VLDB 2026 Research / reviewers in the wild / expert
Andrea Continella
dblp:190/9885
· DBLP profile ↗
35ranked-venue papers
4as first author
25since 2021 · last 2026
0000-0002-0329-1830ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 33 · 4 first-author · 23 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ImmuCheck: Selective Immutability for Container Escape Detection in Containerized MicroservicesabstractContainer escape attacks break isolation boundaries, granting threat actors code execution on the underlying host and potentially full control over the entire cluster. Existing runtime defenses exhibit an inherent trade-off. Anomaly- and provenance-based detection mechanisms achieve broad escape detection, yet incur substantial operational costs due to model retraining requirements or system-wide provenance capture. In contrast, industry rule-based detectors avoid these costs but offer limited detection coverage. Asbat El Khairi, Amina Bassit, Andreas Peter 0001, Andrea Continella |
AsiaCCS | 4 |
| 2026 | SoK: Systematization, Detection, and Hunting of Windows Malware Persistence TechniquesabstractIn order to maintain its presence on an infected system, malware employs a variety of persistence techniques. Although persistence is a well-known tactic of modern malware, our community lacks a comprehensive understanding of the types and prevalence of techniques adopted by Windows malware. Jorik van Nielen, Andrea Oliveri, Jerre Starink, Andreas Peter 0001, Marieke Huisman, Simone Aonzo, Davide Balzarotti, Andrea Continella |
AsiaCCS | 8 |
| 2026 | SoK: Understanding the state of IoT-specific vulnerabilities via CVE characterization with LLIoTabstractFollowing the expansion of IoT systems, spanning from devices to cloud backends, reported IoT CVE vulnerabilities have increased at an alarming pace. Since most IoT attacks exploit known vulnerabilities, understanding known vulnerabilities is vital for defense and security research. In this work, we systematize the prior research on studying IoT vulnerabilities, revealing the absence of consistent IoT definitions, reliable and scalable classification methodologies, and high-quality IoT CVE datasets. To overcome these limitations, we design LLIoT, a novel and LLM-assisted approach that systematically and automatically distinguishes IoT-specific CVEs at large scale, enabling in-depth under-standing of IoT vulnerabilities. First, leveraging the systematization knowledge from the literature, we derive a four-layer IoT ecosystem taxonomy and define classification criteria for distinguishing IoT CVEs. Then, using an expert-validated ground-truth dataset, we demonstrate that LLMs can reliably distinguish IoT from non-IoT CVEs with a high accuracy of 95%, outperforming humans by avoiding cognitive errors and gaps in domain knowledge. Applying LLIoT to CVEs from 2013-2024, we build a dataset of 15,116 IoT-specific vulnerabilities, of which 8,368 are newly classified with respect to previous datasets. Using this dataset, which we share with the research community for further research and reproducibility, we characterize how IoT vulnerabilities differ from traditional IT vulnerabilities. Upon our observation, we provide actionable recommendations for responsible stakeholders. Tina Rezaei, Suzan Bayhan, Andrea Continella, Jeroen van der Ham, Roland van Rijswijk-Deij |
EuroS&P | 3 |
| 2025 | R+R: IoT Device Identification Under Realistic ConditionsabstractInternet of Things (IoT) devices are ubiquitous, yet they often present security issues. The research community has invested substantial effort in designing automated methods for identifying these devices through passive network analysisan essential step in security applications such as anomaly detection, traffic monitoring, and vulnerability scanning. However, despite the promising results reported in laboratory settings, the effectiveness of these methods under realistic conditions remains unclear. In this work, we systematically review the existing literature on IoT device identification by studying the approaches, features, and evaluation environments. We then design and implement a framework to reproduce and evaluate selected identification methods. We re-implement the selected methods and assess their performance, using our framework, under realistic environmental factors, such as non-IoT traffic, dynamic user activity, and unknown devices. Our study reveals several important insights. We demonstrate that the performances of current identification methods significantly decline under realistic conditions. Furthermore, we highlight these methods' inability to differentiate between known and unknown devices, raising concerns about their effectiveness in security applications such as anomaly detection. We conclude by providing actionable recommendations for future research. Chakshu Gupta, Andreas Peter 0001, Andrea Continella |
