VLDB 2026 Research / reviewers in the wild / expert
Davide Berardi
dblp:233/5692
· DBLP profile ↗
10ranked-venue papers
5as first author
9since 2021 · last 2025
0000-0002-2473-2439ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 2 · 1 first-author · 2 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Extending Test-driven development to Softwarized Networks and Intent Based NetworkingabstractThe field of Intent Based Networking (IBN) has recently focused on the use of systems powered by Generative Artificial Intelligence and Large Language Models (LLMs) to generate and configure the network. While being a powerful tool to assist Network Administrators, these methods are far from perfect. They tend to hallucinate and generate bad or sub-optimal configurations. To avoid these problems, we propose the integration of Test-Driven development to the world of Softwarized Networks, as a feedback for automated assistants such as LLMbased configuration generator, leveraging technologies such as Atomic Predicates (AP) and Retrieval Augmented Generation (RAG). In this paper, we describe the usage of an assistant over a softwarized network, making it work in conjunction with Network Policy Enforcement, generating an effective Test-Driven Development for Softwarized Network. Our findings highlight the potential of these combined approaches, mutually benefit each other to reach the goal of a powerful co-pilot for Complex Network Configuration. Davide Berardi, Mattia Fontana, Barbara Martini |
CNSM | 1 |
| 2025 | Extreme Edge Sensing-as-a-Service: Bridging Containerization for IoT End Devices
Davide Berardi, Ivan D. Zyrianoff, Federico Montori, Marco Di Felice |
INFOCOM | 1 |
| 2025 | Leveraging LLM-Powered Intelligent Chatbots for Intent-Based Networking in 5G Modem ReconfigurationabstractIntent-Based Networking (IBN) has simplified network management and orchestration at a high level, but configuring User Equipment (UE), like 5G modems, is still a complex and demanding task due to dynamic requirements and intricate device-specific settings, and scalability challenges, especially when dealing with distributed, edge-based devices. This paper explores the potential of using Intelligent Chatbots powered by Generative Artificial Intelligence and Large Language Models (LLMs) operating as co-pilots to automate and optimize modem configurations. We propose a scalable chatbot system that translates user intents into actionable configurations, enhancing security, performance, and adaptability. To this end, we introduce a middleware that bridges LLMs with 5G Modem interfaces, eliminating retraining needs while ensuring engaging, real-time interaction with users. Additionally, we analyze key challenges in integrating LLM-based chatbots with UE and discuss the benefits of query caching in optimizing response times. Our findings highlight the potential of Intelligent Chatbots in extending IBN principles to UE, enabling a more automated and user-friendly approach to network configuration. Mattia Fontana, Davide Berardi, Stefano D'Urso, Filippo Sciarrone, Barbara Martini |
NetSoft | 2 |
| 2023 | Towards the Creation of Interdisciplinary Consumer-Oriented Security MetricsabstractInformation systems are evolving: IoT devices and Cyber-physical systems (CPS) impact on the security of assets and people in the real world. Old cybersecurity approaches, which focused on seeing humans “as a problem”, could be substitute by new paradigms of seeing humans “as a solution”. Therefore, consumers awareness will be one of the building blocks, as well as initiative that aim to create a set of standardized security metrics that can evaluate the security of systems. In order to do that, researchers need to study which are the essential factors that our future metrics should focus on. In this paper we analyzed this problem over CPS while assuming the consumer perspective. We summarize the state of the art in security metrics and advocate the need for a research effort aimed at taking the field to a new level of formal soundness and practical usability by considering interdisciplinary implications on cybersecurity. Giacomo Gori, Andrea Melis 0001, Davide Berardi, Marco Prandini, Amir Al Sadi, Franco Callegati |
CCNC | 3 |
| 2023 | A Structured Approach to Insider Threat Monitoring for Offensive Security TeamsabstractIn many countries, government agencies resort to third parties to acquire security services of many kinds, including Red Team operations to test the effectiveness of own defenses mechanisms. Absolute trust is a key requirement, lest a potentially devastating finding be exploited by a treacherous Red Team against the same entity which commissioned the operation, or sold to its adversaries. In our endeavour as a joint private-academic initiative to address this peculiar market, we observed that a structured approach to this issue is much less common than we would have expected. In this work, we outline the process we are devising to offer customers a verified environment, but integrating it with an evidence-based proof of their correct behavior during the operation, striving to solve the “Quis custodiet ipsos custodes” struggle in an offensive setting. Amir Al Sadi, Davide Berardi, Franco Callegati, Andrea Melis 0001, Marco Prandini, Luca Tolomei |
CCNC | 2 |
