EDBT 2026 Demo / reviewers in the wild / expert
David Garcia Rosado
dblp:27/6712
· DBLP profile ↗
19ranked-venue papers
11as first author
8since 2021 · last 2025
0000-0003-4613-5501ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 5 first-author · 5 since 2021Software engineering, systems software and programming languages · 4 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-authorComputer networks · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Design and Development of a Predictive Security Threat Management System Leveraging CWEs, CVEs, and CAPECsabstractOrganizations increasingly rely on digital platforms to support their operations, decision-making processes, and the delivery of critical services. This growing dependence has expanded their exposure to cyber threats that jeopardize the confidentiality, integrity, avail-ability, and operational continuity of information systems. This paper presents a system specifically designed to support the identi- fication and management of risks in technological infrastructures. The proposed solution collects vulnerability data daily from official sources and correlates it with the organization’s assets, enabling the prioritization of risks according to their criticality level. Further-more, the system integrates a prediction module based on machine learning techniques, capable of estimating the aggregated evolu- tion of risk for the following month. This predictive capability facilitates preventive decision-making and strengthens proactive cybersecurity risk management strategies. Joaquín Sierra-Granados, José L. Ruiz-Catalán, David Garcia Rosado, Manuel A. Serrano |
BDCAT | 3 |
| 2025 | Towards a sustainable cybersecurity framework for Agriculture 4.0 based on a systematic analysis of proposalsabstractThe world is currently experiencing a profound transformation driven by the convergence of disruptive technologies under the concept of Industry 4.0. These technologies have driven sectors such as agriculture to modernize and automate for greater sustainability, leading to what is now referred to as Agriculture 4.0 However, this transformation entails risks and requires new frameworks that address cybersecurity, sustainability, and knowledge reuse. In this paper, we conduct a systematic review of these new systems with the aim of identifying their main shortcomings and proposing a new framework. The review revealed a significant gap in comprehensively addressing cybersecurity, AI, and sustainability. This highlights the need for deeper exploration of how these elements interact to benefit the agricultural sector. To this end, we propose the development of the QUILLAQUA framework, oriented towards secure, intelligent, and sustainable agriculture, with a focus on fostering effective synergies among these crucial components. This framework integrates advanced technologies in cybersecurity, IoT, and AI to optimise the management of water and nutritional resources in hydroponic systems, ensuring sustainability and data security. This approach aims to enhance technological efficiency in agriculture. It also aims to foster greater awareness to tackle present and future challenges in sustainable agriculture. By doing so, it ensures a successful transition toward more digitized and secure agricultural practices. Diegof Bustamantev, Luis Enrique Sánchez Crespo, David Garcia Rosado, Antonio Santos-Olmo, Eduardo Fernández-Medina |
Comput. Secur. | 3 |
| 2025 | Integrated maritime protection: Innovation for the safeguarding of maritime systems based on MARISMAabstractThe maritime sector is becoming increasingly susceptible to sophisticated cyber-attacks, underscoring the pressing necessity for advanced research and development to establish robust safeguards for maritime assets. Although risk assessment methods for traditional IT systems are now highly developed, they are not directly applicable to risk assessment in maritime environments due to the specific characteristics and particularities of the latter. Therefore, there is an urgent need to define approaches that adequately support risk assessment in maritime environments. To contribute to this important challenge, we propose a novel risk analysis technique, specifically tailored for the maritime sector, based on MARISMA, a security management methodology, and eMARISMA, its cloud-based technological support tool. Our work contributes to the state of the art by defining the MARISMA-SHIPS maritime cybersecurity pattern, which includes a set of reusable and adaptable elements that enable risk management and control in a maritime environment, and is aligned with major international standards such as ENISA and NIST, as well as existing maritime regulations, becoming a key part of our ongoing POSEIDON maritime cybersecurity framework. A case study is presented for a ship developed in the main shipyard in Colombia, which shows how the reusability and adaptability of the proposal allows the proposed MARISMA-SHIPS pattern to be easily adapted to any maritime environment, and which allowed the identification of critical areas of cybersecurity that could be improved. The application of the process in the maritime domain has proven its value in improving the efficiency and security management of maritime assets. Ferney Martínez 0001, Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, David Garcia Rosado, Eduardo Fernández-Medina |
Comput. Secur. | 4 |
