VLDB 2026 Research / reviewers in the wild / expert
Corrado Aaron Visaggio
dblp:38/2506 · also Aaron Visaggio
· DBLP profile ↗
77ranked-venue papers
1as first author
24since 2021 · last 2026
0000-0002-0558-4450ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 44 · 1 first-author · 12 since 2021Security and privacy · 25 · 6 since 2021Artificial intelligence and machine learning · 4 · 3 since 2021Systems, architecture and hardware · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Computer networks · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Breaking the Imitation Game: Can LLMs Fool Humans and Machines Alike?abstractThe emergence of large language models (LLMs) has significantly advanced natural language processing (NLP); however, their capacity to generate human‐like content introduces serious security concerns. In particular, the misuse of LLMs for disinformation and impersonation on social media platforms such as X creates new opportunities for large‐scale manipulation and deception of users. This study aims to conduct a comprehensive investigation to (i) understand the distinct stylistic features effectively mimicked by 10 different LLMs and (ii) distinguish between LLM‐driven and human authors when LLMs are explicitly instructed to mimic a specific human writing style. In particular, we design adversarial prompts to mimic the writing style of human authors based on key stylometric features (quantitative analysis of writing style) and assess the mimicking effectiveness of different LLMs through extensive statistical testing. In addition, we conduct a survey that gauges human ability to recognize the author of a text and train machine learning models to identify human‐ and LLM‐driven authors, focusing on scenarios where specifically crafted adversarial prompts are employed to facilitate style impersonation. Our findings demonstrate that, when explicitly instructed, LLMs can effectively replicate features of human writing style. In addition, the survey results indicate that it is challenging for the participants to distinguish between the different types of authors. In fact, the participants only demonstrated a classification accuracy of 15% in correctly identifying the text generated by the LLM. In contrast, high detection performance is achieved only when the training data incorporate adversarially generated LLM samples produced using impersonation‐oriented prompts. Under this threat‐model–aligned training regime, stylometric‐based classifiers exhibit strong discriminative capability, attaining classification accuracy of up to 99% in distinguishing human‐authored text from LLM‐generated authorship. Sonia Laudanna, Andrea Di Sorbo, Corrado Aaron Visaggio |
Int. J. Intell. Syst. | 4 |
| 2025 | Design and Implementation of a Multi-Agent Threat Intelligence Assistant Based on Generative AI
Francesco Saccone, Alessandro Manzi, Andrea Di Sorbo, Elisa Costante, Corrado Aaron Visaggio |
IEEE Big Data | 5 |
| 2025 | The Future of Software Transparency: Bridging Understanding, Measurement, and PracticeabstractAlthough the study of software transparency has deep roots in software engineering, a shared definition and practical application in real-world development contexts remain elusive. Through an in-depth analysis of the academic and industrial landscape, this article provides an overview of the current state of knowledge on software transparency, outlining a path to a deeper understanding of the subject for both developers and researchers. The challenge of software transparency involves not only establishing a formal, widely accepted understanding within the community, but also measuring and quantifying it in production environments. To this end, we survey academics and developers to evaluate an innovative approach to defining transparency and present a vision of a new framework for its quantification. Gregorio Dalia, Annibale Panichella, Andrea Di Sorbo, Gerardo Canfora, Corrado Aaron Visaggio |
ASE | 5 |
| 2025 | SecDefender: Detecting low-quality models in multidomain federated learning systems
K. M. Sameera, Arnaldo Sgueglia, P. Vinod 0001, Rafidha Rehiman K. A., Corrado Aaron Visaggio, Andrea Di Sorbo, Mauro Conti |
Future Gener. Comput. Syst. | 5 |
| 2025 | The ransomware blueprint: Attack patterns and strategic variations across gangsabstractIn recent years, ransomware attacks have attracted the attention of researchers and companies, prompting new issues in identifying effective defense techniques. The study provides a comprehensive analysis of ransomware attacks and their employed tactics from 2020 to 2024, leveraging a large dataset of over 16,000 documented ransomware incidents involving 155 distinct gangs. Using this data, we identify the exploited software vulnerabilities (CVEs) and map them to specific adversarial behaviors within the MITRE ATT&CK framework. In addition to this technical mapping, we differentiated between broadly targeting “generalist” gangs and industry-focused ”specialist” gangs, and we examined variations in attack patterns across target sectors and geographic origins. Our methodology reveals the core ”ransomware blueprint”: a unified kill-chain model comprising recurring techniques spanning initial access through encryption. Key findings include the use of high-severity, widely deployed CVEs (particularly public-facing exploits, such as T1190) as entry points, followed by routine privilege escalation, lateral movement, and impact actions (e.g., T1486 for data encryption). The analysis also reveals regional and sectoral differences: (i) Russian-origin groups often emphasize rapid disruption and recovery inhibition, and (ii) other groups focus on stealthier reconnaissance. Generalist gangs (e.g., LockBit, Cl0p, ALPHV) employ advanced techniques across multiple industries, while specialist gangs concentrate on narrower sectors, using simpler methods such as phishing and credential reuse. Moreover, the number of shared techniques is employed to assess the degree of interconnection among the gangs. These findings provide actionable intelligence for defenders, highlighting the need for multi-layered defenses, targeted vulnerability management, and sector-specific hardening strategies to mitigate evolving ransomware threats. Francesco Saccone, Pietro Melillo, Arnaldo Sgueglia, Andrea Di Sorbo, Corrado Aaron Visaggio |
J. Inf. Secur. Appl. | 5 |
| 2024 | SBOM Ouverture: What We Need and What We HaveabstractA Software Bill of Materials (SBOM) is an inventory of the software components used to build a product, which can help customers track security risks throughout the development lifecycle. The popularity of SBOMs grew in May 2021 when the White House issued an executive order to improve the security of the software supply chain and the transparency of the government’s software inventory. Although the growing interest in SBOM, many open challenges need to be addressed to help reduce exposure to cyber risks and enhance the security of software supply chains. To help the industry and research assemble the roadmap to achieve SBOM adoption in practice, in this paper, we analyze the challenges related to enabling technologies and the open issues that research must investigate. Furthermore, we perform a comparative analysis of the existing tools to generate SBOMs, demonstrating that the enabling technologies have not yet reached full automation and maturity. Gregorio Dalia, Corrado Aaron Visaggio, Andrea Di Sorbo, Gerardo Canfora |
ARES | 2 |
| 2024 | Poster: A Multi-step Approach for Classification of Malware SamplesabstractThe rapid spread of unknown malware has prompted many companies and researchers to improve their detection and classification systems. Cyber security companies must deal with the newest malware samples captured by their honeypots, aiming to analyze and classify them to develop several countermeasures. This process could only be feasible with a strong ground truth baseline; companies could only securely store the samples, waiting for further developments. This paper proposes a multi-step approach to support the classification process of unknown malware samples. Specifically, our approach first leverages well-known classification techniques and third-party services to collect as much information as possible about the samples and combines them with Machine Learning (ML)-based techniques to classify the remaining samples. Our case study, conducted on industrial data, shows how the combination offers superior performance than using each method individually. Arnaldo Sgueglia, Rocco Addabbo, Andrea Di Sorbo, Stanislav Dashevskyi, Daniel Ricardo dos Santos, Corrado Aaron Visaggio |
