EDBT 2026 Demo / reviewers in the wild / expert
Cristóbal Arellano
dblp:58/354
· DBLP profile ↗
17ranked-venue papers
4as first author
3since 2021 · last 2024
0000-0001-7878-3306ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Databases, data management, data science and information retrieval · 12 · 3 first-authorSoftware engineering, systems software and programming languages · 7 · 2 first-authorSecurity and privacy · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Gotham Testbed: A Reproducible IoT Testbed for Security Experiments and Dataset GenerationabstractThe growing adoption of the Internet of Things (IoT) has brought a significant increase in attacks targeting those devices. Machine learning (ML) methods have shown promising results for intrusion detection; however, the scarcity of IoT datasets remains a limiting factor in developing ML-based security systems for IoT scenarios. Static datasets get outdated due to evolving IoT architectures and threat landscape; meanwhile, the testbeds used to generate them are rarely published. This paper presents the Gotham testbed, a reproducible and flexible security testbed extendable to accommodate new emulated devices, services or attackers. Gotham is used to build an IoT scenario composed of 100 emulated devices communicating via MQTT, CoAP and RTSP protocols, among others, in a topology composed of 30 switches and 10 routers. The scenario presents three threat actors, including the entire Mirai botnet lifecycle and additional red-teaming tools performing DoS, scanning, and attacks targeting IoT protocols. The testbed has many purposes, including a cyber range, testing security solutions, and capturing network and application data to generate datasets. We hope that researchers can leverage and adapt Gotham to include other devices, state-of-the-art attacks and topologies to share scenarios and datasets that reflect the current IoT settings and threat landscape. Xabier Sáez de Cámara, Jose Luis Flores 0001, Cristóbal Arellano, Aitor Urbieta, Urko Zurutuza |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | Federated Explainability for Network Anomaly CharacterizationabstractMachine learning (ML) based systems have shown promising results for intrusion detection due to their ability to learn complex patterns. In particular, unsupervised anomaly detection approaches offer practical advantages as does not require labeling the training data, which is costly and time-consuming. To further address practical concerns, there is a rising interest in adopting federated learning (FL) techniques as a recent ML model training paradigm for distributed settings (e.g., IoT), thereby addressing challenges such as data privacy, availability and communication cost concerns. However, output generated by unsupervised models provide limited contextual information to security analysts at SOCs, as they usually lack the means to know why a sample was classified as anomalous or cannot distinguish between different types of anomalies, difficulting the extraction of actionable information and correlation with other indicators. Moreover, ML explainability methods have received little attention in FL settings and present additional challenges due to the distributed nature and data locality requirements. This paper proposes a new methodology to characterize and explain the anomalies detected by unsupervised ML-based intrusion detection models in FL settings. We adapt and develop explainability, clustering and cluster validation algorithms to FL settings to mine patterns in the anomalous samples and identify different threats throughout the entire network, demonstrating the results on two network intrusion detection datasets containing real IoT malware, namely Gafgyt and Mirai, and various attack traces. The learned clustering results can be used to classify emerging anomalies, provide additional context that can be leveraged to gain more insight and enable the correlation of the anomalies with alerts triggered by other security solutions. Xabier Sáez de Cámara, Jose Luis Flores 0001, Cristóbal Arellano, Aitor Urbieta, Urko Zurutuza |
RAID | 3 |
| 2023 | Clustered federated learning architecture for network anomaly detection in large scale heterogeneous IoT networksabstractThere is a growing trend of cyberattacks against Internet of Things (IoT) devices; moreover, the sophistication and motivation of those attacks is increasing. The vast scale of IoT, diverse hardware and software, and being typically placed in uncontrolled environments make traditional IT security mechanisms such as signature-based intrusion detection and prevention systems challenging to integrate. They also struggle to cope with the rapidly evolving IoT threat landscape due to long delays between the analysis and publication of the detection rules. Machine learning methods have shown faster response to emerging threats; however, model training architectures like cloud or edge computing face multiple drawbacks in IoT