EDBT 2026 Demo / reviewers in the wild / expert
Juan Tapiador
dblp:98/3527 · also Juan E. Tapiador, Juan M. Estévez-Tapiador
· DBLP profile ↗
84ranked-venue papers
11as first author
20since 2021 · last 2026
0000-0002-4573-3967ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 40 · 5 first-author · 14 since 2021Computer networks · 21 · 4 first-author · 3 since 2021Artificial intelligence and machine learning · 8 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 7 · 1 first-author · 1 since 2021Systems, architecture and hardware · 3Software engineering, systems software and programming languages · 3 · 2 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Dead Domains, Living Data: A Privacy Risk Analysis of Domain Lifecycle in Android AppsabstractMobile applications transmit sensitive data and user identifiers to domain-based endpoints embedded in SDKs and third-party services. Unlike the web, where operators can update or remove third-party endpoints, apps are static binaries that remain installed for years and continue sending identifiers to endpoints whose domains may expire, change ownership, or become abandoned. This mismatch creates a privacy risk, since identifiers may flow to hijacked, unmaintained, or maliciously re-registered endpoints without users' knowledge or consent. This work presents a privacy risk analysis of domain endpoints in Android apps. We identify endpoints receiving sensitive identifiers through dynamic analysis of 11,131 apps and track the lifecycle of 3,420 associated domains around their expiration events. Our analysis reveals that 25.3% of domains are renewed after expiration, with 78.7% of these belonging to third-party services or SDKs embedded in apps whose install brackets total over 78 billion cumulative downloads, placing a potential user base of billions at risk. While the majority of these lapses are short and fall within registrar grace periods, we identify 218 domains with dangling CNAMEs susceptible to subdomain hijacking (34 of which received 91 valid TLS certificates during their expired period), and show that 17.0% of domains experience TLS issuance gaps where confidentiality is lost. We categorize high-risk endpoints into Advertising and Tracking vs Backend and Utility services, finding that vulnerable endpoints are embedded in over 4,000 apps. By correlating WHOIS, DNS, and TLS lifecycles with dynamically observed identifier flows, we expose how domain mismanagement translates into data flows and user privacy harm. Finally, we derive mitigation strategies to address these supply-chain risks. Gabriel Hortea, Aniketh Girish, Narseo Vallina-Rodriguez, Juan Tapiador |
Proc. Priv. Enhancing Technol. | 4 |
| 2026 | Did I Vet You Before? Assessing the Chrome Web Store Vetting Process Through Browser Extension Similarity
José Miguel Moreno, Narseo Vallina-Rodriguez, Juan Tapiador |
IEEE Trans. Serv. Comput. | 3 |
| 2025 | Beneath the Surface: An Analysis of OEM Customizations on the Android TLS Protocol StackabstractThe open-source nature of the Android Open Source Project (AOSP) allows Original Equipment Manufacturers (OEMs) to customize the Android operating system, contributing to what is known as Android fragmentation. Google has implemented the Compatibility Definition Document (CDD) and the Compatibility Test Suite (CTS) to ensure the integrity and security of the Android ecosystem. However, the effectiveness of these policies and measures in warranting OEM compliance remains uncertain. This paper empirically studies for the first time the nature of OEM customizations in the Android TLS protocol stack, and their security implications on user-installed mobile apps across thousands of Android models. We find that approximately 80% of the analyzed Android models deviate from the standard AOSP TLS codebase and that OEM customizations often involve code changes in functions used by app developers for enhancing TLS security like end-point and certificate verification. Our analysis suggests that these customizations are likely influenced by factors such as manufacturers’ supply chain dynamics and patching prioritization tactics, including the need to support legacy components. We conclude by identifying potential root causes and emphasizing the need for stricter policy enforcement, better supply chain controls, and improved patching processes across the ecosystem. Vinuri Bandara, Stijn Pletinckx, Ilya Grishchenko, Christopher Krügel, Giovanni Vigna, Juan Tapiador, Narseo Vallina-Rodriguez |
EuroS&P | 6 |
| 2025 | Attack structure matters: Causality-preserving metrics for Provenance-based Intrusion Detection SystemsabstractProvenance-based Intrusion Detection Systems (PIDS) detect attacks and reconstruct attack scenarios by analyzing provenance graphs. These graphs, constructed from events captured by system logs and security sensors, model the causal relationships between operations performed by system entities. In PIDS research, evaluations typically rely on standard metrics such as precision and recall, computed at the graph level. To assess the accuracy of reconstructed attack graphs, researchers often use proxy metrics at the node level, as computing similarity between provenance graphs remains an open problem. In this paper, we address this problem by introducing SDTED (Structure and Depth Preserving Tree Edit Distance), a variant of the recently proposed Generalized Weisfeiler–Lehman Graph Kernel, adapted to capture the distinctive properties of provenance graphs. Using a dataset of attack scenarios from the DARPA Engagements program, we show that SDTED accurately measures similarity between provenance graphs in cases where node-level metrics yield suboptimal results. Moreover, SDTED is capable of detecting changes in causal relationships between provenance graphs, an essential property for robust evaluation of PIDS proposals. We open source our implementation of SDTED to support reproducibility and encourage adoption within the research community. Manuel Suarez-Roman, Juan Tapiador |
Comput. Secur. | 2 |
| 2025 | Your Signal, Their Data: An Empirical Privacy Analysis of Wireless-scanning SDKs in AndroidabstractMobile apps frequently use Bluetooth Low Energy (BLE) and WiFi scanning permissions to discover nearby devices like peripherals and connect to WiFi Access Points (APs). However, wireless interfaces also serve as a covert proxy for geolocation data, enabling continuous user tracking and profiling. This includes technologies like BLE beacons, which are BLE devices broadcasting unique identifiers to determine devices' indoor physical locations; such beacons are easily found in shopping centres. Despite the widespread use of wireless scanning APIs and their potential for privacy abuse, the interplay between commercial mobile SDKs with wireless sensing and beaconing technologies remains largely unexplored. In this work, we conduct the first systematic analysis of 52 wireless-scanning SDKs, revealing their data collection practices and privacy risks. We develop a comprehensive analysis pipeline that enables us to detect beacon scanning capabilities, inject wireless events to trigger app behaviors, and monitor runtime execution on instrumented devices. Our findings show that 86% of apps integrating these SDKs collect at least one sensitive data type, including device and user identifiers such as AAID, email, along with GPS coordinates, WiFi and Bluetooth scan results. We uncover widespread SDK-to-SDK data sharing and evidence of ID bridging, where persistent and resettable identifiers are shared and synchronized within SDKs embedded in applications to potentially construct detailed mobility profiles, compromising user anonymity and enabling long-term tracking. We provide evidence of key actors engaging in these practices and conclude by proposing mitigation strategies such as stronger SDK sandboxing, stricter enforcement of platform policies, and improved transparency mechanisms to limit unauthorized tracking. Aniketh Girish, Joel Reardon, Juan Tapiador, Srdjan Matic, Narseo Vallina-Rodriguez |
Proc. Priv. Enhancing Technol. | 3 |
