Igor Santos

dblp:49/4967 · also Igor Santos-Grueiro · DBLP profile ↗
← Back
38ranked-venue papers
8as first author
1since 2021 · last 2025
0000-0002-9511-8612ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 16 · 3 first-authorArtificial intelligence and machine learning · 9 · 3 first-authorDatabases, data management, data science and information retrieval · 9 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 3Graphics, computer vision, multimedia, augmented reality and games · 2Systems, architecture and hardware · 1Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1Human-computer interaction and ubiquitous computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
6 papers
Web and mobile security · 50% Network security · 18% Privacy and data protection · 12%
Human-computer interaction and pervasive computing
1 paper
Usability and user experience research · 100%

Topics — the 9 heaviest of 15, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Web and mobile security
web security
0.912025
A Permissions Odyssey: A Systematic Study of Browser Permissions on Modern Websites · IMC 2025
Network security › traffic analysis
device fingerprinting
0.312018
Clock Around the Clock: Time-Based Device Fingerprinting · CCS 2018
Privacy and data protection
web tracking
0.312018
Clock Around the Clock: Time-Based Device Fingerprinting · CCS 2018
Network security
anonymity networks
0.312017
The Onions Have Eyes: A Comprehensive Structure and Privacy Analysis of Tor Hidden Services · WWW 2017
Web and mobile security › browser security
browser extension security
0.312017
Extension Breakdown: Security Analysis of Browsers Extension Resources Control Policies · USENIX Security Symposium 2017
Network security › anonymity networks › tor
tor hidden services
0.312017
The Onions Have Eyes: A Comprehensive Structure and Privacy Analysis of Tor Hidden Services · WWW 2017
Systems and software security › software supply chain security
supply chain attacks
0.312025
A Permissions Odyssey: A Systematic Study of Browser Permissions on Modern Websites · IMC 2025
Web and mobile security
browser security
0.112017
Extension Breakdown: Security Analysis of Browsers Extension Resources Control Policies · USENIX Security Symposium 2017
Malware analysis
malware obfuscation
0.112015
SoK: Deep Packer Inspection: A Longitudinal Study of the Complexity of Run-Time Packers · IEEE Symposium on Security and Privacy 2015

Methods — techniques the papers use, named apart from their topics

web measurement · 0.9user study · 0.9structural analysis · 0.6privacy measurement · 0.6security analysis · 0.3dynamic analysis · 0.2
YearPublicationVenuePosition
2025 A Permissions Odyssey: A Systematic Study of Browser Permissions on Modern Websites
abstract
Modern websites behave like OS-native applications and use powerful APIs, such as camera or microphone.To ensure that untrusted third-party components, such as ads, cannot abuse powerful features granted to web applications, these features are governed via a permission system: containing the Permissions-Policy header and iframe allow attribute.Even though the first versions of the permission system were implemented when browsers first allowed access to powerful features more than ten years ago, it is unclear if and how websites are using the permission system.To answer these questions, we systematically measured the permission ecosystem across the top 1,000,000 websites.Our results show that 48.52% of visited websites exhibit permissionrelated functionality, and 12.07% of websites delegate permissions to embedded iframes using the allow attribute.Out of these delegations, many appear overly broad and unused by the iframe, posing a threat in the context of supply chain attacks.Additionally, only 4.5% websites use the Permissions-Policy header, and the primary use case is to turn off powerful APIs such as a camera entirely.Finally, we developed open-source tools to help developers deploy the correct Permission-Policy header and iframe allow attributes following the principle of least privilege. CCS Concepts• Security and privacy → Privacy protections
Alberto Fernández de Retana, Jannis Rautenstrauch, Igor Santos, Ben Stock
IMC3
2020 Dirty Clicks: A Study of the Usability and Security Implications of Click-related Behaviors on the Web
abstract
Web pages have evolved into very complex dynamic applications, which are often very opaque and difficult for non-experts to understand. At the same time, security researchers push for more transparent web applications, which can help users in taking important security-related decisions about which information to disclose, which link to visit, and which online service to trust.
Iskander Sánchez-Rola, Davide Balzarotti, Christopher Krügel, Giovanni Vigna, Igor Santos
WWW5
2019 BakingTimer: privacy analysis of server-side request processing time
abstract
Cookies were originally introduced as a way to provide state awareness to websites, and are now one of the backbones of the current web. However, their use is not limited to store the login information or to save the current state of user browsing. In several cases, third-party cookies are deliberately used for web tracking, user analytics, and for online advertisement, with the subsequent privacy loss for the end users.
