VLDB 2026 Research / reviewers in the wild / expert
Michele Beretta 0001
dblp:03/11327-1
· DBLP profile ↗
6ranked-venue papers
0as first author
6since 2021 · last 2025
0009-0003-4026-8589ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | POSTER: Transparent Temporally-Specialized System Call Filters
Matthew Rossi, Michele Beretta 0001, Dario Facchinetti, Stefano Paraboschi |
AsiaCCS | 2 |
| 2025 | POSTER: Policy-driven security-aware scheduling in Kubernetes
Matthew Rossi, Michele Beretta 0001, Dario Facchinetti, Stefano Paraboschi |
AsiaCCS | 2 |
| 2025 | Secure Kubernetes Workload Deployment with Automated Enforcement of Cluster-Defined PoliciesabstractScheduling pods on separate physical nodes is a crucial strategy to isolate workloads with incompatible security requirements. In Kubernetes, this is enforced using metadata such as node selectors, affinity rules, and topology spread constraints, all manually defined by developers at resource creation. The aforementioned process is complex and prone to errors, frequently resulting in misconfigurations that expose systems to data breaches and regulatory violations. This paper proposes an approach to constrain scheduling using policies defined once at the cluster level and automatically evaluated by Kubernetes during each workload deployment. The advantages are (i) automatic rejection of uncompliant resource creation requests, (ii) streamlined support for executing multi-tenant workloads, and (iii) secure scheduling and deployment of workloads based on security requirements. To implement this solution, we integrate the native Kubernetes node-filtering capabilities with OPA Gatekeeper for policy enforcement. We demonstrate how this approach reliably enforces common corporate governance policies and analyze its performance advantage over isolation achieved solely through sandboxing. The experimental evaluation confirms the effectiveness of our proposal and the minimal overhead. Matthew Rossi, Michele Beretta 0001, Dario Facchinetti, Stefano Paraboschi |
CloudCom | 2 |
| 2024 | Supporting Data Owner Control in IPFS NetworksabstractDecentralized storage architectures are emerging as valid complementary solutions to cloud-based storage services. InterPlanetary File System (IPFS) is one of the most well-known distributed file storage protocols with wide adoption, good performance, and a variety of applications built over it. However, IPFS does not natively support data confidentiality and its decentralized nature limits the ability of data owners to maintain control on their resources and to force their deletion. We propose Mix-IPFS, an approach that allows data owners to maintain control on their resources uploaded to IPFS, guaranteeing their confidentiality and supporting secure deletion. Mix-IPFS is based on AONT encryption, which has the nice property of preventing decryption if the whole ciphertext is not available. Data owners can permanently delete a resource by making a small portion of its encrypted representation unavailable. Our solution uses a virtual file system to guarantee transparency to data owners (i.e., they can operate on plaintext resources). The experimental evaluation shows that the overhead of our approach is negligible (less than 2% for both upload and access operations). Marco Abbadini 0001, Michele Beretta 0001, Sabrina De Capitani di Vimercati, Dario Facchinetti, Sara Foresti, Gianluca Oldani, Stefano Paraboschi, Matthew Rossi, Pierangela Samarati |
ICC | 2 |
| 2023 | POSTER: Leveraging eBPF to enhance sandboxing of WebAssembly runtimesabstractWebAssembly is a binary instruction format designed as a portable compilation target enabling the deployment of untrusted code in a safe and efficient manner. While it was originally designed to be run inside web browsers, modern runtimes like Wasmtime and WasmEdge can execute WebAssembly directly on various systems. In order to access system resources with a universal hostcall interface, a standardization effort named WebAssembly System Interface (WASI) is currently undergoing. With specific regard to the file system, runtimes must prevent hostcalls to access arbitrary locations, thus they introduce security checks to only permit access to a pre-defined list of directories. This approach not only suffers from poor granularity, it is also error-prone and has led to several security issues. In this work we replace the security checks in hostcall wrappers with eBPF programs, enabling the introduction of fine-grained per-module policies. Preliminary experiments confirm that our approach introduces limited overhead to existing runtimes. Marco Abbadini 0001, Michele Beretta 0001, Dario Facchinetti, Gianluca Oldani, Matthew Rossi, Stefano Paraboschi |
AsiaCCS | 2 |
| 2023 | Lightweight Cloud Application SandboxingabstractModern cloud applications can quickly grow to an elaborate and intricate tangle of services. In this scenario, paying attention to security aspects is important to mitigate the impact of incidents. Indeed, several research works and industrial standards recommend the integration of least privilege policies to prevent disruptions such as file system tampering. Unfortunately, technologies like containers virtualize file system resources with a volume-based approach, which may be overly coarse.In this work we address this problem proposing an approach that restrict application access to file system resources with a resource-based granularity. To this end, we develop a flexible and intuitive tool that relies on instrumentation to collect, merge, and audit the activity traces generated by any application component. We then demonstrate how this information is used to create fine-grained access policies, and introduce sandboxing using recent kernel security modules, strengthening the security boundary of the whole application. In the experimental evaluation we showcase the mitigation capabilities associated with our approach, and the low performance footprint. The proposal is associated with an open source implementation. Marco Abbadini 0001, Michele Beretta 0001, Dario Facchinetti, Gianluca Oldani, Matthew Rossi, Stefano Paraboschi |
CloudCom | 2 |