| 2025 | Tracking Without Borders: Studying the Role of WebViews in Bridging Mobile and Web TrackingabstractWebViews are a core component of today's in-app browsing technologies on mobile platforms, playing a central role in rendering web content like mobile advertisements. However, their use and potential to bridge web and mobile tracking paradigms comes at a significant privacy cost for users. Although prior work has highlighted privacy risks associated with WebViews, the real-world scale and privacy impact of their misuse and abuse remain unexplored due to the hybrid nature of WebViews-combining Java, native, and dynamically-loaded JavaScript (JS) code. In this paper, we present the first large-scale empirical study of WebView abuse in Android apps. We analyze how app developers and third-party SDKs facilitate user tracking by configuring WebViews to bypass default platform privacy protections and enable invasive tracking through JavaScript code. Using a novel analysis pipeline that combines static and dynamic analysis of Java/Kotlin code and JavaScript, we reveal how numerous actors undermine users' privacy and exploit WebViews in the wild. We show that harmful JavaScript code, often distributed via unvetted Real-Time Bidding (RTB) processes, exploits WebViews to perform advanced tracking techniques such as cookie sync-ing, canvas fingerprinting, and misuse of the Java-JS interface and permission-protected JavaScript APIs to silently leak unique user identifiers and geolocation data without user awareness for cross-platform tracking. Nipuna Weerasekara, José Miguel Moreno, Srdjan Matic, Joel Reardon, Juan Tapiador, Narseo Vallina-Rodriguez |
Proc. Priv. Enhancing Technol. | 5 |
| 2024 | Reviewing War: Unconventional User Reviews as a Side Channel to Circumvent Information ControlsabstractDuring the first days of the 2022 Russian invasion of Ukraine, Russia's media regulator blocked access to many global social media platforms and news sites, including Twitter, Facebook, and the BBC. To bypass the information controls set by Russian authorities, pro-Ukrainian groups explored unconventional ways to reach out to the Russian population, such as posting war-related content in the user reviews of Russian businesses available on Google Maps or Tripadvisor. This paper provides a first analysis of this new phenomenon by analyzing the unconventional strategies used to avoid state censorship in the Russian Federation during the conflict. Specifically, we analyze reviews posted on these platforms from the beginning of the war to September 2022. We measure the channeling of war-related messages through user reviews on Tripadvisor and Google Maps. Our analysis of the content posted on these services reveals that users leveraged these platforms to seek and exchange humanitarian and travel advice, but also to disseminate disinformation and polarized messages. Finally, we analyze the response of platforms in terms of content moderation and their impact. José Miguel Moreno, Sergio Pastrana, Jens Helge Reelfs, Pelayo Vallina, Savvas Zannettou, Andriy Panchenko 0001, Georgios Smaragdakis, Oliver Hohlfeld, Narseo Vallina-Rodriguez, Juan Tapiador |
ICWSM | 10 |
| 2024 | Mules and Permission Laundering in Android: Dissecting Custom Permissions in the WildabstractAndroid implements a permission system to regulate apps' access to system resources and sensitive user data. One salient feature of this system is its extensibility: apps can define their own custom permissions to expose features and data to other apps. However, little is known about how widespread the usage of custom permissions is, and what is the impact that these permissions can have on users' privacy and security. In this paper, we empirically study the usage of custom permissions at large scale, using a dataset of 2.2M pre-installed and app-store-downloaded apps. We find the usage of custom permissions to be widespread, and seemingly growing over time. Despite this prevalence, we find that custom permissions are virtually invisible to end users, and their purpose mostly undocumented. This lack of transparency can lead to serious security and privacy problems: we show that custom permissions can facilitate access to permission-protected system resources to apps that lack those permissions without user awareness. To detect this practice, we design and implement two static analysis tools, and highlight multiple concerning cases spotted in the wild. We conclude this study with a discussion of potential solutions to mitigate the privacy and security risks of custom permissions. Julien Gamba, Álvaro Feal, Eduardo Blázquez, Vinuri Bandara, Abbas Razaghpanah, Juan Tapiador, Narseo Vallina-Rodriguez |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2023 | Chrowned by an Extension: Abusing the Chrome DevTools Protocol through the Debugger APIabstractThe Chromium open-source project has become a fundamental piece of the Web as we know it today, with multiple vendors offering browsers based on its codebase. One of its most popular features is the possibility of altering or enhancing the browser functionality through third-party programs known as browser extensions. Extensions have access to a wide range of capabilities through the use of APIs exposed by Chromium. The Debugger API—arguably the most powerful of such APIs—allows extensions to use the Chrome DevTools Protocol (CDP), a capability-rich tool for debugging and instrumenting the browser. In this paper, we describe several vulnerabilities present in the Debugger API and in the granting of capabilities to extensions that can be used by an attacker to take control of the browser, escalate privileges, and break context isolation. We demonstrate their impact by introducing six attacks that allow an attacker to steal user information, monitor network traffic, modify site permissions (e.g., access to camera or microphone), bypass security interstitials without user intervention, and change the browser settings. Our attacks work in all major Chromium-based browsers as they are rooted at the core of the Chromium project. We reported our findings to the Chromium Development Team, who already fixed some of them and are currently working on fixing the remaining ones. We conclude by discussing how questionable design decisions, lack of public specifications, and an overpowered Debugger API have contributed to enabling these attacks, and propose mitigations. José Miguel Moreno, Narseo Vallina-Rodriguez, Juan Tapiador |
EuroS&P | 3 |
| 2023 | In the Room Where It Happens: Characterizing Local Communication and Threats in Smart HomesabstractThe network communication between Internet of Things (IoT) devices on the same local network has significant implications for platform and device interoperability, security, privacy, and correctness. Yet, the analysis of local home Wi-Fi network traffic and its associated security and privacy threats have been largely ignored by prior literature, which typically focuses on studying the communication between IoT devices and cloud end-points, or detecting vulnerable IoT devices exposed to the Internet. In this paper, we present a comprehensive and empirical measurement study to shed light on the local communication within a smart home deployment and its threats. We use a unique combination of passive network traffic captures, protocol honeypots, dynamic mobile app analysis, and crowdsourced IoT data from participants to identify and analyze a wide range of device activities on the local network. We then analyze these datasets to characterize local network protocols, security and privacy threats associated with them. Our analysis reveals vulnerable devices, insecure use of network protocols, and sensitive data exposure by IoT devices. We provide evidence of how this information is exfiltrated to remote servers by mobile apps and third-party SDKs, potentially for household fingerprinting, surveillance and cross-device tracking. We make our datasets and analysis publicly available to support further research in this area. Aniketh Girish, Tianrui Hu, Daniel J. Dubois, Srdjan Matic, Danny Yuxing Huang, Serge Egelman, Joel Reardon, Juan Tapiador, David R. Choffnes, Narseo Vallina-Rodriguez |
IMC | 9 |
| 2023 | Log: It's Big, It's Heavy, It's Filled with Personal Data! Measuring the Logging of Sensitive Information in the Android Ecosystem
Allan Lyons, Julien Gamba, Austin Shawaga, Joel Reardon, Juan Tapiador, Serge Egelman, Narseo Vallina-Rodriguez |
USENIX Security Symposium | 5 |
