VLDB 2026 Research / reviewers in the wild / expert
Alessio Merlo
dblp:54/3464
· DBLP profile ↗
69ranked-venue papers
11as first author
25since 2021 · last 2026
0000-0002-2272-2376ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 32 · 5 first-author · 12 since 2021Systems, architecture and hardware · 8 · 2 first-authorSoftware engineering, systems software and programming languages · 8 · 5 since 2021Human-computer interaction and ubiquitous computing · 8 · 4 first-author · 2 since 2021Computer networks · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Artificial intelligence and machine learning · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Unknown Target: Uncovering and Detecting Novel In-Flight Attacks to Collision Avoidance (TCAS)
Giacomo Longo, Giacomo Ratto, Alessio Merlo, Enrico Russo 0001 |
NDSS | 3 |
| 2026 | Multi-agent deep reinforcement learning for penetration testing of IoT devices through their mobile companion appabstractThe increasing integration of IoT devices into critical infrastructure has made them prime targets for cyberattacks. Many of these devices rely on outdated or legacy software, which introduces inherent vulnerabilities and complicates firmware updates, making identifying and testing these weaknesses essential. Traditional methods typically employ black-box approaches, mutating network requests generated during device operation to craft potential attack vectors. However, these methods face limitations when dealing with encrypted or proprietary protocols. Recent tools, such as Diane and IoTFuzzer, interact with IoT devices through their mobile companion apps and use fuzzing techniques to modify request content, causing crashes in IoT device software. Although these approaches can effectively trigger software crashes, they do not generate actual exploits, as they do not precisely target or exploit specific vulnerabilities. To address these limitations, we introduce MITHRAS, the first approach that uses mobile companion apps to deliver maliciously mutated requests directly to IoT devices, explicitly targeting Remote Code Execution (RCE) vulnerabilities. MITHRAS uses Deep Reinforcement Learning to efficiently navigate the communication code within companion apps, dynamically mutating request payloads before transmission. Adapting to previous attack outcomes, MITHRAS refines its strategy, mimicking human decision-making to improve the effectiveness of exploit generation. Francesco Pagano, Mariano Ceccato, Alessio Merlo, Paolo Tonella |
J. Syst. Softw. | 3 |
| 2025 | An Empirical Study on Reproducible Packaging in Open-Source EcosystemsabstractThe integrity of software builds is fundamental to the security of the software supply chain. While Thompson first raised the potential for attacks on build infrastructure in 1984, limited attention has been given to build integrity in the past 40 years, enabling recent attacks on SolarWinds, event-stream, and xz. The best-known defense against build system attacks is creating reproducible builds; however, achieving them can be complex for both technical and social reasons and thus is often viewed as impractical to obtain. In this paper, we analyze reproducibility of builds in a novel context: reusable components distributed as packages in six popular software ecosystems (npm, Maven, PyPI, Go, RubyGems, and Cargo). Our quantitative study on a representative sample of 4000 packages in each ecosystem raises concerns: Rates of reproducible builds vary widely between ecosystems, with some ecosystems having all packages reproducible whereas others have reproducibility issues in nearly every package. However, upon deeper investigation, we identified that with relatively straightforward infrastructure configuration and patching of build tools, we can achieve very high rates of reproducible builds in all studied ecosystems. We conclude that if the ecosystems adopt our suggestions, the build process of published packages can be independently confirmed for nearly all packages without individual developer actions, and doing so will prevent significant future software supply chain attacks. Giacomo Benedetti, Oreofe Solarin, Courtney Miller, Greg Tystahl, William Enck, Christian Kästner, Alexandros Kapravelos, Alessio Merlo, Luca Verderame |
ICSE | 8 |
| 2025 | SSI-MedRx: A fraud-resilient healthcare system based on blockchain and SSIabstractToday, healthcare fraud poses a significant issue, encompassing everything from falsified billing claims and phantom services to the excessive prescription of opioid medications and medical identity theft. These deceptive activities cause substantial financial losses, erode patient trust, compromise healthcare quality, and threaten patient safety. In this paper, we introduce SSI-MedRx, a healthcare system based on blockchain technology and Self-Sovereign Identity (SSI). It is designed to ensure cross-border interoperability, preserve patient privacy, and prevent challenging healthcare frauds, including medical identity theft, phantom billing, kickbacks, and opioid overprescribing. By design, our system empowers patients by granting them complete control over their personal and health data. This shift toward patient-centric data management can potentially reduce the risk of data breaches, enhance care coordination, and improve overall healthcare outcomes. Meriem Guerar, Mauro Migliardi, Enrico Russo 0001, Djamel Khadraoui, Alessio Merlo |
Blockchain Res. Appl. | 5 |
| 2025 | A data anonymization methodology for security operations centers: Balancing data protection and security in industrial systemsabstractIn an era where industrial Security Operations Centers (SOCs) are paramount to enabling cybersecurity, they can unintentionally become enablers of intellectual property theft through the data they analyze and retain. The above issue requires finding solutions to strike a balance between data protection and security. This paper proposes a real-time data anonymization framework designed to operate directly within network devices. Using an extensive case study, our approach demonstrates how valuable intellectual property associated with industrial processes can be protected without compromising the effectiveness of behavioral anomaly detection systems. The methodology is designed to be nonintrusive, reversible, and seamlessly portable on existing security solutions. We evaluated these properties through comprehensive experimental testing, which showed both the method's effectiveness in securing intellectual property and its suitability for continuous real-time operation. Giacomo Longo, Francesco Lupia, Alessio Merlo, Francesco Pagano, Enrico Russo 0001 |
Inf. Sci. | 3 |
| 2025 | Light up that Droid! On the effectiveness of static analysis features against app obfuscation for Android malware detectionabstractMalware authors have seen obfuscation as the mean to bypass malware detectors based on static analysis features. For Android, several studies have confirmed that many anti-malware products are easily evaded with simple program transformations. As opposed to these works, ML detection proposals for Android leveraging static analysis features have also been proposed as obfuscation-resilient. Therefore, it needs to be determined to what extent the use of a specific obfuscation strategy or tool poses a risk for the validity of ML Android malware detectors based on static analysis features. To shed some light in this regard, in this article we assess the impact of specific obfuscation techniques on common features extracted using static analysis and determine whether the changes are significant enough to undermine the effectiveness of ML malware detectors that rely on these features. The experimental results suggest that obfuscation techniques affect all static analysis features to varying degrees across different tools. However, certain features retain their validity for ML malware detection even in the presence of obfuscation. Based on these findings, we propose a ML malware detector for Android that is robust against obfuscation and outperforms current state-of-the-art detectors. Borja Molina-Coronado, Antonio Ruggia, Usue Mori, Alessio Merlo, Alexander Mendiburu, José Miguel-Alonso |