| 2024 | Towards an integrated risk analysis security framework according to a systematic analysis of existing proposalsabstractAbstract The information society depends increasingly on risk assessment and management systems as means to adequately protect its key information assets. The availability of these systems is now vital for the protection and evolution of companies. However, several factors have led to an increasing need for more accurate risk analysis approaches. These are: the speed at which technologies evolve, their global impact and the growing requirement for companies to collaborate. Risk analysis processes must consequently adapt to these new circumstances and new technological paradigms. The objective of this paper is, therefore, to present the results of an exhaustive analysis of the techniques and methods offered by the scientific community with the aim of identifying their main weaknesses and providing a new risk assessment and management process. This analysis was carried out using the systematic review protocol and found that these proposals do not fully meet these new needs. The paper also presents a summary of MARISMA, the risk analysis and management framework designed by our research group. The basis of our framework is the main existing risk standards and proposals, and it seeks to address the weaknesses found in these proposals. MARISMA is in a process of continuous improvement, as is being applied by customers in several European and American countries. It consists of a risk data management module, a methodology for its systematic application and a tool that automates the process. Antonio Santos-Olmo, Luis Enrique Sánchez Crespo, David Garcia Rosado, Manuel A. Serrano, Carlos Blanco 0001, Haralambos Mouratidis, Eduardo Fernández-Medina |
Frontiers Comput. Sci. | 3 |
| 2024 | Enabling security risk assessment and management for business process modelsabstractBusiness processes (BP) are considered the enterprise’s cornerstone but are increasingly in the spotlight of attacks. Therefore, the design of business processes must consider the security risks and be adequately integrated into the information and operational systems. However, security risk assessment and management are rarely considered at the level of business processes during design time, let alone considering a risk architecture that takes into account the connection and dependencies of risks at these levels of the organisation, business processes, and information systems. In general, most approaches deal with integrating new artefacts for business process models to support risk analysis, but sometimes, the notation can increase complexity, making it difficult to have a risk management tool to support the analysis. After analysing the current risk processes and frameworks, we have realised that they are often neglected when considering organisational and business process levels. In this paper, MARISMA-BP (MARISMA for Business Process) pattern is proposed, a security risk pattern to enable the assessment and management of risks for business process models. This approach is an artefact that has been validated in a real scenario following the design science methodology. Further, MARISMA-BP pattern is supported by eMARISMA, an automated infrastructure that allows the definition and reuse of each risk component, helping us to carry out the risk assessment and management process in an efficient and dynamic way. To demonstrate the applicability of the proposal, MARISMA-BP pattern is applied to a real health-based business process scenario. The findings illustrate the efficacy of MARISMA-BP within eMARISMA for comprehensive risk assessment and management, underscoring its versatility and practical relevance in any business process environment. David Garcia Rosado, Luis Enrique Sánchez Crespo, Angel Jesus Varela-Vaca, Antonio Santos-Olmo, María Teresa Gómez-López, Rafael M. Gasca, Eduardo Fernández-Medina |
J. Inf. Secur. Appl. | 1 |
| 2024 | Minimizing incident response time in real-world scenarios using quantum computingabstractAbstract The Information Security Management Systems (ISMS) are global and risk-driven processes that allow companies to develop their cybersecurity strategy by defining security policies, valuable assets, controls, and technologies for protecting their systems and information from threats and vulnerabilities. Despite the implementation of such management infrastructures, incidents or security breaches happen. Each incident has associated a level of severity and a set of mitigation controls, so in order to restore the ISMS, the appropriate set of controls to mitigate their damage must be selected. The time in which the ISMS is restored is a critical aspect. In this sense, classic solutions are efficient in resolving scenarios with a moderate number of incidents in a reasonable time, but the response time increases exponentially as the number of incidents increases. This makes classical solutions unsuitable for real scenarios in which a large number of incidents are handled and even less appropriate for scenarios in which security management is offered as a service to several companies. This paper proposes a solution to the incident response problem that acts in a minimal amount of time for real scenarios in which a large number of incidents are handled. It applies quantum computing, as a novel approach that is being successfully applied to real problems, which allows us to obtain solutions in a constant time regardless of the number of incidents handled. To validate the applicability and efficiency of our proposal, it has been applied to real cases using our framework (MARISMA). Manuel A. Serrano, Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, David Garcia Rosado, Carlos Blanco 0001, Vita Santa Barletta, Danilo Caivano, Eduardo Fernández-Medina |