| 2023 | An analysis of fake social media engagement servicesabstractFake engagement services allow users of online social media and other web platforms to illegitimately increase their online reach and boost their perceived popularity. Driven by socio-economic and even political motivations, the demand for fake engagement services has increased in the last years, which has incentivized the rise of a vast underground market and support infrastructure. Prior research in this area has been limited to the study of the infrastructure used to provide these services (e.g., botnets) and to the development of algorithms to detect and remove fake activity in online targeted platforms. Yet, the platforms in which these services are sold (known as panels) and the underground markets offering these services have not received much research attention. To fill this knowledge gap, this paper studies Social Media Management (SMM) panels, i.e., reselling platforms—often found in underground forums—in which a large variety of fake engagement services are offered. By daily crawling 86 representative SMM panels for 4 months, we harvest a dataset with 2.8 M forum entries grouped into 61k different services. This dataset allows us to build a detailed catalog of the services for sale, the platforms they target, and to derive new insights on fake social engagement services and its market. We then perform an economic analysis of fake engagement services and their trading activities by automatically analyzing 7k threads in underground forums. Our analysis reveals a broad range of offered services and levels of customization, where buyers can acquire fake engagement services by selecting features such as the quality of the service, the speed of delivery, the country of origin, and even personal attributes of the fake account (e.g., gender). The price analysis also yields interesting empirical results, showing significant disparities between prices of the same product across different markets. These observations suggest that the market is still undeveloped and sellers do not know the real market value of the services that they offer, leading them to underprice or overprice their services. David Nevado Catalán, Sergio Pastrana, Narseo Vallina-Rodriguez, Juan Tapiador |
Comput. Secur. | 4 |
| 2023 | Mixed Signals: Analyzing Software Attribution Challenges in the Android EcosystemabstractThe ability to identify the author responsible for a given software object is critical for many research studies and for enhancing software transparency and accountability. However, as opposed to other application markets like Apple's iOS App Store, attribution in the Android ecosystem is known to be hard. Prior research has leveraged market metadata and signing certificates to identify software authors without questioning the validity and accuracy of these attribution signals. However, Android application (app) authors can, either intentionally or by mistake, hide their true identity due to: (1) the lack of policy enforcement by markets to ensure the accuracy and correctness of the information disclosed by developers in their market profiles during the app release process, and (2) the use of self-signed certificates for signing apps instead of certificates issued by trusted CAs. In this paper, we perform the first empirical analysis of the availability, volatility and overall aptness of publicly available market and app metadata for author attribution in Android markets. To that end, we analyze a dataset of over 2.5 million market entries and apps extracted from five Android markets for over two years. Our results show that widely used attribution signals are often missing from market profiles and that they change over time. We also invalidate the general belief about the validity of signing certificates for author attribution. For instance, we find that apps from different authors share signing certificates due to the proliferation of app building frameworks and software factories. Finally, we introduce the concept of anattribution graphand we apply it to evaluate the validity of existing attribution signals on the Google Play Store. Our results confirm that the lack of control over publicly available signals can confuse automatic attribution processes. Kaspar Hageman, Álvaro Feal, Julien Gamba, Aniketh Girish, Jakob Bleier, Martina Lindorfer, Juan Tapiador, Narseo Vallina-Rodriguez |
IEEE Trans. Software Eng. | 7 |
| 2022 | Towards an extensible privacy analysis framework for smart homesabstractThe IoT ecosystem is an intricate and complex network of stakeholders that includes platforms, developers, ad networks and cloud providers. However, the ability of smart home platforms and devices to interact and exchange data, together with the data-driven business models adopted by most IoT stakeholders open the ground for unknown and unexpected privacy risks. Existing black-box testing approaches to audit IoT platforms cannot identify data dissemination through side- and covert-channels, and for this reason they are not well suited for rich execution environments where a wide range of devices and applications can co-operate using multiple network protocols and interfaces. This poster proposes ImposTer, a cost-effective and extensible privacy framework for exhaustively testing the IoT ecosystem. Our framework is able to capture, model and emulate horizontal interactions that occur across the different devices in a consumer household. Aniketh Girish, Juan Tapiador, Srdjan Matic, Narseo Vallina-Rodriguez |
IMC | 2 |
| 2022 | Optimization of code caves in malware binaries to evade machine learning detectorsabstractMachine Learning (ML) techniques, especially Artificial Neural Networks, have been widely adopted as a tool for malware detection due to their high accuracy when classifying programs as benign or malicious. However, these techniques are vulnerable to Adversarial Examples (AEs), i.e., carefully crafted samples designed by an attacker to be misclassified by the target model. In this work, we propose a general method to produce AEs from existing malware, which is useful to increase the robustness of ML-based models. Our method dynamically introduces unused blocks (caves) in malware binaries, preserving their original functionality. Then, by using optimization techniques based on Genetic Algorithms, we determine the most adequate content to place in such code caves to achieve misclassification. We evaluate our model in a black-box setting with a well-known state-of-the-art architecture (MalConv), resulting in a successful evasion rate of 97.99 % from the 2k tested malware samples. Additionally, we successfully test the transferability of our proposal to commercial AV engines available at VirusTotal, showing a reduction in the detection rate for the crafted AEs. Finally, the obtained AEs are used to retrain the ML-based malware detector previously evaluated, showing an improve on its robustness. Javier Yuste, Eduardo G. Pardo, Juan Tapiador |
Comput. Secur. | 3 |
| 2022 | Scramblesuit: An effective timing side-channels framework for malware sandbox evasionabstractOnline malware scanners are one of the best weapons in the arsenal of cybersecurity companies and researchers. A fundamental part of such systems is the sandbox that provides an instrumented and isolated environment (virtualized or emulated) for any user to upload and run unknown artifacts and identify potentially malicious behaviors. The provided API and the wealth of information in the reports produced by these services have also helped attackers test the efficacy of numerous techniques to make malware hard to detect. The most common technique used by malware for evading the analysis system is to monitor the execution environment, detect the presence of any debugging artifacts, and hide its malicious behavior if needed. This is usually achieved by looking for signals suggesting that the execution environment does not belong to a native machine, such as specific memory patterns or behavioral traits of certain CPU instructions. In this paper, we show how an attacker can evade detection on such analysis services by incorporating a Proof-of-Work (PoW) algorithm into a malware sample. Specifically, we leverage the asymptotic behavior of the computational cost of PoW algorithms when they run on some classes of hardware platforms to effectively detect a non bare-metal environment of the malware sandbox analyzer. To prove the validity of this intuition, we design and implement Scramblesuit, a framework to automatically (i) implement sandbox detection strategies, and (ii) embed a test evasion program into an arbitrary malware sample. We perform a comprehensive evaluation of Scramblesuit across a wide range of: 1) COTS architectures (ARM, Apple M1, i9, i7 and Xeon), 2) malware families, and 3) online sandboxes (JoeSandbox, Sysinternals, C2AE, Zenbox, Dr.Web VX Cube, Tencent HABO, YOMI Hunter). Our empirical evaluation shows that a PoW-based evasion technique is hard to fingerprint, and reduces existing malware detection rate by a factor of 10. The only plausible counter-measure to Scramblesuit is to rely on bare-metal online malware scanners, which is unrealistic given they currently handle millions of daily submissions. Antonio Nappa, Aaron Úbeda-Portugués, Panagiotis Papadopoulos, Matteo Varvello, Juan Tapiador, Andrea Lanzi |