J. Netw. Comput. Appl. | 4 |
| 2025 | Would you mind hiding my malware? Building malicious Android apps with StegoPackabstractThis paper empirically explores the resilience of the current Android ecosystem against stegomalware, which involves both Java/Kotlin and native code. To this aim, we rely on a methodology that goes beyond traditional approaches by hiding malicious Java code and extending it to encoding and dynamically loading native libraries at runtime. By merging app resources, steganography, and repackaging, the methodology seamlessly embeds malware samples into the assets of a host app, making detection significantly more challenging. We implemented the methodology in a tool, StegoPack, which allows the extraction and execution of the payload at runtime through reverse steganography. We used StegoPack to embed well-known DEX and native malware samples over 14 years into real Android host apps. We then challenged top-notch antivirus engines, which previously had high detection rates on the original malware, to detect the embedded samples. Our results reveal a significant reduction in the number of detections (up to zero in most cases), indicating that current detection techniques, while thorough in analyzing app code, largely disregard app assets, leading us to believe that steganographic adversaries are not even included in the adversary models of most deployed defensive analysis systems. Thus, we propose potential countermeasures for StegoPack to detect steganographic data in the app assets and the dynamic loader used to execute malware. Danilo Dell'Orco, Giorgio Bernardinetti, Giuseppe Bianchi 0001, Alessio Merlo, Alessandro Pellegrini 0001 |
Pervasive Mob. Comput. | 4 |
| 2025 | The Dark Side of Native Code on AndroidabstractFrom a little research experiment to an essential component of military arsenals, malicious software has constantly been growing and evolving for more than three decades. On the other hand, from a negligible market share, the Android operating system is nowadays the most widely used mobile operating system, becoming a desirable target for large-scale malware distribution. While scientific literature has followed this trend, one aspect has been understudied: the role of native code in malicious Android apps. Android apps are written in high-level languages, but thanks to the Java Native Interface (JNI), Android also supports calling native (C/C++) library functions. While allowing native code in Android apps has a strong positive impact from a performance perspective, it dramatically complicates its analysis because bytecode and native code need different abstractions and analysis algorithms, and they thus pose different challenges and limitations. Consequently, these difficulties are often (ab)used to hide malicious payloads. In this work, we propose a novel methodology to reverse engineering Android apps focusing on suspicious patterns related to native components, i.e., surreptitious code that requires further inspection. We implemented a static analysis tool based on such methodology, which can bridge the “Java” and the native worlds and perform an in-depth analysis of tag code blocks responsible for suspicious behavior. These tags benefit the human facing the reverse engineering task: they clearly indicate which part of the code to focus on to find malicious code. Then, we performed a longitudinal analysis of Android malware over the past 10 years and compared the recent malicious samples with actual top apps on the Google Play Store. Our work depicts typical behaviors of modern malware, its evolution, and how it abuses the native layer to complicate the analysis, especially with dynamic code loading and novel anti-analysis techniques. Finally, we show a use case for our suspicious tags: we trained and tested a machine learning algorithm for a binary classification task. Even if suspicious does not imply malicious, our classifier obtained a remarkable F1-score of 0.97, showing that our methodology can be helpful to both humans and machines. Antonio Ruggia, Andrea Possemato, Savino Dambra, Alessio Merlo, Simone Aonzo, Davide Balzarotti |
ACM Trans. Priv. Secur. | 4 |
| 2024 | Unmasking the Veiled: A Comprehensive Analysis of Android Evasive MalwareabstractSince Android is the most widespread operating system, malware targeting it poses a severe threat to the security and privacy of millions of users and is increasing from year to year. The response from the community was swift, and many researchers have ventured to defend this system. In this cat-and-mouse game, attackers pay special attention to flying under the radar of analysis tools, and the techniques to understand whether their app is under analysis have become more and more sophisticated. Moreover, these evasive techniques are also adopted by benign apps to deter reverse engineering, making this phenomenon pervasive in the Android app ecosystem. Antonio Ruggia, Dario Nisi, Savino Dambra, Alessio Merlo, Davide Balzarotti, Simone Aonzo |
AsiaCCS | 4 |
| 2024 | Obfuscating Code Vulnerabilities Against Static Analysis in Android Apps
Francesco Pagano, Luca Verderame, Alessio Merlo |
SEC | 3 |
| 2024 | On a Collision Course: Unveiling Wireless Attacks to the Aircraft Traffic Collision Avoidance System (TCAS)
Giacomo Longo, Martin Strohmeier, Enrico Russo 0001, Alessio Merlo, Vincent Lenders |
USENIX Security Symposium | 4 |
| 2023 | Android, Notify Me When It Is Time To Go PhishingabstractA mobile banking app just started up, and the notification "App updated, click here to restart" appears. The graphic theme is the same as the bank. Can we trust it? What if we cannot even trust that tapping an app actually loads the original one? More generally, what if Android notifies an attacker when her victim has just launched the target app of her phishing campaign so that she could cast the hook at the perfect moment?In this paper, we abuse inotify APIs, a mechanism for monitoring file system events, to mount a state inference-based phishing attack from a malicious app installed on the victim's smartphone. We also verified the novelty of our work analyzing 10,000 recent Android malware, and although we found some cases where malware uses inotify for their petty purposes, our attack seems to be publicly unknown.However, since Android constantly evolves year after year, we studied its feasibility over different Android versions and attacker's capabilities. By analyzing 4, 863 of the most popular apps, the most disconcerting finding is that if the attacker knows the installation path of the target app, all Android apps are vulnerable, regardless of the system version. Getting the installation path of an app is a capability that is only protected by a normal permission, and to make matters worse, there are workarounds to get it even without such permission.Even if this capability is denied, we propose different attack models under which this attack is still possible; however, at the end of our work, we provide the remediation to eradicate once and for all these attacks. Through this work, we reported three vulnerabilities to Google. Two were acknowledged as bugs of moderate severity, while the last one was already known but not public. Antonio Ruggia, Andrea Possemato, Alessio Merlo, Dario Nisi, Simone Aonzo |
EuroS&P | 3 |
