VLDB 2026 Research / reviewers in the wild / expert
Valentina Casola
dblp:30/5893
· DBLP profile ↗
59ranked-venue papers
32as first author
17since 2021 · last 2026
0000-0003-0964-7014ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 7 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 8 · 7 first-authorComputer networks · 5 · 2 first-author · 3 since 2021Systems, architecture and hardware · 4 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 4 · 3 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-authorGraphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | On the Evaluation of FPGA-Based Physical Unclonable Functions
Daniele Lombardi, Mario Barbareschi, Valentina Casola, Elena I. Vatajelu, Giorgio Di Natale |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2025 | PUF-Based Secure Key Management for Continuum Computing
Mario Barbareschi, Valentina Casola, Antonio Emmanuele, Daniele Lombardi |
AINA (6) | 2 |
| 2025 | A Moving Target Defense Framework to Improve Resilience of Cloud-Edge Systems
Valentina Casola, Alessandra De Benedictis, Daniele Iorio, Salvatore Migliaccio |
AINA (6) | 1 |
| 2024 | Transfer Adversarial Attacks through Approximate ComputingabstractConvolutional Neural Networks (CNNs), have demonstrated remarkable performance across a range of domains, including computer vision and healthcare. However, they encounter challenges related to the increasing demands for resources and their susceptibility to adversarial attacks. Despite the significance of these challenges, they are often addressed independently in the scientific literature, which has led to conflicting findings. Valentina Casola, Salvatore Della Torca |
ARES | 1 |
| 2024 | AI-Powered Penetration Testing using Shennina: From Simulation to ValidationabstractArtificial intelligence has been greatly improved nowadays, providing innovative approaches in cybersecurity both on offensive and defensive tactics. AI can be specifically utilized to automate and conduct penetration testing, a task that is usually time-intensive, involves high-costs, and requires cybersecurity professionals of high expertise. In this research paper, we utilize an AI penetration testing framework to validate, discover and analyze the techniques that were used. To this end, we conducted a validation process in a realistic environment and to collect the relevant datasets from the execution of the cyberattacks. Finally, the behavior of the AI penetration testing was analyzed in order to adapt and upgrade further. Overall, the research paper provides contributions to dataset generation and a methodology to understand the details of the attack simulation. Stylianos Karagiannis, Camilla Fusco, Leonidas Agathos, Wissam Mallouli, Valentina Casola, Christoforos Ntantogian, Emmanouil Magkos |
ARES | 5 |
| 2024 | A comprehensive evaluation of interrupt measurement techniques for predictability in safety-critical systemsabstractIn the last few decades, the increasing adoption of computer systems for monitoring and control applications has fostered growing attention to real-time behavior, i.e., the property that ensures predictable reaction times to external events. In this perspective, performance of the interrupt management mechanisms are among the most relevant aspects to be considered. Therefore, the service-latency of interrupts is one of the metrics considered while assessing the predictability of such systems. To this purpose, there are different techniques to estimate it, including the use of on-board timers, oscilloscopes and logic analyzers, or even real-time tracers. Each of these techniques, however, is affected by some degrees of inaccuracy, and choosing one over the other have pros and cons. In this paper, we review methodologies for measuring interrupt-latency from the scientific literature and, for the first time, we define an analytical model that we exploit to figure out measurement errors committed. Finally, we prove the effectiveness of the model relying on measurements taken from Xilinx MPSoC devices and present a case study whose purpose is to validate the proposed model. Daniele Lombardi, Mario Barbareschi, Salvatore Barone, Valentina Casola |
ARES | 4 |
| 2024 | DEFEDGE: Threat-Driven Security Testing and Proactive Defense Identification for Edge-Cloud Systems
Valentina Casola, Marta Catillo, Alessandra De Benedictis, Felice Moretta, Antonio Pecchia, Massimiliano Rak, Umberto Villano |
AINA (5) | 1 |
| 2024 | Secure software development and testing: A model-based methodologyabstractModern industries widely rely upon software and IT services, in a context where cybercrime is rapidly spreading in more and more sectors. Unfortunately, despite greater general awareness of security risks and the availability of security tools that can help to cope with those risks, many organizations (especially medium/small-size ones) still lag when it comes to building security into their services. This is mainly due to the limited security skills of common developers/IT project managers and to the typically high costs of security procedures. In fact, while automated tools exist to perform code analysis, vulnerability scanning, or security testing, the manual intervention of security experts is still required not only for security analysis and design, but also to configure and elaborate the output of the security testing tools. In this paper, we propose a novel secure software development methodology aimed at supporting developers from security design to security testing, suitable for integration within modern DevOps pipelines according to a DevSecOps (or SecDevOps) approach. The proposed methodology leverages a model-based process that enables identifying existing threats, selecting appropriate countermeasures to enforce, and verify their mitigation effectiveness through both static assessment procedures and targeted security tests. To demonstrate our approach's feasibility and concretely illustrate the devised activities, we provide a step-by-step description of the whole process concerning a containerized microservice-based application case study. In addition, we discuss the application of the proposed methodology, in its threat modeling and security testing phases, to a well-known vulnerable web application widely used for security training purposes, to illustrate that we can identify most of the existing vulnerabilities and determine appropriate test plans to assess and mitigate such vulnerabilities. Valentina Casola, Alessandra De Benedictis, Carlo Mazzocca, Vittorio Orbinato |
Comput. Secur. | 1 |
