Antonia Affinito

dblp:222/3194 · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
8since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 3 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2025 GRASS: Green Ranking of Autonomous SystemS
abstract
The rapid growth of the Internet has raised concerns about the carbon emissions linked to data transmission. Autonomous Systems (ASes), which make inter-domain routing decisions, influence how traffic moves through the network and, indirectly, where emissions are generated. Although carbon-aware routing is gaining interest, limited visibility into emission sources remains a key challenge. In this paper, we present GRASS (Green Ranking of Autonomous SystemS), a framework for estimating the CO2intensity of ASes based on their geographic distribution and the carbon efficiency of regional electricity grids. GRASS combines geolocation, routing, and carbon data to infer probabilistic location profiles and compute a CO2intensity score for each AS. Using GRASS, we analyze emission patterns across AS popularity tiers, and customer cone sizes, and assess the carbon intensity of AS-to-AS links based on associated organizations. Our results show that a small number of structurally central ASes and links account for a large fraction of total Internet-related emissions. We propose a novel approach to assessing the CO2intensity of ASes and their interconnections, offering insights that enable targeted interventions for greener network operations and routing policies.
Antonia Affinito, Cristian Hesselman, Savvas Kastanakis
CNSM1
2025 90th Minute: A First Look to Collateral Damages and Efficacy of the Italian Piracy Shield
abstract
In the fight against illegal football streaming, Italy introduced Piracy Shield, a platform through which copyright holders can notify the national regulator (AGCOM), which in turn orders ISPs to block infringing resources -- such as IP addresses and Fully Qualified Domain Names (FQDNs) -- within 30 minutes. In this paper, we present the first investigation into the platform's real-world impact by reconstructing and analyzing its blocking activity. Our analysis shows that the platform causes significant collateral damage. Indiscriminate IP-level blocking has disrupted and continues to disrupt hundreds of legitimate, non-streaming websites. At the same time, the platform's effectiveness may have been undermined by streamers who evaded enforcement by migrating to new infrastructure and unfiltered IP address space. Based on these findings, we call on Italian authorities and policymakers to critically reconsider the platform's core blocking principles. The evidence suggests that its broad impact on legitimate services and the potential national security risks outweigh its intended benefits.
Raffaele Sommese, Anna Sperotto, Antonio Prado, Jeroen van der Ham, Antonia Affinito
CNSM5
2025 Victimization in DDoS attacks: The role of popularity and industry sector
abstract
Distributed denial-of-service (DDoS) attacks may be driven not only by economic motives such as extortion, but also by social or political goals, including hacktivism and state-sponsored operations. Therefore, the monetary value of a target alone does not fully explain why some organizations are more frequently victimized. While cloud providers deploy advanced defenses — such as Anycast routing, traffic scrubbing, and filtering — they also concentrate many potential targets within a shared infrastructure, increasing their exposure to DDoS attacks. This study aims to understand what makes organizations more suitable DDoS targets by examining two key attributes: visibility and perceived value, represented by website popularity and industry sector. We also investigate how the customer portfolio of cloud and data center providers influences the DDoS threat to their infrastructure. Research Questions: • How do organizational characteristics related to value and visibility — specifically, popularity and industry sector — correlate with the threat of DDoS attacks? • How does the diversity of customer business sectors hosted by a cloud or data center provider influence the DDoS threat to its infrastructure? Methodology: We conducted a large-scale analysis of DDoS incidents inferred from network telescope data spanning five years. We estimated target visibility and value using Alexa ranks and Cisco Umbrella content categories. We also analyzed the relationship between customer sector composition and DDoS threat at the provider level. Key Findings: • Popular websites are more frequently attacked, though this pattern weakened during the COVID-19 pandemic. • Certain industry sectors face significantly higher and repeated DDoS threats. • Cloud providers serving a higher proportion of high-risk sectors are more likely to face frequent DDoS attacks.
Muhammad Yasir Muzayan Haq, Antonia Affinito, Alessio Botta, Anna Sperotto, Lambert J. M. Nieuwenhuis, Mattijs Jonker, Abhishta
J. Inf. Secur. Appl.2
2024 Analyzing Privacy Implications of Mobile Apps Data Collection across Age Groups
abstract
Mobile applications increasingly access a wide range of personal information, raising significant privacy concerns, particularly for children and teenagers. Previous studies have shown low compliance between privacy policies and permissions in mobile apps. However, current research has not yet explored how an app’s target age group influences the permissions it requests, especially among minors. While recent regulatory frameworks like COPPA, CCPA, and GDPR establish clear rules for data acquisition and privacy for specific age groups, their practical application remains uncertain. This research investigates how data collection practices align with privacy policies among mobile applications targeting different age groups. We show that, on average, the same application collects more user data when downloaded from Google Play than the Apple App Store. Furthermore, applications targeting teenagers collect data more frequently than those targeting other age groups, indicating the necessity for strict regulations for this age group.
