VLDB 2026 Research / reviewers in the wild / expert
Federica Paci
dblp:18/3134
· DBLP profile ↗
44ranked-venue papers
8as first author
7since 2021 · last 2026
0000-0003-3122-0236ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 3 first-author · 4 since 2021Software engineering, systems software and programming languages · 14 · 3 first-author · 1 since 2021Databases, data management, data science and information retrieval · 6 · 2 first-authorArtificial intelligence and machine learning · 3 · 2 since 2021Systems, architecture and hardware · 3Applied, interdisciplinary, general and emerging computing · 3Human-computer interaction and ubiquitous computing · 2Computer networks · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Computing the Distribution of the Traces of a Business Process by Their Lengths
Matteo Cristani, Tewabe Chekole Workneh, Claudio Tomazzoli, Federica Paci |
IEA/AIE (3) | 4 |
| 2025 | A Formal Methodology for Risk Estimation in Business Process Management
Matteo Cristani, Tewabe Chekole Workneh, Claudio Tomazzoli, Federica Paci |
PRIMA | 4 |
| 2023 | HoneyICS: A High-interaction Physics-aware Honeynet for Industrial Control SystemsabstractIndustrial control systems (ICSs) are vulnerable to cyber-physical attacks, i.e., security breaches in cyberspace that adversely affect the underlying physical processes. In this context, honeypots are effective countermeasures both to defend against such attacks and discover new attack strategies. In recent years, honeypots for ICSs have made significant progress in faithfully emulating OT networks, including physical process interactions. We propose HoneyICS, a high-interaction, physics-aware, scalable, and extensible honeynet for ICSs, equipped with an advanced monitoring system. We deployed our honeynet on the Internet and conducted experiments to evaluate the effectiveness of HoneyICS. Marco Lucchese, Francesco Lupia, Massimo Merro, Federica Paci, Nicola Zannone, Angelo Furfaro |
ARES | 4 |
| 2023 | Mitigating Privilege Misuse in Access Control through Anomaly DetectionabstractAccess control is a fundamental component of IT systems to guarantee the confidentiality and integrity of sensitive resources. However, access control systems have inherent limitations: once permissions have been assigned to users, access control systems do not provide any means to prevent users from misusing such permissions. The problem of privilege misuse is typically addressed by employing auditing mechanisms, which verify users’ activities a posteriori. However, auditing does not allow for the timely detection and mitigation of privilege misuse. In this work, we propose a framework that complements access control with anomaly detection for the run-time monitoring of access requests and raises an alert when a user diverges from her normal access behavior. To detect anomalous access requests, we propose a novel approach to build user profiles by eliciting patterns of typical access behavior from historical access data. We evaluated our framework using the access log of a hospital. The results show that our framework has very few false positives and can detect several attack scenarios. Gelareh Hasel Mehri, Inez L. Wester, Federica Paci, Nicola Zannone |
ARES | 3 |
| 2023 | A Comprehensive Study on Third-Party User Tracking in Mobile ApplicationsabstractThird-party tracking is becoming a prevalent practice in mobile app ecosystems. While providing benefits for app developers, this practice also introduces several privacy issues for end-users. The European General Data Protection Regulation (GDPR) and the ePrivacy Directive (ePD) mandate that mobile apps must obtain user consent before sharing users’ personal data with third-party trackers. This work presents an empirical study investigating the compliance of 400 popular mobile apps (200 Android apps and their corresponding version for iOS) with the ePD and GDPR requirements on valid consent. Moreover, we determined whether these mobile apps actually enforce the consent given by users on being tracked and which are the more common third-party tracker domains contacted by the apps. The analysis shows that none of the studied apps fully comply with ePD and GDPR requirements on valid consent. The most common violations were associated with the principles of freely-given, specific, and revocable consent. Moreover, we found that almost half of the analyzed apps contact third-party tracker domains even when the user has not given their consent to be tracked. Federica Paci, Jacopo Pizzoli, Nicola Zannone |
ARES | 1 |
| 2023 | A new, evidence-based, theory for knowledge reuse in security risk analysisabstractAbstract Security risk analysis (SRA) is a key activity in software engineering but requires heavy manual effort. Community knowledge in the form of security patterns or security catalogs can be used to support the identification of threats and security controls. However, no evidence-based theory exists about the effectiveness of security catalogs when used for security risk analysis. We adopt a grounded theory approach to propose a conceptual, revised and refined theory of SRA knowledge reuse. The theory refinement is backed by evidence gathered from conducting interviews with experts (20) and controlled experiments with both experts (15) and novice analysts (18). We conclude the paper by providing insights into the use of catalogs and managerial implications. Katsiaryna Labunets, Fabio Massacci, Federica Paci, Katja Tuma |