ACSAC | 3 |
| 2025 | WhisperTest: A Voice-Control-based Library for iOS UI AutomationabstractDynamic analysis and UI automation are essential for scalable detection of privacy leaks, vulnerabilities, and malicious code in mobile apps. While the Android ecosystem offers a variety of tools, options for iOS apps are limited and require either access to the app source code or jailbreaking the test device. To address this gap, we introduce WhisperTest, an open-source iOS UI automation library that operates without jailbreaking. WhisperTest is based on a newly designed approach that leverages Apple's Voice Control accessibility feature to interact with app or system UIs via text-to-speech. During interactions, WhisperTest monitors the device system logs in real time and scrapes the UI via screenshots and accessibility audits to recover app state changes. We demonstrate WhisperTest's capabilities through a diverse set of tasks, including a web privacy measurement and a fully-automated dynamic analysis of 200 child-directed iOS apps. To overcome the challenges of automating apps with diverse UI designs, WhisperTest optionally integrates multimodal large language models to reason about context and interact with system permission prompts, consent dialogs, subscription prompts, and age gates. Our exploratory analysis of children's apps uncovers widespread use of third-party tracking, limited recognition of user consent, and unencrypted HTTP requests. Overall, we show that WhisperTest enables scalable dynamic analysis of iOS applications across diverse tasks, contributing to a safer and more transparent mobile ecosystem. Zahra Moti, Tom Janssen-Groesbeek, Steven Monteiro, Andrea Continella, Gunes Acar |
CCS | 4 |
| 2025 | LibAFLstar: Fast and State-Aware Protocol Fuzzing
Cristian Daniele, Timme Bethe, Marcello Maugeri, Andrea Continella, Erik Poll |
ESORICS (3) | 4 |
| 2025 | SoK: Hardening Techniques in the Mobile Ecosystem - Are We There Yet?abstractIrrespective of the security and isolation guarantees offered by the mobile operating system, the Mobile Application Security Verification Standard (MASVS) recommends app developers to implement hardening techniques for self-protection—to prevent tampering and leakage, detect jailbreaks, etc. Despite regulations incentivize developers toward implementing self-protection, our understanding of the use of hardening techniques is still very limited—especially regarding differences, if any, between the two main mobile ecosystems. In this paper, we systematize knowledge on the use and analysis of hardening techniques, covering, for the first time, both Android and iOS apps.To this end, we present HALY, a framework to analyze the adoption of hardening techniques. Using HALY’s static and dynamic analysis, we analyze 2,646 popular apps available on both Android and iOS, and measure the prevalence of hardening techniques. Contrary to expectation, apps on iOS underperform in self-protection, implementing only half of the recommended hardening techniques compared to their Android counterparts—challenging the long-held belief that iOS is simply “more secure.” Equally surprising, while privacy-sensitive apps implement more self-protection, many apps implement hardening techniques on only one of the two OSes. Furthermore, as many common techniques are easy to individually bypass, the additional security is questionable. Overall, almost all apps implement some hardening techniques, but as many as 24.1% (Android) and 73.6% (iOS) implement fewer than half of the recommended ones, and we only found 26 apps on Android to implement all eight and only one app on iOS adopt all seven analyzed techniques. Magdalena Steinböck, Jens Troost, Wilco Van Beijnum, Jan Seredynski, Herbert Bos, Martina Lindorfer, Andrea Continella |
EuroS&P | 7 |
| 2025 | SoK: Automated TTP Extraction from CTI Reports - Are We There Yet?
