Arcangelo Castiglione

dblp:117/9048 · DBLP profile ↗
← Back
50ranked-venue papers
16as first author
24since 2021 · last 2026
0000-0002-7991-2410ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 12 · 1 first-author · 9 since 2021Systems, architecture and hardware · 9 · 4 first-author · 3 since 2021Computer networks · 7 · 6 since 2021Security and privacy · 7 · 4 first-author · 2 since 2021Databases, data management, data science and information retrieval · 5 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-authorTheory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2026 SEAD-Net:Complex underwater image segmentation via semantic-enhanced and detail-aware collaboration
Linshu Chen, Anxing Hu, Yuanhui Liu, Wei Liang 0005, Ling-Huey Li, Arcangelo Castiglione, Kuanching Li
Image Vis. Comput.7
2026 ARETO : A joint entity and relation extraction model for the triple overlapping problem
Jing Liao 0004, Lei Jiang 0007, Xiande Su, Wei Liang 0005, Ling-Huey Li, Arcangelo Castiglione, Kuanching Li
Knowl. Based Syst.7
2025 Enhancing Vehicle Communication Security: Implementing Post-quantum Solutions for CAN Networks
Arcangelo Castiglione, Teresa Elia
AINA (4)1
2025 A Modular and Scalable Framework for Effective Server-Side Forensic Analysis of XSS Attacks
Raffaele Pizzolante, Arcangelo Castiglione, Michele Mastroianni, Francesco Palmieri 0002
AINA (4)2
2025 A Mobile Forensic Tool for Enhancing Cyber-Physical Security by Detecting XSS Attacks Through Web Server Access Log Analysis
Raffaele Pizzolante, Arcangelo Castiglione, Michele Mastroianni, Francesco Palmieri 0002
AINA (8)2
2025 AI-Driven Intelligent Attack Detection for IoT Networks Using Big Data and Machine Learning
abstract
With the exponential growth of IoT networks, ensuring robust security has become increasingly critical, as these systems are vulnerable to various cyberattacks. Traditional methods often struggle to handle the massive data generated by IoT devices. This paper introduces an AI-driven, big data approach to intelligent attack detection for IoT networks. Utilizing the NSLKDD dataset, we employed PySpark for preprocessing and chi-square-based feature selection to identify the 15 most significant features, optimizing performance and reducing computational costs. The proposed model, based on XGBoost, achieved outstanding classification results with 98.93% accuracy, and precision, recall, and F1-score approaching 99 %. Comparative analysis against models like Random Forest and LightGBM confirmed its effectiveness, providing a scalable, accurate solution for IoT security.
Akshat Gaurav, Razaz Waheeb Attar, Varsha Arya, Arcangelo Castiglione, Kwok Tai Chui
ICC4
2025 Fennec Fox Optimized Federated Learning for Phishing Detection in Next-Generation Smart Device Networks
abstract
Phishing attacks remain a critical threat to smart devices, especially in next-generation networks, where distributed environments pose unique challenges for detection. In this context, We propose an optimal federated learning system to solve this problem. We fine-tune hyperparameters at the server using the Fennec Fox Optimization (FFO) method, then distribute them to federated clients. Trained across ten rounds, the model obtained an accuracy of 94 %, with consistently exceeding 93 % in F1, precision, and recall. Comparative study of distributed and centralized losses revealed the robustness of the model, therefore strengthening our approach and enabling phishing detection in next-generation smart device networks on a scalable basis.
Brij B. Gupta, Akshat Gaurav, Arcangelo Castiglione, Kwok Tai Chui
ICC3
2024 Unlocking Insights: An Extensible Framework for Automated Metadata Extraction from Online Documents
abstract
Information Gathering is a fundamental stage in a typical Penetration Testing (PT) process, in which penetration testers collect as much information as possible regarding a target system to uncover vulnerabilities, threats, and security issues. Metadata extraction plays an important role in this stage since it can reveal significant details about the target system, such as used technologies, software versions, user information, and network data, which can expose potential attack vectors. This paper introduces a novel framework for automated metadata extraction from documents linked within a specified web page. The framework is designed to streamline Information Gathering processes by offering an easy-to-use, integrated, extensible, and flexible solution. Our proposal can be effective in uncovering information that is not immediately visible to a penetration tester, giving them a greater chance of success in identifying the most fruitful attack patterns.
