EDBT 2026 Demo / reviewers in the wild / expert
Pantaleone Nespoli
dblp:220/2751
· DBLP profile ↗
9ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0002-4041-1205ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021Computer networks · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Reactive cyber deception: Stealth-based adaptive redirection to on-demand honeypots with AI-driven data generationabstractCybersecurity is evolving rapidly, incorporating paradigms such as Cyber Deception (CYDEC) and Moving Target Defense (MTD) to counter sophisticated attacks. CYDEC misleads adversaries by diverting their actions into controlled environments where they unknowingly interact with decoy assets. This work introduces a deception mechanism based on stealthy TCP redirection to dynamically instantiated honeypots. Unlike static decoys, the system creates a honey server on-demand that replicates the victim asset in real time. To enhance credibility, the replica is enriched with fake but coherent data generated by a Large Language Model (LLM), producing realistic documents, logs, or configurations tailored to the compromised pillar, that is, confidentiality, integrity, or availability. The architecture builds on Software-Defined Networking (SDN), enabling flexible deployment and adaptive deception at scale. The SDN Controller manages redirection and cloning while preserving TCP session continuity through sequence-number manipulation, making the diversion virtually undetectable. Experiments validated the approach in diverse environments. Results show negligible latency overheads, even under encrypted protocols, seamless honeypot instantiation, and highly plausible LLM-generated honeydata that deceives Attackers while enriching threat intelligence. Deployment on resource-constrained hardware such as Raspberry Pi demonstrates feasibility for IoT and embedded contexts. Overall, combining SDN and LLM technologies enables a scalable, adaptive, and robust CYDEC-based defense capable of deceiving adversaries in real time while strengthening cyber threat intelligence. Pedro Beltrán López, Manuel Gil Pérez, Emmanouil Vasilomanolakis, Pantaleone Nespoli |
Comput. Networks | 4 |
| 2025 | DEFENDIFY: defense amplified with transfer learning for obfuscated malware frameworkabstractAbstract The existence of malicious software (malware) represents a potential threat to users who connect to a large set of services provided by multiple providers. Such malware is capable of stealing, spying on, encrypting data from users, and spreading, provoking impacts that are beyond a single citizen’s device and reaching critical information systems. To detect malware families, Machine Learning and Deep Learning techniques have been employed recently, demonstrating promising results. However, these techniques lack in detecting more advanced malware that employs obfuscation techniques. In this paper, we present DEFENDIFY, a novel framework, empowered by Computer Vision, Deep Learning, and Transfer Learning techniques, that is able to detect completely obfuscated malware with high performance in terms of accuracy and computational consumption. DEFENDIFY comprises three modules: Dataset Creation, Binary Obfuscation, and Model Generation. These modules work together to detect both obfuscated and non-obfuscated malware. The core module, i.e., the Model Generation, employs an entropy tester that determines whether a sample is obfuscated or not. Then, a Deep Learning model powered by Transfer Learning is employed to determine if it is malware or goodware. We validated our framework using real data gathered from malware repositories and legitimate software. The proposed framework was configured to test four Convolutional Neural Network architectures: ResNet18, ResNet34, EfficientNetB3, and EfficientNetV2S. Among them, the ResNet18 architecture obtained the best performance in detecting both non-obfuscated and obfuscated samples with an F1-score of 99.34% and 97.5%, respectively. Rodrigo Castillo Camargo, Juan Murcia Nieto, Nicolás Rojas 0004, Daniel Díaz López, Santiago Alférez, Ángel Luis Perales Gómez, Pantaleone Nespoli, Félix Gómez Mármol, Umit Karabiyik |
Cybersecur. | 7 |
| 2024 | Bridging the Gap: Cyber Defence Skills for the FutureabstractAs cyber threats continue to evolve, the need for highly skilled cyber defence operators becomes increasingly critical. In this work, we aim to provide a multidisciplinary exploration into the current educational landscape, focusing on the following pivotal areas: cyber defence educational initiatives, digital skills, technological enablers, and ethical considerations. First, we present the current landscape of cyber defence educational initiatives. Then, we examine the required digital skills, virtual reality and augmented reality initiatives for immersive learning experiences and delve into the advantages of game-based learning for skill acquisition in order to finally provide a holistic evaluation of the complexities involved in cyber defence training. We underscore the importance of standardising training modules tailored to diverse roles within cyber defence. The discussion emphasises the need for ethical and legal guidelines, especially concerning privacy and bias in AI-driven educational tools. Finally, we highlight the importance of dynamic curricula that include technical, legal, and soft skills, along with hands-on training through simulations to prepare operators for real-world cyber threats. This work will serve as a foundation for academics, industry professionals, and policy-makers interested in elevating the standards and effectiveness of cyber defence training suggesting ideas for more specialised, adaptable, and ethically responsible programs. Sofia Strukova, Mariano Albaladejo-González, Maya Bozhilova, Alejandro Campos Fuentes, Simone Lenti, Gregorio Martínez Pérez, Daniel Navarro-Martínez, Pantaleone Nespoli, Giuseppe Santucci, Marco Antonio Sotelo Monge, Nikolai Stoianov, Eugenio Viesca Revuelta, José A. Ruipérez-Valiente |
EDUCON | 8 |