| 2023 | Electronic Attacks as a Cyber False Flag against Maritime Radars SystemsabstractRadar systems have long been essential for safe navigation in various transportation sectors, including aviation, maritime, and automotive. While these systems provide invaluable situational awareness and decision-making capabilities, they increasingly become targets for malicious actors aiming to disrupt their normal operations. Electronic countermeasures (ECM) have traditionally been the predominant form of attack. However, recent findings have uncovered their vulnerability to cyber-based actions, capitalizing on their digitization and network connectivity. In this paper, we propose a novel threat model that exploits cyber attack capabilities against radar systems to simulate the effects of ECM. This model goes beyond known attacks by introducing a deceptive element, challenging attribution. To evaluate the feasibility of these attacks, extensive experimentation is conducted using a realistic case study involving the maritime domain. Through this research, we aim to highlight the evolving threats facing radar systems and the need for comprehensive security measures. Giacomo Longo, Alessio Merlo, Alessandro Armando, Enrico Russo 0001 |
LCN | 2 |
| 2023 | Assessing the security of inter-app communications in android through reinforcement learning
Andrea Romdhana, Alessio Merlo, Mariano Ceccato, Paolo Tonella |
Comput. Secur. | 2 |
| 2023 | PARIOT: Anti-repackaging for IoT firmware integrityabstractIoT repackaging refers to an attack devoted to tampering with a legitimate firmware package by modifying its content (e.g., injecting some malicious code) and re-distributing it in the wild. In such a scenario, the firmware delivery and update processes are central to ensuring firmware integrity. Unfortunately, several existing solutions lack proper integrity verification, exposing firmware to repackaging attacks. If this is not the case, they still require an external trust anchor (e.g., signing keys or secure storage technologies), which could limit their adoption in resource-constrained environments. In addition, state-of-the-art frameworks do not cope with the entire firmware production and delivery process, thereby failing to protect the content generated by the firmware producers through the whole supply chain. To mitigate such a problem, in this paper, we introduce PARIOT, a novel self-protecting scheme for IoT that injects integrity checks, called anti-tampering (AT) controls, directly into the firmware. The AT controls enable the runtime detection of repackaging attempts without needing signing keys, internet connection, secure storage technologies, or external trusted parties. PARIOT can be adopted on top of existing state-of-the-art solutions ensuring the widest compatibility with current IoT ecosystems and update frameworks. Also, we have implemented this scheme into PARIOTIC, a prototype to protect C/C++ IoT firmware automatically. The evaluation phase of 50 real-world firmware samples demonstrated the proposed methodology’s feasibility and robustness against practical repackaging attacks without altering the firmware behavior or severe overheads. Luca Verderame, Antonio Ruggia, Alessio Merlo |
J. Netw. Comput. Appl. | 3 |
| 2023 | You Can't Always Get What You Want: Towards User-Controlled Privacy on AndroidabstractMobile applications (hereafter, apps) collect a plethora of information regarding the user behavior and his device through third-party analytics libraries. However, the collection and usage of such data raised several privacy concerns, mainly because the end-user - i.e., the actual owner of the data - is out of the loop in this collection process. Also, the existing privacy-enhanced solutions that emerged in the last years follow an ”all or nothing” approach, leaving the user the sole option to accept or completely deny access to privacy-related data. This work has the two-fold objective of assessing the privacy impact of mobile analytics libraries and proposing a data anonymization methodology that offers a trade-off between the utility and privacy of the collected data and enables complete control over the sharing process. To achieve that, we present an empirical privacy assessment on the analytics libraries used in the 4500 most-used Android apps of the Google Play Store in late 2020. Then, we propose an empowered anonymization methodology, based on MobHide (Caputoet al., 2020), that gives the end-user complete control over the collection and anonymization process. Finally, we empirically demonstrate the applicability and effectiveness of our solution thanks to HideDroid, a fully-fledged anonymization app for the Android ecosystem. Davide Caputo, Francesco Pagano, Giovanni Bottino, Luca Verderame, Alessio Merlo |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | LiDiTE: A Full-Fledged and Featherweight Digital Twin FrameworkabstractThe rising of the Cyber-Physical System (CPS) and the Industry 4.0 paradigms demands the design and implementation of Digital Twin Frameworks (DTFs) that may support the quick build of reliable Digital Twins (DTs) for experimental and testing purposes. Most of the current DTF proposals allow the generation of DTs at a good pace but affect generality, scalability, portability, and completeness. As a consequence, current DTF are mostly domain-specific and hardly span several application domains (e.g., from simple IoT deployments to the modeling of complex critical infrastructures). Furthermore, the generated DTs often requires a high amount of computational resource to run. In this paper, we present LiDiTE, a solution based on a novel reference model for general-purpose DTFs. LiDiTE overcomes the limitations of state-of-the-art tools by supporting the fine-grained development of real-world complexity scenarios. To achieve that, LiDiTE builds on technologies that favor scalability, reuse, and extensibility of scenarios. We show such features by building the DT of real critical infrastructure and evaluating the performance of our DT against those of the real system. Further contributions of this paper include open access to the source code of LiDiTE and the experimental dataset. Enrico Russo 0001, Gabriele Costa 0001, Giacomo Longo, Alessandro Armando, Alessio Merlo |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | Attacking (and Defending) the Maritime Radar SystemabstractThe operation of radar equipment is one of the key facilities navigators use to gather situational awareness about their surroundings. With an ever-increasing need for always-running logistics and tighter shipping schedules, operators rely more on computerized instruments and their indications. As a result, modern ships have become complex cyber-physical systems in which sensors and computers constantly communicate and coordinate. In this work, we discuss novel threats related to the radar system, one of a ship’s most security-sensitive components. In detail, we first discuss some new attacks capable of compromising the integrity of data displayed on a radar system, with potentially catastrophic impacts on the crew’s situational awareness or safety. Then, we present a detection system to highlight anomalies in the radar video feed, requiring no modifications to the target ship configuration. Finally, we stimulate our detection system by performing the attacks inside a simulated environment. The experimental results indicate that the attacks are feasible, easy to carry out, and hard to detect. Moreover, they prove that the proposed detection technique is effective. Giacomo Longo, Enrico Russo 0001, Alessandro Armando, Alessio Merlo |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | Enabling Real-Time Remote Monitoring of Ships by Lossless Protocol TransformationsabstractThis paper uses data processing techniques to reduce the required transmission bandwidth in ship-to-shore communications. The proposed framework (ONline Efficient Sources Transmission Optimizer - ONESTO) leverages state-of-the-art technologies and novel algorithms to automatically optimize transmissions under structural (e.g., available bandwidth, fixed packet overhead) and