EDBT 2026 Demo / reviewers in the wild / expert
Gustavo Gonzalez Granadillo
dblp:119/6733 · also Gustavo Daniel Gonzalez Granadillo
· DBLP profile ↗
17ranked-venue papers
13as first author
5since 2021 · last 2025
0000-0003-2036-981XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 11 first-author · 5 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1Theory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | AI-Based Anomaly Detection and Classification of Traffic Using NetflowabstractInternational audience Gustavo Gonzalez Granadillo, Nesrine Kaaniche |
SECRYPT | 1 |
| 2022 | Efficient Hybrid Model for Intrusion Detection SystemsabstractInternational audience Nesrine Kaaniche, Aymen Boudguiga, Gustavo Gonzalez Granadillo |
SECRYPT | 3 |
| 2022 | A Trusted Platform Module-based, Pre-emptive and Dynamic Asset Discovery ToolabstractThis paper presents an original Intelligent and Secure Asset Discovery Tool (ISADT) that uses artificial intelligence and TPM-based technologies to: (i) detect the network assets, and (ii) detect suspicious pattern in the use of the network. The architecture has specifically been designed to discover the assets of medium and large size companies and institutions, such as hospitals, universities, or government buildings. Given the distributed design of the architecture, it can cope with the problem of the isolation of different Virtual Local Area Networks (VLANs). This is done by collecting information from all the VLANs and storing it in a central node, which can be accessed by the network administrator, who may consult and visualize the status in any moment, or even by other authorized applications. The collected data is kept in a secure warehouse by the use of a Trusted Platform Module. Moreover, collected data is processed by the use of artificial intelligence in two ways: (i) the traffic of each network is analysed so that suspicious patterns can be detected, and (ii) identified ports and status are analysed to detect anomalous combinations of open ports in a device. Antonio Jesús Díaz-Honrubia, Alberto Blázquez-Herranz, Lucía Prieto Santamaría, Ernestina Menasalvas Ruiz, Alejandro Rodríguez González, Gustavo Gonzalez Granadillo, Emmanouil A. Panaousis, Christos Xenakis |
J. Inf. Secur. Appl. | 6 |
| 2021 | An Improved Live Anomaly Detection System (I-LADS) based on Deep Learning Algorithms
Gustavo Gonzalez Granadillo, Alejandro G. Bedoya |
SECRYPT | 1 |
| 2021 | ETIP: An Enriched Threat Intelligence Platform for improving OSINT correlation, analysis, visualization and sharing capabilities
Gustavo Gonzalez Granadillo, Mario Faiella, Iberia Medeiros, Rui Azevedo, Susana Gonzalez Zarzosa |
J. Inf. Secur. Appl. | 1 |
| 2020 | Stateful RORI-based countermeasure selection using hypergraphs
Gustavo Gonzalez Granadillo, Elena Fedorchenko, Joaquín García 0001, Igor V. Kotenko, Andrey Fedorchenko |
J. Inf. Secur. Appl. | 1 |
| 2020 | Stateful RORI-based countermeasure selection using hypergraphs
Gustavo Gonzalez Granadillo, Elena Fedorchenko, Joaquín García 0001, Igor V. Kotenko, Andrey Fedorchenko |
J. Inf. Secur. Appl. | 1 |
| 2019 | An Overview of the CUREX PlatformabstractHealth sector is becoming more and more dependent on digital information every day. This fact can be exploited by cyber criminals who may obtain very lucrative benefits from stolen data. Moreover, a breach of integrity of health data can have terrible consequences for the patients. CUREX project aims to protect the confidentiality of health data and to maintain its integrity by producing a novel, flexible and scalable situational awareness-oriented platform. CUREX has been conceived as GDPR compliant by design. This design has been thought as a decentralised architecture enhanced with a private blockchain infrastructure. Thus, it ensures the integrity of the risk assessment process and of all data transactions. Antonio Jesús Díaz-Honrubia, Alejandro Rodríguez González, Juan Mora Zamorano, Jesús Rey Jiménez, Gustavo Gonzalez Granadillo, Mariza Konidi, Panos Papachristou, Sokratis Nifakos, Georgia Kougka, Anastasios Gounaris |
CBMS | 5 |
