Salvatore D'Antonio

dblp:06/552 · DBLP profile ↗
← Back
40ranked-venue papers
10as first author
12since 2021 · last 2026
0000-0001-9327-0138ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 3 first-author · 2 since 2021Computer networks · 8 · 3 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 7 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 3 since 2021Systems, architecture and hardware · 4 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 EigenFL: An EigenLayer-Restaked Blockchain Solution for Secure Federated Learning
Giovanni Maria Cristiano, Salvatore D'Antonio, Giovanni Mazzeo
COMPSAC2
2026 Introduction to Special Issue on DLT for Security, Privacy and Trust
Stavros Shiaeles, Nicholas Kolokotronis, Salvatore D'Antonio, Luca Faramondi
Distributed Ledger Technol. Res. Pract.3
2025 An experimental evaluation of TEE technology: Benchmarking transparent approaches based on SGX, SEV, and TDX
abstract
Protection of data-in-use is a key priority, for which Trusted Execution Environment (TEE) technology has unarguably emerged as a — possibly the most — promising solution. Multiple server-side TEE offerings have been released over the years, exhibiting substantial differences with respect to several aspects. The first comer was Intel SGX, which featured Process-based TEE protection, an efficient yet difficult to use approach. Some SGX limitations were (partially) overcome by runtimes, notably: Gramine , Scone , and Occlum . A major paradigm shift was later brought by AMD SEV, with VM-based TEE protection, which enabled ”lift-and-shift” deployment of legacy applications. This new paradigm has been implemented by Intel only recently, in TDX. While the threat model of the aforementioned TEE solutions has been widely discussed, a thorough performance comparison is still lacking in the literature. This paper provides a comparative evaluation of TDX , SEV , Gramine-SGX , and Occlum-SGX . We study computational overhead and resource usage, under different operational scenarios and using a diverse suite of legacy applications. By doing so, we provide a reliable performance assessment under realistic conditions. We explicitly emphasize that — at the time of writing — TDX was recently released to the public. Thus, the evaluation of TDX is a unique feature of this study.
Luigi Coppolino, Salvatore D'Antonio, Giovanni Mazzeo, Luigi Romano
Comput. Secur.2
2025 The good, the bad, and the algorithm: The impact of generative AI on cybersecurity
abstract
Generative Adversarial Networks (GANs) are emerging as a transformative technology in cybersecurity, presenting both opportunities and challenges in enhancing defensive and offensive strategies. This paper explores the impact that Generative Artificial Intelligence (AI) has on cybersecurity, focusing on its application in the field of network and web security. Current research reveals robust defensive approaches; however, there remains a significant gap in the application of Generative AI to develop advanced attack scenarios capable of bypassing existing defense mechanisms. Our work attempts to fill this gap and spreads awareness regarding a potential exposure of Neural Network (NN)-based Intrusion Detection Systems (IDSs) against AI-enhanced attacks. Unlike conventional approaches that focus on Input Perturbation, Data Poisoning, or Spoofing, we propose a novel offensive strategy called Attack Obfuscation. This strategy leverages Conditional GANs (CGANs) to conceal genuine attacks by injecting synthetic traffic designed to deceive NN-based IDS. The experimental investigation validates the proposed approach against three distinct datasets and different typologies of attacks, managing to successfully deceive the IDS.
Luigi Coppolino, Salvatore D'Antonio, Giovanni Mazzeo, Federica Uccello
Neurocomputing2
2024 Enhancing Network Security Through Granular Computing: A Clustering-by-Time Approach to NetFlow Traffic Analysis
abstract
This paper presents a study of the effect of the size of the time window from which network features are derived on the predictive ability of a Random Forest classifier implemented as a network intrusion detection component. The network data is processed using granular computing principles, gradually increasing the time windows to allow the detection algorithm to find patterns in the data at different levels of granularity. Experiments were conducted iteratively with time windows ranging in size from 2 to 1024 seconds. Each iteration involved time-based clustering of the data, followed by splitting into training and test sets at a ratio of 67% - 33%. The Random Forest algorithm was applied as part of a 10-fold cross-validation. Assessments included standard detection metrics: accuracy, precision, F1 score, BCC, MCC and recall. The results show a statistically significant improvement in the detection of cyber attacks in network traffic with a larger time window size (p-value 0.001953125). These results highlight the effectiveness of using longer time intervals in network data analysis, resulting in increased anomaly detection.