CCS | 6 |
| 2024 | Beyond Words: Stylometric Analysis for Detecting AI Manipulation on Social Media
Sonia Laudanna, P. Vinod 0001, Andrea Di Sorbo, Corrado Aaron Visaggio, Gerardo Canfora |
ESORICS (1) | 5 |
| 2024 | Functional suitability assessment of smart contracts: A survey and first proposalabstractAbstract Blockchain is a cross‐cutting technology allowing interactions among untrusted entities in a distributed manner without the need for involving a trusted third party. Smart contracts (i.e., programs running on the blockchain) enabled organizations to envision and implement solutions to real‐world problems in less cost and time. Given the immutability of blockchain and the lack of best practices for properly designing and developing smart contracts, it is crucial to assure smart contract quality before deployment. With the help of an exploratory survey involving developers and researchers, this paper identifies the practices and tools used to develop, implement, and evaluate smart contracts. The survey received 55 valid responses. Such responses indicate that (i) inefficiencies may occur during the development cycle of a smart contract, especially regarding requirements specification, design, and testing phases, and (ii) the lack of a shared standard to evaluate the functional quality of implemented smart contracts. To start coping with these issues, the adoption of functional suitability assessment measures recommended by the ISO/IEC 25000 standard, widely used in software engineering, is proposed by adapting them to the context of smart contracts. Through some examples, the manuscript also illustrates how to measure the functional completeness and correctness of smart contracts. The proposed procedure to measure smart contract functional suitability brings advantages to both developers and users of decentralized finance or non‐fungible tokens platforms, data marketplaces, or shipping and real estate services, just to mention a few. In particular, it helps (i) better outline the responsibilities of smart contracts, (ii) uncover errors and deficiencies of smart contracts in the early stages, and (iii) ensure that the established requirements are met. Anna Vacca, Michele Fredella, Andrea Di Sorbo, Corrado Aaron Visaggio, Mario Piattini |
J. Softw. Evol. Process. | 4 |
| 2023 | Automated Identification and Qualitative Characterization of Safety Concerns Reported in UAV Software PlatformsabstractUnmanned Aerial Vehicles (UAVs) are nowadays used in a variety of applications. Given the cyber-physical nature of UAVs, software defects in these systems can cause issues with safety-critical implications. An important aspect of the lifecycle of UAV software is to minimize the possibility of harming humans or damaging properties through a continuous process of hazard identification and safety risk management. Specifically, safety-related concerns typically emerge during the operation of UAV systems, reported by end-users and developers in the form of issue reports and pull requests. However, popular UAV systems daily receive tens or hundreds of reports of varying types and quality. To help developers timely identify and triage safety-critical UAV issues, we (i) experiment with automated approaches (previously used for issue classification) for detecting the safety-related matters appearing in the titles and descriptions of issues and pull requests reported in UAV platforms and (ii) propose a categorization of the main hazards and accidents discussed in such issues. Our results (i) show that shallow machine learning (ML)-based approaches can identify safety-related sentences with precision, recall, and F-measure values of about 80%; and (ii) provide a categorization and description of the relationships between safety issue hazards and accidents. Andrea Di Sorbo, Fiorella Zampetti, Corrado Aaron Visaggio, Massimiliano Di Penta, Sebastiano Panichella |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2022 | We cannot trust in you: a study about the dissonance among anti-malware enginesabstractThe impressive volume of malware circulating today, the increase in its sophistication, its unpredictability and evasiveness pose new problems to face in the deployment of effective defence systems. It is proven today that no single anti-malware solution could be universally effective in protecting from all threats due to its inherent inaccuracy. Different anti-malware solutions could produce analyses that may significantly vary, in terms of both detection rate (not all are able to recognize the same malware) and classification (not all assign the same family name to the same malware). In this study we realize a quantitative analysis of the dissonance among anti-malware solutions commonly used in the marketplace and widely deployed in real world with the aim of evaluating the classification inaccuracies. We carried out this evaluation on two datasets: one comprising 103,073 malware updated to 2020/10/03 from the MalwareBazaar repository; the other composed of 100k malware extracted from EMBER dataset. Our results show that there is a large disagreement in classification and the uncertainty about type and family identification is still high. Davide Cocca, Antonio Pirozzi, Corrado Aaron Visaggio |
ARES | 3 |
| 2022 | An empirical investigation on the trade-off between smart contract readability and gas consumptionabstractBlockchain technology is becoming increasingly popular, and smart contracts (i.e., programs that run on top of the blockchain) represent a crucial element of this technology. In particular, smart contracts running on Ethereum (i.e., one of the most popular blockchain platforms) are often developed with Solidity, and their deployment and execution consume gas (i.e., a fee compensating the computing resources required). Smart contract development frequently involves code reuse, but poor readable smart contracts could hinder their reuse. However, writing readable smart contracts is challenging, since practices for improving the readability could also be in contrast with optimization strategies for reducing gas consumption. This paper aims at better understanding (i) the readability aspects for which traditional software and smart contracts differ, and (ii) the specific smart contract readability features exhibiting significant relationships with gas consumption. We leverage a set of metrics that previous research has proven correlated with code readability. In particular, we first compare the values of these metrics obtained for both Solidity smart contracts and traditional software systems (written in Java). Then, we investigate the correlations occurring between these metrics and gas consumption and between each pair of metrics. The results of our study highlight that smart contracts usually exhibit lower readability than traditional software for what concerns the number of parentheses, inline comments, and blank lines used. In addition, we found some readability metrics (such as the average length of identifiers and the average number of keywords) that significantly correlate with gas consumption. Anna Vacca, Michele Fredella, Andrea Di Sorbo, Corrado Aaron Visaggio, Gerardo Canfora |
ICPC | 4 |