| 2024 | A Lightweight PUF-Based Protocol for Dynamic and Secure Group Key Management in IoTabstractIn many Internet of Things (IoT) applications, resource-constrained devices often collaborate in groups for the acquisition, transmission, and management of sensitive information. To uphold the security of these operations, symmetric encryption algorithms are commonly employed due to their efficiency and speed. Nevertheless, establishing a key management mechanism, that accommodates the distinctive features of the IoT domain, remains an ongoing challenge. This paper introduces Group-Key PHEMAP, a novel Physically Unclonable Function (PUF)-based protocol for group key management in IoT applications. The proposed protocol relies solely on lightweight operations for group key management and supports dynamic membership without leveraging additional cryptographic keys. We present a mathematical demonstration for security properties and a comprehensive analysis, regarding both computational and communication costs, as well as scalability property concerning the growing number of devices within the group. Finally, we validate the suitability of our proposal by resorting to the ns-3 network simulator, and, by implementing the protocol on devices representing typical characteristics of those used in IoT applications. Mario Barbareschi, Valentina Casola, Antonio Emmanuele, Daniele Lombardi |
IEEE Internet Things J. | 2 |
| 2023 | Automatic Test Generation to Improve Scrum for Safety Agile MethodologyabstractContinuous compliance and living traceability, i.e., assure the technical quality of the software during the incremental flow of the agile process and trace the requirements’ implementation at any time during the development cycle, are two of the most challenging aspects of adopting agile methodologies in the safety critical domain. This is even more true when either user requirements are unstable, the knowledge of the product to be delivered is not enough, or there is no clear interfaces between various hardware/software subsystems, as it may be in a research and development context. In order to reduce the overall cost of these activities, in this manuscript, we discuss benefits resulting from adopting a semi-automatic method to perform continuous compliance and living traceability. The method aims to finding inconsistency between artifacts produced at the end of each iteration by exploit automatic generation of unit tests and coverage metrics. We validated the applicability of the proposed methodology over a real case study from the railway domain, proving it can find inconsistency between several regulations-required artifacts, including the requirements specification, the architectural specification, test specifications and their implementation, and the software implementation. Mario Barbareschi, Salvatore Barone, Valentina Casola, Salvatore Della Torca, Daniele Lombardi |
ARES | 3 |
| 2023 | Ensuring End-to-End Security in Computing Continuum Exploiting Physical Unclonable FunctionsabstractIn recent years, there has been an increase in Cloud Continuum adoption to support Internet of Things applications. Inevitably, such a paradigm introduces novel security challenges, particularly concerning the security of communicating nodes to prevent malicious actors from tampering within the network, and ensuring the confidentiality of sensitive data during transmissions. Traditional security methods often fall short in addressing these issues, especially where network nodes are built upon resource-constrained devices. Consequently, the scientific community has begun exploring the potential of Physical Unclonable Functions (PUFs), which are unique digital identifiers derived from the inherent variability in the manufacturing process of integrated circuits, as a means to enhance security mechanisms at minimal overhead cost. This paper introduces Secure-PHEMAP (S-PHEMAP), a novel and lightweight PUF-based key management scheme designed for end-to-end communications that guarantees authenticity, confidentiality and integrity for pair communications. The proposed scheme builds upon the PHEMAP protocols, inheriting its security properties. S-PHEMAP can be employed in scenarios where both communicating devices embeds a PUF or in situations where only one of them has a PUF. In addition, the paper includes a deployment strategy in a Cloud Continuum domain, by leveraging the Chef automation framework. Mario Barbareschi, Valentina Casola, Daniele Lombardi |
CloudCom | 2 |
| 2022 | Scrum for safety: an agile methodology for safety-critical software systemsabstractAbstract In the last years, agile methodologies are gaining substantial momentum, becoming increasingly popular in a broad plethora of industrial contexts. Unfortunately, many obstacles have been met while pursuing adoption in secure and safe systems, where different standards and operational constraints apply. In this paper, we propose a novel agile methodology for the development and innovation of safety-critical systems. In particular, we developed an extension of the well-known Scrum methodology and discussed the complete workflow. We finally validated the applicability of the proposed methodology over a real case study from the railway domain. Mario Barbareschi, Salvatore Barone, Riccardo Carbone, Valentina Casola |
Softw. Qual. J. | 4 |
| 2022 | Guest Editorial: Advanced Computing and Blockchain Applications for Critical Industrial IoT
Ahmed A. Abd El-Latif 0001, Yassine Maleh, Marinella Petrocchi, Valentina Casola |
IEEE Trans. Ind. Informatics | 4 |
| 2021 | Security-Aware Deployment Optimization of Cloud-Edge Systems in Industrial IoTabstractCloud computing, edge computing, and the Internet of Things are significantly changing from the original architectural models with pure provisioning of virtual resources (and services) to a transparent and adaptive hosting environment, where cloud providers, as well as “on-premise” resources and end nodes, fully realize the “everything-as-a-service” provisioning concept. The optimal design of these architectures, including the selection of optimal services to acquire, is not trivial in the cloud-edge context due to the involvement of a variable number and the type of available resources offerings and to the impact on cost, performance, and other relevant features such as security, almost never considered. This article presents a novel formalization of the cloud-edge allocation problem for the industrial IoT context. The proposed optimization process takes explicitly into account two critical aspects that are often overlooked in similar approaches, namely, the new cloud-edge on-demand service offerings model for the allocation of resources and the impact on the deployed application, in terms of cost, performance, and security policies actually implemented. An efficient yet suboptimal deterministic solver is also presented and compared with a linear programming one. Results are the same in 86% of the cases on the considered data set while our solver is orders of magnitude faster than the linear one. Valentina Casola, Alessandra De Benedictis, Sergio Di Martino, Nicola Mazzocca, Luigi L. L. Starace |
