Lorenzo Rinieri

dblp:327/1572 · DBLP profile ↗
← Back
9ranked-venue papers
4as first author
9since 2021 · last 2026
0000-0003-1767-7256ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 1 first-author · 3 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2026 In-Network Security for Smart Buildings BACnet Communications
abstract
Building Automation and Control Systems increasingly rely on BACnet/IP to interconnect heterogeneous field devices and supervisory applications. Although BACnet Secure Connect provides end-to-end protection via TLS, its adoption in smart-building deployments is hindered by the limited capabilities of legacy devices and the additional communication overhead. In this paper, we propose an in-network security approach for BACnet/IP communications based on two P4-programmable boundary switches that transparently provide confidentiality, integrity, and authentication across exposed network segments without requiring modifications to BACnet endpoints. The solution combines AES-based encryption with support for 128-, 192-, and 256-bit keys and SHA-256 HMAC protection. The proposed approach is validated on a virtualized testbed that we developed on top of the NIST Net-Zero Energy Residential Test Facility (NZERTF) HVAC reference scenario. Experimental results show that the proposed in-network approach achieves a mean RTT between 1393μs and 1541μs, thus reducing latency by 22.8%−30.2%with respect to BACnet/SC (1995 μ s), while remaining above plaintext BACnet/IP (951 μs) by 46.5%−62.0%.
Lorenzo Rinieri, Antonio Iacobelli, Andrea Melis 0001, Roberto Girau, Franco Callegati, Marco Prandini
NetSoft1
2026 P4ICS: P4 in-network security for Industrial Control Systems networks
abstract
Industrial Control Systems (ICS) are increasingly interconnected with enterprise IT and cloud services, yet their communications remain largely unprotected due to the limited adoption of Transport Layer Security (TLS) and other cryptographic standards. Legacy devices often lack the resources to support TLS, and operators face performance constraints and complex certificate management. To address this gap, we present P4ICS, a framework that provides confidentiality, integrity, and replay protection for industrial protocols by shifting security functions from endpoints into P4-programmable switches. P4ICS transparently parses and protects Modbus, DNP3, EtherNet/IP, and MQTT traffic, establishing switch-to-switch encrypted tunnels that secure untrusted network segments while preserving interoperability with legacy equipment. Our evaluation on an ad hoc physical testbed shows that P4ICS introduces only a modest overhead compared to plaintext communication, while consistently outperforming TLS, reducing delays by about 12% for Modbus and DNP3, 43% for EtherNet/IP, and 47% for MQTT. By leveraging in-network computing, P4ICS delivers a practical and deployable security layer for Industry 4.0 communications, narrowing the gap between available secure protocol profiles and their limited use in operational ICS.
Lorenzo Rinieri, Andrea Melis 0001, Roberto Girau, Giovanni Pau 0001, Marco Prandini, Franco Callegati
Comput. Networks1
2026 PLC-Defuser: Detecting hidden Ladder Logic Bombs in PLCs via Control Flow Graph and model checking
abstract
Industrial Control Systems (ICS) are responsible for the operations of critical industrial infrastructures such as water treatment facilities and nuclear plants. To control sensors and actuators, ICSs rely on Programmable Logic Controllers (PLCs), which have become the target of an increasing number of cyberattacks, particularly since the appearance of Stuxnet. In response, numerous anomaly detection methods have been proposed in the literature to identify stealthy attacks targeting ICS sensors and actuators. However, no existing method specifically addresses the detection of Ladder Logic Bombs (LLBs), a class of attacks designed to disrupt the normal operation of PLCs. In this work, we introduce PLC-Defuser, an automated framework specifically tailored to the task of LLB detection. PLC-Defuser first employs static analysis through Control Flow Graphs (CFG) to identify possible LLB triggers within the PLC control logic. It then performs model checking to formally verify whether the identified suspicious triggers activate malicious LLBs. We evaluate PLC-Defuser considering a simplified version of the Secure Water Treatment System (SWaT), for which we built a dataset of PLC programs containing 150 malicious and 150 legitimate samples. Our results demonstrate that PLC-Defuser effectively protects industrial plants without producing false positives and achieves an average execution time of less than 0.5 s.
Lorenzo Rinieri, Antonio Iacobelli, Andrea Melis 0001, Marco Prandini, Franco Callegati
Comput. Secur.1
2026 SIP-Classifier: Unsupervised Classification of SIP-IMS Signaling With Transformer and Clustering
abstract
Ensuring the reliability of voice services in 5G networks requires effective detection of anomalies in IMS signaling. However, this task remains challenging due to the architectural complexity of IMS and the large volume of signaling data. In this paper, we propose SIP-Classifier, an unsupervised methodology that combines Transformer-based representation learning with clustering to identify anomalous SIP sequences. The approach encodes SIP messages through protocol-aware tokenization, learns latent representations via an autoregressive Transformer, and clusters them to distinguish valid from anomalous flows. We evaluate the method on real-world IMS data collected from operational 5G networks. It achieves 98% accuracy, 98% precision, 95% recall, and a 96% F1-score, significantly outperforming state-of-the-art approaches.