Raffaele Pizzolante, Arcangelo Castiglione, Francesco Palmieri 0002
TrustCom2
2024 DSTGCS: an intelligent dynamic spatial-temporal graph convolutional system for traffic flow prediction in ITS
Na Hu, Da-Fang Zhang 0001, Wei Liang 0005, Kuanching Li, Arcangelo Castiglione
Soft Comput.5
2023 A novel system for medical equipment supply chain traceability based on alliance chain and attribute and role access control
Dezhi Han, Zhongdai Wu, Kuanching Li, Arcangelo Castiglione
Future Gener. Comput. Syst.6
2023 IoT-based health monitoring system to handle pandemic diseases using estimated computing
Lidia Ogiela, Arcangelo Castiglione, Brij B. Gupta, Dharma P. Agrawal
Neural Comput. Appl.2
2023 CTDM: cryptocurrency abnormal transaction detection method with spatio-temporal and global representation
Dezhi Han, Dun Li, Wei Liang 0005, Ce Yang 0007, Kuanching Li, Arcangelo Castiglione
Soft Comput.7
2022 Robust End Hopping for Secure Satellite Communication in Moving Target Defense
abstract
Satellite communication contributes tremendously to the Industrial Internet of Things (IIoT) with telecommunication efficiency and data accessibility at global-scale coverage. However, realizing proactive defense for satellite communication remains a challenge. In order to address such an issue, we first explore state-of-the-art proactive defense methods and, following next, a step forward on proposing an end hopping scheme based on fixed hopping timeslot and strict time synchronization strategy by utilizing moving target defense (MTD). In addition, we worked on a Proof of Concept (PoC) to evaluate the scheme’s theoretical protection performance for Distributed Denial of Service (DDoS). Experimental evaluation and analysis of the proposed scheme show that it is efficient and secure, as seen when the attack rate is 100 times/s, the response time of the hopping state is 69.98% shorter than that of the normal state, and when the attack rate is 1000 times/s, the response time of the hopping state is 90.15% shorter.
Yongkai Fan, Guodong Wu, Kuanching Li, Arcangelo Castiglione
IEEE Internet Things J.4
2022 DNS tunnels detection via DNS-images
Gianni D'Angelo, Arcangelo Castiglione, Francesco Palmieri 0002
Inf. Process. Manag.2
2022 Blockchain for federated learning toward secure distributed machine learning systems: a systemic survey
Dun Li, Dezhi Han, Tien-Hsiung Weng, Zibin Zheng, Hongzhi Li 0003, Han Liu 0009, Arcangelo Castiglione, Kuanching Li
Soft Comput.7
2022 Privacy-preserving Secure Media Streaming for Multi-user Smart Environments
abstract
Over the last years, our lifestyle has been positively upset by the sudden advent of technology. The Internet of Things (IoT), offering universal and ubiquitous connectivity to both people and objects, revealed to be the silver bullet for enabling a vast number of previously unexpected applications. In particular, media streaming providers are growing in business and scope, and we can forecast that soon, video streaming will substitute TV broadcasting activities. With the increasing success of multi-user smart environments, empowered by new-generation smart devices and IoT architectures, multimedia contents (i.e., images and videos) need to be effectively accessed anytime and anywhere. Recent advances in computer vision technologies have made the development of intelligent monitoring systems for video surveillance and ambient-assisted living. Such a scenario permits better integration among technologies, multimedia content, and end-users. However, there are several challenges, and some are still open. More precisely, due to the sensitivity of some multimedia content (e.g., video-surveillance streams), it is paramount to preserve users’ privacy. Again, it is necessary to guarantee the integrity of usage rights during any multimedia transmission process, starting from the video encoding phase. In this way, the private content is disclosed only when the stream is decoded on the other endpoint, by the legitimate user. In this article, we present a secure video transmission strategy that can address the challenges mentioned above. The proposed strategy takes advantage of both watermarking and video scrambling techniques to make it possible for the secure and privacy-preserving transmission of multimedia streaming. Through our proposal, multimedia streaming is of low quality and thus unusable. However, it can be fully recovered and enjoyed only by authorized users. Finally, due to its low complexity and energy-efficiency, our proposal is particularly suitable for onboard implementations.