Softw. Qual. J. | 4 |
| 2022 | Security policies by design in NoSQL document databasesabstractThe importance of data security is currently increasing owing to the number of data transactions that are continuously taking place. Large amounts of data are generated, stored, modified and transferred every second, signifying that databases require an appropriate capacity, control and protection that will enable them to maintain a secure environment for so much data. Big Data is becoming a prominent trend in our society, and increasing amounts of data, including sensitive and personal information, are being loaded into NoSQL and other Big Data technologies for analysis and processing. However, current security approaches do not take into account the special characteristics of these technologies, leaving sensitive and personal data unprotected and consequently risking considerable financial losses and brand damage. In this paper, we focus on NoSQL document databases and present a proposal for the design and implementation of security policies in this type of databases. We first follow the concept of security by design in order to propose a metamodel that allows the specification of both the structure and the security policies required for document databases. We also define an implementation model by analysing the implementation features provided by a specific NoSQL document database management system (MongoDB). Having obtained the design and implementation models, we follow the model-driven development philosophy and propose a set of transformation rules that allow the automatic generation of the final implementation of security policies. We additionally provide a technological solution in which the Eclipse Modelling Framework environment is employed in order to implement both the design metamodel (Emfatic) and the transformations (Epsilon, EGL). Finally, we apply the proposed framework to a case study carried out in the airport domain. This proposal, in addition to saving development time and costs, generates more robust solutions by considering security by design. This, therefore, abstracting the designer from both specific aspects of the target tool and having to choose the best strategies for the implementation of security policies. Carlos Blanco 0001, Diego García-Saiz, David Garcia Rosado, Antonio Santos-Olmo, Jesús Peral Cortés, Alejandro Maté, Juan Trujillo 0001, Eduardo Fernández-Medina |
J. Inf. Secur. Appl. | 3 |
| 2021 | MARISMA-BiDa pattern: Integrated risk analysis for big data
David Garcia Rosado, Julio Moreno, Luis Enrique Sánchez Crespo, Antonio Santos-Olmo, Manuel A. Serrano, Eduardo Fernández-Medina |
Comput. Secur. | 1 |
| 2015 | Special Issue on Secure Information Systems EngineeringabstractThe development of secure software and systems presents many challenges, as demonstrated by the high number of security weaknesses that are discovered in practice on a continuous basis. This has motivated a significant amount of work in the fields of security engineering and security software engineering, with corresponding technical, experimental and methodological contributions, as well as applications of the results in practice. Topics of particular current interest include work on security engineering, security models, security governance, standards, and controls, security ontology, security metrics, security in data warehouses, security and trust in service oriented architecture (SOA) and cloud computing [also in the context of service level agreements (SLAs)], privacy and security requirements, and information systems engineering security. A further important topic is data privacy and how to enforce it within the processing of information, for example, within a cloud environment. Also, the topic of model-based security analysis using the unified modelling language (UML) remains a topic of high current interest, as well as techniques for domain-specific security modelling and meta-modelling. This special issue of The Computer Journal therefore includes papers received from the public Call for Papers and extended and improved versions of those papers that were selected from the best of the International Workshop on Security in Information Systems (WOSIS, 2013) and International Workshop on Information Systems Security Engineering (WISSE, 2013). It aims to serve as a forum in which to unite academics, researchers, practitioners and students in the field of security engineering and security software engineering, by presenting technical, experimental, methodological and/or applicative contributions, and to promote the exchange of ideas, discussion and development in these areas. This special issue includes 10 papers of interest within the wide spectrum of research into the area of information systems security. Six of them have been selected as the best papers presented in the two workshops, and the remaining papers are from the public call. There is a predominance of theoretical papers, which are principally focused on security engineering, security models, security ontology, security metrics, security in data warehouses, security in SOA and cloud computing, privacy and security requirements, but there is also an important sample of papers which contribute to the area of information systems engineering security. A brief introduction to each of the papers selected is presented in the following paragraphs. The first contribution, ‘Privacy-Preserving Query Processing