EDBT 2026 Demo / reviewers in the wild / expert
Mikel Iturbe
dblp:183/3631
· DBLP profile ↗
9ranked-venue papers
1as first author
7since 2021 · last 2026
0000-0001-9641-5646ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 1 first-author · 4 since 2021Computer networks · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Replica-Based Moving Target Defense Against Injection Attacks in Software-Defined Industrial Control SystemsabstractRecent incidents have demonstrated the increasing vulnerability of Industrial Control Systems (ICSs) to sophisticated and targeted attacks orchestrated by adversaries with high motivation, resources, and domain knowledge. Among these threats, False Data Injection (FDI) attacks have emerged as one of the main security threats to ICSs, involving the deliberate manipulation or injection of false data into the control system to deceive or disrupt operations. FDI attacks pose a significant risk due to their high capacity of concealment and ability to evade intrusion detection systems that rely on accurate ICS models. In this paper, we presentdefclon, a novel Software-Defined Networking (SDN)-based Moving Target Defense (MTD) approach against FDI attacks.Defclonproactively replicates network packets across multiple network paths and adaptively selects a single path using a signaling game model to reach the destination end-device. We demonstrate the effectiveness of our approach through simulations, numerical analysis, and experiments on ICS network traffic and topologies. Experimental results show thatdefclonis able to not only mitigate the effects of FDI attacks, but also to introduce different levels of uncertainty without degrading network performance, significantly increasing the difficulty for adversaries to gather information and launch attacks. Xabier Etxezarreta, Federico Turrin, Iñaki Garitano, Mikel Iturbe, Urko Zurutuza, Mauro Conti |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Sow Smarter, Not Harder: Evaluating LLM-Generated Seeds for Fuzzing Critical Infrastructure
Jorge Barredo, Maialen Eceiza, Jose Luis Flores 0001, Mikel Iturbe |
CRITIS | 4 |
| 2025 | GJALLARHORN: A framework for vulnerability detection via electromagnetic side-channel analysis in embedded systemsabstractThe proliferation of embedded systems within the Internet of Things (IoT) has heightened the difficulty of detecting vulnerabilities due to their inherent resource constraints. This paper introduces GJALLARHORN, a framework extending electromagnetic side-channel analysis (EM SCA) for early-stage vulnerability detection in embedded systems. Unlike conventional methods requiring code access or imposing computational overhead, GJALLARHORN non-invasively analyses EM emissions to identify anomalous patterns indicating potential security vulnerabilities. By observing hardware-level manifestations of software execution, GJALLARHORN complements software-level analysis, revealing vulnerabilities that might otherwise remain undetected. The framework adapts to device complexity, enabling categorisation of up to 16 distinct vulnerability types, including buffer overflows, memory leaks, and arithmetic errors. Evaluations on both low-end (STM NUCLEO-144) and high-end (Raspberry Pi 3B) architectures demonstrate GJALLARHORN’s effectiveness, achieving a recall of 95.94% and F 1 score of 96.39% on the low-end system, and 73.33% recall with 84.61% F 1 score on the high-end system. Our results reveal that memory-related vulnerabilities produce more distinguishable EM signatures than arithmetic errors, offering valuable insights for externally detecting vulnerabilities. By enabling detection during development, GJALLARHORN helps mitigate risks before deployment, potentially reducing the economic impact of security incidents in IoT infrastructure. Jorge Barredo, Maialen Eceiza, Jose Luis Flores 0001, Mikel Iturbe |
Comput. Secur. | 4 |
| 2024 | Low delay network attributes randomization to proactively mitigate reconnaissance attacks in industrial control systemsabstractAbstract Industrial Control Systems are used in a wide variety of industrial facilities, including critical infrastructures, becoming the main target of multiple security attacks. A malicious and successful attack against these infrastructures could cause serious economic and environmental consequences, including the loss of human lives. Static networks configurations and topologies, which characterize Industrial Control Systems, represent an advantage for attackers, allowing them to scan for vulnerable devices or services before carrying out the attack. Identifying active devices and services is often the first step for many attacks. This paper presents a proactive network reconnaissance defense mechanism based on the temporal randomization of network IP addresses, MAC addresses and port numbers. The obtained information distortion minimizes the knowledge acquired by the attackers, hindering any attack that relies on network addressing. The temporal randomization of network attributes is performed in an adaptive way, minimizing the overhead introduced in the network and avoiding any error and latency in communications. The implementation as well as the tests have been carried out in a laboratory with real industrial equipment, demonstrating the effectiveness of the presented solution. Xabier Etxezarreta, Iñaki Garitano, Mikel Iturbe, Urko Zurutuza |
Wirel. Networks | 3 |
| 2024 | On the use of MiniCPS for conducting rigorous security experiments in Software-Defined Industrial Control SystemsabstractAbstract Software-Defined Networking (SDN) offers a global view over the network and the ability of centrally and dynamically managing network flows, making them ideal for creating security threat detection and mitigation solutions. Industrial networks possess specific characteristics that make them well-suited for such solutions, leading to extensive research efforts in this area. However, due to the high economic cost and potential risks associated with real equipment interaction, most studies rely on testbeds for demonstration purposes. Therefore, it becomes crucial to understand the limitations and safe operating ranges of testbed environments to ensure the development of scientifically rigorous experiments and accurate result measurements. This study focuses on analyzing MiniCPS-based testbeds in terms of network performance, experiment replicability, and the effects of different attacker implementation modes. The findings demonstrate that utilizing MiniCPS on actual hardware enables the development of highly replicable and high-performance testbeds, as long as they operate within the predefined safe operating ranges. Additionally, this work provides an in-depth analysis of various attacker implementation techniques and their impact on the network. Xabier Etxezarreta, Iñaki Garitano, Mikel Iturbe, Urko Zurutuza |