IEEE Internet Things J. | 1 |
| 2021 | Combining contextualized word representation and sub-document level analysis through Bi-LSTM+CRF architecture for clinical de-identification
Rosario Catelli, Valentina Casola, Giuseppe De Pietro, Hamido Fujita, Massimo Esposito |
Knowl. Based Syst. | 2 |
| 2021 | On the Adoption of Physically Unclonable Functions to Secure IIoT DevicesabstractThe growing convergence among information and operation technology worlds in modern Industrial Internet of Things (IIoT) systems is posing new security challenges, requiring the adoption of novel security mechanisms involving light architectures and protocols to cope with IIoT devices resource constraints. In this article, we investigate the adoption of physically unclonable functions (PUFs) in the IIoT context, and propose the design of a PUF-based architecture (Pseudo-PUF), obtained by suitably combining a weak PUF and an encryption module, that can be successfully adopted to implement advanced security primitives while meeting the existing requirements of IIoT devices in terms of cost and resource demand. To demonstrate the feasibility of our proposal, we analyzed the overall quality of different Pseudo-PUF instances with respect to well-known PUF quality metrics, and found that it is possible to obtain good results with a negligible impact on the devices, thus making our approach suited to IIoT deployments. Mario Barbareschi, Valentina Casola, Alessandra De Benedictis, Erasmo La Montagna, Nicola Mazzocca |
IEEE Trans. Ind. Informatics | 2 |
| 2021 | A Security and Privacy Validation Methodology for e-Health Systemsabstracte-Health applications enable one to acquire, process, and share patient medical data to improve diagnosis, treatment, and patient monitoring. Despite the undeniable benefits brought by the digitization of health systems, the transmission of and access to medical information raises critical issues, mainly related to security and privacy. While several security mechanisms exist that can be applied in an e-Health system, they may not be adequate due to the complexity of involved workflows, and to the possible inherent correlation among health-related concepts that may be exploited by unauthorized subjects. In this article, we propose a novel methodology for the validation of security and privacy policies in a complex e-Health system, that leverages a formal description of clinical workflows and a semantically enriched definition of the data model used by the workflows, in order to build a comprehensive model of the system that can be analyzed with automated model checking and ontology-based reasoning techniques. To validate the proposed methodology, we applied it to two case studies, subjected to the directives of the EU GDPR regulation for the protection of health data, and demonstrated its ability to correctly verify the fulfillment of desired policies in different scenarios. Flora Amato, Valentina Casola, Giovanni Cozzolino, Alessandra De Benedictis, Nicola Mazzocca, Francesco Moscato 0001 |
ACM Trans. Multim. Comput. Commun. Appl. | 2 |
| 2020 | Towards Tracking Data Flows in Cloud ArchitecturesabstractAs cloud services become central in an increasing number of applications, they process and store more personal and business-critical data. At the same time, privacy and compliance regulations such as the General Data Protection Regulation (GDPR), the EU ePrivacy regulation, and the upcoming EU Cybersecurity Act raise the bar for secure processing and traceability of critical data. Especially the demand to provide information about existing data records of an individual and the ability to delete them on demand is central in privacy regulations. Common to these requirements is that cloud providers must be able to track data as it flows across the different services to ensure that it never moves outside of the legitimate realm, and it is known at all times where a specific copy of a record that belongs to a specific individual or business process is located. However, current cloud architectures do neither provide the means to holistically track data flows across different services nor to enforce policies on data flows. In this paper, we point out the deficits in the data flow tracking functionalities of major cloud providers by means of a set of practical experiments. We then generalize from these experiments introducing a generic architecture that aims at solving the problem of cloud-wide data flow tracking and show how it can be built in a Kubernetes-based prototype implementation. Immanuel Kunz, Valentina Casola, Angelika Schneider, Christian Banse, Julian Schütte |
CLOUD | 2 |
| 2020 | Exploiting Workflow Languages and Semantics for Validation of Security Policies in IoT Composite ServicesabstractInternet of Things (IoT) ecosystems are recently experiencing a significant growth in complexity. Most IoT applications in domains like healthcare, industry, automotive, and smart energy are composed of several interconnected subsystems that produce, collect, process, and exchange a huge amount of data, and that offer composite services to the end users based on these data. This scenario is exacerbated by the dynamism of the IoT device layer, which may be subject to structural or technological changes over time, to cope for example with the need for new sensing/actuation capabilities requirements or with technical issues. Due to the inherent sensitive nature of the data that is typically processed by IoT applications, security represents one of the primary issues to address. It is worth noting that each subsystem integrated within a composite IoT application may have different requirements and enforce different local security policies, and the policies that result globally enforced at the system level may not comply with the existing global requirements. In general, the analysis and validation of security properties in a composite IoT system represents a very complex task, made even more complex by the introduction of new laws and regulations during system life. To cope with the above issues, in this article, we propose a methodology that leverages both workflow languages and semantics in order to enable the validation of the security features offered by a composite IoT system, with the goal of verifying whether they match with global end-user policies and even with national and international laws and rules. Flora Amato, Valentina Casola, Giovanni Cozzolino, Alessandra De Benedictis, Francesco Moscato 0001 |
IEEE Internet Things J. | 2 |
| 2020 | A novel Security-by-Design methodology: Modeling and assessing security by SLAs with a quantitative approach
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano |
J. Syst. Softw. | 1 |
