VLDB 2026 Research / reviewers in the wild / expert
Daniele Canavese
dblp:09/10350
· DBLP profile ↗
15ranked-venue papers
4as first author
8since 2021 · last 2026
0000-0002-4265-7743ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 5 · 2 first-author · 2 since 2021Computer networks · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Automatic selection of protections to mitigate risks against software applicationsabstractThis paper introduces a novel approach for the automated selection of software protections to mitigate Machine-At-The-End risks against critical assets within software applications. We formalize the key elements involved in protection decision-making — including code artifacts, assets, security requirements, attacks, and software protections — and frame the protection process through a model inspired by game theory. In this model, a defender strategically applies protections to various code artifacts of a target application, anticipating repeated attack attempts by adversaries against the confidentiality and integrity of the application’s assets. The selection of the optimal defense maximizes resistance to attacks while ensuring the application remains usable by constraining the overhead introduced by protections. The game is solved through a heuristic based on a mini-max depth-first exploration strategy, augmented with dynamic programming optimizations for improved efficiency. Central to our formulation is the introduction of the Software Protection Index, an original contribution that extends existing notions of potency and resilience by evaluating protection effectiveness against attack paths using software metrics and expert assessments. We validate our approach through a proof-of-concept implementation and expert evaluations, demonstrating that automated software protection is a practical and effective solution for risk mitigation in software. Daniele Canavese, Leonardo Regano, Cataldo Basile, Bjorn De Sutter |
Comput. Secur. | 1 |
| 2026 | Empirical assessment of the code comprehension effort needed to attack programs protected with obfuscationabstractEvaluating the effectiveness of software protection is crucial for selecting the most effective methods to safeguard assets within software applications. Obfuscation involves techniques that deliberately modify software to make it more challenging to understand and reverse-engineer, while maintaining its original functionality. Although obfuscation is widely adopted, its effectiveness remains largely unexplored and not rigorously evaluated. This paper presents a controlled experiment involving Master’s students performing code comprehension tasks on applications hardened with obfuscation. The experiment’s goals are to assess the effectiveness of obfuscation in delaying code comprehension by attackers and to determine whether complexity metrics can accurately predict the impact of these protections on success rates and durations of code comprehension tasks. The study is the first to evaluate the effect of layering multiple obfuscation techniques on a single piece of protected code. It also provides experimental evidence of the correlation between objective metrics of the attacked code and the likelihood of a successful attack, bridging the gap between objective and subjective approaches to estimating potency. Finally, the paper highlights significant aspects that warrant additional analysis and opens new avenues for further experiments. Leonardo Regano, Daniele Canavese, Cataldo Basile, Marco Torchiano |
Comput. Secur. | 2 |
| 2026 | Uncovering challenges of cybersecurity cross-regulation in EU legislationabstractContext: The European Union has recently introduced a suite of foundational digital regulations—the Cyber Resilience Act, the Artificial Intelligence Act, the Radio Equipment Directive, the NIS 2 Directive, and the Cybersecurity Act—that directly affect the engineering of software-intensive systems. While these instruments aim to enhance trust and security, their overlapping scopes generate a complex compliance landscape that software development must address at the design, implementation, and deployment stages. Objectives: This paper examines the cross-regulatory impact of such EU cybersecurity legislation from a software engineering perspective, aiming to provide a set of guidelines and recommendations for implementing a compliance-by-design approach. Method: We analyse and compare the five legal instruments, focusing on how their obligations intersect with each other. We then translate their regulatory requirements into actionable artefacts, ranging from architectural constraints and security controls to organisational processes, using a legal engineering approach. Finally, we propose a compliance-by-design lifecycle pattern that integrates regulatory alignment into requirements engineering, system design, and testing. Results: To