Nicola d'Ambrosio

dblp:320/7587 · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0001-8430-9061ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 first-author · 3 since 2021Computer networks · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2026 CUTIE: Component-specific Unsupervised Technique for In-node Examination
abstract
Industrial Control Systems (ICS) are increasingly targeted by sophisticated cyber-attacks that can disrupt physical processes, compromise safety, and cause substantial operational and environmental damage. Traditional intrusion detection systems (IDS) for ICS often rely on centralized monitoring architectures, which introduce latency, create single points of failure, and hinder precise localization of compromised components. To address these limitations, we propose CUTIE, a component-specific distributed IDS that deploys lightweight detection modules directly at each Programmable Logic Controller (PLC). Each module is trained in an unsupervised manner on the normal behavior of its corresponding network traffic, enabling the detection of localized anomalies without requiring labeled attack data. CUTIE leverages bidirectional flow representations and timing-based aggregation to balance early detection with meaningful traffic abstraction, while maintaining low computational and memory overhead suitable for resource-constrained industrial environments. Extensive evaluation on the SWaT dataset demonstrates that CUTIE achieves high detection accuracy and robust performance across multiple lightweight model architectures.
Andrea Vignali, Nicola d'Ambrosio
Comput. Networks2
2025 SMASH: An SDN-MTD framework for efficient honeypot deployment and insider threat mitigation
abstract
Conventional cybersecurity tools, such as firewalls and Intrusion Prevention Systems, have been widely employed to protect against digital threats. However, these approaches reveal their inherent limitations as the complexity and sophistication of cyberattacks increase. Consequently, there is a growing demand for more proactive and adaptive cyber-defense strategies. Deception-based techniques, such as Moving Target Defense (MTD) and honeypots, have emerged as powerful approaches to enhance security by confusing and misleading attackers. Despite their potential, deploying these solutions in large-scale network infrastructures poses significant challenges. Manual configuration of honeypots is time-consuming, resource-intensive, and difficult to scale. Moreover, it is mandatory to ensure that honeypots do not become a pivot for attackers to penetrate the enterprise network infrastructure further. To address these issues, we propose “Sdn-Mtd Automated System with Honeypot integration” (SMASH), a framework that leverages Software Defined Networking (SDN) principles in conjunction with MTD and decoy techniques. Following a Design Science approach, we designed, implemented, and evaluated SMASH to overcome these deployment and management challenges. SMASH not only makes it more difficult for attackers to target the production network infrastructure, but also provides valuable real-time threat intelligence by observing attacker behavior. When an intrusion attempt is detected, MTD techniques redirect the attacker to an isolated subnet dedicated to threat monitoring, preventing access to sensitive systems and data. Furthermore, SMASH introduces a flexible and scalable management system that allows automatic deployment, setup, and real-time monitoring of honeypots. This dynamic adaptability allows organizations to scale their defenses in response to evolving threats, significantly enhancing the security posture of real-world enterprise environments.
Nicola d'Ambrosio, Claudio Lista, Gaetano Perrone, Simon Pietro Romano
Comput. Networks1
2025 SCASS: Breaking into SCADA Systems Security
abstract
Industrial Controls Systems (ICS) represent a relevant target for attackers. In order to prevent such critical security threats, ICS security assessment activities should be conducted. Conventional vulnerability assessment and penetration testing within ICSs are not practicable due to safety risks and cost constraints. To overcome these challenges, security researchers have developed cybersecurity testbeds. However, these testbeds commonly rely on closed components, cannot be extended, and are very expensive. This research investigates how a modular, open-source framework can enhance the development of robust cybersecurity testbeds and facilitate the implementation of digital twins for securing Industrial Control Systems. We present SCASS, a fully customizable testbed designed to replicate complex SCADA and ICS environments with high fidelity. SCASS addresses the need for accessible, scalable platforms by supporting both physical and virtual components while enabling the evaluation of heterogeneous attack scenarios and security methodologies. By combining advanced attack scenarios with an objective comparative analysis against existing testbeds, SCASS demonstrates its ability to fill critical gaps in the ICS security landscape, fostering collaboration and advancing security assessment methodologies.
Nicola d'Ambrosio, Giulio Capodagli, Gaetano Perrone, Simon Pietro Romano
Comput. Secur.1
2025 A cyber-resilient open architecture for drone control
abstract
Unmanned Aerial Vehicles (UAVs) are becoming important tools in both military and civilian sectors. However, the prevalent use of monolithic architectures in contemporary platforms limits the swift integration of new features and significantly hampers the adaptability of UAVs to an ever-changing operational environment. Furthermore, this constantly evolving landscape highlights the inherent complexity of assessing drone safety and security since this process requires managing multiple and rapidly changing variables. Therefore, it is imperative to adopt an open system approach that relies on microservices and virtualization in order to overcome the limits of traditional drone architectures. This study presents a new method that involves breaking down the UAV monolithic system into a network of separate and virtualized components, each holding a single responsibility and designed according to the Open System Architecture (OSA) principle. Moreover, this work proposes a novel cyber-resilience model to determine cyber threats and assess their impact on the system. This approach leverages NIST 800-53, MITRE ATT&CK, STPA-Sec, and Attack Graph in order to identify the sequence of malicious actions that can lead to a specific hazardous scenario. Lastly, we demonstrate the effectiveness of this novel architectural paradigm by developing a software-in-the-loop simulation testbed for fast prototyping new features and validating the results of the cyber-resilience model.
Nicola d'Ambrosio, Gaetano Perrone, Simon Pietro Romano, Alberto Urraro
Comput. Secur.1
2024 Securing Industrial Systems: A Testbed for Cyber-Defense Evaluation and Data Collection
abstract
Over recent years, many Industrial Control System (ICS) components have been exposed to both the Internet and corporate networks to enhance the management of industrial processes. However, this increased exposure has often taken place without adequate consideration for cybersecurity, making industrial networks more vulnerable to cyberattacks. In this context, digital twins have emerged as innovative solutions to evaluate novel cyber-defense strategies that can mitigate threats affecting industrial networks. Unfortunately, to the best of the authors’ knowledge, there is no digital twin that is flexible enough to integrate both physical and virtualized components according to user preferences while simultaneously supporting novel approaches based on the Software-Defined Networking (SDN) paradigm. To address these issues, we developed a flexible hybrid/virtual digital twin that mimics a physical Microgrid testbed known as EPIC. Specifically, our solution leverages vir-tualization and containerization to create a lightweight platform that can include the widest possible range of vulnerabilities. Furthermore, we employ Open vSwitch to implement SDN-based methodologies and integrate physical components into our platform. Lastly, we provide a comprehensive tool that collects all possible logs from the testbed.
Raffaele Cuorvo, Nicola d'Ambrosio, Domenico Iorio, Gaetano Perrone, Simon Pietro Romano
CNSM2
2023 Including insider threats into risk management through Bayesian threat graph networks
Nicola d'Ambrosio, Gaetano Perrone, Simon Pietro Romano
Comput. Secur.1