| 2019 | Enabling Technologies: Infrastructure for Collaborative Enterprises Editorial for WETICE 2019 ConferenceabstractThe International Conference on Enabling Technologies: Infrastructure for Collaborative Enterprises WETICE is an international forum for state-of the-art research in enabling technologies for collaboration. The 28th WETICE edition takes place on June 12-14, 2019 in Capri (Napoli), Italy and it is made of eleven scientific tracks. Valentina Casola, Alessandra De Benedictis, Umberto Villano |
WETICE | 1 |
| 2019 | A First Step Towards an ISO-Based Information Security Domain OntologyabstractThe need for Information Security Management Systems (SIEMs) has increased the effort requested to companies to improve the security level of their systems and their compliance with national and international standards. Unfortunately, the existence of several different security standards to comply with and the lack of well-defined guidelines related to documents preparation and reporting, may result into a bad security management and may cause several security issues. In this paper, we introduce a modeling approach to the definition of a SIEM that leverages a double-layered ontology: it is composed of a highlevel ontology, used to model complex relations among domains, and of a low-level, domain-specific ontology, aimed at modeling the ISO 27000 family of standards. Valentina Casola, Rosario Catelli, Alessandra De Benedictis |
WETICE | 1 |
| 2019 | The Applicability of a SIEM Solution: Requirements and EvaluationabstractThe need for SIEM systems increased in the last few years, especially as cyber-attacks are evolving and targeting enterprises, which may cause discontinuity of their services, leakage of their data, and affect their reputation. Cybersecurity breaches can range from no or limited impact to stealing or manipulation of data, or even taking control of systems. Many companies seek to reinforce their security capabilities to better safeguard against cybersecurity threats, so they adopt multi-layered security strategies that include using a SIEM solution. A significant factor for the increasing adoption of SIEMs is the capabilities that such systems offer, being able to provide near-real time analysis of security alerts and logs generated from various set of sources within an organization IT infrastructure. However, implementing a SIEM solution is not just an installation phase that fits any scenario within any organization; the best SIEM system for an organization may not be suitable at all for another one. An organization should consider other factors along with the technical side when evaluating a SIEM solution. This paper proposes an approach to aid enterprises, in selecting the most suitable SIEM solution; it suggests technical and organizational requirements that should be addressed and examines the SIEM applicability using quantitative and qualitative evaluation criteria. Hassan Mokalled, Rosario Catelli, Valentina Casola, Daniele Debertol, Ermete Meda, Rodolfo Zunino |
WETICE | 3 |
| 2018 | A Proposal of a Cloud-Oriented Security and Performance Simulator Provided as-a-Service
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano |
CISIS | 1 |
| 2018 | Towards Automated Penetration Testing for Cloud ApplicationsabstractThe development of cloud applications raises several security concerns due to the lack of control over involved resources. Security testing is fundamental to identify the existing security issues and is particularly powerful when carried out by means of penetration testing techniques. Unfortunately, penetration testing requires a deep knowledge of the possible attacks and of the available hacking tools and is very energy demanding. In this paper, we present a methodology that allows to easily carry out a coarse-grained security evaluation of a cloud application by automating the set-up and execution of penetration tests. The methodology relies on the knowledge of the application architecture and on the availability of a catalogue including security-related data collected from multiple sources and properly correlated. Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano |
WETICE | 1 |
| 2018 | Editorial: Security and privacy protection vs sustainable development
Elisa Bertino, Valentina Casola, Aniello Castiglione, Willy Susilo |
Comput. Secur. | 2 |
| 2018 | Security-by-design in multi-cloud applications: An optimization approach
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano |
Inf. Sci. | 1 |
| 2017 | A Security Metric Catalogue for Cloud Applications
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano |
CISIS | 1 |
| 2017 | An Automatic Tool for Benchmark Testing of Cloud Applications
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano |
CLOSER | 1 |
| 2017 | Towards Model-Based Security Assessment of Cloud Applications
Valentina Casola, Alessandra De Benedictis, Roberto Nardone |
GPC | 1 |
| 2017 | MUSA Deployer: Deployment of Multi-cloud ApplicationsabstractThe development of applications based on services offered by different, not conscious, providers, is expected to be growing in the next years. In order to offer effectively multicloud applications, many challenges still need to be faced. At this aim, the MUSA framework provides a DevOps approach to develop multi-cloud applications with desired Security Service Level Agreements (SLAs). This paper describes the MUSA Deployer models, which help developers to express their security requirements, and a Deployer tool that automatically provides cloud security services to offer Security SLAs. Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano, Erkuden Rios, Angel Rego, Giancarlo Capone |
WETICE | 1 |
| 2017 | Automatically Enforcing Security SLAs in the CloudabstractDealing with the provisioning of cloud services granted by Security SLAs is a very challenging research topic. At the state of the art, the main related issues involve: (i) representing security features so that they are understandable by both customers and providers and measurable (by means of verifiable security-related Service Level Objectives (SLOs)), (ii) automating the provisioning of security mechanisms able to grant desired security features (by means of a security-driven resource allocation process), and (iii) continuously monitoring the services in order to verify the fulfillment of specified Security SLOs (by means of cloud security monitoring solutions). We propose to face the Security SLA life cycle management with a framework able to enrich cloud applications with security features. In this paper we (i) present a novel Security SLA model and (ii) illustrate a security-driven planning process that can be adopted to determine the (optimum) deployment of security-related software components. Such process takes into account both specific implementation constraints of the security components to be deployed and customers security requirements, and enables the automatic provisioning and configuration of all needed resources. In order to demonstrate the applicability of the approach, we present and discuss a practical application of the model on a real case study. Valentina Casola, Alessandra De Benedictis, Madalina Erascu, Jolanda Modic, Massimiliano Rak |