demonstrate applicability, we evaluate three representative use cases: an AI-enabled power plant, an autonomous drone delivery platform, and an AI-powered clinical decision support system. These examples demonstrate that multiple regulatory regimes often govern software-based systems. We conclude with practical recommendations for suppliers, deployers, and policymakers towards an integrated compliance framework to promote compliance-aware software engineering. Conclusion: Our findings indicate that the European digital landscape is shifting compliance from a post-hoc audit exercise to a design-time engineering principle. Embedding compliance early into the software development lifecycle not only supports regulatory alignment but also improves system resilience and trustworthiness. Daniele Canavese, Afonso Ferreira, Liina Kamm, Adrian Quesada Rodriguez |
Inf. Softw. Technol. | 1 |
| 2025 | No Root, No Problem: Automating Linux Least Privilege and Securing Ansible Deployments
Eddie Billoir, Romain Laborde, Daniele Canavese, Yves Rütschlé, Ahmad Samer Wazan, Benzekri Abdelmalek |
ESORICS (3) | 3 |
| 2025 | Game of Zones: An Automated Intent-Based Network Micro-segmentation MethodologyabstractThis article presents a novel approach that automates part of the work of network security architects, enabling them to design fine-grained secure network architectures. We have developed a methodology that, starting from high-level security requirements, called intents, and an initial unprotected network architecture, computes the optimal security zones and integrates security functions to protect both inter- and intra-zone communications. We implemented this methodology as a proof-of-concept framework, leveraging the flexibility and expressivity of Answer Set Programming, a form of declarative logic programming. Daniele Canavese, Romain Laborde, Abir Laraba, Afonso Ferreira, Benzekri Abdelmalek |
NOMS | 1 |
| 2023 | Autoencoder-SAD: An Autoencoder-based Model for Security Attacks DetectionabstractIn recent years, a variety of cybersecurity attacks affected national infrastructures, big companies, and even medium size organizations. As countermeasures are implemented, new attack variants appear. Historically, signature-based and anomaly-based Intrusion Detection Systems (IDSs) are used for detecting abnormal network behavior. The signature-based IDS is typically effective against attacks for which attack signatures exist. The anomaly-based IDS instead performs traffic analysis and raises alerts when encountering suspicious network patterns. They can detect attacks without registered signatures through different mechanisms, including machine learning (ML) techniques. We propose Autoencoder-SAD, an anomaly-based detection model, which can individuate new cybersecurity attacks by exploiting the Autoencoder model. Through empirical tests with two datasets (CIC-IDS2017 and TORSEC), we evaluated Autoencoder-SAD against two supervised ML models (Random Forest and Extreme Gradient Boosting) and one semi-supervised Autoencoder-based model. The results are promising since our approach shows an AUC of 0.94 for known attacks and 0.68 for unknown attacks. Diana Berbecaru, Stefano Giannuzzi, Daniele Canavese |
ISCC | 3 |
| 2023 | Design, implementation, and automation of a risk management approach for man-at-the-End software protectionabstractThe last years have seen an increase in Man-at-the-End (MATE) attacks against software applications, both in number and severity. However, software protection, which aims at mitigating MATE attacks, is dominated by fuzzy concepts and security-through-obscurity. This paper presents a rationale for adopting and standardizing the protection of software as a risk management process according to the NIST SP800-39 approach. We examine the relevant constructs, models, and methods needed for formalizing and automating the activities in this process in the context of MATE software protection. We highlight the open issues that the research community still has to address. We discuss the benefits that such an approach can bring to all stakeholders. In addition, we present a Proof of Concept (PoC) decision support system that instantiates many of the discussed construct, models, and methods and automates many activities in the risk analysis methodology for the protection of software. Despite being a prototype, the PoC’s validation with industry experts indicated that several aspects of the proposed risk management process can already be formalized and automated with our existing toolbox and that it can actually assist decision making in industrially relevant settings. Cataldo Basile, Bjorn De Sutter, Daniele Canavese, Leonardo Regano, Bart Coppens 0001 |
Comput. Secur. | 3 |
