Aniello Castiglione

dblp:46/295 · DBLP profile ↗
← Back
118ranked-venue papers
21as first author
31since 2021 · last 2026
0000-0003-0571-1074ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 37 · 5 first-author · 6 since 2021Security and privacy · 20 · 3 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 13 · 6 first-author · 10 since 2021Artificial intelligence and machine learning · 12 · 7 since 2021Computer networks · 10 · 3 first-author · 4 since 2021Databases, data management, data science and information retrieval · 7Graphics, computer vision, multimedia, augmented reality and games · 4 · 3 since 2021Human-computer interaction and ubiquitous computing · 4Software engineering, systems software and programming languages · 3 · 3 first-authorTheory of computation · 1
YearPublicationVenuePosition
2026 Speaker-attributed meeting transcription refinement with constrained open-weight language models
abstract
Speaker diarization and Automatic Speech Recognition (ASR) are traditionally evaluated as independent components. A particular use case, is practical meeting transcription that requires the seamless integration of accurate speaker segments and reliable speaker-attributed text. This paper presents a modular offline pipeline for speaker-attributed meeting transcription that integrates Pyannote for diarization, Whisper for ASR, and a constrained open-weight Large Language Model (LLM) for transcript refinement. The evaluation of the proposed solution is conducted using the AMI Meeting Corpus. We use a rigorous methodology that converts manual annotations into time-aligned speaker activity segments and reference transcripts. This enables a multi-dimensional performance analysis using standard metrics, including Diarization Error Rate (DER), Jaccard Error Rate (JER), Word Error Rate (WER), and concatenated minimum-permutation Word Error Rate (cpWER). The post-processing stage is formulated as a constrained correction task, where small, instruction-tuned models are deployed locally to ensure data privacy and eliminate reliance on proprietary APIs. These models are restricted to conservative corrections, specifically targeting speaker-attribution inconsistencies and repetitive ASR artifacts. Our experimental results demonstrate that while unconstrained LLM post-processing effectively reduces repetitions, it often compromises lexical fidelity. Conversely, our proposed conservative validation and acceptance filtering mechanism maintains WER and cpWER parity with the baseline while significantly mitigating transcript artifacts. Our findings suggest that local, open-weight LLMs are more effective as selective verification modules than as autonomous rewriters in high-fidelity transcription systems.
Costin-Alexandru Deonise, Taisia-Maria Coconu, Muhammad Khurram Zahur Bajwa, Catalin Negru, Bodgan-Costel Mocanu, Aniello Castiglione, Florin Pop
Future Gener. Comput. Syst.6
2026 Explainable AI for multimodal stress detection: interpreting model decisions across physiological, video and audio modalities
Andrea F. Abate, Carmen Bisogni, Aniello Castiglione, Maddalena Migliaccio
Multim. Tools Appl.3
2026 OpenV2X: A Modular Cyber-Physical Framework for Vision-Driven Environmental Perception and Interactive Feedback in Software-Defined Vehicles
abstract
The evolution of software-defined vehicles and intelligent transportation systems requires cyber-physical frameworks capable of integrating real-time perception, communication, and human interaction. In industrial automotive environments, enhancing situational awareness while maintaining system modularity, energy efficiency, and interpretability remains a critical challenge. This work presentsOpenV2X, a modular cyber-physical framework designed for real-time perception and human-in-the-loop feedback in software-defined vehicles. The primary goal is to provide a modular system for environment reconstruction, overcoming the limitations of closed industrial systems and research efforts focused on individual modules. OpenV2X combines onboard vision-based sensors with Message Queuing Telemetry Transport (MQTT)-enabled vehicle-to-everything (V2X) communication, extending environmental awareness beyond sensor line-of-sight and adhering to the principles of industrial informatics and resilient automation. Its architecture decouples object and lane detection modules, enabling dynamic model updates without system overhaul, and supports interactive feedback through a graphical interface, fostering end-user trust. Furthermore, the framework allows operation beyond simulated tests: the collected data can be sent to the original equipment manufacturer (OEM) to continuously improve software, achieving the main objective of the work. Experimental validation in real highway scenarios demonstrates 84.3% accuracy in orientation-aware object detection, 73% intersection-over-union for lane detection under adverse weather conditions, and submillisecond V2X latency with minimal energy overhead. Designed for embedded edge deployment, OpenV2X provides a reproducible open-source platform that integrates perception, communication, and user feedback in next-generation industrial vehicular systems.
Aniello Castiglione, Lucia Cimmino, Michele Nappi, Luigi Emanuele Sica
IEEE Trans. Ind. Informatics1
2025 Mel Spectrogram-Based CNN Framework for Explainable Audio Deepfake Detection
Muhammad Khurram Zahur Bajwa, Aniello Castiglione, Chiara Pero
AINA (8)2
2025 A speech denoising demonstration system using multi-model deep-learning neural networks
Ching-Ta Lu, Jun-Hong Shen, Aniello Castiglione, Cheng-Han Chung, Yen-Yu Lu
Multim. Tools Appl.3
2025 Integrating Post-Quantum Cryptography and Blockchain to Secure Low-Cost IoT Devices
abstract
In the contemporary era, the global proliferation of Internet of Things (IoT) devices exceeds 15 billion, serving functions from wearables to smart grid monitoring. These devices frequently manage sensitive data, underscoring the need for secure and reliable IoT networks leveraging blockchain technology. A key innovation of this study is an approach to mitigate vulnerabilities that quantum computing poses to blockchain-based IoT systems, which existing cryptographic methods cannot effectively address. Quantum computers could exploit these weaknesses to compromise key-pair generation and extract private keys from transaction signatures. To overcome this, the research introduces an optimized implementation of the post-quantum digital signature algorithm Dilithium-5, ensuring blockchain security and quantum readiness. These transaction signatures are designed for low-power, cost-effective microcontrollers, such as the ESP32, making the solution accessible for a wide range of IoT devices. In addition, the study includes a case study involving a post-quantum safe portable device for measuring blood oxygen levels and heart rate, illustrating the practical benefits and effectiveness of the proposed solution in enhancing IoT security against quantum threats. The results demonstrate that the proposed approach ensures quantum-resistant security while maintaining performance efficiency, making it suitable for real-world IoT applications.
Aniello Castiglione, Jacopo Gennaro Esposito, Vincenzo Loia, Michele Nappi, Chiara Pero, Matteo Polsinelli
IEEE Trans. Ind. Informatics1
2025 Enhancing trust of deep learning models with post-quantum digital signatures
abstract
Abstract High-performance computing (HPC) is crucial for artificial intelligence (AI) and deep learning (DL) but faces challenges related to scalability, data transfer costs, and security risks. Federated Learning (FL) enables collaborative model training without centralized data aggregation. However, FL introduces vulnerabilities, as exchanged models can be intercepted and manipulated, necessitating robust cryptographic protection. With the advent of quantum computing, traditional security mechanisms are at risk, requiring the adoption of Post-Quantum Cryptographic (PQC) algorithms. This study benchmarks three PQC digital signature algorithms: Falcon, SPHINCS+, and ML-DSA. Their execution time, memory usage, and computational efficiency are evaluated in a simulated FL setting. To extend the analysis, different cryptographic hash functions (SHA3-256, SHA3-512, and BLAKE3) are analyzed to assess hashing efficiency under varying computational loads. Both centralized and decentralized FL scenarios are simulated, incorporating PQC-based digital signatures at each phase of the communication pipeline to ensure model integrity and authenticity. The results provide insights into the trade-offs between security and computational overhead, guiding the selection of scalable cryptographic solutions for FL. Falcon and ML-DSA demonstrate minimal impact on computational performance, making them strong candidates for securing FL environments. Future research directions include the direct signing of DL models to enhance security and the integration of widely used FL libraries for more realistic evaluations. These advancements could improve the practical deployment of post-quantum security solutions in FL, ensuring resilience against emerging quantum threats.
Aniello Castiglione, Jacopo Gennaro Esposito, Vincenzo Loia, Michele Nappi, Chiara Pero, Matteo Polsinelli
J. Supercomput.1
2024 A Power Monitoring Framework of a Post-quantum Cryptography Web Server
Aniello Castiglione, Vincenzo Loia, Alberto Volpe
ICA3PP (5)1
2024 Efficient and precise visual location estimation by effective priority matching-based pose verification in edge-cloud collaborative IoT
Ning Li 0050, Xiaojun Ren, Aniello Castiglione
Future Gener. Comput. Syst.3
2024 CDT-CAD: Context-Aware Deformable Transformers for End-to-End Chest Abnormality Detection on X-Ray Images
abstract
Deep learning methods have achieved great success in medical image analysis domain. However, most of them suffer from slow convergency and high computing cost, which prevents their further widely usage in practical scenarios. Moreover, it has been proved that exploring and embedding context knowledge in deep network can significantly improve accuracy. To emphasize these tips, we present CDT-CAD, i.e., context-aware deformable transformers for end-to-end chest abnormality detection on X-Ray images. CDT-CAD firstly constructs an iterative context-aware feature extractor, which not only enlarges receptive fields to encode multi-scale context information via dilated context encoding blocks, but also captures unique and scalable feature variation patterns in wavelet frequency domain via frequency pooling blocks. Afterwards, a deformable transformer detector on the extracted context features is built to accurately classify disease categories and locate regions, where a small set of key points are sampled, thus leading the detector to focus on informative feature subspace and accelerate convergence speed. Through comparative experiments on Vinbig Chest and Chest Det 10 Datasets, CDT-CAD demonstrates its effectiveness in recognizing chest abnormities and outperforms 1.4% and 6.0% than the existing methods in$AP_{5}0$and$AR$on VinBig dateset, and 0.9% and 2.1% on Chest Det-10 dataset, respectively.
Yirui Wu, Qiran Kong, Lilai Zhang, Aniello Castiglione, Michele Nappi, Shaohua Wan 0001
IEEE Trans. Comput. Biol. Bioinform.4
2024 Backdoor Two-Stream Video Models on Federated Learning
abstract
Video models on federated learning (FL) enable continual learning of the involved models for video tasks on end-user devices while protecting the privacy of end-user data. As a result, the security issues on FL, e.g., the backdoor attacks on FL and their defense have increasingly become the domains of extensive research in recent years. The backdoor attacks on FL are a class of poisoning attacks, in which an attacker, as one of the training participants, submits poisoned parameters and thus injects the backdoor into the global model after aggregation. Existing backdoor attacks against videos based on FL only poison RGB frames, which makes it that the attack could be easily mitigated by two-stream model neutralization. Therefore, it is a big challenge to manipulate the most advanced two-stream video model with a high success rate by poisoning only a small proportion of training data in the framework of FL. In this paper, a new backdoor attack scheme incorporating the rich spatial and temporal structures of video data is proposed, which injects the backdoor triggers into both the optical flow and RGB frames of video data through multiple rounds of model aggregations. In addition, the adversarial attack is utilized on the RGB frames to further boost the robustness of the attacks. Extensive experiments on real-world datasets verify that our methods outperform the state-of-the-art backdoor attacks and show better performance in terms of stealthiness and persistence.
