VLDB 2026 Research / reviewers in the wild / expert
Silvia Sisinni
dblp:331/6456
· DBLP profile ↗
5ranked-venue papers
1as first author
5since 2021 · last 2026
0000-0003-1870-6303ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 1 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Implicit end-point attestation for trusted channel establishment in the keystone TEEabstractNowadays, various contexts and applications include IoT devices. Due to their limited resources and power constraints, these systems are a possible threat vector that adversaries may exploit for cyberattacks. Despite the protection of network communication with Secure Channels, such as TLS and IPsec, the endpoint with which we exchange information may still be compromised. Thus, an adversary may obtain access to sensitive information or send corrupted data without being detected by the other network nodes. Remote Attestation is a possible security control that can detect device misbehaviours, allowing an external entity to verify a platform’s trustworthiness. Attestation reports contain system measures and configuration information to prove the system state. So, the external entity can verify the platform’s authenticity and integrity by comparing the data included in the report with the corresponding expected values. Several solutions addressing this issue are presented in the literature, including Remote Attestation over secure channels. Trusted Channels is the name given to these protocols, as the trustworthiness of the endpoints is a security property guaranteed by the Channel, in addition to the properties of a secure channel. This paper proposes a new certification protocol for IoT devices that merges Remote Attestation with the issuance of a certificate for a key pair generated and stored securely on the platform. This new credential enables the establishment of TLS channels; therefore, the other endpoint obtains information about the node’s trustworthiness. We implemented the protocol within the Keystone framework, which enables a customizable Trusted Execution Environment that provides the Remote Attestation mechanism. Giacomo Bruno, Silvia Sisinni, Enrico Bravi, Lorenzo Ferro, Flavio Ciravegna, Antonio Lioy |
Comput. Networks | 2 |
| 2025 | Application Integrity Verification in Confidential Computing ScenarioabstractThe proliferation of cloud computing has transformed the deployment and scalability of applications, enabling organizations to leverage virtualized infrastructures for enhanced flexibility and efficiency. However, this shift has also introduced significant security and privacy challenges, particularly concerning the protection of sensitive data during processing. Confidential Computing has emerged as a paradigm to address these concerns by safeguarding data in use through hardwarebased Trusted Execution Environments (TEEs). TEEs provide isolated environments that ensure the confidentiality and integrity of code and data, even in the presence of potentially compromised host systems. Despite the advancements in TEE technologies, the heterogeneity among implementations poses challenges for developers aiming to create portable and secure applications. Enarx, an open-source project under the Confidential Computing Consortium, addresses this issue by offering a platformagnostic framework that abstracts the complexities of various TEE architectures, facilitating the deployment of applications across different environments. While Enarx ensures the attestation of the underlying hardware and its own components, it currently lacks mechanisms to allow remote attestation of user-developed applications deployed and running within the TEE. This paper proposes an extension to the Enarx framework that incorporates a mechanism that enables application-level remote attestation, guaranteeing the trustworthiness of workloads deployed in TEEs. By integrating a Trust Monitor system into the remote attestation process, our approach enables the validation of application authenticity and integrity, thereby strengthening the overall security posture of Confidential Computing deployments. This advancement is particularly pertinent for sectors requiring stringent data protection measures, such as finance, healthcare, and critical infrastructure. Enrico Bravi, Silvia Sisinni, Antonio Lioy |
ISCC | 2 |
| 2024 | On the evaluation of X.509 certificate processing in Transport Layer Security interceptorsabstractThe Transport Layer Security (TLS) interceptors are applications running on client devices or on separate machines that filter TLS-protected traffic between two endpoints. They split the original TLS channel into two TLS channels and they might significantly impact the security obtained. They are increasingly used and installed by numerous end users or network administrators. It is necessary to assess X.509 certificate processing in TLS interceptors since flaws or problems in performing this task correctly and completely may weaken the client’s communication security. We define X.509-related tests, which are divided into five categories based on which part(s) of the X.509 certificate fields or extensions get analyzed. We propose a method for automatically generating wrong, malformed, or unusual X.509 certificates (and chains) and configuration files suitable for the most common web servers, like Apache or Nginx. We deploy the generated configuration files on the TLS-aware web servers in an experimental testbed set up for testing the behavior of four selected TLS interceptors, two antivirus, and two proxy applications running on different operating systems. We report the results obtained, underlining the need to test in-depth such applications so that they would not decrease the security levels achieved by the clients. Diana Berbecaru, Silvia Sisinni, Matteo Simone |
ISCC | 2 |
| 2024 | MATCH-IN: Mutual Attestation for Trusted Collaboration in Heterogeneous IoT NetworksabstractAs the Internet of Things (IoT) continues to evolve, ensuring the security and trustworthiness of devices within heterogeneous IoT networks becomes of paramount importance. This paper presents MATCH-IN (Mutual Attestation for Trusted Collaboration in Heterogeneous IoT Networks), a novel approach to establish trusted connections based on mutual attestation between IoT devices that dynamically join a network. Drawing inspiration from the Trusted Computing Group’s "Device Identifier Composition Engine" specification, MATCH-IN introduces a comprehensive scheme for device mutual attestation. The proposed schema enhances the security posture of unstructured IoT networks by enabling devices to mutually attest their identities and configurations, without the need for a centralized verifier for checking the trustworthiness of devices, while these operate in the field. Through a detailed exploration of the DICE specification, this paper provides insights into the integration of MATCH-IN within the context of diverse IoT environments. Our approach aims to foster trusted collaboration among heterogeneous IoT devices, laying the foundation for enhanced security and reliability in the rapidly expanding IoT landscape. Silvia Sisinni, Diana Berbecaru, Valerio Donnini, Antonio Lioy |
ISCC | 1 |
| 2022 | (POSTER) Using MACsec to protect a Network Functions Virtualisation infrastructureabstractIEEE 802.1AE is a standard for Media Access Control security (MACsec), which enables data integrity, authentication, and confidentiality for traffic in a broadcast domain. This protects network communications against attacks at link layer, hence it provides a higher degree of security and flexibility compared to other security protocols, such as IPsec. Softwarised network infrastructures, based on Network Functions Virtualisation (NFV) and Software Defined Networking (SDN), provide higher flexibility than traditional networks. Nonetheless, these networks have a larger attack surface compared to legacy infrastructures based on hardware appliances. In this scenario, communication security is important to ensure that the traffic in a broadcast domain is not intercepted or manipulated. We propose an architecture for centralised management of MACsec-enabled switches in a NFV environment. Moreover, we present a PoC that integrates MACsec in the Open Source MANO NFV framework and we evaluate its performance. Antonio Lioy, Ignazio Pedone, Silvia Sisinni |
ISCC | 3 |