Adamo Mariani, Matteo Liberato, Anna Sperotto, Antonia Affinito
CNSM4
2024 DarkDNS: Revisiting the Value of Rapid Zone Update
abstract
Malicious actors exploit the DNS namespace to launch spam campaigns, phishing attacks, malware, and other harmful activities. Combating these threats requires visibility into domain existence, ownership and nameservice activity that the DNS protocol does not itself provide. To facilitate visibility and security-related study of the expanding gTLD namespace, ICANN introduced the Centralized Zone Data Service (CZDS) that shares daily zone file snapshots of new gTLD zones. However, a remarkably high concentration of malicious activity is associated with domains that do not live long enough make it into these daily snapshots. Using public and private sources of newly observed domains, we discover that even with the best available data there is a considerable visibility gap in detecting short-lived domains. We find that the daily snapshots miss at least 1% of newly registered and short-lived domains, which are frequently registered with likely malicious intent. In reducing this critical visibility gap using public sources of data, we demonstrate how more timely access to TLD zone changes can provide valuable data to better prevent abuse. We hope that this work sparks a discussion in the community on how to effectively and safely revive the concept of sharing Rapid Zone Updates for security research. Finally, we release a public live feed of newly registered domains, with the aim of enabling further research in abuse identification.
Raffaele Sommese, Gautam Akiwate, Antonia Affinito, Mattijs Jonker, K. C. Claffy
IMC3
2023 Prediction of RTT Through Radio-Layer Parameters in 4G/5G Dual-Connectivity Mobile Networks
abstract
With E-UTRA-NR Dual Connectivity, terminals can connect to 4G Long-Term Evolution and 5G New Radio networks at the same time. This technology allows using multiple bandwidths belonging to the two radio layers, enhancing the overall system performance. The system also adopts Multiple Input Multiple Output on top of the dual radio layer access. Authors predict application-layer Round-Trip Time with Machine Learning algorithms leveraging radio layer parameters such as received power and signal quality. Binary classification techniques are adopted to predict if Round-Trip Time values are above or below a threshold. The prediction is tested with real data collected in two measurement campaigns. Results show that Random Forest and Decision Tree Classifiers are the best algorithms with a precision score of respectively 0.84 and 0.92 in both measurement setups. They also evidence the radio- and physical-layer information having more importance for predicting application-layer RTT.
Stefania Zinno, Antonia Affinito, Nicola Pasquino, Giorgio Ventre, Alessio Botta
ISCC2
2023 The evolution of Mirai botnet scans over a six-year period
abstract
The proliferation of Internet of Things devices has resulted in an increase in security vulnerabilities and network attacks. The Mirai botnet is a well-known example of a network used for malicious activities, detected for the first time by the white-hat research group in August 2016. Since then, Mirai initiated massive DDoS attacks by scanning for and exploiting vulnerabilities in network devices. In this paper, we investigate the evolution of the Mirai botnet over a six-year period, analyzing the TCP SYN packets using Mirai signature, i.e. with TCP sequence number equal to the destination IP address. Our analysis stands out as we extensively investigate the evolution of Mirai scans over a prolonged six-year period (2016–2022). Our findings reveal that the Mirai signature is still implemented by malicious actors today, in contrast with previous works. Moreover, we observe that the number of hijacked devices and TCP SYN packets involved in the scanning phase have increased over time. We also confirm that cybercriminals generally target Telnet port 23, followed by fewer requests on Telnet port 2323. Conversely, the number of probes on the SSH ports decreases over time, followed by a subsequent increase in 2022. Lastly, we identify several ports that had not been contacted until 2018 but have since received a large number of TCP SYN packets that verify the Mirai’s signature. These ports are linked with the emergence of new variants of the Mirai botnet.
Antonia Affinito, Stefania Zinno, Giovanni Stanco, Alessio Botta, Giorgio Ventre
J. Inf. Secur. Appl.1
2022 Where .ru?: assessing the impact of conflict on russian domain infrastructure
abstract
The hostilities in Ukraine have driven unprecedented forces, both from third-party countries and in Russia, to create economic barriers. In the Internet, these manifest both as internal pressures on Russian sites to (re-)patriate the infrastructure they depend on (e.g., naming and hosting) and external pressures arising from Western providers disassociating from some or all Russian customers. While quite a bit has been written about this both from a policy perspective and anecdotally, our paper places the question on an empirical footing and directly measures longitudinal changes in the makeup of naming, hosting and certificate issuance for domains in the Russian Federation.
Mattijs Jonker, Gautam Akiwate, Antonia Affinito, K. C. Claffy, Alessio Botta, Geoffrey M. Voelker, Roland van Rijswijk-Deij, Stefan Savage
IMC3