VLDB 2026 Research / reviewers in the wild / expert
Enrico Branca
dblp:305/3185
· DBLP profile ↗
12ranked-venue papers
1as first author
12since 2021 · last 2026
0000-0001-6316-7789ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 1 first-author · 8 since 2021Computer networks · 3 · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Detecting and Characterizing the Hidden Collaborative Network Supporting Ethereum ScamsabstractSimilar to all other cryptocurrency platforms, Ethereum is constantly confronted with malicious activities. In recent years, research efforts have targeted the detection and mitigation of malicious activities and the associated accounts within the Ethereum ecosystem. Yet, the malicious accounts represent only a small visible part of the substantial collaborative network enabling these activities. In this work, we offer the first analysis of this collaborative network and the corresponding affiliate accounts that often remain hidden from detection. We present enEtherShield, an enhanced framework for detecting affiliate accounts that assist malicious accounts in the related Ethereum scams. Our research findings lay the foundation for the detection of the collaborative network enabling Ethereum scams. Bofeng Pan, Andrei Natadze, Enrico Branca, Jadyn Kimber, Natalia Stakhanova |
ACM Trans. Internet Techn. | 3 |
| 2025 | More Than You Signed Up For: Exposing Gaps in the Validation of Android's App Signing
Norah Ridley, Enrico Branca, Natalia Stakhanova |
DIMVA (2) | 2 |
| 2025 | An End to End Analysis of Crypto Scams on EthereumabstractThe increasing number of Ethereum scams is causing significant concern within the blockchain community, costing users millions of dollars annually. Yet, our understanding of how these scams operate remains limited. In this study, we present the first end-to-end analysis of crypto scams using a large set of malicious Ethereum accounts as a case study. We examine the tactics these scams employ on social media platforms to deceive users and convince them to transfer funds to malicious accounts. Our analysis explores the full life cycle of these scams, considering both their distribution through social media and their activity on the Ethereum blockchain. We identify several unique aspects of Ethereum phishing scams that have not been documented in prior literature and find that these scams generally persist significantly longer and result in greater financial losses compared to traditional phishing scams studied in earlier research. Jadyn Kimber, Enrico Branca, Andrei Natadze, Natalia Stakhanova |
ACM Trans. Internet Techn. | 2 |
| 2025 | Measuring and Characterizing Propagation of Reuse RSA Certificates and Keys Across PKI EcosystemabstractThe insecurities of public-key infrastructure on the Internet have been the focus of research for over a decade. The extensive presence of broken, weak, and vulnerable cryptographic keys has been repeatedly emphasized by many studies. Analyzing the security implications of cryptographic keys’ vulnerabilities, several studies noted the presence of public key reuse. While the phenomenon of private key sharing was extensively studied, the prevalence of public key sharing on the Internet remains largely unknown. In this work, we perform a large-scale analysis of public key reuse within the PKI ecosystem. We investigate the presence and distribution of duplicate X.509 certificates and reused RSA public keys across a large collection containing over 314 million certificates and over 13 million SSH keys collected by different sources at different times. We analyze the cryptographic weaknesses of duplicate certificates and reused keys and investigate the reasons and sources of reuse. Our results reveal that certificate and key sharing are common and persistent. Our findings show over 10 million certificates and 17 million public keys are reused across time and shared between our collections. We observe keys with non-compliant cryptographic elements stay available for an extended period of time. Fatemeh Nezhadian, Enrico Branca, Anna Barzolevskaia, Andrei Natadze, Natalia Stakhanova |
IEEE Trans. Netw. | 2 |
| 2024 | Measuring and Characterizing (Mis)compliance of the Android Permission SystemabstractWithin the Android mobile operating system, Android permissions act as a system of safeguards designed to restrict access to potentially sensitive data and privileged components. Multiple research studies indicate flaws and limitations of the Android permission system, prompting Google to implement a more regulated and fine-grained permission model. This newly-introduced complexity creates confusion for developers leading to incorrect permissions and a significant risk to users security and privacy. We present a systematic study of theoretical and practical misuse of permissions. For this analysis we derive the unified permissions and call mappings that represent theoretical requirements of permissions and calls. We develop PChecker, an approach that identifies the discrepancies between the official Android permissions documentation and permission implementation in the Android platform source code based on these mappings. We evaluate four versions of the Android Open Source Project code (major versions 10–13) and shed light on the prevalence of discrepancies between the official Android guidelines for permissions and their implementation in the Android platform source code. We further show that these discrepancies result in miscompliance in third-party Android apps. Anna Barzolevskaia, Enrico Branca, Natalia Stakhanova |
IEEE Trans. Software Eng. | 2 |
| 2023 | Certificate Reuse in Android Applications
Fatemeh Nezhadian, Enrico Branca, Natalia Stakhanova |
ISC | 2 |
| 2023 | Learning AI Coding Style for Software Plagiarism Detection
Sri Haritha Ambati, Natalia Stakhanova, Enrico Branca |
SecureComm (2) | 3 |
| 2023 | Dataset Characteristics for Reliable Code Authorship AttributionabstractCode authorship attribution aims to identify the author of software source code according to the author’s unique coding style characteristics. The lack of benchmark data in the field, forced researchers to employ various resources that often did not reflect real programming practices. Throughout the years, research studies have used textbook examples, students’ programming assignments, faculty code samples, code from programming competitions and files retrieved from open-source repositories as research objects. The diversity of the data raised concerns about the feasibility of capturing the appropriate data characteristics to reliably evaluate code attribution. In this paper, we investigate these concerns and analyze the effect of the dataset characteristics and feature elimination techniques on the accuracy of code attribution. Unlike the majority of the work done in this field, which mainly concentrates on designing new features, we explore the nature of the data used in previous studies and assess the factors that influence the attribution task. Within this analysis, we investigate the robustness of three feature sets regarded as reliable benchmarks in the attribution research. Based on our findings, we define a process for deriving a reduced set of features for accurate and predictable attribution and make recommendations on the dataset characteristics. Farzaneh Abazari, Enrico Branca, Norah Ridley, Natalia Stakhanova, Mila Dalla Preda |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Analysis and prediction of web proxies misbehavior
Zahra Nezhadian, Enrico Branca, Natalia Stakhanova |
ARES | 2 |
| 2022 | HTTPFuzz: Web Server Fingerprinting with HTTP Request Fuzzing
Animesh Kar, Andrei Natadze, Enrico Branca, Natalia Stakhanova |
SECRYPT | 3 |
| 2022 | Language and Platform Independent Attribution of Heterogeneous Code
Farzaneh Abazari, Enrico Branca, Evgeniya Novikova, Natalia Stakhanova |
SecureComm | 2 |
| 2021 | Origin Attribution of RSA Public Keys
Enrico Branca, Farzaneh Abazari, Ronald Rivera Carranza, Natalia Stakhanova |
SecureComm (1) | 1 |