Marvin Büchel, Tommaso Paladini, Stefano Longari, Michele Carminati, Stefano Zanero, Hodaya Binyamini, Gal Engelberg, Daniel Klein 0003, Giancarlo Guizzardi, Marco Caselli, Andrea Continella, Maarten van Steen, Andreas Peter 0001, Thijs van Ede |
USENIX Security Symposium | 11 |
| 2025 | Behavior Nets: Context-Aware Behavior Modeling for Code Injection-Based Windows MalwareabstractDespite significant effort put into research and development of defense mechanisms, new malware is continuously developed rapidly, making it still one of the major threats on the Internet. For malware to be successful, it is in the developer’s best interest to evade detection as long as possible. One method in achieving this is using Code Injection, where malicious code is injected into another benign process, making it do something it was not intended to do. Automated detection and characterization of Code Injection is difficult. Many injection techniques depend solely on system calls that in isolation look benign and can easily be confused with other background system activity. There is therefore a need for models that can consider the context in which a single system event resides, such that relevant activity can be distinguished easily. In previous work, we conducted the first systematic study on code injection to gain more insights into the different techniques available to malware developers on the Windows platform. This paper extends this work by introducing and formalizing Behavior Nets: A novel, reusable, context-aware modeling language that expresses malicious software behavior in observable events and their general interdependence. This allows for matching on system calls, even if those system calls are typically used in a benign context. We evaluate Behavior Nets and experimentally confirm that introducing event context into behavioral signatures yields better results in characterizing malicious behavior than the state of the art. We conclude with valuable insights on how future malware research based on dynamic analysis should be conducted. Jerre Starink, Marieke Huisman, Andreas Peter 0001, Andrea Continella |
ACM Trans. Priv. Secur. | 4 |
| 2024 | Inferring Recovery Steps from Cyber Threat Intelligence Reports
Zsolt Levente Kucsván, Marco Caselli, Andreas Peter 0001, Andrea Continella |
DIMVA | 4 |
| 2024 | REPLICAWATCHER: Training-less Anomaly Detection in Containerized Microservices
Asbat El Khairi, Marco Caselli, Andreas Peter 0001, Andrea Continella |
NDSS | 4 |
| 2024 | ERAFL: Efficient Resource Allocation for Federated Learning Training in Smart HomesabstractWith the growing number of Federated Learning (FL) applications in smart homes, it becomes crucial to manage communication and computation resources within the smart home so that FL applications can complete their training on time. While computation offloading has relieved the challenge of timely completion of applications in case of high competition for local resources, privacy of the smart home data remains a critical concern. This paper introduces ERAFL, a resource allocation and computation offloading algorithm running on a home gateway. Unlike privacy-oblivious prior works, ERAFL considers privacy-sensitivity level of FL training data in offloading decision, prioritizing local processing of more sensitive data, e.g., biological personal data. Moreover, in case of insufficient local resources, ERAFL offloads a part of data and accelerates training by leveraging parallel training on the cloud and the edge device. It also imposes limits on the amount of offloaded data or performs the training either locally or remotely to ensure model accuracy. Our simulation results show that ERAFL can satisfy more FL training tasks and reduce data privacy leakage in comparison to the baselines that do not consider partial offloading, privacy sensitivity of application data or resource allocation. Tina Rezaei, Suzan Bayhan, Andrea Continella, Roland van Rijswijk-Deij |
NOMS | 3 |
| 2024 | Large-Scale Security Analysis of Real-World Backend Deployments Speaking IoT-Focused ProtocolsabstractInternet-of-Things (IoT) devices, ranging from smart home assistants to health devices, are pervasive: Forecasts estimate their number to reach 29 billion by 2030. Understanding the security of their machine-to-machine communication is crucial. Prior work focused on identifying devices’ vulnerabilities or proposed protocol-specific solutions. Instead, we investigate the security of backends speaking IoT protocols, that is, the backbone of the IoT ecosystem. Carlotta Tagliaro, Martina Komsic, Andrea Continella, Kevin Borgolte, Martina Lindorfer |
RAID | 3 |
| 2023 | Divak: Non-invasive Characterization of Out-of-Bounds Write Vulnerabilities
Linus Hafkemeyer, Jerre Starink, Andrea Continella |