Empir. Softw. Eng. | 3 |
| 2021 | Verifiable Hierarchical Key Assignment Schemes
Anna Lisa Ferrara, Federica Paci, Chiara Ricciardi |
DBSec | 2 |
| 2020 | A real world study on employees' susceptibility to phishing attacksabstractPhishing email attacks have been around for fifteen years but they are still among the top security risks faced by organisations. The most common approach to mitigate these attacks is employees' education and awareness. Employees' awareness on phishing attacks is achieved by embedded training that educate employees when they fall for the attack. However, the effectiveness of embedded training in workplace settings is uncertain given the large number of employees that remain vulnerable to phishing email attacks. Similarly, the role of persuasion techniques in making employees vulnerable to phishing attacks is yet to be investigated in the workplace settings. Therefore, in this paper we investigate which persuasion technique between authority and urgency is more effective in making employees susceptible to phishing, the relation between employees' susceptibility and their demographic data, and the effectiveness of embedded training in reducing employees' susceptibility to phishing attacks. To this end, we conducted a real phishing study with 191 employees of an Italian company. We found that employees were more vulnerable to phishing attacks when urgency principle was exploited. The study also showed no significant effect of employees' demographic data on susceptibility to phishing. Embedded training was perceived as effective by employees but it did not reduce their susceptibility to phishing. Marco De Bona, Federica Paci |
ARES | 2 |
| 2020 | Riskio: A Serious Game for Cyber Security Awareness and Education
Stephen Hart, Andrea Margheri, Federica Paci, Vladimiro Sassone |
Comput. Secur. | 3 |
| 2020 | Fuzzy-based approach to assess and prioritize privacy risks
Stephen Hart, Anna Lisa Ferrara, Federica Paci |
Soft Comput. | 3 |
| 2019 | Access control in Internet-of-Things: A survey
Sowmya Ravidas, Alexios Lekidis, Federica Paci, Nicola Zannone |
J. Netw. Comput. Appl. | 3 |
| 2018 | Towards Adaptive Access Control
Luciano Argento, Andrea Margheri, Federica Paci, Vladimiro Sassone, Nicola Zannone |
DBSec | 3 |
| 2018 | Model comprehension for security risk assessment: an empirical comparison of tabular vs. graphical representationsabstractContext: Tabular and graphical representations are used to communicate security risk assessments for IT systems. However, there is no consensus on which type of representation better supports the comprehension of risks (such as the relationships between threats, vulnerabilities and security controls). Vessey's cognitive fit theory predicts that graphs should be better because they capture spatial relationships. Method: We report the results of two studies performed in two countries with 69 and 83 participants respectively, in which we assessed the effectiveness of tabular and graphical representations concerning the extraction of correct information about security risks. Results: Participants who applied tabular risk models gave more precise and complete answers to the comprehension questions when requested to find simple and complex information about threats, vulnerabilities, or other elements of the risk models. Conclusions: Our findings can be explained by Vessey's cognitive fit theory as tabular models implicitly capture elementary linear spatial relationships. Interest for ICSE: It is almost taken for granted in Software Engineering that graphical-, diagram-based models are "the" way to go (e.g., the SE Body of Knowledge [3]). This paper provides some experimental-based doubts that this might not always be the case. It will provide an interesting debate that might ripple to traditional requirements and design notations outside security. Katsiaryna Labunets, Fabio Massacci, Federica Paci, Sabrina Marczak, Flávio M. de Oliveira |
ICSE | 3 |
| 2017 | Privacy-Preserving Access Control in Cloud FederationsabstractA Cloud federation is a collaboration of organizations sharing data hosted on their private cloud infrastructures in order to exploit a common business opportunity. However, the adoption of cloud federations is hindered by member organizations' concerns on sharing their data with potentially competing organizations. For cloud federations to be viable, federated organizations' privacy concerns should be alleviated by providing mechanisms that allow organizations to control which users from other federated organizations can access which data. We propose the architecture of a novel identity and access management system part of FaaS, a cloud federation service developed by the H2020 SUNFISH project. Our system allows federated organizations to enforce attribute-based access control policies on their data in a privacy-preserving fashion. Users are granted access to federated data when their identity attributes match the policies, but without revealing their attributes in clear. The architecture relies on two novel technologies, blockchain and Intel SGX hardware platform to guarantee integrity of the policy evaluation process. Shorouq Alansari, Federica Paci, Andrea Margheri, Vladimiro Sassone |
