Logo of the University of Passau

Dr. Juan David Parra Rodriguez

Former Activities

I was a research assistant obtaining my Doctor degree at the IT security chair. In particular, I am interested in exploring unconventional attacks using HTML5 technologies to use the browser's resources as well as their countermeasures. I am currently working in the Semiotics project. Before that I was package leader for the security tasks in the AGILE project. The main focus of our work is on identity management, access and usage control of the data, and data provenance collection. I have previously also worked for the COMPOSE Project, where my tasks were related to identity management, data provenance, and reputation collection.

Research Interests

  • Parasitic computing
  • Unconventional attacks based on HTML5 technologies
  • Machine Learning methods applied to security
  • Internet of Things

Publications

2020

Computational Resource Abuse in Web Applications

J. D. Parra Rodriguez, "Computational Resource Abuse in Web Applications", 01 2020.

File: https://opus4.kobv.de/opus4-uni-passau/files/770/diss-parra-rodriguez.pdf

2019

A Generic Lightweight and Scalable Access Control Framework for IoT Gateways

J. D. Parra Rodriguez, "A Generic Lightweight and Scalable Access Control Framework for IoT Gateways" in Information Security Theory and Practice , Springer, 2019. pp. 207-222.

2018

CSP \& Co. Can Save Us from a Rogue Cross-Origin Storage Browser Network! But for How Long?

J. D. Parra Rodriguez and J. Posegga, "CSP \& Co. Can Save Us from a Rogue Cross-Origin Storage Browser Network! But for How Long?" in Proceedings of the Eighth ACM Conference on Data and Application Security and Privacy , New York, NY, USA: ACM, 2018. pp. 170--172.

DOI: 10.1145/3176258.3176951

ISBN: 978-1-4503-5632-9

File: http://doi.acm.org/10.1145/3176258.3176951

Local Storage on Steroids: Abusing Web Browsers for Hidden Content Storage and Distribution

J. D. Parra Rodriguez and J. Posegga, "Local Storage on Steroids: Abusing Web Browsers for Hidden Content Storage and Distribution" in Proc. of 14th EAI International Conference on Security and Privacy in Communication Networks (SECURECOMM) , 2018.

File: https://web.sec.uni-passau.de/papers/preprint-securecomm2018.pdf

RAPID: Resource and API-Based Detection Against In-Browser Miners

J. D. Parra Rodriguez and J. Posegga, "RAPID: Resource and API-Based Detection Against In-Browser Miners" in ACSAC 2018: Proceedings of the 34th Annual Computer Security Applications Conference , New York, NY, USA: ACM, 2018.

DOI: https://doi.org/10.1145/3274694.3274735

ISBN: 978-1-4503-6569-7/18/12

File: https://web.sec.uni-passau.de/papers/acsac2018-parra.pdf

Short Paper: Offloading Execution from Edge to Cloud: a Dynamic Node-RED Based Approach

R. Soza, C. Kiraly and J. D. Parra Rodriguez, "Short Paper: Offloading Execution from Edge to Cloud: a Dynamic Node-RED Based Approach" in {IEEE} 10th International Conference on Cloud Computing Technology and Science, CloudCom 2018, Cyprus, December 10-13, 2018 , 2018.

File: https://web.sec.uni-passau.de/papers/cloudcomm18-soza-preprint.pdf

When Your Browser Becomes the Paper Boy

J. D. Parra Rodriguez, E. Brehm and J. Posegga, "When Your Browser Becomes the Paper Boy" in ICT Systems Security and Privacy Protection , Janczewski, Lech Jan and Kutylowski, Miroslaw, Eds. Cham: Springer International Publishing, 2018. pp. 94--107.

ISBN: 978-3-319-99828-2

File: https://web.sec.uni-passau.de/papers/parra-ifisec-preprint18.pdf

2016

Addressing Data-Centric Security Requirements for IoT-Based Systems

J. D. Parra Rodriguez, D. Schreckling and J. Posegga, "Addressing Data-Centric Security Requirements for IoT-Based Systems" in {2016 International Workshop on Secure Internet of Things (SIoT)} , 2016. pp. 1-10.

DOI: https://doi.org/10.1109/SIoT.2016.007

2015

Data centric Security for IoT

D. Schreckling, J. D. Parra Rodriguez and J. Posegga, "Data centric Security for IoT" in {Proc. of 2nd EAI International Conference on IoT as a Service} , Springer, 2015.

Identity Management in Platforms Offering IoT as a Service

[English] J. D. Parra Rodriguez, D. Schreckling and J. Posegga, "Identity Management in Platforms Offering IoT as a Service" in Internet of Things. User-Centric IoT , Giaffreda, Raffaele and Vieriu, Radu-Laurentiu and Pasher, Edna and Bendersky, Gabriel and Jara, Antonio J. and Rodrigues, Joel J.P.C. and Dekel, Eliezer and Mandler, Benny, Eds. Springer International Publishing, 2015, pp. 281-288.

DOI: 10.1007/978-3-319-19656-5_40

ISBN: 978-3-319-19655-8

File: http://dx.doi.org/10.1007/978-3-319-19656-5_40

Why Servers Should Fear their Clients: Abusing Websockets in Browsers for DoS

J. D. Parra Rodriguez and J. Posegga, "Why Servers Should Fear their Clients: Abusing Websockets in Browsers for DoS" in Proc. of 11th EAI International Conference on Security and Privacy in Communication Networks (SECURECOMM) , 2015.

File: https://web.sec.uni-passau.de/papers/2015_Parra-WebSockets.pdf

I agree that a connection to the Vimeo server will be established when the video is played and that personal data (e.g. your IP address) will be transmitted.
I agree that a connection to the YouTube server will be established when the video is played and that personal data (e.g. your IP address) will be transmitted.
Show video