user-defined (e.g., maximum latency) constraints. In addition, ONESTO authenticates and encrypts the communication between the ship and the shore via mainstream free and open-source software components. Initially, we present the abstract mathematical formulation of the problem, with its assumptions, goal function, constraints, and significant quantities. Then, we introduce the architecture of a system capable of continuously estimating the compressibility, processing and transmission time of streaming data. Such estimations allow ONESTO to calculate and apply optimal parameters for achieving the best compression ratio. Lastly, using a prototypical implementation, we evaluate the system performance with a Class B ship simulator on two realistic use cases. Our experiments show an excellent compression ratio with maritime protocols (more than 40:1) and a limited latency impact, demonstrating the approach’s viability. Giacomo Longo, Alessandro Orlich, Alessio Merlo, Enrico Russo 0001 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2022 | IFRIT: Focused Testing through Deep Reinforcement LearningabstractSoftware is constantly changing as developers add new features or make changes. This directly impacts the effectiveness of the test suite associated with that software, especially when the new modifications are in an area where no test case exists. This article addresses the issue of developing a high-quality test suite to repeatedly cover a given point in a program, with the ultimate goal of exposing faults affecting the given program point. Our approach, IFRIT, uses Deep Reinforcement Learning to generate diverse inputs while keeping a high level of reachability of the desired program point. IFRIT achieves better results than state-of-the-art and baseline tools, improving reachability, diversity and fault detection. Andrea Romdhana, Mariano Ceccato, Alessio Merlo, Paolo Tonella |
ICST | 3 |
| 2022 | Deep Reinforcement Learning for Black-box Testing of Android AppsabstractThe state space of Android apps is huge, and its thorough exploration during testing remains a significant challenge. The best exploration strategy is highly dependent on the features of the app under test. Reinforcement Learning (RL) is a machine learning technique that learns the optimal strategy to solve a task by trial and error, guided by positive or negative reward, rather than explicit supervision. Deep RL is a recent extension of RL that takes advantage of the learning capabilities of neural networks. Such capabilities make Deep RL suitable for complex exploration spaces such as one of Android apps. However, state-of-the-art, publicly available tools only support basic, Tabular RL. We have developed ARES, a Deep RL approach for black-box testing of Android apps. Experimental results show that it achieves higher coverage and fault revelation than the baselines, including state-of-the-art tools, such as TimeMachine and Q-Testing. We also investigated the reasons behind such performance qualitatively, and we have identified the key features of Android apps that make Deep RL particularly effective on them to be the presence of chained and blocking activities. Moreover, we have developed FATE to fine-tune the hyperparameters of Deep RL algorithms on simulated apps, since it is computationally expensive to carry it out on real apps. Andrea Romdhana, Alessio Merlo, Mariano Ceccato, Paolo Tonella |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2021 | Repack Me If You Can: An Anti-Repackaging Solution Based on Android VirtualizationabstractA growing trend in repackaging attacks exploits the Android virtualization technique, in which malicious code can run together with the victim app in a virtual container. In such a scenario, the attacker can directly build a malicious container capable of hosting the victim app instead of tampering with it, thus neglecting any anti-repackaging protection developed so far. Also, existing anti-virtualization techniques are ineffective since the malicious container can intercept - and tamper with - such controls at runtime. So far, only two solutions have been specifically designed to address virtualization-based repackaging attacks. However, their effectiveness is limited since they both rely on static taint analysis, thus not being able to evaluate code dynamically loaded at runtime. Antonio Ruggia, Eleonora Losiouk, Luca Verderame, Mauro Conti, Alessio Merlo |
ACSAC | 5 |
| 2021 | COSMO: Code Coverage Made Easier for AndroidabstractThe degree of code coverage reached by a test suite is an important indicator of the thoroughness of testing. Most coverage tools for Android apps work at the bytecode level and provide no information to developers about which source code lines have not yet been exercised by any test case. In this paper, we present COSMO, the first fully automated Android app instrumenter publicly available that operates at the source code level in a completely transparent way, making it fully compatible with existing system level testing technologies and Android test generators. The experiments that we have conducted on a large benchmark of Android apps show that COSMO can successfully instrument most apps without altering their execution traces, introducing a small, acceptable runtime overhead. Andrea Romdhana, Mariano Ceccato, Gabriel Claudiu Georgiu, Alessio Merlo, Paolo Tonella |
ICST | 4 |
| 2021 | You Shall not Repackage! Demystifying Anti-Repackaging on Android
Alessio Merlo, Antonio Ruggia, Luigi Sciolla, Luca Verderame |
Comput. Secur. | 1 |
| 2021 | ARMAND: Anti-Repackaging through Multi-pattern Anti-tampering based on Native Detection
Alessio Merlo, Antonio Ruggia, Luigi Sciolla, Luca Verderame |
Pervasive Mob. Comput. | 1 |
| 2020 | On the (Un)Reliability of Privacy Policies in Android AppsabstractThe access to privacy-sensitive information on Android is a growing concern in the mobile community. Albeit Google Play recently introduced some privacy guidelines, it is still an open problem to soundly verify whether apps actually comply with such rules. To this aim, in this paper, we discuss a novel methodology based on a fruitful combination of static analysis, dynamic analysis, and machine learning techniques, which allows assessing such compliance. More in detail, our methodology checks whether each app i) contains a privacy policy that complies with the Google Play privacy guidelines, and ii) accesses privacy-sensitive information only upon the acceptance of the policy by the user. Furthermore, the methodology also allows checking the compliance of third-party libraries embedded in the apps w.r.t. the same privacy guidelines. We implemented our methodology in a tool, 3PDroid, and we carried out an assessment on a set of recent and most-downloaded Android apps in the Google Play Store. Experimental results suggest that more than 95% of apps access user's privacy-sensitive information, but just a negligible subset of them (≈ 1%) fully complies with the Google Play privacy guidelines. Luca Verderame, Davide Caputo, Andrea Romdhana, Alessio Merlo |
IJCNN | 4 |
| 2020 | Prevalence and Impact of Low-Entropy Packing Schemes in the Malware Ecosystem
Alessandro Mantovani, Simone Aonzo, Xabier Ugarte-Pedrero, Alessio Merlo, Davide Balzarotti |
NDSS | 4 |
| 2020 | Enabling Next-Generation Cyber Ranges with Mobile Security Components
Enrico Russo 0001, Luca Verderame, Alessio Merlo |
ICTSS | 3 |
| 2020 | APPregator: A Large-Scale Platform for Mobile Security Analysis
Luca Verderame, Davide Caputo, Andrea Romdhana, Alessio Merlo |
ICTSS | 4 |