Jie Peng 0009, Weizhe Zhang, Jiangqun Ni, Arun Kumar Sangaiah, Aniello Castiglione
ACM Trans. Multim. Comput. Commun. Appl.8
2023 A Deep Learning-based Fast Fake News Detection Model for Cyber-Physical Social Services
Zhiwei Guo 0004, Yanyan Zhu, Pandi Vijayakumar, Aniello Castiglione, Brij B. Gupta
Pattern Recognit. Lett.5
2022 Dependable workflow management system for smart farms
abstract
Smart Farming is a new and emerging domain representing the application of modern technologies into agriculture, leading to a revolution of this classic domain. CLUeFARM is a web platform in the domain of smart farming which main purpose is to help farmers to easily manage and supervise their farms from any device connected to the Internet, offering some useful services. Cloud technologies evolved a lot in recent years and based on this growth, microservices are more and more used. If for the server side, the scalability and reusability are solved in high proportion by microservices, on the client side of web applications, there was no independent solution until the recent emergence of web components. They can be seen as the microservices of the front-end. Microservices and web components are usually used isolated one of each other. This paper proposes and presents the functionality and implementation of a dependable workflow management service by using an end-to-end microservices approach.
Catalin Negru, George-Alexandru Musat, Madalin Colezea, Constantin Anghel, Alexandru Dumitrascu, Florin Pop, Carmen De Maio, Aniello Castiglione
Connect. Sci.8
2022 Head pose estimation: An extensive survey on recent techniques and applications
Andrea F. Abate, Carmen Bisogni, Aniello Castiglione, Michele Nappi
Pattern Recognit.3
2022 Trustworthiness Evaluation-Based Routing Protocol for Incompletely Predictable Vehicular Ad Hoc Networks
abstract
Incompletely predictable vehicular ad hoc networks is a type of networks where vehicles move in a certain range or just in a particular tendency, which is very similar to some circumstances in reality. However, how to route in such type of networks more efficiently according to the node motion characteristics and related historical big data is still an open issue. In this paper, we propose a novel routing protocol named trustworthiness evaluation-based routing protocol (TERP). In our protocol, trustworthiness of each individual is calculated by the cloud depending on the attribute parameters uploaded by the corresponding vehicle. In addition, according to the trustworthiness provided by the cloud, vehicles in the network choose reliable forward nodes and complete the entire route. The analysis shows that our protocol can effectively improve the fairness of the trustworthiness judgement. In the simulation, our protocol has a good performance in terms of the packet delivery ratio, normalized routing overhead and average end-to-end delay.
Jian Shen 0001, Chen Wang 0015, Aniello Castiglione, Dengzhi Liu, Christian Esposito 0001
IEEE Trans. Big Data3
2022 Policy-Based Broadcast Access Authorization for Flexible Data Sharing in Clouds
abstract
Cloud storage services allow data owners to outsource their potentially sensitive data (e.g., private genome data) to remote cloud servers in a ciphertext form. To enable data owners to further share the data encrypted in ciphertexts, many proxy re-encryption (PRE) schemes are proposed. However, most schemes only support single-recipient or coarse-grained re-encryption, which may limit the flexibility for data sharing. To address this issue, we propose a Policy-based Broadcast Access Authorization (PBAA) scheme by introducing the well-established identity-based broadcast encryption (IBBE) and key-policy attribute-based encryption into PRE. In our PBAA scheme, a data owner can apply IBBE to encrypt his data to a group of recipients. More importantly, the data owner can generate a delegation key with an access policy, and send this key to the cloud such that it can convert any initial ciphertext satisfying the access policy into a new ciphertext for a new group of recipients. With these features, cloud users can share their remote data in a secure and flexible way. Security analysis and performance evaluation show that the PBAA scheme is secure and efficient, respectively.
Jixin Zhang, Zheng Qin 0001, Qianhong Wu, Hui Yin 0001, Aniello Castiglione
IEEE Trans. Dependable Secur. Comput.6
2022 Impact of Deep Learning Approaches on Facial Expression Recognition in Healthcare Industries
abstract
A facial expression recognition system that can provide quick assistance to the healthcare system and exceptional services to the patients is proposed in this article. The implementation of this work is divided into three components. In the first component, landmark points on the facial region are detected; a fixed-sized rectangular box is obtained by normalizing the detected face region, and then, down sampled to its varying sizes producing multiresolution images. Different convolution neural network architectures are proposed in the second component for analyzing the textual information within the multiresolution facial images. To extract more discriminating features and enhance the proposed system’s performance, some amalgamation of transfer learning, progressive image resizing, data augmentation, and fine tuning of parameters are employed in the third component. For experimental purposes, three benchmark databases, static facial expressions in the wild, Cohn-Kanade, and Karolinska directed emotional faces, are employed with some existing methods concerning these databases. The comparison with these databases shows the superiority of the proposed system.
Carmen Bisogni, Aniello Castiglione, Sanoar Hossain, Fabio Narducci, Saiyed Umer
IEEE Trans. Ind. Informatics2
2022 Guest Editorial: Biometrics in Industry 4.0: Open Challenges and Future Perspectives
Zhiwei Gao 0001, Aniello Castiglione, Michele Nappi
IEEE Trans. Ind. Informatics2
2022 An End-to-End Curriculum Learning Approach for Autonomous Driving Scenarios
abstract
In this work, we combine Curriculum Learning with Deep Reinforcement Learning to learn without any prior domain knowledge, an end-to-end competitive driving policy for the CARLA autonomous driving simulator. To our knowledge, we are the first to provide consistent results of our driving policy on all towns available in CARLA. Our approach divides the reinforcement learning phase into multiple stages of increasing difficulty, such that our agent is guided towards learning an increasingly better driving policy. The agent architecture comprises various neural networks that complements the main convolutional backbone, represented by a ShuffleNet V2. Further contributions are given by (i) the proposal of a novel value decomposition scheme for learning the value function in a stable way and (ii) an ad-hoc function for normalizing the growth in size of the gradients. We show both quantitative and qualitative results of the learned driving policy.
Luca Anzalone, Paola Barra, Silvio Barra, Aniello Castiglione, Michele Nappi
IEEE Trans. Intell. Transp. Syst.4
2021 Fostering secure cross-layer collaborative communications by means of covert channels in MEC environments
Aniello Castiglione, Michele Nappi, Fabio Narducci, Chiara Pero
Comput. Commun.1
2021 Vessel to shore data movement through the Internet of Floating Things: A microservice platform at the edge
abstract
Summary The rise of the Internet of Things has generated high expectations about the improvement in people's lifestyles. In the last decade, we saw several examples of instrumented cities where different types of data were gathered, processed, and made available to inspire the next generation of scientists and engineers. In this framework, sensors and actuators became leading actors of technologically pervasive urban environments. However, in coastal areas, marine data crowdsourcing is difficult to apply due to the challenging operational conditions, extremely unstable network connectivity, and security issues in data movement. To fill this gap, we present a novel version of our DYNAMO transfer protocol (DTP), a platform‐independent data mover framework where data collected on board of vessels are stored locally and then moved from the edge to the cloud when the operating conditions are favorable. We evaluate the performance of DTP in a controlled environment with a private cloud by measuring the time it takes for the clouds ide to process and store a fixed amount of data while varying the number of microservice instances. We show that the time decreases exponentially when the number of microservice instances goes from 1 to 16 and it remains constant above that number.
Diana Di Luccio, Sokol Kosta, Aniello Castiglione, Antonio Maratea, Raffaele Montella
Concurr. Comput. Pract. Exp.3
2021 OBPP: An ontology-based framework for privacy-preserving in IoT-based smart city
Mehdi Gheisari, Hamid Esmaeili Najafabadi, Jafar Ahmad Abed Alzubi, Jiechao Gao, Guojun Wang 0001, Aaqif Afzaal Abbasi, Aniello Castiglione
Future Gener. Comput. Syst.7
2021 A human-centered artificial intelligence approach for privacy protection of elderly App users in smart cities
Haroon Elahi, Aniello Castiglione, Guojun Wang 0001, Oana Geman
Neurocomputing2
2021 The Role of Internet of Things to Control the Outbreak of COVID-19 Pandemic
abstract
Currently, COVID-19 pandemic is the major cause of disease burden globally. So, there is a need for an urgent solution to fight against this pandemic. Internet of Things (IoT) has the ability of data transmission without human interaction. This technology enables devices to connect in the hospitals and other planned locations to combat this situation. This article provides a road map by highlighting the IoT applications that can help to control it. This study also proposes a real-time identification and monitoring of COVID-19 patients. The proposed framework consists of four components using the cloud architecture: 1) data collection of disease symptoms (using IoT-based devices); 2) health center or quarantine center (data collected using IoT devices); 3) data warehouse (analysis using machine learning models); and 4) health professionals (provide treatment). To predict the severity level of COVID-19 patients on the basis of IoT-based real-time data, we experimented with five machine learning models. The results reveal that random forest outperformed among all other models. IoT applications will help management, health professionals, and patients to investigate the symptoms of contagious disease and manage COVID-19 +ve patients worldwide.
Aniello Castiglione, Muhammad Umer 0001, Saima Sadiq, Mohammad S. Obaidat, Pandi Vijayakumar
IEEE Internet Things J.1
2021 Deep learning for emotion driven user experiences
Carmen Bisogni, Lucia Cascone, Aniello Castiglione, Ignazio Passero
Pattern Recognit. Lett.3
2021 User recognition based on periocular biometrics and touch dynamics
Andrea Casanova, Lucia Cascone, Aniello Castiglione, Weizhi Meng 0001, Chiara Pero
Pattern Recognit. Lett.3
2021 Introduction to the special issue on "Biometrics in Smart Cities: Techniques and Applications (BI_SCI)"
Michele Nappi, Silvio Barra, Aniello Castiglione, Fabio Narducci, Pandi Vijayakumar
Pattern Recognit. Lett.3
2021 Cognitive Analysis in Social Networks for Viral Marketing
abstract
Viral marketing is the modern version of the old “word-of-mouth” advertising, where companies choose a restricted number of persons, considered “influential,” recommending them products or services that will be in turn iteratively suggested. In this article, we propose cognitive models and algorithms for marketing applications through online social networks, considered as a graph database, and define the concept of influence graph leveraging particular user behavioral patterns, by querying the initial heterogeneous graph network. We also model the diffusion across the network, without any preliminary information, as a combinatorial multiarmed bandit problem, for the selection of most influential users. We have used the YELP social network as a case study for our approach, showing how it is possible to generate an influence graph considering several kinds of relevant paths (mainly considering reviews to the same firms) by which a user can influence other ones. Several experiments have been carried out and discussed, putting into evidence the effectiveness and efficacy of the proposed methods for influence maximization with respect to other approaches of state of the art.
Aniello Castiglione, Giovanni Cozzolino, Francesco Moscato 0001, Vincenzo Moscato
IEEE Trans. Ind. Informatics1
2021 Trustworthy Method for Person Identification in IIoT Environments by Means of Facial Dynamics
abstract
In industrial Internet of Things (IIoT) environments, dependability of a complex manufacturing process in which human operators play a key role can be improved by identity recognition/authentication of whoever is involved in various stages of a production process, according to where and when he/she is supposed to be. To this aim, we propose an approach that exploits the dynamic appearance and the time-dependent local features characterizing the face of an individual during speech utterance with regard to their spatial and temporal components. The proposed method models these dynamic facial patterns captured from edge Internet of Things devices by means of the Local Binary Pattern on Three Orthogonal Planes descriptor, which effectively extract both face's local features and movement at the fog level of the architecture. A deep feedforward network available in the cloud is trained and optimized to match the extracted features to a reference database. The achieved results highlight state-of-the-art performances of the proposed method with regard to robustness and trustworthiness of identification, especially for challenging IIoT scenarios.