settings, including network overhead and data isolation arising from the large scale and heterogeneity that characterizes these networks. This work presents an architecture for training unsupervised models for network intrusion detection in large, distributed IoT and Industrial IoT (IIoT) deployments. We leverage Federated Learning (FL) to collaboratively train between peers and reduce isolation and network overhead problems. We build upon it to include an unsupervised device clustering algorithm fully integrated into the FL pipeline to address the heterogeneity issues that arise in FL settings. The architecture is implemented and evaluated using a testbed that includes various emulated IoT/IIoT devices and attackers interacting in a complex network topology comprising 100 emulated devices, 30 switches and 10 routers. The anomaly detection models are evaluated on real attacks performed by the testbed’s threat actors, including the entire Mirai malware lifecycle, an additional botnet based on the Merlin command and control server and other red-teaming tools performing scanning activities and multiple attacks targeting the emulated devices. Xabier Sáez de Cámara, Jose Luis Flores 0001, Cristóbal Arellano, Aitor Urbieta, Urko Zurutuza |
Comput. Secur. | 3 |
| 2018 | Model-Based Personalized Visualization System for Monitoring Evolving Industrial Cyber-Physical SystemabstractMonitoring Industrial Cyber-Physical Systems (ICPSs) is increasingly becoming essential, which requires the development of new approaches to capture data from an ICPS for visualization, automated analyses, decision making, and anomaly detection. Towards this end, first, we present requirements for enabling personalized data visualization for monitoring evolving ICPS during its operation. Such requirements were identified from our experience of designing and developing an industrial Automated Warehouse (AW). Second, the identified requirements were validated with a questionnaire-based survey by soliciting views of industry experts from the Software Monitoring Systems and Data Visualizations domains. Based on the analysis of the survey results, the need of developing personalized ICPS monitoring systems was confirmed as a step forward to enable the efficient detection of anomalies, improvement in productivity, and providing a better overview of the monitored ICPSs. Third, we developed a model-based visualization system (named as PAVS) for monitoring ICPSs, which conforms to the identified requirements, and was validated it with a dataset collected from a real AW developed by our industrial partner: ULMA Handling System, Spain. In the end, we also provide a set of lessons learned when PAVS was transferred to ULMA. Aitziber Iglesias, Tao Yue 0002, Cristóbal Arellano, Shaukat Ali 0001, Goiuria Sagardui Mendieta |
APSEC | 3 |
| 2015 | Editing Anxiety in Corporate Wikis: From Private Drafting to Public Edits
Cristóbal Arellano, Oscar Díaz 0001, Maider Azanza |
CAiSE | 1 |
| 2015 | The Augmented Web: Rationales, Opportunities, and Challenges on Browser-Side TranscodingabstractToday’s web personalization technologies use approaches like user categorization, configuration, and customization but do not fully support individualized requirements. As a significant portion of our social and working interactions are migrating to the web, we can expect an increase in these kinds of minority requirements. Browser-side transcoding holds the promise of facilitating this aim by opening personalization to third parties through web augmentation (WA), realized in terms of extensions and userscripts. WA is to the web what augmented reality is to the physical world: to layer relevant content/layout/navigation over the existing web to improve the user experience. From this perspective, WA is not as powerful as web personalization since its scope is limited to the surface of the web. However, it permits this surface to be tuned by developers other than the sites’ webmasters. This opens up the web to third parties who might come up with imaginative ways of adapting the web surface for their own purposes. Its success is backed up by millions of downloads. This work looks at this phenomenon, delving into the “what,” the “why,” and the “what for” of WA, and surveys the challenges ahead for WA to thrive. To this end, we appraise the most downloaded 45 WA extensions for Mozilla Firefox and Google Chrome as well as conduct a systematic literature review to identify what quality issues received the most attention in the literature. The aim is to raise awareness about WA as a key enabler of the personal web and point out research directions. Oscar Díaz 0001, Cristóbal Arellano |
ACM Trans. Web | 2 |
| 2014 | End-User Browser-Side Modification of Web Pages
Oscar Díaz 0001, Cristóbal Arellano, Iñigo Aldalur, Haritz Medina, Sergio Firmenich |
WISE (1) | 2 |