Bruno Carpentieri, Arcangelo Castiglione, Alfredo De Santis, Francesco Palmieri 0002, Raffaele Pizzolante
ACM Trans. Internet Techn.2
2021 A novel approach for phishing URLs detection using lexical based machine learning in a real-time environment
Brij B. Gupta, Krishna Yadav, Muhammad Imran Razzak, Kostas E. Psannis, Arcangelo Castiglione, Xiaojun Chang
Comput. Commun.5
2021 On the undetectability of payloads generated through automatic tools: A human-oriented approach
abstract
Abstract Nowadays, several tools have been proposed to support the operations performed during a security assessment process. In particular, it is a common practice to rely on automated tools to carry out some phases of this process in an automatic or semiautomatic way. In this article, we focus on tools for the automatic generation of custom executable payloads. Then, we will show how these tools can be transformed, through some human‐oriented modifications on the generated payloads, into threats for a given asset's security. The danger of such threats lies in the fact that they may not be detected by common antivirus (AVs). More precisely, in this article, we show a general approach to make a payload generated through automated tools run undetected by most AVs. In detail, we first analyze and explain most of the methods used by AVs to recognize malicious payloads and, for each one of them, we outline the relative strengths and flaws, showing how these flaws could be exploited using a general approach to evade AVs controls, by performing simple human‐oriented operations on the payloads. The testing activity we performed shows that our proposal is helpful in evading virtually all the most popular AVs on the market. Therefore, low‐skilled malicious users could easily use our approach.
Bruno Carpentieri, Arcangelo Castiglione, Francesco Palmieri 0002, Raffaele Pizzolante
Concurr. Comput. Pract. Exp.2
2021 A machine learning-based memory forensics methodology for TOR browser artifacts
abstract
Summary At present, 96% of the resources available into the World‐Wide‐Web belongs to the Deep Web, which is composed of contents that are not indexed by search engines. The Dark Web is a subset of the Deep Web, which is currently the favorite place for hiding illegal markets and contents. The most important tool that can be used to access the Dark Web is the Tor Browser. In this article, we propose a bottom‐up formal investigation methodology for the Tor Browser's memory forensics. Based on a bottom‐up logical approach, our methodology enables us to obtain information according to a level of abstraction that is gradually higher, to characterize semantically relevant actions carried out by the Tor browser. Again, we show how the proposed three‐layer methodology can be realized through open‐source tools. Also, we show how the extracted information can be used as input to a novel Artificial Intelligence‐based architecture for mining effective signatures capable of representing malicious activities in the Tor network. Finally, to assess the effectiveness of the proposed methodology, we defined three test cases that simulate widespread real‐life scenarios and discuss the obtained results. To the best of our knowledge, this is the first work that deals with the forensic analysis of the Tor Browser in a live system, in a formal and structured way.
Raffaele Pizzolante, Arcangelo Castiglione, Bruno Carpentieri, Roberto Contaldo, Gianni D'Angelo, Francesco Palmieri 0002
Concurr. Comput. Pract. Exp.2
2021 Effective classification of android malware families through dynamic features and neural networks
abstract
Due to their open nature and popularity, Android-based devices have attracted several end-users around the World and are one of the main targets for attackers. Because of the reasons given above, it is necessary to build tools that can reliably detect zero-day malware on these devices. At the moment, many of the frameworks that have been proposed to detect malware applications leverage Machine Learning (ML) techniques. However, an essential requirement to build these frameworks consists of using very large and sophisticated datasets for model construction and training purposes. Their success, indeed, strongly depends on the choice of the right features used for building a classification model providing adequate generalisation capability. Furthermore, the creation of a training dataset that well represents the malware properties and behaviour is one of the most critical challenges in malware analysis. Therefore, the main aim of this paper is proposing a new dataset called Unisa Malware Dataset (UMD) available on http://antlab.di.unisa.it/malware/, which is based on the extraction of static and dynamic features characterising the malware activities. Additionally, we will show some experiments concerning common ML tools to demonstrate how it is possible to build efficient ML-based malware classification frameworks using the proposed dataset.
