Andrea Tundis

dblp:23/10589 · DBLP profile ↗
← Back
23ranked-venue papers
14as first author
7since 2021 · last 2025
0000-0002-7729-2780ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 9 first-author · 5 since 2021Computer networks · 3 · 3 first-authorArtificial intelligence and machine learning · 2 · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2025 Zero-Shot Cross-City Trajectory Prediction Using Hypernetworks
abstract
City-wide mobility prediction models typically rely on either training with extensive local trajectory data or applying transfer learning from data-rich cities to those with limited data. In both cases, the resulting models are specialized to a specific target city for which they require at least some trajectory data to adapt. Consequently, they cannot generalize to cities unseen during training and are inapplicable where no mobility data exist. In this work, we propose H 0 xtra, a novel approach that enables zero-shot trajectory prediction in entirely unseen cities. H0xtra leverages a hypernetwork to generate city-specific location embeddings from spatial distributions of points of interest, e.g., restaurants or stores. These embeddings capture city-agnostic location semantics, enabling a transformer to learn universal trajectory patterns across cities. At inference, H0xtra performs zeroshot transfer without requiring any mobility data or retraining. Adaptation requires only points of interest data, which are often publicly available, to generate location embeddings specific to the target city. Trained only on a small set of source cities, H0xtra achieves strong zero-shot generalization. In our experiments, the zero-shot performance achieves an accuracy improvement of 11.3% and an average displacement error reduction of 11.5% on average compared to state-of-the-art non-zero-shot baselines. Our code can be accessed at https://github.com/DLR-Prot-of-Terrestrial-Infrastructures/H0xtra.
Jonas Stickel, Andrea Tundis, Max Mühlhäuser
ICDM2
2024 Navigating the landscape of IoT security and associated risks in critical infrastructures
abstract
The Internet of Things (IoT) presents transformative opportunities for connectivity and automation across various sectors, but it also introduces significant security risks that need to be comprehensively addressed. Indeed, the growing integration of IoT devices, including their vulnerabilities, into critical infrastructures amplifies potential risks in daily life, making these systems prime targets for cybercriminal activities, including espionage and sabotage. Cases where IoT devices have been misused, due to firmware vulnerabilities, embedded passwords, and hidden backdoors are real-world scenarios, that pose significant threats to privacy and security. That’s why this paper aims to point out the urgency of addressing these issues as IoT applications continue to proliferate across healthcare, transportation, urban development and other sectors. Different types of vulnerabilities and their implications with focus on urban critical infrastructures, which can lead to severe consequences like energy blackouts, water contamination, and widespread service disruptions, especially in densely populated areas, are discussed. Moreover, the need of a multidimensional approach that encompasses technological, legal, social, and economic considerations, to deal with those broader cybersecurity and risk management implications of IoT is highlighted. As a consequence, the need for continuous evolution in security strategies to keep pace with the rapid advancements in IoT technologies is pointed out, thus arguing for a proactive approach to safeguard IoT systems against emerging threats and to ensure the safe and resilient operation of these increasingly integral parts of modern critical infrastructures.
Andrej Pastorek, Andrea Tundis
ARES2
2023 From the detection towards a pyramidal classification of terrorist propaganda
Andrea Tundis, Ahmed Ali Shams, Max Mühlhäuser
J. Inf. Secur. Appl.1
2022 A Feature-driven Method for Automating the Assessment of OSINT Cyber Threat Sources
Andrea Tundis, Samuel Ruppert, Max Mühlhäuser
Comput. Secur.1
2022 Formal requirements modeling for cyber-physical systems engineering: an integrated solution based on FORM-L and Modelica
abstract
Abstract The increasing complexity of cyber-physical systems (CPSs) makes their design, development and operation extremely challenging. Due to the nature of CPS that involves many heterogeneous components, which are often designed and developed by organizations belonging to different engineering domains, it is difficult to manage, trace and verify their properties, requirements and constraints throughout their lifecycle by using classical techniques. In this context, the paper presents an integrated solution to formally define system requirements and automate their verification through simulation. The solution is based on the FOrmal Requirements Modeling Language and the Modelica language. The solution is exemplified through two case studies concerning a Trailing-Edge High-Lift system and a Heating, Ventilation and Air Conditioning system.