| 2022 | An Exploratory Study on Self-Fixed Software Vulnerabilities in OSS ProjectsabstractRemediation to a software vulnerability can be accomplished either by the developer who introduced it or by a different one. In this context, we refer to a self-fixed vulnerability when the fixing is carried out by the developer who introduced it. Previous research demonstrated that a developer who introduces a bug is also the best candidate to fix it. However, as vulnerabilities conceptually differ from non-security bugs and specific skills and knowledge are required for solving them, it is unclear if the previous finding also applies to vulnerabilities or specific vulnerability types. To fill this gap, in this paper, we investigate the diffusion of self-fixed vulnerabilities within software projects, the types of vulnerabilities that are more prone to self-fixing, and the time required to solve self-fixed vulnerabilities compared to non-self-fixed ones. Specifically, we analyzed 1,752 commits related to C and PHP open-source projects aimed at fixing (or self-fixing) vulnerabilities spanning 17 different types of software weaknesses. The results of our study show that 20.55% of the considered vulnerabilities in C projects and 36.46% of the considered vulnerabilities in PHP projects are self-fixed. In addition, the average remediation time of self-fixed vulnerabilities is generally shorter than non-self-fixed ones. In particular, in C projects, self-fixed integer overflow vulnerabilities are patched about 5 times shorter than non-self-fixed ones, while vulnerabilities related to improper calculation or conversion of numbers are generally fixed faster by other developers. Similarly, in PHP projects, CSRF vulnerabilities tend to be patched in a shorter time when they are self-fixed, while unauthorized access vulnerabilities are likely repaired faster by other developers. Our results can help both researchers and practitioners identifying the best candidates to solve specific vulnerability bugs. Sara Forootani, Andrea Di Sorbo, Corrado Aaron Visaggio |
SANER | 3 |
| 2022 | A systematic literature review of IoT time series anomaly detection solutions
Arnaldo Sgueglia, Andrea Di Sorbo, Corrado Aaron Visaggio, Gerardo Canfora |
Future Gener. Comput. Syst. | 3 |
| 2022 | Patchworking: Exploring the code changes induced by vulnerability fixing activities
Gerardo Canfora, Andrea Di Sorbo, Sara Forootani, Matias Martinez, Corrado Aaron Visaggio |
Inf. Softw. Technol. | 5 |
| 2022 | Profiling gas consumption in solidity smart contracts
Andrea Di Sorbo, Sonia Laudanna, Anna Vacca, Corrado Aaron Visaggio, Gerardo Canfora |
J. Syst. Softw. | 4 |
| 2021 | It's a Matter of Style: Detecting Social Bots through Writing Style ConsistencyabstractSocial bots are computer algorithms able to produce content and interact with other users on social media autonomously, trying to emulate and possibly influence humans’ behavior. Indeed, bots are largely employed for malicious purposes, like spreading disinformation and conditioning electoral campaigns. Nowadays, bots’ capability of emulating human behaviors has become increasingly sophisticated, making their detection harder. In this paper, we aim at recognizing bot-driven accounts by evaluating the consistency of users’ writing style over time. In particular, we leverage the intuition that while bots compose posts according to fairly deterministic processes, humans are influenced by subjective factors (e.g., emotions) that can alter their writing style. To verify this assumption, by using stylistic consistency indicators, we characterize the writing style of more than 12,000 among bot-driven and human-operated Twitter accounts and find that statistically significant differences can be observed between the different types of users. Thus, we evaluate the effectiveness of different machine learning (ML) algorithms based on stylistic consistency features in discerning between human-operated and bot-driven Twitter accounts and show that the experimented ML algorithms can achieve high performance (i.e., F-measure values up to 98%) in social bot detection tasks. Matteo Cardaioli, Mauro Conti, Andrea Di Sorbo, Enrico Fabrizio, Sonia Laudanna, Corrado Aaron Visaggio |
ICCCN | 6 |
| 2021 | iSCREAM: a suite for Smart Contract REAdability assessMentabstractBlockchain is increasingly revolutionizing a variety of sectors, from finance to healthcare. Indeed, the availability of public blockchain platforms, such as Ethereum, has stimulated the development of hundreds of decentralized apps (dApps) that combine smart contract(s) and a front-end user interface. Smart contracts are software, as well, and, as traditional software, they require to be developed and maintained or evolved. Among all the quality properties that must be assessed and guaranteed, readability is a key aspect of source code: a highly readable code facilitates its maintainability, portability, and reusability. This is especially true when considering smart contracts, where code reuse is widely adopted. Indeed, smart contract developers often integrate code portions from other smart contracts in their artifacts. To help developers and researchers more easily estimating and monitoring the code readability of smart contracts, in this demo, we present iSCREAM. iSCREAM automatically inspects Solidity smart contracts and computes a set of metrics that previous research demonstrated being related to code readability. We evaluated iSCREAM on 90 real-world smart contract functions, showing that our tool correctly computes all the aforementioned metrics. Demo webpage: https://github.com/mfredella/iSCREAM Gerardo Canfora, Andrea Di Sorbo, Michele Fredella, Anna Vacca, Corrado Aaron Visaggio |
ICSME | 5 |
| 2021 | An NLP-based Tool for Software Artifacts AnalysisabstractSoftware developers rely on various repositories and communication channels to exchange relevant information about their ongoing tasks and the status of overall project progress. In this context, semi-structured and unstructured software artifacts have been leveraged by researchers to build recommender systems aimed at supporting developers in different tasks, such as transforming user feedback in maintenance and evolution tasks, suggesting experts, or generating software documentation. More specifically, Natural Language (NL) parsing techniques have been successfully leveraged to automatically identify (or extract) the relevant information embedded in unstructured software artifacts. However, such techniques require the manual identification of patterns to be used for classification purposes. To reduce such a manual effort, we propose an NL parsing-based tool for software artifacts analysis named NEON that can automate the mining of such rules, minimizing the manual effort of developers and researchers. Through a small study involving human subjects with NL processing and parsing expertise, we assess the performance of NEON in identifying rules useful to classify app reviews for software maintenance purposes. Our results show that more than one-third of the rules inferred by NEON are relevant for the proposed task. Demo webpage: https://github.com/adisorbo/NEON_tool Andrea Di Sorbo, Corrado Aaron Visaggio, Massimiliano Di Penta, Gerardo Canfora, Sebastiano Panichella |
ICSME | 2 |
| 2021 | Automatic Classification of Vulnerabilities using Deep Learning and Machine Learning AlgorithmsabstractAs the field of computer science has advanced over the years, there has been a tremendous increase in the software being created, and this increase has been accompanied by an increase in the number of software vulnerabilities. A software vulnerability is a security flaw found in software that can potentially be exploited by attackers to perform cyber attacks. Since automatic approaches for identifying and analyzing vulnerabilities have become a trending topic in research, community, the classification of vulnerability is still an open issue. Developers need to know more about characteristics and types of vulnerabilities in systems to adopt suitable countermeasures in current and next versions. With this paper, we investigate whether vulnerability descriptions alone can be used to identify the type of vulnerability, by comparing five shallow learning models and fourteen deep learning models. The model with the highest F1-score was the Stacking-DNN (98.8%). On performing comprehensive analysis, the experiments demonstrate that both shallow and deep classifiers show comparable performance when trained and tested using the dataset without duplicates, while shallow classifiers showed better performance when trained and tested using the dataset with duplicates. Vishnu Ramesh, Sara Abraham, P. Vinod 0001, Isham Mohamed, Corrado Aaron Visaggio, Sonia Laudanna |
IJCNN | 5 |
| 2021 | Malware detection employed by visualization and deep neural network
