EDBT 2026 Demo / reviewers in the wild / expert
Celeste Campo
dblp:21/2847
· DBLP profile ↗
19ranked-venue papers
2as first author
12since 2021 · last 2026
0000-0003-1788-890XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 2 first-author · 11 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 since 2021Systems, architecture and hardware · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GUARDIAN: Gaze User Authentication and Reference Detection for Integrity Analysis on Netflix
Marta Moure-Garrido, Melanie Heck, Christian Becker 0001, Celeste Campo, Carlos García-Rubio |
ETRA | 4 |
| 2026 | CO-DEFEND: Continuous decentralized federated learning for secure DoH-based threat detectionabstractThe use of DNS over HTTPS (DoH) tunneling by an attacker to hide malicious activity within encrypted DNS traffic poses a serious threat to network security, as it allows malicious actors to bypass traditional monitoring and intrusion detection systems while evading detection by conventional traffic analysis techniques. Machine Learning (ML) techniques can be used to detect DoH tunnels; however, their effectiveness relies on large datasets containing both benign and malicious traffic. Sharing such datasets across entities is challenging due to privacy concerns. In this work, we propose CO-DEFEND (Continuous Decentralized Federated Learning for Secure DoH-Based Threat Detection), a Decentralized Federated Learning (DFL) framework that enables multiple entities to collaboratively train a classification machine learning model for DoH threat detection while preserving data privacy, enhancing scalability and resilience against single points of failure. The proposed DFL framework provides a realistic implementation for DoH threat detection, enabling multiple entities to train their local models online with incoming DoH flows in real-time batches as they are processed – an approach that fits naturally within modern Internet architectures. This framework adapts four classical machine learning algorithms, Support Vector Machines (SVM), Logistic Regression (LR), Decision Trees (DT), and Random Forest (RF), for federated scenarios and efficient training. In addition, a key methodological feature of CO-DEFEND is the use of DT and RF as model selection rather than aggregation mechanisms, allowing each participant to retain interpretable and locally optimal decision structures while benefiting from collective updates. We compare our proposed method by using the dataset CIRA-CIC-DoHBrw-2020 with existing machine learning approaches, including more computationally complex alternatives such as neural networks, to demonstrate its effectiveness in detecting malicious DoH tunnels while improving scalability and computational efficiency. Diego Cajaraville-Aboy, Marta Moure-Garrido, Carlos Beis-Penedo, Carlos García-Rubio, Rebeca P. Díaz Redondo, Celeste Campo, Ana Fernández Vilas, Manuel Fernández-Veiga |
Comput. Networks | 6 |
| 2026 | The persistent vulnerability: Characterizing metadata leakage in DNS over QUICabstractWhile DNS over QUIC (DoQ) integrates encryption and transport layer optimizations to ensure confidentiality, the protocol remains susceptible to sophisticated traffic analysis. This paper characterizes the structural metadata leakage of DoQ by evaluating the geographical invariance of traffic signatures across a multi vantage point experimental framework comprising several global nodes. By leveraging Explainable AI (XAI) and systematic feature ablation, we deconstruct the underlying deterministic patterns (specifically temporal mass distribution and burst size sequences) that facilitate high accuracy website fingerprinting. Our findings demonstrate a critical early identification inflection point where domain identification becomes feasible within the initial 200 ms of a connection, effectively bypassing full session establishment. These results quantify the persistent vulnerabilities inherent in the protocol handshake and initial query exchange, remaining consistent across disparate network latencies and regional artifacts. Finally, we discuss the implications of this leakage for privacy preserving DNS architectures and provide a technical benchmark for the development of next generation zero delay traffic obfuscation defenses. Marta Moure-Garrido, Carlos García-Rubio, Celeste Campo |
Comput. Networks | 3 |