CLOUD | 2 |
| 2017 | A Distributed Access Control System for Cloud FederationsabstractCloud federations are a new collaboration paradigm where organizations share data across their private cloud infrastructures. However, the adoption of cloud federations is hindered by federated organizations' concerns on potential risks of data leakage and data misuse. For cloud federations to be viable, federated organizations' privacy concerns should be alleviated by providing mechanisms that allow organizations to control which users from other federated organizations can access which data. We propose a novel identity and access management system for cloud federations. The system allows federated organizations to enforce attribute-based access control policies on their data in a privacy-preserving fashion. Users are granted access to federated data when their identity attributes match the policies, but without revealing their attributes to the federated organization owning data. The system also guarantees the integrity of the policy evaluation process by using block chain technology and Intel SGX trusted hardware. It uses block chain to ensure that users identity attributes and access control policies cannot be modified by a malicious user, while Intel SGX protects the integrity and confidentiality of the policy enforcement process. We present the access control protocol, the system architecture and discuss future extensions. Shorouq Alansari, Federica Paci, Vladimiro Sassone |
ICDCS | 2 |
| 2017 | Decentralised Runtime Monitoring for Access Control Systems in Cloud FederationsabstractCloud federation is an emergent cloud-computing paradigm where partner organisations share data and services hosted on their own cloud platforms. In this context, it is crucial to enforce access control policies that satisfy data protection and privacy requirements of partner organisations. However, due to the distributed nature of cloud federations, the access control system alone does not guarantee that its deployed components cannot be circumvented while processing access requests. In order to promote accountability and reliability of a distributed access control system, we present a decentralised runtime monitoring architecture based on blockchain technology. Md Sadek Ferdous, Andrea Margheri, Federica Paci, Mu Yang, Vladimiro Sassone |
ICDCS | 3 |
| 2017 | On the Equivalence Between Graphical and Tabular Representations for Security Risk Assessment
Katsiaryna Labunets, Fabio Massacci, Federica Paci |
REFSQ | 3 |
| 2017 | Model comprehension for security risk assessment: an empirical comparison of tabular vs. graphical representations
Katsiaryna Labunets, Fabio Massacci, Federica Paci, Sabrina Marczak, Flávio M. de Oliveira |
Empir. Softw. Eng. | 3 |
| 2016 | Towards Empirical Evaluation of Automated Risk Assessment Methods
Olga Gadyatskaya, Katsiaryna Labunets, Federica Paci |
CRiSIS | 3 |
| 2016 | Formal Modelling of Data Integration Systems Security PoliciesabstractData Integration Systems (DIS) are concerned with integrating data from multiple data sources to resolve user queries. Typically, organisations providing data sources specify security policies that impose stringent requirements on the collection, processing, and disclosure of personal and sensitive data. If the security policies were not correctly enforced by the integration component of DIS, the data is exposed to data leakage threats, e.g. unauthorised disclosure or secondary use of the data. SecureDIS is a framework that helps system designers to mitigate data leakage threats during the early phases of DIS development. SecureDIS provides designers with a set of informal guidelines written in natural language to specify and enforce security policies that capture confidentiality, privacy, and trust properties. In this paper, we apply a formal approach to model a DIS with the SecureDIS security policies and verify the correctness and consistency of the model. The model can be used as a basis to perform security policies analysis or automatically generate a Java code to enforce those policies within DIS. Fatimah Y. Akeel, Asieh Salehi Fathabadi, Federica Paci, Andrew M. Gravell, Gary B. Wills |
Data Sci. Eng. | 3 |
| 2015 | The Role of Catalogues of Threats and Security Controls in Security Risk Assessment: An Empirical Study with ATM Professionals
Martina de Gramatica, Katsiaryna Labunets, Fabio Massacci, Federica Paci, Alessandra Tedeschi |
REFSQ | 4 |
