Andrea Monzani

dblp:406/7189 · DBLP profile ↗
← Back
3ranked-venue papers
1as first author
3since 2021 · last 2026
0009-0009-3301-5253ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2026 Unveiling BYOVD Threats: Malware's Use and Abuse of Kernel Drivers
Andrea Monzani, Antonio Parata, Andrea Oliveri, Simone Aonzo, Davide Balzarotti, Andrea Lanzi
NDSS1
2026 RemOTA: Remote attestation for detecting use-after-free in low-power microcontrollers
abstract
In this paper, we introduce RemOTA , a novel remote attestation protocol to capture dynamic memory allocations and uses in microcontroller embedded systems, enabling detection of use-after-free errors. RemOTA performs a precomputation analysis to identify a minimal set of key points in the control flow graph, called checkpoints, which serve as boundaries enclosing sequences of pointer operations that occur along the same execution path. These checkpoints allow the grouping of multiple pointer usages into larger, semantically meaningful units, enabling efficient and targeted instrumentation. This approach is particularly effective in resource-constrained environments, as it minimizes runtime overhead while offloading verification to a remote server. RemOTA incorporates a remote verifier that receives information from the executing firmware and replicates instructions to dynamically reconstruct pointer usage and emulate memory state, allowing lightweight use-after-free detection. Through the evaluation of real-world firmware on an STM32 microcontroller, RemOTA demonstrates high precision 100% with low overhead, geometric mean 4.47% on the tested dataset. Its scalability and efficiency make RemOTA a practical solution for securing resource-constrained embedded devices in production environments.
Matteo Zoia, Mirco Picca, Davide Rusconi, Andrea Monzani, Flavio Toffalini, Danilo Bruschi, Andrea Lanzi
Comput. Secur.4
2025 VS-TEE: A Framework for Virtualizing TEEs in ARM Cloud Contexts
abstract
Cloud computing processes and stores critical data, necessitating robust protections against unauthorized access. Confidential Computing (CC) technologies address this need by enabling secure computation in hardware-backed Trusted Execution Environments (TEEs). While solutions like AMD's Secure Encrypted Virtualization (SEV) provide strong protections, they remain vulnerable to attacks targeting applications within virtual machines (VMs). Similarly, the recent Armv9-A architecture introduces a promising Realm World for enhanced security, but its adoption is limited by hardware availability and upgrade constraints. ARM TrustZone, while widely supported, lacks native support for multiple isolated TEEs. In this paper we proposed framework eliminates the need for these components in the Trusted Computing Base (TCB), enabling secure integration of TEEs with VMs. It features a VS-TEE Driver for VM interaction and a VS-TEE Hypervisor for secure communication, ensuring compatibility with ARM TrustZone and OP-TEE libraries. We developed and evaluated an open-source prototype, demonstrating its effectiveness in addressing challenges like memory translation, resource management, and interoperability. Our framework enhances security for cloud environments, allowing multiple VMs to securely share TEE capabilities.
Matteo Zoia, Marco Cutecchia, Davide Rusconi, Andrea Monzani, Mirco Picca, Danilo Bruschi, Andrea Lanzi
CODASPY4