EDBT 2026 Demo / reviewers in the wild / expert
Urko Zurutuza
dblp:59/5122 · also Urko Zurutuza Ortega
· DBLP profile ↗
18ranked-venue papers
1as first author
7since 2021 · last 2026
0000-0003-3720-6048ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 5 · 1 since 2021Systems, architecture and hardware · 2Computer networks · 2 · 2 since 2021Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Replica-Based Moving Target Defense Against Injection Attacks in Software-Defined Industrial Control SystemsabstractRecent incidents have demonstrated the increasing vulnerability of Industrial Control Systems (ICSs) to sophisticated and targeted attacks orchestrated by adversaries with high motivation, resources, and domain knowledge. Among these threats, False Data Injection (FDI) attacks have emerged as one of the main security threats to ICSs, involving the deliberate manipulation or injection of false data into the control system to deceive or disrupt operations. FDI attacks pose a significant risk due to their high capacity of concealment and ability to evade intrusion detection systems that rely on accurate ICS models. In this paper, we presentdefclon, a novel Software-Defined Networking (SDN)-based Moving Target Defense (MTD) approach against FDI attacks.Defclonproactively replicates network packets across multiple network paths and adaptively selects a single path using a signaling game model to reach the destination end-device. We demonstrate the effectiveness of our approach through simulations, numerical analysis, and experiments on ICS network traffic and topologies. Experimental results show thatdefclonis able to not only mitigate the effects of FDI attacks, but also to introduce different levels of uncertainty without degrading network performance, significantly increasing the difficulty for adversaries to gather information and launch attacks. Xabier Etxezarreta, Federico Turrin, Iñaki Garitano, Mikel Iturbe, Urko Zurutuza, Mauro Conti |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Gotham Testbed: A Reproducible IoT Testbed for Security Experiments and Dataset GenerationabstractThe growing adoption of the Internet of Things (IoT) has brought a significant increase in attacks targeting those devices. Machine learning (ML) methods have shown promising results for intrusion detection; however, the scarcity of IoT datasets remains a limiting factor in developing ML-based security systems for IoT scenarios. Static datasets get outdated due to evolving IoT architectures and threat landscape; meanwhile, the testbeds used to generate them are rarely published. This paper presents the Gotham testbed, a reproducible and flexible security testbed extendable to accommodate new emulated devices, services or attackers. Gotham is used to build an IoT scenario composed of 100 emulated devices communicating via MQTT, CoAP and RTSP protocols, among others, in a topology composed of 30 switches and 10 routers. The scenario presents three threat actors, including the entire Mirai botnet lifecycle and additional red-teaming tools performing DoS, scanning, and attacks targeting IoT protocols. The testbed has many purposes, including a cyber range, testing security solutions, and capturing network and application data to generate datasets. We hope that researchers can leverage and adapt Gotham to include other devices, state-of-the-art attacks and topologies to share scenarios and datasets that reflect the current IoT settings and threat landscape. Xabier Sáez de Cámara, Jose Luis Flores 0001, Cristóbal Arellano, Aitor Urbieta, Urko Zurutuza |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Low delay network attributes randomization to proactively mitigate reconnaissance attacks in industrial control systemsabstractAbstract Industrial Control Systems are used in a wide variety of industrial facilities, including critical infrastructures, becoming the main target of multiple security attacks. A malicious and successful attack against these infrastructures could cause serious economic and environmental consequences, including the loss of human lives. Static networks configurations and topologies, which characterize Industrial Control Systems, represent an advantage for attackers, allowing them to scan for vulnerable devices or services before carrying out the attack. Identifying active devices and services is often the first step for many attacks. This paper presents a proactive network reconnaissance defense mechanism based on the temporal randomization of network IP addresses, MAC addresses and port numbers. The obtained information distortion minimizes the knowledge acquired by the attackers, hindering any attack that relies on network addressing. The temporal randomization of network attributes is performed in an adaptive way, minimizing the overhead introduced in the network and avoiding any error and latency in communications. The implementation as well as the tests have been carried out in a laboratory with real industrial equipment, demonstrating the effectiveness of the presented solution. Xabier Etxezarreta, Iñaki Garitano, Mikel Iturbe, Urko Zurutuza |
Wirel. Networks | 4 |