| 2023 | Data Flooding against Ransomware: Concepts and ImplementationsabstractRansomware is one of the most infamous kinds of malware, particularly the “crypto” subclass, which encrypts users’ files, asking for some monetary ransom in exchange for the decryption key. Recently, crypto-ransomware grew into a scourge for enterprises and governmental institutions. The most recent and impactful cases include an oil company in the US, an international Danish shipping company, and many hospitals and health departments in Europe. Attacks result in production lockdowns, shipping delays, and even risks to human lives. To contrast ransomware attacks (crypto, in particular), we propose a family of solutions, called Data Flooding against Ransomware, tackling the main phases of detection, mitigation, and restoration, based on a mix of honeypots, resource contention, and moving target defence. These solutions hinge on detecting and contrasting the action of ransomware by flooding specific locations (e.g., the attack location, sensible folders, etc.) of the victim’s disk with files. Besides the abstract definition of this family of solutions, we present an open-source tool that implements the mitigation and restoration phases, called Ranflood. In particular, Ranflood supports three flooding strategies, apt for different attack scenarios. At its core, Ranflood buys time for the user to counteract the attack, e.g., to access an unresponsive, attacked server and shut it down manually. We benchmark the efficacy of Ranflood by performing a thorough evaluation over 6 crypto-ransomware (e.g., WannaCry, LockBit) for a total of 78 different attack scenarios, showing that Ranflood consistently lowers the amount of files lost to encryption. Davide Berardi, Saverio Giallorenzo, Andrea Melis 0001, Simone Melloni, Loris Onori, Marco Prandini |
Comput. Secur. | 1 |
| 2023 | Time sensitive networking security: issues of precision time protocol and its implementationabstractAbstract Time Sensitive Networking (TSN) will be an integral component of industrial networking. Time synchronization in TSN is provided by the IEEE-1588, Precision Time Protocol (PTP) protocol. The standard, dating back to 2008, marginally addresses security aspects, notably not encompassing the frames designed for management purposes (Type Length Values or TLVs). In this work we show that the TLVs can be abused by an attacker to reconfigure, manipulate, or shut down time synchronization. The effects of such an attack can be serious, ranging from interruption of operations to actual unintended behavior of industrial devices, possibly resulting in physical damages or even harm to operators. The paper analyzes the root causes of this vulnerability, and provides concrete examples of attacks leveraging it to de-synchronize the clocks, showing that they can succeed with limited resources, realistically available to a malicious actor. Davide Berardi, Nils Ole Tippenhauer, Andrea Melis 0001, Marco Prandini, Franco Callegati |
Cybersecur. | 1 |
| 2022 | An Industrial Network Digital Twin for enhanced security of Cyber-Physical SystemsabstractIn this manuscript we describe the implementation of a digital twin for industrial networks. The aim is to provide a playground for cyber-security analysis and validation without the risk of interfering to any extent with the real cyber-physical system and its environment. The proposed implementation methodology provides a very high degree of automation, following the telecom-oriented NFV-MANO approach, and shows that different network topologies may be activated in a matter of just a few minutes. Each topology may then be used as a sort of cyber-range for the experimentation of possible attacks and validation of related countermeasures. Chiara Grasselli, Andrea Melis 0001, Lorenzo Rinieri, Davide Berardi, Giacomo Gori, Amir Al Sadi |
ISNCC | 4 |
| 2021 | P-SCOR: Integration of Constraint Programming Orchestration and Programmable Data PlaneabstractIn this manuscript we present an original implementation of network management functions in the context of Software Defined Networking. We demonstrate a full integration of an artificial intelligence driven management, an SDN control plane, and a programmable data plane. Constraint Programming is used to implement a management operating system that accepts high level specifications, via a northbound interface, in terms of operational objective and directives. These are translated in technology-specific constraints and directives for the SDN control plane, leveraging the programmable data plane, which is enriched with functionalities suited to feed data that enable the most effective operation of the “intelligent” control plane, by exploiting the P4 language. Andrea Melis 0001, Siamak Layeghy, Davide Berardi, Marius Portmann, Marco Prandini, Franco Callegati |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2020 | TechNETium: Atomic Predicates and Model Driven Development to Verify Security Network PoliciesabstractFifth-generation (5G) networks will deliver unprecedented levels of quality of service for online gaming and multimedia-rich social interaction, providing virtual environments optimized for vertical applications through innovative approaches to physical resource management. These techniques must consider security aspects in all phases and at every layer. Trusted communications between individuals and reliable platforms running services for social good depend on the resiliency to network-level attacks such as hijacking and denial-of-service. The verification of topological properties represents a well-suited approach to address these issues in a 5G environment. This paper illustrates moves from formal methods existing in literature, namely atomic predicates (AP) and header space analysis (HSA). It describes a method of integrating AP in Software Defined Network architectures, achieving the same expressive power as HSA without its performance hit, to make topology verification viable for real-time security applications. Davide Berardi, Franco Callegati, Andrea Melis 0001, Marco Prandini |
CCNC | 1 |