Daniel Bouskela, Alberto Falcone, Alfredo Garro, Audrey Jardin, Martin Otter, Nguyen Thuy, Andrea Tundis
Requir. Eng.7
2021 Fighting organized crime by automatically detecting money laundering-related financial transactions
abstract
Money laundering is the set of operations aimed at giving a legitimate appearance to capital whose origin is illegal, thus making it more difficult to identify and subsequently recover it. It is one of the phenomena on which the so-called underground economy relies and therefore constitutes a crime for which the charge for money laundering applies. For supporting the fight against this phenomenon, the interest towards analysis models for Anti-Money Laundering (AML) based on a combined use of automatic tools and artificial intelligence (AI) techniques increases, as it is also shown by the European Central Bank (ECB) during recent press conferences. Following this direction, this paper proposes a model for enhancing the detection of suspicious transactions related to money laundering. It is based on a set of features that are defined by considering different aspects such as the time, the amount of money, number of transactions, type of operations and level of internationalization. An AI-based computational approach centered on Machine Learning (ML) techniques has been adopted to evaluate the goodness of such feature-based model, in supporting the automatic detection of suspicious transactions, by experimenting 5 different classifiers. From the experiments emerged that the Random Forest provided the best performance not only among the classifiers tested within the paper, but also in comparison to those presented in the related work with an accuracy, a recall and f1-score greater than 94% by decreasing the False Positive Rate (FPR). Furthermore, an analysis on the feature importance has been provided, to understand which feature, among the proposed ones, plays the major role in such application domain.
Andrea Tundis, Soujanya Nemalikanti, Max Mühlhäuser
ARES1
2021 An exploratory analysis on the impact of Shodan scanning tool on the network attacks
abstract
Network flexibility, openness and systems integration has brought in the last years many advantages in the society in terms of communication and information sharing. Beside that, new issues are emerging related to vulnerabilities in the Internet, which can affect not only virtual environments in an isolated way but this can have serious repercussions in the real world. That is why, the identification of new system vulnerabilities represents an important information for malicious parties. Currently, several tools, known as Online Public Scanning Tools (OPSTs) represent for attackers an attractive source of information from which to draw in order to plan and launch attacks. Indeed, they can automatically scan services, platforms and IoT devices connected to the Internet in order to retrieve information related to them, by including those related to vulnerabilities. In this context, this work aims to investigate how such OPSTs impact the launch of attacks on the network. To this purpose, a model centered on 3 main actors, (i.e. the attack, the hacker and the OPST) has been proposed by defining a set of features which aims to support the evaluation. Shodan was chosen as the OPST, as it is the most popular based on the related review works, while a honey-based approach was adopted to support monitoring and information extraction related to attacks. The results of these analyzes, which show how Shodan influence the attackers in carrying out network attacks are presented and discussed.
Andrea Tundis, Eric Marc Modo Nga, Max Mühlhäuser
ARES1
2020 Mixed-code text analysis for the detection of online hidden propaganda
abstract
Internet-based communication systems have become an increasing tool for spreading misinformation and propaganda. Though mechanisms adept in tracking unwarranted information and messages exist, users have devised different methods to avoid scrutiny and detection. One of such method is the use of mixed-code language. Mixed code is text written in an unconventional form combining different languages, symbols, scripts and shapes, with the aim to make it difficult to detect due to its custom approach and its ever changing aspects. Utilizing special characters to substitute for alphabets, which makes it readable to humans but nonsensical to machine. The intuition is that a substituted alphabet should resemble the shape of the intended alphabet. In this context, the paper explores the possibility of identifying such mixed code texts with special characters by proposing an approach to normalize them and determine if it contains propaganda elements. As a consequence, a tailored algorithm in combination with a deep learning models for character selection is defined and presented. The results gathered from its experimentation are discussed and the achieved performances are compared with the related works1.
Andrea Tundis, Gaurav Mukherjee, Max Mühlhäuser
ARES1
2020 Concepts of a Pyramidal Model for Assessing Internet-based Terrorist Propaganda
abstract
The Internet provides a borderless environment to interact and communicate with each other, not only for legitimate purposes but also to spread radicalization, propaganda, brainwashing and for online recruitment. Due to the large amount of daily data generated, and especially the different levels of radicalization of the users, make it difficult to define countermeasures against such phenomenon. In this context, the paper introduces the concepts of using a pyramidal model, to support the detection of terrorist propaganda, as well as its categorization by allocating it to different level of radicalization. After the description of the model, the main advantages in terms of intervention prioritization and application of targeted countermeasures are discussed.