| 2023 | Securing cloud-based military systems with Security Chaos Engineering and Artificial IntelligenceabstractRecently, system security represents a big challenge for many organizations, and it must be specifically handled when a system is intended to be deployed in a cloud environment. Cloud environments provide multiple security services that run over a Shared Responsibility Model that requires the participation of the cloud provider and the customer. Thus, this paper proposes an architecture based on Artificial Intelligence to support the finding of system threats and errors in an early stage and on Security Chaos Engineering methodology to reliably test the existence of such errors. This proposed architecture may help orientate better system designs and contribute to building holistic security. A particular use case is described to show how the proposal can be applied to a system that supports services for a military-related organization. Martin Bedoya, Sara Palacios Chavarro, Daniel Díaz López, Pantaleone Nespoli, Estefania Laverde, Sebastián Suárez |
ARES | 4 |
| 2021 | AISGA: Multi-objective parameters optimization for countermeasures selection through genetic algorithmabstractCyberattacks targeting modern network infrastructures are increasing in number and impact. This growing phenomenon emphasizes the central role of cybersecurity and, in particular, the reaction against ongoing threats targeting assets within the protected system. Such centrality is reflected in the literature, where several works have been presented to propose full-fledged reaction methodologies to tackle offensive incidents’ consequences. In this direction, the work in [18] developed an immuno-based response approach based on the application of the Artificial Immune System (AIS) methodology. That is, the AIS-powered reaction is able to calculate the optimal set of atomic countermeasure to enforce on the asset within the monitored system, minimizing the risk to which those are exposed in a more than adequate time. To further contribute to this line, the paper at hand presents AISGA, a multi-objective approach that leverages the capabilities of a Genetic Algorithm (GA) to optimize the selection of the input parameters of the AIS methodology. Specifically, AISGA selects the optimal ranges of inputs that balance the tradeoff between minimizing the global risk and the execution time of the methodology. Additionally, by flooding the AIS-powered reaction with a wide range of possible inputs, AISGA intends to demonstrate the robustness of such a model. Exhaustive experiments are executed to precisely compute the optimal ranges of parameters, demonstrating that the proposed multi-objective optimization prefers a fast-but-effective reaction. Pantaleone Nespoli, Félix Gómez Mármol, Georgios Kambourakis |
ARES | 1 |
| 2021 | Cyberprotection in IoT environments: A dynamic rule-based solution to defend smart devicesabstractUndoubtedly, modern human digital lives are every day more and more connected, and the revolution of “everything connected” is already becoming a reality. Indeed, humans live in the age of the Internet of Things (IoT), and one of the most usual IoT contexts is a smart home. Unfortunately, such significant enhancement also means that common home devices, such as fridges, cameras, or even bulbs, are exposed to malevolent entities whose primary goal is to threaten the confidentiality, integrity, and availability of the automatically-exchanged information. Aiming at fine-tuning the protection of the smart devices, this paper proposes a novel dynamic rule management solution adaptable to the current status of the IoT environment, so to protect it against cyberattacks. Experiments demonstrated that a notable reduction in the CPU and RAM consumption was achieved when applying this novel scheme. Additionally, the number of packets processed per second increased substantially, inducing a meaningful enhancement also from a security perspective. Pantaleone Nespoli, Daniel Díaz López, Félix Gómez Mármol |
J. Inf. Secur. Appl. | 1 |
| 2021 | COnVIDa: COVID-19 multidisciplinary data collection and dashboard
Enrique Tomás Martínez Beltrán, Mario Quiles Pérez, Javier Pastor-Galindo, Pantaleone Nespoli, Félix J. García Clemente, Félix Gómez Mármol |
J. Biomed. Informatics | 4 |
| 2020 | Spotting Political Social Bots in Twitter: A Use Case of the 2019 Spanish General Election
Javier Pastor-Galindo, Mattia Zago, Pantaleone Nespoli, Sergio López Bernal, Alberto Huertas Celdrán, Manuel Gil Pérez, José A. Ruipérez-Valiente, Gregorio Martínez Pérez, Félix Gómez Mármol |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2018 | Shielding IoT against Cyber-Attacks: An Event-Based Approach Using SIEMabstractDue to the growth of IoT (Internet of Things) devices in different industries and markets in recent years and considering the currently insufficient protection for these devices, a security solution safeguarding IoT architectures are highly desirable. An interesting perspective for the development of security solutions is the use of an event management approach, knowing that an event may become an incident when an information asset is affected under certain circumstances. The paper at hand proposes a security solution based on the management of security events within IoT scenarios in order to accurately identify suspicious activities. To this end, different vulnerabilities found in IoT devices are described, as well as unique features that make these devices an appealing target for attacks. Finally, three IoT attack scenarios are presented, describing exploited vulnerabilities, security events generated by the attack, and accurate responses that could be launched to help decreasing the impact of the attack on IoT devices. Our analysis demonstrates that the proposed approach is suitable for protecting the IoT ecosystem, giving an adequate protection level to the IoT devices. Daniel Díaz López, María Blanco Uribe, Claudia Santiago Cely, Andrés Vega Torres, Nicolás Moreno Guataquira, Stefany Morón Castro, Pantaleone Nespoli, Félix Gómez Mármol |
Wirel. Commun. Mob. Comput. | 7 |