Iskander Sánchez-Rola, Davide Balzarotti, Igor Santos
ACSAC3
2019 Can I Opt Out Yet?: GDPR and the Global Illusion of Cookie Control
abstract
The European Union's (EU) General Data Protection Regulation (GDPR), in effect since May 2018, enforces strict limitations on handling users' personal data, hence impacting their activity tracking on the Web. In this study, we perform an evaluation of the tracking performed in 2,000 high-traffic websites, hosted both inside and outside of the EU. We evaluate both the information presented to users and the actual tracking implemented through cookies; we find that the GDPR has impacted website behavior in a truly global way, both directly and indirectly: USA-based websites behave similarly to EU-based ones, while third-party opt-out services reduce the amount of tracking even for websites which do not put any effort in respecting the new law. On the other hand, we find that tracking remains ubiquitous. In particular, we found cookies that can identify users when visiting more than 90% of the websites in our dataset - and we also encountered a large number of websites that present deceiving information, making it it very difficult, if at all possible, for users to avoid being tracked.
Iskander Sánchez-Rola, Matteo Dell'Amico, Platon Kotzias, Davide Balzarotti, Leyla Bilge, Pierre-Antoine Vervier, Igor Santos
AsiaCCS7
2019 Special issue HAIS 2015: Recent advancements in hybrid artificial intelligence systems and its application to real-world problems
Pablo García Bringas, Igor Santos, Enrique Onieva, Eneko Osaba, Héctor Quintián, Emilio Corchado
Neurocomputing2
2018 Clock Around the Clock: Time-Based Device Fingerprinting
abstract
Physical device fingerprinting exploits hardware features to uniquely identify a machine. This technique has been used for authentication, license binding, or attackers identification, among other tasks. More recently, hardware features have also been introduced to identify web users and perform web tracking. A particular type of hardware fingerprint exploits differences in the computer internal clock signals. However, previous methods to test for these differences relied on complex experiments performed by running native code in the target machine. In this paper, we show a new way to compute a hardware finger- printing, based on timing the execution of sequences of instructions readily available in API functions. Due to its simplicity, this method can also be performed remotely by simply timing few seemingly innocuous lines of JavaScript code. We tested our approach with different functions, such as common string manipulation or widespread cryptographic routines, and found that several of them can be used as basic blocks for fingerprinting. Using this technique, we implemented a tool called CryptoFP. We tested its native implementation in a homogeneous scenario, to distinguish among a perfectly identical (both in software and hardware) set of computers. CryptoFP was able to correctly discriminate all the identical computers in this scenario and recognize the same computer also under different CPU load configurations, outperforming every other hardware fingerprinting method. We then show how CryptoFP can be implemented using a combination of the HTML5 Cryptography API and standard timing API for web device fingerprinting. In this case, we compared our method, both in the same homogeneous scenario and by performing an experiment with real-world users running heterogeneous devices, against other state-of-the-art web device fingerprinting solutions. In both cases, our approach clearly outperforms all existing methods.
Iskander Sánchez-Rola, Igor Santos, Davide Balzarotti
CCS2
2018 Knockin' on Trackers' Door: Large-Scale Automatic Analysis of Web Tracking
Iskander Sánchez-Rola, Igor Santos
DIMVA2
2017 Extension Breakdown: Security Analysis of Browsers Extension Resources Control Policies
Iskander Sánchez-Rola, Igor Santos, Davide Balzarotti
USENIX Security Symposium2
2017 The Onions Have Eyes: A Comprehensive Structure and Privacy Analysis of Tor Hidden Services
abstract
Tor is a well known and widely used darknet, known for its anonymity. However, while its protocol and relay security have already been extensively studied, to date there is no comprehensive analysis of the structure and privacy of its Web Hidden Service.
Iskander Sánchez-Rola, Davide Balzarotti, Igor Santos
WWW3
2016 RAMBO: Run-Time Packer Analysis with Multiple Branch Observation
Xabier Ugarte-Pedrero, Davide Balzarotti, Igor Santos, Pablo García Bringas
DIMVA3
2016 Text normalization and semantic indexing to enhance Instant Messaging and SMS spam filtering
Tiago A. Almeida 0001, Tiago P. Silva, Igor Santos, José María Gómez Hidalgo
Knowl. Based Syst.3
2015 SoK: Deep Packer Inspection: A Longitudinal Study of the Complexity of Run-Time Packers
abstract
Run-time packers are often used by malware-writers to obfuscate their code and hinder static analysis. The packer problem has been widely studied, and several solutions have been proposed in order to generically unpack protected binaries. Nevertheless, these solutions commonly rely on a number of assumptions that may not necessarily reflect the reality of the packers used in the wild. Moreover, previous solutions fail to provide useful information about the structure of the packer or its complexity. In this paper, we describe a framework for packer analysis and we propose a taxonomy to measure the runtime complexity of packers. We evaluated our dynamic analysis system on two datasets, composed of both off-the-shelf packers and custom packed binaries. Based on the results of our experiments, we present several statistics about the packers complexity and their evolution over time.
