Research

The CyberCARDS team carries out fundamental and applied research aimed at understanding, modeling and countering the threats facing today's computer systems and digital infrastructures. Our scientific identity rests on a rigorous approach combining formal proofs, experimental analysis and transfer to industry.

Our work spans a broad spectrum: designing and analyzing cryptographic primitives resistant to classical and quantum attacks, detecting intrusions and analyzing malware in networks and embedded systems, formally verifying security protocols and critical software, and designing mechanisms that guarantee privacy protection in distributed systems and large-scale data processing.

This work is carried out through national and international collaborations, with academic and industrial partners, and leads to regular contributions to the field's reference conferences and journals, as well as to the development of open-source software made available to the community.

Research Themes

Assurance, Audit, and Certification

Independent evidence that systems meet their security claims: assurance cases, security audits, structured assessment methods, and certification processes for critical software and infrastructure.

Learn more

Human Aspects

The human side of security: social engineering, insider risk, socio-technical security, and how people perceive and interact with security mechanisms, so systems stay secure in practice, not just on paper.

Learn more

Legal Aspects

The regulatory and societal dimensions of cybersecurity: analysis and design of cybersecurity regulation, support for cybercrime investigations, and the legal and societal issues raised by security policy.

Learn more

Security Management and Governance

Risk, threat, and governance frameworks that keep organizations secure and resilient: risk and attack modeling (including adversarial machine learning), information security standards, incident and business-continuity governance, regulatory compliance, and the economics of cybersecurity.

Learn more

Software and System Security Engineering

Building security into software and systems from the ground up: secure-by-design architectures, model-driven and formal specification of security properties, security design patterns, and rigorous validation across the full engineering lifecycle.

Learn more