Magaña Lizarrondo, Eduardo
Loading...
Email Address
person.page.identifierURI
Birth Date
Job Title
Last Name
Magaña Lizarrondo
First Name
Eduardo
person.page.departamento
Ingeniería Eléctrica, Electrónica y de Comunicación
person.page.instituteName
ISC. Institute of Smart Cities
ORCID
person.page.observainves
person.page.upna
Name
- Publications
- item.page.relationships.isAdvisorOfPublication
- item.page.relationships.isAdvisorTFEOfPublication
- item.page.relationships.isAuthorMDOfPublication
55 results
Search Results
Now showing 1 - 10 of 55
Publication Open Access The European Traffic Observatory Measurement Infraestructure (ETOMIC): a testbed for universal active and passive measurements(IEEE, 2005) Morató Osés, Daniel; Magaña Lizarrondo, Eduardo; Izal Azcárate, Mikel; Aracil Rico, Javier; Naranjo Abad, Francisco José; Alonso Camaró, Ulisses; Astiz Saldaña, Francisco Javier; Vattay, Gábor; Csabai, István; Hága, Péter; Simon, Gábor; Stéger, József; Automática y Computación; Automatika eta KonputazioaThe European Traffic Observatory is a European Union VI Framework Program sponsored effort, within the Integrated Project EVERGROW, that aims at providing a paneuropean traffic measurement infrastructure with highprecision, GPS-synchronized monitoring nodes. This paper describes the system and node architectures, together with the management system. On the other hand, we also present the testing platform that is currently being used for testing ETOMIC nodes before actual deployment.Publication Open Access Techniques for better alias resolution in Internet topology discovery(IEEE, 2009) García-Jiménez, Santiago; Magaña Lizarrondo, Eduardo; Morató Osés, Daniel; Izal Azcárate, Mikel; Automática y Computación; Automatika eta KonputazioaOne of the challenging problems related with network topology discovery in Internet is the process of IP address alias identification. Topology information is usually obtained from a set of traceroutes that provide IP addresses of routers in the path from a source to a destination. If these traceroutes are repeated between several source/destination pairs we can get a sampling of all IP addresses for crossed routers. In order to generate the topology graph in which each router is a node, it is needed to identify all IP addresses that belong to the same router. In this work we propose improvements over existing methods to obtain alias identification related mainly with the types and options in probing packets.Publication Open Access Mejoras en la identificación de tráfico de aplicación basado en firmas(2008) Santolaya Bea, Néstor; Magaña Lizarrondo, Eduardo; Izal Azcárate, Mikel; Morató Osés, Daniel; Automática y Computación; Automatika eta KonputazioaTraffic identification has been based traditionally on transport protocol ports, associating always the same ports with the same applications. Nowadays that assumption is not true and new methods like signature identification or statistical techniques are applied. This work presents a method based on signature identification with some improvements. The use of regular expressions for typical applications has been studied deeply and its use has been improved in the aspects of percentage identification and resources consumption. On the other hand, a flows-record structure has been applied in order to classify those packets that do not verify any regular expression. Results are compared with the opensource related project L7-filter, and the improvements are presented. Finally, detailed regular expressions for analyzed applications are included in the paper, especially P2P applications.Publication Open Access Collecting packet traces at high speed(2006) Aguirre Cascallana, Gorka; Magaña Lizarrondo, Eduardo; Automática y Computación; Automatika eta KonputazioaIn order to capture packet traces at high speed using a low-cost platform, we have to optimize the networking stack of a general purpose operating system. Different techniques are compared with the final objective of avoiding packet loss. Among those techniques we will study the performance of NAPI [6] and PF-RING [9]. Depending on the final application, we should tune certain parameters accordingly. We also present the advantages of a multiprocessor platform and the problematic of storing full packets directly to hard disk.Publication Open Access Ransomware early detection by the analysis of file sharing traffic(Elsevier, 2018) Morató Osés, Daniel; Berrueta Irigoyen, Eduardo; Magaña Lizarrondo, Eduardo; Izal Azcárate, Mikel; Ingeniaritza Elektrikoa, Elektronikoaren eta Telekomunikazio Ingeniaritzaren; Institute of Smart Cities - ISC; Ingeniería Eléctrica, Electrónica y de ComunicaciónCrypto ransomware is a type of malware that locks access to user files by encrypting them and demands a ransom in order to obtain the decryption key. This type of malware has become a serious threat for most enterprises. In those cases where the infected computer has access to documents in network shared volumes, a single host can lock access to documents across several departments in the company. We propose an algorithm that can detect ransomware action and prevent further activity over shared documents. The algorithm is based on the analysis of passively monitored traffic by a network probe. 