Xabier Ugarte-Pedrero, Davide Balzarotti, Igor Santos, Pablo García Bringas
IEEE Symposium on Security and Privacy3
2014 Procedural Playable Cave Systems Based on Voronoi Diagram and Delaunay Triangulation
abstract
The volumetric approach for terrain representation is a technique used by several video-games and other graphic applications to manage both surface and geological data from the virtual world. To enhance the exploration experience and due to the amount of data required by this approach, volumetric terrains are usually generated with procedural methods. Nevertheless, one of the main issues of those methods is the generation of cave systems with playable features and a natural appearance. In this paper we propose a new method to generate playable cave systems for 2D and 3D volumetric terrains, based on Voronoi diagrams and Delaunay triangulations. Our approach is completely customizable by the designer by a set of parameters directly related to the cave itself avoiding technical concepts. Additionally, the method runs in a completely independent way, with no interactive steps.
Aitor Santamaría-Ibirika, Xabier Cantero, Sergio Huerta, Igor Santos, Pablo García Bringas
CW4
2014 On the adoption of anomaly detection for packed executable filtering
Xabier Ugarte-Pedrero, Igor Santos, Iván García-Ferreira, Sergio Huerta, Borja Sanz 0001, Pablo García Bringas
Comput. Secur.2
2014 Study on the effectiveness of anomaly detection for spam filtering
Carlos Laorden, Xabier Ugarte-Pedrero, Igor Santos, Borja Sanz 0001, Javier Nieves, Pablo García Bringas
Inf. Sci.3
2014 Procedural approach to volumetric terrain generation
Aitor Santamaría-Ibirika, Xabier Cantero, Mikel Salazar, Jaime Devesa, Igor Santos, Sergio Huerta, Pablo García Bringas
Vis. Comput.5
2013 JURD: Joiner of Un-Readable Documents to reverse tokenization attacks to content-based spam filters
abstract
Spam has become a major issue in computer security because it is a channel for threats such as computer viruses, worms and phishing. More than 85% of received e-mails are spam. Historical approaches to combating these messages, including simple techniques like sender blacklisting or the use of e-mail signatures, are no longer completely reliable. Many current solutions feature machine-learning algorithms trained using statistical representations of the terms that most commonly appear in such e-mails. However, there are attacks that can subvert the filtering capabilities of these methods. Tokenization attacks, in particular, insert characters that create divisions within words, causing incorrect representations of e-mails. In this paper, we introduce a new method that reverses the effects of tokenization attacks. Our method processes e-mails iteratively by considering possible words, starting from the first token and compares the word candidates with a common dictionary to which spam words have been previously added. We provide an empirical study of how tokenization attacks affect the filtering capability of a Bayesian classifier and we show that our method can reverse the effects of tokenization attacks.
Igor Santos, Carlos Laorden, Borja Sanz 0001, Pablo García Bringas
CCNC1
2013 MADS: Malicious Android Applications Detection through String Analysis
Borja Sanz 0001, Igor Santos, Javier Nieves, Carlos Laorden, Iñigo Alonso 0001, Pablo García Bringas
NSS2
2013 Filtering Trolling Comments through Collective Classification
Jorge de-la-Peña-Sordo, Igor Santos, Iker Pastor-López, Pablo García Bringas
NSS2
2013 Instance-based Anomaly Method for Android Malware Detection
Borja Sanz 0001, Igor Santos, Xabier Ugarte-Pedrero, Carlos Laorden, Javier Nieves, Pablo García Bringas
SECRYPT2
2013 Mama: manifest Analysis for Malware Detection in Android
abstract
The use of mobile phones has increased because they offer nearly the same functionality as a personal computer. In addition, the number of applications available for Android-based mobile devices has increased. Google offers programmers the opportunity to upload and sell applications in the Android Market, but malware writers upload their malicious code there. In light of this background, we present here manifest analysis for malware detection in Android (MAMA), a new method that extracts several features from the Android manifest of the applications to build machine learning classifiers and detect malware.