Andrea Tundis, Ahmed Ali Shams, Max Mühlhäuser
NCA1
2020 Human Physical Status detection related to Danger Situations based on Smartwatch and Smartphone
Andrea Tundis, Max Mühlhäuser
Networking1
2019 Limits in the data for detecting criminals on social media
abstract
Social media represent one of the most popular online tools to spread and exchange formal and informal information based on specific human interests, habits and purposes. As they are free, easy to use and widely adopted, criminals commonly exploit them to quickly disseminate information and propaganda, to recruit people and so on. Due to the vast usage and breadth of topics discussed on them, it is not trivial to identify criminals abusing of social media for their purposes. Machine learning techniques have already shown benefits in classification problems in different application domains. As a consequence, a trained classifier for the identification of potential malicious users on these platforms would represent a desirable solution. In this perspective, this work explores the possibility of using data which are extracted from public personal features in order to identify potential terrorists on social media, by showing current limits. To this aim, a public dataset on known terrorist's details is combined with a manually collected dataset of public Facebook profiles. The adopted approach is presented and then the data-related issues, which emerged from this experience, are discussed1.
Andrea Tundis, Leon Bock, Victoria Stanilescu, Max Mühlhäuser
ARES1
2019 Similarity Analysis of Criminals on Social Networks: An Example on Twitter
abstract
Terrorist Networks (TNs) and Organized Crime (OC) are nowadays an increasing threat in the modern society. Due to the strong adoption of the IT technology, an emergent phenomenon is represented by the exploitation of social media, such as Twitter, Facebook, YouTube to disseminate and promote illegal activities, recruit terrorists and establish collaborations. The traditional approaches and countermeasures against cyber-crimes result inadequate in the cyber-space. In this context, the paper proposes an engineering method, centered on three main phases, to support the analysis of suspicious users on social media related to OC and TNs. It is based on the exploitation and extension of social network analysis approaches combined with well-known clustering techniques and association rules. It aims to identify similarities as well as groups of users associated to specific illegal activities such as drugs, weapons and human trafficking. Moreover, it supports the identification process of leaders in groups and mediators between them. A software, which enables the automatic execution of the proposed method, is developed and experimented on the Twitter social media. The results show both the identification of groups of users related to OC and TNs along with their intra-group activities as well as inter-group relationships through potential mediators.
Andrea Tundis, Archit Jain, Gaurav Bhatia, Max Mühlhäuser
ICCCN1
2019 Tracking Criminal Events through IoT Devices and an Edge Computing Approach
abstract
The occurrence of criminal and terrorist activities is one of the biggest problems which is afflicting the current society. Indeed, criminal events are both hard to predict and difficult to handle once they take place. The classic methods applied by Police Forces (PFs) and Law Enforcement Agencies (LEAs) are in fact not effective, in terms of time management, communication and countermeasures, because of gaps among the occurrence of the criminal event, its identification and the intervention of the PFs for its management. In this regard, this paper proposes a solution which aims to enhance the communication and collaboration among citizens and police forces. It is based on an IoT app which exploits the edge computing approach to face with the above mentioned gaps. In particular, the proposed model as well as the algorithm, along with their main features, are described. The operation logic is then exemplified through the implementation of a simulator that shows its functioning.
Andrea Tundis, Humayun Kaleem, Max Mühlhäuser
ICCCN1
2018 Cybercrime and Organized Crime
abstract
The way of live in the modern society has changed radically over the past few decades. In particular, thanks to the strong use of information technology, many activities have moved from the real world to the digital world. This has obviously introduced advantages in terms of data management and communication efficiency. Nevertheless, it has given also to the criminals the possibility to move into cybernetic space and, as a consequence, to exploit all the technological advantages available for carrying out their activities. In this context the paper provide an overview on the cybercrime and organized crime by focusing on the concept of crime as a service as well as the main issues related to big data by highlighting the social aspects.
Václav Jirovský, Andrej Pastorek, Max Mühlhäuser, Andrea Tundis
ARES4
2018 A review of network vulnerabilities scanning tools: types, capabilities and functioning
abstract
The rapid growth of the Internet in the last years has brought many advantages in the modern society in terms of communication and information sharing. Beside that, new and complex issues are emerging due to the network flexibility, openness and systems integration. The vulnerabilities of systems are the basis of these issues. Unfortunately, such vulnerabilities in the Internet can affect not only virtual environments in an isolated way but this can have serious repercussions in the real world. That is why, identifying new system vulnerability represents an important information for malicious parties. Currently, several tools (e.g. Shodan or Censys), which automatically scan the Internet, are available. They first scan the whole IPv4 public address range and ports in a distributed and random manner and then the obtained results are published on the publicly accessible websites. Such information can be later used for the benign or malicious purposes. In the latter case the main advantage for the potential attackers is that they gain reconnaissance data without even directly contacting the targeted device. Additionally, a large list of potential victims sharing the same vulnerability can be rapidly acquired. In this context, this paper aims at providing an overview of various publicly available network vulnerabilities scanning tools. In particular, first the main scanning tools are identified and classified. Then their main features are described and finally their advantages and disadvantages are highlighted.