Wirel. Networks | 3 |
| 2023 | Improving fuzzing assessment methods through the analysis of metrics and experimental conditionsabstractFuzzing is nowadays one of the most widely used bug hunting techniques. By automatically generating malformed inputs, fuzzing aims to trigger unwanted behavior on its target. While fuzzing research has matured considerably in the last years, the evaluation and comparison of different fuzzing proposals remain challenging, as no standard set of metrics, data, or experimental conditions exist to allow such observation. This paper aims to fill that gap by proposing a standard set of features to allow such comparison. For that end, it first reviews the existing evaluation methods in the literature and discusses all existing metrics by evaluating seven fuzzers under identical experimental conditions. After examining the obtained results, it recommends a set of practices –particularly on the metrics to be used–, to allow proper comparison between different fuzzing proposals. Maialen Eceiza, Jose Luis Flores 0001, Mikel Iturbe |
Comput. Secur. | 3 |
| 2021 | Fuzzing the Internet of Things: A Review on the Techniques and Challenges for Efficient Vulnerability Discovery in Embedded SystemsabstractWith a growing number of embedded devices that create, transform, and send data autonomously at its core, the Internet of Things (IoT) is a reality in different sectors, such as manufacturing, healthcare, or transportation. With this expansion, the IoT is becoming more present in critical environments, where security is paramount. Infamous attacks, such as Mirai, have shown the insecurity of the devices that power the IoT, as well as the potential of such large-scale attacks. Therefore, it is important to secure these embedded systems that form the backbone of the IoT. However, the particular nature of these devices and their resource constraints mean that the most cost-effective manner of securing these devices is to secure them before they are deployed, by minimizing the number of vulnerabilities they ship. To this end, fuzzing has proved itself as a valuable technique for automated vulnerability finding, where specially crafted inputs are fed to programs in order to trigger vulnerabilities and crash the system. In this survey, we link the world of embedded IoT devices and fuzzing. For this end, we list the particularities of the embedded world as far as security is concerned, we perform a literature review on fuzzing techniques and proposals, studying their applicability to embedded IoT devices and, finally, we present future research directions by pointing out the gaps identified in the review. Maialen Eceiza, Jose Luis Flores 0001, Mikel Iturbe |
IEEE Internet Things J. | 3 |
| 2018 | Truth Will Out: Departure-Based Process-Level Detection of Stealthy Attacks on Control SystemsabstractRecent incidents have shown that Industrial Control Systems (ICS) are becoming increasingly susceptible to sophisticated and targeted attacks initiated by adversaries with high motivation, domain knowledge, and resources. Although traditional security mechanisms can be implemented at the IT-infrastructure level of such cyber-physical systems, the community has acknowledged that it is imperative to also monitor the process-level activity, as attacks on ICS may very well influence the physical process. In this paper, we present PASAD, a novel stealthy-attack detection mechanism that monitors time series of sensor measurements in real time for structural changes in the process behavior. We demonstrate the effectiveness of our approach through simulations and experiments on data from real systems. Experimental results show that PASAD is capable of detecting not only significant deviations in the process behavior, but also subtle attack-indicating changes, significantly raising the bar for strategic adversaries who may attempt to maintain their malicious manipulation within the noise level. Wissam Aoudi, Mikel Iturbe, Magnus Almgren |
CCS | 2 |
| 2017 | Towards Large-Scale, Heterogeneous Anomaly Detection Systems in Industrial Networks: A Survey of Current TrendsabstractIndustrial Networks (INs) are widespread environments where heterogeneous devices collaborate to control and monitor physical processes. Some of the controlled processes belong to Critical Infrastructures (CIs), and, as such, IN protection is an active research field. Among different types of security solutions, IN Anomaly Detection Systems (ADSs) have received wide attention from the scientific community. While INs have grown in size and in complexity, requiring the development of novel, Big Data solutions for data processing, IN ADSs have not evolved at the same pace. In parallel, the development of Big Data frameworks such as Hadoop or Spark has led the way for applying Big Data Analytics to the field of cyber-security, mainly focusing on the Information Technology (IT) domain. However, due to the particularities of INs, it is not feasible to directly apply IT security mechanisms in INs, as IN ADSs face unique characteristics. In this work we introduce three main contributions. First, we survey the area of Big Data ADSs that could be applicable to INs and compare the surveyed works. Second, we develop a novel taxonomy to classify existing IN-based ADSs. And, finally, we present a discussion of open problems in the field of Big Data ADSs for INs that can lead to further development. Mikel Iturbe, Iñaki Garitano, Urko Zurutuza, Roberto Uribeetxeberria |
Secur. Commun. Networks | 1 |