19 different ransomware families were used for testing the algorithm in action. The results show that it can detect ransomware activity in less than 20 s, before more than 10 files are lost. Recovery of even those files was also possible because their content was stored in the traffic monitored by the network probe. Several days of traffic from real corporate networks were used to validate a low rate of false alarms. This paper offers also analytical models for the probability of early detection and the probability of false alarms for an arbitrarily large population of users.Publication Open Access Detección de congestión en la Internet europea(IEEE, 2007) Hernández, Ana; Magaña Lizarrondo, Eduardo; Izal Azcárate, Mikel; Morató Osés, Daniel; Automática y Computación; Automatika eta KonputazioaIn this paper we present a study about the utilization of one-way delay measurements to detect and characterize network congestion in the european Internet. The experiments have been made using the ETOMIC platfom that allows one-way delay measurement with high precision timestamps. We have found a peculiar router behaviour in which the bottleneck is not the available bandwidth but it is the packet processing power of the router (backplane and CPU constraints). This router has been characterized with several network parameters. Some of them are the dependency of this limitation with the input data rate in packets per second, the size of burst packet losses measured in packets or time and the absence of specific scheduling algorithms in the router that could affect to larger flows.Publication Open Access Técnicas eficientes de filtrado y análisis de tráfico para la monitorización continua de redes de comunicaciones(1999) Ruiz, José Javier; Magaña Lizarrondo, Eduardo; Aracil Rico, Javier; Villadangos Alonso, Jesús; Automática y Computación; Automatika eta KonputazioaThis paper presents an efficient traffic filtering and analysis architecture for network monitoring. Opposed to the usual network monitoring architectures that provide simultaneous filters as requested by managers (packet filters), we propose a different approach that aims at minimizing CPU load by avoiding unnecessary filter duplicates. Such architecture makes it possible to optimize several parallel filters execution and thus is suitable for continuous network monitoring in which it is necessary to keep track of hundreds of filters. This architecture has been implemented in a network-monitoring tool called PROMIS whose main features are detailed in this paper.Publication Open Access Predicción de tráfico de Internet and aplicaciones(2001) Bernal, I.; Aracil Rico, Javier; Morató Osés, Daniel; Izal Azcárate, Mikel; Magaña Lizarrondo, Eduardo; Díez Marca, L. A.; Automática y Computación; Automatika eta KonputazioaIn this paper we focus on traffic prediction as a means to achieve dynamic bandwidth allocation in a generic Internet link. Our findings show that coarse prediction (bytes per interval) proves advantageous to perform dynamic link dimensioning, even if we consider a part of the top traffic producers in the traffic predictor.Publication Open Access Performance evaluation of client-based traffic sniffing for very large populations(Elsevier, 2019-11-09) Roquero, Paula; Magaña Lizarrondo, Eduardo; Leira, Rafael; Aracil Rico, Javier; Ingeniería Eléctrica, Electrónica y de Comunicación; Ingeniaritza Elektrikoa, Elektronikoa eta Telekomunikazio IngeniaritzaCurrent Internet users are demanding an increased mobility and service ubiquity, which, in turns, requires that Internet services are provided from different datacenters in the cloud. Traffic monitoring in such a mobile scenario, for security and QoS monitoring purposes, is rather challenging, as the sniffing points may be fully distributed in the operator's network. To complicate matters, out-going traffic may leave the network through a given PoP and return through a different one. As a result, traffic monitoring at the edges, at the very client terminal or domestic router, becomes a sensible alternative. However, such a measurement scheme implies that millions of tiny monitoring probes are contin- uously producing flow r ecords, which builds up a significant load fo r the monitoring data collector and for the network itself, aside from the induced load to the client terminal or router. In this paper, we study whether such large scale deployment of microsniffers is feasible in terms of the resulting load, namely deployment of lightweight network probes that perform passive measurements at the client terminal. We further propose data summarization schemes to reduce load with minimum information loss. Our findings show that deployment of a large populations of microsniffers is feasible, provided that adequate data thinning techniques are provided, as we propose in this paper.Publication Open Access Internet technologies course with combined professor and on-line contents methodology(IEEE, 2003) Magaña Lizarrondo, Eduardo; Morató Osés, Daniel; Automática y Computación; Automatika eta KonputazioaIn this paper we present the experience and results in the teaching of a course titled “Internet Technologies”. This course, offered in Public University of Navarra (Spain), uses a special methodology that combines in-classroom lectures in front of computers with on-line contents. The students work on the on-line course lesson at the same time that the professor is available in the classroom to help the students during the hours assigned to the course. The tool used to manage the on-line contents, tests, exercises and grades, was designed specially for this course. It incorporates a student profile classification based on the time used to solve the tests.