Aniello Castiglione, Michele Nappi, Stefano Ricciardi
IEEE Trans. Ind. Informatics1
2021 COVID-19: Automatic Detection of the Novel Coronavirus Disease From CT Images Using an Optimized Convolutional Neural Network
abstract
It is widely known that a quick disclosure of the COVID-19 can help to reduce its spread dramatically. Transcriptase polymerase chain reaction could be a more useful, rapid, and trustworthy technique for the evaluation and classification of the COVID-19 disease. Currently, a computerized method for classifying computed tomography (CT) images of chests can be crucial for speeding up the detection while the COVID-19 epidemic is rapidly spreading. In this article, the authors have proposed an optimized convolutional neural network model (ADECO-CNN) to divide infected and not infected patients. Furthermore, the ADECO-CNN approach is compared with pretrained convolutional neural network (CNN)-based VGG19, GoogleNet, and ResNet models. Extensive analysis proved that the ADECO-CNN-optimized CNN model can classify CT images with 99.99% accuracy, 99.96% sensitivity, 99.92% precision, and 99.97% specificity.
Aniello Castiglione, Pandi Vijayakumar, Michele Nappi, Saima Sadiq, Muhammad Umer 0001
IEEE Trans. Ind. Informatics1
2021 Waiting for Tactile: Robotic and Virtual Experiences in the Fog
abstract
Social robots adopt an emotional touch to interact with users inducing and transmitting humanlike emotions. Natural interaction with humans needs to be in real time and well grounded on the full availability of information on the environment. These robots base their way of communicating on direct interaction (touch, listening, view), supported by a range of sensors on the surrounding environment that provide a radially central and partial knowledge on it. Over the past few years, social robots have been demonstrated to implement different features, going from biometric applications to the fusion of machine learning environmental information collected on the edge. This article aims at describing the experiences performed and still ongoing and characterizes a simulation environment developed for the social robot Pepper that aims to foresee the new scenarios and benefits that tactile connectivity will enable.
Lucia Cascone, Aniello Castiglione, Michele Nappi, Fabio Narducci, Ignazio Passero
ACM Trans. Internet Techn.2
2020 DELEX: a DEep Learning Emotive eXperience: Investigating empathic HCI
abstract
Recent advances in Machine Learning have unveiled interesting possibilities for real-time investigating about user characteristics and expressions like, but not limited to, age, sex, body posture, emotions and moods. These new opportunities lay the foundations for new HCI tools for interactive applications that adopt user emotions as a communication channel.
Andrea F. Abate, Aniello Castiglione, Michele Nappi, Ignazio Passero
AVI2
2020 Cognitive IoT system with intelligence techniques in sustainable computing environment
Arun Kumar Sangaiah, Jerline Sheebha Anni Dhanaraj, Prabu Mohandas, Aniello Castiglione
Comput. Commun.4
2020 A semantic-based methodology for digital forensics analysis
Flora Amato, Aniello Castiglione, Giovanni Cozzolino, Fabio Narducci
J. Parallel Distributed Comput.2
2020 Distributed Group Key Management for Event Notification Confidentiality Among Sensors
abstract
There is an increasing involvement of the Internet of Things (IoT) in many of our daily activities, with the aim of improving their efficiency and effectiveness. We are witnessing the advent of smart cities, in which IoT is exploited to improve the management of a city's assets, as well as smart factories, where IoT is paving the way for the forth industrial revolution. These applications and many other ones imply several non-functional requirements to be satisfied by the adopted IoT solution, where security assumes paramount importance. Secure communications among the IoT nodes are strongly needed due to the use of wireless technologies that are easy to eavesdrop, in order to steal valuable information. Accordingly, confidentiality is a fundamental prerequisite, but the existing solutions based on transport-level encryption are ineffective, while the ones with application-level encryption may be too expensive in terms of energy consumption. In this work, we propose a series of solutions and methods to achieve confidentiality with end-to-end guarantees, by using group-based keys within the context of a clustered and distributed key management framework. We have implemented such solutions on top of TinyOS, and assessed their achievable quality by means of the TOSSIM simulator.
Christian Esposito 0001, Massimo Ficco, Aniello Castiglione, Francesco Palmieri 0002, Alfredo De Santis
IEEE Trans. Dependable Secur. Comput.3
2020 Inter-Beam Interference Cancellation and Physical Layer Security Constraints by 3D Polarized Beamforming in Power Domain NOMA Systems
abstract
The application of BF techniques in power domain non-orthogonal multiple access (NOMA) schemes allows users to share the same single BF vector for operational reliability. The occurrence of inter-beam interference (IBI) is highly probable in a congested cell (i.e., a cell with high user density and active users). IBI cancellation by using 3D polarized BF in order to enhance the practicability of NOMA systems is the focus of this paper. An IBI cancellation scheme is proposed and evaluations of the spectrum efficiency according to the scenario congestion, as well as of the interference reduction by narrowing the generated beam to a desired beam-width, are presented. The security in the physical (PHY) layer in order to achieve confidential and authentic communication is also an important consideration. The proposed scheme checks the PHY layer security constraints on the number of users served per beam. In simulations, the robustness of the proposed scheme allows the average half power beam-width (HPBW) to be brought to about 20° for different steps in HPBW and for different user densities. Furthermore, depending on the user density, spectrum efficiency gains of approximately 4 bits/s/Hz and 9 bits/s/Hz are achieved by the described IBI cancellation scheme.
Xin Su 0002, Pascal Nkurunziza, Junrong Gu, Aniello Castiglione, Chang Choi
IEEE Trans. Sustain. Comput.4
2019 Forward to the special issue of the 9th International Symposium on Cyberspace Safety and Security (CSS 2017)
abstract
Fog computing, a paradigm that extends cloud computing and services to the edge of the network, meets enhanced requirements by locating data, computation power, and networking capabilities closer to end nodes. Fog computing is distinguished by its accessibility to end users, particularly its support for mobility. Fog nodes are geographically distributed and are deployed near wireless access points in areas with a significant usage. Fog devices may take the form of stand-alone servers or network devices with on-board computing capabilities. Services are hosted at the network edge or even within end-user devices, such as set-top boxes or access points. This reduces service latency, improves quality of service, and provides a superior experience for the user. Fog computing supports emerging Internet of Things (IoT) applications that demand real-time or predictable latency, such as industrial automation, transportation, and networks of sensors and actuators. Due to the capability to support a wide geographical distribution, fog computing is well positioned for real-time big data analytics. Fog supports densely distributed data collection points, adding a fourth axis to the often-mentioned big data dimensions (volume, variety, and velocity). Issues of security and privacy are in fog computing, but this remains understudied particularly in the design and implementation of fog computing; such solutions may not suit fog computing devices that are at the edges of networks. In such environments, fog computing devices face threats that do not arise in a well-managed cloud environment. The aim of this special issue in Concurrency and Computation Practice and Experience (CCPE) is to promote research and reflect the most recent advances of security and privacy issues in Fog computing. It includes invited, high-quality papers presented at the 9th International Symposium on Cyberspace Safety and Security (CSS 2017). This is also an open special issue where everyone is encouraged to submit papers. This special issue contains research papers addressing the state of the art technologies related to the security and privacy of fog computing. The set of accepted papers can be organised under the following key themes. Security has long been a critical but difficult problem to be addressed in the fog computing field. In this scheme, there are four high-quality papers accepted for publication in this special issue.1-4 First, Yu et al shared their survey work about services communication of Microservice-enabled Fog applications.1 Because a fog application based on Microservices architecture consists of numerous services and communication among services, they mainly focus on the security issues that arise in services communication of Microservices in four aspects: containers, data, permission, and network. Second, Zhao et al presented an IP geolocation method based on identification routers and local delay distribution similarity.2 IP geolocation is usually used in fog computing to avoid high latency and discriminate malicious requests by judging the location of users. Existing delay measurement-based IP geolocation approaches are not applicable to the network that has hierarchical topology and weak connectivity, and the precision of the classical Street-Level Geolocation (SLG) method will decrease dramatically when the common routers are anonymous. In this paper, the authors proposed an IP geolocation method based on identification routers and local delay distribution similarity to solve the IP geolocation problem in fog computing. Third, return-Oriented Programming (ROP) attacks become very popular in recent years as these attacks can bypass traditional defense mechanisms such as data execution prevention (DEP) effectively. Previous solutions suffer from limitations in that (1) some methods need to modify the target programs, (2) some methods introduce considerable performance cost, (3) some methods rely on the special hardware, and (4) most of existing methods could not provide an online protection for the target processes. In this paper, Tian et al presented OnRop, an on-the-fly ROP attack protection system by using the commodity hardware features and OS internal facilities.3 Their system is compatible with the existing programs, and its protection layer can be added on demand. Finally, Zhang et al proposed an algorithm to address the problems of latency in video denoising in fog computing environment. A series of measures has been applied in their algorithm, such as communication rate, and extremely heavy noise, structure registration, inter-frame and inner-frame filters, and distribution compensation. Privacy is another important issue in fog computing. In this scheme, there are also four accepted papers. First, Li et al proposed two practical approaches to implement a cloud-based DPI middlebox.5 The outsourced DPI middle-box performed payload inspection over encrypted traffic while preserving the privacy of both communication data and inspection rules. Second, Cao et al proposed an effective privacy-preserving scheme for electric load monitoring,6 which could guarantee differential privacy of data disclosure in smart grid. In the proposed scheme, an energy consumption behaviour model based on Factorial Hidden Markov Model (FHMM) is established. In addition, noise is added to the behaviour parameter, which is different from the traditional methods that usually add noise to the energy consumption data. Third, Zhou et al proposed effective methods to assist users to balance between the full control and the additional interaction burden,7 including sorting, recommendations, and establishing profiles. Finally, Zhang et al mainly focused on the privacy for Video Denoising.4 All these four papers have well introduced the latest research to the academia on addressing the privacy problem in fog computing. The next scheme is about the cryptography in fog computing. We accepted three papers for this scheme.8-10 First, Li et al proposed a verifiable chaotic encryption based on Chebyshev polynomials.8 The method supported verifiable function for data integrity. To further improve the efficiency of the method, a corresponding outsourced encryption method is constructed, where the heavy overhead evaluations of Chebyshev polynomials were transferred from the user side to the cloud server. The outsourced encryption also provided the checkability for data integrity and correctness of cloud computations. The method is suitable for mobile users with limited computing resources. Second, Bahrami et al proposed a novel hierarchical key pre-distribution method based on “Residual Design” for fog networks.9 The proposed key distribution method was designed to minimise storage overhead and memory consumption while increasing network scalability. The method was also designed to be secure against node capture attacks. Third, Wang et al proposed a new general pairing-free certificate-less signature method based on the variant of RSA problem and the discrete logarithm problem.10 As far as we know, this method was the first RSA-based certificate-less signature scheme that can possess resistance to Type I and Type II adversaries. There are also two papers that adopted blockchain techniques into Fog computing.11, 12 First, Huang et al proposed a new mechanism SeShare for data storing based on blockchain to realise signature uniqueness, which solved the problem of generating signatures for the same file meanwhile by different group users.11 Specifically, their method recorded every signature of a file in a blockchain in chronological order, and only one user was allowed to add new signature at the end of the blockchain when modification conflicts occurred. Second, Huang et al proposed a fair three-party contract signing protocol based on the primitive of blockchain, which could be applied to the scenario of fog computing.12 Their proposed construction allowed the participants to sign a contract in a fair way without the involvement of an arbitrator. Moreover, the privacy of the contract content could be preserved on the public chain. Their method also realised the proposed protocol through the private blockchain and provided the experimental