| 2025 | Enhancing Privacy in DNS Communications with Energy-Aware MethodologiesabstractThe proliferation of mobile devices and permanent Internet connectivity generates massive data flows that carry personal information and can compromise user privacy. This doctoral research focuses on analyzing privacy vulnerabilities in the Domain Name System (DNS), a fundamental protocol for Internet communications, and its encrypted variants. The research aims to develop novel methodologies that enhance DNS privacy protection while optimizing energy consumption. Initial contributions include the proposal of DNS query forgery techniques as privacy-enhancing mechanisms and the development of PARROT, a reproducible traffic capture system for mobile app analysis. The work demonstrates protocol evolution trends and validates privacy protection strategies through experimental evaluation using synthetic datasets. Future research will focus on energy-aware optimization of DNS privacy solutions and the development of practical implementations for mobile environments. Andrea Jimenez-Berenguel, Celeste Campo, Marta Moure-Garrido |
MSWiM | 2 |
| 2025 | Fingerprinting Encrypted DNS: Exploiting Metadata Leakage in DNS over QUICabstractThe growing adoption of HTTP/3 and its underlying transport protocol, Quick UDP Internet Connections (QUIC), represents a major step forward in Internet communications, improving performance, latency, congestion control, and encryption. Domain Name Server (DNS) over QUIC (DoQ) has emerged to enhance DNS confidentiality and performance, but remains vulnerable to website fingerprinting (WF) attacks, which exploit observable traffic patterns, even in the presence of encryption. In this study, we conduct a detailed analysis into the vulnerability of the DoQ protocol to WF attacks, examining how encrypted DNS traffic can still leak identifiable patterns that adversaries may exploit to infer users’ web activity. We implement a comprehensive feature extraction framework adapted to encrypted DNS traffic. This approach enables accurate classification using a real-world dataset. We apply explainable Artificial Intelligence (XAI) to identify which features drive model predictions, offering new insights into the sources of metadata leakage. The findings of the present study reinforce the efficacy of fingerprinting attacks on DoQ traffic, highlighting the persistent nature of these vulnerabilities despite DoQ’s encryption mechanisms. Consequently, the development of effective fingerprinting mitigation strategies in encrypted environments like DoQ continues to pose a critical challenge for protecting user privacy, underscoring the need for robust mitigation strategies to safeguard user privacy. Marta Moure-Garrido, Celeste Campo, Carlos García-Rubio |
MSWiM | 2 |
| 2025 | Beyond PKI: A DNSSEC Delegation Approach for Scalable Dynamic Credential Management in IoTabstractInternet of Things (IoT) systems that manage data across cloud, fog, and edge environments—and the devices that consume those services—face substantial challenges in confidentiality, privacy, and authentication. However, traditional Public Key Infrastructure (PKI) is too rigid and costly for massive, ephemeral IoT deployments. Moreover, device authentication is often overlooked in favor of service authentication, neglecting the security of the entire ecosystem. DNSSEC combined with DANE introduces a new paradigm in which service authentication can be managed globally, extending trust to locally generated, type-agnostic credentials. This framework can accommodate PKI certificates, self-signed credentials, and local keys, all of which can be verified by any client, local or remote. However, DNSSEC’s signature proofs grow linearly with the number of secured records, inflating communication overhead and energy consumption—an issue aggravated by the larger sizes of post-quantum signatures. Additionally, current DNSSEC delegation mechanisms lack the flexibility needed for secure load balancing and isolation. In this article, we present a collision-based DNSSEC signature-delegation mechanism designed to overcome these scalability limitations. By allowing a central DNS authority to delegate signing responsibilities to local DNS servers, our approach reduces certificate-management overhead and enables a dynamic, hierarchical trust model. It supports both service and device authentication in a unified DNS-name-based security context. Our evaluation shows that the proposed mechanism maintains a stable computational cost irrespective of credential count, a critical benefit for large-scale, resource-constrained IoT deployments. By leveraging existing DNS infrastructure and standards, this solution enhances scalability and efficiency compared to traditional PKI and DNSSEC, while promoting interoperability and ease of deployment. It also opens the adoption of future post quantum trapdoor systems still under research and development. Daniel Díaz Sánchez, Florina Almenárez, Celeste Campo, Carlos García-Rubio, Robert Simon Sherratt |