| 2022 | A model of capabilities of Network Security FunctionsabstractThis paper presents a formal model of the features, named security capabilities, offered by the controls used for enforcing security policies in computer networks. It has been designed to support policy refinement and policy translation and address useful, practical tasks in a vendor-independent manner. The model adopts state-of-the-art design patterns and has been designed to be extensible. The model describes the actions that the controls can perform (e.g. deny packets or encrypt flows), the conditions to select on what to apply the actions, how to compose valid configuration rules from them, and how to build configurations from rules. It proved effective to model filtering controls and iptables. Cataldo Basile, Daniele Canavese, Leonardo Regano, Ignazio Pedone, Antonio Lioy |
NetSoft | 2 |
| 2019 | A meta-model for software protections and reverse engineering attacks
Cataldo Basile, Daniele Canavese, Leonardo Regano, Paolo Falcarin, Bjorn De Sutter |
J. Syst. Softw. | 2 |
| 2017 | Towards Optimally Hiding Protected Assets in Software ApplicationsabstractSoftware applications contain valuable assets that, if compromised, can make the security of users at stake and cause huge monetary losses for software developers. Software protections are applied whenever assets' security is at risk as they delay successful attacks. Unfortunately, protections might have recognizable fingerprints that can expose the location of the assets, thus facilitating the attackers' job. This paper presents a novel approach that uses three main methods to hide the protected assets: protection fingerprint replication, enlargement, and shadowing. The best way to hide assets is determined with a Mixed Integer Linear Program, which is automatically built starting from the code structure, the protected assets, and a model that depicts the dependencies among protection and the fingerprints they generate. Additional constraints, such as overhead limits are also supported to ensure the usability of the protected applications. Our implementation, which uses off-the-shelf solvers, showed promising performance and scalability on large applications. Leonardo Regano, Daniele Canavese, Cataldo Basile, Antonio Lioy |
QRS | 2 |
| 2017 | Classification and Analysis of Communication Protection Policy AnomaliesabstractThis paper presents a classification of the anomalies that can appear when designing or implementing communication protection policies. Together with the already known intra- and inter-policy anomaly types, we introduce a novel category, the inter-technology anomalies, related to security controls implementing different technologies, both within the same network node and among different network nodes. Through an empirical assessment, we prove the practical significance of detecting this new anomaly class. Furthermore, this paper introduces a formal model, based on first-order logic rules that analyses the network topology and the security controls at each node to identify the detected anomalies and suggest the strategies to resolve them. This formal model has manageable computational complexity and its implementation has shown excellent performance and good scalability. Fulvio Valenza, Cataldo Basile, Daniele Canavese, Antonio Lioy |
IEEE/ACM Trans. Netw. | 3 |
| 2016 | Towards Automatic Risk Analysis and Mitigation of Software Applications
Leonardo Regano, Daniele Canavese, Cataldo Basile, Alessio Viticchié, Antonio Lioy |
WISTP | 2 |
| 2015 | Light combinators for finite fields arithmetic
Daniele Canavese, Emanuele Cesena, Rachid Ouchary, Marco Pedicini, Luca Roversi |
Sci. Comput. Program. | 1 |
| 2014 | Inter-technology Conflict Analysis for Communication Protection Policies
Cataldo Basile, Daniele Canavese, Antonio Lioy, Fulvio Valenza |
CRiSIS | 2 |
| 2013 | Improved Reachability Analysis for Security ManagementabstractNetwork reachability analysis evaluates the actual connectivity of an IT infrastructure. It can be performed by active network probing or examining a formal model of a target IT infrastructure. The latter approach is preferable as it does not interfere with the normal network behaviour and can be easily used during development and change management phases. In this paper we propose a novel modelling approach based on a geometric representation of device configurations (i.e. the policies) which allows the computation of the reachability analysis using the concept of equivalent firewall. An equivalent firewall is a fictitious device, ideally connected directly to the communication endpoints, that summarizes the network behaviour between them. Our model supports routing, filtering and address translation devices in a computationally effective way. In fact, the experimental results show that the computation of equivalent firewalls is performed in a negligible time and that then the reachability queries are answered in few seconds. Cataldo Basile, Daniele Canavese, Antonio Lioy, Christian Pitscheider |
PDP | 2 |