Andrea Tundis, Wojciech Mazurczyk, Max Mühlhäuser
ARES1
2018 Supporting the Identification and the Assessment of Suspicious Users on Twitter Social Media
abstract
The exploitation of Internet technology represents for terrorists and criminals a convenient means for establishing and advertising illegal activities. Especially, social networks facilitate new collaborations as well as the spreading of information with a lower risk of being exposed and fetched. Indeed, due to the increasing number of social media and the huge amount of data continuously generated from them, the discovering process of cyber-criminals is a hard task to be performed by the Law Enforcement Agencies and Police Forces if only based on traditional approaches. It becomes even harder if the heterogeneous nature of data, due to multi-cultural aspects, such as the variety of languages, is considered during the searching process. As a consequence, the adoption of a computer-based approach represents a viable solution. In particular, this paper aims at supporting the automatic identification process of potential online suspicious users, who act on social media. A methodological process, centered on the combination of well-known text analysis techniques by considering multi-language aspects, is proposed. In addition, an evaluation approach, based on the exploitation of different qualitative evaluation criteria, is employed to assess the level of suspiciousness of the identified users. Finally, a software tool that supports the execution of the proposed process is developed and its experimentation is shown through a case study on Twitter.
Andrea Tundis, Gaurav Bhatia, Archit Jain, Max Mühlhäuser
NCA1
2018 Cybersecurity compliance analysis as a service: Requirements specification and application scenarios
abstract
Summary Cybersecurity compliance analysis is the process of assessing whether the behavior of an IT system or application conforms to the cybersecurity rules and regulations in force. This assessment can be offered as a service by exploiting available cloud technologies, and, indeed, it is one of the services classified by the Cloud Security Alliance (CSA) as part of the security information and event management (SIEM) category of the SecaaS (security as a service) domain. The definition and implementation of this typology of cloud services are challenging activities due to the complexity of both the reference business domain and the compliance analysis services to be provided themselves. The paper exploits a recently proposed requirements methodology, called GOReM (goal‐oriented requirements methodology), to support the conceptualization and subsequent implementation of cybersecurity compliance analysis services. In particular, two different application scenarios regarding compliance analysis of an existing or under development IT system/application are presented and discussed. In both the scenarios, GOReM allows to grasp and understand the many and complex issues to address for providing secure cloud services to worldwide customers, also due to the numerous, different and ever changing legal aspects, which have to be taken into account by service providers.
Angelo Furfaro, Teresa Gallo, Alfredo Garro, Domenico Saccà, Andrea Tundis
Concurr. Comput. Pract. Exp.5
2017 Attack Scenario Modeling for Smart Grids Assessment through Simulation
abstract
Smart Grids (SGs) are Critical Infrastructures (CI), which are responsible for controlling and maintaining the distribution of electricity. To manage this task, modern SGs integrate an Information and Communication Infrastructure (ICT) beside the electrical power grid. Aside from the benefits derived from the increasing control and management capabilities offered by the ICT, unfortunately the introduction of this cyber layer provides an attractive attack surface for hackers. As a consequence, security becomes a fundamental prerequisite to be fulfilled. In this context, the adoption of Systems Engineering (SE) tools combined with Modeling and Simulation (M&S) techniques represent a promising solution to support the evaluation process of a SG during early design stages. In particular, the paper investigates on the identification, modeling and assessment of attacks in SG environments, by proposing a model for representing attack scenarios as a combination of attack types, attack schema and their temporal occurrence. Simulation techniques are exploited to enable the execution of such attack combinations in the SG domain. Specifically, a simulator, which allows to assess the SG behaviour to identify possible flaws and provide preventive actions before its realization, is developed on the basis of the proposed model and exemplified through a case study.
Andrea Tundis, Rolf Egert, Max Mühlhäuser
ARES1
2017 Systemic Risk Modeling and Evaluation through Simulation and Bayesian Networks
abstract
In the Risk Analysis domain an increasing interest has been gaining by the System Risk Analysis that aims at investigating the risk deriving by the interdependence of the system under consideration by other systems and, in general, by the interactions among them. Indeed, an adverse event occurring in a certain system can cause negative effects on the other interconnected systems and compromise their operation. An effective analysis of the Systemic Risk requires suitable methods and techniques able to handle the high level of complexity typical of Systems and Systems characterized by several interconnected, distributed, autonomous and changing components. In this context, the paper proposes a method for Systemic Risk Analysis that combines a Goal-Oriented Methodology for Requirement Modeling (GOReM) with a Model-Based method for System Dependability Analysis (RAMSoS). Such combination enables the modeling and the evaluation of Systemic Risk scenarios by using agent-based simulations and the complementary quantitative evaluation of performance indices through Bayesian Networks. A concrete exploitation of the proposed approach to Systemic Risk Analysis in the cyber-security domain is also presented1.