simulation that analyses the efficiency and effectiveness. The articles presented in this special issue provides insights related to the security and privacy issues in fog computing, including blockchain-based techniques, cryptography, performance evaluation and improvements, and application developments. We wish the readers can benefit from insights of these papers, and contribute to these rapidly growing areas. Sheng Wen received his PhD degree from Deakin University, Melbourne, in October 2014. Currently, he has been working full-time as a senior lecturer (A/P in US) in Swinburne University of Technology. Before this, he first worked as a research fellow and then a Lecturer in Computer Science in the School of Information Technology at Deakin University from the year of 2015. Dr. Wen manages several research projects in the last three years. Since late 2014, Dr. Wen has received a large amount of funding from both academia and industries as co-/Chief Investigator (CI), including ARC Linkage Projects and CSRIO-Defence Joint Projects. Dr. Wen is now the Program Leader for System Security & Blockchain in Swinburne Cybersecurity Lab and Blockchain Innovation Lab. He is leading a medium-size research team in the system security area. This team includes Dr. Wen, eight Ph.D. students in Swinburne as co-/supervisors and three Honours students. Dr Wen has published over seventy fully-refereed papers in prestigious journals and leading conferences. He has also edited three books and seven journal special issues. In particular, Dr Wen has published forty fully refereed high-quality journal articles. Among these articles, fifteen articles are published in the most prestigious IEEE or ACM Transactions. Due to his outstanding performance in research, he was selected as the representative young scientist in Australia parliament (2015). Sheng is leading a blockchain project with Austrac to stop money laundering in Australia. The collaboration with Austrac is significant and has been reported in top blockchain related media like ‘Bitcoin’ website. He has also been selected as the cyber security expert in SBS channel to deliver security related knowledge and comment on security related event to the mass. His research impact not only contributes to his own academic reputation, but also promotes the reputation of Swinburne University in Australia. Aniello Castiglione received the Ph.D. degree in Computer Science from the University of Salerno, Italy. He is currently an Assistant Professor (tenured as Associate Professor) at the University of Naples “Parthenope,” Italy. Previously, he was Adjunct Professor at the University of Salerno, Italy, and at the University of Naples “Federico II.” He received the Italian national qualification as an Associate Professor of Computer Science. He published more than 210 papers in international journals and conferences. Considering his journal papers, more than 70 of them are ranked Q1 in Scopus/Scimago classification and more than 50 of them are ranked Q1 in the Clarivate Analytics/ISI-WoS classification. The international academic profile of Dr. Castiglione is spread among his 86 international co-authors who belong to 75 different institutions located in 18 countries. He served in the organization (mainly as the program chair and a TPC member) in around 230 international conferences (some of them are ranked A+/A/A- in the CORE, LiveSHINE, and Microsoft Academic international classifications). In 2014, one of his papers (published on the IEEE TDSC) has been selected as the Featured Article in the IEEE Cybersecurity Initiative. In 2018, another paper (published on the IEEE Cloud Computing) has been selected as the Featured Article in the IEEE Cloud Computing Initiative. He served as a reviewer for around 110 international journals and was the managing editor of two ISI-ranked international journals. He acted as a Guest Editor in around 20 special issues, including Future Generation Computer Systems (Elsevier), Information Sciences (Elsevier), Journal of Network and Computer Applications (Elsevier), Journal of Parallel and Distributed Computing (Elsevier), Computers & Security (Elsevier), Concurrency and Computation: Practice and Experience (Wiley), IEEE Communications Magazine, IEEE Access and served as an editor on around 10 editorial boards of international journals. His current research interests include Information Forensics, Digital Forensics, Security and Privacy on Cloud, Communication Networks, Applied Cryptography, and Sustainable Computing. Tian Wang received the B.Sc. and M.Sc. degrees in computer science from the Central South University, Changsha, China, in 2004 and 2007, respectively, and the Ph.D. degree in computer science from the City University of Hong Kong, Kowloon, Hong Kong, SAR, in 2011. He was a research assistant in the City University of Hong Kong from 2006-2008. He is currently an Associate Professor at the College of Computer Science and Technology, Huaqiao University, Xiamen, China. His research interests include wireless sensor networks, cloud computing, and fog computing. Dr. Wang manages several research projects such as the National Natural Science Foundation of China (NSFC). He has 2 patents and more than 70 technical publications in international conferences and journals in the areas of wireless sensor networks, cloud computing, and mobile computing. His papers have appeared in the prestigious journals/conferences in the domain, including IEEE TMC, IEEE TVT, ACM TOSN, Information Sciences, Computer networks, ACM Mobihoc, IEEE RTSS, IEEE MASS, IEEE ICC, and so on. He has served as publicity chair and program committee member of numerous international conferences. He serves as a publicity chair for IEEE DependSys 2016, session chair for SpaCCS 2016, track co-chair for IEEE CSS 2017, and program committee member of numerous international conferences (3PGCIC 2014, APSCC 2014, HPCC 2015, CoCoNet'15, ICA3PP 2015, WASA 2015, HPCC 2016, DependSys 2015, DependSys 2016). He is on the editorial board of International Journal of High-Performance Computing and Networking (IJHPCN). Md Zakirul Alam Bhuiyan is currently an Assistant Professor of Computer and Information Sciences at the Fordham University. Before that, he worked for Temple University USA. He also worked as a Postdoctoral Research Fellow in the School of Information Science and Engineering and the School of Software at Central South University, China. He received the Ph.D. degree and the MEng degree in Computer Science and Technology from Central South University (CSU), China, in 2013 and 2009, respectively. He received the BSc degree in Computer Science and Engineering from International Islamic University Chittagong, Bangladesh, in 2005. He is a key member of the Trusted Computing Institute of CSU, where his research interests lie in cyber-physical systems (CPS), wireless sensor network applications, fault-tolerance and reliability, and sensor-cloud computing. He was a Research Assistant at the Hong Kong Polytechnic University in 2010-2011 and a Software Engineer at international software companies. He was a recipient of a “Youth Scientific Fund 2015-2017” from NSF of China, “2012 Top-notch Ph.D. Student Award” from CSU, “2012 Hunan Province Innovative Engineering Research Fund Award,” and a recipient of the "Outstanding Master Degree Dissertation Award” at both the provincial and the university levels. His papers have appeared in the prestigious journals/conferences in the domain, including ACM TOSN, IEEE TC, IEEE TPDS, IEEE SECON, IEEE/IFIP DSN, IEEE SRDS, IEEE DCOSS, and so on. He won the “Best Paper Award” at the IEEE ISPA 2013, Melbourne, Australia, and the “Best Academic Paper Award 2012.” He was invited to serve as a Guest Editor, Workshop Chair, Publicity Chair, Program Co-Chair, TPC, and reviewer for international journal/conference proceedings. He is a member of IEEE and a member of ACM. We would like to thank all of the authors who provided valuable contributions to this special issue. We are also grateful to the Review Committee for the feedback provided to the authors, which are essential in further enhancing the papers. Finally, we would like to express our sincere gratitude to Professor Geoffrey Fox, the Editor in Chief, for providing us with this unique opportunity to present our works in the international journal of Concurrency and Computation: Practice and Experience.
Sheng Wen, Aniello Castiglione, Tian Wang 0001, Md. Zakirul Alam Bhuiyan
Concurr. Comput. Pract. Exp.2
2019 Foreword to the special issue on security, privacy, and social networks
abstract
Social computing and cloud computing are the major trends of technology development in recent years. With the unparalleled popularity, social networks and cloud platforms have become part of our daily lives. Users have produced big data that are beyond the ability of commonly used computer software and hardware tools to capture, manage, and process within a tolerable elapsed time. It has been widely recognized that security and privacy are the key challenges for social network and cloud services due to their scale, complexity, and heterogeneity. The goal of this special issue is to promote research on security, privacy, and social networks. Eleven papers were carefully selected from open submissions and invited from the best original presentations at the 13th International Conference on Information Security Practice and Experience (ISPEC 2017) and the Third International Symposium on Security and Privacy in Social Networks and Big Data (SocialSec 2017). These research papers address the state-of-the-art technologies related to security, privacy, and social networks. The papers are organized under the following topics: security and privacy in social network and web, big data and information security, hardware and software security, and network security. Social media has greater and greater influence on society in recent years. Hu et al1 present an interesting study on the influence of negative opinions spreading in social media during election period. Unlike existing approaches that rely on sentiment analysis and emotional words, the authors take advantage of nouns with emotional context to determine the election preference of each user more accurately. Protecting social networks from security threats and preserving user privacy are the key challenges in social network security. To protect social network users against cross-site scripting worms, Gupta et al2 propose a client-server JavaScript code rewriting-based framework. A Java-based prototype has been developed by the authors, and the authors test its malicious script alleviation capability on several web applications. Yang et al3 propose a novel privacy-preserving authentication protocol for anonymous web browsing, which help users avoid being monitored by the web server on the basis of the identity. In particular, the proposed protocol makes use of a pseudoidentity mechanism and an identity-based elliptic-curve cryptography algorithm. In the area of big data and cloud computing, secure nearest neighbor query over encrypted data is an important issue. Zhu et al4 put forward an efficient attack against the CloudBI-II scheme that is designed for resisting the collusion of cloud server and query users. Accordingly, the authors present an enhanced scheme that can resist the collusion attack. Outsourcing heavy computational tasks to cloud service providers has become popular in the cloud era. As commercial cloud service providers are not trusted, preserving the integrity of computational results becomes an important challenge. Yang et al5 propose a verifiable computation scheme that can protect the output privacy. Ciphertext-policy attribute-based encryption (CP-ABE) is widely used for data access control in cloud storage, which gives data owners direct and flexible control on access policies. Zhang et al6 present a multiauthority attribute-based encryption scheme with constant-size ciphertexts and user revocation for threshold access policy, which addresses the practical challenges in CP-ABE. The security and reliability of information transmission in vehicular ad hoc networks have attracted a lot of research efforts in recent years. Wang et al7 propose a neighborhood trustworthiness-based vehicle-to-vehicle authentication scheme, which uses cloud computing to evaluate the trustworthiness of vehicles for emergent information delivery. The security of ARM embedded devices is important as they are becoming increasingly ubiquitous. Chang et al8 propose a hardware-assisted memory isolation protection mechanism using the B method, and present an implementation of the proposed system on an ARM-based platform. Function-call graph matching is useful in binary code analysis for software security purposes. Huang et al9 propose a function-call graph matching method based on the Hungarian algorithm. The proposed method solves the maximum weight matching problem in polynomial time, which allows matching between graphs of large scale. This special issue would not be complete without covering network security. Yang et al10 use software-defined network techniques to build a moving target defense model that maps physical network elements to a considerably large address space and creates different times of validity randomly to generate mapping addresses. The proposed model helps make it more difficult for attackers to find the targets in a network. Shan et al11 propose a node importance scheme to a community-based caching scheme with network coding for information centric networking. Experimental results indicate that the proposed scheme can improve network performance including average download time, cache hit rate, and instantaneous hop reduction rate. The articles presented in this special issue report recent advances in some areas of security, privacy, and social networks, including security and privacy in social network and web, big data and information security, hardware and software security, and network security. We hope the readers can benefit from the insights of these works and make further contributions to these important and rapidly growing fields. We are grateful to the authors who submitted papers to this special issue. We would also like to thank the reviewers for their hard work and their valuable feedback to the authors. Finally, we would like to express our sincere gratitude to Professor Geoffrey Fox, the Editor in Chief, for providing the opportunity and assistance to edit this special issue in the international journal of Concurrency and Computation: Practice and Experience.