| 2020 | Securing PIN-based authentication in smartwatches with just two gesturesabstractSummary Smartwatches are becoming increasingly ubiquitous as they offer new capabilities to develop sophisticated applications that make daily life easier and more convenient for consumers. The services provided include applications for mobile payment, ticketing, identification, access control, etc. While this makes modern smartwatches very powerful devices, it also makes them very attractive targets for attackers. Indeed, PINs and Pattern Lock have been widely used in smartwatches for user authentication. However, such authentication methods are not robust against various forms of cybersecurity attacks, such as side channel, phishing, smudge, shoulder surfing, and video‐recording attacks. Moreover, the recent adoption of hardware‐based solutions, like the Trusted Execution Environment (TEE), can mitigate only partially such problems. Thus, the user's security and privacy are at risk without a strong authentication scheme in place. In this work, we propose 2GesturePIN, a new authentication framework that allows users to authenticate securely to their smartwatches and related sensitive services through solely two gestures. 2GesturePIN leverages the rotating bezel or crown, which are the most intuitive ways to interact with a smartwatch, as a dedicated hardware. 2GesturePIN improves the resilience of the regular PIN authentication method against state‐of‐the‐art cybersecurity attacks while maintaining a high level of usability. Meriem Guerar, Mauro Migliardi, Francesco Palmieri 0002, Luca Verderame, Alessio Merlo |
Concurr. Comput. Pract. Exp. | 5 |
| 2020 | A secure cloud-edges computing architecture for metagenomics analysis
Luca Verderame, Ivan Merelli, Lucia Morganti, Elena Corni, Daniele Cesini, Daniele D'Agostino, Alessio Merlo |
Future Gener. Comput. Syst. | 7 |
| 2020 | CirclePIN: A Novel Authentication Mechanism for Smartwatches to Prevent Unauthorized Access to IoT DevicesabstractIn the last months, the market for personal wearable devices has been booming significantly, and, in particular, smartwatches are starting to assume a fundamental role in the Bring Your Own Device (BYOD) arena as well as in the more general Internet of Things (IoT) ecosystem, by acting both as sensitive data sources and as user identity proxies. These new roles, complementing the more traditional personal assistance and telemetry/tracking ones, open new perspectives in their integration in complex IoT-based critical infrastructures such as e-payment, health care monitoring, and emergency systems, as well as in their usage as remote control facilities in smart services. Users can access their IoT devices at any time from any place through smartwatches. We argue that this new scenario calls for a strengthened and more resilient authentication of users on these devices, despite their limitations in terms of dimensions and hardware constraints that may considerably affect the usability of security mechanisms. In this article, we present an innovative authentication scheme targeted at smartwatches, namely CirclePIN, that provides both resilience to most common attacks and a high level of usability in tests with real users. Meriem Guerar, Luca Verderame, Alessio Merlo, Francesco Palmieri 0002, Mauro Migliardi, Luca Vallerini |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2020 | Low-Resource Footprint, Data-Driven Malware Detection on AndroidabstractResource-constrained systems are becoming more and more common as users migrate from PCs to mobile devices and as IoT systems enter the mainstream. At the same time, it is not acceptable to reduce the level of security hence it is necessary to accommodate the required security into the system-imposed resource constraints. This paper introduces BAdDroIds, a mobile application leveraging machine learning for detecting malware on resource constrained devices. BAdDroIds executes in background and transparently analyzes the applications as soon as they are installed, i.e., before infecting the device. BAdDroIds relies on static analysis techniques and features provided by the Android OS to build up sound and complete models of Android apps in terms of permissions and API invocations. It uses ad-hoc supervised classification techniques to allow resource-efficient malware detection. By exploiting the intrinsic nature of data, it has been possible to implement a state-of-the-art data-driven model which provides deep insights on the detection problem and can be efficiently executed on the device itself as it requires a very limited computational effort. Besides its limited resource footprint, BAdDroIds is extremely effective: An extensive experimental evaluation shows that it outperforms the currently available solutions in terms of accuracy, which is around 99 percent. Simone Aonzo, Alessio Merlo, Mauro Migliardi, Luca Oneto, Francesco Palmieri 0002 |
IEEE Trans. Sustain. Comput. | 2 |
| 2019 | Droids in Disarray: Detecting Frame Confusion in Hybrid Android Apps
Davide Caputo, Luca Verderame, Simone Aonzo, Alessio Merlo |
DBSec | 4 |
| 2019 | Blockchain-based risk mitigation for invoice financingabstractThe market for invoice financing has been steadily growing in the last few years and has been the third financing market in size in 2016. Most solutions in this field are based on private platforms and even the new proposals based on blockchain are mostly adopting a private, permissioned blockchain. In this paper, we propose an idea based on a public blockchain that allows both fully open and group-restricted auctioning of invoices. Furthermore, our proposal introduces a reputation system that is based on the past behavior of entities, as it is photographed by the public blockchain, to allow insurance companies modulate the cost of the insurance contracts they offer. This combination guarantees the complete transparency and tamperproof-ness of a public blockchain, while it allows reducing insurance costs and fraud possibilities. Meriem Guerar, Luca Verderame, Alessio Merlo, Mauro Migliardi |
IDEAS | 3 |
| 2019 | 2GesturePIN: Securing PIN-Based Authentication on SmartwatchesabstractSmartwatches offer new capabilities to develop sophisticated applications that make daily life easier and more convenient for consumers and are becoming increasingly ubiquitous. The kind of services these devices are capable to provide include applications for mobile payment, ticketing, identification, access control, etc. While this makes modern smartwatches very powerful devices, it also makes them very attractive targets for attackers. PINs and Pattern Lock have been widely used in smartwatches for user authentication, however, those types of passwords are not robust against various forms of attacks, such as side channel, phishing, smudge, shoulder surfing, and videorecording attacks. In this work, we propose 2GesturePIN, a new authentication method that allows users to authenticate securely to their smartwatches and sensitive services through solely two gestures. It leverages the rotating bezel or the crown which are the most intuitive channels to interact with a smartwatch. 2GesturePIN enhances the resilience of the regular PIN to common attacks while maintaining a high level of usability. Meriem Guerar, Luca Verderame, Mauro Migliardi, Alessio Merlo |
WETICE | 4 |
| 2019 | Towards Policy-Driven Monitoring of Fog ApplicationsabstractThis paper introduces a proposal aimed at defining a novel methodology for run-time monitoring of Fog applications which is both policy-driven and app-agnostic. The first feature grants the possibility to define security policies that are enforced at run-time on a single or a set of Fog applications. The latter allows to enforce the security policies independently from the execution environment of the Fog applications (e.g., Virtual Machine, Container, PaaS, ...). The paper also discusses a PoC implementation on Cisco IOx. Enrico Russo 0001, Luca Verderame, Alessio Merlo |
WETICE | 3 |
| 2019 | Automated Security Analysis of IoT Software Updates
Nicolas Dejon, Davide Caputo, Luca Verderame, Alessandro Armando, Alessio Merlo |
WISTP | 5 |
