Sara Lazzaro

dblp:327/9490 · DBLP profile ↗
← Back
15ranked-venue papers
3as first author
15since 2021 · last 2026
0000-0002-0846-4980ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 1 first-author · 7 since 2021Computer networks · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 CallTrust: A federated system for call authentication in telephony networks
Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro, Carmen Licciardi
J. Inf. Secur. Appl.3
2025 MQTT-E: E2E encryption in MQTT via proxy re-encryption avoiding broker overloading
abstract
A smart traffic monitoring system in smart city surveillance requires publisher and subscriber MQTT-enabled vehicles to share sensitive vehicle and route data with semi-trusted RSU nodes as brokers. To ensure end-to-end confidentiality, we propose the use of an RSU broker as a proxy to perform re-encryption of the exchanged messages between publisher and subscriber vehicles. The RSU brokers are implemented as serverless edge devices with the proxy re-encryption functions designed as function-as-a-service. In peak traffic scenarios, the RSU proxy brokers can become overloaded and drop the re-encryption operations. Additionally, a malicious actor can send counterfeit re-encryption requests to overload the brokers leading to Denial-of-Service attacks. In this paper, we propose a novel solution to mitigate DoS attacks by balancing the re-encryption functions from overloaded brokers. This problem is modeled as an online optimization problem , solved using a greedy heuristic approach, and compared with a baseline approach. The objective function is to reallocate the minimum number of clients when brokers are overloaded since this operation brings additional overhead for clients. Our experimental analysis shows that the greedy approach manages to move up to 5 times fewer clients than the baseline approach, depending on the scenario considered.
Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro, Anusha Vangala
Ad Hoc Networks3
2025 Extending Tor to achieve recipient anonymity
abstract
Abstract Tor is a well-known routing protocol implementing the Onion multi-layered encryption to achieve communication anonymity. Among other possible attacks, Tor is vulnerable to passive attacks based on the compromise of multiple nodes, allowing the adversary to observe the traffic flow and then identify the relationship between sender and recipient. Relationship anonymity, in every threat model, can be reached by achieving at least one between sender and recipient anonymity. Tor implements the onion-service mechanism to offer recipient anonymity. However, it does not protect against a global adversary, that monitors the traffic exchanged in the network. The idea of this paper is to achieve such protection by relying on the collaboration of k Tor relays to hide the actual recipient within an anonymity set of relays. Our approach also includes the exchange of cover traffic among the collaborating Tor relays. We implement this approach by first proposing a modification to Tor (called L-Tor) that preserves the linear circuits as in standard Tor. Then, we propose B-Tor, extending Tor via tree-like circuits. Our analysis shows that using linear circuits (as in L-Tor) would not lead to advantageous results due to the resulting high latency. Instead, we show that B-Tor achieves protection against global adversaries while preserving low-latency applications.
Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro
Cybersecur.3
2025 Hiding identities of MQTT devices against a global network adversary
abstract
In the IoT context, there is an increasing demand for privacy. Indeed, IoT devices can collect and transmit sensitive data that can reveal users’ behavior and preferences to third parties. Making the identity of devices anonymous is one of the privacy challenges. In this paper, we address this problem by referring to the MQTT protocol. MQTT is a widely adopted publish-subscribe model tailored for low-end devices. In particular, we propose an approach to achieve anonymity guarantees in MQTT against a global network adversary. Our approach takes inspiration from mixnet-based anonymous protocols, but it is appropriately tailored for MQTT clients. Indeed, our solution has the following features: (1) it is lightweight for MQTT clients, (2) it satisfies the decoupling principles, and (3) it guarantees that subscribers can join and leave the system at any time. By analyzing the security of the proposed approach, we demonstrate that the considered adversary, via known attacks, is unable to reduce its uncertainty in identifying the originator (publisher) or the recipient (subscriber) of a message. We conducted an experimental campaign showing that the strong benefits of anonymity provided by our solution come at the cost of latency with respect to state of the art which offers lower anonymity guarantees. However, this price is acceptable for the amount of bytes typically sent by IoT devices.