| 2015 | Preventing Information Inference in Access ControlabstractTechnological innovations like social networks, personal devices and cloud computing, allow users to share and store online a huge amount of personal data. Sharing personal data online raises significant privacy concerns for users, who feel that they do not have full control over their data. A solution often proposed to alleviate users' privacy concerns is to let them specify access control policies that reflect their privacy constraints. However, existing approaches to access control often produce policies which either are too restrictive or allow the leakage of sensitive information. In this paper, we present a novel access control model that reduces the risk of information leakage. The model relies on a data model which encodes the domain knowledge along with the semantic relations between data. We illustrate how the access control model and the reasoning over the data model can be automatically translated in XACML. We evaluate and compare our model with existing access control models with respect to its effectiveness in preventing leakage of sensitive information and efficiency in authoring policies. The evaluation shows that the proposed model allows the definition of effective access control policies that mitigate the risks of inference of sensitive data while reducing users' effort in policy authoring compared to existing models. Federica Paci, Nicola Zannone |
SACMAT | 1 |
| 2014 | EMFASE - An Empirical Framework for Security Design and Economic Trade-offabstractEvaluation and validation methodologies are integral parts of Air Traffic Management (ATM). They are well understood for safety, environment and other Key Performance Areas, for which operational validation guidelines are well defined and widely used. In contrast, the effectiveness of risk assessment methods and practices for security, as well as their comparative evaluation is largely uncharted territory. There is limited information about the degree the practices and their corresponding activities provide security and whether or not they give return on investment. The "Empirical Framework for Security Design and Economics Trade-off" (EMFASE) project is investigating the above questions by applying different risk assessment methods on different application scenarios, such as the Remotely Operated Tower, and by evaluating them with respect to their performance, security impact, usability, and economy. In this paper we report the preliminary work carried out in EMFASE about the elicitation of a set of ATM relevant evaluation criteria for the comparison and assessment of the risk assessment methods under study and a brief description of the first set of experiments carried out. Fabio Massacci, Federica Paci, Bjørnar Solhaug, Alessandra Tedeschi |
ARES | 2 |
| 2014 | Security triage: an industrial case study on the effectiveness of a lean methodology to identify security requirementsabstractContext: Poste Italiane is a large corporation offering integrated services in banking and savings, postal services, and mobile communication. Every year, it receives thousands of change requests for its ICT services. Applying to each and every request a security assessment "by the book" is simply not possible. Goal: We report the experience by Poste Italiane of a lean methodology to identify security requirements that can be inserted in the production cycle of a normal company. Method: The process is based on surveying the overall IT architectures (Security Survey) and then a lean dynamic process (Security Triage) to evaluate individual change requests, so that important changes get the attention they need, minor changes can be quickly implemented, and compliance and security obligations are met. Results: The empirical evaluation conducted for over an year at Poste Italiane shows that the process significantly reduces the time to identify security requirements at the pace of change. Conclusions: The Security Survey and Triage process should thus be embedded in a company's production cycle as mandatory step to manage change requests so that security initiatives are prioritized based on the relevance of the assets and of the business objectives of the company. Matteo Giacalone, Federica Paci, Rocco Mammoliti, Rodolfo Perugino, Fabio Massacci, Claudio Selli |
ESEM | 2 |
| 2014 | Assessing a requirements evolution approach: Empirical studies in the air traffic management domain
Fabio Massacci, Federica Paci, Le Minh Sang Tran, Alessandra Tedeschi |
J. Syst. Softw. | 2 |
| 2013 | Detecting Insider Threats: A Trust-Aware FrameworkabstractThe number of insider threats hitting organizations and big enterprises is rapidly growing. Insider threats occur when trusted employees misuse their permissions on organizational assets. Since insider threats know the organization and its processes, very often they end up undetected. Therefore, there is a pressing need for organizations to adopt preventive mechanisms to defend against insider threats. In this paper, we propose a framework for insiders identification during the early requirement analysis of organizational settings and of its IT systems. The framework supports security engineers in the detection of insider threats and in the prioritization of them based on the risk they represent to the organization. To enable the automatic detection of insider threats, we extend the SI* requirement modeling language with an asset model and a trust model. The asset model allows associating security properties and sensitivity levels to assets. The trust model allows specifying the trust level that a user places in another user with respect to a given permission on an asset. The insider threats identification leverages the trust levels associated with the permissions assigned to users, as well as the sensitivity of the assets to which access is granted. We illustrate the approach based on a patient monitoring scenario. Federica Paci, Carmen Fernández Gago, Francisco Moyano |