| 2018 | Phishing Attacks on Modern AndroidabstractModern versions of Android have introduced a number of features in the name of convenience. This paper shows how two of these features, mobile password managers and Instant Apps, can be abused to make phishing attacks that are significantly more practical than existing ones. We have studied the leading password managers for mobile and we uncovered a number of design issues that leave them open to attacks. For example, we show it is possible to trick password managers into auto-suggesting credentials associated with arbitrary attacker-chosen websites. We then show how an attacker can abuse the recently introduced Instant Apps technology to allow a remote attacker to gain full UI control and, by abusing password managers, to implement an end-to-end phishing attack requiring only few user's clicks. We also found that mobile password managers are vulnerable to "hidden fields" attacks, which makes these attacks even more practical and problematic. We conclude this paper by proposing a new secure-by-design API that avoids common errors and we show that the secure implementation of autofill functionality will require a community-wide effort, which this work hopes to inspire. Simone Aonzo, Alessio Merlo, Giulio Tavella, Yanick Fratantonio |
CCS | 2 |
| 2018 | Saving energy in aggressive intrusion detection through dynamic latency sensitivity recognition
Sherenaz W. Al-Haj Baddar, Alessio Merlo, Mauro Migliardi, Francesco Palmieri 0002 |
Comput. Secur. | 2 |
| 2018 | Invisible CAPPCHA: A usable mechanism to distinguish between malware and humans on the mobile IoT
Meriem Guerar, Alessio Merlo, Mauro Migliardi, Francesco Palmieri 0002 |
Comput. Secur. | 2 |
| 2018 | HPC & Co strike back: Where are distributed paradigms heading toward?abstractFrom the dawn of parallelization, the diffusion of High-Performance Computing (HPC) has grown exponentially until nowadays, thereby leading to the birth and development of a huge research community in this field.During the last decades, the important research results have led to extend the domain of HPC into three different dimensions, namely Architectures, Research Topics, and Application Domains. ArchitecturesTraditional HPC architectures have been sided with several wide-area distributed paradigms such as Peer-to-Peer (P2P), Grid, Cloud, Fog and Pervasive Computing.[1][2][3] Each of them aims new specific objectives along with the original goal of improving performance and reliability.In this paper, the different declinations of the traditional HPC are grouped into three macro-categories, namely SIMD, Multi- * , and Cluster.• SIMD.It stands for "single instruction, multiple data" according to the Flynn taxonomy.4 This refers to computing systems where a single instruction stream operates on multiple data streams in order to perform operations that may be naturally parallelized (eg, array processors, GPUs, GPGPUs, etc).This category also includes many specialized processing units, as vector extensions of modern processors like Streaming SIMD Extensions (SSE) 5 or Advanced Vector Extensions (AVX). 6• Multi- * .It refers to many-core, multi-core, and multi-processor architectures.They are all architectures characterized by the presence of multiple instruction streams operating on multiple data streams.What distinguishes this type of architectures from other MIMD architectures ("multiple instructions, multiple data" always according to the Flynn taxonomy 4 ) is the sharing of the central memory.• Cluster.It refers to Cluster Computing, namely a group of cost-effective linked commercial off-the-shelf computers working together so closely that they act as a single machine.What distinguishes this type of architecture from other MIMD-like architectures is the absence of central memory sharing (each processing unit has its own private memory) but the presence of mass memory sharing.As a matter of fact, the current Top500 supercomputers 7 are mostly clusters.Regarding wide-area distributed paradigms, all of them are included in the MIMD category (according to the Flynn's taxonomy).What distinguishes this type of architecture from other MIMD architectures is the lack of sharing of both the central memory and the mass memory.This paper takes into consideration the main four distributed paradigms that arose from traditional HPC, namely Grid Computing, Ubiquitous Computing, Peer-to-Peer Computing, Cloud, and the emerging Fog Computing.In brief:• Grid Computing 8-10 denotes a distributed architecture that enables coordinated resource sharing for problem-solving within dynamic organizations consisting of individuals, institutions, and resources.• Ubiquitous Computing (also known as Pervasive Computing or UbiComp) 11,12 refers to making available to users computational resources, which provide information and services, anytime and everywhere throughout the physical environment.• Peer-to-peer (P2P) 13 is a distributed paradigm made by a network of nodes, where each node has the same capabilities of other nodes; the computation is carried out by the interactions between a node and its neighbors.P2P networks have been originally used for sharing contents.• Cloud and Fog Computing 14,15 refers to a computing model that enables ubiquitous and on-demand access to a shared set of resources spread over the Internet and delivered as services.Such resources are quickly provisioned and released at an infrastructure, platform, or application level.Cloud Computing 15 is often seen as an evolution of Grid Computing where the best-effort access to resources is substituted by a rapid provision of customized resources requiring a minimal management effort.Indeed, both Grid and Cloud computing trace their roots back to the notion of Utility Computing, ie, computing being delivered as a public utility.This notion was introduced by John McCarthy in a speech at the MIT Centennial in 1961.16 As in the Cloud, the computation is executed on remote machines; there could be non-negligible latency and security issues.This Sébastien Limet, Alessio Merlo, Luca Spalazzi |
Concurr. Comput. Pract. Exp. | 2 |
| 2018 | Automatic security verification of mobile app configurations
Gabriele Costa 0001, Alessio Merlo, Luca Verderame, Alessandro Armando |
Future Gener. Comput. Syst. | 2 |
| 2018 | Completely Automated Public Physical test to tell Computers and Humans Apart: A usability study on mobile devices
Meriem Guerar, Alessio Merlo, Mauro Migliardi |
Future Gener. Comput. Syst. | 2 |
| 2018 | Using Screen Brightness to Improve Security in Mobile Social Network AccessabstractIn the today's mobile communications scenario, smartphones offer new capabilities to develop sophisticated applications that seem to make daily life easier and more convenient for users. Such applications, which may involve mobile ticketing, identification, access control operations, etc., are often accessible through social network aggregators, that assume a fundamental role in the federated identity management space. While this makes modern smartphones very powerful devices, it also makes them very attractive targets for spyware injection. This kind of malware is able to bypass classic authentication measures and steal user credentials even when a secure element is used, and can, therefore, perform unauthorized mobile access to social network services without the user's consent. Such an event allows stealing sensitive information or even a full identity theft. In this work, we address this issue by introducing BrightPass, a novel authentication mechanism based on screen brightness. BrightPass allows users to authenticate safely with a PIN-based confirmation in the presence of specific operations on sensitive data. We compare BrightPass with existing schemes, in order to show its usability and security within the social network arena. Furthermore, we empirically assess the security of BrightPass through experimentation. Our tests indicate that BrightPass protects the PIN code against automatic submissions carried out by malware while granting fast authentication phases and reduced error rates. Meriem Guerar, Mauro Migliardi, Alessio Merlo, Mohamed Benmohammed, Francesco Palmieri 0002, Aniello Castiglione |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2017 | Reducing the Impact of Traffic Sanitization on Latency Sensitive Applications