Anson Pinhero, Anupama M. L, P. Vinod 0001, Corrado Aaron Visaggio, Aneesh N, Abhijith S, AnanthaKrishnan S |
Comput. Secur. | 4 |
| 2021 | A systematic literature review of blockchain and smart contract development: Techniques, tools, and open challenges
Anna Vacca, Andrea Di Sorbo, Corrado Aaron Visaggio, Gerardo Canfora |
J. Syst. Softw. | 3 |
| 2021 | Investigating the criticality of user-reported issues through their relations with app ratingabstractAbstract App quality impacts user experience and satisfaction. As a consequence, both app ratings and user feedback reported in app reviews are directly influenced by the user‐perceived app quality. Through an empirical study involving 210,517 reviews related to 317 Android apps, in this paper, we experiment with the combined usage of app rating and user reviews analysis (i) to investigate the most important factors influencing the perceived app quality, (ii) focusing on the topics discussed in user review that most relate with app rating. Besides, we investigate whether specific code quality metrics could be monitored to prevent the rising of negative user feedback (i.e., types of user review comments), connected with low ratings. Our study demonstrates that user comments reporting bugs are negatively correlated with the rating, while reviews reportingfeature requests do not. Interestingly, depending on the app category, we observed that different kinds of issues have rather different relationships with the rating and the user‐perceived quality of the app. In particular, we observe that for specific app categories (e.g., communication), some code quality factors have significant relationships with the raising of certain types of feedback, which, in turn, are negatively connected with app ratings. Andrea Di Sorbo, Giovanni Grano, Corrado Aaron Visaggio, Sebastiano Panichella |
J. Softw. Evol. Process. | 3 |
| 2021 | Exploiting Natural Language Structures in Software Informal DocumentationabstractCommunication means, such as issue trackers, mailing lists, Q&A forums, and app reviews, are premier means of collaboration among developers, and between developers and end-users. Analyzing such sources of information is crucial to build recommenders for developers, for example suggesting experts, re-documenting source code, or transforming user feedback in maintenance and evolution strategies for developers. To ease this analysis, in previous work we proposed Development Emails Content Analyzer (DECA), a tool based on Natural Language Parsing that classifies with high precision development emails' fragments according to their purpose. However, DECA has to be trained through a manual tagging of relevant patterns, which is often effort-intensive, error-prone and requires specific expertise in natural language parsing. In this paper, we first show, with an empirical study, the extent to which producing rules for identifying such patterns requires effort, depending on the nature and complexity of patterns. Then, we propose an approach, named Nlp-based softwarE dOcumentation aNalyzer (NEON), that automatically mines such rules, minimizing the manual effort. We assess the performances of NEON in the analysis and classification of mobile app reviews, developers discussions, and issues. NEON simplifies the patterns identification and rules definition processes, allowing a savings of more than 70 percent of the time otherwise spent on performing such activities manually. Results also show that NEON-generated rules are close to the manually identified ones, achieving comparable recall. Andrea Di Sorbo, Sebastiano Panichella, Corrado Aaron Visaggio, Massimiliano Di Penta, Gerardo Canfora, Harald C. Gall |
IEEE Trans. Software Eng. | 3 |
| 2020 | About the Robustness and Looseness of Yara Rules
Gerardo Canfora, Mimmo Carapella, Andrea Del Vecchio, Laura Nardi, Antonio Pirozzi, Corrado Aaron Visaggio |
ICTSS | 6 |
| 2020 | Investigating the vulnerability fixing process in OSS projects: Peculiarities and challenges
Gerardo Canfora, Andrea Di Sorbo, Sara Forootani, Antonio Pirozzi, Corrado Aaron Visaggio |
Comput. Secur. | 5 |
| 2020 | Demystifying the adoption of behavior-driven development in open source projects
Fiorella Zampetti, Andrea Di Sorbo, Corrado Aaron Visaggio, Gerardo Canfora, Massimiliano Di Penta |
Inf. Softw. Technol. | 3 |
| 2019 | On the effectiveness of system API-related information for Android ransomware detection
Michele Scalas, Davide Maiorca, Francesco Mercaldo, Corrado Aaron Visaggio, Fabio Martinelli, Giorgio Giacinto |
Comput. Secur. | 4 |
| 2019 | Summarizing vulnerabilities' descriptions to support experts during vulnerability assessment activities
Ernesto Rosario Russo, Andrea Di Sorbo, Corrado Aaron Visaggio, Gerardo Canfora |
J. Syst. Softw. | 3 |
| 2019 | LEILA: Formal Tool for Identifying Mobile Malicious BehaviourabstractWith the increasing diffusion of mobile technologies, nowadays mobile devices represent an irreplaceable tool to perform several operations, from posting a status on a social network to transfer money between bank accounts. As a consequence, mobile devices store a huge amount of private and sensitive information and this is the reason why attackers are developing very sophisticated techniques to extort data and money from our devices. This paper presents the design and the implementation of LEILA (formaL tool for idEntifying mobIle maLicious behAviour), a tool targeted at Android malware families detection. LEILA is based on a novel approach that exploits model checking to analyse and verify the Java Bytecode that is produced when the source code is compiled. After a thorough description of the method used for Android malware families detection, we report the experiments we have conducted using LEILA. The experiments demonstrated that the tool is effective in detecting malicious behaviour and, especially, in localizing the payload within the code: we evaluated real-world malware belonging to several widespread families obtaining an accuracy ranging between 0.97 and 1. Gerardo Canfora, Fabio Martinelli, Francesco Mercaldo, Vittoria Nardone, Antonella Santone, Corrado Aaron Visaggio |
IEEE Trans. Software Eng. | 6 |
| 2018 | A Nlp-based Solution to Prevent from Privacy Leaks in Social Network PostsabstractPrivate and sensitive information is often revealed in posts appearing in Social Networks (SN). This is due to the users' willingness to increase their interactions within specific social groups, but also to a poor knowledge about the risks for privacy. We argue that technologies able to evaluate the sensitiveness of information while it is being published could enhance privacy protection by warning the user about the risks deriving from the disclosure of a certain information. To this aim, we propose a method, and an accompanying tool, to automatically intercept the sensitive information which is delivered in a social network post, through the exploitation of recurrent natural language patterns that are often used by users to disclose private data. A comparison with several machine learning techniques reveals that our method outperforms them, since it is more precise, accurate and not dependent on (i) a specific training set, or (ii) the selection of particular features. Gerardo Canfora, Andrea Di Sorbo, Enrico Emanuele, Sara Forootani, Corrado Aaron Visaggio |
ARES | 5 |
| 2018 | Impact of Code Obfuscation on Android Malware Detection based on Static and Dynamic AnalysisabstractThe huge diffusion of malware in mobile platform is plaguing users. New malware proliferates at a very fast pace: as a matter of fact, to evade the signature-based mechanism implemented in current antimalware, the application of trivial obfuscation techniques to existing malware is sufficient. In this paper, we show how the application of several morphing techniques affects the effectiveness of two widespread malware detection approaches based on Machine Learning coupled respectively with static and dynamic analysis. We demonstrate experimentally that dynamic analysis-based detection performs equally well in evaluating obfuscated and non-obfuscated malware. On the other hand, static analysis-based detection is more accurate on non-obfuscated samples but is greatly negatively affected by obfuscation: however, we also show that this effect can be mitigated by using obfuscated samples also in the learning phase. Alessandro Bacci, Alberto Bartoli, Fabio Martinelli, Eric Medvet, Francesco Mercaldo, Corrado Aaron Visaggio |