Mikolaj Komisarek, Marek Pawlicki, Salvatore D'Antonio, Rafal Kozik, Aleksandra Pawlicka, Michal Choras
ARES3
2024 A Novel Approach to the Use of Explainability to Mine Network Intrusion Detection Rules
Federica Uccello, Marek Pawlicki, Salvatore D'Antonio, Rafal Kozik, Michal Choras
ACIIDS (1)3
2024 Evaluating the necessity of the multiple metrics for assessing explainable AI: A critical examination
abstract
This paper investigates the specific properties of Explainable Artificial Intelligence (xAI), particularly when implemented in AI/ML models across high-stakes sectors, in this case cybersecurity. The authors execute a comprehensive systematic review of xAI properties, various evaluation metrics, and existing frameworks to assess their utility and relevance. Subsequently, the experimental sections evaluate selected xAI techniques against these metrics, delivering key insights into their practical utility and effectiveness. The findings highlight that the proliferation of metrics enhances the understanding of xAI systems but simultaneously exposes challenges such as metric duplication, inefficacy, and confusion. These issues underscore the pressing need for standardized evaluation frameworks to streamline their application and strengthen their effectiveness, thereby improving the overall utility of xAI in critical domains.
Marek Pawlicki, Aleksandra Pawlicka, Federica Uccello, Sebastian Szelest, Salvatore D'Antonio, Rafal Kozik, Michal Choras
Neurocomputing5
2023 A Tamper-Resistant Storage Framework for Smart Grid security
abstract
In the past few years, the energy sector has been among the most targeted by cyber-criminals. Due to the strong reliance of Critical Infrastructures on energy distribution, and the strategic value of such systems, the impact of intrusions and data breaches cannot be underestimated. In this scenario, data constitutes a critical asset to protect, especially as the latest technological development has led to interconnected intelligent systems, named smart grids. The consequences of data tampering, exposure or loss can range from disruption of essential services, to serious risks for environment, economy and people safety. Data provenance, as the documentation of the origin of data and the processes and methodology that led to it, can bring support when facing the aforementioned attacks. The present work aims to address security issues in the energy domain, by proposing the Advanced Tamper-Resistant Storage (ATRS), a novel framework for data provenance based on blockchain technology. The ATRS allows for the creation and storage of provenance records, whose reliability is ensured by the tamper-resistance feature enabled through the combination of blockchain and TLS-based communication. The framework, tailored and tested for the smart grid domain, can easily be customized for different critical use cases.
Salvatore D'Antonio, Roberto Nardone, Nicola Russo, Federica Uccello
PDP1
2022 Data Provenance for healthcare: a blockchain-based approach
abstract
With the advent of Industry 4.0, information has become a key aspect for virtually any system. Critical infrastructures haven't been excluded by this technological revolution, which has led to several advantages in terms of communication, interoperability, and scalability. On the other hand, these systems are now targeted by new attacks, previously exclusive to cybersystems. The potential of data violation ranges from the interruption of the service provided to, in the worst cases, disastrous consequences in environmental, economic and safety terms. Consequently, ensuring data reliability is an essential task to prevent these kinds of attacks. Data provenance, a kind of metadata that identifies the derivation history of a data, can provide a possible solution. This paper aims to discuss solutions for a tamper proof data provenance extended, but not limited, to the healthcare scenario. The proposed approach is based on blockchain technology to ensure protection of sensitive data, such as medical records and healthcare data.