Mauro Migliardi, Alessio Merlo, Sherenaz W. Al-Haj Baddar |
CISIS | 2 |
| 2017 | Dynamic Latency Sensitivity Recognition: An Application to Energy Saving
Sherenaz W. Al-Haj Baddar, Alessio Merlo, Mauro Migliardi, Francesco Palmieri 0002 |
GPC | 2 |
| 2017 | BYODCert: Toward a Cross-Organizational BYOD Paradigm
Alessio Merlo |
GPC | 1 |
| 2017 | RiskInDroid: Machine Learning-Based Risk Analysis on Android
Alessio Merlo, Gabriel Claudiu Georgiu |
SEC | 1 |
| 2017 | RmPerm: A Tool for Android Permissions RemovalabstractAndroid apps are generally over-privileged, i.e., they request more permissions than they actually need to execute properly. Prior to version 6 users can install an app only by accepting all its requested permissions, while newer Android versions allow users to dynamically grant/deny groups of permissions. Since some them impact on users' privacy, we argue that users should be granted control at the granularity of the single permission. We propose a novel approach, which does not require any change to the underlying OS, allowing users to selectively remove permissions from apps before installing them, and with a finer granularity. \nWe developed \tool, an open-source tool, that implements our methodology, and we present the viability of our approach via an empirical assessment on 81K apps, \nunderlining that, in the worst case, up to 86% of the apps can execute without crashing when none of the requested privacy-related permissions are granted. Simone Aonzo, Giovanni Lagorio, Alessio Merlo |
SECRYPT | 3 |
| 2016 | FLEX: A Flexible Code Authentication Framework for Delegating Mobile App CustomizationabstractMobile code distribution relies on digital signatures to guarantee code authenticity. Unfortunately, standard signature schemes are not well suited for use in conjunction with program transformation techniques, such as aspect-oriented programming. With these techniques, code development is performed in sequence by multiple teams of programmers. This is fundamentally different from traditional single-developer/ single-user models, where users can verify end-to-end (i.e., developer-to-user) authenticity of the code using digital signatures. To address this limitation, we introduce FLEX, a flexible code authentication framework for mobile applications. FLEX allows semi-trusted intermediaries to modify mobile code without invalidating the developer's signature, as long as the modification complies with a "contract" issued by the developer. We introduce formal definitions for secure code modification, and show that our instantiation of FLEX is secure under these definitions. Although FLEX can be instantiated using any language, we design AMJ--a novel programming language that supports code annotations--and implement a FLEX prototype based on our new language. Gabriele Costa 0001, Paolo Gasti, Alessio Merlo, Shunt-Hsi Yu |
AsiaCCS | 3 |
| 2016 | Android vs. SEAndroid: An empirical assessment
Alessio Merlo, Gabriele Costa 0001, Luca Verderame, Alessandro Armando |
Pervasive Mob. Comput. | 1 |
| 2015 | Android Permissions UnleashedabstractThe Android Security Framework controls the executions of applications through permissions which are statically granted by the user during installation. However, the definition of security policies over permissions is not supported. Security policies must be therefore manually encoded into the application by the developer, which is a dangerous practice and may cause security breaches. We propose an improvement over the Android permission system that supports the specification and enforcement of fine-grained security policies. Enforcement is achieved by reducing policy decision problems to propositional satisfiability and leveraging a state-of-the-art SAT solver. Unlike alternative proposals, our approach does not require changes in the operating system and, therefore, it can be readily deployed in any commercial device. Alessandro Armando, Roberto Carbone, Gabriele Costa 0001, Alessio Merlo |
CSF | 4 |
| 2015 | SAM: The Static Analysis Module of the MAVERIC Mobile App Security Verification Platform
Alessandro Armando, Gianluca Bocci, Giantonio Chiarelli, Gabriele Costa 0001, Gabriele De Maglie, Rocco Mammoliti, Alessio Merlo |
TACAS | 7 |
| 2015 | Measuring and estimating power consumption in Android to support energy-based intrusion detectionabstractThis paper investigates the feasibility of constructing power-consumption-based sensors for the identification of security threats (e.g. battery-drain attacks) on Android based mobile devices. In particular, this paper proposes a measurement methodology and high-level models for the energy consumpt ion of two very important hardware subsystems in a mobile device, namely the Wi-Fi and the CPU. The measuring methodology and the high-level models are then compared to others described in the literature and validated through actual experiments. Finally, the proposed methodology is tested with an energy oriented variant of the ping-flood attack performed while a legitimate application is running. Experimental results show that the measurement methodology is sound, precise and reliable in detecting the onset of an attack. Alessio Merlo, Mauro Migliardi, Paolo Fontanelli |
J. Comput. Secur. | 1 |
| 2015 | A survey on energy-aware security mechanisms
Alessio Merlo, Mauro Migliardi, Luca Caviglione |
Pervasive Mob. Comput. | 1 |
| 2014 | Enabling BYOD through secure meta-marketabstractMobile security is a hot research topic. Yet most of available techniques focus on securing individual applications and therefore cannot possibly tackle security weaknesses stemming from the combined use of one or more applications (e.g. confused deputy attacks). Preventing these types of attacks is crucial in many important application scenarios. For instance, their prevention is a prerequisite for the widespread adoption of the BYOD paradigm in the corporate setting. Alessandro Armando, Gabriele Costa 0001, Alessio Merlo, Luca Verderame |
WISEC | 3 |
| 2014 | A Denial of Service Attack to UMTS Networks Using SIM-Less DevicesabstractOne of the fundamental security elements in cellular networks is the authentication procedure performed by means of the Subscriber Identity Module that is required to grant access to network services and hence protect the network from unauthorized usage. Nonetheless, in this work we present a new kind of denial of service attack based on properly crafted SIM-less devices that, without any kind of authentication and by exploiting some specific features and performance bottlenecks of the UMTS network attachment process, are potentially capable of introducing significant service degradation up to disrupting large sections of the cellular network coverage. The knowledge of this attack can be exploited by several applications both in security and in network equipment manufacturing sectors. Alessio Merlo, Mauro Migliardi, Nicola Gobbo, Francesco Palmieri 0002, Aniello Castiglione |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2013 | An Empirical Evaluation of the Android Security Framework
Alessandro Armando, Alessio Merlo, Luca Verderame |
SEC | 2 |
| 2013 | Breaking and fixing the Android Launching Flow
Alessandro Armando, Alessio Merlo, Mauro Migliardi, Luca Verderame |
Comput. Secur. | 2 |
| 2013 | Secure cooperative access control on grid
Alessio Merlo |
Future Gener. Comput. Syst. | 1 |
| 2012 | Would You Mind Forking This Process? A Denial of Service Attack on Android (and Some Countermeasures)