ICISSP | 6 |
| 2018 | An exploratory study on the evolution of Android malware qualityabstractAbstract In the context of software engineering, product software quality measures how well a software artifact is designed and coded. Software products must satisfy nonfunctional properties (eg, reliability, usability, understandability, and maintainability), in order to make maintenance and evolution sustainable in the long period. Software evolution is an issue of interest for the malware writers, too, for 2 reasons. First, to evade detection with the minimum effort, malware writers use to produce “variants,” which are obtained by applying little changes to existing malware. Morevoer, recent studies demonstrated that malware is increasingly improving evasion strategies and infection mechanisms and is using more and more complex payloads. This suggests that malware writers are devoting relevant efforts and skills for producing high‐quality software. For this reason, we wonder whether malware writers are devoting effort to improve the structural quality of their code, too, as it happens in the development of goodware. To investigate this question, we (1) characterize a dataset containing about 20 000 Android applications, divided into goodware and malware ones, relying on the Android API version they require, and (2) compute software quality metrics, divided into 4 categories (ie, dimensional, complexity, object‐oriented, and Android‐oriented metrics) for apps belonging to each population. We then identify evolution trends of these metrics in malware and goodware. The results of our study demonstrate that goodware and malicious applications exhibit similar evolution trends for some of the quality indicators, suggesting that malware writers care about the overall quality of their code. Code quality could be considered an indirect measure of how many and how fast variants of existing malware will be released in the wild. Francesco Mercaldo, Andrea Di Sorbo, Corrado Aaron Visaggio, Aniello Cimitile, Fabio Martinelli |
J. Softw. Evol. Process. | 3 |
| 2017 | Identifying Mobile Repackaged Applications through Formal Methods
Fabio Martinelli, Francesco Mercaldo, Vittoria Nardone, Antonella Santone, Corrado Aaron Visaggio |
ICISSP | 5 |
| 2017 | "Mirror, Mirror on the Wall, Who is the Fairest One of All?" - Machine Learning versus Model Checking: A Comparison between Two Static Techniques for Malware Family Identification
Vittoria Nardone, Corrado Aaron Visaggio |
ICISSP | 2 |
| 2017 | Mobile Silent and Continuous Authentication using Apps Sequence
Gerardo Canfora, Giovanni Cappabianca, Pasquale Carangelo, Fabio Martinelli, Francesco Mercaldo, Ernesto Rosario Russo, Corrado Aaron Visaggio |
SECRYPT | 7 |
| 2017 | s2ipt: A Lightweight Network Intrusion Detection/Prevention System based on IPtablesabstractSince each organization has its own security culture and background, there is not an out-of-the-box solution that fits all the possible security requirements.There may be some contexts in which it is necessary to monitor and prevent certain application-level attacks with less impact on pre-existent configuration.For example, there may be some constraints on processing resources of some embedded devices.Starting from this consideration, we developed s2ipt, a python-powered tool which aims to implement a lightweight Netfilter-based network intrusion detection and prevention system (IDS/IPS) by translating Snort community rules into iptables rulesset.s2ipt utilizes the netfilter string matching module to detect application-level attacks.Netfilter reduces the impact on a system, has less memory and CPU footprint, which makes it suitable to run even on low-cost devices than a solution like Snort.s2ipt allows iptables to detect application layer attacks in a transparent way, in fact it only adds new application layer ruleset leaving the existing ones unchanged. Gerardo Canfora, Antonio Pirozzi, Corrado Aaron Visaggio |
SECRYPT | 3 |
| 2016 | Spotting the Malicious Moment: Characterizing Malware Behavior Using Dynamic FeaturesabstractWhile mobile devices have become more pervasive every day, the interest in them from attackers has also been increasing, making effective malware detection tools of ultimate importance for malware investigation and user protection. Most informative malware identification techniques are the ones that are able to identify where the malicious behavior is located in applications. In this way, better understanding of malware can be achieved and effective tools for its detection can be written. However, due to complexity of such a task, most of the current approaches just classify applications as malicious or benign, without giving any further insights. In this work, we propose a technique for automatic analysis of mobile applications which allows its users to automatically identify the sub-sequences of execution traces where malicious activity happens, hence making further manual analysis and understanding of malware easier. Our technique is based on dynamic features concerning resources usage and system calls, which are jointly collected while the application is executed. An execution trace is then split in shorter chunks that are analyzed with machine learning techniques to detect local malicious behaviors. Obtained results on the analysis of 3,232 Android applications show that collected features contain enough information to identify suspicious execution traces that should be further analysed and investigated. Alberto Ferrante, Eric Medvet, Francesco Mercaldo, Jelena Milosevic, Corrado Aaron Visaggio |
ARES | 5 |
| 2016 | Ransomware Steals Your Phone. Formal Methods Rescue It
Francesco Mercaldo, Vittoria Nardone, Antonella Santone, Corrado Aaron Visaggio |
FORTE | 4 |
| 2016 | Identification of Android Malware Families with Model Checking
Pasquale Battista, Francesco Mercaldo, Vittoria Nardone, Antonella Santone, Corrado Aaron Visaggio |
ICISSP | 5 |
| 2016 | Exploring Mobile User Experience Through Code Quality Metrics
Gerardo Canfora, Andrea Di Sorbo, Francesco Mercaldo, Corrado Aaron Visaggio |
PROFES | 4 |
| 2016 | I find your behavior disturbing: Static and dynamic app behavioral analysis for detection of Android malwareabstractMalicious Android applications are currently the biggest threat in the scope of mobile security. To cope with their exponential growth and with their deceptive and hideous behaviors, static analysis signature based approaches are not enough to timely detect and tackle brand new threats such as polymorphic and composition malware. This work presents BRIDEMAID, a novel framework for analysis of Android apps' behavior, which exploits both a static and dynamic approach to detect malicious apps directly on mobile devices. The static analysis is based on n-grams matching to statically recognize malicious app execution patterns. The dynamic analysis is instead based on multi-level monitoring of device, app and user behavior to detect and prevent at runtime malicious behaviors. The framework has been tested against 2794 malicious apps reporting a detection accuracy of 99,7% and a negligible false positive rate, tested on a set of 10k genuine apps. Fabio Martinelli, Francesco Mercaldo, Andrea Saracino, Corrado Aaron Visaggio |
PST | 4 |
| 2016 | How I Met Your Mother? - An Empirical Study about Android Malware PhylogenesisabstractAndroid malware is becoming more and more aggressive, in terms of impact on the victim’s device and in terms of capability of evading detection. Not only smartphones with their sensitive information are targeted by attackers, but also devices such as watches, glasses and everything that can be connected to the Internet of Things. Current signature based antimalware or anomaly based detection are not able to detect zero-day attacks: even trivial code transformation can overcome detection. New malware is often not really new: malware writers are used to add functionality to existing malware, or merge different pieces of existing malware code: this determines the families of Android malware i.e. malware programs that have in common some essential features or behaviors and modify some other parts. To be able to recognize the malware familiy a malware belongs to is useful for malware analysis, fast infection response, and quick incident resolution. In this paper we introduce DescentDroid, a tool that traces back the malware descendant family. We experiment our technique with an extended dataset comprising malware and trusted applications, obtaining high precision in recognizing the malware family membership. Gerardo Canfora, Francesco Mercaldo, Antonio Pirozzi, Corrado Aaron Visaggio |