IEEE Trans. Serv. Comput. | 1 |
| 2016 | A Security SLA-driven Methodology to Set-Up Security Capabilities on Top of Cloud ServicesabstractThe extensive use of cloud services by both individual users and organizations induces several security risks. The risk perception is higher when Cloud Service Providers (CSPs) do not clearly state their security policies and/or when such policies do not directly match user-defined requirements. Security-oriented Service Level Agreements (Security SLAs) represent a fundamental means to encourage the adoption of cloud services in contexts where security is mandatory. Nevertheless, despite the number of existing initiatives aimed at formalizing Security SLAs and at representing security guarantees by taking into account both customers' and providers' perspectives, they are far from being commonly adopted in practice by CSPs, due to the difficulty in automatically enforcing and monitoring the security capabilities agreed with customers. In this paper we illustrate, through a case study, a methodology to set-up a catalogue of security capabilities that can be offered as-a-service, on top of which specific guarantees can be specified through a Security SLA. Such a methodology, which explicitly takes into account the constraints behind the definition of formal guarantees related to security, is meant to serve as a guideline for providers willing to offer for their services specific security features that can be monitored and assessed by customers during operation. Valentina Casola, Alessandra De Benedictis, Madalina Erascu, Massimiliano Rak, Umberto Villano |
CISIS | 1 |
| 2016 | Methodology to Obtain the Security Controls in Multi-cloud ApplicationsabstractPublisher Copyright: Copyright © 2016 by SCITEPRESS-Science and Technology Publications, Lda. All rights reserved. Samuel Olaiya Afolaranmi, Luis E. Gonzalez Moctezuma, Massimiliano Rak, Valentina Casola, Erkuden Rios, José L. Martínez Lastra |
CLOSER (1) | 4 |
| 2016 | Providing Security SLA in Next Generation Data Centers with SPECS: The EMC Case StudyabstractNext generation Data Centers (ngDC) are the cloud-based architectures devoted to offering infrastructure services in flexible ways: managing in an integrated way compute, network and storage services. This solution is very attractive from an organisation’s perspective but one of the main challenges to adoption is the perception of loss of security and control over resources that are dynamically acquired in the cloud and that reside on remote providers. For a full adoption, datacenter customers need more guarantees about the security levels provided, creating the need for tools to dynamically negotiate and monitor the security requirements. The SPECS project proposes a platform that offers security features with an as-a-service approach, furthermore it uses Security Service Level Agreements (Security SLA) as a means for establishing a clear statement between customers and providers to define a mutual agreement. This paper presents an industrial experience from EMC that integrates the SPECS Platform and their innovative solutions for ngDC. In particular, the paper will illustrate how it is possible to negotiate, enforce and monitor a Security SLA in a cloud infrastructure offering. Valentina Casola, Massimiliano Rak, Isidoro S. La Porta, Andrew Byrne |
CLOSER (2) | 1 |
| 2016 | Per-Service Security SLa: A New Model for Security Management in CloudsabstractIn the cloud computing context, Service Level Agreements (SLAs) are contracts between Cloud Service Providers (CSPs) and Cloud Service Customers (CSCs), stating the guaranteed quality level of the services offered by CSPs. Existing cloud SLAs focus only on few service terms, completely ignoring all security related aspects. They are often reported in a way that is hardly understandable for customers. Moreover, they offer guarantees uniform for all offered services and all customers, regardless of particular service characteristics or customers specific needs. This paper presents a framework that enables the adoption of a per-service SLA model, by supporting the automatic implementation of cloud Security SLAs tailored to the needs of each customer for specific service instances. In particular, the process and the software architecture for per-service SLA implementation are shown. A case study application demonstrates the feasibility and effectiveness of the proposed solution. Valentina Casola, Alessandra De Benedictis, Jolanda Modic, Massimiliano Rak, Umberto Villano |
WETICE | 1 |
| 2016 | Cloud Computing for Earth Surface Deformation Analysis via Spaceborne Radar Imaging: A Case StudyabstractWe present a case study on the migration to a Cloud Computing environment of the advanced differential synthetic aperture radar interferometry (DInSAR) technique, referred to as Small BAseline Subset (SBAS), which is widely used for the investigation of Earth surface deformation phenomena. In particular, we focus on the SBAS parallel algorithmic solution, namely P-SBAS, that allows the production of mean deformation velocity maps and the corresponding displacement time-series from a temporal sequence of radar images by exploiting distributed computing architectures. The Cloud migration is carried out by encapsulating the overall P-SBAS application in virtual machines running on the Cloud; moreover, the Cloud resources provisioning and configuration phases are implemented in an automatic way. Such an approach allows us to preserve the P-SBAS parallelization strategy and to straightforwardly evaluate its performance within a Cloud environment by comparing it with those achieved on a HPC in-house cluster. The results we present were achieved by using the Amazon Elastic Compute Cloud (EC2) of the Amazon Web Services (AWS) to process SAR datasets collected by the ENVISAT satellite and show that, thanks to the Cloud resources availability and flexibility, large DInSAR data volumes can be processed through the P-SBAS algorithm in short time frames and at reduced costs. As a case study, the mean deformation velocity map of the southern California area has been generated by processing 172 ENVISAT images. By exploiting 32 EC2 instances this processing took less than 17 hours to complete, with a cost of USD 850. Considering the available PB-scale archives of SAR data and the upcoming huge SAR data flow relevant to the recently launched (April 2014) Sentinel-1A and the forthcoming Sentinel-1B satellites, the exploitation of Cloud Computing solutions is particularly relevant because of the possibility to provide Cloud-based multi-user services allowing worldwide scientists to quickly process SAR data and to manage and access the achieved DInSAR results. Ivana Zinno, Lorenzo Mossucca, Stefano Elefante, Claudio De Luca, Valentina Casola, Olivier Terzo, Francesco Casu, Riccardo Lanari |
