<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
<title>IMDEA Networks</title>
<link href="https://hdl.handle.net/20.500.12761/1" rel="alternate"/>
<subtitle/>
<id>https://hdl.handle.net/20.500.12761/1</id>
<updated>2026-07-21T20:30:00Z</updated>
<dc:date>2026-07-21T20:30:00Z</dc:date>
<entry>
<title>Crime VIP: A Closed-Access Underground Hacking Forum</title>
<link href="https://hdl.handle.net/20.500.12761/2058" rel="alternate"/>
<author>
<name>Mischinger, Mariella</name>
</author>
<author>
<name>Pastrana, Sergio</name>
</author>
<author>
<name>Suarez-Tangil, Guillermo</name>
</author>
<id>https://hdl.handle.net/20.500.12761/2058</id>
<updated>2026-07-18T00:00:09Z</updated>
<published>2026-05-01T00:00:00Z</published>
<summary type="text">Crime VIP: A Closed-Access Underground Hacking Forum
Mischinger, Mariella; Pastrana, Sergio; Suarez-Tangil, Guillermo
We present XIN, the dataset of a closed-access Russian-English underground hacking forum. It contains a collection of ≈1.3M posts from over 20 years (Feb 2005-Aug 2025), and --- to the best of our knowledge --- is the largest collection of a closed-access underground hacking forum available for research. While there is a wide range of underground forum datasets available, there is a lack of non-English forums, and especially closed-access forums. Those are particularly challenging to crawl as the access is gated. Hence, a limited few-shot opportunity requires extreme care when crawling to avoid detection, which leads to account banning. Our stealthy data collection spanned 5 years (2020-2025). &#13;
&#13;
The statistical analysis of our data mirrors how cybercrime gradually shifted from technical, hands-on hacking to an industry where different building blocks can be assembled and applied in the absence of a broad or profound technical understanding. This dataset will contribute to a more complete evaluation of the cybercriminal landscape, shedding light on the activity that happens in closed-door, non-English communities.
</summary>
<dc:date>2026-05-01T00:00:00Z</dc:date>
</entry>
<entry>
<title>An Agent-Orchestrated Anomaly Detection Pipeline for Network Performance</title>
<link href="https://hdl.handle.net/20.500.12761/2057" rel="alternate"/>
<author>
<name>Rachiele, Luigi</name>
</author>
<author>
<name>Mancuso, Vincenzo</name>
</author>
<author>
<name>Ramirez, Juan Marcos</name>
</author>
<id>https://hdl.handle.net/20.500.12761/2057</id>
<updated>2026-07-17T00:00:13Z</updated>
<published>2026-07-03T00:00:00Z</published>
<summary type="text">An Agent-Orchestrated Anomaly Detection Pipeline for Network Performance
Rachiele, Luigi; Mancuso, Vincenzo; Ramirez, Juan Marcos
Today's telecom anomaly detection relies on hand-engineered pipelines that break whenever data or scenario shifts. We propose a reasoning agent that builds, tunes, and explains its own detection pipeline by orchestrating tools in an adaptive loop, thereby turning a brittle process into an auditable one and laying the foundation for agentic reasoning on cellular networks.
</summary>
<dc:date>2026-07-03T00:00:00Z</dc:date>
</entry>
<entry>
<title>Island-Ready 5G Deployments: Decentralized Core Networks Enabling Crisis Connectivity at the Edge</title>
<link href="https://hdl.handle.net/20.500.12761/2056" rel="alternate"/>
<author>
<name>Janzen, Leon</name>
</author>
<author>
<name>Bloessl, Bastian</name>
</author>
<author>
<name>Hollick, Matthias</name>
</author>
<id>https://hdl.handle.net/20.500.12761/2056</id>
<updated>2026-07-16T00:00:14Z</updated>
<published>2026-06-01T00:00:00Z</published>
<summary type="text">Island-Ready 5G Deployments: Decentralized Core Networks Enabling Crisis Connectivity at the Edge
Janzen, Leon; Bloessl, Bastian; Hollick, Matthias
The concept of island readiness envisions that communication networks can fall back to local connectivity islands when global connectivity breaks, e.g., after natural disasters or targeted attacks. Island connectivity would enable users to use crisis-relevant applications hosted at the local edge during crisis response. However, realizing island readiness involves many stakeholders, and this paper is the first to consider the perspective of mobile network operators (MNOs). This paper explains why today’s 5G-Advanced deployments are not island-ready and outlines the options MNOs have to support island connectivity. We introduce a design for island-ready 5G and beyond core networks and demonstrate its functionality in an end-to-end lab testbed with commercial smartphones.
</summary>
<dc:date>2026-06-01T00:00:00Z</dc:date>
</entry>
<entry>
<title>DEMO: Recent Advancements in Detecting Cellular Attacks with CellGuard</title>
<link href="https://hdl.handle.net/20.500.12761/2055" rel="alternate"/>
<author>
<name>Lange, Swantje</name>
</author>
<author>
<name>Arnold, Lukas</name>
</author>
<author>
<name>Paß, Maximillian</name>
</author>
<author>
<name>Hollick, Matthias</name>
</author>
<author>
<name>Classen, Jiska</name>
</author>
<id>https://hdl.handle.net/20.500.12761/2055</id>
<updated>2026-07-16T00:00:18Z</updated>
<published>2026-06-29T00:00:00Z</published>
<summary type="text">DEMO: Recent Advancements in Detecting Cellular Attacks with CellGuard
Lange, Swantje; Arnold, Lukas; Paß, Maximillian; Hollick, Matthias; Classen, Jiska
A viable remote attack surface of smartphones is the baseband chip, which handles the communication with cellular networks. One attack that is often conducted, e.g., to track users, is the deployment of Rogue Base Stations (RBSs). We built and actively maintain CellGuard, an iOS app that analyzes the interaction of an iPhone with its baseband chip to detect whether the phone connects to an RBS. In this demo, we showcase CellGuard's base functionality of dissecting baseband communication packets and assessing nearby cells for trustworthiness, as well as recent developments. We present the latest changes to the app, including support for Apple's new C1 and C1X baseband chips, architectural improvements, user interface enhancements, and additional notifications for suspicious baseband activity.
</summary>
<dc:date>2026-06-29T00:00:00Z</dc:date>
</entry>
</feed>