SECRYPT | 4 |
| 2016 | Silent and Continuous Authentication in Mobile EnvironmentabstractDue to the increasing pervasiveness of mobile technologies, sensitive user information is often stored on
mobile devices. Nowadays, mobile devices do not continuously verify the identity of the user while sensitive
activities are performed. This enables attackers full access to sensitive data and applications on the device, if
they obtain the password or grab the device after login. In order to mitigate this risk, we propose a continuous
and silent monitoring process based on a set of features: orientation, touch and cell tower. The underlying
assumption is that the features are representative of smartphone owner behaviour and this is the reason why
the features can be useful to discriminate the owner by an impostor. Results show that our system, modeling
the user behavior of 21 volunteer participants, obtains encouraging results, since we measured a precision in
distinguishing an impostor from the owner between 99% and 100%. Gerardo Canfora, Paolo Di Notte, Francesco Mercaldo, Corrado Aaron Visaggio |
SECRYPT | 4 |
| 2016 | ARdoc: app reviews development oriented classifierabstractGoogle Play, Apple App Store and Windows Phone Store are well known distribution platforms where users can download mobile apps, rate them and write review comments about the apps they are using. Previous research studies demonstrated that these reviews contain important information to help developers improve their apps. However, analyzing reviews is challenging due to the large amount of reviews posted every day, the unstructured nature of reviews and its varying quality. Sebastiano Panichella, Andrea Di Sorbo, Emitza Guzman, Corrado Aaron Visaggio, Gerardo Canfora, Harald C. Gall |
SIGSOFT FSE | 4 |
| 2016 | What would users change in my app? summarizing app reviews for recommending software changesabstractMobile app developers constantly monitor feedback in user reviews with the goal of improving their mobile apps and better meeting user expectations. Thus, automated approaches have been proposed in literature with the aim of reducing the effort required for analyzing feedback contained in user reviews via automatic classification/prioritization according to specific topics. In this paper, we introduce SURF (Summarizer of User Reviews Feedback), a novel approach to condense the enormous amount of information that developers of popular apps have to manage due to user feedback received on a daily basis. SURF relies on a conceptual model for capturing user needs useful for developers performing maintenance and evolution tasks. Then it uses sophisticated summarisation techniques for summarizing thousands of reviews and generating an interactive, structured and condensed agenda of recommended software changes. We performed an end-to-end evaluation of SURF on user reviews of 17 mobile apps (5 of them developed by Sony Mobile), involving 23 developers and researchers in total. Results demonstrate high accuracy of SURF in summarizing reviews and the usefulness of the recommended changes. In evaluating our approach we found that SURF helps developers in better understanding user needs, substantially reducing the time required by developers compared to manually analyzing user (change) requests and planning future software changes. Andrea Di Sorbo, Sebastiano Panichella, Carol V. Alexandru, Junji Shimagaki, Corrado Aaron Visaggio, Gerardo Canfora, Harald C. Gall |
SIGSOFT FSE | 5 |
| 2016 | Hey Malware, I Can Find You!abstractAndroid smartphones are the most widespread in the world. This is the reason why attackers write code more and more aggressive in order to steal data and other important information stored in the phone. One of the most representative malware that implements the typical trojan behaviour in Android environment is the so-called Fake Installer. In this paper we use formal methods, in particular model checking, in order to identify Fake Installer malware. We specify a set of formulae and then we check these on a designed application model, built in CCS, to recognize whether an application is a malware belonging to Fake Installer family or a legitimate sample. We experiment our methodology on 1125 real world samples obtaining very promising results. Francesco Mercaldo, Vittoria Nardone, Antonella Santone, Corrado Aaron Visaggio |
WETICE | 4 |
| 2016 | An HMM and structural entropy based detector for Android malware: An empirical study
Gerardo Canfora, Francesco Mercaldo, Corrado Aaron Visaggio |
Comput. Secur. | 3 |
| 2015 | Effectiveness of Opcode ngrams for Detection of Multi Family Android MalwareabstractWith the wide diffusion of smartphones and their usage in a plethora of processes and activities, these devices have been handling an increasing variety of sensitive resources. Attackers are hence producing a large number of malware applications for Android (the most spread mobile platform), often by slightly modifying existing applications, which results in malware being organized in families. Some works in the literature showed that opcodes are informative for detecting malware, not only in the Android platform. In this paper, we investigate if frequencies of ngrams of opcodes are effective in detecting Android malware and if there is some significant malware family for which they are more or less effective. To this end, we designed a method based on state-of-the-art classifiers applied to frequencies of opcodes ngrams. Then, we experimentally evaluated it on a recent dataset composed of 11120 applications, 5560 of which are malware belonging to several different families. Results show that an accuracy of 97% can be obtained on the average, whereas perfect detection rate is achieved for more than one malware family. Gerardo Canfora, Andrea De Lorenzo, Eric Medvet, Francesco Mercaldo, Corrado Aaron Visaggio |
ARES | 5 |
| 2015 | Composition-Malware: Building Android Malware at Run TimeabstractWe present a novel model of malware for Android, named composition-malware, which consists of composing fragments of code hosted on different and scattered locations at run time. An key feature of the model is that the malicious behavior could dynamically change and the payload could be activated under logic or temporal conditions. These characteristics allow a malware written according to this model to evade current malware detection technologies for Android platform, as the evaluation has demonstrated. The aim of the paper is to propose new approaches to malware detection that should be adopted in anti-malware tools for blocking a composition-malware. Gerardo Canfora, Francesco Mercaldo, Giovanni Moriano, Corrado Aaron Visaggio |
ARES | 4 |
| 2015 | 6th International Workshop on Emerging Trends in Software Metrics (WETSoM 2015)abstractWETSoM is a gathering of researchers and practitioners to discuss the progress on software metrics knowledge. Motivations for this workshop include the low impact that software metrics have on current software development and the increased interest in research. The goals of this workshop include critically examining the evidence for the effectiveness of existing metrics and identifying new directions for metrics. Evidence for existing metrics includes how the metrics have been used in practice and studies showing their effectiveness. Identifying new directions includes use of new theories, such as complex network theory, on which to base metrics. Steve Counsell, Corrado Aaron Visaggio, Roberto Tonelli, Ewan D. Tempero |
ICSE (2) | 2 |