Salvatore D'Antonio, Federica Uccello
COMPSAC1
2022 PriSIEM: Enabling privacy-preserving Managed Security Services
Luigi Coppolino, Salvatore D'Antonio, Giovanni Mazzeo, Luigi Romano, Luigi Sgaglione
J. Netw. Comput. Appl.2
2021 Privacy-Preserving Credit Scoring via Functional Encryption
Lorenzo Andolfo, Luigi Coppolino, Salvatore D'Antonio, Giovanni Mazzeo, Luigi Romano, Matthew Ficke, Arne Hollum, Darshan Vaydia
ICCSA (8)3
2021 VISE: Combining Intel SGX and Homomorphic Encryption for Cloud Industrial Control Systems
abstract
Protecting data-in-use from privileged attackers is challenging. New CPU extensions (notably: Intel SGX) and cryptographic techniques (specifically: Homomorphic Encryption) can guarantee privacy even in untrusted third-party systems. HE allows sensitive processing on ciphered data. However, it is affected by i) a dramatic ciphertext expansion making HE unusable when bandwidth is narrow, ii) unverifiable conditional variables requiring off-premises support. Intel SGX allows sensitive processing in a secure enclave. Unfortunately, it is i) strictly bonded to the hosting server making SGX unusable when the live migration of cloud VMs/Containers is desirable, ii) limited in terms of usable memory, which is in contrast with resource-consuming data processing. In this article, we propose the VIrtual Secure Enclave (VISE), an approach that effectively combines the two aforementioned techniques, to overcome their limitations and ultimately make them usable in a typical cloud setup. VISE moves the execution of sensitive HE primitives (e.g., encryption) to the cloud in a remotely attested SGX enclave, and then performs sensitive processing on HE data-outside the enclave-leveraging all the memory resources available. We demonstrate that VISE meets the challenging security and performance requirements of a substantial application in the Industrial Control Systems domain. Our experiments prove the practicability of the proposed solution.
Luigi Coppolino, Salvatore D'Antonio, Valerio Formicola, Giovanni Mazzeo, Luigi Romano
IEEE Trans. Computers2
2020 An abstract reasoning architecture for privacy policies monitoring
Flora Amato, Luigi Coppolino, Salvatore D'Antonio, Nicola Mazzocca, Francesco Moscato 0001, Luigi Sgaglione
Future Gener. Comput. Syst.3
2019 Privacy Preserving Intrusion Detection Via Homomorphic Encryption
abstract
In the recent years, we are assisting to an undiminished, and unlikely to stop number of cyber threats, that have increased the organizations/companies interest about security concerns. Further, the rising costs of an efficient IT security staff and environment is posing a significant challenge. These have created a new fast growing trend named Managed Security Services (MSS). Often customers turn to MSS providers to alleviate the pressures they face daily related to information security. One of the most critical aspect, related to the outsourcing of security issues, is privacy. Security monitoring and in general security services require access to as much data as possible, in order to provide an effective and reliable service. It is the well known conflict between privacy and security, a particularly evident problem in security monitoring solutions. This paper analyzes a scenario of MSS in order to provide a privacy preserving solution that allows the security monitoring without violating the privacy requirements. The basic idea relies on the usage of the Homomorphic Encryption technology. Encrypting data using homomorphic schemes, cloud computing and MSS providers can perform different computations on encrypted data without ever having access to their decryption. This solution keeps data confidential and secured, not only during exchange and storage, but also during processing. We provide an ad-hoc Intrusion Detection System architecture for privacy preserving security monitoring, considering as counter threats Code Injection attacks on homomorphically encrypted fields.
Luigi Sgaglione, Luigi Coppolino, Salvatore D'Antonio, Giovanni Mazzeo, Luigi Romano, Domenico Cotroneo, Andrea Scognamiglio
WETICE3
2019 A comparative analysis of emerging approaches for securing java software with Intel SGX
Luigi Coppolino, Salvatore D'Antonio, Giovanni Mazzeo, Luigi Romano
Future Gener. Comput. Syst.2
2018 Message from the SIS-SS 2018 Workshop Organizers
abstract
Presents the introductory welcome message from the conference proceedings. May include the conference officers' congratulations to all involved with the conference event and publication of the proceedings record.
