezvous on a common channel in a minimum amount of time. The jump-stay rendezvous algorithm has been created by Lin et al. to solve this problem. We develop a new analysis for the two-user expected time to rendezvous in the jump-stay rendezvous algorithm, under the asymmetric model, that better reflects its performance. Michel Barbeau, Gimer Cervera, Joaquín García 0001, Evangelos Kranakis |
ICC | 3 |
| 2014 | The Bidirectional Algorithm for Channel Selection Using a Two-Radio ModelabstractWe study the problem of establishing rendezvous between two secondary users. We assume that each user has two radios that can be used concurrently. We present the bidirectional algorithm that exploits the two radios. Assuming the availability of m channels, rendezvous between two start-asynchronous users is guaranteed within a delay of m time slots. The expected time-to-rendezvous is m/3 time slots. Assuming users are start-synchronous, rendezvous is made in at most (m+1)/2 time slots. The expected time-to-rendezvous is m/4 + 1 - 1/4m time slots. Michel Barbeau, Gimer Cervera, Joaquín García 0001, Evangelos Kranakis |
VTC Fall | 3 |
| 2014 | KEDGEN2: A key establishment and derivation protocol for EPC Gen2 RFID systems
Wiem Tounsi, Nora Cuppens, Joaquín García 0001, Yannick Chevalier, Frédéric Cuppens |
J. Netw. Comput. Appl. | 3 |
| 2014 | Searching for a black hole in interconnected networks using mobile agents and tokens
Wei Shi 0001, Joaquín García 0001, Jean-Pierre Corriveau |
J. Parallel Distributed Comput. | 2 |
| 2013 | Privacy-enhanced filtering and collection middleware in EPCglobal networksabstractCollection and distribution of Radio Frequency IDentification (RFID) data are subject to various privacy concerns. These concerns are of paramount importance when sensitive data are processed (e.g., medical data). Therefore, it is crucial to treat sensitive data privacy in early stages to master the data view for upper layers and to minimize, as soon as possible, the risk of unauthorized disclosures. While most recent works focus on securing the access and visibility of collected information in the final databases, data processed in the middleware do not seem involved in the process of privacy protection. Current EPCglobal standards for RFID also suffer from insufficient attention to this issue. In this paper, we propose a privacy controller module that enhances the Filtering and Collection (F&C) middleware of the EPCglobal network. We provide a privacy policy-driven model, using some enhanced contextual concepts of the extended Role Based Access Control model. The feasibility of our privacy-enhanced model is shown by integrating our solution into the F&C middleware of the Fosstrak framework, an open-source implementation of the EPCglobal network specifications. Wiem Tounsi, Nora Cuppens, Frédéric Cuppens, Joaquín García 0001 |
CRiSIS | 4 |
| 2013 | Fine-grained privacy control for the RFID middleware of EPCglobal networksabstractThe Electronic Product Code (EPC) is a Radio Frequency IDentification (RFID) that offers a new way of automating identification. However, once RFID tags carry more than just an identifier, privacy may be violated. Treating the privacy in early stages helps to master the data view before interpreting and storing it in databases. An RFID middleware is the entity that sits between tag readers and database applications. It is in charge of collecting, filtering, aggregating and grouping the requested events from heterogeneous RFID environments. Thus, the system, at this point, is likely to suffer from parameter manipulation and eavesdropping, raising privacy concerns. We propose a privacy controller module that enhances the Filtering and Collection middleware of the RFID EPCglobal network. We provide a privacy policy-driven model using some enhanced contextual concepts of the extended Role Based Access Control model. To show the feasibility of our privacy-enhanced model, we provide a proof-of-concept prototype integrated into the middleware of the Fosstrak framework, an open-source implementation of the EPCglobal specifications. Wiem Tounsi, Nora Cuppens, Frédéric Cuppens, Joaquín García 0001 |
MEDES | 4 |
| 2013 | Model-Driven Extraction and Analysis of Network Security Policies
Salvador Martínez Perez, Joaquín García 0001, Frédéric Cuppens, Nora Cuppens, Jordi Cabot |
MoDELS | 2 |
| 2013 | Real-time malicious fast-flux detection using DNS and bot related featuresabstractFast-flux is a protection technique used by botnets to protect their communication servers. We present a detection method for the real-time discovery of fast-flux services. We implemented our approach and conducted experiments that verify the superiority of our approach to previous efforts. Sergi Martinez-Bea, Sergio Castillo-Perez, Joaquín García 0001 |
PST | 3 |