Sara Lazzaro, Vincenzo De Angelis, Francesco Buccafurri
EURASIP J. Inf. Secur.1
2025 A black-box assessment of authentication and reliability in consumer IoT devices
Sara Lazzaro, Vincenzo De Angelis, Anna Maria Mandalari, Francesco Buccafurri
Pervasive Mob. Comput.1
2024 A Framework for Secure Internet of Things Applications
abstract
MQTT is the de facto standard protocol for Internet of Things (IoT) devices. It is a messaging protocol based on lightweight publish-subscribe architecture, tailored specifically for devices with limited computational capabilities. Being a lightweight protocol, it lacks security and privacy features. The OASIS standard suggests some mechanisms to enhance the MQTT protocol. Therefore it is the implementer’s responsibility to include these mechanisms as part of their design. In this paper, we identify three main missing features in MQTT, which are: (1) the presence of weak authentication procedures, (2) the lack of end-to-end security mechanisms, and (3) the lack of privacy mechanisms. Therefore, we propose to fill these gaps with three solutions from the literature, all leveraging the standard MQTT primitives. Finally, we propose a comprehensive framework showing how to combine the three above solutions with the security guidelines presented in the OASIS standard.
Francesco Buccafurri, Sara Lazzaro
CoDIT2
2024 Is Your Kettle Smarter Than a Hacker? A Scalable Tool for Assessing Replay Attack Vulnerabilities on Consumer IoT Devices
abstract
Consumer Internet of Things (IoT) devices often leverage the local network to communicate with the corresponding companion app or other devices. This has benefits in terms of efficiency since it offloads the cloud. ENISA and NIST security guidelines underscore the importance of enabling default local communication for safety and reliability. Indeed, an IoT device should continue to function in case the cloud connection is not available. While the security of cloud-device connections is typically strengthened through the usage of standard protocols, local connectivity security is frequently overlooked. Neglecting the security of local communication opens doors to various threats, including replay attacks. In this paper, we investigate this class of attacks by designing a systematic methodology for automatically testing IoT devices vulnerability to replay attacks. Specifically, we propose a tool, named REPLIoT, able to test whether a replay attack is successful or not, without prior knowledge of the target devices. We perform thousands of automated experiments using popular commercial devices spanning various vendors and categories. Notably, our study reveals that among these devices, 51% of them do not support local connectivity, thus they are not compliant with the reliability and safety requirements of the ENISA/NIST guidelines. We find that 75% of the remaining devices are vulnerable to replay attacks with REPLIoT having a detection accuracy of 0.98-1. Finally, we investigate the possible causes of this vulnerability, discussing possible mitigation strategies.
Sara Lazzaro, Vincenzo De Angelis, Anna Maria Mandalari, Francesco Buccafurri
PerCom1
2024 K-Anonymous Payments in Pseudonymous Blockchains
abstract
Linkability of transactions is a serious threat to cryptocurrency payment anonymity. In fact, in pseudonymous blockchains, payments are not considered to be effectively anonymous. Blockchains such as Monero or Zcash aim to prevent transaction linkability by using complex cryptographic mechanisms. Therefore, they are considered anonymous blockchains. However, the recent literature has proven that, in a threat model in which the adversary is able to monitor network traffic, transaction linkability can be achieved even in anonymous blockchains. In this paper, we propose a solution that allows k-anonymous payments also in the above threat model, thus overcoming the privacy problem that plagues blockchains. The solution is inspired by overlay-routing approaches used in the context of anonymous communication networks when the global network adversary is allowed.
Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro
WiMob3
2024 Enforcing security policies on interacting authentication systems
abstract
Security policies of authentication systems are a crucial factor in mitigating the risk of impersonation, which is often the first stage of advanced persistent threats. Online authentication systems may often interact with each other, due to various mechanisms, such as account recovery or federated authentication. This leads to an implicit extension of the security policies of an authentication system with policies over which the system has no control. As a result, an authentication system that adopts very strong security policies can be unexpectedly weak. This paper deals with the above problem, which affects most real-world online authentication systems. The paper proposes a theoretical framework that formalizes authentication policies and interactions among authentication systems, together with a protocol that prevents, whenever an interaction is established or updated, the security issues described above. An SSI-based implementation of the proposed protocol is presented as well. • Online authentication systems may interact with each other (e.g., for account recovery, federated authentication, etc.). • Interaction between authentication systems may be adopted to bypass strong security policies of authentication systems. • Our work proposes a framework that formalizes authentication policies and interactions among authentication systems. • We provide an SSI-based protocol for the establishment and the update of the interactions between authentication systems.
Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro, Andrea Pugliese 0001
Comput. Secur.3
2024 MQTT-I: Achieving End-to-End Data Flow Integrity in MQTT
abstract
MQTT has become the de facto standard in the IoT. Although standard MQTT lacks built-in security features, several proposals have been made to address this gap. Unfortunately, no existing proposal aims to offer end-to-end data flow integrity in the threat model of untrusted broker. Consider that, the broker has a privileged role, since it is in the middle of communication between publishers and subscribers. Our paper attempts to bridge this gap by introducing a new protocol called MQTT-I, which achieves end-to-end data flow integrity. Our solution is inspired by approaches based on Merkle Hash Trees, commonly used in the context of outsourced data to guarantee data integrity. Our solution aligns with the specific nature of MQTT, in which: (1) publishers and subscribers dynamically join and leave the system, (2) the decoupling principle holds, meaning that publishers and subscribers do not establish any form of agreement, and (3) data, whose integrity should be protected, are multi-topic streams. Moreover, the proposed solution allows us to find the right balance between performance and security. We perform both theoretical and experimental analysis to demonstrate that the introduced security features come with an acceptable overhead in terms of computational and energy cost.
Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro
IEEE Trans. Dependable Secur. Comput.3
2023 COPSEC: Compliance-Oriented IoT Security and Privacy Evaluation Framework
abstract
A rising number of Internet of Things (IoT) security and privacy threats have been documented over the last few years. However, IoT devices' domain designs are out-of-date and do not take into consideration the changing dangers associated with them. In this paper, we present COPSEC, a novel framework for evaluating whether IoT devices are compliant with security guidelines and privacy regulations. We extract metrics from existing guidelines and regulations and test them on a set of devices by performing hundreds of automated experiments. Our results indicate not only that these devices are not compliant with basic security guidelines, but also that their data collection operations may introduce privacy risks for the users that adopt them.
Gianluca Anselmi, Anna Maria Mandalari, Sara Lazzaro, Vincenzo De Angelis
MobiCom3
2023 Adapting P2P Mixnets to Provide Anonymity for Uplink-Intensive Applications
Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro
SECRYPT3
2023 MQTT-A: A Broker-Bridging P2P Architecture to Achieve Anonymity in MQTT
abstract
The demand for privacy in the current digital era is continuously growing. This is particularly true in the context of IoT, in which huge amounts of data are handled. Communication anonymity is a fundamental requirement when high privacy levels should be guaranteed. On the other hand, very little attention has been devoted to this problem in the past scientific literature, when referring to MQTT, which is the de-facto standard for IoT communication. In this paper, we try to cover this gap. Specifically, we propose a new protocol, called MQTT-A, which extends the MQTT bridging mechanism to support the anonymity of both publishers and subscribers. This task is accomplished through the P2P collaboration of intermediate bridge brokers, which forward the requests of clients so that the final broker cannot understand the actual source/destination. Moreover, an anonymity-preserving topic discovery mechanism is provided, which allows clients to discover available topics and associated brokers, preventing client identification. Importantly, all the MQTT-A messages are exchanged by leveraging standard MQTT primitives and the bridging mechanism natively offered by MQTT. This allows us not to require changes in the standard MQTT infrastructure. To validate the performance of our solution, we performed a deep experimental campaign by deploying the bridge brokers on cloud platforms in various countries of the world. The experimental validation shows that, the price of latency we have to pay because of the trade-off with anonymity is quite reasonable. Moreover, no significant impact on goodput occurs in the case of good network conditions.
Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro
IEEE Internet Things J.3
2023 Enabling anonymized open-data linkage by authorized parties
abstract
Nowadays, many entities collect useful information about users, in order to implement the provided service, and publish them as open data. To prevent privacy leakage, data are often anonymized prior to publication. Unfortunately, anonymization strongly hinders data linkage, which can be very useful for analysis purposes instead. In this paper, we deal with the above problem, by proposing a technique that enriches anonymized open data with pseudo-random labels. This way, some authorized parties (i.e., the analysts) are enabled to link data regarding the same user coming from different sources. Instead, for non-authorized people, labels do not carry any information, thus not introducing additional privacy threats with respect to original open data. In other words, our solution allows us to recover linkage capabilities on anonymized open data, thus enabling more powerful data exploitation. Indeed, the linked open data paradigm, involving both the public sector and business, is recognized as one of the most promising approaches for boosting societal growth. To offer a concrete solution, we refer to an existing open-data standard and we implement the protocol through a SAML-based SSO framework adhering to the eIDAS regulation.
Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro
J. Inf. Secur. Appl.3
2022 The Ginger: Another Spice to Hinder Attacks on Password Files
Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro
WEBIST3