ARES | 1 |
| 2013 | An Experimental Comparison of Two Risk-Based Security MethodsabstractA significant number of methods have been proposed to identify and analyze threats and security requirements, but there are few empirical evaluations that show these methods work in practice. This paper reports a controlled experiment conducted with 28 master students to compare two classes of risk-based methods, visual methods (CORAS) and textual methods (SREP). The aim of the experiment was to compare the effectiveness and perception of the two methods. The participants divided in groups solved four different tasks by applying the two methods using a randomized block design. The dependent variables were effectiveness of the methods measured as number of threats and security requirements identified, and perception of the methods measured through a post-task questionnaire based on the Technology Acceptance Model. The experiment was complemented with participants' interviews to determine which features of the methods influence their effectiveness. The main findings were that the visual method is more effective for identifying threats than the textual one, while the textual method is slightly more effective for eliciting security requirements. In addition, visual method overall perception and intention to use were higher than for the textual method. Katsiaryna Labunets, Fabio Massacci, Federica Paci, Le Minh Sang Tran |
ESEM | 3 |
| 2013 | Privacy-Aware Web Service Composition and RankingabstractService selection is a key issue in the Future Internet, where applications are built by composing services and content offered by different service providers. Most existing service selection schemas only focus on QoS properties of services such as throughput, latency and response time, or on their trust and reputation level. By contrast, the risk of privacy breaches arising from the selection of component services whose privacy policy is not compliant with customers' privacy preferences is largely ignored. In this paper, we propose a novel privacy-preserving Web service composition and selection approach which (i) makes it possible to verify the compliance between users' privacy requirements and providers' privacy policies and (ii) ranks the composite Web services with respect to the privacy level they offer. We demonstrate our approach using a travel agency Web service as an example of service composition. Elisa Costante, Federica Paci, Nicola Zannone |
ICWS | 2 |
| 2012 | Managing Evolution by Orchestrating Requirements and Testing Engineering ProcessesabstractChange management and change propagation across the various models of the system (such as requirements, design and testing models) are well-known problems in software engineering. For such problems a number of solutions have been proposed that are usually based on the integration of model repositories and on the maintenance of traceability links between the models. We propose to manage the mutual evolution of requirements models and tests models by orchestrating processes based on a minimal shared interface. Thus, requirement and test engineers must only have a basic knowledge about the ``other'' domain, share a minimal set of concepts and can follow their ``own'' respective processes. The processes are orchestrated in the sense that when a change affects a concept of the interface, the change is propagated to the other domain. We illustrate the approach using the evolution of the Global Platform standard. Federica Paci, Fabio Massacci, Fabrice Bouquet, Stephane Debricon |
ICST | 1 |
| 2011 | Managing changes with legacy security engineering processesabstractManaging changes in Security Engineering is a difficult task: the analyst must keep the consistency between security knowledge such as assets, attacks and treatments to stakeholders' goals and security requirements. Research-wise the usual solution is an integrated methodology in which risk, security requirements and architectural solutions are addressed within the same tooling environment and changes can be easily propagated. This solution cannot work in practice as the steps of security engineering process requires to use artefacts (documents, models, data bases) and manipulate tools that are disjoint and cannot be fully integrated for a variety of reasons (separate engineering domains, outsourcing, confidentiality, etc.). We call such processes legacy security engineering processes. In this paper, we propose a change management framework for legacy security engineering processes. The key idea is to separate concerns between the requirements, risk and architectural domains while keeping an