Yang Xiang 0001, Md. Zakirul Alam Bhuiyan, Aniello Castiglione, Yu Wang 0017
Concurr. Comput. Pract. Exp.3
2019 Biometric data on the edge for secure, smart and user tailored access to cloud services
Silvio Barra, Aniello Castiglione, Fabio Narducci, Maria De Marsico, Michele Nappi
Future Gener. Comput. Syst.2
2019 Distributed temporal link prediction algorithm based on label propagation
Xiaolong Xu 0002, Marcello Trovati, Francesco Palmieri 0002, Georgios Kontonatsios, Aniello Castiglione
Future Gener. Comput. Syst.7
2019 On Data Sovereignty in Cloud-Based Computation Offloading for Smart Cities Applications
abstract
Smart city applications are increasingly popular due to their potential to improve quality of life in an urbanized society, and such applications typically leverage on cloud computing for data and computation offloading from the sensing infrastructure. Despite the capability of achieving scalability and flexibility, the use of cloud computing imposes inherent security and privacy concerns regarding data analysis and exchange, as well as legal implications. For example, data in a smart city application being outsourced to the cloud and/or exchanged among sensing devices may be accessible to users located in a different jurisdiction or subsequently reside in a data center in a different jurisdiction. There may be conflicting privacy protection and disclosure laws among these jurisdictions/locations; thus, limiting the widespread adoption of smart city applications. Restricting the data flow for such applications is not viable since it may cause inefficiencies, although there are situations requiring to limit the data access to selected geographical locations. Therefore, we propose addressing this issue by using a location-dependent cryptographic approach, and we integrate such an approach within the context of cloud-based smart city applications.
Christian Esposito 0001, Aniello Castiglione, Flavio Frattini, Marcello Cinque, Yanjiang Yang, Kim-Kwang Raymond Choo
IEEE Internet Things J.2
2019 Fine-grained information flow control using attributes
Jinguang Han, Liqun Chen 0002, Willy Susilo, Xinyi Huang 0001, Aniello Castiglione, Kaitai Liang
Inf. Sci.5
2019 Data fusion technique in SPIDER Peer-to-Peer networks in smart cities for security enhancements
Bogdan-Costel Mocanu, Florin Pop, Alexandra Mihaita Mocanu, Ciprian Dobre, Aniello Castiglione
Inf. Sci.5
2019 CSP-E2: An abuse-free contract signing protocol with low-storage TTP for energy-efficient electronic transaction ecosystems
Guangquan Xu, Yao Zhang 0019, Arun Kumar Sangaiah, Xiaohong Li 0001, Aniello Castiglione, James Xi Zheng
Inf. Sci.5
2019 New publicly verifiable computation for batch matrix multiplication
Xiaoyu Zhang 0010, Tao Jiang 0017, Kuanching Li, Aniello Castiglione, Xiaofeng Chen 0001
Inf. Sci.4
2019 PhysioUnicaDB: a dataset of EEG and ECG simultaneously acquired
Silvio Barra, Matteo Fraschini, Andrea Casanova, Aniello Castiglione, Gianni Fenu
Pattern Recognit. Lett.4
2019 CNN-based anti-spoofing two-tier multi-factor authentication system
Salman Khan 0004, Tanveer Hussain 0001, Khan Muhammad 0001, Arun Kumar Sangaiah, Aniello Castiglione, Christian Esposito 0001, Sung Wook Baik
Pattern Recognit. Lett.6
2019 A Novel Methodology to Acquire Live Big Data Evidence from the Cloud
abstract
In the last decade Digital Forensics has experienced several issues when dealing with network evidence. Collecting network evidence is difficult due to its volatility. In fact, such information may change overtime, may be stored on a server out jurisdiction or geographically far from the crime scene. On the other hand, the explosion of the Cloud Computing as the implementation of the Software as a Service (SaaS) paradigm is pushing users toward remote data repositories such as Dropbox, Amazon Cloud Drive, Apple iCloud, Google Drive, Microsoft OneDrive. In this paper is proposed a novel methodology for the collection of network evidence. In particular, it is focused on the collection of information from online services, such as web pages, chats, documents, photos and videos. The methodology is suitable for both expert and non-expert analysts as it “drives” the user through the whole acquisition process. During the acquisition, the information received from the remote source is automatically collected. It includes not only network packets, but also any information produced by the client upon its interpretation (such as video and audio output). A trusted-third-party, acting as a digital notary, is introduced in order to certify both the acquired evidence (i.e., the information obtained from the remote service) and the acquisition process (i.e., all the activities performed by the analysts to retrieve it). A proof-of-concept prototype, called LINEA, has been implemented to perform an experimental evaluation of the methodology.
Aniello Castiglione, Giuseppe Cattaneo, Giancarlo De Maio, Alfredo De Santis, Gianluca Roscigno
IEEE Trans. Big Data1
2019 Memory-Efficient Implementation of Elliptic Curve Cryptography for the Internet-of-Things
abstract
In this paper, we present memory-efficient and scalable implementations of NIST standardized elliptic curves P-256, P-384 and P-521 on three ARMv6-M processors (i.e. Cortex-M0, M0+, and M1). Specifically, we propose a refined approach to perform the Multiply-ACcumulate (MAC) operation using hardware multiplier provided by ARMv6-M processor, and a compact doubling routine for multi-precision squaring that executes both doubling and partial product operations in an efficient way. We demonstrate that the proposed squaring implementation achieves a speed up of 28 percent compared to the same operation employed in Micro-ECC. Then, we reduce one modular reduction in co-Z conjugate point addition by using lazy reduction and special form representation (CD-AB, EF-AB), which further reduces the execution time of both P-256 and P-384 implementations. Finally, we propose scalable implementations of ECC scalar multiplication on ARMv6-M processors that are widely used for Internet of Things applications.
Zhe Liu 0001, Hwajeong Seo, Aniello Castiglione, Kim-Kwang Raymond Choo, Howon Kim 0001
IEEE Trans. Dependable Secur. Comput.3
2018 Walking on the Cloud: Gait Recognition, a Wearable Solution
Aniello Castiglione, Kim-Kwang Raymond Choo, Maria De Marsico, Alessio Mecca
NSS1
2018 Creating and Managing Realism in the Next-Generation Cyber Range
Dragos-George Ionica, Florin Pop, Aniello Castiglione
NSS3
2018 Recognizing human behaviours in online social networks
Flora Amato, Aniello Castiglione, Aniello De Santo, Vincenzo Moscato, Antonio Picariello, Fabio Persia, Giancarlo Sperlì
Comput. Secur.2
2018 Editorial: Security and privacy protection vs sustainable development
Elisa Bertino, Valentina Casola, Aniello Castiglione, Willy Susilo
Comput. Secur.3
2018 On the protection of consumer genomic data in the Internet of Living Things
Raffaele Pizzolante, Arcangelo Castiglione, Bruno Carpentieri, Alfredo De Santis, Francesco Palmieri 0002, Aniello Castiglione
Comput. Secur.6
2018 Information theoretic-based detection and removal of slander and/or false-praise attacks for robust trust management with Dempster-Shafer combination of linguistic fuzzy terms
abstract
Summary Critical systems are progressively abandoning the traditional isolated and closed architectures, and adopting more federated solutions, in order to deal with orchestrated decision making within large‐scale infrastructures. Such an increasing connectivity and the possibility of dynamically integrate constituents in a seamless manner by means of a decoupling middleware solution are causing the flouring of novel and previously unseen security threats, such as internal attacks conducted by camouflaged and/or compromised federated systems. Trust management is the most efficient way for dealing with such attacks, so that each constituent computes a trust degree of the other interacting ones based on the direct experiences and of collected reputation scores. An adversary may negatively affect the overall process with false reputations, which must not be considered when estimating a trust degree. Our work combines a multi‐criteria linguistic fuzzy term formulation of the trust degree with the concept of entropy for measuring the divergence of certain scores from the other ones and to avoid to consider them during reputation aggregation. A set of experiments have been conducted in order to measure the quality and effectiveness of the presented approach.
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002
Concurr. Comput. Pract. Exp.2
2018 Multimedia story creation on social networks
Flora Amato, Aniello Castiglione, Fabio Mercorio, Mario Mezzanzanica, Vincenzo Moscato, Antonio Picariello, Giancarlo Sperlì
Future Gener. Comput. Syst.2
2018 CHIS: A big data infrastructure to manage digital cultural items
Aniello Castiglione, Francesco Colace, Vincenzo Moscato, Francesco Palmieri 0002
Future Gener. Comput. Syst.1
2018 A coral-reefs and Game Theory-based approach for optimizing elastic cloud resource allocation
Massimo Ficco, Christian Esposito 0001, Francesco Palmieri 0002, Aniello Castiglione
Future Gener. Comput. Syst.4
2018 Controlling and filtering users data in Intelligent Transportation System
Catalin Gosman, Tudor Cornea, Ciprian Dobre, Florin Pop, Aniello Castiglione
Future Gener. Comput. Syst.5
2018 Power domain NOMA to support group communication in public safety networks
Xin Su 0002, Aniello Castiglione, Christian Esposito 0001, Chang Choi
Future Gener. Comput. Syst.2
2018 Multi-layer cloud architectural model and ontology-based security service framework for IoT-based smart homes
Jinglong Zuo, Zhusong Liu, Aniello Castiglione, Francesco Palmieri 0002
Future Gener. Comput. Syst.4
2018 Recent advances in security and privacy in Social Big Data
Jun Zhang 0010, Aniello Castiglione, Laurence T. Yang, Yan Zhang 0002
Future Gener. Comput. Syst.2
2018 Loss-Tolerant Event Communications Within Industrial Internet of Things by Leveraging on Game Theoretic Intelligence
abstract
Internet of Things (IoT) is one of the key technologies paving the way for the next industrial revolution named as Industry 4.0, since it promises to realize smarter factories by optimizing costs and productivity. Traditionally, the adopted communication protocols among the sensors are required to manage the large scale of the infrastructure in terms on the high number of interconnected nodes and the massive volume of exchanged data. However, due to the key role of those Industrial IoT in exchanging business critical data, such protocols need to also provide high resiliency guarantees to the message exchange, with as few delivery misses as possible. The publish/subscribe interaction pattern and the protocol implementing it are a technically sound approach for achieving scalability and elasticity, thanks to their intrinsic decoupling among the interacting nodes. However, they are often unsuitable in their current form, because they provide only best-effort delivery guarantees, or they adopt naive solutions to achieve resilient communication, especially when wireless networks are used. This paper presents a clustered lightweight gossiping algorithm for resilient event based communications among the sensors, without requiring a pre-deployed brokering infrastructure supporting the adopted publish/subscribe protocol. A simulation-based assessment has been performed in order to empirically show the improvements in terms of successfully delivered notification without the excessive costs of the state-of-the-art solutions available in the literature.
