Manuel Suárez Román

Short bio
I’m a PhD Student at the Computer Security Lab (COSEC) from Universidad Carlos III de Madrid. I studied a double degree in mathematics and computer science at the Universidad Autonoma de Madrid and I specialized by studying a master’s degree in cybersecurity and another one in artificial intelligence. Before joining the lab, I previously worked in the Cryptology and nformation Security research group (GiCSI) and in the Cybersecurity and Privacy Protection research group (GiCP) of the Leonardo Torres Quevedo Institute, ITEFI, of the Spanish National Research Council (CSIC).
Research
My research interests sit at the intersection of cybersecurity, artificial intelligence, and cyber threat intelligence (CTI), with a focus on Advanced Persistent Threats (APTs). I develop graph- and learning-based methods that leverage system-level data provenance to detect, explain, and evaluate host-based APT activity, including work on causality-preserving metrics for provenance-based intrusion detection systems.
In parallel, I explore CTI problems around threat actor characterization, attribution, and the normalization of inconsistent naming taxonomies across vendors, using large-scale TTP and open-source intelligence signals.
Service
- Reviewer: Journal of Computers & Security.
Publications
Suarez-Roman, Manuel;
Tapiador, Juan.
Attack structure matters: Causality-preserving metrics for Provenance-based Intrusion Detection Systems.
Computers & Security.
Elsevier.

Suarez-Roman, Manuel;
Sanz-Rodrigo, Mario;
Marín-López, Andrés;
Arroyo, David.
A Digital Twin Threat Survey.
Big Data and Cognitive Computing.
MDPI.

de Paz, Alfonso; Suarez-Roman, Manuel; Palmero, Santiago; Degli-Esposti, Sara; Arroyo, David. Following Negationists on Twitter and Telegram: Application of NCD to the Analysis of Multiplatform Misinformation Dynamics. Lecture Notes in Networks and Systems. Proceedings of the International Conference on Ubiquitous Computing & Ambient Intelligence (UCAmI). Springer.
Degli-Esposti, Sara;
Suarez-Roman, Manuel.
La investigación en ciberseguridad en España.
IV Informe sobre la Ciencia y la Tecnología en España. Situar a España en el marco geopolítico de la I+D+i.
Fundación Alternativas.