orchestrated view (as opposed to an integrated view). We identify some mapping concepts among the domains so that little knowledge is required from the requirement manager about the other domains, and similarly for security risk manager and the system designer: they can stick to their well known (and possibly certified) internal process. This minimal set of concepts is the interface between the legacy processes. The processes are then orchestrated in the sense that when a change affects a concept of the interface, the change is propagated to the other domain. We illustrate this example by using the risk modeling language (Security DSML) from Thales Research and the security requirement language (SI*) from the Univ. of Trento. Edith Felix, Olivier Delande, Fabio Massacci, Federica Paci |
ISI | 4 |
| 2011 | ACConv - An Access Control Model for Conversational Web ServicesabstractWith organizations increasingly depending on Web services to build complex applications, security and privacy concerns including the protection of access control policies are becoming a serious issue. Ideally, service providers would like to make sure that clients have knowledge of only portions of the access control policy relevant to their interactions to the extent to which they are entrusted by the Web service and without restricting the client’s choices in terms of which operations to execute. We propose ACConv , a novel model for access control in Web services that is suitable when interactions between the client and the Web service are conversational and long-running. The conversation-based access control model proposed in this article allows service providers to limit how much knowledge clients have about the credentials specified in their access policies. This is achieved while reducing the number of times credentials are asked from clients and minimizing the risk that clients drop out of a conversation with the Web service before reaching a final state due to the lack of necessary credentials. Clients are requested to provide credentials, and hence are entrusted with part of the Web service access control policies, only for some specific granted conversations which are decided based on: (1) a level of trust that the Web service provider has vis-à-vis the client, (2) the operation that the client is about to invoke, and (3) meaningful conversations which represent conversations that lead to a final state from the current one. We have implemented the proposed approach in a software prototype and conducted extensive experiments to show its effectiveness. Federica Paci, Massimo Mecella, Mourad Ouzzani, Elisa Bertino |
ACM Trans. Web | 1 |
| 2010 | PriMa: an effective privacy protection mechanism for social networksabstractIn this paper, we propose PriMa (Privacy Manager), a privacy protection mechanism which supports semi-automated generation of access rules for users' profile information. PriMa access rules are tailored by the users' privacy preferences for their profile data, the sensitivity of the data itself, and the objective risk of disclosing this data to other users. The resulting rules are simple, yet powerful specifications indicating the adequate level of protection for each user, and are dynamically adapted to the ever changing setting of the users' preferences and SN configuration. Anna Cinzia Squicciarini, Federica Paci, Smitha Sundareswaran |
AsiaCCS | 2 |
| 2010 | A privacy-preserving approach to policy-based content disseminationabstractWe propose a novel scheme for selective distribution of content, encoded as documents, that preserves the privacy of the users to whom the documents are delivered and is based on an efficient and novel group key management scheme. Our document broadcasting approach is based on access control policies specifying which users can access which documents, or subdocuments. Based on such policies, a broadcast document is segmented into multiple subdocuments, each encrypted with a different key. In line with modern attribute-based access control, policies are specified against identity attributes of users. However our broadcasting approach is privacy-preserving in that users are granted access to a specific document, or subdocument, according to the policies without the need of providing in clear information about their identity attributes to the document publisher. Under our approach, not only does the document publisher not learn the values of the identity attributes of users, but it also does not learn which policy conditions are verified by which users, thus inferences about the values of identity attributes are prevented. Moreover, our key management scheme on which the proposed broadcasting approach is based is efficient in that it does not require to send the decryption keys to the users along with the encrypted document. Users are able to reconstruct the keys to decrypt the authorized portions of a document based on subscription information they have received from the document publisher. The scheme also efficiently handles new subscription of users and revocation of subscriptions. Mohamed Nabeel, Federica Paci, Elisa Bertino |
ICDE | 3 |