Christian Esposito 0001, Massimo Ficco, Aniello Castiglione, Francesco Palmieri 0002, Huimin Lu 0001
IEEE Internet Things J.3
2018 Computational Intelligence and its Applications in New Computing Models
Jin Li 0002, Aniello Castiglione
Inf. Sci.2
2018 Special issue on security in cloud computing
Jin Li 0002, Aniello Castiglione, Changyu Dong
J. Netw. Comput. Appl.2
2018 Event-based sensor data exchange and fusion in the Internet of Things environments
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002, Massimo Ficco, Ciprian Dobre, George V. Iordache, Florin Pop
J. Parallel Distributed Comput.2
2018 Advanced services for efficient management of smart farms
George-Alexandru Musat, Madalin Colezea, Florin Pop, Catalin Negru, Mariana Mocanu, Christian Esposito 0001, Aniello Castiglione
J. Parallel Distributed Comput.7
2018 Multimedia summarization using social media content
Flora Amato, Aniello Castiglione, Vincenzo Moscato, Antonio Picariello, Giancarlo Sperlì
Multim. Tools Appl.2
2018 Using Screen Brightness to Improve Security in Mobile Social Network Access
abstract
In the today's mobile communications scenario, smartphones offer new capabilities to develop sophisticated applications that seem to make daily life easier and more convenient for users. Such applications, which may involve mobile ticketing, identification, access control operations, etc., are often accessible through social network aggregators, that assume a fundamental role in the federated identity management space. While this makes modern smartphones very powerful devices, it also makes them very attractive targets for spyware injection. This kind of malware is able to bypass classic authentication measures and steal user credentials even when a secure element is used, and can, therefore, perform unauthorized mobile access to social network services without the user's consent. Such an event allows stealing sensitive information or even a full identity theft. In this work, we address this issue by introducing BrightPass, a novel authentication mechanism based on screen brightness. BrightPass allows users to authenticate safely with a PIN-based confirmation in the presence of specific operations on sensitive data. We compare BrightPass with existing schemes, in order to show its usability and security within the social network arena. Furthermore, we empirically assess the security of BrightPass through experimentation. Our tests indicate that BrightPass protects the PIN code against automatic submissions carried out by malware while granting fast authentication phases and reduced error rates.
Meriem Guerar, Mauro Migliardi, Alessio Merlo, Mohamed Benmohammed, Francesco Palmieri 0002, Aniello Castiglione
IEEE Trans. Dependable Secur. Comput.6
2018 Integrity for an Event Notification Within the Industrial Internet of Things by Using Group Signatures
abstract
In the last years, several academic research efforts have focused on security requirements, threat models, and attack taxonomies concerning the application of the Internet of Things (IoT) in critical systems. Since such systems are strongly data intensive, it is of pivotal importance to provide integrity for the messages moving throughout the IoT infrastructure by means of publish/subscribe services. Integrity provisioning in industrial IoT scenarios has received marginal attention with respect to other primary security features. The existing solutions are lacking the needed focus on the peculiarities of the event notification and on the demand introduced by resource-constrained devices. This work contributes by applying group signatures so as to avoid managing certificates, violating the spatial decoupling, or implying an excessive resource usage. A proof-of-concept prototype of the proposed solution has been realized for platforms based on TinyOS, and simulations with TOSSIM have been conducted in order to empirically assess its performance and effectiveness.
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002, Alfredo De Santis
IEEE Trans. Ind. Informatics2
2017 Flaw Recovery in Cloud Based Bio-inspired Peer-to-Peer Systems for Smart Cities
Bogdan-Costel Mocanu, Florin Pop, Alexandra Mihaita Mocanu, Ciprian Dobre, Valentin Cristea, Aniello Castiglione
GPC6
2017 Efficient k-NN query over encrypted data in cloud with limited key-disclosure and offline data owner
Youwen Zhu, Aniello Castiglione
Comput. Secur.3
2017 A secure and resilient cross-domain SIP solution for MANETs using dynamic clustering and joint spatial and temporal redundancy
abstract
Summary In this paper, we extend our earlier work (where we presented a cross‐domain Session Initiation Protocol solution for mobile ad hoc networks using dynamic clustering) to handle packet losses affecting wireless networks and deal with outbound requests using reputation method. The (extended) solution is designed also to avoid the inherent shortcomings associated with centralized approaches (e.g. single point of failure). Using simulations, we evaluate the extended solution under different conditions. Findings from the evaluations demonstrate the utility of our solution. Copyright © 2016 John Wiley & Sons, Ltd.
Ala' F. A. Aburumman, Wei Jye Seo, Christian Esposito 0001, Aniello Castiglione, Md. Rafiqul Islam 0001, Kim-Kwang Raymond Choo
Concurr. Comput. Pract. Exp.4
2017 A collaborative clinical analysis service based on theory of evidence, fuzzy linguistic sets and prospect theory and its application to craniofacial disorders in infants
Arcangelo Castiglione, Raffaele Pizzolante, Christian Esposito 0001, Alfredo De Santis, Francesco Palmieri 0002, Aniello Castiglione
Future Gener. Comput. Syst.6
2017 Improving the gossiping effectiveness with distributed strategic learning (Invited paper)
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002, Massimo Ficco
Future Gener. Comput. Syst.2
2017 Trust management for distributed heterogeneous systems by using linguistic term sets and hierarchies, aggregation operators and mechanism design
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002, Massimo Ficco
Future Gener. Comput. Syst.2
2017 Supporting dynamic updates in storage clouds with the Akl-Taylor scheme
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Xinyi Huang 0001, Aniello Castiglione
Inf. Sci.6
2017 Layered multicast for reliable event notification over large-scale networks
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002
Inf. Sci.2
2017 On-Board Format-Independent Security of Functional Magnetic Resonance Images
abstract
Functional magnetic resonance imaging (fMRI) provides an effective and noninvasive tool for researchers to understand cerebral functions and correlate them with brain activities. In addition, with the ever-increasing diffusion of the Internet, such images may be exchanged in several ways, allowing new research and medical services. On the other hand, ensuring the security of exchanged fMRI data becomes a main concern due to their special characteristics arising from strict ethics and legislative and diagnostic implications. Again, the risks increase when dealing with open environments like the Internet. For this reason, security mechanisms that ensure protection of such data are strongly required. However, we remark that the mechanisms commonly employed for data protection are doomed to fail when dealing with imaging data. In this article, we propose a novel watermarking scheme explicitly addressed for this type of imaging. Such a scheme can be used for several purposes, particularly to ensure authenticity and integrity. Moreover, we show how to integrate our scheme within commercial off-the-shelf fMRI system. Finally, the validity and the efficiency of our scheme has been assessed through testing.
Arcangelo Castiglione, Raffaele Pizzolante, Francesco Palmieri 0002, Barbara Masucci, Bruno Carpentieri, Alfredo De Santis, Aniello Castiglione
ACM Trans. Embed. Comput. Syst.7
2017 Exploiting Battery-Drain Vulnerabilities in Mobile Smart Devices
abstract
Differently from attacks aimed at gaining control of the resources of a mobile device, energy-related attacks have the essential goal of significantly raising the energy demand on the victim side, without apparently affecting its activities. It is a fundamental point to highlight how such a goal can possibly be accomplished by mounting well-known canonical attacks and waiting for the system defenses to detect and stop them. In such an endeavor, defenses require additional amounts of energy which eventually render the mobile device completely useless. In the System on Chip (SoC) architecture, many components, each with a separate function, are integrated. As the total energy adsorption is the composition of the energy consumptions of individual components, each component may be the target of an energy-based attack. This work analyzes and discusses the effects and implication of new energy-based Denial of Service attacks based on the proper solicitation of hardware-layer encode/decode capabilities by using specifically crafted multimedia resources, in order to introduce an anomalous battery drain, and hence significantly shorten the overall battery lifetime in mobile smart devices. These attacks do not require physical access nor compromise of the target device, and they take advantage of new HTML5 functionalities that can be properly triggered during normal browsing activity. The more significant result is that the Digital Signal Processor (DSP) offers an exploitable attack surface to be kept into consideration early in the design process. Countermeasures include special filtering rules that prevent “irrelevant” content from reaching the DSP or, in a more far-reached perspective, the introduction of a power-draw controller on the SoC with the purpose of monitoring energy consumption and raising alerts.
Ugo Fiore, Aniello Castiglione, Alfredo De Santis, Francesco Palmieri 0002
IEEE Trans. Sustain. Comput.2
2016 On the Relations Between Security Notions in Hierarchical Key Assignment Schemes for Dynamic Structures
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Aniello Castiglione
ACISP (2)5
2016 Putting the User in Control of the Intelligent Transportation System
Catalin Gosman, Tudor Cornea, Ciprian Dobre, Florin Pop, Aniello Castiglione
ACISP (1)5
2016 An HLA-based framework for simulation of large-scale critical systems
abstract
Summary Evaluating the dependability of large‐scale critical infrastructures is a very difficult task that requires sophisticated modeling practices and experimentation environments/infrastructures. In particular, simulation of complex distributed systems require the integration of several different simulation tools and real‐time prototypes or emulated subsystems, which have to inter‐operate in a coordinated way. This paper presents a framework integrating simulation and emulation‐based subsystems, which is able to provide greater realism of the scenario under test. However, integrating simulation and emulation is a challenging issue because of the different time domains and to the communication overhead between the different time models, as well as to the large number of involved entities. Therefore, the high level architecture has been used to perform integration in a robust and standardized scenario. A cloud‐based virtualization platform has been adopted in order to reproduce complex system architectures on an elastic and adaptive locally controlled testbed. Copyright © 2015 John Wiley & Sons, Ltd.
Massimo Ficco, Giovanni Avolio, Francesco Palmieri 0002, Aniello Castiglione
Concurr. Comput. Pract. Exp.4
2016 GRASP-based resource re-optimization for effective big data access in federated clouds
Francesco Palmieri 0002, Ugo Fiore, Sergio Ricciardi, Aniello Castiglione
Future Gener. Comput. Syst.4
2016 A secure payment system for multimedia on demand on mobile VANET clouds
abstract
Abstract The more recent advances in network communication and cloud computing technologies have the potential of significantly improving traveling experience by providing value‐added services, such as multimedia on demand (MoD), in vehicular ad hoc networks, where the involved vehicles are provided with enough communication, storage, and computing capabilities. In this scenario, despite many consolidated mobile cloud solutions and pay‐per‐view systems have been developed and widely deployed in public transportation, the security and privacy of mobile users, mainly concerning the association between users' identities and requested multimedia contents, still presents several open challenges. Mainly, providing pay‐per‐view services in vehicular clouds while protecting the passenger's anonymity and simultaneously ensuring the robustness of the payment system has become an important issue.Accordingly, we present a novel smart card‐based MoD payment solution, to be used in mobile cloud‐empowered public transportation systems, that not only guarantees the passenger's anonymity but also uses a personal trusted device to protect the passenger's sensitive information so that he can enjoy the multimedia contents during the long hours of travel. In the future, such scheme can become common practice on MoD‐related equipment in vehicular ad hoc networks, thereby enhancing the competitiveness of public transport companies. Copyright © 2016 John Wiley & Sons, Ltd.