by Multi-Party Computation’, by M. Sepehri et al., addresses the problem of Privacy-Preserving Querying Partitioned (P3Q) databases. It first proposes a novel protocol called B-SMEQ to privately compute queries and then offers three techniques for selection, range and equi-join queries. These techniques are based on B-SMEQ. The demonstration of the protocol efficiency in term of computational and communication complexity has been performed through experimental tests executed on randomly generated large size databases. The second paper, entitled ‘Privacy as an Integral Part for the Implementation of Cloud Solutions’, by E. Kavakli et al., contributes to the existing literature through the identification of cloud-specific privacy properties and it advances the state of the art in privacy engineering for cloud computing. The authors introduce a number of implementation techniques that assure privacy properties in a cloud environment. The third contribution, ‘A Trust Evaluation Model for Cloud Computing using SLA’, by M. Dhanraj et al., presents a trust mining model to identify trusted cloud services while negotiating an SLA. The proposed trust model helps both the service provider and cloud user, where the user can make a decision on whether to continue or discontinue the service with the service provider. The fourth contribution, ‘ISGcloud: A Security Governance Framework for Cloud Computing’, by O. Rebollo et al., has the objective of introducing a comprehensive security governance framework (ISGcloud) with its focus on the cloud computing environment. Its four main processes are based on the ISO/IEC 38500 governance standard, and it also proposes a cloud service lifecycle based on the ISO/IEC 27036 security for supplier relationships standard. This proposal offers an overall methodology which guides organizations in the process of deploying a security governance structure during the entire cloud service lifecycle. The fifth paper, ‘A Discussion of Communication Schemes for Process Execution. Histories to Enforce Entailment Constraints in Process-Driven SOAs’, by T. Quirchmayr et al., investigates about different communication schemes for orchestration engines and for choreography engines and extends the informal discussion on the enforcement of entailment constraints in process-driven SOAs. The authors examine the efficiency of these schemes in case of omission failures occur. The sixth contribution, entitled ‘The Robust Measurement Method for Security Metrics Generation’, by K. Mazur et al., is focused on a new security measurement model that extends that presented in the ISO/IEC 27004 with the measurement validation methods. Through the verification of the gathered results, developed information security performance metrics provide a means for the monitoring, reporting, improving and assessing the effectiveness of the implemented security controls. The authors also present a case study of using the new proposed model for cryptographic modules and an implementation of the Crypto-Metrics Tool that is a benchmarking and results validation tool used for testing the performance of the cryptographic primitives. The seventh paper, entitled ‘Reference Ontology for Cybersecurity Operational Information’, by T. Takahashi et al., proposes a reference ontology for cybersecurity operational information in order to build a basis for cybersecurity information exchange on a global scale. The ontology structures cybersecurity information, orchestrates and collaborates with industry specifications, and thus facilitates the exchange of an assortment of cybersecurity information in different schemata. The authors also review existing industry specifications of cybersecurity information schemata by mapping the specifications for each of the information types defined by the ontology. The eighth contribution, ‘Modelling Security of Critical Infrastructures: A Survivability Assessment’, by R.J. Rodríguez et al., presents standard modelling techniques using UML profiling (namely, SecAM profile) plus formal models (namely, Generalized Stochastic Petri nets) are used to assess the security and survivability of critical infrastructures, normally targeted by malicious intended attacks. Thus, security properties specification and assessment are carried out during early phases (requirements, design) of system development life cycle. As case study, the survivability of the Saudi Arabia crude-oil network is evaluated under two different attack scenarios where the minimization of attack damages is quantitatively estimated. The ninth paper, entitled ‘An Integrated Security and Systems Engineering Process and Modelling Framework’, by J. Ruiz et al., studies the Integrated Security and System Engineering Process supports system engineers in integrating security in the development of their systems since the beginning of the design phase. The definition of the security knowledge is done in artefacts called Domain Security Metamodels, which specify the information and solutions of a specific domain (e.g. cloud, metering systems, etc.). The process is supported by a tool for MagicDraw that covers all the system's life cycle and helps system engineers in selecting and applying the security solutions that better fit their requirements. Finally, the 10th contribution, entitled ‘Modernizing Secure OLAP Applications with a Model Driven Approach’, by C. Blanco et al., is focused on the evolution problem of on-line analytical processing (OLAP) applications. It offers a reverse engineering approach that enables an automatic deduction