| 2024 | On the use of MiniCPS for conducting rigorous security experiments in Software-Defined Industrial Control SystemsabstractAbstract Software-Defined Networking (SDN) offers a global view over the network and the ability of centrally and dynamically managing network flows, making them ideal for creating security threat detection and mitigation solutions. Industrial networks possess specific characteristics that make them well-suited for such solutions, leading to extensive research efforts in this area. However, due to the high economic cost and potential risks associated with real equipment interaction, most studies rely on testbeds for demonstration purposes. Therefore, it becomes crucial to understand the limitations and safe operating ranges of testbed environments to ensure the development of scientifically rigorous experiments and accurate result measurements. This study focuses on analyzing MiniCPS-based testbeds in terms of network performance, experiment replicability, and the effects of different attacker implementation modes. The findings demonstrate that utilizing MiniCPS on actual hardware enables the development of highly replicable and high-performance testbeds, as long as they operate within the predefined safe operating ranges. Additionally, this work provides an in-depth analysis of various attacker implementation techniques and their impact on the network. Xabier Etxezarreta, Iñaki Garitano, Mikel Iturbe, Urko Zurutuza |
Wirel. Networks | 4 |
| 2023 | Federated Explainability for Network Anomaly CharacterizationabstractMachine learning (ML) based systems have shown promising results for intrusion detection due to their ability to learn complex patterns. In particular, unsupervised anomaly detection approaches offer practical advantages as does not require labeling the training data, which is costly and time-consuming. To further address practical concerns, there is a rising interest in adopting federated learning (FL) techniques as a recent ML model training paradigm for distributed settings (e.g., IoT), thereby addressing challenges such as data privacy, availability and communication cost concerns. However, output generated by unsupervised models provide limited contextual information to security analysts at SOCs, as they usually lack the means to know why a sample was classified as anomalous or cannot distinguish between different types of anomalies, difficulting the extraction of actionable information and correlation with other indicators. Moreover, ML explainability methods have received little attention in FL settings and present additional challenges due to the distributed nature and data locality requirements. This paper proposes a new methodology to characterize and explain the anomalies detected by unsupervised ML-based intrusion detection models in FL settings. We adapt and develop explainability, clustering and cluster validation algorithms to FL settings to mine patterns in the anomalous samples and identify different threats throughout the entire network, demonstrating the results on two network intrusion detection datasets containing real IoT malware, namely Gafgyt and Mirai, and various attack traces. The learned clustering results can be used to classify emerging anomalies, provide additional context that can be leveraged to gain more insight and enable the correlation of the anomalies with alerts triggered by other security solutions. Xabier Sáez de Cámara, Jose Luis Flores 0001, Cristóbal Arellano, Aitor Urbieta, Urko Zurutuza |
RAID | 5 |
| 2023 | Clustered federated learning architecture for network anomaly detection in large scale heterogeneous IoT networksabstractThere is a growing trend of cyberattacks against Internet of Things (IoT) devices; moreover, the sophistication and motivation of those attacks is increasing. The vast scale of IoT, diverse hardware and software, and being typically placed in uncontrolled environments make traditional IT security mechanisms such as signature-based intrusion detection and prevention systems challenging to integrate. They also struggle to cope with the rapidly evolving IoT threat landscape due to long delays between the analysis and publication of the detection rules. Machine learning methods have shown faster response to emerging threats; however, model training architectures like cloud or edge computing face multiple drawbacks in IoT settings, including network overhead and data isolation arising from the large scale and heterogeneity that characterizes these networks. This work presents an architecture for training unsupervised models for network intrusion detection in large, distributed IoT and Industrial IoT (IIoT) deployments. We leverage Federated Learning (FL) to collaboratively train between peers and reduce isolation and network overhead problems. We build upon it to include an unsupervised device clustering algorithm fully integrated into the FL pipeline to address the heterogeneity issues that arise in FL settings. The architecture is implemented and evaluated using a testbed that includes various emulated IoT/IIoT devices and attackers interacting in a complex network topology comprising 100 emulated devices, 30 switches and 10 routers. The anomaly detection models are evaluated on real attacks performed by the testbed’s threat actors, including the entire Mirai malware lifecycle, an additional botnet based on the Merlin command and control server and other red-teaming tools performing scanning activities and multiple attacks targeting the emulated devices. Xabier Sáez de Cámara, Jose Luis Flores 0001, Cristóbal Arellano, Aitor Urbieta, Urko Zurutuza |
Comput. Secur. | 5 |
| 2022 | Deep learning models for predictive maintenance: a survey, comparison, challenges and prospects
Oscar Serradilla-Casado, Ekhi Zugasti, Jon Rodriguez, Urko Zurutuza |
Appl. Intell. | 4 |