Gianni D'Angelo, Francesco Palmieri 0002, Antonio Robustelli, Arcangelo Castiglione
Connect. Sci.4
2021 A Cluster-Based Multidimensional Approach for Detecting Attacks on Connected Vehicles
abstract
Nowadays, modern vehicles are becoming even more connected, intelligent, and smart. A modern vehicle encloses several cyber-physical systems, such as actuators and sensors, which are controlled by electronic control units (ECUs). Such ECUs are connected through in-vehicle networks, and, in turn, such networks are connected to the Internet of Vehicles (IoV) to provide advanced and smart features. However, the increase in vehicle connectivity and computerization, although it brings clear advantages, it introduces serious safety problems that can also endanger the life of the driver and passengers of the vehicle, as well as that of pedestrians. Such problems are mainly caused by the security weaknesses affecting the controller area network (CAN) bus, used to exchange data between ECUs. In this article, we provide two algorithms that implement a data-driven anomaly detection system. The first algorithm (cluster-based learning algorithm), is used to learn the behavior of messages passing on the CAN bus, for base-lining purposes, while the second one (data-driven anomaly detection algorithm) is used to perform real-time classification of such messages (licit or illicit) for early alerting in the presence of malicious usages. The experimental results, obtained by using data coming from a real vehicle, have shown that our approach is capable of performing better than other anomaly detection-based approaches.
Gianni D'Angelo, Arcangelo Castiglione, Francesco Palmieri 0002
IEEE Internet Things J.2
2021 A novel Byzantine fault tolerance consensus for Green IoT with intelligence based on reinforcement
Peng Chen 0032, Dezhi Han, Tien-Hsiung Weng, Kuanching Li, Arcangelo Castiglione
J. Inf. Secur. Appl.5
2021 A clique-based discrete bat algorithm for influence maximization in identifying top-k influential nodes of social networks
Lihong Han, Kuanching Li, Arcangelo Castiglione, Jianxin Tang, Hengjun Huang, Qingguo Zhou
Soft Comput.3
2021 A two-stage intrusion detection approach for software-defined IoT networks
Qiuting Tian, Dezhi Han, Meng-Yen Hsieh, Kuanching Li, Arcangelo Castiglione
Soft Comput.5
2020 On the File Recovery in Systems Infected by Ransomware
Raffaele D'Arco, Raffaele Pizzolante, Arcangelo Castiglione, Francesco Palmieri 0002
AINA3
2020 Network Forensics of WhatsApp: A Practical Approach Based on Side-Channel Analysis
Gianluca De Luca Fiscone, Raffaele Pizzolante, Arcangelo Castiglione, Francesco Palmieri 0002
AINA3
2020 Vulsploit: A Module for Semi-automatic Exploitation of Vulnerabilities
Arcangelo Castiglione, Francesco Palmieri 0002, Mariangela Petraglia, Raffaele Pizzolante
ICTSS1
2020 An intrusion detection approach based on improved deep belief network
Qiuting Tian, Dezhi Han, Kuanching Li, XingAo Liu, Letian Duan, Arcangelo Castiglione
Appl. Intell.6
2020 Compression-based steganography
abstract
Summary Conventional privacy‐enforcement mechanisms, such as encryption‐based ones, are frequently used to prevent third‐party eavesdroppers to intercept confidential information exchanged between two or more parties. However, the use of such mechanisms can be perceivable and it alerts the involved intercepting entities that could devote some effort in trying to remove the protection, eg, by cracking the encryption keys used or by exploiting the vulnerabilities of the technological solution used to protect the data. Sometimes, from the security point of view, avoiding to draw the attention or suspect to intermediate intercepting entities, may be better than protecting a data in a conventional manner. In such direction, one of the most effective approaches is hiding the secret information to be exchanged inside other data, through steganographic techniques. In this work, we exploit, for this specific purpose, the hierarchical structure of a compressed archive, as well as the algorithms and parameters used to create and maintain such archive. It is important to point out that, by doing this, the secret information is in no way semantically related to the contents of the compressed archive. This can be extremely useful in many cloud‐based situations where several confidential data is moved across multiple independent data center, which are under the control of different and not always fully trusted authorities. The effectiveness of this proposal has been assessed by using a properly designed and implemented prototype, where extensive tests have been performed within the context of a proof‐of‐concept.