J. Comput. Secur. | 5 |
| 2021 | The Stress as Adversarial Factor for Cyber Decision MakingabstractThere are several factors that make cyber operations stressful, which include their complexity, unpredictability, and a continuum of decisions involving high risk and fast cost-benefit reasoning. These operations are subject to the reception of a large number of events to which the operator must learn (feedback) and respond appropriately in a timely manner, presenting particular cyber stressors able to trigger combat exhaustion battle fatigue. Their consequences will vary and evolve according to changes in the operational context, which makes them difficult to prevent, detect and mitigate. Among others, these attenuate the perception of a lack of self-efficacy, reduces the cyber decision-maker ability of distinguishing ally, neutral and hostile assets; or tend to wrongly perceive the decision cost (effort, time, self-protection, etc.) as much higher than the expected benefits. With the motivation of facilitating the understanding of the impact of the combat and operational stress at cyber operations, this paper discusses the related recent insights for cognitive dominance at decision making on the cyberspace. David Sandoval Rodríguez-Bermejo, Jorge Maestre Vidal, Juan Tapiador |
ARES | 3 |
| 2021 | PoW-How: An Enduring Timing Side-Channel to Evade Online Malware Sandboxes
Antonio Nappa, Panagiotis Papadopoulos, Matteo Varvello, Daniel Aceituno Gomez, Juan Tapiador, Andrea Lanzi |
ESORICS (1) | 5 |
| 2021 | Trouble Over-The-Air: An Analysis of FOTA Apps in the Android EcosystemabstractAndroid firmware updates are typically managed by the so-called FOTA (Firmware Over-the-Air) apps. Such apps are highly privileged and play a critical role in maintaining devices secured and updated. The Android operating system offers standard mechanisms—available to Original Equipment Manufacturers (OEMs)—to implement their own FOTA apps but such vendor-specific implementations could be a source of security and privacy issues due to poor software engineering practices. This paper performs the first large-scale and systematic analysis of the FOTA ecosystem through a dataset of 2,013 FOTA apps detected with a tool designed for this purpose over 422,121 pre-installed apps. We classify the different stakeholders developing and deploying FOTA apps on the Android update ecosystem, showing that 43% of FOTA apps are developed by third parties. We report that some devices can have as many as 5 apps implementing FOTA capabilities. By means of static analysis of the code of FOTA apps, we show that some apps present behaviors that can be considered privacy intrusive, such as the collection of sensitive user data (e.g., geolocation linked to unique hardware identifiers), and a significant presence of third-party trackers. We also discover implementation issues leading to critical vulnerabilities, such as the use of public AOSP test keys both for signing FOTA apps and for update verification, thus allowing any update signed with the same key to be installed. Finally, we study telemetry data collected from real devices by a commercial security tool. We demonstrate that FOTA apps are responsible for the installation of non-system apps (e.g., entertainment apps and games), including malware and Potentially Unwanted Programs (PUP). Our findings suggest that FOTA development practices are misaligned with Google’s recommendations. Eduardo Blázquez, Sergio Pastrana, Álvaro Feal, Julien Gamba, Platon Kotzias, Narseo Vallina-Rodriguez, Juan Tapiador |
SP | 7 |
| 2021 | Blocklist Babel: On the Transparency and Dynamics of Open Source BlocklistingabstractBlocklists constitute a widely-used Internet security mechanism to filter undesired network traffic based on IP/domain reputation and behavior. Many blocklists are distributed in open source form by threat intelligence providers who aggregate and process input from their own sensors, but also from third-party feeds or providers. Despite their wide adoption, many open-source blocklist providers lack clear documentation about their structure, curation process, contents, dynamics, and inter-relationships with other providers. In this paper, we perform a transparency and content analysis of 2,093 free and open source blocklists with the aim of exploring those questions. To that end, we perform a longitudinal 6-month crawling campaign yielding more than 13.5M unique records. This allows us to shed light on their nature, dynamics, inter-provider relationships, and transparency. Specifically, we discuss how the lack of consensus on distribution formats, blocklist labeling taxonomy, content focus, and temporal dynamics creates a complex ecosystem that complicates their combined crawling, aggregation and use. We also provide observations regarding their generally low overlap as well as acute differences in terms of liveness (i.e., how frequently records get indexed and removed from the list) and the lack of documentation about their data collection processes, nature and intended purpose. We conclude the paper with recommendations in terms of transparency, accountability, and standardization. Álvaro Feal, Pelayo Vallina, Julien Gamba, Sergio Pastrana, Antonio Nappa, Oliver Hohlfeld, Narseo Vallina-Rodriguez, Juan Tapiador |
IEEE Trans. Netw. Serv. Manag. | 8 |
| 2020 | The Lockdown Effect: Implications of the COVID-19 Pandemic on Internet TrafficabstractDue to the COVID-19 pandemic, many governments imposed lock-downs that forced hundreds of millions of citizens to stay at home. The implementation of confinement measures increased Internet traffic demands of residential users, in particular, for remote working, entertainment, commerce, and education, which, as a result, caused traffic shifts in the Internet core. Anja Feldmann, Oliver Gasser, Franziska Lichtblau, Enric Pujol-Gil, Ingmar Poese, Christoph Dietzel, Matthias Wichtlhuber, Juan Tapiador, Narseo Vallina-Rodriguez, Oliver Hohlfeld, Georgios Smaragdakis |
Internet Measurement Conference | 9 |
| 2020 | Mis-shapes, Mistakes, Misfits: An Analysis of Domain Classification ServicesabstractDomain classification services have applications in multiple areas, including cybersecurity, content blocking, and targeted advertising. Yet, these services are often a black box in terms of their methodology to classifying domains, which makes it difficult to assess their strengths, aptness for specific applications, and limitations. In this work, we perform a large-scale analysis of 13 popular domain classification services on more than 4.4M hostnames. Our study empirically explores their methodologies, scalability limitations, label constellations, and their suitability to academic research as well as other practical applications such as content filtering. We find that the coverage varies enormously across providers, ranging from over 90% to below 1%. All services deviate from their documented taxonomy, hampering sound usage for research. Further, labels are highly inconsistent across providers, who show little agreement over domains, making it difficult to compare or combine these services. We also show how the dynamics of crowd-sourced efforts may be obstructed by scalability and coverage aspects as well as subjective disagreements among human labelers. Finally, through case studies, we showcase that most services are not fit for detecting specialized content for research or content-blocking purposes. We conclude with actionable recommendations on their usage based on our empirical insights and experience. Particularly, we focus on how users should handle the significant disparities observed across services both in technical solutions and in research. Pelayo Vallina, Victor Le Pochat, Álvaro Feal, Marius Paraschiv, Julien Gamba, Tim Burke, Oliver Hohlfeld, Juan Tapiador, Narseo Vallina-Rodriguez |