Luca Vollero, Salvatore D'Antonio
COMPSAC (2)2
2018 An Approach for Securing Critical Applications in Untrusted Clouds
abstract
The cloud computing has recently emerged as compelling paradigm for managing and delivery services over the internet. However, users as well as critical infrastructure operators, have legitimate concerns about the confidentiality, integrity and availability, in short the dependability, of applications and their data hosted on a third-party cloud. The dependability is become a commercial imperative for cloud providers, especially to support cloud computing for critical infrastructures. In this paper the SecureCloud project, its approach and goals are presented. SecureCloud aims to remove technical impediments to dependable cloud computing, encouraging and enabling a greater uptake of cost-effective, environment-friendly, and innovative cloud solutions, in particular, for critical infrastructure applications.
Luigi Coppolino, Salvatore D'Antonio, Giovanni Mazzeo, Gaetano Papale, Luigi Sgaglione, Ferdinando Campanile
PDP2
2018 An OpenNCP-based Solution for Secure eHealth Data Exchange
Mariacarla Staffa, Luigi Sgaglione, Giovanni Mazzeo, Luigi Coppolino, Salvatore D'Antonio, Luigi Romano, Erol Gelenbe, Oana Stan, Sergiu Carpov, Evangelos Grivas, Paolo Campegiani, Luigi Castaldo, Konstantinos Votis, Vassilis Koutkias, Ioannis Komnios
J. Netw. Comput. Appl.5
2017 Addressing Security Issues in the eHeatlh Domain Relying on SIEM Solutions
abstract
During the last decade, we witnessed a constantly increasing digitalization in the health-care domain that, while from the one hand, has increased the average life expectancy representing one of the crowning achievements of the last years, from the other hand, has introduced extra challenges due to the simultaneous increasing of the proliferation of cyber-crime and the creation of malicious applications which try to access health sensitive data. This created the need for increased security implementations, leading to improved user acceptance of such applications and thus to large-scale adoption of these technologies and to full exploitation of their advantages. We here propose the use of a SIEM-based framework specifically tailored for a healthcare portal developed within the context of the Italian National Project eHealthNet, which allows real time monitoring of portal accesses with the aim of detecting potential threats and anomalies that could cause major security issues.
Luigi Coppolino, Salvatore D'Antonio, Luigi Romano, Luigi Sgaglione, Mariacarla Staffa
COMPSAC (2)2
2017 Security in Cross - Border Medical Data Interchange: A Technical Analysis and a Discussion of Possible Improvements
abstract
Freedom of movement in the European Union (EU) requires the possibility to exchange healthcare - related information across borders. Such an interchange must face legal, technical and security issues. In this work, we provide a technical analysis of the state - of - the - art software for cross - border eHealth data exchange in the EU, namely OpenNCP, from the security point of view. Moreover, we present a number of solutions that will be developed during the 36 - months, EU - funded KONFIDO project to improve the security of healthcare - related data exchange and to add support for smart IoT sensors.
Raffaele Martino, Salvatore D'Antonio, Luigi Coppolino, Luigi Romano
COMPSAC (2)2
2017 Cloudifying Critical Applications: A Use Case from the Power Grid Domain
abstract
The cloud computing paradigm is gaining more and more momentum, to the extent that it is no more confined to its initial application domains, i.e. use by enterprises and businesses that are simply willing to lower costs or to increase computing capacity in a flexible manner. In particular, increasing interest is recently being paid to the dramatic potentials that the use of cloud computing technology by critical infrastructure (CI) operators might bring about, in terms of benefits for the society at large. Since accidental or deliberate damage to a CI may result in devastating consequences, this mandates for dependable and trustworthy security mechanisms in cloud platforms. In this paper, we present a distributed application for real-Time monitoring of a Power Grid. The application, which is called PoGriMon, is deployed on top of the SecureCloud platform, a security-enhanced IaaS solution that exploits the Intel Software Guard eXtension (SGX) technology. PoGriMon has been designed based on the requirements of the SCADA network of the Israeli Electric Corporation (IEC), and it is currently being validated in a realistic setup also provided by IEC.