Antonio Iacobelli, Giorgio Franceschelli, Lorenzo Rinieri, Mirco Musolesi, Marco Prandini, Franco Callegati
IEEE Trans. Netw. Serv. Manag.3
2025 Time-Sensitive Networking Digital Twin for STRIDE-based security testing
abstract
Time-sensitive networking is set to play a pivotal role in the evolution of modern industrial and 5G networks, enabling them to meet the strictest communication requirements for guaranteed low latency and high reliability. Given the critical and complex environments in which TSN will be deployed, such as industrial automation, autonomous systems, and mission-critical applications, ensuring robust protection against security threats becomes an essential design consideration. The inherent low-latency and deterministic characteristics of TSN, while beneficial for performance, also introduce unique vulnerabilities that attackers could exploit. Consequently, safeguarding time-sensitive networks is fundamental to their successful implementation and reliability in real-world applications. In this paper, we present a flexible and reconfigurable Digital Twin for TSN protocol validation and security testing. Its deployment in different and heterogeneous testing scenarios is fully automated via the Infrastructure as Code approach. Our proposed TSN Digital Twin employs advanced virtualization technologies and network emulation tools to replicate the stringent requirements of TSN. It also implements advanced Linux queuing disciplines to emulate TSN scheduling and traffic shaping. Finally, we assess the potential for adaptability of the proposed architecture for TSN security testing by simulating two attack scenarios derived from the TSN STRIDE threat model.
Andrea Melis 0001, Andrea Giovine, Lorenzo Rinieri
EURASIP J. Inf. Secur.3
2024 In-Network Encryption for Secure Industrial Control Systems Communications
abstract
In this manuscript, we present a solution to provide secure communication in Industry 4.0 environments. Legacy ICS components that do not have encryption capabilities will be able to communicate using secured channels by means of P4 programmable switches that implement security in the data plane. We will compare the proposed solution with TLS end-to-end encryption, showing that it offers similar performance with no need to interact with the end hosts.
Lorenzo Rinieri, Antonio Iacobelli, Amir Al Sadi, Andrea Melis 0001, Franco Callegati, Marco Prandini
NetSoft1
2024 Leveraging Data Plane Programmability to enhance service orchestration at the edge: A focus on industrial security
abstract
The Edge Computing paradigm is increasingly gaining traction in modern telecommunication scenarios, as it enables the offloading of computational tasks from end devices to a variety of nodes located in close proximity to them. This approach is essential for meeting the ever-stricter Quality of Service requirements imposed by modern applications. Concurrently, the advent of Data Plane Programmability allows for unmatched flexibility on the networking plane, supporting processing of multiple protocols in a logically centralized fashion with simple in-line computation, and offering the possibility to offload additional services to networking equipment. Reaping those benefits necessitates heedful management of resources and infrastructure. This, in turn, calls for the introduction of a service orchestration entity, capable of taking advantage of device heterogeneity to enable efficient and swift service provisioning. This work delves into the potential of introducing an orchestration system able to cope with the challenges of offloading security tasks at the Edge. This effort involves developing and implementing novel architectural components that capitalize on the heterogeneous nature of the Edge infrastructure as well as of the Programmable Data Plane as a potential tool for service offloading. To establish the feasibility and performance of this approach, an industrial scenario is considered, where the integrity of data from legacy devices must be ensured. Following an evaluation of the hashing performance of the Programmable Data Plane in comparison to general-purpose devices, a simulation study is conducted on the overall orchestration system, demonstrating the viability of the proposed approach.
Gaetano Francesco Pittalà, Lorenzo Rinieri, Amir Al Sadi, Gianluca Davoli, Andrea Melis 0001, Marco Prandini, Walter Cerroni
Comput. Networks2
2022 Metrics for Cyber-Physical Security: a call to action
abstract
Cyber-physical systems, by definition, have an effect on assets and people in the real world. Security factors, thus, should play a central role in every decision regarding their deployment and configuration, but this is possible only if said factors are properly defined and can be objectively measured. In this paper, we summarize the state of the art in security metrics, and advocate the need for a research effort aimed at taking the field to a new level of formal soundness and practical usability.
Giacomo Gori, Andrea Melis 0001, Lorenzo Rinieri, Marco Prandini, Amir Al Sadi, Franco Callegati
ISNCC3
2022 An Industrial Network Digital Twin for enhanced security of Cyber-Physical Systems
abstract
In this manuscript we describe the implementation of a digital twin for industrial networks. The aim is to provide a playground for cyber-security analysis and validation without the risk of interfering to any extent with the real cyber-physical system and its environment. The proposed implementation methodology provides a very high degree of automation, following the telecom-oriented NFV-MANO approach, and shows that different network topologies may be activated in a matter of just a few minutes. Each topology may then be used as a sort of cyber-range for the experimentation of possible attacks and validation of related countermeasures.
Chiara Grasselli, Andrea Melis 0001, Lorenzo Rinieri, Davide Berardi, Giacomo Gori, Amir Al Sadi
ISNCC3