| 2013 | Onion routing circuit construction via latency graphs
Sergio Castillo-Perez, Joaquín García 0001 |
Comput. Secur. | 2 |
| 2013 | Management of stateful firewall misconfiguration
Joaquín García 0001, Frédéric Cuppens, Nora Cuppens, Salvador Martínez Perez, Jordi Cabot |
Comput. Secur. | 1 |
| 2013 | Editorial
Frédéric Cuppens, Nora Cuppens, Ernesto Damiani, Radu State, Joaquín García 0001, Nadia Tawbi |
J. Inf. Secur. Appl. | 5 |
| 2013 | Semantic analysis of role mining results and shadowed roles detection
Safaà Hachana, Frédéric Cuppens, Nora Cuppens, Joaquín García 0001 |
Inf. Secur. Tech. Rep. | 4 |
| 2013 | A multipath routing strategy to prevent flooding disruption attacks in link state routing protocols for MANETs
Gimer Cervera, Michel Barbeau, Joaquín García 0001, Evangelos Kranakis |
J. Netw. Comput. Appl. | 3 |
| 2012 | Towards Automated Assistance for Mined Roles Analysis in Role Mining ApplicationsabstractThe use of role engineering has grown in importance with the expansion of highly abstracted access control frameworks in organizations. In particular, the use of role mining techniques for the discovery of roles from previously deployed authorizations has facilitated the configuration of such frameworks. However, the literature lacks from a clear basis for appraising and leveraging the learning outcomes of the role mining process. In this paper, we provide such a formal basis. We compare sets of roles by projecting roles from one set into the other set. This approach allows to measure how comparable the two configurations of roles are, and to interpret each role. We formally define the problem of comparing sets of roles, and prove that the problem is NP-complete. Then, we propose an algorithm to map the inherent relation among the sets based on algebraic expressions. We demonstrate the correctness and completeness of our solution, and investigate some further issues that may benefit from our approach, such as detection of unhandled perturbations or source misconfiguration. Safaà Hachana, Frédéric Cuppens, Nora Cuppens, Joaquín García 0001 |
ARES | 4 |
| 2012 | HADEGA: A novel MPLS-based mitigation solution to handle network attacksabstractWe present HADEGA, a novel adaptive mitigation solution to handle the impact of network attacks. By extracting information from network detection alerts, and build upon the Multiprotocol Label Switching (MPLS) standard, the solution assigns labels and quality of service treatments to suspicious flows. As a result, those labeled flows are controlled and properly handled inside the core network of service providers. We conducted simulations in order to evaluate the efficiency of our approach. Results are presented. Nabil Hachem, Hervé Debar, Joaquín García 0001 |
IPCCC | 3 |
| 2012 | Handling Stateful Firewall Anomalies
Frédéric Cuppens, Nora Cuppens, Joaquín García 0001, Tarik Moataz, Xavier Rimasson |
SEC | 3 |
| 2012 | Transaction-based authentication and key agreement protocol for inter-domain VoIP
Patrick Battistello, Joaquín García 0001, Cyril Delétré |
J. Netw. Comput. Appl. | 2 |
| 2011 | Improved flooding of broadcast messages using extended multipoint relaying
Pere Montolio-Aranda, Joaquín García 0001, David Megías 0001 |
J. Netw. Comput. Appl. | 2 |
| 2011 | Dynamic deployment of context-aware access control policies for constrained security devices
Stere Preda, Frédéric Cuppens, Nora Cuppens, Joaquín García 0001, Laurent Toutain |
J. Syst. Softw. | 4 |
| 2010 | Mitigation of topology control traffic attacks in OLSR networksabstractThe core of the Optimized Link State Routing (OLSR) protocol is the selection of Multipoint Relays (MPRs) as a flooding mechanism for distributing control traffic messages. A node in an OLSR network, selects its MPR set such that all two-hop neighbors are reachable through, at least, one MPR. However, if an MPR misbehaves during the execution of the protocol, the connectivity of the network is compromised. Additional coverage in the selection of the MPRs helps to mitigate the effect of control traffic attacks. RFC3626 defines the selection of MPRs with additional coverage. Nevertheless, the overhead of the network increases due to the added number of control traffic messages. In this paper, we propose an improved MPR selection with additional coverage. Every node selects, if it is possible, k + 1 disjoint MPR sets. The union of those sets, is a k-robust-MPR set. Thus, given a node, alternative paths are created to reach any destination two-hops away. We test both approaches against two kinds of adversaries misbehaving during the execution of the protocol. Our proposed MPR selection with additional coverage mitigates the effect of control traffic attacks by offering equivalent protection compared to the MPR selection with extra coverage presented in RFC3626, but reducing the overhead generated by redundant control information. Gimer Cervera, Michel Barbeau, Joaquín García 0001, Evangelos Kranakis |
