Gustavo Gonzalez Granadillo

dblp:119/6733 · also Gustavo Daniel Gonzalez Granadillo · DBLP profile ↗
← Back
17ranked-venue papers
13as first author
5since 2021 · last 2025
0000-0003-2036-981XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 14 · 11 first-author · 5 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1Theory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 AI-Based Anomaly Detection and Classification of Traffic Using Netflow
abstract
International audience
Gustavo Gonzalez Granadillo, Nesrine Kaaniche
SECRYPT1
2022 Efficient Hybrid Model for Intrusion Detection Systems
abstract
International audience
Nesrine Kaaniche, Aymen Boudguiga, Gustavo Gonzalez Granadillo
SECRYPT3
2022 A Trusted Platform Module-based, Pre-emptive and Dynamic Asset Discovery Tool
abstract
This paper presents an original Intelligent and Secure Asset Discovery Tool (ISADT) that uses artificial intelligence and TPM-based technologies to: (i) detect the network assets, and (ii) detect suspicious pattern in the use of the network. The architecture has specifically been designed to discover the assets of medium and large size companies and institutions, such as hospitals, universities, or government buildings. Given the distributed design of the architecture, it can cope with the problem of the isolation of different Virtual Local Area Networks (VLANs). This is done by collecting information from all the VLANs and storing it in a central node, which can be accessed by the network administrator, who may consult and visualize the status in any moment, or even by other authorized applications. The collected data is kept in a secure warehouse by the use of a Trusted Platform Module. Moreover, collected data is processed by the use of artificial intelligence in two ways: (i) the traffic of each network is analysed so that suspicious patterns can be detected, and (ii) identified ports and status are analysed to detect anomalous combinations of open ports in a device.
Antonio Jesús Díaz-Honrubia, Alberto Blázquez-Herranz, Lucía Prieto Santamaría, Ernestina Menasalvas Ruiz, Alejandro Rodríguez González, Gustavo Gonzalez Granadillo, Emmanouil A. Panaousis, Christos Xenakis
J. Inf. Secur. Appl.6
2021 An Improved Live Anomaly Detection System (I-LADS) based on Deep Learning Algorithms
Gustavo Gonzalez Granadillo, Alejandro G. Bedoya
SECRYPT1
2021 ETIP: An Enriched Threat Intelligence Platform for improving OSINT correlation, analysis, visualization and sharing capabilities
Gustavo Gonzalez Granadillo, Mario Faiella, Iberia Medeiros, Rui Azevedo, Susana Gonzalez Zarzosa
J. Inf. Secur. Appl.1
2020 Stateful RORI-based countermeasure selection using hypergraphs
Gustavo Gonzalez Granadillo, Elena Fedorchenko, Joaquín García 0001, Igor V. Kotenko, Andrey Fedorchenko
J. Inf. Secur. Appl.1
2020 Stateful RORI-based countermeasure selection using hypergraphs
Gustavo Gonzalez Granadillo, Elena Fedorchenko, Joaquín García 0001, Igor V. Kotenko, Andrey Fedorchenko
J. Inf. Secur. Appl.1
2019 An Overview of the CUREX Platform
abstract
Health sector is becoming more and more dependent on digital information every day. This fact can be exploited by cyber criminals who may obtain very lucrative benefits from stolen data. Moreover, a breach of integrity of health data can have terrible consequences for the patients. CUREX project aims to protect the confidentiality of health data and to maintain its integrity by producing a novel, flexible and scalable situational awareness-oriented platform. CUREX has been conceived as GDPR compliant by design. This design has been thought as a decentralised architecture enhanced with a private blockchain infrastructure. Thus, it ensures the integrity of the risk assessment process and of all data transactions.
Antonio Jesús Díaz-Honrubia, Alejandro Rodríguez González, Juan Mora Zamorano, Jesús Rey Jiménez, Gustavo Gonzalez Granadillo, Mariza Konidi, Panos Papachristou, Sokratis Nifakos, Georgia Kougka, Anastasios Gounaris
CBMS5
2018 A Pyramidal-based Model to Compute the Impact of Cyber Security Events
abstract
This paper presents a geometrical model that projects malicious and benign events (e.g., attacks, security countermeasures) as pyramidal instances in a multidimensional coordinate system. The approach considers internal event data related to the target system (e.g., users, physical, and logical resources, IP addresses, port numbers, etc.), and external event data related to the attacker (e.g., knowledge, motivation, skills, etc.) that can be obtained a priori and a posteriori. Internal data is used to model the base of the pyramid, whereas external data is used to model its height. In addition, the approach considers state transitions taken by the attacker to model the steps of a multi-stage attack to reach to its final goal. As a result, for each modeled state, new countermeasures are evaluated and the attacker's knowledge a posteriori changes accordingly, making it possible to evaluate the impact of the attack at time Ti, where i denotes the stage at which the attack is executed. A graphical representation of the impact of each evaluated event is depicted for visualization purposes. A use case of a cyber-physical system is proposed at the end of the paper to illustrate the applicability of the proposed geometrical model.