Internet Measurement Conference | 8 |
| 2020 | An Analysis of Pre-installed Android SoftwareabstractThe open-source nature of the Android OS makes it possible for manufacturers to ship custom versions of the OS along with a set of pre-installed apps, often for product differentiation. Some device vendors have recently come under scrutiny for potentially invasive private data collection practices and other potentially harmful or unwanted behavior of the preinstalled apps on their devices. Yet, the landscape of preinstalled software in Android has largely remained unexplored, particularly in terms of the security and privacy implications of such customizations. In this paper, we present the first large- scale study of pre-installed software on Android devices from more than 200 vendors. Our work relies on a large dataset of real-world Android firmware acquired worldwide using crowd-sourcing methods. This allows us to answer questions related to the stakeholders involved in the supply chain, from device manufacturers and mobile network operators to third- party organizations like advertising and tracking services, and social network platforms. Our study allows us to also uncover relationships between these actors, which seem to revolve primarily around advertising and data-driven services. Overall, the supply chain around Android's open source model lacks transparency and has facilitated potentially harmful behaviors and backdoored access to sensitive data and services without user consent or awareness. We conclude the paper with recommendations to improve transparency, attribution, and accountability in the Android ecosystem. Julien Gamba, Mohammed Rashed, Abbas Razaghpanah, Juan Tapiador, Narseo Vallina-Rodriguez |
SP | 4 |
| 2019 | AndrEnsemble: Leveraging API Ensembles to Characterize Android Malware FamiliesabstractAssigning family labels to malicious apps is a common practice for grouping together malware with identical behavior. However, recent studies show that apps labeled as belonging to the same family do not necessarily behave similarly: one app may lack or have extra capabilities compared to others in the same family, and, conversely, two apps labeled as belonging to different families may exhibit close behavior. To reveal these inconsistencies, this paper presents AndrEnsemble, a characterization system for Android malware families based on ensembles of sensitive API calls extracted from aggregated call graphs of different families. Our method has several advantages over similar characterization approaches, including a greater reduction ratio with respect to original call graphs, robustness against transformation attacks, and flexibility to be applied at different granularity levels. We experimentally validate our approach and discuss three specific use cases: mobile ransomware, SMS Trojans and banking Trojans. This left us with some interesting findings. First of all, malicious operations in these types of malware are not necessarily exercised by using several sensitive API calls all together. Second, SMS Trojans have larger ensembles of API calls compared to the other types. Last but not least, we identified several samples with identical ensembles though being labeled as part of different families. Omid Mirzaei, Guillermo Suarez-Tangil, José María de Fuentes, Juan Tapiador, Gianluca Stringhini |
AsiaCCS | 4 |
| 2019 | Measuring eWhoringabstracteWhoring is the term used by offenders to refer to a type of online fraud in which cybersexual encounters are simulated for financial gain. Perpetrators use social engineering techniques to impersonate young women in online communities, e.g., chat or social networking sites. They engage potential customers in conversation with the aim of selling misleading sexual material -- mostly photographs and interactive video shows -- illicitly compiled from third-party sites. eWhoring is a popular topic in underground communities, with forums acting as a gateway into offending. Users not only share knowledge and tutorials, but also trade in goods and services, such as packs of images and videos. In this paper, we present a processing pipeline to quantitatively analyse various aspects of eWhoring. Our pipeline integrates multiple tools to crawl, annotate, and classify material in a semi-automatic way. It builds in precautions to safeguard against significant ethical issues, such as avoiding the researchers' exposure to pornographic material, and legal concerns, which were justified as some of the images were classified as child exploitation material. We use it to perform a longitudinal measurement of eWhoring activities in 10 specialised underground forums from 2008 to 2019. Our study focuses on three of the main eWhoring components: (i) the acquisition and provenance of images; (ii) the financial profits and monetisation techniques; and (iii) a social network analysis of the offenders, including their relationships, interests, and pathways before and after engaging in this fraudulent activity. We provide recommendations, including potential intervention approaches. Sergio Pastrana, Alice Hutchings, Daniel R. Thomas, Juan Tapiador |
Internet Measurement Conference | 4 |
| 2019 | AndrODet: An adaptive Android obfuscation detectorabstractObfuscation techniques modify an app’s source (or machine) code in order to make it more difficult to analyze. This is typically applied to protect intellectual property in benign apps, or to hinder the process of extracting actionable information in the case malware. Since malware analysis often requires considerable resource investment, detecting the particular obfuscation technique used may contribute to apply the right analysis tools, thus leading to some savings. In this paper, we propose AndrODet , a mechanism to detect three popular types of obfuscation in Android applications, namely identifier renaming, string encryption, and control flow obfuscation. AndrODet leverages online learning techniques, thus being suitable for resource-limited environments that need to operate in a continuous manner. We compare our results with a batch learning algorithm using a dataset of 34,962 apps from both malware and benign apps. Experimental results show that online learning approaches are not only able to compete with batch learning methods in terms of accuracy, but they also save significant amount of time and computational resources. Particularly, AndrODet achieves an accuracy of 92.02% for identifier renaming detection, 81.41% for string encryption detection, and 68.32% for control flow obfuscation detection, on average. Also, the overall accuracy of the system when apps might be obfuscated with more than one technique is around 80.66%. Omid Mirzaei, José María de Fuentes, Juan Tapiador, Lorena González-Manzano |
Future Gener. Comput. Syst. | 3 |
| 2019 | Feasibility analysis of Inter-Pulse Intervals based solutions for cryptographic token generation by two electrocardiogram sensors
Lara Ortiz-Martin, Pablo Picazo-Sanchez, Pedro Peris-Lopez, Juan Tapiador, Gerardo Schneider |
Future Gener. Comput. Syst. | 4 |
| 2019 | The MalSource Dataset: Quantifying Complexity and Code Reuse in Malware DevelopmentabstractDuring the last decades, the problem of malicious and unwanted software (malware) has surged in numbers and sophistication. Malware plays a key role in most of today's cyberattacks and has consolidated as a commodity in the underground economy. In this paper, we analyze the evolution of malware from 1975 to date from a software engineering perspective. We analyze the source code of 456 samples from 428 unique families and obtain measures of their size, code quality, and estimates of the development costs (effort, time, and number of people). Our results suggest an exponential increment of nearly one order of magnitude per decade in aspects such as size and estimated effort, with code quality metrics similar to those of benign software. We also study the extent to which code reuse is present in our dataset. We detect a significant number of code clones across malware families and report which features and functionalities are more commonly shared. Overall, our results support claims about the increasing complexity of malware and its production progressively becoming an industry. Alejandro Calleja, Juan Tapiador, Juan Caballero |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | Beyond Google Play: A Large-Scale Comparative Study of Chinese Android App Markets