Alessandro Armando, Alessio Merlo, Mauro Migliardi, Luca Verderame |
SEC | 2 |
| 2011 | What is Green Security?abstractGreen Security is a new research field defining and investigating security solutions under an energy-aware perspective. Green Security aims at: (1) evaluating the actual security mechanisms in order to assess their energy consumption; (2) building new security mechanisms by considering energy costs from the design phase. In this paper, we first provide a definition of Green Security and formalism to model it, then we provide a use case showing how it is possible to model the energy consumption of two Intrusion Detection System (IDS) strategies, finally we leverage this model to assess the energy leakage due to the late discovery of bad packets. Luca Caviglione, Alessio Merlo, Mauro Migliardi |
IAS | 2 |
| 2011 | On Re-use of randomness in broadcast encryptionabstractBroadcast encryption provides an efficient way to encrypt a message for a large number of receivers. This paper investigates whether it is possible to further improve efficiency of an existing state-of-the-art broadcast encryption scheme by reusing a some of the random choices among different encryptions, without compromising the security of the original scheme. We introduce two schemes: the first allows a transmitter to efficiently encrypt several messages to a set of users; the second scheme extends the first by allowing the transmitter to efficiently send independent messages to different groups at once. We illustrate two scenarios where our schemes provide significant advantages compared to existing solutions. Paolo Gasti, Alessio Merlo |
PST | 2 |
| 2011 | Quality of Service on Grid: architectural and methodological issuesabstractAbstract The rapid evolution of Grid Computing and the development of new middleware services make Grid platforms increasingly used not only for best effort scientific jobs but also in industrial and business applications. This has taken to the growing demand of Quality of Service (QoS) support. However, the QoS issue on Grid is quite difficult, as Grid has been originally designed without any QoS support, and it is a complex system. During the previous years some solutions have been proposed to supply QoS for specific classes of applications. This results in a focused and a heterogeneous approach, so that it is hard to evaluate its sufficiency and its robustness with respect to the large spectrum of possible Grid applications. In this context, our contribution concerns three points: first, we analyze the current approach to QoS on Grid as a relationship among QoS features, applications, and architectures; second, we evaluate the QoS requirements of two recent QoS‐demanding applications on Grid, namely Massive Multiplayer Online Games and Urgent Computing, comparing these requirements with the support provided by current QoS architectures; and third, we propose an alternative approach to QoS provision on Grid based on the definition of a dedicated QoS‐management layer to overcome the limitations of the current methodologies. Copyright © 2010 John Wiley & Sons, Ltd. Alessio Merlo, Andrea Clematis, Angelo Corana, Vittoria Gianuzzi |
Concurr. Comput. Pract. Exp. | 1 |
| 2010 | Cooperative access control for the GridabstractThe access to Grid resources depends on rules defined by the administrators of the physical organizations and of the Grid middleware. This approach does not require support for access control in the middleware, but since changes in the access control policy of the Virtual Organization imply the involvement of one or more administrators, it lacks the flexibility needed in a several application scenarios. In this paper we propose a group-based access control model for Grid environments that increases the flexibility of the access control model offered by state-of-the-art Grid platforms without requiring changes in the middleware. The approach is based on collaboration among Grid users and allows them to exchange access permissions to Virtual Resources without the intervention administrators. We show that our solution can be defined on top of the access control mechanisms offered by state-of-the-art Grid middleware and illustrate how the proposed model can be implemented as a service in a service-oriented Grid environment. Alessio Merlo, Alessandro Armando |
IAS | 1 |
| 2010 | On the Integrity of Network Coding-Based Anonymous P2P File Sharing NetworksabstractNetwork coding is a class of routing algorithms offering increased throughput and improved robustness to random failures. With traditional routing, intermediate nodes in the network may only forward unmodified packets. With network coding, instead, intermediate nodes are allowed to forward linear combinations of received packets. Original data can be reconstructed after collecting sufficiently many linear combinations. Current file sharing systems offer either low overhead and high bandwidth with no privacy, or acceptable privacy at very low speed. Thanks to network coding, a general-purpose P2P network can obtain a privacy/performance tradeoff that may be considered reasonable in most real-world scenarios. In this paper we present an integrity strategy for network coding-based P2P anonymous systems, specifically designed to preserve the anonymity of peers. Our approach is significantly easier to implement than current solutions when anonymity is required. We implement the cryptographic algorithms on which our method is based and provide performance figures. We also define verification strategies which use batching for improved performances together with an efficiency analysis. Paolo Gasti, Alessio Merlo, Giuseppe Ciaccio, Giovanni Chiola |
NCA | 2 |
| 2008 | A Distributed Approach for Structured Resource Discovery on GridabstractWe present a distributed approach for grid resource discovery, which combines a structured view of resources (single machines, homogeneous and heterogeneous clusters) at the physical organization (PO) level with a super-peer network connecting the various POs. The proposed architecture is modular and independent of the particular grid middleware. After a general description, we present some implementation aspects which refer to the Globus Toolkit 4 as grid middleware and to the JXTA platform to set-up the super-peer network. The system is particularly suitable for discovering resources for structured parallel applications on very large grids. Andrea Clematis, Daniele D'Agostino, Alfonso Quarati, Angelo Corana, Vittoria Gianuzzi, Alessio Merlo |
CISIS | 6 |
| 2008 | Managing Networks of Mobiles Entities Using the HyVonNe P2P ArchitectureabstractVoronoi diagrams and Delaunay triangulations are gaining attention in several P2P applications managing a wide number of distributed and mobile entities, from resource discovery in auction-like networks to the realization of networked virtual environments. In this paper we consider a scalable partitioning technique of the entity space based on Voronoi diagrams, useful for a wide variety of distributed applications that exhibit a dynamically changing topology. Using the HyVonNe (hybrid Voronoi network) architecture, the space is partitioned in Voronoi regions, each one including a limited number of entities and managed by a region leader, that are created and deleted depending on the spatial density of such entities, while the Delaunay triangulation connecting the region leaders is used to support the partitioning, routing and searching activities. The resulting two-layers structure (entity space and Voronoi regions) is scalable and extendable, allows to reduce the propagation of the entity position updates in the network and to maintain the load balancing among regions. Simulation results related to two different application fields are presented. Vittoria Gianuzzi, Alessio Merlo, Andrea Clematis, Daniele D'Agostino |
CISIS | 2 |