Andrea Tundis, Alfredo Garro, Teresa Gallo, Domenico Saccà, Simona Citrigno, Sabrina Graziano, Max Mühlhäuser
ARES1
2017 HOLEG: A simulator for evaluating resilient energy networks based on the Holon analogy
abstract
The process of designing and evaluating distributed Cyber-Physical Systems (CPSs) is not a trivial task. There are many challenges to tackle such as managing distributed resources, enabling communication between components, and choosing performance metrics to evaluate the “goodness” of the system. Smart Grids (SGs) are prominent representatives of CPSs, a particular type of Critical Infrastructure (CI), whose organizational model is becoming more distributed and dynamic. Due to this paradigm shift, new control and management mechanisms need to be identified and tested to guarantee uninterrupted operation. However, novel approaches cannot always be tested against real networks as the economic cost and risk can be high. In contrast, modeling and simulation techniques are viable evaluation mechanisms that support the continuous evolution of CIs. In this paper, we present an Open Source time-discrete simulation software, called HOLEG, that models and evaluates SGs. The software is based on the Holon analogy, a bio-inspired approach that enables systems resilience through flexible reconfiguration mechanisms. The presented software provides features that enable the integration and execution of optimization algorithms along with their evaluation. To demonstrate HOLEG, a case study is presented where a heuristic algorithm is implemented to minimize wasted energy while preventing network destabilization.
Rolf Egert, Carlos Garcia Cordero, Andrea Tundis, Max Mühlhäuser
DS-RT3
2016 ResDevOps: A Software Engineering Framework for Achieving Long-Lasting Complex Systems
abstract
The development of high quality complex software systems and quick time-to-market with full customer satisfaction often appear as two competing forces. Many industry efforts have been directed towards agile methodologies completed with the DevOps approach, whereas traditional requirements engineering with much documentation, is considered surpassed. The aim is to obtain a longer life software because it suddenly responds to the customers changing requirements from which it receives continuous input. This might create a serious cost implication and a real risk to lose system requirements control. In this paper, we propose a framework able to govern the complexity of the system requirements and to allow the embedding, occasionally, of technological innovations into the overall system. ResDevOps joins the value of the agile world with DevOps, with the additional value deriving from an unceasing parallel innovation management process, which we call ResDevs. ResDevOps includes a continuous research and innovation process, which provides an asynchronous, additional input to the agile process inside a chain of concurrent engineering collaboration. This is a suitable trade-off to maintain modern IT Systems live for a longer time, with many consequent advantages for both total investment and system quality. The practical use of the ResDevOps approach is shown by means of a case study.
Angelo Furfaro, Teresa Gallo, Alfredo Garro, Domenico Saccà, Andrea Tundis
RE5
2015 An analytical processing approach to supporting cyber security compliance assessment
abstract
Compliance analysis is an important step for the security management process of systems. It aims at both increasing service quality and reducing service vulnerabilities by exploiting security mechanisms able to improve the fulfillment of requirements whose failure may cause direct and indirect costs, related to the existence of missed normative provisions, risk of loss of certifications, and increased probability and impact of security incidents. Due to the increasing in system complexity there are hundreds of requirements that must be observed simultaneously and satisfied. As a consequence, the need for innovative approaches centered on effective solutions able to support the evaluation and the validation of requirements and constraints over the time is today greater than ever. In this context, the paper proposes a method for supporting the compliance assessment of services, in respect of norms and regulations, exploitable both in design phase or during the operation of existing services supported by (semi-)automatic tools. The effectiveness of the method is then tested through a case study taken from the experience of the Computer Emergency Response Team (CERT) of Poste Italiane, concerning the compliance assessment of an Electronic Payment Service by credit card.
Francesco Buccafurri, Lidia Fotia, Angelo Furfaro, Alfredo Garro, Matteo Giacalone, Andrea Tundis
SIN6
2012 Enhancing the RAMSAS Method for System Reliability Analysis - An Exploitation in the Automotive Domain
Alfredo Garro, Andrea Tundis
SIMULTECH2