| 2015 | How can i improve my app? Classifying user reviews for software maintenance and evolutionabstractApp Stores, such as Google Play or the Apple Store, allow users to provide feedback on apps by posting review comments and giving star ratings. These platforms constitute a useful electronic mean in which application developers and users can productively exchange information about apps. Previous research showed that users feedback contains usage scenarios, bug reports and feature requests, that can help app developers to accomplish software maintenance and evolution tasks. However, in the case of the most popular apps, the large amount of received feedback, its unstructured nature and varying quality can make the identification of useful user feedback a very challenging task. In this paper we present a taxonomy to classify app reviews into categories relevant to software maintenance and evolution, as well as an approach that merges three techniques: (1) Natural Language Processing, (2) Text Analysis and (3) Sentiment Analysis to automatically classify app reviews into the proposed categories. We show that the combined use of these techniques allows to achieve better results (a precision of 75% and a recall of 74%) than results obtained using each technique individually (precision of 70% and a recall of 67%). Sebastiano Panichella, Andrea Di Sorbo, Emitza Guzman, Corrado Aaron Visaggio, Gerardo Canfora, Harald C. Gall |
ICSME | 4 |
| 2015 | Development Emails Content Analyzer: Intention Mining in Developer Discussions (T)abstractWritten development communication (e.g. mailing lists, issue trackers) constitutes a precious source of information to build recommenders for software engineers, for example aimed at suggesting experts, or at redocumenting existing source code. In this paper we propose a novel, semi-supervised approach named DECA (Development Emails Content Analyzer) that uses Natural Language Parsing to classify the content of development emails according to their purpose (e.g. feature request, opinion asking, problem discovery, solution proposal, information giving etc), identifying email elements that can be used for specific tasks. A study based on data from Qt and Ubuntu, highlights a high precision (90%) and recall (70%) of DECA in classifying email content, outperforming traditional machine learning strategies. Moreover, we successfully used DECA for re-documenting source code of Eclipse and Lucene, improving the recall, while keeping high precision, of a previous approach based on ad-hoc heuristics. Andrea Di Sorbo, Sebastiano Panichella, Corrado Aaron Visaggio, Massimiliano Di Penta, Gerardo Canfora, Harald C. Gall |
ASE | 3 |
| 2015 | Evaluating Mobile Malware by Extracting User Experience-Based Features
Francesco Mercaldo, Corrado Aaron Visaggio |
PROFES | 2 |
| 2015 | Mobile Malware Detection using Op-code Frequency HistogramsabstractMobile malware has grown in scale and complexity, as a consequence of the unabated uptake of smartphones worldwide. Malware writers have been developing detection evasion techniques which are rapidly making anti-malware technologies uneffective. In particular, zero-days malware is able to easily pass signature based detection, while dynamic analysis based techniques, which could be more accurate and robust, are too costly or inappropriate to real contexts, especially for reasons related to usability. This paper discusses a technique for discriminating Android malware from trusted applications that does not rely on signature, but on identifying a vector of features obtained from the static analysis of the Android's Dalvik code. Experimentation accomplished on a sample of 11,200 applications revealed that the proposed technique produces high precision (over 93%) in mobile malware detection, with an accuracy of 95%. Gerardo Canfora, Francesco Mercaldo, Corrado Aaron Visaggio |
SECRYPT | 3 |
| 2013 | A Classifier of Malicious Android ApplicationsabstractMalware for smart phones is rapidly spreading out. This paper proposes a method for detecting malware based on three metrics, which evaluate: the occurrences of a specific subset of system calls, a weighted sum of a subset of permissions that the application required, and a set of combinations of permissions. The experimentation carried out suggests that these metrics are promising in detecting malware, but further improvements are needed to increase the quality of detection. Gerardo Canfora, Francesco Mercaldo, Corrado Aaron Visaggio |
ARES | 3 |
| 2013 | 4th international workshop on emerging trends in software metrics (WETSoM 2013)abstractThe International Workshop on Emerging Trends in Software Metrics aims at gathering together researchers and practitioners to discuss the progress of software metrics. The motivation for this workshop is the low impact that software metrics has on current software development. The goals of this workshop includes critically examining the evidence for the effectiveness of existing metrics and identifying new directions for metrics. Evidence for existing metrics includes how the metrics have been used in practice and studies showing their effectiveness. Identifying new directions includes use of new theories, such as complex network theory, on which to base metrics. Steve Counsell, Michele Marchesi, Ewan D. Tempero, Corrado Aaron Visaggio |
ICSE | 4 |
| 2013 | A Case Study of Automating User Experience-Oriented Performance Testing on SmartphonesabstractWe have developed a platform named Advanced Test Environment (ATE) for supporting the design and the automatic execution of UX tests for applications running on Android smartphones. The platform collects objective metrics used to estimate the UX. In this paper, we investigate the extent that the metrics captured by ATE are able to approximate the results that are obtained from UX testing with real human users. Our findings suggest that ATE produces UX estimations that are comparable to those reported by human users. We have also compared ATE with three widespread benchmark tools that are commonly used in the industry, and the results show that ATE outperforms these tools. Gerardo Canfora, Francesco Mercaldo, Corrado Aaron Visaggio, Mauro D'Angelo, Antonio Furno, Carminantonio Manganelli |
ICST | 3 |
| 2009 | A Test Framework for Assessing Effectiveness of the Data Privacy Policy's Implementation into Relational DatabasesabstractThe growing migration of business transactions toward the web made data privacy a critical issue to cope with. Many technologies have been proposed in order to preserve sensitive data from illegal disclosure, also known as privacy enhancing technology (PET). Unfortunately, under certain conditions, sensitive data could be obtained by leveraging different malicious mechanisms which exploit actions permitted to the user. Thus, it is needed to face the problem also at the system design level, and not only by integrating a specific PET into the final system. We propose a framework for testing the software systempsilas capability of respecting established data privacy policy. Our test framework aims at detecting the sequence of legal actions which could allow a user to breach the mechanisms for preserving data privacy. The test output helps designers to properly modify those usage scenarios which could compromise data privacy. Experimentation has been carried out in order to make a preliminary assessment of the method. Gerardo Canfora, Corrado Aaron Visaggio, Vito Paradiso |
ARES | 2 |
| 2008 | A System to Prevent Multi-users and Multi-sessions Attack to Breach Privacy Policies in a Trust-End FilterabstractAmong the different technological solutions realized in order to preserve data privacy, the front end trust filter could be effectively applied in environments characterized by high dynamism and untrustworthiness. Unfortunately, a preliminary assessment of this approach suggested a possible weakness: by using different user's profiles the privacy policy can be eluded and sensitive information could be obtained by inference over legal data set. This paper proposes a solution that could be helpful for two purposes: it could be used in the design phase for identifying which use scenarios (i.e., sequences of legal queries) could threaten data privacy; additionally, it could be used for identifying users which could potentially exploit inference for disclosing confidential information. Gerardo Canfora, Corrado Aaron Visaggio |