DIMVA | 3 |
| 2023 | AoT - Attack on Things: A security analysis of IoT firmware updatesabstractIoT devices implement firmware update mechanisms to fix security issues and deploy new features. These mechanisms are often triggered and mediated by mobile companion apps running on the users’ smartphones. While it is crucial to update devices, these mechanisms may cause critical security flaws if they are not implemented correctly. Given their relevance, in this paper, we perform a systematic security analysis of the firmware update mechanisms adopted by IoT devices via their companion apps. First, we define a threat model for IoT firmware updates, and we categorize the different potential security issues affecting them. Then, we analyze 23 popular IoT devices (and corresponding companion apps) to identify vulnerable devices and the SDKs that such devices use to implement the update functionality. Our analysis reveals that 6 popular SDKs present dangerous security flaws. Additionally, we fingerprint each vulnerable SDK and we leverage our fingerprints to perform a large-scale analysis of companion apps from the Google Play Store. Our results show that 61 popular devices and 1,356 apps rely on vulnerable SDKs, thus, they potentially adopt an insecure firmware update mechanism. Muhammad Ibrahim 0004, Andrea Continella, Antonio Bianchi |
EuroS&P | 2 |
| 2023 | Columbus: Android App Testing Through Systematic Callback ExplorationabstractWith the continuous rise in the popularity of Android mobile devices, automated testing of apps has become more important than ever. Android apps are event-driven programs. Unfortunately, generating all possible types of events by interacting with an app's interface is challenging for an automated testing approach. Callback-driven testing eliminates the need for event generation by directly invoking app callbacks. However, existing callback-driven testing techniques assume prior knowledge of Android callbacks, and they rely on a human expert, who is familiar with the Android API, to write stub code that prepares callback arguments before invocation. Since the Android API is very large and keeps evolving, prior techniques could only support a small fraction of callbacks present in the Android framework. In this work, we introduce Columbus, a callback-driven testing technique that employs two strategies to eliminate the need for human involvement: (i) it automatically identifies callbacks by simultaneously analyzing both the Android framework and the app under test; (ii) it uses a combination of under-constrained symbolic execution (primitive arguments), and type-guided dynamic heap introspection (object arguments) to generate valid and effective inputs. Lastly, Columbus integrates two novel feedback mechanisms-data dependency and crash-guidance- during testing to increase the likelihood of triggering crashes and maximizing coverage. In our evaluation, Columbus outperforms state-of-the-art model-driven, checkpoint-based, and callback-driven testing tools both in terms of crashes and coverage. Priyanka Bose, Dipanjan Das 0002, Saastha Vasan, Sebastiano Mariani, Ilya Grishchenko, Andrea Continella, Antonio Bianchi, Christopher Krügel, Giovanni Vigna |
ICSE | 6 |
| 2023 | Shimware: Toward Practical Security Retrofitting for Monolithic Firmware ImagesabstractIn today’s era of the Internet of Things, we are surrounded by security- and safety-critical, network-connected devices. In parallel with the rise in attacks on such devices, we have also seen an increase in devices that are abandoned, reached the end of their support periods, or will not otherwise receive future security updates. While this issue exists for a wide array of devices, those that use monolithic firmware, where the code and data are opaquely intermixed, have traditionally been difficult to examine and protect. Eric Gustafson, Paul Grosen, Nilo Redini, Saagar Jha, Andrea Continella, Ruoyu Wang 0001, Kevin Fu, Sara Rampazzi, Christopher Krügel, Giovanni Vigna |
RAID | 5 |
| 2023 | Understanding and Measuring Inter-process Code Injection in Windows Malware
Jerre Starink, Marieke Huisman, Andreas Peter 0001, Andrea Continella |
SecureComm (2) | 4 |