IEEE Trans. Cloud Comput. | 5 |
| 2015 | Security Monitoring in the Cloud: An SLA-Based ApproachabstractIn this paper we present a monitoring architecture that is automatically configured and activated based on a signed Security SLA. Such monitoring architecture integrates different security-related monitoring tools (either developed ad-hoc or already available as open-source or commercial products) to collect measurements related to specific metrics associated with the set of security Service Level Objectives (SLOs) that have been specified in the Security SLA. To demonstrate our approach, we discuss a case study related to detection and management of vulnerabilities and illustrate the integration of the popular open source monitoring system Open VAS into our monitoring architecture. We show how the system is configured and activated by means of available Cloud automation technologies and provide a concrete example of related SLOs and metrics. Valentina Casola, Alessandra De Benedictis, Massimiliano Rak |
ARES | 1 |
| 2015 | Towards Self-Protective Multi-Cloud Applications - MUSA - a Holistic Framework to Support the Security-Intelligent Lifecycle Management of Multi-Cloud ApplicationsabstractThe most challenging applications in heterogeneous cloud ecosystems are those that are able to maximise the benefits of the combination of the cloud resources in use: multi-cloud applications. They have to deal with the security of the individual components as well as with the overall application security including the communications and the data flow between the components. In this paper we present a novel approach currently in progress, the MUSA framework. The MUSA framework aims to support the security-intelligent lifecycle management of distributed applications over heterogeneous cloud resources. The framework includes security-by-design mechanisms to allow application self-protection at runtime, as well as methods and tools for the integrated security assurance in both the engineering and operation of multi-cloud applications. The MUSA framework leverages security-by-design, agile and DevOps approaches to enable the security-aware development and operation of multi-cloud applications. Erkuden Rios, Eider Iturbe, Leire Orue-Echevarria Arrieta, Massimiliano Rak, Valentina Casola |
CLOSER | 5 |
| 2015 | Unsupervised on-demand web service for DInSAR processing: The P-SBAS implementation within the ESA G-POD environmentabstractThis paper presents the integration of the advanced Differential SAR Interferometry (DInSAR) algorithm referred to as Parallel Small BAseline Subset (P-SBAS) within the ESA's Grid Processing on Demand (G-POD) environment in the framework of ESA Geohazards Exploitation Platform (GEP). The aim of this activity is to set up a scientific service that allows, in unsupervised manner, the generation of SBAS-DInSAR products, such as surface mean deformation velocity map and the corresponding time series. In particular, such a web tool is aimed at efficiently exploit the huge ESA's SAR data archives (ERS and ENVISAT), giving a support to scientific users, especially those non-expert of SAR data processing, for interferometric analysis in a short time frame. Claudio De Luca, Roberto Cuccu, Stefano Elefante, Ivana Zinno, Michele Manunta, Giancarlo Rivolta, Valentina Casola, Riccardo Lanari, Francesco Casu |
IGARSS | 7 |
| 2014 | Preliminary Design of a Platform-as-a-Service to Provide Security in CloudabstractCloud computing is an emerging paradigm, recently widely adopted in distributed and business computing.
Even if it is very attractive, due to its business model (pay-per-use) and its flexibility (self-service on demand approach), one of the main limits for its adoption is the perception of loss of security and control over resources that are dynamically acquired in the cloud and that reside on remote providers.
Moreover, security mechanisms are usually integrated into system architectures, and are not offered to users in a way that enables customization and is easy to use. As a consequence, as far as security is concerned, cloud customers are usually tied to a limited set of offerings made available by providers, often without real grants about the way in which such mechanisms are actually implemented and enforced.
This paper deals with the architecture underlying the SPECS platform, which aims at offering security features by an as-a-service approach, using Service Level Agreements as a mean for clear statement between customers and providers to define mutual rights and constraints.
The goal is to show the main requirements of such platform and to present the global architecture, in terms of components and their interactions, dedicated to negotiate, to monitor and to enforce the security mechanisms to be applied over existing cloud providers. Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano |
CLOSER | 1 |
| 2014 | A Cloud Application for Security Service Level Agreement EvaluationabstractCloud security is today considered the main limit to a widespread adoption of Cloud Computing. In this paradigm, due to the serlf-service on-demand characteristic, all data, servers infrastructures resides on the cloud and charged on a pay-per-use basis.
If this implies great advantages from business point of view, because there are no maintenance and start-up costs for infrastructures, there is the perception of a loss of control over the resources, that impacts the security requirements.
Academic works and the Cloud community (e.g., work-groups at the European Network and Information Security Agency, ENISA) have identified that specifying security parameters in Service Level Agreements actually enables the establishment of a common semantic in order to model security among users and Cloud Service providers (CSPs).
However, despite the state of the art efforts aiming at building and representing Cloud SecLAs there is still a gap on the techniques to reason about them. Moreover a lot of activities are being carrying out to clearly state which are the parameters to be shared, their meanings and how they affect service provisioning.
In this paper we propose to build up cloud applications that are able to offer Security level Evaluation over SLA expressed in many different ways. Such applications can be offered as a service by Third Parties in order to help customers to evaluate the offerings from providers.