Borja Sanz 0001, Igor Santos, Carlos Laorden, Xabier Ugarte-Pedrero, Javier Nieves, Pablo García Bringas, Gonzalo Álvarez
Cybern. Syst.2
2013 Opcode sequences as representation of executables for data-mining-based unknown malware detection
Igor Santos, Felix Brezo, Xabier Ugarte-Pedrero, Pablo García Bringas
Inf. Sci.1
2012 On the study of anomaly-based spam filtering using spam as representation of normality
abstract
In previous work, we presented the first spam filtering method based on anomaly detection that reduces the necessity of labelling spam messages and only employs the representation of legitimate e-mails. This method achieved high accuracy rates detecting spam while maintaining a low false positive rate and reducing the effort produced by labelling spam. In this paper, we study the performance of our previous method when using spam messages to represent normality.
Carlos Laorden, Xabier Ugarte-Pedrero, Igor Santos, Borja Sanz 0001, Javier Nieves, Pablo García Bringas
CCNC3
2012 On the automatic categorisation of android applications
abstract
The presence of mobile devices has increased in our lives offering almost the same functionality as a personal computer. Android devices have appeared lately and, since then, the number of applications available for this operating system have increased exponentially. Google already has its Android Market where applications are offered and, as happens with every popular media, is prone to misuse. A malware writer may insert a malicious application into this market without being noticed. Indeed, there are already several cases of Android malware within the Android Market. Therefore, an approach that can automatically characterise the different types of applications can be helpful for both organising the Android Market and detecting fraudulent or malicious applications. In this paper, we propose a new method for categorising Android applications through machine-learning techniques. To represent each application, our method extracts different feature sets: (i) the frequency of occurrence of the printable strings, (ii) the different permissions of the application itself and (iii) the permissions of the application extracted from the Android Market. We evaluate this approach of automatically categorisation of Android applications and show that achieves a high performance.
Borja Sanz 0001, Igor Santos, Carlos Laorden, Xabier Ugarte-Pedrero, Pablo García Bringas
CCNC2
2012 Countering entropy measure attacks on packed software detection
abstract
Malware writers usually employ several techniques to evade detection. For the last years, the number of variants detected each day has increased significantly. Traditional approaches such as signature scanning, one of the most common techniques employed by anti-virus companies, are becoming inefficient for the high amount of samples found in the wild. In order to bypass this kind of filters, malware writers usually obfuscate and transform the code of their creations. One of the methods employed is executable packing, which consists in compressing or ciphering the real malicious code, and injecting a decryption routine into the executable that will load and decompress it at run-time. Entropy is a common heuristic for the detection of packed executables. High entropy values indicate a random distribution of the bytes that compose the executable, a property very common in compressed and ciphered data. Unfortunately, this entropy measure can be altered by different techniques that modify randomness. In this paper, we detail various attacks found on real Zeus family samples, one of the most powerful and spread malware families at this moment, which are protected by custom made packers. In addition, we describe a method for obtaining an alternative entropy measure more resilient to these techniques, and evaluate it for the classification of packed/not-packed executables, obtaining satisfactory detection and false positive rates.
Xabier Ugarte-Pedrero, Igor Santos, Borja Sanz 0001, Carlos Laorden, Pablo García Bringas
CCNC2
2012 Supervised classification of packets coming from a HTTP botnet
abstract
The posibilities that the management of a vast amount of computers and/or networks offer, is attracting an increasing number of malware writers. In this document, the authors propose a methodology thought to detect malicious botnet traffic, based on the analysis of the packets flow that circulate in the network. This objective is achieved by means of the parametrization of the static characteristics of packets, which are lately analysed using supervised machine learning techniques focused on traffic labelling so as to face proactively to the huge volume of information nowadays filters work with.