Bruno Carpentieri, Arcangelo Castiglione, Alfredo De Santis, Francesco Palmieri 0002, Raffaele Pizzolante
Concurr. Comput. Pract. Exp.2
2020 Securing visual search queries in ubiquitous scenarios empowered by smart personal devices
Bruno Carpentieri, Arcangelo Castiglione, Alfredo De Santis, Francesco Palmieri 0002, Raffaele Pizzolante, Xiaofei Xing
Inf. Sci.2
2020 Securing the internet of vehicles through lightweight block ciphers
Arcangelo Castiglione, Francesco Palmieri 0002, Francesco Colace, Marco Lombardi 0001, Domenico Santaniello, Giuseppe D'Aniello
Pattern Recognit. Lett.1
2019 One-pass lossless data hiding and compression of remote sensing data
Bruno Carpentieri, Arcangelo Castiglione, Alfredo De Santis, Francesco Palmieri 0002, Raffaele Pizzolante
Future Gener. Comput. Syst.2
2019 Secure weighted possibilistic c-means algorithm on cloud for clustering big data
Qingchen Zhang 0001, Laurence T. Yang, Arcangelo Castiglione, Zhikui Chen, Peng Li 0027
Inf. Sci.3
2018 On the protection of consumer genomic data in the Internet of Living Things
Raffaele Pizzolante, Arcangelo Castiglione, Bruno Carpentieri, Alfredo De Santis, Francesco Palmieri 0002, Aniello Castiglione
Comput. Secur.2
2018 Building a network embedded FEC protocol by using game theory
Christian Esposito 0001, Arcangelo Castiglione, Francesco Palmieri 0002, Massimo Ficco
Inf. Sci.2
2018 Quantum technique for access control in cloud computing II: Encryption and key distribution
Lu Zhou 0002, Xin Sun 0001, Piotr Kulicki, Arcangelo Castiglione
J. Netw. Comput. Appl.5
2017 Secure group communication schemes for dynamic heterogeneous distributed computing
Arcangelo Castiglione, Paolo D'Arco, Alfredo De Santis, Rosario Russo
Future Gener. Comput. Syst.1
2017 A collaborative clinical analysis service based on theory of evidence, fuzzy linguistic sets and prospect theory and its application to craniofacial disorders in infants
Arcangelo Castiglione, Raffaele Pizzolante, Christian Esposito 0001, Alfredo De Santis, Francesco Palmieri 0002, Aniello Castiglione
Future Gener. Comput. Syst.1
2017 Supporting dynamic updates in storage clouds with the Akl-Taylor scheme
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Xinyi Huang 0001, Aniello Castiglione
Inf. Sci.1
2017 On-Board Format-Independent Security of Functional Magnetic Resonance Images
abstract
Functional magnetic resonance imaging (fMRI) provides an effective and noninvasive tool for researchers to understand cerebral functions and correlate them with brain activities. In addition, with the ever-increasing diffusion of the Internet, such images may be exchanged in several ways, allowing new research and medical services. On the other hand, ensuring the security of exchanged fMRI data becomes a main concern due to their special characteristics arising from strict ethics and legislative and diagnostic implications. Again, the risks increase when dealing with open environments like the Internet. For this reason, security mechanisms that ensure protection of such data are strongly required. However, we remark that the mechanisms commonly employed for data protection are doomed to fail when dealing with imaging data. In this article, we propose a novel watermarking scheme explicitly addressed for this type of imaging. Such a scheme can be used for several purposes, particularly to ensure authenticity and integrity. Moreover, we show how to integrate our scheme within commercial off-the-shelf fMRI system. Finally, the validity and the efficiency of our scheme has been assessed through testing.