CRiSIS | 3 |
| 2009 | Semantic context aware security policy deploymentabstractThe successful deployment of a security policy is closely related not only to the complexity of the security requirements but also to the capabilities/functionalities of the security devices. The complexity of the security requirements is additionally increased when contextual constraints are taken into account. Such situations appear when addressing the dynamism of some security requirements or when searching a finer granularity for the security rules. The context denotes those specific conditions in which the security requirements are to be met. (Re)deploying a contextual security policy depends on the security device functionalities: either (1) the devices include all functionalities necessary to deal with a context and the policy is consequently deployed for ensuring its automatic changes or (2) the devices do not have the right functionalities to entirely interpret a contextual requirement. We present a solution to cope with this issue: the (re)deployment of access control policies in a system that lacks the necessary functionalities to deal with contexts. Stere Preda, Frédéric Cuppens, Nora Cuppens, Joaquín García 0001, Laurent Toutain, Yehia Elrakaiby |
AsiaCCS | 4 |
| 2009 | A secured delegation of remote services on IPv6 home networksabstractIPv6 is an attractive technology for innovative services such as health care monitoring, alarm systems, peer to peer applications, virtual machine systems and so on. The generalization of end to end paradigm, possible due to the length of IPv6 addresses, eases the deployment of such services. Nevertheless end to end connection can be a threat since application can be easily accessible from outside and thus a compromised application may endanger others. In this paper, we study some of the advantages of using the IPv6 protocol in home networks but most particularly how to improve the security of home networks. We present an architecture allowing the definition of a partition between groups of applications and where communication between these groups is not permitted if there is no explicit delegation. We overview the key points of the current implementation and some initial results of our approach. Stere Preda, Laurent Toutain, Nora Cuppens, Frédéric Cuppens, Joaquín García 0001 |
CRiSIS | 5 |
| 2009 | A Policy Based Approach for the Management of Web Browser Resources to Prevent Anonymity Attacks in Tor
Guillermo Navarro-Arribas, Joaquín García 0001 |
SEC | 2 |
| 2007 | Aggregating and Deploying Network Access Control PoliciesabstractThe existence of errors or inconsistencies in the configuration of security components, such as filtering routers and/or firewalls, may lead to weak access control policies - potentially easy to be evaded by unauthorized parties. We present in this paper a proposal to create, manage, and deploy consistent policies in those components in an efficient way. To do so, we combine two main approaches. The first approach is the use of an aggregation mechanism that yields consistent configurations or signals inconsistencies. Through this mechanism we can fold existing policies of a given system and create a consistent and global set of access control rules - easy to maintain and manage by using a single syntax. The second approach is the use of a refinement mechanism that guarantees the proper deployment of such a global set of rules into the system, yet free of inconsistencies Joaquín García 0001, Frédéric Cuppens, Nora Cuppens |
ARES | 1 |
| 2007 | A Survey on Detection Techniques to Prevent Cross-Site Scripting Attacks on Current Web Applications
Joaquín García 0001, Guillermo Navarro-Arribas |
CRITIS | 1 |
| 2007 | Management of Exceptions on Access Control Policies
Joaquín García 0001, Frédéric Cuppens, Nora Cuppens |
SEC | 1 |
| 2007 | Reliable Process for Security Policy Deployment
Stere Preda, Nora Cuppens, Frédéric Cuppens, Joaquín García 0001, Laurent Toutain |
SECRYPT | 4 |
| 2006 | Protection of Components Based on a Smart-Card Enhanced Security Module
Joaquín García 0001, Sergio Castillo-Perez, Jordi Castellà-Roca, Guillermo Navarro-Arribas, Joan Borrell |
CRITIS | 1 |
| 2006 | Analysis of Policy Anomalies on Distributed Network Security Setups
Joaquín García 0001, Frédéric Cuppens, Nora Cuppens |
ESORICS | 1 |
| 2006 | Towards Filtering and Alerting Rule Rewriting on Single-Component Policies
Joaquín García 0001, Frédéric Cuppens, Nora Cuppens |
SAFECOMP | 1 |
| 2004 | Decentralized Publish-Subscribe System to Prevent Coordinated Attacks via Alert Correlation
Joaquín García 0001, Fabien Autrel, Joan Borrell, Sergio Castillo-Perez, Frédéric Cuppens, Guillermo Navarro-Arribas |
ICICS | 1 |