IEEE Internet Things J. | 3 |
| 2024 | Real-Time Analysis of Encrypted DNS Traffic for Threat DetectionabstractDomain Name System (DNS) tunneling is a well-known cyber-attack that allows data exfiltration - the attackers exploit this tunnel to extract sensitive information from the system. Advanced Persistent Threat (APT) attackers encapsulate malicious traffic in a DNS connection to elude security mechanisms such as Intrusion Detection System (IDS). Although different techniques have been implemented to detect these targeted attacks, their rise induces a threat to Cyber-Physical Systems (CPS). The DNS over HTTPS (DoH) tunnel detection is a challenge because the encrypted data prevents an analysis of DNS traffic content. In this paper, we present a novel detection system that identifies malicious DoH tunnels in real time. We study the normal traffic pattern and based on that, we define a profile. The objective of this system is to detect malicious activity on the system as early as possible through a lightweight packet by packet analysis based on a real-time IDS classifier. This system is evaluated on three available data sets and the results obtained are compared with a machine learning technique. We demonstrate that the identification of anomalous activity, in particular DoH tunnels, is possible by analyzing different traffic features. Marta Moure-Garrido, Sajal K. Das 0001, Celeste Campo, Carlos García-Rubio |
ICC | 3 |
| 2024 | Integrating Post-Quantum Cryptography into CoAP and MQTT-SN ProtocolsabstractPost-Quantum Cryptography (PQC) is a practical and cost-effective solution to defend against emerging quantum computing threats. So, leading worldwide security agencies and standardization bodies strongly advocate for the proactive integration of PQ cryptography into underlying frameworks to support applications, protocols, and services. The current research predominantly addresses the incorporation of PQC in Internet communication protocols such as HTTP and DNS; nevertheless, the focus on embedded devices has been limited to evaluating PQC’s integration within TLS/DTLS in isolation. Hence, there is a notable gap in understanding how PQC impacts IoT-specific communication protocols. This paper presents the integration of PQC into two communication protocols specifically tailored for IoT devices, the Constrained Application Protocol (CoAP) and MQTT for Sensor Networks (MQTT-SN), via the wolfSSL library. These two integrations contribute to the understanding of PQC’s implications for IoT communication protocols. Javier Blanco-Romero, Vicente Lorenzo, Florina Almenárez, Daniel Díaz Sánchez, Celeste Campo, Carlos García-Rubio |
ISCC | 5 |
| 2024 | Inferring mobile applications usage from DNS trafficabstractIn the digital era, our lives are intrinsically linked to the daily use of mobile applications. As a consequence, we generate and transmit a large amount of personal data that puts our privacy in danger. Despite having encrypted communications, the DNS traffic is usually not encrypted, and it is possible to extract valuable information from the traffic generated by mobile applications. This study focuses on the analysis of the DNS traffic behavior found in mobile application traces, developing a methodology capable of identifying mobile applications based on the domains they query. With this methodology, we were able to identify apps with 98% accuracy. Furthermore, we have validated the effectiveness of the characterization obtained with one dataset by identifying traces from other independent datasets. The evaluation showed that the methodology provides successful results in identifying mobile applications. Celeste Campo, Carlos García-Rubio, Andrea Jimenez-Berenguel, Marta Moure-Garrido, Florina Almenárez, Daniel Díaz Sánchez |
Ad Hoc Networks | 1 |
