Gustavo Betarte

dblp:06/4140 · DBLP profile ↗
← Back
8ranked-venue papers in the field
3as first author
6since 2021 · last 2025
0000-0002-6863-1082ORCID · corroborated

Domains — venue-derived; a paper can count in several

Other / Interdisciplinary · 8 (3 first)
YearPublicationVenuePosition
2025 A comparative study of implementations for validating consent in personal data access control
abstract
Attribute-based access control (ABAC) and relationship-based access control (ReBAC) are innovative access control methods that extend traditional models, including role-based access control (RBAC). This paper examines these models to suggest their application as a means of verifying the consent of a personal data subject. The objective is to apply these models in accordance with the General Data Protection Regulation (GDPR), which requires data owners to consent to the processing of their data for defined purposes, and ensure users utilize this data solely for those purposes. To validate this, we explore a benchmark proposed by NIST related to access control in a hospital setting, modifying it to assess data subject consent. From this case study, we deployed both access control approaches and subsequently compared their performance.
María Fernanda Molina, Gustavo Betarte, Carlos Daniel Luna
CLEI2
2024 Process Mining-Based Assessment of Cyber Range Trainings
abstract
Cyber ranges are computer systems designed to create realistic cybersecurity scenarios for training purposes. It is essential to have a reliable evaluation process to determine whether users have achieved their objectives. User training involves a sequence of activities that are performed in a specific order to reach a particular goal. This article presents a cyber range implementation and puts forth an evaluation methodology that employs process mining to analyze training processes from different perspectives. The methodology is applied in a training session conducted in the cyber range.
Guillermo Guerrero, Gustavo Betarte, Juan Diego Campo
CLEI2
2023 A Security Analysis of a Referential Architecture of the FIWARE Platform
abstract
In this paper we present the results of carrying out a security assessment of the FIWARE technology, by adopting an offensive perspective in the search of potential vulnerabilities involved in deployments of FIWARE components in certain architecture configurations. We consider a referential scenario that includes core components of a FIWARE platform. By experimenting in a locally controlled environment, it was possible to identify a series of security issues. Then, we put forward a threat model following the OWASP methodology that embodies several artifacts, namely, decomposition of the referential platform, a data flow diagram, a STRIDE threat modeling, attack analysis and the identification of attack objectives. We were able to implement attacks for three of the identified attack goals. The approach conducted for the referential platform was validated by performing an exploratory analysis of a real working and productive FIWARE platform, distinguishing different types of attacks that could be implemented, ending up with a set of recommendations in terms of components, architecture and access control.
Juan Pablo Perata, Gustavo Betarte
CLEI2
2022 An Idealized Model for the Formal Security Analysis of the Mimblewimble Cryptocurrency Protocol
abstract
Mimblewimble is a privacy-oriented cryptocurrency technology that provides security and scalability properties that distinguish it from other protocols. Mimblewimble’s cryptographic approach is based on Elliptic Curve Cryptography which allows verifying a transaction without revealing any information about the transactional amount or the parties involved. Mimblewimble combines Confidential transactions, CoinJoin, and cut-through to achieve a higher level of privacy, security, and scalability. In our previous work ([2], [26], [25]), we have presented and discussed these security properties and presented a model-driven verification approach in order to guarantee the correctness of the protocol implementations. In particular, we have proposed an idealized model that is essential to the described verification process. In that formal setting, we say that a transaction is valid if it is balanced, all output range proofs are valid and the kernel signature is valid for the excess. However, no formal and precise definition was given to the signature requirement. In this paper, we put forward an extension of our model to enable signatures. We specify a signature scheme that allows us to develop several properties and lemmas we have defined on our initial idealized model. The definition of a valid transaction is extended accordingly.
Adrián Silveira, Gustavo Betarte, Maximiliano Cristiá, Carlos Daniel Luna
CLEI2
2021 Proximity tracing applications for COVID-19: data privacy and security
abstract
Since the beginning of 2020, COVID-19 has had a strong impact on the health of the world population. Tracing the contacts of infected people is one of the main strategies for controlling the pandemic. Given the high rates of contagion, which makes difficult an effective manual tracing, multiple initiatives arose for developing digital proximity tracing technologies. In this paper, we discuss in depth the security and personal data protection requirements that these technologies must satisfy, and we present an exhaustive and detailed list of the various applications that have been deployed globally. In particular, we identify potential threats that could undermine the satisfaction of the analyzed requirements, violating hegemonic personal data protection regulations.
Gustavo Betarte, Juan Diego Campo, Andrea Delgado 0001, Pablo Ezzatti, Laura González 0001, Alvaro Martín, Rodrigo Martínez, Bárbara Muracciole
CLEI1
2021 Exploring the Application of Process Mining Techniques to Improve Web Application Security
abstract
Web applications are permanently being exposed to attacks that exploit their vulnerabilities. To detect and prevent misuse of the functionality provided by an application, it has become necessary to develop techniques that help discern between a valid user of the system and a malicious agent. In recent years, a technology that has been widely deployed to provide automated and non-invasive support for detecting web application attacks is Web Application Firewalls. In this work, we put forward and discuss the application of Process Mining techniques to detect deviations from the expected behavior of web applications. The objects of behavior analysis are logs generated by a widely deployed WAF called ModSecurity. We discuss experiments we have carried out applying our mining method on the well-known e-commerce platform Magento and using the ProM tool for the execution of the process mining techniques.
Marcelo Bruno, Pablo Ibáñez 0002, Tamara Techera, Daniel Calegari, Gustavo Betarte
CLEI5
2017 Towards formal model-based analysis and testing of Android's security mechanisms
abstract
This article reports on our experiences in applying formal methods to verify the security mechanisms of Android. We have developed a comprehensive formal specification of Android's permission model, which has been used to state and prove properties that establish expected behavior of the procedures that enforce the defined access control policy. We are also interested in providing guarantees concerning actual implementations of the mechanisms. Therefore we are following a verification approach that combines the use of idealized models on which fundamental properties are formally verified with testing of actual implementations using lightweight model-based techniques. We describe the formalized model, present security properties that have been verified using the Coq proof assistant and discuss a testing technique that relies on the use of certified algorithms.
Gustavo Betarte, Juan Diego Campo, Maximiliano Cristiá, Felipe Gorostiaga, Carlos Daniel Luna, Camila Sanz
CLEI1
2013 Design and implementation of a computer security Diploma
abstract
This paper presents a Specialization Diploma in Computer Security (Diploma de Especialización en Seguridad Informática), defined in the context of the work of the Computer Security Group (GSI, Grupo de Seguridad Informática) of the Department of Computer Science (InCo, Instituto de Computación) at Facultad de Ingeniería, Universidad de la República, which is part of the course offerings by Centro de Posgrado y Actualización Profesional (CPAP). It describes the context in which it is developed, the objectives and structure of the curriculum, the teaching methodology used, and the educational tools.
Gustavo Betarte, Maria E. Corti
CLEI1