COMPSAC | 2 |
| 2008 | Evaluation of BPMN Models Quality - A Family of Experiments
Elvira Rolón Aguilar, Félix García 0001, Francisco Ruiz 0001, Mario Piattini, Corrado Aaron Visaggio, Gerardo Canfora |
ENASE | 5 |
| 2008 | Are fit tables really talking?: a series of experiments to understand whether fit tables are useful during evolution tasksabstractTest-driven software development tackles the problem of operationally defining the features to be implemented by means of test cases. This approach was recently ported to the early development phase, when requirements are gathered and clarified. Among the existing proposals, Fit (Framework for Integrated Testing) supports the precise specification of requirements by means of so called Fit tables, which express relevant usage scenarios in a tabular format, easily understood also by the customer. Fit tables can be turned into executable test cases through the creation of pieces of glue code, called fixtures. Filippo Ricca, Massimiliano Di Penta, Marco Torchiano, Paolo Tonella, Mariano Ceccato, Corrado Aaron Visaggio |
ICSE | 6 |
| 2007 | Tuning anonymity level for assuring high data quality: an empirical studyabstractPreserving data privacy is posing new challenges to software engineering researchers. Current technologies can be too cumbersome, pervasive or costly to be successfully applied in dynamic and complex scenarios where data exchange occurs among a large number of applications. Anonymization techniques seem to be a promising candidate, even if preliminary investigations suggest that they could deteriorate the quality of data. An empirical study has been carried out in order to understand the relationship between the anonymization level and the degradation of data quality. Gerardo Canfora, Corrado Aaron Visaggio |
ESEM | 2 |
| 2007 | Building measure-based prediction models for UML class diagram maintainability
Marcela Genero, M. Esperanza Manso, Corrado Aaron Visaggio, Gerardo Canfora, Mario Piattini |
Empir. Softw. Eng. | 3 |
| 2007 | Evaluating performances of pair designing in industry
Gerardo Canfora, Aniello Cimitile, Félix García 0001, Mario Piattini, Corrado Aaron Visaggio |
J. Syst. Softw. | 5 |
| 2006 | Productivity of Test Driven Development: A Controlled Experiment with Professionals
Gerardo Canfora, Aniello Cimitile, Félix García 0001, Mario Piattini, Corrado Aaron Visaggio |
PROFES | 5 |
| 2006 | WECAP: A Web Environment for Project Planning
Lerina Aversano, Gerardo Canfora, Corrado Aaron Visaggio |
SEKE | 3 |
| 2006 | How Distribution Affects the Success of Pair ProgrammingabstractRecent experiments demonstrated the effectiveness of pair programming in terms of quality and productivity. Growing interest towards global software development is fostering the design of suitable methods and tools for distributing software processes, at any level of detail, from entire subprocesses up to a single activity. Consequently, people placed in different locations could also share programming tasks and related practices, such as pair programming. Unfortunately, distribution might seriously compromise the success of pair programming, due to communication and collaboration issues. We have performed an experiment in order to investigate the impact of distribution on pair programming when performing maintenance tasks. An interesting conjecture stems from the experiment: under certain conditions, distributed pair's components tend to dismiss from each other, stopping the collaborative work. This can be a very expensive risk factor to keep into account when planning tasks of distributed pair programming. Gerardo Canfora, Aniello Cimitile, Giuseppe A. Di Lucca, Corrado Aaron Visaggio |
Int. J. Softw. Eng. Knowl. Eng. | 4 |
| 2006 | FMESP: Framework for the modeling and evaluation of software processes
Félix García 0001, Mario Piattini, Francisco Ruiz 0001, Gerardo Canfora, Corrado Aaron Visaggio |
J. Syst. Archit. | 5 |
| 2006 | Applying a framework for the improvement of software process maturityabstractAbstract This article presents the results and lessons learned in the application of the Framework for the Modelling and Measurement of Software Processes (FMESP) in a software company dedicated to the development and maintenance of software for information systems. The aim of FMESP is to provide companies with a conceptual and technological framework for the management of their process models and measurement models in an integrated way. Modelling and measurement are two key factors to promote continuous process improvement. As a result, important benefits were obtained. The company improved the maturity of its processes which allowed it to obtain the ISO 9000 certification. From a research point of view, Action‐Research was successfully applied and as a result the framework was improved and important feedback was obtained, bringing to light new important issues which will be tacked in future work. Copyright © 2005 John Wiley & Sons, Ltd. Gerardo Canfora, Félix García 0001, Mario Piattini, Francisco Ruiz 0001, Corrado Aaron Visaggio |
Softw. Pract. Exp. | 5 |
| 2005 | Empirical validation of pair programmingabstractThis paper discusses an empirical assessment of pair programming. Corrado Aaron Visaggio |
ICSE | 1 |
| 2005 | Empirical Study on the Productivity of the Pair Programming
Gerardo Canfora, Aniello Cimitile, Corrado Aaron Visaggio |
XP | 3 |
| 2005 | A family of experiments to validate metrics for software process models
Gerardo Canfora, Félix García 0001, Mario Piattini, Francisco Ruiz 0001, Corrado Aaron Visaggio |
J. Syst. Softw. | 5 |
| 2005 | Pair designing as practice for enforcing and diffusing design knowledgeabstractEvolving software's design requires that the members of the team acquire a deep and complete knowledge of the domain, the architectural components, and their integration. Such information is scarcely addressed within the design documentation and it is not trivial to derive it. A strategy for enforcing the consciousness of such hidden aspects of software's design is needed. One of the expected benefits of pair programming is fostering (tacit) knowledge building between the components of the pair and fastening its diffusion within the project's team. We have applied the paradigm of pair programming to the design phase and we have named it ‘pair designing’. We have realized an experiment and a replica in order to understand if pair designing can be used as an effective means for diffusing and enforcing the design knowledge while evolving the system's design. The results suggest that pair designing could be a suitable means to disseminate and enforce design knowledge. Copyright © 2005 John Wiley & Sons, Ltd. Emilio Bellini, Gerardo Canfora, Félix García 0001, Mario Piattini, Corrado Aaron Visaggio |
J. Softw. Maintenance Res. Pract. | 5 |
| 2004 | Introducing Quality System in Small and Medium Enterprises: An Experience Report
Lerina Aversano, Gerardo Canfora, Giovanni Capasso, Giuseppe A. Di Lucca, Corrado Aaron Visaggio |
PROFES | 5 |
| 2002 | A Decision Model Supporting Cooperative Work as an Experience PackageabstractSubcontracting is one of the challenges modern software engineering must face. The need for decision models to guide software engineers in identifying when it is advisable and how to divide a contract, which risks it involves and which actions should be adopted to control them, is continuously increasing. Many researchers have proposed and experimented with these decision models from various viewpoints. We feel the need for a method able to merge and formalize these experiences in order for them to be reused by the entire community. This work presents an approach for formalizing such experience. It also proposes a decision model for dividing a contract according to its characteristics and to the cooperating organizations. This decision model, together with others present in the literature, have been integrated and formalized in an experience package. Maria Teresa Baldassarre, Danilo Caivano, Corrado Aaron Visaggio, Giuseppe Visaggio |
COMPSAC | 3 |
| 2002 | From Knowledge Management Concepts Toward Software Engineering Practices
Gerardo Canfora, Aniello Cimitile, Corrado Aaron Visaggio |
PROFES | 3 |