| 2024 | Evaluating integration methods of a quantum random number generator in OpenSSL for TLSabstractThe rapid advancement of quantum computing poses a significant threat to conventional cryptography. Whilst post-quantum cryptography (PQC) stands as the prevailing trend for fortifying the security of cryptographic systems, the coexistence of quantum and classical computing paradigms presents an opportunity to leverage the strengths of both technologies, for instance, nowadays the use of Quantum Random Number Generators (QRNGs) – considered as True Random Number Generators (TRNGs) – opens up the possibility of discussing hybrid systems. In this paper, we evaluate both aspects, on the one hand, we use hybrid TLS (Transport Layer Security) protocol that leverages the widely used secure protocol on the Internet and integrates PQC algorithms, and, on the other hand, we evaluate two approaches to integrate a QRNG, i.e., Quantis PCIe-240M, in OpenSSL 3.0 to be used by TLS. Both approaches are compared through a Nginx Web server, that uses OpenSSL’s implementation of TLS 1.3 for secure web communication. Our findings highlight the importance of optimizing such integration method, because while direct integration can lead to performance penalties specific to the method and hardware used, alternative methods demonstrate the potential for efficient QRNG deployment in cryptographic systems. Javier Blanco-Romero, Vicente Lorenzo, Florina Almenárez, Daniel Díaz Sánchez, Carlos García-Rubio, Celeste Campo, Andrés Marín López |
Comput. Networks | 6 |
| 2023 | Real time detection of malicious DoH traffic using statistical analysisabstractThe DNS protocol plays a fundamental role in the operation of ubiquitous networks. All devices connected to these networks need DNS to work, both for traditional domain name to IP address translation, and for more advanced services such as resource discovery. DNS over HTTPS (DoH) solves certain security problems present in the DNS protocol. However, malicious DNS tunnels, a covert way of encapsulating malicious traffic in a DNS connection, are difficult to detect because the encrypted data prevents performing an analysis of the content of the DNS traffic. In this study, we introduce a real-time system for detecting malicious DoH tunnels, which is based on analyzing DoH traffic using statistical methods. Our research demonstrates that it is feasible to identify in real-time malicious traffic by analyzing specific parameters extracted from DoH traffic. In addition, we conducted statistical analysis to identify the most significant features that distinguish malicious traffic from benign traffic. Using the selected features, we achieved satisfactory results in classifying DoH traffic as either benign or malicious. Marta Moure-Garrido, Celeste Campo, Carlos García-Rubio |
Comput. Networks | 2 |
| 2021 | Performance evaluation of CoAP and MQTT with security support for IoT environmentsabstractWorld is living an overwhelming explosion of smart devices: electronic gadgets, appliances, meters, cars, sensors, camera and even traffic lights, that are connected to the Internet to extend their capabilities, constituting what is known as Internet of Things (IoT). In these environments, the application layer is decisive for the quality of the connection, which has dependencies to the transport layer, mainly when secure communications are used. This paper analyses the performance offered by these two most popular protocols for the application layer: Constrained Application Protocol (CoAP) and Message Queue Telemetry Transport (MQTT). This analysis aims to examine the features and capabilities of the two protocols and to determine their feasibility to operate under constrained devices taking into account security support and diverse network conditions, unlike the previous works. Since IoT devices typically show battery constraints, the analysis is focused on bandwidth and CPU use, using realistic network scenarios, since this use translates to power consumption. Victor Seoane, Carlos García-Rubio, Florina Almenárez, Celeste Campo |
Comput. Networks | 4 |