Arcangelo Castiglione, Raffaele Pizzolante, Francesco Palmieri 0002, Barbara Masucci, Bruno Carpentieri, Alfredo De Santis, Aniello Castiglione
ACM Trans. Embed. Comput. Syst.1
2016 On the Relations Between Security Notions in Hierarchical Key Assignment Schemes for Dynamic Structures
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Aniello Castiglione
ACISP (2)1
2016 Key Indistinguishability versus Strong Key Indistinguishability for Hierarchical Key Assignment Schemes
abstract
A hierarchical key assignment scheme is a method to assign some private information and encryption keys to a set of classes in a partially ordered hierarchy, in such a way that the private information of a higher class can be used to derive the keys of all classes lower down in the hierarchy. In this paper we analyze the security of hierarchical key assignment schemes according to different notions: security with respect to key indistinguishability and against key recovery, as well as the two recently proposed notions of security with respect to strong key indistinguishability and against strong key recovery . We first explore the relations between all security notions and, in particular, we prove that security with respect to strong key indistinguishability is not stronger than the one with respect to key indistinguishability. Afterwards, we propose a general construction yielding a hierarchical key assignment scheme offering security against strong key recovery, given any hierarchical key assignment scheme which guarantees security against key recovery.
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci
IEEE Trans. Dependable Secur. Comput.1
2016 Hierarchical and Shared Access Control
abstract
Access control ensures that only the authorized users of a system are allowed to access certain resources or tasks. Usually, according to their roles and responsibilities, users are organized in hierarchies formed by a certain number of disjoint classes. Such hierarchies are implemented by assigning a key to each class, so that the keys for descendant classes can be efficiently derived from classes higher in the hierarchy. However, pure hierarchical access may represent a limitation in many real-world cases. In fact, sometimes it is necessary to ensure access to a resource or task by considering both its directly responsible user and a group of users possessing certain credentials. In this paper, we first propose a novel model that generalizes the conventional hierarchical access control paradigm, by extending it to certain additional sets of qualified users. Afterward, we propose two constructions for hierarchical key assignment schemes in this new model, which are provably secure with respect to key indistinguishability. In particular, the former construction relies on both symmetric encryption and perfect secret sharing, whereas, the latter is based on public-key threshold broadcast encryption.
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Aniello Castiglione, Jin Li 0002, Xinyi Huang 0001
IEEE Trans. Inf. Forensics Secur.1
2016 Cryptographic Hierarchical Access Control for Dynamic Structures
abstract
A hierarchical key assignment scheme is a method to assign some private information and encryption keys to a set of classes in a partially ordered hierarchy, in such a way that the private information of a higher class can be used to derive the keys of all classes lower down in the hierarchy. Sometimes, it is necessary to make dynamic updates to the hierarchy, in order to implement an access control policy which evolves with time. All security models for hierarchical key assignment schemes have been designed to cope with static hierarchies and do not consider the issue of performing dynamic updates to the hierarchy. In this paper, we define the concept of hierarchical key assignment schemes supporting dynamic updates, formalizing the relative security model. In particular, we provide the notion of security with respect to key indistinguishability, by considering the dynamic changes to the hierarchy. Moreover, we show how to construct a hierarchical key assignment scheme supporting dynamic updates, by using as a building block a symmetric encryption scheme. The proposed construction is provably secure with respect to key indistinguishability, and provides efficient key derivation and updating procedures, while requiring each user to store only a single private key.
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Aniello Castiglione, Xinyi Huang 0001
IEEE Trans. Inf. Forensics Secur.1
2015 On the Protection of fMRI Images in Multi-domain Environments
abstract
Functional Magnetic Resonance Imaging provides researchers with an effective and non-invasive tool to understand cerebral functions and correlate them with brain activities. With the ever increasing diffusion of the Internet such images may be exchanged in several ways, thus allowing new research and medical services. On the other hand, ensuring the security of exchanged fMRI data becomes a main concern, due to the special characteristics arising from strict ethics, legislative and diagnostic implications. So it is very important to prevent unauthorized manipulation and misappropriation of such images. The risks are increased when dealing with open environments like the Internet. For this reason, security mechanisms which ensure protection of such data are required. In this paper we introduce a watermarking scheme explicitly designed for this kind of images. In particular, such a scheme belongs to the category of fragile reversible watermarking. The validity of this scheme has been demonstrated through testing. Finally, by using the proposed scheme, we show how to create a distributed security solution that models a multi-domain environment, for ensuring authenticity and integrity of such images.