Gustavo Gonzalez Granadillo, Jose Rubio-Hernan, Joaquín García 0001
ARES1
2018 Dynamic risk management response system to handle cyber threats
Gustavo Gonzalez Granadillo, Samuel Dubus, Alexander Motzek, Joaquín García 0001, Ender Alvarez, Matteo Merialdo, Serge Papillon, Hervé Debar
Future Gener. Comput. Syst.1
2017 Towards a Security Event Data Taxonomy
Gustavo Gonzalez Granadillo, Jose Rubio-Hernan, Joaquín García 0001
CRiSIS1
2017 Selection of Pareto-efficient response plans based on financial and operational assessments
abstract
Finding adequate responses to ongoing attacks on ICT systems is a pertinacious problem and requires assessments from different perpendicular viewpoints. However, current research focuses on reducing the impact of an attack irregardless of side effects caused by responses. In order to achieve a comprehensive yet accurate response to possible and ongoing attacks on a managed ICT system, we propose an approach that evaluates a response from two perpendicular perspectives: (1) A response financial impact assessment, considering the financial benefits of restoring and protecting potentially threatened operational capabilities while considering implementation and maintenance costs of responses. (2) A response operational impact assessment, which assesses potential impacts that efficient mitigation actions may inadvertently cause on the organization in an operational perspective, e.g., negative side effects of deploying mitigations. It is the key benefit of the presented approach to combine all obtained evaluations with a multi-dimensional optimization procedure such that a response plan is selected which reduces a state of risk below an admissible level while minimizing potential negative side effects of deliberately taken actions.
Alexander Motzek, Gustavo Gonzalez Granadillo, Hervé Debar, Joaquín García 0001, Ralf Möller 0001
EURASIP J. Inf. Secur.2
2017 A polytope-based approach to measure the impact of events against critical infrastructures
Gustavo Gonzalez Granadillo, Joaquín García 0001, Hervé Debar
J. Comput. Syst. Sci.1
2016 Selection of Mitigation Actions Based on Financial and Operational Impact Assessments
abstract
Finding adequate responses to ongoing attacks on ICT systems is a pertinacious problem and requires assessments from different perpendicular viewpoints. However, current research focuses on reducing the impact of an attack irregardless of side-effects caused by responses. In order to achieve a comprehensive yet accurate response to possible and ongoing attacks on a managed ICT system, we propose an approach that relies on a response system that continuously quantifies risks, and decides how to respond to cyber-threats that target a monitored ICT system. Our Dynamic Risk Management Response (DRMR) model is composed of two main modules: a Response Financial Impact Assessor (RFIA), which provides an assessment concerning the potential financial impact that responses may cause to an organization, and a Response Operational Impact Assessor (ROIA), which assesses potential impacts that efficient mitigation actions may cause on the organization in an operational perspective. As a result, the DRMR model proposes response plans to mitigate identified risks, enable choice of the most suitable response possibilities to reduce identified risks below an admissible level while minimizing potential negative side effects of deliberately taken actions.
Gustavo Gonzalez Granadillo, Alexander Motzek, Joaquín García 0001, Hervé Debar
ARES1
2016 An n-Sided Polygonal Model to Calculate the Impact of Cyber Security Events
Gustavo Gonzalez Granadillo, Joaquín García 0001, Hervé Debar
CRiSIS1
2015 Attack Volume Model: Geometrical Approach and Application
Gustavo Gonzalez Granadillo, Grégoire Jacob, Hervé Debar
CRiSIS1
2015 Using a 3D Geometrical Model to Improve Accuracy in the Evaluation and Selection of Countermeasures Against Complex Cyber Attacks
Gustavo Gonzalez Granadillo, Joaquín García 0001, Hervé Debar
SecureComm1