Felix Brezo, José Gaviria de la Puerta, Xabier Ugarte-Pedrero, Igor Santos, Pablo García Bringas, David Barroso
CLEI4
2012 Combination of Machine-Learning Algorithms for Fault Prediction in High-Precision Foundries
Javier Nieves, Igor Santos, Pablo García Bringas
DEXA (2)2
2012 Enhanced Topic-based Vector Space Model for semantics-aware spam filtering
Igor Santos, Carlos Laorden, Borja Sanz 0001, Pablo García Bringas
Expert Syst. Appl.1
2012 Automatic categorisation of comments in social news websites
Igor Santos, Jorge de-la-Peña-Sordo, Iker Pastor-López, Patxi Galán-García, Pablo García Bringas
Expert Syst. Appl.1
2011 Boosting Scalability in Anomaly-Based Packed Executable Filtering
Xabier Ugarte-Pedrero, Igor Santos, Pablo García Bringas
Inscrypt2
2011 Anomaly Detection for the Prediction of Ultimate Tensile Strength in Iron Casting Production
Igor Santos, Javier Nieves, Xabier Ugarte-Pedrero, Pablo García Bringas
DEXA (2)1
2011 Semi-supervised learning for packed executable detection
abstract
The term malware is coined to name any software with malicious intentions. One of the methods malware writers use for hiding their creations is executable packing. Packing consists of encrypting or hiding the real code of the executable in such a way that it is decrypted or unhidden in its execution. Widespread solutions to this issue first try to identify the packer used and next apply the corresponding unpacking routine for each packing algorithm. As it happens with malware obfuscations, this approach fails to detect new and custom packers. Generic unpacking is a technique that has been proposed to solve this issue. These methods usually execute the binary in a contained environment or sandbox to retrieve the real code of the packed executable. Because these approaches incur in a high performance overhead, a filter step is required to determine whether an executable is packed or not. Supervised machine-learning approaches have been proposed to handle this filtering step. However, the usefulness of supervised learning is far to be complete because it requires a high amount of packed and not packed executables to be identified and labelled previously. In this paper, we propose a new method for packed executable detection that adopts a well-known semi-supervised learning approach to reduce the labelling requirements of completely supervised approaches. We performed an empirical validation demonstrating that the labelling efforts are lower than when supervised learning is used while the system maintains high accuracy rates.
Xabier Ugarte-Pedrero, Igor Santos, Pablo García Bringas, Mikel Gastesi, José Miguel Esparza
NSS2
2011 Collective Classification for Unknown Malware Detection
Igor Santos, Carlos Laorden, Pablo García Bringas
SECRYPT1
2011 Anomaly-based Spam Filtering
Igor Santos, Carlos Laorden, Xabier Ugarte-Pedrero, Borja Sanz 0001, Pablo García Bringas
SECRYPT1
2011 Using opcode sequences in single-class learning to detect unknown malware
abstract
Malware is any type of malicious code that has the potential to harm a computer or network. The volume of malware is growing at a faster rate every year and poses a serious global security threat. Although signature-based detection is the most widespread method used in commercial antivirus programs, it consistently fails to detect new malware. Supervised machine-learning models have been used to address this issue. However, the use of supervised learning is limited because it needs a large amount of malicious code and benign software to be labelled first. In this study, the authors propose a new method that uses single-class learning to detect unknown malware families. This method is based on examining the frequencies of the appearance of opcode sequences to build a machine-learning classifier using only one set of labelled instances within a specific class of either malware or legitimate software. The authors performed an empirical study that shows that this method can reduce the effort of labelling software while maintaining high accuracy.
Igor Santos, Felix Brezo, Borja Sanz 0001, Carlos Laorden, Pablo García Bringas
IET Inf. Secur.1
2010 Automatic Morphological Categorisation of Carbon Black Nano-aggregates
Juan López-de-Uralde, Iraide Ruiz, Igor Santos, Agustín Zubillaga, Pablo García Bringas, Ana Okariz, Teresa Guraya
DEXA (2)3
2010 Enhanced Foundry Production Control
Javier Nieves, Igor Santos, Yoseba K. Penya, Felix Brezo, Pablo García Bringas
DEXA (1)2
2009 Mechanical properties prediction in high-precision foundry production
abstract
Mechanical properties are the attributes of a metal to withstand several forces and tensions. Specifically, ultimate tensile strength is the force a material can resist until it breaks. The only way to examine this mechanical property is the employment of destructive inspections that renders the casting invalid with the subsequent cost increment. In a previous work we showed that modelling the foundry process as a probabilistic constellation of interrelated variables allows Bayesian networks to infer causal relationships. In other words, they may guess the value of a variable (for instance, the value of ultimate tensile strength). Against this background, we present here the first ultimate tensile strength prediction system that, upon the basis of a Bayesian network, is able to foresee the values of this property in order to correct it before the casting is made. Further, we have tested the accuracy and error rate of the system with data of a real foundry.
Javier Nieves, Igor Santos, Yoseba K. Penya, Sendoa Rojas-Lertxundi, Mikel Salazar, Pablo García Bringas
INDIN2