| 2022 | Stepping out of the MUD: Contextual threat information for IoT devices with manufacturer-provided behavior profilesabstractBesides coming with unprecedented benefits, the Internet of Things (IoT) suffers deficits in security measures, leading to attacks increasing every year. In particular, network environments such as smart homes lack managed security capabilities to detect IoT-related attacks; IoT devices hosted therein are thus more easily targeted by threats. As such, context awareness of IoT infections is hard to achieve, preventing prompt response. In this work, we propose MUDscope, an approach to monitor malicious network activities affecting IoT systems in real-world consumer environments. We leverage the recent Manufacturer Usage Description (MUD) specification, which defines networking allow-lists for IoT devices in MUD profiles, to reflect consistent and necessarily-anomalous activities from smart things. Our approach characterizes this traffic and extracts signatures for given attacks. By analyzing attack signatures for multiple devices, we gather insights into emerging attack patterns. We evaluate our approach on both an existing dataset and a new, openly available dataset created for this research. We show that MUDscope detects several attacks targeting IoT devices with an F1-score of 95.77% and correctly identifies signatures for specific attacks with an F1-score of 87.72%. Luca Morgese Zangrandi, Thijs van Ede, Tim M. Booij, Savio Sciancalepore, Luca Allodi, Andrea Continella |
ACSAC | 6 |
| 2022 | DEEPCASE: Semi-Supervised Contextual Analysis of Security EventsabstractSecurity monitoring systems detect potentially malicious activities in IT infrastructures, by either looking for known signatures or for anomalous behaviors. Security operators investigate these events to determine whether they pose a threat to their organization. In many cases, a single event may be insufficient to determine whether certain activity is indeed malicious. Therefore, a security operator frequently needs to correlate multiple events to identify if they pose a real threat. Unfortunately, the vast number of events that need to be correlated often overload security operators, forcing them to ignore some events and, thereby, potentially miss attacks. This work studies how to automatically correlate security events and, thus, automate parts of the security operator workload. We design and evaluate DEEPCASE, a system that leverages the context around events to determine which events require further inspection. This approach reduces the number of events that need to be inspected. In addition, the context provides valuable insights into why certain events are classified as malicious. We show that our approach automatically filters 86.72% of the events and reduces the manual workload of security operators by 90.53%, while underestimating the risk of potential threats in less than 0.001% of cases. Thijs van Ede, Hojjat Aghakhani, Noah Spahn, Riccardo Bortolameotti, Marco Cova, Andrea Continella, Maarten van Steen, Andreas Peter 0001, Christopher Krügel, Giovanni Vigna |
SP | 6 |
| 2022 | A Systematical and longitudinal study of evasive behaviors in windows malware
Nicola Galloro, Mario Polino, Michele Carminati, Andrea Continella, Stefano Zanero |
Comput. Secur. | 4 |
| 2021 | Bran: Reduce Vulnerability Search Space in Large Open Source Repositories by Learning Bug SymptomsabstractSoftware is continually increasing in size and complexity, and therefore, vulnerability discovery would benefit from techniques that identify potentially vulnerable regions within large code bases, as this allows for easing vulnerability detection by reducing the search space. Previous work has explored the use of conventional code-quality and complexity metrics in highlighting suspicious sections of (source) code. Recently, researchers also proposed to reduce the vulnerability search space by studying code properties with neural networks. However, previous work generally failed in leveraging the rich metadata that is available for long-running, large code repositories. Dongyu Meng, Michele Guerriero, Aravind Machiry, Hojjat Aghakhani, Priyanka Bose, Andrea Continella, Christopher Krügel, Giovanni Vigna |
AsiaCCS | 6 |
| 2021 | SyML: Guiding Symbolic Execution Toward Vulnerable States Through Pattern LearningabstractExploring many execution paths in a binary program is essential to discover new vulnerabilities. Dynamic Symbolic Execution (DSE) is useful to trigger complex input conditions and enables an accurate exploration of a program while providing extensive crash replayability and semantic insights. Nicola Ruaro, Kyle Zeng, Lukas Dresel, Mario Polino, Tiffany Bao, Andrea Continella, Stefano Zanero, Christopher Krügel, Giovanni Vigna |
RAID | 6 |