Chin-Ling Chen, Yu-Fan Lin, Aniello Castiglione, Francesco Palmieri 0002
Secur. Commun. Networks3
2016 Human continuous activity recognition based on energy-efficient schemes considering cloud security technology
abstract
Smartphone is broadly applicable to the human activity recognition HAR mobile devices. However, energy consumption becomes a big obstacle to such mobile devices of real-time monitoring. In order to solve this problem, this paper presents a method of activity recognition based on energy-efficient schemes. In terms of data acquisition and processing, energy-efficient schemes adopt the best sample rate and extract the most effective feature combinations in accordance with the different activities, so as not to increase energy consumption; while in terms of recognition algorithm, we adopt the improved structure of multi-class support vector machine, combine it with the probability of activity occurrence, so as to reduce the time complexity of recognition. This method can minimize energy consumption greatly under the premise of maintaining higher recognition accuracy. Moreover, this paper adopts mobile cloud security technology to reduce potential risk of the smartphone's data transmission and processing. We present our work with an experimental study, and our experiments show that the accuracy of activity recognition based on energy-efficient schemes we proposed is up to 90.6%. In addition, this method will save 51.0% energy than that when sample rate and extracted features are, respectively, fixed at 100Hz and combined features. Copyright © 2016 John Wiley & Sons, Ltd.
Zhide Chen, Jiyun Wu, Aniello Castiglione, Wei Wu 0001
Secur. Commun. Networks3
2016 Smart Cloud Storage Service Selection Based on Fuzzy Logic, Theory of Evidence and Game Theory
abstract
Cloud platforms encompass a large number of storage services that can be used to manage the needs of customers. Each of these services, offered by a different provider, is characterized by specific features, limitations and prices. In presence of multiple options, it is crucial to select the best solution fitting the customer requirements in terms of quality of service and costs. Most of the available approaches are not able to handle uncertainty in the expression of subjective preferences from customers, and can result in wrong (or sub-optimal) service selections in presence of rational/selfish providers, exposing untrustworthy indications concerning the quality of service levels and prices associated to their offers. In addition, due to its multi-objective nature, the optimal service selection process results in a very complex task to be managed, when possible, in a distributed way, for well-known scalability reasons. In this work, we aim at facing the above challenges by proposing three novel contributions. The fuzzy sets theory is used to express vagueness in the subjective preferences of the customers. The service selection is resolved with the distributed application of fuzzy inference or Dempster-Shafer theory of evidence. The selection strategy is also complemented by the adoption of a game theoretic approach for promoting truth-telling ones among service providers. We present empirical evidence of the proposed solution effectiveness through properly crafted simulation experiments.
Christian Esposito 0001, Massimo Ficco, Francesco Palmieri 0002, Aniello Castiglione
IEEE Trans. Computers4
2016 Hierarchical and Shared Access Control
abstract
Access control ensures that only the authorized users of a system are allowed to access certain resources or tasks. Usually, according to their roles and responsibilities, users are organized in hierarchies formed by a certain number of disjoint classes. Such hierarchies are implemented by assigning a key to each class, so that the keys for descendant classes can be efficiently derived from classes higher in the hierarchy. However, pure hierarchical access may represent a limitation in many real-world cases. In fact, sometimes it is necessary to ensure access to a resource or task by considering both its directly responsible user and a group of users possessing certain credentials. In this paper, we first propose a novel model that generalizes the conventional hierarchical access control paradigm, by extending it to certain additional sets of qualified users. Afterward, we propose two constructions for hierarchical key assignment schemes in this new model, which are provably secure with respect to key indistinguishability. In particular, the former construction relies on both symmetric encryption and perfect secret sharing, whereas, the latter is based on public-key threshold broadcast encryption.
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Aniello Castiglione, Jin Li 0002, Xinyi Huang 0001
IEEE Trans. Inf. Forensics Secur.5
2016 Cryptographic Hierarchical Access Control for Dynamic Structures
abstract
A hierarchical key assignment scheme is a method to assign some private information and encryption keys to a set of classes in a partially ordered hierarchy, in such a way that the private information of a higher class can be used to derive the keys of all classes lower down in the hierarchy. Sometimes, it is necessary to make dynamic updates to the hierarchy, in order to implement an access control policy which evolves with time. All security models for hierarchical key assignment schemes have been designed to cope with static hierarchies and do not consider the issue of performing dynamic updates to the hierarchy. In this paper, we define the concept of hierarchical key assignment schemes supporting dynamic updates, formalizing the relative security model. In particular, we provide the notion of security with respect to key indistinguishability, by considering the dynamic changes to the hierarchy. Moreover, we show how to construct a hierarchical key assignment scheme supporting dynamic updates, by using as a building block a symmetric encryption scheme. The proposed construction is provably secure with respect to key indistinguishability, and provides efficient key derivation and updating procedures, while requiring each user to store only a single private key.
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Aniello Castiglione, Xinyi Huang 0001
IEEE Trans. Inf. Forensics Secur.5
2015 On the Protection of fMRI Images in Multi-domain Environments
abstract
Functional Magnetic Resonance Imaging provides researchers with an effective and non-invasive tool to understand cerebral functions and correlate them with brain activities. With the ever increasing diffusion of the Internet such images may be exchanged in several ways, thus allowing new research and medical services. On the other hand, ensuring the security of exchanged fMRI data becomes a main concern, due to the special characteristics arising from strict ethics, legislative and diagnostic implications. So it is very important to prevent unauthorized manipulation and misappropriation of such images. The risks are increased when dealing with open environments like the Internet. For this reason, security mechanisms which ensure protection of such data are required. In this paper we introduce a watermarking scheme explicitly designed for this kind of images. In particular, such a scheme belongs to the category of fragile reversible watermarking. The validity of this scheme has been demonstrated through testing. Finally, by using the proposed scheme, we show how to create a distributed security solution that models a multi-domain environment, for ensuring authenticity and integrity of such images.
Arcangelo Castiglione, Alfredo De Santis, Raffaele Pizzolante, Aniello Castiglione, Vincenzo Loia, Francesco Palmieri 0002
AINA4
2015 Heterogeneous Network Handover Using 3GPP ANDSF
abstract
In this paper, we propose an improved IP-based handover scheme, named the Heterogeneous Network Handover by using 3GPP ANDSF (HNH3A for short) for S-PMIPv6 where S-PMIPv6 is a MIPv6 family protocol developed in one of our previous studies, and ANDSF (standing for Access Network Discovery and Selection Function) is an entity within an evolved packet core (EPC) of the system architecture evolution (SAE) for 3GPP compliant mobile networks. The purpose of using the ANDSF is to assist user equipment (UE) to discover non-3GPP access networks, such as WiFi or WIMAX. The HNH3A can help the handover among mobile WiMAX (i.e., Worldwide Interoperability for Microwave Access), 3GPP (i.e., 3rd Generation Partnership Project) family (including 3GPP systems, 3G LTE and 4G LTE-A) and WiFi based on existing handover techniques among the three heterogeneous networks. The analytical results demonstrate that the HNH3A can effectively mitigate handover delays and handover signaling costs.
Chin-Yu Liu, Fang-Yie Leu, Jung-Chun Liu, Aniello Castiglione, Francesco Palmieri 0002
AINA4
2015 Modeling security requirements for cloud-based system development
abstract
Summary The Cloud Computing paradigm provides a new model for the more flexible utilization of computing and storage services. However, such enhanced flexibility, which implies outsourcing the data and business applications to a third party, may introduce critical security issues. Therefore, there is a clear necessity of new security paradigms able to face all the problems introduced by the cloud approach. Although, in the last years, several solutions have been proposed, the implementation of secure cloud applications and services is still a complex and far from consolidated task. Starting from these considerations, this work fosters the development of a methodology that considers security concerns as an integral part of cloud‐based applications design and implementation. Accordingly, we present a set of stereotypes that defines a vocabulary for annotating Unified Modeling Language based models with information relevant for integrating the specification of security requirements into cloud architectures. This approach can be used to significantly improve productivity and overall success in the development of secure distributed cloud applications and systems. Copyright © 2014 John Wiley & Sons, Ltd.
Massimo Ficco, Francesco Palmieri 0002, Aniello Castiglione
Concurr. Comput. Pract. Exp.3
2015 Cloud-based adaptive compression and secure management services for 3D healthcare data
Arcangelo Castiglione, Raffaele Pizzolante, Alfredo De Santis, Bruno Carpentieri, Aniello Castiglione, Francesco Palmieri 0002
Future Gener. Comput. Syst.5
2015 Modeling energy-efficient secure communications in multi-mode wireless mobile devices
Arcangelo Castiglione, Francesco Palmieri 0002, Ugo Fiore, Aniello Castiglione, Alfredo De Santis
J. Comput. Syst. Sci.4
2015 Energy efficiency of elastic frequency grids in multilayer IP/MPLS-over-flexgrid networks
Sergio Ricciardi, Francesco Palmieri 0002, Aniello Castiglione, Davide Careglio
J. Netw. Comput. Appl.3
2015 A knowledge-based platform for Big Data analytics based on publish/subscribe services and stream processing
Christian Esposito 0001, Massimo Ficco, Francesco Palmieri 0002, Aniello Castiglione
Knowl. Based Syst.4
2015 Secure and reliable data communication in developing regions and rural areas
Arcangelo Castiglione, Raffaele Pizzolante, Francesco Palmieri 0002, Alfredo De Santis, Bruno Carpentieri, Aniello Castiglione
Pervasive Mob. Comput.6
2015 Modeling performances of concurrent big data applications
abstract
Summary Big Data applications are characterized by a non‐negligible number of complex parallel transactions on a huge amount of data that continuously varies, generally increasing over time. Because of the amount of needed resources, the ideal runtime scenario for these applications is based on complex cloud computing and storage infrastructures, providing a scalable degree of parallelism together with isolation between different applications and resource abstraction. However, such additional abstraction degree also introduces significant complexity in performance modeling and decision making. Potential concurrency of many applications on the same cloud infrastructure has to be evaluated, and, simultaneously, scalability of applications over time has to be studied through proper modeling practices, in order to predict the system behavior as the usage patterns evolve and the load increases. For this purpose, in this paper, we propose an analytic modeling technique based on the use of Markovian Agents and Mean Field Analysis that allows the effective description of different concurrent Big Data applications on a same, multi‐site cloud infrastructure, accounting for mutual interactions, in order to support the careful evaluation of several elements in terms of real costs/risks/benefits for correctly dimensioning and allocating the resources and verifying the existing service level agreements. Copyright © 2014 John Wiley & Sons, Ltd.