Ferdinando Campanile, Luigi Coppolino, Salvatore D'Antonio, Leonid Lev, Giovanni Mazzeo, Luigi Romano, Luigi Sgaglione, Francesco Tessitore
PDP3
2016 A framework for mastering heterogeneity in multi-layer security information and event correlation
Luigi Coppolino, Salvatore D'Antonio, Valerio Formicola, Luigi Romano
J. Syst. Archit.2
2015 Efficient Supply Chain Management via Federation-Based Integration of Legacy ERP Systems
Luigi Coppolino, Salvatore D'Antonio, Carmine Massei, Luigi Romano
SoMeT2
2014 Trust-Based Intrusion Tolerant Routing in Wireless Sensor Networks
Francesco Buccafurri, Luigi Coppolino, Salvatore D'Antonio, Alessia Garofalo, Gianluca Lax, Antonino Nocera, Luigi Romano
SAFECOMP3
2012 Enhancing SIEM Technology to Protect Critical Infrastructures
Luigi Coppolino, Salvatore D'Antonio, Valerio Formicola, Luigi Romano
CRITIS2
2011 On the Security of the Terminal Operations for Container Shipping in Multimodal Transport: the SIS-TEMA Project
abstract
In the era of the global economy the container shipping represents a fundamental link of the logistic chain of the multimodal transport. The optimization of the cargo handling and, generally, of the port operations becomes a challenge for improving the performance of the whole supply chain. The adoption of Information and Communication Technologies can largely support operations management in a container terminal. On the other hand, the terroristic threats have dramatically increased the need for protecting critical infrastructures like ports, railway stations, airports. In this paper we describe the case study of the SIS-TEMA project which aims at designing a secure integrated framework for management of port operations. An architecture which guarantees both the efficiency of terminal operations and the security of the overall critical infrastructure is presented.
Luigi Coppolino, Salvatore D'Antonio, Valerio Formicola, Francesco Oliviero, Luigi Romano
CRiSIS2
2011 Security Analysis of Smart Grid Data Collection Technologies
Luigi Coppolino, Salvatore D'Antonio, Ivano Alessandro Elia, Luigi Romano
SAFECOMP2
2011 Integration of a System for Critical Infrastructure Protection with the OSSIM SIEM Platform: A dam case study
Luigi Coppolino, Salvatore D'Antonio, Valerio Formicola, Luigi Romano
SAFECOMP2
2010 Performance assessment of a distributed intrusion detection system in a real network scenario
abstract
The heterogeneity and complexity of modern networks and services urge the requirement for flexible and scalable security systems, which can be dynamically configured to suit the everchanging nature of security threats and user behavior patterns. In this paper we present a distributed architecture for an Intrusion Detection System, allowing for traffic analysis at different granularity levels, performed by using the best available techniques. Such architecture leverages the principle of separation of concerns, and hence proposes to build up a system comprising entities specialized in performing different tasks, appropriately orchestrated by a broker entity playing the crucial role of the mediator. This paper stresses the point that a distributed system, besides being inherently more scalable than a centralized one, allows for better detection capabilities thanks to the effective exploitation of the inner heterogeneity of the involved detection engines. In order to support our findings, we will describe the design, implementation and deployment of the proposed solution in the framework of the INTERSECTION FP7 European Project.