| 2018 | A Pyramidal-based Model to Compute the Impact of Cyber Security EventsabstractThis paper presents a geometrical model that projects malicious and benign events (e.g., attacks, security countermeasures) as pyramidal instances in a multidimensional coordinate system. The approach considers internal event data related to the target system (e.g., users, physical, and logical resources, IP addresses, port numbers, etc.), and external event data related to the attacker (e.g., knowledge, motivation, skills, etc.) that can be obtained a priori and a posteriori. Internal data is used to model the base of the pyramid, whereas external data is used to model its height. In addition, the approach considers state transitions taken by the attacker to model the steps of a multi-stage attack to reach to its final goal. As a result, for each modeled state, new countermeasures are evaluated and the attacker's knowledge a posteriori changes accordingly, making it possible to evaluate the impact of the attack at time Ti, where i denotes the stage at which the attack is executed. A graphical representation of the impact of each evaluated event is depicted for visualization purposes. A use case of a cyber-physical system is proposed at the end of the paper to illustrate the applicability of the proposed geometrical model. Gustavo Gonzalez Granadillo, Jose Rubio-Hernan, Joaquín García 0001 |
ARES | 1 |
| 2018 | Dynamic risk management response system to handle cyber threats
Gustavo Gonzalez Granadillo, Samuel Dubus, Alexander Motzek, Joaquín García 0001, Ender Alvarez, Matteo Merialdo, Serge Papillon, Hervé Debar |
Future Gener. Comput. Syst. | 1 |
| 2017 | Towards a Security Event Data Taxonomy
Gustavo Gonzalez Granadillo, Jose Rubio-Hernan, Joaquín García 0001 |
CRiSIS | 1 |
| 2017 | Selection of Pareto-efficient response plans based on financial and operational assessmentsabstractFinding adequate responses to ongoing attacks on ICT systems is a pertinacious problem and requires assessments from different perpendicular viewpoints. However, current research focuses on reducing the impact of an attack irregardless of side effects caused by responses. In order to achieve a comprehensive yet accurate response to possible and ongoing attacks on a managed ICT system, we propose an approach that evaluates a response from two perpendicular perspectives: (1) A response financial impact assessment, considering the financial benefits of restoring and protecting potentially threatened operational capabilities while considering implementation and maintenance costs of responses. (2) A response operational impact assessment, which assesses potential impacts that efficient mitigation actions may inadvertently cause on the organization in an operational perspective, e.g., negative side effects of deploying mitigations. It is the key benefit of the presented approach to combine all obtained evaluations with a multi-dimensional optimization procedure such that a response plan is selected which reduces a state of risk below an admissible level while minimizing potential negative side effects of deliberately taken actions. Alexander Motzek, Gustavo Gonzalez Granadillo, Hervé Debar, Joaquín García 0001, Ralf Möller 0001 |
EURASIP J. Inf. Secur. | 2 |
| 2017 | A polytope-based approach to measure the impact of events against critical infrastructures
Gustavo Gonzalez Granadillo, Joaquín García 0001, Hervé Debar |
J. Comput. Syst. Sci. | 1 |
| 2016 | Selection of Mitigation Actions Based on Financial and Operational Impact AssessmentsabstractFinding adequate responses to ongoing attacks on ICT systems is a pertinacious problem and requires assessments from different perpendicular viewpoints. However, current research focuses on reducing the impact of an attack irregardless of side-effects caused by responses. In order to achieve a comprehensive yet accurate response to possible and ongoing attacks on a managed ICT system, we propose an approach that relies on a response system that continuously quantifies risks, and decides how to respond to cyber-threats that target a monitored ICT system. Our Dynamic Risk Management Response (DRMR) model is composed of two main modules: a Response Financial Impact Assessor (RFIA), which provides an assessment concerning the potential financial impact that responses may cause to an organization, and a Response Operational Impact Assessor (ROIA), which assesses potential impacts that efficient mitigation actions may cause on the organization in an operational perspective. As a result, the DRMR model proposes response plans to mitigate identified risks, enable choice of the most suitable response possibilities to reduce identified risks below an admissible level while minimizing potential negative side effects of deliberately taken actions. Gustavo Gonzalez Granadillo, Alexander Motzek, Joaquín García 0001, Hervé Debar |
ARES | 1 |
| 2016 | An n-Sided Polygonal Model to Calculate the Impact of Cyber Security Events
Gustavo Gonzalez Granadillo, Joaquín García 0001, Hervé Debar |
CRiSIS | 1 |
| 2015 | Attack Volume Model: Geometrical Approach and Application
Gustavo Gonzalez Granadillo, Grégoire Jacob, Hervé Debar |
CRiSIS | 1 |
| 2015 | Using a 3D Geometrical Model to Improve Accuracy in the Evaluation and Selection of Countermeasures Against Complex Cyber Attacks
Gustavo Gonzalez Granadillo, Joaquín García 0001, Hervé Debar |
SecureComm | 1 |