Such application can be used in order to help customers to negotiate security parameters in a Multi-Cloud system and perform Cloud brokering on the basis of a quantitative evaluation of security parameters. Valentina Casola, Massimiliano Rak, Giuseppe Alfieri |
CLOSER | 1 |
| 2014 | Cloud Platform for Scientific Advances in Earth Surface Interferometric SAR Image AnalysisabstractThe advanced Differential SAR Interferometers (DInSAR) methodologies are widely used for the investigation of Earth's surface deformation phenomena. In particular, the advanced DInSAR approach referred to as Small Baseline Subset (SBAS) technique is able to produce deformation velocity maps and the corresponding displacement time-series from a temporal sequence of space borne SAR acquisitions. Considering the already huge SAR data archives as well the upcoming massive data flow coming from the SENTINEL satellite constellation, cloud computing can be a valid solution to carry out DInSAR analyses thanks to its scalability and flexibility features. In this paper, the focus is given on the migration of the whole parallel version of the SBAS technique, namely P-SBAS, to a cloud environment by taking into account different parameters that influence processing time. Experimental tests that have been performed using both private and public cloud are also presented. Lorenzo Mossucca, Ivana Zinno, Stefano Elefante, Claudio De Luca, Valentina Casola, Olivier Terzo, Francesco Casu, Riccardo Lanari |
CloudCom | 5 |
| 2013 | Performance Evaluation of Video Analytics for Surveillance On-Board Trains
Valentina Casola, Mariana Esposito, Francesco Flammini, Nicola Mazzocca, Concetta Pragliola |
ACIVS | 1 |
| 2013 | An SLA-Based Approach to Manage Sensor Networks as-a-ServiceabstractThe integration of sensing infrastructures into the Cloud gives a number of advantages in providing sensor data as a service over the Internet. Many solutions are now available in the literature, and most of them focus on modeling sensor networks as part of the infrastructure to be offered as a service (IaaS), directly managed by means of the Cloud tools that provide resource virtualization. We propose a different approach: sensor networks are modeled as providers that offer their resources to a Cloud application that runs independently from Cloud providers. Being offered as a Service, any user can negotiate with the provider his desired requirements in terms of operational parameters and non-functional features (i.e. security, dependability, etc). In particular, we propose a SLA-based approach for the specification and management of usage term guarantees related to the access and configuration of private sensor networks. To this end, a Cloud Sensing Brokering Platform is designed to illustrate the innovative way to integrate Cloud and Sensor Networks. Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Giuseppe Aversano, Umberto Villano |
CloudCom (1) | 1 |
| 2013 | Security as a Service Using an SLA-Based Approach via SPECSabstractThe cloud offers attractive options to migrate corporate applications, without any implication for the corporate security manager to manage or to secure physical resources. While this ease of migration is appealing, several security issues arise: can the validity of corporate legal compliance regulations still be ensured for remote data storage? How is it possible to assess the Cloud Service Provider (CSP) ability to meet corporate security requirements? Can one monitor and enforce the agreed cloud security levels? Unfortunately, no comprehensive solutions exist for these issues. In this context, we introduce a new approach, named SPECS. It aims to offer mechanisms to specify cloud security requirements and to assess the security features offered by CSPs, and to integrate the desired security services (e.g., credential and access management) into cloud services with a Security-as-a-Service approach. Furthermore, SPECS intends to provide systematic approaches to negotiate, to monitor and to enforce the security parameters specified in Service Level Agreements (SLA), to develop and to deploy security services that are cloud SLA-aware and are implemented as an open-source Platform-as-a-Service (PaaS). This paper introduces the main concepts of SPECS. Massimiliano Rak, Neeraj Suri, Jesus Luna, Dana Petcu, Valentina Casola, Umberto Villano |
CloudCom (2) | 5 |
| 2013 | Towards Automatic Generation of Hardware Classifiers
Flora Amato, Mario Barbareschi, Valentina Casola, Antonino Mazzeo, Sara Romano |
ICA3PP (2) | 3 |
| 2013 | The CloudGrid approach: Security analysis and performance evaluation
Valentina Casola, Antonio Cuomo, Massimiliano Rak, Umberto Villano |
Future Gener. Comput. Syst. | 1 |
| 2011 | A Semantic-based Document Processing Framework: A Security PerspectiveabstractThe coexistence of different formats and physical supports to store data is one of the main open issues in document management systems, in particular, the presence of unstructured data represents a huge limitation for the elaboration and analysis of many documents and processes. At this aim we are exploiting the adoption of different techniques to analyze texts and automatically extract relevant information, concepts or complex relations, in this paper we proposed a general framework for data transformation and implemented such model trough an architecture based on semantic analysis. The analysis that can be performed on data has many different applications, in this paper we illustrate an interesting perspective related on how to enforce a fine grained access control on sensitive data that are in capsulated in unstructured, monolithic files. We also presented a case study for the formalization and protection of e-health medical records. Flora Amato, Valentina Casola, Nicola Mazzocca, Sara Romano |
CISIS | 2 |
| 2010 | A semantic based methodology to classify and protect sensitive data in medical recordsabstractThe e-Health is going to change the way how patients and healthcare providers interact. The exchange of confidential and integer information is one of the major open issues for the health care sector. While it is quite easy to enforce fine grain access control policies to new well structured medical records managed by newly designed information systems, many eHealth systems are based on “document management systems”. In the practice the system provides a digital version of the whole medical record and it is impossible to enforce fine grain access rules. In this paper we propose the adoption of a semantic based methodology that is able to automatically retrieve the security level associated to a portion of a medical record and use this information to classify resources and locate the proper security rules to apply. Flora Amato, Valentina Casola, Antonino Mazzeo, Sara Romano |
IAS | 2 |