| 2020 | Data-Driven Industrial Human-Machine Interface Temporal Adaptation for Process OptimizationabstractThe application of Artificial Intelligence (AI) into Industrial Human-Machine Interfaces (HMIs) moved old systems with physical buttons and analogue actuators into adaptive interaction models and context-based self adjusted interfaces. To date, little attention has been paid to industrial Human-Machine Interfaces (HMI) which play a vital role in the communication between operator and complex productive systems. Current industrial HMIs do not take into account operator behaviour, but rather focus on the production process. To enhance User Experience (UX) and improve performance it is necessary to adapt the interface to the needs of the operator. This paper proposes a Machine Learning (ML) based operator interaction Data-Driven methodology to extract a set of interface adaptation rules. The methodology optimizes the interaction by reducing the number of actions and hence the amount of time and possible errors in repetitive monitoring and control tasks. An experiment with real operators was conducted to validate the proposed approach. The system was able to extract their interaction patterns and propose temporal interface adaptations, leading to a personalized, adaptive and more effective interaction. Daniel Reguera-Bakhache, Iñaki Garitano, Roberto Uribeetxeberria, Carlos Cernuda, Urko Zurutuza |
ETFA | 5 |
| 2020 | Interpreting Remaining Useful Life estimations combining Explainable Artificial Intelligence and domain knowledge in industrial machineryabstractThis paper presents the implementation and explanations of a remaining life estimator model based on machine learning, applied to industrial data. Concretely, the model has been applied to a bushings testbed, where fatigue life tests are performed to find more suitable bushing characteristics. Different regressors have been compared Environmental and Operational Condition and setting variables as input data to prognosticate the remaining life on each observation during fatigue tests, where final model is a Random Forest was chosen given its accuracy and explainability potential. The model creation, optimisation and interpretation has been guided combining eXplainable Artificial Intelligence with domain knowledge. Precisely, ELI5 and LIME explainable techniques have been used to perform local and global explanations. These were used to understand the relevance of predictor variables in individual and overall remaining life estimations. The achieved results have been process knowledge gain and expert knowledge validation, assertion of huge potential of data-driven models in industrial processes and highlight the need of collaboration between expert knowledge technicians and eXplainable Artificial Intelligence techniques to understand advanced machine learning models. Oscar Serradilla-Casado, Ekhi Zugasti, Carlos Cernuda, Andoitz Aranburu, Julian Ramirez de Okariz, Urko Zurutuza |
FUZZ-IEEE | 6 |
| 2020 | SDRS: A new lossless dimensionality reduction for text corpora
Iñaki Vélez, Vitor Basto-Fernandes, Enaitz Ezpeleta, José Ramón Méndez 0001, Urko Zurutuza |
Inf. Process. Manag. | 5 |
| 2019 | Analyze, Sense, Preprocess, Predict, Implement, and Deploy (ASPPID): An incremental methodology based on data analytics for cost-efficiently monitoring the industry 4.0
Jesús Para, Javier Del Ser, Antonio J. Nebro, Urko Zurutuza, Francisco Herrera |
Eng. Appl. Artif. Intell. | 4 |
| 2018 | Implementation of a Reference Architecture for Cyber Physical Systems to support Condition Based MaintenanceabstractThis paper presents the implementation of a reference architecture for Cyber Physical Systems (CPS) to support Condition Based Maintenance (CBM) of industrial assets. The article focuses on describing how the MANTIS Reference Architecture is implemented to support predictive maintenance of clutch-brake assets fleet, and includes the data analysis techniques and algorithms implemented at platform level to facilitate predictive maintenance activities. These technologies are (1) Root Cause Analysis powered by Attribute Oriented Induction Clustering and (2) Remaining Useful Life powered by Time Series Forecasting. The work has been conducted in a real use case within the EU project MANTIS. Felix Larrinaga, Javier Fernandez-Anakabe, Ekhi Zugasti, Iñaki Garitano, Urko Zurutuza, Mikel Anasagasti, Mikel Mondragon |
CoDIT | 5 |
| 2017 | Short Messages Spam Filtering Combining Personality Recognition and Sentiment AnalysisabstractCurrently, short communication channels are growing up due to the huge increase in the number of smartphones and online social networks users. This growth attracts malicious campaigns, such as spam campaigns, that are a direct threat to the security and privacy of the users. While most researches are focused on automatic text classification, in this work we demonstrate the possibility of improving current short messages spam detection systems using a novel method. We combine personality recognition and sentiment analysis techniques to analyze Short Message Services (SMS) texts. We enrich a publicly available dataset adding these features, first separately and after in combination, of each message to the dataset, creating new datasets. We apply several combinations of the best SMS spam classifiers and filters to each dataset in order to compare the results of each one. Taking into account the experimental results we analyze the real inuence of each feature and the combination of both. At the end, the best results are improved in terms of accuracy, reaching to a 99.01% and the number of false positive is reduced. Enaitz Ezpeleta, Iñaki Garitano, Urko Zurutuza, José María Gómez Hidalgo |
Int. J. Uncertain. Fuzziness Knowl. Based Syst. | 3 |