| 2010 | Group-Based Negotiations in P2P SystemsabstractIn P2P systems, groups are typically formed to share resources and/or to carry on joint tasks. In distributed environments formed by a large number of peers conventional authentication techniques are inadequate for the group joining process, and more advanced ones are needed. Complex transactions among peers may require more elaborate interactions based on what peers can do or possess instead of peers' identity. In this work, we propose a novel peer group joining protocol. We introduce a highly expressive resource negotiation language, able to support the specification of a large variety of conditions applying to single peers or groups of peers. Moreover, we define protocols to test such resource availability customized to the level of assurance required by the peers. Our approach has been tested and evaluated on an extension of the JXTA P2P platform. Our results show the robustness of our approach in detecting malicious peers, detected both during the negotiation and during the peer group lifetime. Regardless of the peer group cardinality and interaction frequency, the peers always detect possible free riders within a small time frame. Anna Cinzia Squicciarini, Federica Paci, Elisa Bertino, Alberto Trombetta, Stefano Braghin |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2009 | Identity Attribute-Based Role Provisioning for Human WS-BPEL ProcessesabstractThe WS-BPEL specification focuses on business processes the activities of which are assumed to be interactions with Web services. However, WS-BPEL processes go beyond the orchestration of activities exposed as Web services. There are cases in which people must be considered as additional participants to the execution of a process. The inclusion of humans, in turn, requires solutions to support the specification and enforcement of authorizations to users for the execution of human activities while enforcing authorization constraints. In this paper, we extend RBAC-WS-BPEL, a role-based authorization framework for WS-BPEL processes with an identity attribute-based role provisioning approach that preserves the privacy of the users who claim the execution of human activities. Such approach is based on the notion of identity records and role provisioning policies, and uses Pedersen commitments, aggregated zero knowledge proof of knowledge, and Oblivious Commitment-Based Envelope protocols to achieve privacy of user identity information. Federica Paci, Rodolfo Ferrini, Elisa Bertino |
ICWS | 1 |
| 2009 | VeryIDX - A Privacy Preserving Digital Identity Management System for Mobile DevicesabstractThe combined use of the Internet and mobile technologies is leading to major changes in how individuals communicate, conduct business transactions and access resources and services. In such a scenario, digital identity management (DIM) technology is fundamental for enabling transactions and interactions across the Internet. In this demo, we demonstrate VeryIDX, a system for the privacy-preserving management of users' identity attributes on mobile devices. Federica Paci, Kevin Steuer Jr., Ruchith Fernando, Elisa Bertino |
Mobile Data Management | 1 |
| 2009 | Collective privacy management in social networksabstractSocial Networking is one of the major technological phenomena of the Web 2.0, with hundreds of millions of people participating. Social networks enable a form of self expression for users, and help them to socialize and share content with other users. In spite of the fact that content sharing represents one of the prominent features of existing Social Network sites, Social Networks yet do not support any mechanism for collaborative management of privacy settings for shared content. In this paper, we model the problem of collaborative enforcement of privacy policies on shared data by using game theory. In particular, we propose a solution that offers automated ways to share images based on an extended notion of content ownership. Building upon the Clarke-Tax mechanism, we describe a simple mechanism that promotes truthfulness, and that rewards users who promote co-ownership. We integrate our design with inference techniques that free the users from the burden of manually selecting privacy preferences for each picture. To the best of our knowledge this is the first time such a protection mechanism for Social Networking has been proposed. In the paper, we also show a proof-of-concept application, which we implemented in the context of Facebook, one of today’s most popular social networks. We show that supporting these type of solutions is not also feasible, but can be implemented through a minimal increase in overhead to end-users. Anna Cinzia Squicciarini, Mohamed Shehab, Federica Paci |
WWW | 3 |
| 2008 | A Federated Digital Identity Management Approach for Business Processes
Elisa Bertino, Rodolfo Ferrini, Andrea Musci, Federica Paci, Kevin J. Steuer |
CollaborateCom | 4 |
| 2008 | Monitoring Contract Enforcement within Virtual Organizations
Anna Cinzia Squicciarini, Federica Paci |
CollaborateCom | 2 |
| 2008 | Authorization and User Failure Resiliency for WS-BPEL Business Processes