Salvatore D'Antonio, Valerio Formicola, Claudio Mazzariello, Francesco Oliviero, Simon Pietro Romano
CRiSIS1
2010 Intersection Approach to Vulnerability Handling
Michal Choras, Salvatore D'Antonio, Rafal Kozik, Witold Holubowicz
WEBIST (1)2
2008 INcreasing Security and Protection through Infrastructure REsilience: The INSPIRE Project
Salvatore D'Antonio, Luigi Romano, Abdelmajid Khelil, Neeraj Suri
CRITIS1
2006 High-Speed Intrusion Detection in Support of Critical Infrastructure Protection
Salvatore D'Antonio, Francesco Oliviero, Roberto Setola
CRITIS1
2006 Pinball Caching: Improving Performance of a Framework for Dynamic Web-Content Adaptation and Deliver
abstract
In this work we deal with a multi-layer caching architecture capable to optimize delivery of dynamically produced web content. With reference to such architecture, we propose a technique named Pinball Caching, representing a useful means to estimate attainable performance improvement with respect to the trend of the main parameters characterizing the system. The application of such instrument allows clearly identifying where to concentrate efforts in order to optimize the joint utilization of the content adaptation architecture on one side and the hierarchical caching pool on the other.
Salvatore D'Antonio, Marcello Esposito, Simon Pietro Romano
ISCC1
2006 Techniques for available bandwidth measurement in IP networks: A performance comparison
Leopoldo Angrisani, Salvatore D'Antonio, Marcello Esposito, Michele Vadursi
Comput. Networks2
2006 Design principles and algorithms for effective high-speed IP flow monitoring
Maurizio Molina, Agostino Chiosi, Salvatore D'Antonio, Giorgio Ventre
Comput. Commun.3
2005 INTERMON: An Architecture for Inter-domain Monitoring, Modelling and Simulation
Elisa Boschi, Salvatore D'Antonio, Paul Malone, Carsten Schmoll
NETWORKING2
2005 Time-aware admission control on top of time-unaware network infrastructures
Salvatore D'Antonio, Marcello Esposito, Simon Pietro Romano, Giorgio Ventre
Comput. Commun.1
2004 An architecture for automatic configuration of integrated networks
abstract
Configuration and management activities are frequently performed both in local area and campus networks due to the intrinsic variability characterizing such networks and the innovative services provided through them. Indeed, in order to benefit from services like voice over IP and multimedia content distribution, corporate users need to configure and manage their network appropriately. Suitable strategies have to be undertaken to fulfill stringent requirements imposed by such services on the underlying "integrated" transport infrastructure. These activities are both time and money consuming since they are usually under the responsibility of network administrators and managers. We present an architecture that allows the configuration of network devices in an automatic fashion in order to facilitate traffic management and prioritization in LANs. On one hand, traffic management is optimized through the segmentation of a corporate network into multiple virtual LANs via SNMP. On the other, traffic prioritization is carried out by grouping LAN packets into separate classes associated with different priority levels in compliance with 802.1p. The segmentation process is carried out in two steps: in the first, the network segmentation into "multimedia hosts" (i.e., IP phone and multimedia PC) and "data hosts" is accomplished (as well as traffic prioritization); in the second, the segmentation task is optimized in both VLANs thanks to the utilization of a "partitioning algorithm".
Salvatore D'Antonio, Maurizio D'Arienzo, Antonio Pescapè, Giorgio Ventre
NOMS (1)1
2004 Managing service level agreements in Premium IP networks: a business-oriented approach
Salvatore D'Antonio, Maurizio D'Arienzo, Marcello Esposito, Simon Pietro Romano, Giorgio Ventre
Comput. Networks1
2002 Designing service negotiation entities for the electronic market-place
abstract
The emergence of service providers and brokers who are independent of network providers has opened the way to a spot market in free network resources: it is under everybody's eyes that market enabled service provision based on Service Level Agreements (SLAs) will be essential for the delivery of many services such as bandwidth on demand. In order for those services to be created, configured and delivered dynamically via automated SLAs, a market enabling mechanism is required that is sufficiently flexible to convey the varying information requirements of the various stakeholders involved in the service delivery chain, together with their internal processes. In this paper an innovative framework for the negotiation of services with quality assurances is presented. The study is conducted keeping an eye on the latest standard proposals coming from the electronic business research community, with respect to both the modeling methodology and the actual design for implementation.
Salvatore D'Antonio, B. Fadini, Simon Pietro Romano, Giorgio Ventre
SEKE1