| 2013 | A language for end-user web augmentation: Caring for producers and consumers alikeabstractWeb augmentation is to the Web what augmented reality is to the physical world: layering relevant content/layout/navigation over the existing Web to customize the user experience. This is achieved through JavaScript (JS) using browser weavers (e.g., Greasemonkey). To date, over 43 million of downloads of Greasemonkey scripts ground the vitality of this movement. However, Web augmentation is hindered by being programming intensive and prone to malware. This prevents end-users from participating as both producers and consumers of scripts: producers need to know JS, consumers need to trust JS. This article aims at promoting end-user participation in both roles. The vision is for end-users to prosume (the act of simultaneously caring for producing and consuming) scripts as easily as they currently prosume their pictures or videos. Encouraging production requires more “natural” and abstract constructs. Promoting consumption calls for augmentation scripts to be easier to understand, share, and trust upon. To this end, we explore the use of Domain-Specific Languages (DSLs) by introducing Sticklet . Sticklet is an internal DSL on JS, where JS generality is reduced for the sake of learnability and reliability. Specifically, Web augmentation is conceived as fixing in existing web sites (i.e., the wall ) HTML fragments extracted from either other sites or Web services (i.e., the stickers ). Sticklet targets hobby programmers as producers, and computer literates as consumers. From a producer perspective, benefits are threefold. As a restricted grammar on top of JS, Sticklet expressions are domain oriented and more declarative than their JS counterparts, hence speeding up development. As syntactically correct JS expressions, Sticklet scripts can be installed as traditional scripts and hence, programmers can continue using existing JS tools. As declarative expressions, they are easier to maintain, and amenable for optimization. From a consumer perspective, domain specificity brings understandability (due to declarativeness), reliability (due to built-in security), and “consumability” (i.e., installation/enactment/sharing of Sticklet expressions are tuned to the shortage of time and skills of the target audience). Preliminary evaluations indicate that 77% of the subjects were able to develop new Sticklet scripts in less than thirty minutes while 84% were able to consume these scripts in less than ten minutes. Sticklet is available to download as a Mozilla add-on. Oscar Díaz 0001, Cristóbal Arellano, Maider Azanza |
ACM Trans. Web | 2 |
| 2012 | Opening Personalization to Partners: An Architecture of Participation for Websites
Cristóbal Arellano, Oscar Díaz 0001, Jon Iturrioz |
ICWE | 1 |
| 2012 | Sticklet: An End-User Client-Side Augmentation-Based Mashup Tool
Oscar Díaz 0001, Cristóbal Arellano |
ICWE | 2 |
| 2012 | Web-Based Tool Integration: A Web Augmentation Approach
Oscar Díaz 0001, Josune De Sosa, Cristóbal Arellano, Salvador Trujillo |
ICWE | 3 |
| 2010 | Interfaces for Scripting: Making Greasemonkey Scripts Resilient to Website Upgrades
Oscar Díaz 0001, Cristóbal Arellano, Jon Iturrioz |
ICWE | 2 |
| 2010 | Crowdsourced Web Augmentation: A Security Model
Cristóbal Arellano, Oscar Díaz 0001, Jon Iturrioz |
WISE | 1 |
| 2009 | Tagging-Aware Portlets
Oscar Díaz 0001, Sandy Pérez, Cristóbal Arellano |
ICWE | 3 |
| 2009 | Facing Tagging Data Scattering
Oscar Díaz 0001, Jon Iturrioz, Cristóbal Arellano |
WISE | 3 |
| 2008 | Layman tuning of websites: facing change resilienceabstractClient scripting permits end users to customize content, layout or style of their favourite websites. But current scripting suffers from a tight coupling with the website. If the page changes, all the scripting can fall apart. The problem is that websites are reckoned to evolve frequently, and this can jeopardize all the scripting efforts. To avoid this situation, this work enriches websites with a "modding interface" in an attempt to decouple layman's script from website upgrades. From the website viewpoint, this interface ensures safe scripting, i.e. scripts that do not break the page. From a scripter perspective, this interface limits tuning but increases change resilience. The approach tries to find a balance between openness (scripter free inspection) and modularity (scripter isolation from website design decisions) that permits scripting to scale up as a mature software practice. The approach is realized for Greasemonkey scripts. Oscar Díaz 0001, Cristóbal Arellano, Jon Iturrioz |
WWW | 2 |
| 2006 | Elkar-CM: a Multilingual Collaborative Concept Map EditorabstractAlong this paper Elkar-CM, a multilingual collaborative concept map editor is presented. The paper starts explaining the main characteristics of CM-ED, the kernel in which Elkar-CM is based on. Next, the paper describes the main characteristics and functionalities offered by Elkar-CM. Finally some conclusions are pointed out Cristóbal Arellano, Urko Rueda, Ianire Niebla, Mikel Larrañaga, Ana Arruarte Lasa, Jon A. Elorriaga |
ICALT | 1 |