| 2021 | Diane: Identifying Fuzzing Triggers in Apps to Generate Under-constrained Inputs for IoT DevicesabstractInternet of Things (IoT) devices have rooted themselves in the everyday life of billions of people. Thus, researchers have applied automated bug finding techniques to improve their overall security. However, due to the difficulties in extracting and emulating custom firmware, black-box fuzzing is often the only viable analysis option. Unfortunately, this solution mostly produces invalid inputs, which are quickly discarded by the targeted IoT device and do not penetrate its code. Another proposed approach is to leverage the companion app (i.e., the mobile app typically used to control an IoT device) to generate well-structured fuzzing inputs. Unfortunately, the existing solutions produce fuzzing inputs that are constrained by app-side validation code, thus significantly limiting the range of discovered vulnerabilities.In this paper, we propose a novel approach that overcomes these limitations. Our key observation is that there exist functions inside the companion app that can be used to generate optimal (i.e., valid yet under-constrained) fuzzing inputs. Such functions, which we call fuzzing triggers, are executed before any data-transforming functions (e.g., network serialization), but after the input validation code. Consequently, they generate inputs that are not constrained by app-side sanitization code, and, at the same time, are not discarded by the analyzed IoT device due to their invalid format. We design and develop Diane, a tool that combines static and dynamic analysis to find fuzzing triggers in Android companion apps, and then uses them to fuzz IoT devices automatically. We use Diane to analyze 11 popular IoT devices, and identify 11 bugs, 9 of which are zero days. Our results also show that without using fuzzing triggers, it is not possible to generate bug-triggering inputs for many devices. Nilo Redini, Andrea Continella, Dipanjan Das 0002, Giulio De Pasquale, Noah Spahn, Aravind Machiry, Antonio Bianchi, Christopher Krügel, Giovanni Vigna |
SP | 2 |
| 2021 | Toward a secure crowdsourced location tracking systemabstractLow-energy Bluetooth devices have become ubiquitous and widely used for different applications. Among these, Bluetooth trackers are becoming popular as they allow users to track the location of their physical objects. To do so, Bluetooth trackers are often built-in within other commercial products connected to a larger crowdsourced tracking system. Such a system, however, can pose a threat to the security and privacy of the users, for instance, by revealing the location of a user's valuable object. In this paper, we introduce a set of security properties and investigate the state of commercial crowdsourced tracking systems, which present common design flaws that make them insecure. Leveraging the results of our investigation, we propose a new design for a secure crowdsourced tracking system (SECrow), which allows devices to leverage the benefits of the crowdsourced model without sacrificing security and privacy. Our preliminary evaluation shows that SECrow is a practical, secure, and effective crowdsourced tracking solution. Chinmay Garg, Aravind Machiry, Andrea Continella, Christopher Krügel, Giovanni Vigna |
WISEC | 3 |
| 2020 | FlowPrint: Semi-Supervised Mobile-App Fingerprinting on Encrypted Network Traffic
Thijs van Ede, Riccardo Bortolameotti, Andrea Continella, Daniel J. Dubois, Martina Lindorfer, David R. Choffnes, Maarten van Steen, Andreas Peter 0001 |
NDSS | 3 |
| 2020 | Karonte: Detecting Insecure Multi-binary Interactions in Embedded FirmwareabstractLow-power, single-purpose embedded devices (e.g., routers and IoT devices) have become ubiquitous. While they automate and simplify many aspects of users' lives, recent large-scale attacks have shown that their sheer number poses a severe threat to the Internet infrastructure. Unfortunately, the software on these systems is hardware-dependent, and typically executes in unique, minimal environments with non-standard configurations, making security analysis particularly challenging. Many of the existing devices implement their functionality through the use of multiple binaries. This multi-binary service implementation renders current static and dynamic analysis techniques either ineffective or inefficient, as they are unable to identify and adequately model the communication between the various executables. In this paper, we present Karonte, a static analysis approach capable of analyzing embedded-device firmware by modeling and tracking multi-binary interactions. Our approach propagates taint information between binaries to detect insecure interactions and identify vulnerabilities. We first evaluated Karonte on 53 firmware samples from various vendors, showing that our prototype tool can successfully track and constrain multi-binary interactions. This led to the discovery of 46 zero-day bugs. Then, we performed a large-scale experiment on 899 different samples, showing that Karonte scales well with firmware samples of different size and complexity. Nilo Redini, Aravind Machiry, Ruoyu Wang 0001, Chad Spensky, Andrea Continella, Yan Shoshitaishvili, Christopher Krügel, Giovanni Vigna |
SP | 5 |
| 2019 | Victim-Aware Adaptive Covert Channels