| 2020 | A hybrid analysis of LBSN data to early detect anomalies in crowd dynamicsabstractUndoubtedly, Location-based Social Networks (LBSNs) provide an interesting source of geo-located data that we have previously used to obtain patterns of the dynamics of crowds throughout urban areas. According to our previous results, activity in LBSNs reflects the real activity in the city. Therefore, unexpected behaviors in the social media activity are a trustful evidence of unexpected changes of the activity in the city. In this paper we introduce a hybrid solution to early detect these changes based on applying a combination of two approaches, the use of entropy analysis and clustering techniques, on the data gathered from LBSNs. In particular, we have performed our experiments over a data set collected from Instagram for seven months in New York City, obtaining promising results. Rebeca P. Díaz Redondo, Carlos García-Rubio, Ana Fernández Vilas, Celeste Campo, Alicia Rodriguez-Carrion |
Future Gener. Comput. Syst. | 4 |
| 2012 | Bandwidth efficient broadcasting in VANETsabstractWireless communications amongst vehicles bring the opportunity for a wide range of applications, from safety aid to passenger entertainment. The necessity to broadcast information to several-hop neighbors is common to most of the potential application protocols. Broadcast protocols for VANETs based on diverse techniques have already been proposed. In this article, we compare basic broadcast schemes that are not dependent on neighbor knowledge using ns-2 - simple flooding, probabilistic, counter-based, distance-based and traffic-based broadcast. The objective is to obtain general directions for the design of a bandwidth efficient broadcast. Based on this comparison, we have selected distance-based flooding and proposed a scheme that is easy to adjust to the application's necessities. Estrella M. Garcia-Lozano, Celeste Campo, Carlos García-Rubio, Alberto Cortés-Martín |
IWCMC | 2 |
| 2011 | Trust management for multimedia P2P applications in autonomic networking
Florina Almenárez, Andrés Marín López, Daniel Díaz Sánchez, Alberto Cortés-Martín, Celeste Campo, Carlos García-Rubio |
Ad Hoc Networks | 5 |
| 2008 | A Trust-based Middleware for Providing Security to Ad-Hoc Peer-to-Peer ApplicationsabstractTrust has emerged as an important facet of inter-domain relationships. Trust management in fixed networks is not functional in ad hoc P2P networks, because these require an autonomous, user-centric and non-static trust management. The trust model is the basis of any security infrastructure. In this paper, we propose a trust-based middleware for secure digital content sharing between pervasive devices. Such middleware allows to enhance security support of pervasive devices. Likewise, we propose a suitable and efficient secure file exchange protocol, WSFEP, for content sharing. Both middleware and file sharing application have been successfuly integrated and tested on PDAs. Florina Almenárez, Andrés Marín López, Daniel Díaz Sánchez, Alberto Cortés-Martín, Celeste Campo, Carlos García-Rubio |
PerCom | 5 |
| 2008 | Building an Open Toolkit of Digital Certificate Validation for Mobile Web ServicesabstractMobile devices can both consume and provide services. They act indeed as a peer, according to the OMA mobile Web services specification. It is a move from simple data sharing to full deliver of application services down to mobile devices. The use of digital certificates to ensure the provision of services is suitable because devices can belong to different trust domains without having previously an established relationship. Besides, by interoperability issues, the use of PKI continues to grow and move into diverse environments. However, applications making use of such certificates are burdened with the overhead of constructing and validating the certification paths. These processes can become more complex and costly than fixed-infrastructure networks due to the wireless communications and restricted processing and power capabilities. The IETF PKIX WG has specified different mechanisms for delegating the certificate validation and making lighter the status information obtaining. However, these are not supported currently by mobile devices. For these reasons, we propose to develop an open toolkit for X.509 public key certificate validating based on OpenSSL. This toolkit is being developed and tested successfully in PDAs. Florina Almenárez, Andrés Marín López, Daniel Díaz Sánchez, Alberto Cortés-Martín, Celeste Campo, Carlos García-Rubio |
PerCom | 5 |
| 2007 | Smart card-based agents for fair non-repudiation
Andrés Marín López, Daniel Díaz Sánchez, Florina Almenárez, Carlos García-Rubio, Celeste Campo |
Comput. Networks | 5 |
| 2006 | PDP: A lightweight discovery protocol for local-scope interactions in wireless ad hoc networks
Celeste Campo, Carlos García-Rubio, Andrés Marín López, Florina Almenárez |
Comput. Networks | 1 |