VLDB 2026 Research / reviewers in the wild / expert
Massimiliano Masi
dblp:44/7555
· DBLP profile ↗
5ranked-venue papers
1as first author
3since 2021 · last 2026
0000-0003-4737-7107ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Overcoming Standard Lock-in in C-ITS through Profile-Driven Governance
Tanja Pavleska, Massimiliano Masi, Giovanni Paolo Sellitto, Helder Aranha |
VEHITS | 2 |
| 2024 | A Threat Analysis of Cooperative Intelligent Transport Systems: C-Roads ScenariosabstractThe transition towards cooperative intelligent trans-port systems (C- ITS) requires coordinated efforts from all stakeholders. In this context, the European C- Roads project aims to deploy and harmonize C- ITS at a continental scale to facilitate interconnected and autonomous road networks, enabling efficient traffic management, improved road safety, and reduced emissions. This work provides a third-party point of view on the challenges posed by cyberattacks against these systems. It contextualizes and investigates threat models for C-Roads use cases, introducing key concepts, analyzing the inherent literature on threat modelling, and presenting application-specific scenarios. It discusses results and future directions, highlighting the importance of collaborative efforts from all the involved actors to shape the future of transportation. Gabriele Gatti, Marco Civera, Cataldo Basile, Massimiliano Masi, Michele La Manna |
COMPSAC | 4 |
| 2023 | Securing critical infrastructures with a cybersecurity digital twin
Massimiliano Masi, Giovanni Paolo Sellitto, Helder Aranha, Tanja Pavleska |
Softw. Syst. Model. | 1 |
| 2019 | Securing Mobile e-Health Environments by Design: A Holistic Architectural ApproachabstractEmploying wireless devices, like sensors and re-mote controllers, in medical workflows has become the norm in healthcare treatments, substantially increasing the quality of patient care. Medical data gathered and processed by the hardware and software components continuously traverses the existing IT infrastructures ranging from hospital datacenters to regional healthcare information exchanges. Recent regulations classify such IT infrastructures as critical, mandating precise and specific security requirements. The provision of security is thus not only a technical, but a legal requirement as well. Any vulnerability in a medical device may endanger the patients' privacy, and even their lives. The availability of security expertise, however, cannot be assumed as guaranteed throughout the whole life cycle of the medical devices, mainly due to the scarcity of security experts, among other things.We propose a holistic approach that addresses the challenge of scarce security expertise during the operational phases and is specially devised for mobile medical devices interconnected through healthcare IT infrastructures. Moreover, the model tackles security issues at design time, providing solution architectures that incorporate the security concerns. It combines well-established methodologies and reference models: the former used in the field of Industrial Internet of Things (IIoT) to build robust architectures, and the later employed to guarantee information assurance and security. Helder Aranha, Massimiliano Masi, Tanja Pavleska, Giovanni Paolo Sellitto |
WiMob | 2 |
| 2019 | A Rigorous Framework for Specification, Analysis and Enforcement of Access Control PoliciesabstractAccess control systems are widely used means for the protection of computing systems. They are defined in terms of access control policies regulating the access to system resources. In this paper, we introduce a formally-defined, fully-implemented framework for specification, analysis and enforcement of attribute-based access control policies. The framework rests on FACPL, a language with a compact, yet expressive, syntax for specification of real-world access control policies and with a rigorously defined denotational semantics. The framework enables the automated verification of properties regarding both the authorisations enforced by single policies and the relationships among multiple policies. Effectiveness and performance of the analysis rely on a semantic-preserving representation of FACPL policies in terms of SMT formulae and on the use of efficient SMT solvers. Our analysis approach explicitly addresses some crucial aspects of policy evaluation, such as missing attributes, erroneous values and obligations, which are instead overlooked in other proposals. The framework is supported by Java-based tools, among which an Eclipse-based IDE offering a tailored development and analysis environment for FACPL policies and a Java library for policy enforcement. We illustrate the framework and its formal ingredients by means of an e-Health case study, while its effectiveness is assessed by means of performance stress tests and experiments on a well-established benchmark. Andrea Margheri, Massimiliano Masi, Rosario Pugliese, Francesco Tiezzi 0001 |
IEEE Trans. Software Eng. | 2 |