of a conceptual model corresponding to a legacy OLAP application. This approach exhibits security aspects embedded in an OLAP application. It is built using an model-driven, architecture in order to facilitate the evolution of the resulting conceptual model. We would like to thank Prof. Fionn Murtagh (Editor-in-Chief), Dr Jutta Mackwell (Journal Manager) and Prof. Chris Mitchell (Section Editor) from The Computer Journal for their invaluable help and support, and for giving us the opportunity to edit this special issue. We are also extremely grateful for the hard work and kindness of all the members of our international program committee when performing their timely, complete and professional reviews. Last, but by no means least, we would like to thank the authors for their contributions. David Garcia Rosado, Nadira Lammari, Jan Jürjens |
Comput. J. | 1 |
| 2014 | Enterprise security pattern: a new type of security patternabstractABSTRACT In recent years, most organizations have suffered attacks against their information systems. For this reason, organizations should seek support from enterprise security architectures (ESAs) in order to secure their information assets. Security patterns can help when building complex ESAs, but they have some limitations that reduce their usability. In this paper, we define the metapattern of a new type of security pattern called Enterprise Security Pattern. This new metapattern provides a model‐driven environment and combines all elements that must be considered when designing and building ESAs. We present here a precise meta‐model and four diagrams to describe the metapattern of the enterprise security patterns. When avoiding a security problem, organizations could use enterprise security patterns to provide their designers with an optimal and proven security guideline and so standardize the design and building of the ESA for that problem. Enterprise security patterns could also facilitate the selection and tailoring of security policies, patterns, mechanisms, and technologies when a designer is building ESAs. To illustrate our ideas, we present an instance of this new type of pattern, showing how it can be used. Copyright © 2014 John Wiley & Sons, Ltd. Santiago Moral-García, Santiago Moral-Rubio, David Garcia Rosado, Eduardo B. Fernández, Eduardo Fernández-Medina |
Secur. Commun. Networks | 3 |
| 2011 | Systematic design of secure Mobile Grid systems
David Garcia Rosado, Eduardo Fernández-Medina, Javier López 0001, Mario Piattini |
J. Netw. Comput. Appl. | 1 |
| 2011 | Security services architecture for Secure Mobile Grid Systems
David Garcia Rosado, Eduardo Fernández-Medina, Javier López 0001 |
J. Syst. Archit. | 1 |
| 2010 | A Study of Security Approaches for the Development of Mobile Grid Systems
David Garcia Rosado, Eduardo Fernández-Medina, Javier López 0001 |
ICSOFT (1) | 1 |
| 2010 | Analysis of Secure Mobile Grid Systems: A systematic approach
David Garcia Rosado, Eduardo Fernández-Medina, Javier López 0001, Mario Piattini |
Inf. Softw. Technol. | 1 |
| 2009 | The practical application of a process for eliciting and designing security in web service systems
Carlos Gutiérrez, David Garcia Rosado, Eduardo Fernández-Medina |
Inf. Softw. Technol. | 2 |
| 2008 | PSecGCM: Process for the Development of Secure Grid Computing based Systems with Mobile DevicesabstractMobile Grid, in relevance to both Grid and Mobile Computing, is a full inheritor of Grid with the additional feature of supporting mobile users and resources in a seamless, transparent, secure and efficient way. Security of these systems, due to their distributed and open nature, receives great interest. A formal approach to security in the software life cycle is essential to protect corporate resources. However, little thought has been given to this aspect of software development. Due to its criticality, security should be integrated as a formal approach in the software life cycle. A methodology of development for secure mobile Grid computing based systems is defined, that is to say, an engineering process that defines the steps to follow so that starting from the necessities to solve, we can design and construct a secure Grid system with support for mobile devices that is able to solve and cover these necessities. David Garcia Rosado, Eduardo Fernández-Medina, Javier López 0001, Mario Piattini |
ARES | 1 |
| 2007 | Defining Security Architectural Patterns Based on Viewpoints
David Garcia Rosado, Carlos Gutiérrez, Eduardo Fernández-Medina, Mario Piattini |
ICCSA (3) | 1 |
| 2006 | A Study of Security Architectural PatternsabstractSecurity and reliability issues are rarely considered at the initial stages of software development and are not part of the standard procedures in development of software and services. Security patterns are a recent development as a way to encapsulate the accumulated knowledge about secure systems design, and security patterns are also intended to be used and understood by developers who are not security professionals. In this paper, we compare several security patterns to be used when dealing with application security, following an approach that we consider important for measuring the security degree of the patterns, and indicating a fulfilment or not of the properties and attributes common to all security systems. David Garcia Rosado, Eduardo Fernández-Medina, Mario Piattini, Carlos Gutiérrez |
ARES | 1 |
| 2006 | Defining Viewpoints for Security Architectural Patterns
David Garcia Rosado, Carlos Gutiérrez, Eduardo Fernández-Medina, Mario Piattini |
SECRYPT | 1 |