Haoyu Wang 0001, Zhe Liu 0001, Jingyue Liang, Narseo Vallina-Rodriguez, Yao Guo 0001, Li Li 0029, Juan Tapiador, Jingcun Cao, Guoai Xu |
Internet Measurement Conference | 7 |
| 2018 | Picking on the family: Disrupting android malware triage by forcing misclassificationabstractMachine learning classification algorithms are widely applied to different malware analysis problems because of their proven abilities to learn from examples and perform relatively well with little human input. Use cases include the labelling of malicious samples according to families during triage of suspected malware. However, automated algorithms are vulnerable to attacks. An attacker could carefully manipulate the sample to force the algorithm to produce a particular output. In this paper we discuss one such attack on Android malware classifiers. We design and implement a prototype tool, called IagoDroid, that takes as input a malware sample and a target family, and modifies the sample to cause it to be classified as belonging to this family while preserving its original semantics. Our technique relies on a search process that generates variants of the original sample without modifying their semantics. We tested IagoDroid against RevealDroid, a recent, open source, Android malware classifier based on a variety of static features. IagoDroid successfully forces misclassification for 28 of the 29 representative malware families present in the DREBIN dataset. Remarkably, it does so by modifying just a single feature of the original malware. On average, it finds the first evasive sample in the first search iteration, and converges to a 100% evasive population within 4 iterations. Finally, we introduce RevealDroid*, a more robust classifier that implements several techniques proposed in other adversarial learning domains. Our experiments suggest that RevealDroid* can correctly detect up to 99% of the variants generated by IagoDroid. Alejandro Calleja, Alejandro Martín, Héctor D. Menéndez 0001, Juan Tapiador, David Clark 0001 |
Expert Syst. Appl. | 4 |
| 2017 | TriFlow: Triaging Android Applications using Speculative Information FlowsabstractInformation flows in Android can be effectively used to give an informative summary of an application's behavior, showing how and for what purpose apps use specific pieces of information. This has been shown to be extremely useful to characterize risky behaviors and, ultimately, to identify unwanted or malicious applications in Android. However, identifying information flows in an application is computationally highly expensive and, with more than one million apps in the Google Play market, it is critical to prioritize applications that are likely to pose a risk. In this work, we develop a triage mechanism to rank applications considering their potential risk. Our approach, called TriFlow, relies on static features that are quick to obtain. TriFlow combines a probabilistic model to predict the existence of information flows with a metric of how significant a flow is in benign and malicious apps. Based on this, TriFlow provides a score for each application that can be used to prioritize analysis. TriFlow also provides an explanatory report of the associated risk. We evaluate our tool with a representative dataset of benign and malicious Android apps. Our results show that it can predict the presence of information flows very accurately and that the overall triage mechanism enables significant resource saving. Omid Mirzaei, Guillermo Suarez-Tangil, Juan Tapiador, José María de Fuentes |
AsiaCCS | 3 |
| 2017 | PRACIS: Privacy-preserving and aggregatable cybersecurity information sharing
José María de Fuentes, Lorena González-Manzano, Juan Tapiador, Pedro Peris-Lopez |
Comput. Secur. | 3 |
| 2016 | AVRAND: A Software-Based Defense Against Code Reuse Attacks for AVR Embedded Devices
Sergio Pastrana, Juan Tapiador, Guillermo Suarez-Tangil, Pedro Peris-Lopez |
DIMVA | 2 |
| 2016 | A Look into 30 Years of Malware Development from a Software Metrics Perspective
Alejandro Calleja, Juan Tapiador, Juan Caballero |
RAID | 2 |
| 2016 | A New TRNG Based on Coherent Sampling With Self-Timed RingsabstractRandom numbers play a key role in applications such as industrial simulations, laboratory experimentation, computer games, and engineering problem solving. The design of new true random generators (TRNGs) has attracted the attention of the research community for many years. Designs with little hardware requirements and high throughput are demanded by new and powerful applications. In this paper, we introduce the design of a novel TRNG based on the coherent sampling (CS) phenomenon. Contrary to most designs based on this phenomenon, ours uses self-timed rings (STRs) instead of the commonly employed ring oscillators (ROs). Our design has two key advantages over existing proposals based on CS. It does not depend on the FPGA vendor used and does not need manual placement and routing in the manufacturing process, resulting in a highly portable generator. Our experiments show that the TRNG offers a very high throughput with a moderate cost in hardware. The results obtained with ENT, DIEHARD, and National Institute of Standards and Technology (NIST) statistical test suites evidence that the output bitstream behaves as a truly random variable. Honorio Martín, Pedro Peris-Lopez, Juan Tapiador, Enrique San Millán |
IEEE Trans. Ind. Informatics | 3 |
| 2016 | Alterdroid: Differential Fault Analysis of Obfuscated Smartphone MalwareabstractMalware for smartphones has rocketed over the last years. Market operators face the challenge of keeping their stores free from malicious apps, a task that has become increasingly complex as malware developers are progressively using advanced techniques to defeat malware detection tools. One such technique commonly observed in recent malware samples consists of hiding and obfuscating modules containing malicious functionality in places that static analysis tools overlook (e.g., within data objects). In this paper, we describe Alterdroid, a dynamic analysis approach for detecting such hidden or obfuscated malware components distributed as parts of an app package. The key idea in Alterdroid consists of analyzing the behavioral differences between the original app and a number of automatically generated versions of it, where a number of modifications (faults) have been carefully injected. Observable differences in terms of activities that appear or vanish in the modified app are recorded, and the resulting differential signature is analyzed through a pattern-matching process driven by rules that relate different types of hidden functionalities with patterns found in the signature. A thorough justification and a description of the proposed model are provided. The extensive experimental results obtained by testing Alterdroid over relevant apps and malware samples support the quality and viability of our proposal. Guillermo Suarez-Tangil, Juan Tapiador, Flavio Lombardi, Roberto Di Pietro |
IEEE Trans. Mob. Comput. | 2 |
| 2015 | Compartmentation Policies for Android Apps: A Combinatorial Optimization Approach
Guillermo Suarez-Tangil, Juan Tapiador, Pedro Peris-Lopez |
NSS | 2 |
| 2015 | Electrical Heart Signals can be Monitored from the Moon: Security Implications for IPI-Based Protocols
Alejandro Calleja, Pedro Peris-Lopez, Juan Tapiador |
WISTP | 3 |
| 2015 | Probabilistic yoking proofs for large scale IoT systems
José María de Fuentes, Pedro Peris-Lopez, Juan Tapiador, Sergio Pastrana |
Ad Hoc Networks | 3 |
| 2015 | DEFIDNET: A framework for optimal allocation of cyberdefenses in Intrusion Detection Networks
Sergio Pastrana, Juan Tapiador, Agustín Orfila, Pedro Peris-Lopez |
Comput. Networks | 2 |
| 2015 | Automatic generation of HTTP intrusion signatures by selective identification of anomalies
Pedro García-Teodoro, Jesús Esteban Díaz Verdejo, Juan Tapiador, Rolando Salazar-Hernández |
Comput. Secur. | 3 |
| 2015 | Security and privacy issues in implantable medical devices: A comprehensive survey
Carmen Camara, Pedro Peris-Lopez, Juan Tapiador |
J. Biomed. Informatics | 3 |
| 2015 | Hindering data theft with encrypted data trees