Riccardo Bortolameotti, Thijs van Ede, Andrea Continella, Maarten H. Everts, Willem Jonker, Pieter H. Hartel, Andreas Peter 0001 |
SecureComm (1) | 3 |
| 2018 | There's a Hole in that Bucket!: A Large-scale Analysis of Misconfigured S3 BucketsabstractCloud storage services are an efficient solution for a variety of use cases, allowing even non-skilled users to benefit from fast, reliable and easy-to-use storage. However, using public cloud services for storage comes with security and privacy concerns. In fact, managing access control at scale is often particularly hard, as the size and complexity rapidly increases, especially when the role of access policies is underestimated, resulting in dangerous misconfigurations. Andrea Continella, Mario Polino, Marcello Pogliani, Stefano Zanero |
ACSAC | 1 |
| 2018 | Extended Abstract: Toward Systematically Exploring Antivirus Engines
Davide Quarta, Federico Salvioni, Andrea Continella, Stefano Zanero |
DIMVA | 3 |
| 2018 | Security Evaluation of a Banking Fraud Analysis SystemabstractThe significant growth of banking fraud, fueled by the underground economy of malware, has raised the need for effective detection systems. Therefore, in the last few years, banks have upgraded their security to protect transactions from fraud. State-of-the-art solutions detect fraud as deviations from customers’ spending habits. To the best of our knowledge, almost all existing approaches do not provide an in-depth model’s granularity and security analysis against elusive attacks. In this article, we examine Banksealer, a decision support system for banking fraud analysis that evaluates the influence on detection performance of the granularity at which spending habits are modeled and its security against evasive attacks. First, we compare user-centric modeling, which builds a model for each user, with system-centric modeling, which builds a model for the entire system, from the point of view of detection performance. Then, we assess the robustness of Banksealer against malicious attackers that are aware of the structure of the models in use. To this end, we design and implement a proof-of-concept attack tool that performs mimicry attacks, emulating a sophisticated attacker that cloaks frauds to avoid detection. We experimentally confirm the feasibility of such attacks, their cost, and the effort required by an attacker in order to perform them. In addition, we discuss possible countermeasures. We provide a comprehensive evaluation on a large real-world dataset obtained from one of the largest Italian banks. Michele Carminati, Mario Polino, Andrea Continella, Andrea Lanzi, Federico Maggi 0001, Stefano Zanero |
ACM Trans. Priv. Secur. | 3 |
| 2017 | Measuring and Defeating Anti-Instrumentation-Equipped Malware
Mario Polino, Andrea Continella, Sebastiano Mariani, Stefano D'Alessio, Lorenzo Fontana, Fabio Gritti, Stefano Zanero |
DIMVA | 2 |
| 2017 | Obfuscation-Resilient Privacy Leak Detection for Mobile Apps Through Differential Analysis
Andrea Continella, Yanick Fratantonio, Martina Lindorfer, Alessandro Puccetti, Ali Zand, Christopher Krügel, Giovanni Vigna |
NDSS | 1 |
| 2017 | Prometheus: Analyzing WebInject-based information stealersabstractNowadays Information stealers are reaching high levels of sophistication. The number of families and variants observed increased exponentially in the last years. Furthermore, these trojans are sold on underground markets along with automatic frameworks that include web-based administration panels, builders and customization procedures. From a technical point of view such malware is equipped with a functionality, called WebInject, that exploits API hooking techniques to intercept all sensitive data in a browser context and modify web pages on infected hosts. In this paper we propose Prometheus, an automatic system that is able to analyze trojans that base their attack technique on DOM modifications. Prometheus is able to identify the injection operations performed by malware, and generate signatures based on the injection behavior. Furthermore, it is able to extract the WebInject targets by using memory forensic techniques. We evaluated Prometheus against real-world, online websites and a dataset of distinct variants of financial trojans. In our experiments we show that our approach correctly recognizes known variants of WebInject-based malware and successfully extracts the WebInject targets. Andrea Continella, Michele Carminati, Mario Polino, Andrea Lanzi, Stefano Zanero, Federico Maggi 0001 |
J. Comput. Secur. | 1 |
| 2016 | ShieldFS: a self-healing, ransomware-aware filesystem
Andrea Continella, Alessandro Guagnelli, Giovanni Zingaro, Giulio De Pasquale, Alessandro Barenghi, Stefano Zanero, Federico Maggi 0001 |
ACSAC | 1 |