Aniello Castiglione, Marco Gribaudo, Mauro Iacono, Francesco Palmieri 0002
Softw. Pract. Exp.1
2015 Energy-oriented denial of service attacks: an emerging menace for large cloud infrastructures
Francesco Palmieri 0002, Sergio Ricciardi, Ugo Fiore, Massimo Ficco, Aniello Castiglione
J. Supercomput.5
2015 A triadic closure and homophily-based recommendation system for online social networks
Giuliana Carullo, Aniello Castiglione, Alfredo De Santis, Francesco Palmieri 0002
World Wide Web2
2014 An Efficient and Transparent One-Time Authentication Protocol with Non-interactive Key Scheduling and Update
abstract
Authentication protocols prevent resources to be accessed by unauthorized users. Password authentication is one of the simplest and most convenient authentication mechanism over insecure networks and, in particular, the one-time authentication mechanism, in which the password is valid only for one login session or transaction are a good compromise between simplicity of use and security. Nowadays many of such protocols have been proposed to implement that type of authentication. However, most of them have several drawbacks because they are characterized by considerable overhead in the Key Setup, Key Scheduling and Key Update phases. In addition, they are often vulnerable to several known attacks and are not particularly suitable to be used by mobile terminals. Furthermore, they often rely on smart-card and other hardware tokens, thus requiring an active participation by the user. In this paper, we present a robust one-time authentication protocol, based on two cryptographically strong building blocks, namely, the Authenticated Key Exchange key exchange and the keyed Hash Message Authentication Code (HMAC), that provides several advantages with respect to most of the available solutions at the state of the art. First, it enables transparent mutual authentication between two endpoints. Moreover, Key Setup, Key Scheduling and Key Update operations are accomplished independently by both endpoints, without requiring any interaction among them, thus ensuring the fully independence by any Trusted Third Party. Finally, the proposed protocol is cryptographically secure, under standard assumptions against most of the already known OTP attacks.
Arcangelo Castiglione, Alfredo De Santis, Aniello Castiglione, Francesco Palmieri 0002
AINA3
2014 Multimedia-based battery drain attacks for Android devices
abstract
People using smartphones to connect to the Internet for day-life activities has overtaken the number of people using canonical PCs. This lead to a huge quantity of security threats that usually tend to penetrate the defenses of a smartphone in order to gain control of its resources. Differently, energy-based attacks have the objective of increasing the energy consumption of the victim device. It is important to highlight that this objective could be possibly achieved by just activating the system's defenses as a consequence of canonical attacks and letting the system defenses detect and (try to) defeat them. These activities consume additional energy and could led the mobile device to its complete uselessness. In this paper, an energy-based attack based on soliciting hardware-level encoding/decoding functions through properly crafted multimedia files is analyzed and its impact evaluated. Such kind of attacks are performed without accessing the device by taking advantage of the new HTML5 functionalities. A series of experiments have been performed in order to understand which are the codecs that have a more relevant impact on energy consumption, and, as a consequence, that make the attack more effective.
Ugo Fiore, Francesco Palmieri 0002, Aniello Castiglione, Vincenzo Loia, Alfredo De Santis
CCNC3
2014 A distributed approach to network anomaly detection based on independent component analysis
abstract
SUMMARY Network anomalies, circumstances in which the network behavior deviates from its normal operational baseline, can be due to various factors such as network overload conditions, malicious/hostile activities, denial of service attacks, and network intrusions. New detection schemes based on machine learning principles are therefore desirable as they can learn the nature of normal traffic behavior and autonomously adapt to variations in the structure of ‘normality’ as well as recognize the significant deviations as suspicious or anomalous events. The main advantages of these techniques are that, in principle, they are not restricted to any specific environment and that they can provide a way of detecting unknown attacks. Detection performance is directly correlated with the traffic model quality, in terms of ability of representing the traffic behavior from its most characterizing internal dynamics. Starting from these ideas, we developed a two‐stage anomaly detection strategy based on multiple distributed sensors located throughout the network. By using Independent Component Analysis , the first step, modeled as a Blind Source Separation problem, extracts the fundamental traffic components (the ‘source’ signals), corresponding to the independent traffic dynamics, from the multidimensional time series incoming from the sensors, corresponding to the perceived ‘mixed/aggregate’ effect of traffic on their interfaces. These components will be used to build the baseline traffic profiles needed in the second supervised phase, based on a binary classification scheme (detection is casted into an anomalous/normal classification problem) driven by machine learning‐inferred decision trees. Copyright © 2013 John Wiley & Sons, Ltd.
Francesco Palmieri 0002, Ugo Fiore, Aniello Castiglione
Concurr. Comput. Pract. Exp.3
2014 Exploiting mean field analysis to model performances of big data architectures
Aniello Castiglione, Marco Gribaudo, Mauro Iacono, Francesco Palmieri 0002
Future Gener. Comput. Syst.1
2014 A botnet-based command and control approach relying on swarm intelligence
Aniello Castiglione, Roberto De Prisco, Alfredo De Santis, Ugo Fiore, Francesco Palmieri 0002
J. Netw. Comput. Appl.1
2014 Hybrid indoor and outdoor location services for new generation mobile terminals
Massimo Ficco, Francesco Palmieri 0002, Aniello Castiglione
Pers. Ubiquitous Comput.3
2014 Soft computing for security services in smart and ubiquitous environments
Marek R. Ogiela, Aniello Castiglione, Ilsun You
Soft Comput.2
2014 A Denial of Service Attack to UMTS Networks Using SIM-Less Devices
abstract
One of the fundamental security elements in cellular networks is the authentication procedure performed by means of the Subscriber Identity Module that is required to grant access to network services and hence protect the network from unauthorized usage. Nonetheless, in this work we present a new kind of denial of service attack based on properly crafted SIM-less devices that, without any kind of authentication and by exploiting some specific features and performance bottlenecks of the UMTS network attachment process, are potentially capable of introducing significant service degradation up to disrupting large sections of the cellular network coverage. The knowledge of this attack can be exploited by several applications both in security and in network equipment manufacturing sectors.
Alessio Merlo, Mauro Migliardi, Nicola Gobbo, Francesco Palmieri 0002, Aniello Castiglione
IEEE Trans. Dependable Secur. Comput.5
2014 A secure file sharing service for distributed computing environments
Aniello Castiglione, Luigi Catuogno, Aniello Del Sorbo, Ugo Fiore, Francesco Palmieri 0002
J. Supercomput.1
2013 FeelTrust: Providing Trustworthy Communications in Ubiquitous Mobile Environment
abstract
The growing intelligence and popularity of smartphones and the advances in Mobile Ubiquitous Computing have resulted in rapid proliferation of data-sharing applications. Instances of these applications include pervasive social networking, games, file sharing and so on. In such scenarios, users are usually involved in selecting the peers with whom communication should take place, continuously facing trust issues. Unfortunately, providing trust support in a pervasive world is challenging due to peer mobility and lack in central control. We propose a novel approach that establishes trust leveraging users' profiles: humans today produce rich strings of unique data twenty-four hours a day. These information enables a task-aware trust model, namely a finer-grained model in which users are classified as trusted or not depending on the intended business activity. However, simply collecting user's interests may be insufficient to provide a reasonable trust management system. In order to enable the system to recognize malicious users, we include a recommendation subsystem based on the Wilson score confidence interval. It has been designed to be lightweight, minimizing battery depletion. It also protects user privacy. To make our approach fully deployable, it supports two modalities: a TPM-based one and a TPM-less one. The former gives more security guarantees and ensures a fully distributed approach. The latter, requires a Trusted Authority to avoid feedbacks to get tampered and is no more fully distributed.
Giuliana Carullo, Aniello Castiglione, Giuseppe Cattaneo, Alfredo De Santis, Ugo Fiore, Francesco Palmieri 0002
AINA2
2013 Forensically-Sound Methods to Collect Live Network Evidence
abstract
In the last decade Digital Forensics has experienced several issues when dealing with network evidence. An analyst, which is in charge of managing evidence flowing over a network have to face problems due to the volatile nature of such information. In facts, such data may change over time, may be lying on a server out of the his jurisdiction, or geographically far from where the crime was committed. In this paper two methods to allow remote collection of network evidence produced by online services such as web pages, chats, documents, photos and videos are presented. They enable the analyst to drive the acquisition process through the online services considered potential sources of evidence. During the process, all data flowing through the network is automatically collected (i.e., all the IP packets). The second one also collects the graphical representation of the acquisition (e.g., how the browser visualizes such data). Both methods introduce a trusted third party (acting as a digital notary) which is in charge of collecting and ``certifying'' network evidence. Before closing the acquisition process, a detailed report of the collected evidence is generated and made available to the analyst along with the collected data. Cryptographic primitives are used to demonstrate ex post data integrity, how it has been acquired and the acquisition time. As a proof of concept two prototypes have been implemented. To enhance the Court confidence of the collected evidence, at the same time, the service could be run across multiple coordinated servers acquiring the same data from different point of the network.
Aniello Castiglione, Giuseppe Cattaneo, Giancarlo De Maio, Alfredo De Santis
AINA1
2013 Network anomaly detection with the restricted Boltzmann machine
Ugo Fiore, Francesco Palmieri 0002, Aniello Castiglione, Alfredo De Santis
Neurocomputing3
2012 Engineering a secure mobile messaging framework
Aniello Castiglione, Giuseppe Cattaneo, Maurizio Cembalo, Alfredo De Santis, Pompeo Faruolo, Fabio Petagna, Umberto Ferraro Petrillo
Comput. Secur.1
2011 New Steganographic Techniques for the OOXML File Format
Aniello Castiglione, Bonaventura D'Alessio, Alfredo De Santis, Francesco Palmieri 0002
ARES1
2011 Automated Construction of a False Digital Alibi
Alfredo De Santis, Aniello Castiglione, Giuseppe Cattaneo, Giancarlo De Maio, Mario Ianulardo
ARES2
2010 An Extensible Framework for Efficient Secure SMS
abstract
Nowadays, Short Message Service (SMS) still represents the most used mobile messaging service. SMS messages are used in many different application fields, even in cases where security features, such as authentication and confidentiality between the communicators, must be ensured. Unfortunately, the SMS technology does not provide a built-in support for any security feature. This work presents SEESMS (Secure Extensible and Efficient SMS), a software framework written in Java which allows two peers to exchange encrypted and digitally signed SMS messages. The communication between peers is secured by using public-key cryptography. The key-exchange process is implemented by using a novel and simple security protocol which minimizes the number of SMS messages to use. SEESMS supports the encryption of a communication channel through the ECIES and the RSA algorithms. The identity validation of the contacts involved in the communication is implemented through the RSA, DSA and ECDSA signature schemes. SEESMS is able to certify the phone number of the peers using the framework. Additional cryptosystems can be coded and added to SEESMS as plug-ins. Special attention has been devoted to the implementation of an efficient framework in terms of energy consumption and execution time. This efficiency is obtained in two steps. First, all the cryptosystems available in the framework are implemented using mature and fully optimized cryptographic libraries. Second, an experimental analysis was conducted to determine which combination of cryptosystems and security parameters were able to provide a better trade-off in terms of speed/security and energy consumption. This experimental analysis has also been useful to expose some serious performance issues affecting the cryptographic libraries which are commonly used to implement security features on mobile devices.
Alfredo De Santis, Aniello Castiglione, Giuseppe Cattaneo, Maurizio Cembalo, Fabio Petagna, Umberto Ferraro Petrillo
CISIS2
2010 Security and privacy issues in the Portable Document Format
Aniello Castiglione, Alfredo De Santis, Claudio Soriente
J. Syst. Softw.1
2007 Taking advantages of a disadvantage: Digital forensics and steganography using document metadata
Aniello Castiglione, Alfredo De Santis, Claudio Soriente
J. Syst. Softw.1