Jorge Blasco Alís, Juan Tapiador, Pedro Peris-Lopez, Guillermo Suarez-Tangil |
J. Syst. Softw. | 2 |
| 2015 | Power-aware anomaly detection in smartphones: An analysis of on-platform versus externalized operation
Guillermo Suarez-Tangil, Juan Tapiador, Pedro Peris-Lopez, Sergio Pastrana |
Pervasive Mob. Comput. | 2 |
| 2015 | Key-Recovery Attacks on KIDS, a Keyed Anomaly Detection SystemabstractMost anomaly detection systems rely on machine learning algorithms to derive a model of normality that is later used to detect suspicious events. Some works conducted over the last years have pointed out that such algorithms are generally susceptible to deception, notably in the form of attacks carefully constructed to evade detection. Various learning schemes have been proposed to overcome this weakness. One such system is Keyed IDS (KIDS), introduced at DIMVA “10. KIDS” core idea is akin to the functioning of some cryptographic primitives, namely to introduce a secret element (the key) into the scheme so that some operations are infeasible without knowing it. In KIDS the learned model and the computation of the anomaly score are both key-dependent, a fact which presumably prevents an attacker from creating evasion attacks. In this work we show that recovering the key is extremely simple provided that the attacker can interact with KIDS and get feedback about probing requests. We present realistic attacks for two different adversarial settings and show that recovering the key requires only a small amount of queries, which indicates that KIDS does not meet the claimed security properties. We finally revisit KIDS' central idea and provide heuristic arguments about its suitability and limitations. Juan Tapiador, Agustín Orfila, Arturo Ribagorda, Benjamín Ramos |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2014 | Stegomalware: Playing Hide and Seek with Malicious Components in Smartphone Apps
Guillermo Suarez-Tangil, Juan Tapiador, Pedro Peris-Lopez |
Inscrypt | 2 |
| 2014 | Detecting Targeted Smartphone Malware with Behavior-Triggering Stochastic Models
Guillermo Suarez-Tangil, Mauro Conti, Juan Tapiador, Pedro Peris-Lopez |
ESORICS (1) | 3 |
| 2014 | Trustworthy placements: Improving quality and resilience in collaborative attack detection
Manuel Gil Pérez, Juan Tapiador, John A. Clark, Gregorio Martínez Pérez, Antonio F. Skarmeta |
Comput. Networks | 2 |
| 2014 | Dendroid: A text mining approach to analyzing and classifying code structures in Android malware families
Guillermo Suarez-Tangil, Juan Tapiador, Pedro Peris-Lopez, Jorge Blasco Alís |
Expert Syst. Appl. | 2 |
| 2014 | Randomized Anagram revisited
Sergio Pastrana, Agustín Orfila, Juan Tapiador, Pedro Peris-Lopez |
J. Netw. Comput. Appl. | 3 |
| 2014 | Weaknesses in a new ultralightweight RFID authentication protocol with permutation - RAPPabstractABSTRACT Tian et al. proposed a novel ultralightweight RFID mutual authentication protocol [1] that has recently been analyzed in several articles. In this letter, we first propose a desynchronization attack that succeeds with probability almost 1, which improves upon the 0.25 given in a previous analysis by Ahmadian et al. We also show that the bad properties of the proposed permutation function can be exploited to disclose several bits of the tag's secret (rather than just 1 bit as previously shown by Avoine et al.), which increases the power of a traceability attack. Finally, we show how to extend the aforementioned attack to run a full disclosure attack, which requires to eavesdrop less protocol runs than the proposed attack by Wang et al. (i.e., 192 < < 2 30). Copyright © 2013 John Wiley & Sons, Ltd. Nasour Bagheri, Masoumeh Safkhani, Pedro Peris-Lopez, Juan Tapiador |
Secur. Commun. Networks | 4 |
| 2014 | An Estimator for the ASIC Footprint Area of Lightweight Cryptographic AlgorithmsabstractIn resource-constrained devices such as RFID tags or implantable medical devices, algorithm designers need to make careful choices to ensure that their proposals are sufficiently efficient for the target platform. A common way of expressing such restrictions is in terms of an upper bound for the maximum available footprint area in gate equivalents (GE). For example, RFID tags conforming to standards EPC Class-1 Generation-2 and ISO/IEC 18000-6C can devote up to 4K GE to security functions. However, in most cases, algorithm designers are not hardware experts, nor they have any quantitative means to find out how much area their designs would occupy in a given technology. In this paper, we attempt to fill this gap by providing an estimate of the upper bound for the footprint area of any algorithm. Our approach takes into account the main components of such algorithms, namely, basic arithmetic/logic operations and additional hardware such as registers and multiplexers. We believe that our proposal can help designers in making informed decisions about what kind of algorithmic structures can be afforded for a target environment. Honorio Martín, Pedro Peris-Lopez, Juan Tapiador, Enrique San Millán |
IEEE Trans. Ind. Informatics | 3 |
| 2012 | Bypassing information leakage protection with trusted applications
Jorge Blasco Alís, Julio César Hernández Castro, Juan Tapiador, Arturo Ribagorda |
Comput. Secur. | 3 |
| 2011 | Masquerade mimicry attack detection: A randomised approach
Juan Tapiador, John A. Clark |
Comput. Secur. | 1 |
| 2011 | Cryptanalysis of an EPC Class-1 Generation-2 standard compliant authentication protocol
Pedro Peris-Lopez, Julio César Hernández Castro, Juan Tapiador, Jan C. A. van der Lubbe |
Eng. Appl. Artif. Intell. | 3 |
| 2010 | Quasi-Linear Cryptanalysis of a Secure RFID Ultralightweight Authentication Protocol
Pedro Peris-Lopez, Julio César Hernández Castro, Raphael C.-W. Phan, Juan Tapiador, Tieyan Li |
Inscrypt | 4 |
| 2010 | Fine-Grained Timing Using Genetic Programming
David Robert White, Juan Tapiador, Julio César Hernández Castro, John A. Clark |
EuroGP | 2 |
| 2010 | Information-Theoretic Detection of Masquerade Mimicry AttacksabstractIn a masquerade attack, an adversary who has stolen a legitimate user's credentials attempts to impersonate him to carry out malicious actions. Automatic detection of such attacks is often undertaken constructing models of normal behaviour of each user and then measuring significant departures from them. One potential vulnerability of this approach is that anomaly detection algorithms are generally susceptible of being deceived. In this paper, we first investigate how a resourceful masquerader can successfully evade detection while still accomplishing his goals. We then propose an algorithm based on the Kullback-Leibler divergence which attempts to identify if a sufficiently anomalous attack is present within an apparently normal request. Our experimental results indicate that the proposed scheme achieves considerably better detection quality than adversarial-unaware approaches. Juan Tapiador, John A. Clark |
NSS | 1 |
| 2010 | Risk based Access Control with Uncertain and Time-dependent Sensitivity
John A. Clark, Juan Tapiador, John A. McDermid, Pau-Chen Cheng, Dakshi Agrawal, Natalie Ivanic, Dave Slogget |
SECRYPT | 2 |
| 2010 | Vulnerability analysis of RFID protocols for tag ownership transfer
Pedro Peris-Lopez, Julio César Hernández Castro, Juan Tapiador, Tieyan Li, Yingjiu Li |
Comput. Networks | 3 |
| 2009 | Weaknesses in Two Recent Lightweight RFID Authentication Protocols
Pedro Peris-Lopez, Julio César Hernández Castro, Juan Tapiador, Tieyan Li, Jan C. A. van der Lubbe |
Inscrypt | 3 |
| 2009 | Metaheuristic traceability attack against SLMAP, an RFID lightweight authentication protocolabstractWe present a metaheuristic-based attack against the traceability of an ultra-lightweight authentication protocol for RFID environments called SLMAP, and analyse its implications. The main interest of our approach is that it is a complete black-box technique that doesn't make any assumptions on the components of the underlying protocol and can thus be easily generalised to analyse many other proposals. Julio César Hernández Castro, Juan Tapiador, Pedro Peris-Lopez, John A. Clark, El-Ghazali Talbi |
IPDPS | 2 |
| 2009 | Steganalysis of Hydan
Jorge Blasco Alís, Julio César Hernández Castro, Juan Tapiador, Arturo Ribagorda, Miguel A. Orellana-Quiros |
SEC | 3 |
| 2009 | Practical attacks on a mutual authentication scheme under the EPC Class-1 Generation-2 standard