| 2017 | Towards Large-Scale, Heterogeneous Anomaly Detection Systems in Industrial Networks: A Survey of Current TrendsabstractIndustrial Networks (INs) are widespread environments where heterogeneous devices collaborate to control and monitor physical processes. Some of the controlled processes belong to Critical Infrastructures (CIs), and, as such, IN protection is an active research field. Among different types of security solutions, IN Anomaly Detection Systems (ADSs) have received wide attention from the scientific community. While INs have grown in size and in complexity, requiring the development of novel, Big Data solutions for data processing, IN ADSs have not evolved at the same pace. In parallel, the development of Big Data frameworks such as Hadoop or Spark has led the way for applying Big Data Analytics to the field of cyber-security, mainly focusing on the Information Technology (IT) domain. However, due to the particularities of INs, it is not feasible to directly apply IT security mechanisms in INs, as IN ADSs face unique characteristics. In this work we introduce three main contributions. First, we survey the area of Big Data ADSs that could be applicable to INs and compare the surveyed works. Second, we develop a novel taxonomy to classify existing IN-based ADSs. And, finally, we present a discussion of open problems in the field of Big Data ADSs for INs that can lead to further development. Mikel Iturbe, Iñaki Garitano, Urko Zurutuza, Roberto Uribeetxeberria |
Secur. Commun. Networks | 3 |
| 2012 | A method to construct network traffic models for process control systemsabstractNowadays, it is a well-known fact that modern Critical Infrastructures (CIs) depend on Information and Communication Technologies (ICT). Supervisory Control and Data Acquisition (SCADA) systems with off-the-shelf ICT hardware and software found their way in Process Control Systems (PCSs) due to their simplicity and cost-efficiency. However, recent incidents such as Stuxnet, Duqu or Night Dragon revealed new ICT vulnerabilities and attack scenarios in PCSs. Nevertheless, as shown by recent events, security studies on real SCADA systems are challenging due to the lack of proper experimentation environments. Through this work we develop a method to generate realistic network traffic in laboratory conditions without the need of a real PCS installation. This is indeed our main contribution as the basis of future anomaly detection systems. Such method could support experimentation through the recreation of realistic traffic in simulated environments. The accuracy and fidelity of the proposed approach was validated with several statistical methods that compare the predicted traffic with traffic taken from a real in stallation. Iñaki Garitano, Christos Siaterlis, Béla Genge, Roberto Uribeetxeberria, Urko Zurutuza |
ETFA | 5 |
| 2012 | A Neural-Visualization IDS for Honeynet DataabstractNeural intelligent systems can provide a visualization of the network traffic for security staff, in order to reduce the widely known high false-positive rate associated with misuse-based Intrusion Detection Systems (IDSs). Unlike previous work, this study proposes an unsupervised neural models that generate an intuitive visualization of the captured traffic, rather than network statistics. These snapshots of network events are immensely useful for security personnel that monitor network behavior. The system is based on the use of different neural projection and unsupervised methods for the visual inspection of honeypot data, and may be seen as a complementary network security tool that sheds light on internal data structures through visual inspection of the traffic itself. Furthermore, it is intended to facilitate verification and assessment of Snort performance (a well-known and widely-used misuse-based IDS), through the visualization of attack patterns. Empirical verification and comparison of the proposed projection methods are performed in a real domain, where two different case studies are defined and analyzed. Álvaro Herrero 0001, Urko Zurutuza, Emilio Corchado |
Int. J. Neural Syst. | 2 |
| 2008 | Beacon Frame Spoofing Attack Detection in IEEE 802.11 NetworksabstractA great variety of well-known attacks exist for the IEEE 802.11 protocol. The lack of mechanisms for management frame authentication and the complexity of the protocol itself have derived into a considerable number of denial of service and identity spoofing attacks. As most denial of service attacks are based on spoofing of MAC addresses, spoofed frame detection schemes have gained attentions. Currently the most efficient techniques to detect this kind of attacks are based on the creation of profiles for the wireless nodes and behavior based protocol anomaly detection. However, these techniques tend to generate too many of false positives. This is caused by the unstable nature of the wireless medium and also because of the difficulty to model the behaviour of the diverse implementations from different manufacturers. One way to reduce false positives is to combine different techniques to carry out the analysis. We propose a novel method that identifies the impersonation of certain management frames, which helps to reduce the number of false positives within other existing MAC spoofing detection techniques. Asier Martínez, Urko Zurutuza, Roberto Uribeetxeberria, Miguel Fernández, Jesus Lizarraga, Ainhoa Serna Nocedal, Iñaki Vélez |
ARES | 2 |
| 2007 | Combined Data Mining Approach for Intrusion Detection
Urko Zurutuza, Roberto Uribeetxeberria, Ekain Azketa, G. Gil, Jesus Lizarraga, Miguel Fernández |
SECRYPT | 1 |