Arcangelo Castiglione, Alfredo De Santis, Raffaele Pizzolante, Aniello Castiglione, Vincenzo Loia, Francesco Palmieri 0002
AINA1
2015 Cloud-based adaptive compression and secure management services for 3D healthcare data
Arcangelo Castiglione, Raffaele Pizzolante, Alfredo De Santis, Bruno Carpentieri, Aniello Castiglione, Francesco Palmieri 0002
Future Gener. Comput. Syst.1
2015 Modeling energy-efficient secure communications in multi-mode wireless mobile devices
Arcangelo Castiglione, Francesco Palmieri 0002, Ugo Fiore, Aniello Castiglione, Alfredo De Santis
J. Comput. Syst. Sci.1
2015 Secure and reliable data communication in developing regions and rural areas
Arcangelo Castiglione, Raffaele Pizzolante, Francesco Palmieri 0002, Alfredo De Santis, Bruno Carpentieri, Aniello Castiglione
Pervasive Mob. Comput.1
2014 An Efficient and Transparent One-Time Authentication Protocol with Non-interactive Key Scheduling and Update
abstract
Authentication protocols prevent resources to be accessed by unauthorized users. Password authentication is one of the simplest and most convenient authentication mechanism over insecure networks and, in particular, the one-time authentication mechanism, in which the password is valid only for one login session or transaction are a good compromise between simplicity of use and security. Nowadays many of such protocols have been proposed to implement that type of authentication. However, most of them have several drawbacks because they are characterized by considerable overhead in the Key Setup, Key Scheduling and Key Update phases. In addition, they are often vulnerable to several known attacks and are not particularly suitable to be used by mobile terminals. Furthermore, they often rely on smart-card and other hardware tokens, thus requiring an active participation by the user. In this paper, we present a robust one-time authentication protocol, based on two cryptographically strong building blocks, namely, the Authenticated Key Exchange key exchange and the keyed Hash Message Authentication Code (HMAC), that provides several advantages with respect to most of the available solutions at the state of the art. First, it enables transparent mutual authentication between two endpoints. Moreover, Key Setup, Key Scheduling and Key Update operations are accomplished independently by both endpoints, without requiring any interaction among them, thus ensuring the fully independence by any Trusted Third Party. Finally, the proposed protocol is cryptographically secure, under standard assumptions against most of the already known OTP attacks.
Arcangelo Castiglione, Alfredo De Santis, Aniello Castiglione, Francesco Palmieri 0002
AINA1
2014 A fuzzy logic based reputation system for E-markets
abstract
During the last years, electronic markets (e-markets) are emerging as a new idea of economy, where trade transactions can be performed by buyers and sellers even if they are separated by geographic boundaries, time differences or distance barriers. Unfortunately, in this on-line trade environment, the probability of large-scale fraud and deceit is higher than traditional commerce because of the lack of face-to-face communications. For this reason, reputation systems, which enable to assess the trustiness level of transacting parties, are becoming a fundamental component of any current e-market portal. In this paper, we propose a new fuzzy logic based reputation system capable of efficiently assessing transacting parties through the exploitation of 1) a fuzzy trust model which takes into account a set of metrics reflecting the trust human perception both on seller and buyer side and, furthermore, it does not miss to consider past transactions; 2) a fuzzy based reputation aggregation taking into account credibility concept to discriminate false trust values. As shown by performed experiments, the proposed reputation system yields better performance than that used by one of the most known e-markets, eBay®.
Giovanni Acampora, Arcangelo Castiglione, Autilia Vitiello
FUZZ-IEEE2