Pedro Peris-Lopez, Tieyan Li, Julio César Hernández Castro, Juan Tapiador |
Comput. Commun. | 4 |
| 2008 | On the Salsa20 Core Function
Julio César Hernández Castro, Juan Tapiador, Jean-Jacques Quisquater |
FSE | 2 |
| 2008 | Nature-Inspired Synthesis of Rational Protocols
Almudena Alcaide, Juan Tapiador, Julio César Hernández Castro, Arturo Ribagorda |
PPSN | 2 |
| 2008 | CSteg: Talking in C Code - Steganography of C Source Code in Text
Jorge Blasco Alís, Julio César Hernández Castro, Juan Tapiador, Arturo Ribagorda |
SECRYPT | 3 |
| 2008 | Secure content access and replication in pure P2P networks
Esther Palomar, Juan Tapiador, Julio César Hernández Castro, Arturo Ribagorda |
Comput. Commun. | 2 |
| 2008 | On the Distinguishability of Distance-Bounded Permutations in Ordered ChannelsabstractOrdered channels, such as those provided by Internet protocol and transmission control protocol protocols, rely on sequence numbers to recover from packet reordering due to network dynamics. The existence of covert channels in any ordered channel is a well-known fact: Two parties can reorder the elements (packets) to be sent according to some predefined code. Schemes based on distance-bounded permutations have been proposed for steganographic communication with the aim of keeping and controling the increase of latency due to reordering. In this paper, we demonstrate that distance-bounded permutations are highly anomalous from a metric point of view. Our analysis is based on the study of the distribution of distances between normal permutations generated by the channel, and those produced when embedding hidden information. We provide results for four different distances: Kendall's tau, Spearman's rho, Spearman's footrule, and Levenshtein's distance (which is equivalent to Ulam's distance for permutations). In all cases, it is shown how sequences with hidden information can be separated from the normal ones. As a result, very accurate and efficient distinguishers can be easily constructed. Finally, we study the detection capabilities of the associated detectors through a receiver operating characteristic analysis. Juan Tapiador, Julio César Hernández Castro, Almudena Alcaide, Arturo Ribagorda |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2007 | Heuristic search for non-linear cryptanalytic approximationsabstractIn this work, we show that heuristic techniques (particularly Simulated Annealing) can be successfully applied in the search of good non-linear approximations of cryptographic primitives. We also provide some experimental results, including two excellent non-linear approximations for the output of the Salsa20 stream cipher with 2 and 4 rounds. From these two approximations, very efficient distinguishers for Salsa20 could easily be obtained, leading to a much more practical attack that any other published so far against this cipher. Juan Tapiador, Julio César Hernández Castro, John A. Clark |
IEEE Congress on Evolutionary Computation | 1 |
| 2007 | Non-linear Cryptanalysis Revisited: Heuristic Search for Approximations to S-Boxes
Juan Tapiador, John A. Clark, Julio César Hernández Castro |
IMACC | 1 |
| 2006 | Wheedham: An Automatically Designed Block Cipher by means of Genetic ProgrammingabstractIn this work, we present a general scheme for the design of block ciphers by means of Genetic Programming. In this vein, we try to evolve highly nonlinear and efficient functions to be used for the key expansion and the F-function of a Feistel network. Following this scheme, we propose a new block cipher design called Wheedham, that operates on 512 bit blocks and keys of 256 bits, of which we offer its C code (directly translated from the GP Trees) and some preliminary security results. Julio César Hernández Castro, Juan Tapiador, Arturo Ribagorda, Benjamín Ramos |
IEEE Congress on Evolutionary Computation | 2 |
| 2006 | Certificate-based Access Control in Pure P2P NetworksabstractPure peer-to-peer (P2P) networks are characterized as being extremely decentralized and self-organized, properties which are essential in a number of environments, including teamwork, collaborative, and ad-hoc systems. One of the features offered by P2P networks is the possibility of having several replicas of the same content distributed among multiple nodes. Despite its advantages (e.g. robustness and fault tolerance), it is crucial to guarantee content authenticity, as well as to enforce appropriate access control policies. However, the extremely decentralized nature of these environments makes impossible to apply classic solutions that rely on some kind of fixed infrastructure, typically in the form of on-line trusted third parties. In a previous work, we presented a protocol for content authentication based on public key certificates that does not rely on the existence of a public key infrastructure. In this paper, we show how these certificates can be extended to provide authorization capabilities. In our scheme, each peer classifies her contents according to several security labels. Peers allowed to access a given content must have a security clearance of at least the same level that the content's. These security clearances, which take the form of attributes in public key certificates, can be discretionally issued by the content provider Esther Palomar, Juan Tapiador, Julio César Hernández Castro, Arturo Ribagorda |
Peer-to-Peer Computing | 2 |
| 2006 | Lamar: A New Pseudorandom Number Generator Evolved by Means of Genetic Programming
Carlos Lamenca-Martinez, Julio César Hernández Castro, Juan Tapiador, Arturo Ribagorda |
PPSN | 3 |
| 2006 | M2AP: A Minimalist Mutual-Authentication Protocol for Low-Cost RFID Tags
Pedro Peris-Lopez, Julio César Hernández Castro, Juan Tapiador, Arturo Ribagorda |
UIC | 3 |
| 2006 | Steganography in games: A general methodology and its application to the game of Go
Julio César Hernández Castro, Ignacio Blasco-Lopez, Juan Tapiador, Arturo Ribagorda |
Comput. Secur. | 3 |
| 2005 | A Formal Analysis of Fairness and Non-repudiation in the RSA-CEGD Protocol
Almudena Alcaide, Juan Tapiador, Antonio Izquierdo Manzanares, José María Sierra |
ICCSA (4) | 2 |
| 2005 | Attacks on Port Knocking Authentication Mechanism
Antonio Izquierdo Manzanares, Joaquín Torres Márquez, Juan Tapiador, Julio César Hernández Castro |
ICCSA (4) | 3 |
| 2005 | Detection of Web-Based Attacks through Markovian Protocol ParsingabstractThis paper presents a novel approach based on the monitoring of incoming HTTP requests to detect attacks against Web servers. The detection is accomplished through a Markovian model whose states and transitions between them are determined from the specification of the HTTP protocol while the probabilities of the symbols associated to the Markovian source are obtained during a training stage according to a set of attack-free requests for the target server. The experiments carried out show a high detection capability with low false positive rates at reasonable computation requirements. Juan Tapiador, Pedro García-Teodoro, Jesús Esteban Díaz Verdejo |
ISCC | 1 |
| 2005 | PIM-DM Cost Analysis in Loop Free TopologiesabstractThis paper presents an approach to estimate the cost of the PIM-DM protocol in terms of the number of packets, both for data and control traffic. The proposed approach assumes a loop-free network topology and that all links have equal parameters. Although restrictive at a first glance, the results show a good performance in simulated real networks when mean values for the parameters are used. The expressions are deduced from the protocol functioning, overcoming limitations and approximations of previously published works. Gabriel Maciá-Fernández, Jesús Esteban Díaz Verdejo, Juan Tapiador |
ISCC | 3 |
| 2004 | N3: A Geometrical Approach for Network Intrusion Detection at the Application Layer
Juan Tapiador, Pedro García-Teodoro, Jesús Esteban Díaz Verdejo |
ICCSA (1) | 1 |
| 2004 | Measuring normality in HTTP traffic for anomaly-based intrusion detection
Juan Tapiador, Pedro García-Teodoro, Jesús Esteban Díaz Verdejo |
Comput. Networks | 1 |
| 2004 | Anomaly detection methods in wired networks: a survey and taxonomy
Juan Tapiador, Pedro García-Teodoro, Jesús Esteban Díaz Verdejo |
Comput. Commun. | 1 |
| 2003 | NSDF: a computer network system description framework and its application to network security
Juan Tapiador, Pedro García-Teodoro, Jesús Esteban Díaz Verdejo |
Comput. Networks | 1 |