Federica Paci, Rodolfo Ferrini, Yuqing Sun 0001, Elisa Bertino |
ICSOC | 1 |
| 2007 | User Tasks and Access Control overWeb ServicesabstractWeb services are a successful technology for enterprise information management, where they are used to expose legacy applications on the corporate intranet or in business-to-business scenarios. The technologies used to expose applications as Web services have matured, stabilized, and are defined as W3C standards. Now, the technology used to build applications based on Web services, a process known as orchestration, is also maturing around the Web Services Business Process Execution Language (WS-BPEL). WS-BPEL falls short on one feature though: as it is focused on orchestration of fully automatic Web-services, WS- BPEL does not provide means for specifying human interactions, even less their access-control requirements. Human interactions are nonetheless needed for flexible business processes. This lacking feature of WS-BPEL has been highlighted in a white paper issued jointly by IBM and SAP, which "describes scenarios where users are involved in business processes, and defines appropriate extensions to WS-BPEL to address these." These extensions, called BPEL4People, are well explained, but their implementation isn't. In this paper, we propose a language for specifying these extensions, as well as an architecture to support them. The salient advantage of our architecture is that it allows for the reuse of existing BPEL engines. In addition, our language allows for specifying these extensions within the main BPEL script, hence preserving a global view of the process. We illustrate our extensions by revisiting the classic loan approval BPEL example. Jacques Thomas, Federica Paci, Elisa Bertino, Patrick Eugster |
ICWS | 2 |
| 2007 | PP-trust-X: A system for privacy preserving trust negotiationsabstractTrust negotiation is a promising approach for establishing trust in open systems, in which sensitive interactions may often occur between entities with no prior knowledge of each other. Although, to date several trust negotiation systems have been proposed, none of them fully address the problem of privacy preservation. Today, privacy is one of the major concerns of users when exchanging information through the Web and thus we believe that trust negotiation systems must effectively address privacy issues in order to be widely applicable. For these reasons, in this paper, we investigate privacy in the context of trust negotiations. We propose a set of privacy-preserving features for inclusion in any trust negotiation system, such as the support for the P3P standard, as well as a number of innovative features, such as a novel format for encoding digital credentials specifically designed for preserving privacy. Further, we present a variety of interoperable strategies to carry on the negotiation with the aim of improving both privacy and efficiency. Anna Cinzia Squicciarini, Elisa Bertino, Elena Ferrari 0001, Federica Paci, Bhavani Thuraisingham |
ACM Trans. Inf. Syst. Secur. | 4 |
| 2006 | Access Control and Authorization Constraints for WS-BPELabstractComputerized workflow systems have attracted considerable research interest. More recently, there have been several XML-based languages proposed for specifying and orchestrating business processes, culminating in WS-BPEL. A significant omission from WS-BPEL is the ability to specify authorization information associating users with activities in the business process and authorization constraints on the execution of activities such as separation of duty. In this paper, we address these deficiencies by developing the RBAC-WS-BPEL and BPCL languages. The first of these provides for the specification of authorization information associated with a business process specified in WS-BPEL, while BPCL provides for the articulation of authorization constraints Elisa Bertino, Jason Crampton, Federica Paci |
ICWS | 3 |
| 2006 | Access control enforcement for conversation-based web servicesabstractService Oriented Computing is emerging as the main approach to build distributed enterprise applications on the Web. The widespread use of Web services is hindered by the lack of adequate security and privacy support. In this paper, we present a novel framework for enforcing access control in conversation-based Web services. Our approach takes into account the conversational nature of Web services. This is in contrast with existing approaches to access control enforcement that assume a Web service as a set of independent operations. Furthermore, our approach achieves a tradeoff between the need to protect Web service's access control policies and the need to disclose to clients the portion of access control policies related to the conversations they are interested in. This is important to avoid situations where the client cannot progress in the conversation due to the lack of required security requirements. We introduce the concept of k-trustworthiness that defines the conversations for which a client can provide credentials maximizing the likelihood that it will eventually hit a final state. Massimo Mecella, Mourad Ouzzani, Federica Paci, Elisa Bertino |
WWW | 3 |