| 2010 | Identity federation in cloud computingabstractBoth cloud and GRID are computing paradigms for the large-scale management of distributed resources. Even if the first is usually oriented to transaction-based applications, and the latter to High Performance Computation, there is a lot of interest in their integration. This is typically obtained through the Infrastructure-as-a-Service cloud model, which is exploited in the GRID context to offer machine with full administration rights to users. In this paper the focus is on the security problems linked to the integration of cloud and GRID computing. It is proposed the adoption of identify federation between different security domains to manage the relationship between the user machines and the standard GRID infrastructure. This solution is experimented within PerfCloud, a cloud implementation that exploits an underlying GRID platform. Valentina Casola, Massimiliano Rak, Umberto Villano |
IAS | 1 |
| 2010 | A Common Data Model for Sensor Network IntegrationabstractOne of the main open issues in the development of applications for sensor network management is the definition of interoperability mechanisms among the several monitoring systems and heterogeneous data. Interesting researches related to integration techniques have taken place, they are primary based on the adoption of sharing data-mechanisms; furthermore in the last years, the Service-Oriented Architecture (SOA) approach has become predominant in many sensor network projects as it enables the cooperation and interoperability of different sensor platforms at an higher level of abstraction. In this paper we propose a novel architecture for the interoperability of sensor networks, which is based on Web services technologies and on the definition of a common data model enriched with semantic concepts and annotations. The proposed architecture allows the development of complex application by integration of heterogeneous data, accessible through services, according to standard data format and standard protocols. Flora Amato, Valentina Casola, Andrea Gaglione, Antonino Mazzeo |
CISIS | 2 |
| 2008 | The REM Framework for Security EvaluationabstractA common approach to formally describe security mechanisms is the definition of proper policies. In many contexts, a system could be considered secure and trustworthy if the policy enforced by its security administrator is trust-worthy as well; within such contexts it is possible to evaluate the system security by evaluating its policy. In a previous paper we have proposed a policy-based methodology, the reference evaluation methodology (REM for short), to define and evaluate the security level that a system is able to provide. In this paper we illustrate the implementation of the REM framework to automatically evaluate the security level provided by a system and we discuss a real case study on the evaluation of the Certificate Authorities involved in the EUGridPMA project. Flora Amato, Valentina Casola, Antonino Mazzeo, Valeria Vittorini |
ARES | 2 |
| 2008 | Self-optimization of secure web services
Valentina Casola, Emilio Pasquale Mancini, Nicola Mazzocca, Massimiliano Rak, Umberto Villano |
Comput. Commun. | 1 |
| 2007 | Static evaluation of Certificate Policies for GRID PKIs interoperabilityabstractValidating an end-entity X.509 digital certificate prior to authorizing it for using a resource into the computational grid has become a widely studied topic due to its importance for security. A more comprehensive validation process involves not only a real-time check on the credential's status, but also an evaluation of the trust level applicable to its certification authority. Nowadays policy management authorities (PMAs) gather grid CAs fulfilling a minimum set of requirements defined in an authentication profile thus guaranteeing a trusted interoperability environment for grid projects. Currently this is a manual process that only results in a binary decision (the CA is able to become part of the PMA or not), however in practice, different CAs offer different security levels. In this paper we present ways to apply the reference evaluation methodology (REM) to automatically obtain the security level of a CA. The described process is based on the building of a formalized policy template for grid certificate policies. This methodology has been used to evaluate the security level offered by a set of EUGridPMA's CAs; the obtained results are then conveyed to relying parties using an infrastructure composed of CertiVeR's validation service and the Open GRid Ocsp (OGRO) middleware for the Globus Toolkit 4, thus providing enough information for a comprehensive certificate validation decision Valentina Casola, Nicola Mazzocca, Jesus Luna, Oscar Manso, Manuel Medina |
ARES | 1 |
| 2007 | Building Autonomic and Secure Service Oriented Architectures with MAWeS
Valentina Casola, Emilio Pasquale Mancini, Nicola Mazzocca, Massimiliano Rak, Umberto Villano |
ATC | 1 |
| 2007 | Interoperable Grid PKIs Among Untrusted Domains: An Architectural Proposal
Valentina Casola, Jesus Luna, Oscar Manso, Nicola Mazzocca, Manuel Medina, Massimiliano Rak |
GPC | 1 |
| 2007 | A policy-based evaluation framework for Quality and Security in Service Oriented ArchitecturesabstractIn dynamic cooperative architectures that are based on services (SOA), customers are not only interested in service functionalities, but also in their quality, such as performance, cost, reliability, security and so on. In this scenario, models, techniques and tools supporting the selection of the best service are needed. In this paper, we propose an evaluation framework that includes a flexible quality meta-model for formalising customer and provider views of quality, and a decisional model defining a systematic approach for comparing offered and requested quality of services. We also illustrate the applicability of the framework in a Web service (WS) scenario. Valentina Casola, Anna Rita Fasolino, Nicola Mazzocca, Porfirio Tramontana |
ICWS | 1 |
| 2007 | A policy-based methodology for security evaluation: A Security Metric for Public Key InfrastructuresabstractThe security of complex infrastructures depends on many technical and organizational issues that need to be properly addressed by a security policy. For purpose of our discussion, we define a security policy as a document that states what is and what is not allowed in a system during normal operation; it consists of a set of rules that could be expressed in formal, semi-formal or very informal language. In many contexts, a system can be considered secure and trustworthy if the policy enforced by its security administrator is trustworthy too; from this standpoint it is possible to evaluate the system security by evaluating its policy. In this paper we present a policy-based methodology to formalize and compare policies, and a Security Metric to evaluate the security level that a system is able to grant. All the steps of the methodology will be illustrated with an operative approach, by directly applying it to a real case study: the semi-automated Cross Certification among Public Key Infrastructures. Valentina Casola, Antonino Mazzeo, Nicola Mazzocca, Valeria Vittorini |
J. Comput. Secur. | 1 |